calico
calico copied to clipboard
When enabling NodeLocal DNSCache DNS requests are being blocked
After enabling the NodeLocal DNSCache feature, requests from pods to kube-dns SVC are getting blocked by Calico Policy. The NodeLocal DNS pods are deployed exactly with the same labels as the coredns pods
Steps to Reproduce (for bugs)
- Deploy a K8S cluster.
- Enforce the cluster using Calico GlobalNetworkPolicy
- Enable NodeLocal DNSCache
Your Environment
- Calico version: 3.14.1
- Kubernetes: 1.17.4
- Operating System and version: Centos/Ubuntu https://kubernetes.io/docs/tasks/administer-cluster/nodelocaldns/