level=info msg="Memory available for map entries (0.003% of 16764956672B): 41912391B" subsys=config level=info msg="option bpf-ct-global-tcp-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-ct-global-any-max set by dynamic sizing to 73530" subsys=config level=info msg="option bpf-nat-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-neigh-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-sock-rev-map-max set by dynamic sizing to 73530" subsys=config level=info msg=" --agent-health-port='9879'" subsys=daemon level=info msg=" --agent-labels=''" subsys=daemon level=info msg=" --agent-liveness-update-interval='1s'" subsys=daemon level=info msg=" --agent-not-ready-taint-key='node.cilium.io/agent-not-ready'" subsys=daemon level=info msg=" --allocator-list-timeout='3m0s'" subsys=daemon level=info msg=" --allow-icmp-frag-needed='true'" subsys=daemon level=info msg=" --allow-localhost='auto'" subsys=daemon level=info msg=" --annotate-k8s-node='false'" subsys=daemon level=info msg=" --api-rate-limit=''" subsys=daemon level=info msg=" --arping-refresh-period='30s'" subsys=daemon level=info msg=" --auto-create-cilium-node-resource='true'" subsys=daemon level=info msg=" --auto-direct-node-routes='false'" subsys=daemon level=info msg=" --bgp-announce-lb-ip='false'" subsys=daemon level=info msg=" --bgp-announce-pod-cidr='false'" subsys=daemon level=info msg=" --bgp-config-path='/var/lib/cilium/bgp/config.yaml'" subsys=daemon level=info msg=" --bpf-auth-map-max='524288'" subsys=daemon level=info msg=" --bpf-ct-global-any-max='262144'" subsys=daemon level=info msg=" --bpf-ct-global-tcp-max='524288'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-fin='10s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-syn='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp-grace='1m0s'" subsys=daemon level=info msg=" --bpf-filter-priority='1'" subsys=daemon level=info msg=" --bpf-fragments-map-max='8192'" subsys=daemon level=info msg=" --bpf-lb-acceleration='disabled'" subsys=daemon level=info msg=" --bpf-lb-affinity-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-algorithm='random'" subsys=daemon level=info msg=" --bpf-lb-dev-ip-addr-inherit=''" subsys=daemon level=info msg=" --bpf-lb-dsr-dispatch='opt'" subsys=daemon level=info msg=" --bpf-lb-dsr-l4-xlate='frontend'" subsys=daemon level=info msg=" --bpf-lb-external-clusterip='false'" subsys=daemon level=info msg=" --bpf-lb-maglev-hash-seed='JLfvgnHc2kaSUFaI'" subsys=daemon level=info msg=" --bpf-lb-maglev-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-maglev-table-size='16381'" subsys=daemon level=info msg=" --bpf-lb-map-max='65536'" subsys=daemon level=info msg=" --bpf-lb-mode='snat'" subsys=daemon level=info msg=" --bpf-lb-rev-nat-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-rss-ipv4-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-rss-ipv6-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-service-backend-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-service-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-sock='false'" subsys=daemon level=info msg=" --bpf-lb-sock-hostns-only='false'" subsys=daemon level=info msg=" --bpf-lb-source-range-map-max='0'" subsys=daemon level=info msg=" --bpf-map-dynamic-size-ratio='0.0025'" subsys=daemon level=info msg=" --bpf-map-event-buffers=''" subsys=daemon level=info msg=" --bpf-nat-global-max='524288'" subsys=daemon level=info msg=" --bpf-neigh-global-max='524288'" subsys=daemon level=info msg=" --bpf-policy-map-full-reconciliation-interval='15m0s'" subsys=daemon level=info msg=" --bpf-policy-map-max='16384'" subsys=daemon level=info msg=" --bpf-root='/sys/fs/bpf'" subsys=daemon level=info msg=" --bpf-sock-rev-map-max='262144'" subsys=daemon level=info msg=" --bypass-ip-availability-upon-restore='false'" subsys=daemon level=info msg=" --certificates-directory='/var/run/cilium/certs'" subsys=daemon level=info msg=" --cflags=''" subsys=daemon level=info msg=" --cgroup-root='/run/cilium/cgroupv2'" subsys=daemon level=info msg=" --cilium-endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --cluster-health-port='4240'" subsys=daemon level=info msg=" --cluster-id='0'" subsys=daemon level=info msg=" --cluster-name='default'" subsys=daemon level=info msg=" --cluster-pool-ipv4-cidr='10.0.0.0/8'" subsys=daemon level=info msg=" --cluster-pool-ipv4-mask-size='24'" subsys=daemon level=info msg=" --clustermesh-config='/var/lib/cilium/clustermesh/'" subsys=daemon level=info msg=" --clustermesh-ip-identities-sync-timeout='1m0s'" subsys=daemon level=info msg=" --cmdref=''" subsys=daemon level=info msg=" --cni-chaining-mode='none'" subsys=daemon level=info msg=" --cni-chaining-target=''" subsys=daemon level=info msg=" --cni-exclusive='true'" subsys=daemon level=info msg=" --cni-external-routing='false'" subsys=daemon level=info msg=" --cni-log-file='/var/run/cilium/cilium-cni.log'" subsys=daemon level=info msg=" --cnp-node-status-gc-interval='0s'" subsys=daemon level=info msg=" --config=''" subsys=daemon level=info msg=" --config-dir='/tmp/cilium/config-map'" subsys=daemon level=info msg=" --config-sources='config-map:kube-system/cilium-config'" subsys=daemon level=info msg=" --conntrack-gc-interval='0s'" subsys=daemon level=info msg=" --conntrack-gc-max-interval='0s'" subsys=daemon level=info msg=" --crd-wait-timeout='5m0s'" subsys=daemon level=info msg=" --custom-cni-conf='false'" subsys=daemon level=info msg=" --datapath-mode='veth'" subsys=daemon level=info msg=" --debug='false'" subsys=daemon level=info msg=" --debug-verbose=''" subsys=daemon level=info msg=" --derive-masquerade-ip-addr-from-device=''" subsys=daemon level=info msg=" --devices=''" subsys=daemon level=info msg=" --direct-routing-device=''" subsys=daemon level=info msg=" --disable-cnp-status-updates='true'" subsys=daemon level=info msg=" --disable-endpoint-crd='false'" subsys=daemon level=info msg=" --disable-envoy-version-check='false'" subsys=daemon level=info msg=" --disable-iptables-feeder-rules=''" subsys=daemon level=info msg=" --dns-max-ips-per-restored-rule='1000'" subsys=daemon level=info msg=" --dns-policy-unload-on-shutdown='false'" subsys=daemon level=info msg=" --dnsproxy-concurrency-limit='0'" subsys=daemon level=info msg=" --dnsproxy-concurrency-processing-grace-period='0s'" subsys=daemon level=info msg=" --dnsproxy-enable-transparent-mode='true'" subsys=daemon level=info msg=" --dnsproxy-lock-count='128'" subsys=daemon level=info msg=" --dnsproxy-lock-timeout='500ms'" subsys=daemon level=info msg=" --egress-gateway-policy-map-max='16384'" subsys=daemon level=info msg=" --egress-gateway-reconciliation-trigger-interval='1s'" subsys=daemon level=info msg=" --egress-masquerade-interfaces=''" subsys=daemon level=info msg=" --egress-multi-home-ip-rule-compat='false'" subsys=daemon level=info msg=" --enable-auto-protect-node-port-range='true'" subsys=daemon level=info msg=" --enable-bandwidth-manager='false'" subsys=daemon level=info msg=" --enable-bbr='false'" subsys=daemon level=info msg=" --enable-bgp-control-plane='false'" subsys=daemon level=info msg=" --enable-bpf-clock-probe='false'" subsys=daemon level=info msg=" --enable-bpf-masquerade='false'" subsys=daemon level=info msg=" --enable-bpf-tproxy='false'" subsys=daemon level=info msg=" --enable-cilium-api-server-access='*'" subsys=daemon level=info msg=" --enable-cilium-endpoint-slice='false'" subsys=daemon level=info msg=" --enable-cilium-health-api-server-access='*'" subsys=daemon level=info msg=" --enable-custom-calls='false'" subsys=daemon level=info msg=" --enable-endpoint-health-checking='true'" subsys=daemon level=info msg=" --enable-endpoint-routes='false'" subsys=daemon level=info msg=" --enable-envoy-config='false'" subsys=daemon level=info msg=" --enable-external-ips='false'" subsys=daemon level=info msg=" --enable-health-check-nodeport='true'" subsys=daemon level=info msg=" --enable-health-checking='true'" subsys=daemon level=info msg=" --enable-high-scale-ipcache='false'" subsys=daemon level=info msg=" --enable-host-firewall='false'" subsys=daemon level=info msg=" --enable-host-legacy-routing='false'" subsys=daemon level=info msg=" --enable-host-port='false'" subsys=daemon level=info msg=" --enable-hubble='false'" subsys=daemon level=info msg=" --enable-hubble-recorder-api='true'" subsys=daemon level=info msg=" --enable-icmp-rules='true'" subsys=daemon level=info msg=" --enable-identity-mark='true'" subsys=daemon level=info msg=" --enable-ip-masq-agent='false'" subsys=daemon level=info msg=" --enable-ipsec='false'" subsys=daemon level=info msg=" --enable-ipsec-key-watcher='true'" subsys=daemon level=info msg=" --enable-ipv4='true'" subsys=daemon level=info msg=" --enable-ipv4-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv4-egress-gateway='false'" subsys=daemon level=info msg=" --enable-ipv4-fragment-tracking='true'" subsys=daemon level=info msg=" --enable-ipv4-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6='false'" subsys=daemon level=info msg=" --enable-ipv6-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv6-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6-ndp='false'" subsys=daemon level=info msg=" --enable-k8s='true'" subsys=daemon level=info msg=" --enable-k8s-api-discovery='false'" subsys=daemon level=info msg=" --enable-k8s-endpoint-slice='true'" subsys=daemon level=info msg=" --enable-k8s-event-handover='false'" subsys=daemon level=info msg=" --enable-k8s-networkpolicy='true'" subsys=daemon level=info msg=" --enable-k8s-terminating-endpoint='true'" subsys=daemon level=info msg=" --enable-l2-announcements='false'" subsys=daemon level=info msg=" --enable-l2-neigh-discovery='true'" subsys=daemon level=info msg=" --enable-l2-pod-announcements='false'" subsys=daemon level=info msg=" --enable-l7-proxy='true'" subsys=daemon level=info msg=" --enable-local-node-route='true'" subsys=daemon level=info msg=" --enable-local-redirect-policy='false'" subsys=daemon level=info msg=" --enable-mke='false'" subsys=daemon level=info msg=" --enable-monitor='true'" subsys=daemon level=info msg=" --enable-nat46x64-gateway='false'" subsys=daemon level=info msg=" --enable-node-port='false'" subsys=daemon level=info msg=" --enable-pmtu-discovery='false'" subsys=daemon level=info msg=" --enable-policy='default'" subsys=daemon level=info msg=" --enable-recorder='false'" subsys=daemon level=info msg=" --enable-remote-node-identity='true'" subsys=daemon level=info msg=" --enable-runtime-device-detection='false'" subsys=daemon level=info msg=" --enable-sctp='false'" subsys=daemon level=info msg=" --enable-service-topology='false'" subsys=daemon level=info msg=" --enable-session-affinity='false'" subsys=daemon level=info msg=" --enable-srv6='false'" subsys=daemon level=info msg=" --enable-stale-cilium-endpoint-cleanup='true'" subsys=daemon level=info msg=" --enable-svc-source-range-check='true'" subsys=daemon level=info msg=" --enable-tracing='false'" subsys=daemon level=info msg=" --enable-unreachable-routes='false'" subsys=daemon level=info msg=" --enable-vtep='false'" subsys=daemon level=info msg=" --enable-well-known-identities='false'" subsys=daemon level=info msg=" --enable-wireguard='false'" subsys=daemon level=info msg=" --enable-wireguard-userspace-fallback='false'" subsys=daemon level=info msg=" --enable-xdp-prefilter='false'" subsys=daemon level=info msg=" --enable-xt-socket-fallback='true'" subsys=daemon level=info msg=" --encrypt-interface=''" subsys=daemon level=info msg=" --encrypt-node='false'" subsys=daemon level=info msg=" --endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --endpoint-queue-size='25'" subsys=daemon level=info msg=" --endpoint-status=''" subsys=daemon level=info msg=" --envoy-config-timeout='2m0s'" subsys=daemon level=info msg=" --envoy-log=''" subsys=daemon level=info msg=" --exclude-local-address=''" subsys=daemon level=info msg=" --external-envoy-proxy='false'" subsys=daemon level=info msg=" --fixed-identity-mapping=''" subsys=daemon level=info msg=" --fqdn-regex-compile-lru-size='1024'" subsys=daemon level=info msg=" --gops-port='9890'" subsys=daemon level=info msg=" --http-403-msg=''" subsys=daemon level=info msg=" --http-idle-timeout='0'" subsys=daemon level=info msg=" --http-max-grpc-timeout='0'" subsys=daemon level=info msg=" --http-normalize-path='true'" subsys=daemon level=info msg=" --http-request-timeout='3600'" subsys=daemon level=info msg=" --http-retry-count='3'" subsys=daemon level=info msg=" --http-retry-timeout='0'" subsys=daemon level=info msg=" --hubble-disable-tls='false'" subsys=daemon level=info msg=" --hubble-event-buffer-capacity='4095'" subsys=daemon level=info msg=" --hubble-event-queue-size='0'" subsys=daemon level=info msg=" --hubble-export-file-compress='false'" subsys=daemon level=info msg=" --hubble-export-file-max-backups='5'" subsys=daemon level=info msg=" --hubble-export-file-max-size-mb='10'" subsys=daemon level=info msg=" --hubble-export-file-path=''" subsys=daemon level=info msg=" --hubble-listen-address=''" subsys=daemon level=info msg=" --hubble-metrics=''" subsys=daemon level=info msg=" --hubble-metrics-server=''" subsys=daemon level=info msg=" --hubble-monitor-events=''" subsys=daemon level=info msg=" --hubble-prefer-ipv6='false'" subsys=daemon level=info msg=" --hubble-recorder-sink-queue-size='1024'" subsys=daemon level=info msg=" --hubble-recorder-storage-path='/var/run/cilium/pcaps'" subsys=daemon level=info msg=" --hubble-skip-unknown-cgroup-ids='true'" subsys=daemon level=info msg=" --hubble-socket-path='/var/run/cilium/hubble.sock'" subsys=daemon level=info msg=" --hubble-tls-cert-file=''" subsys=daemon level=info msg=" --hubble-tls-client-ca-files=''" subsys=daemon level=info msg=" --hubble-tls-key-file=''" subsys=daemon level=info msg=" --identity-allocation-mode='crd'" subsys=daemon level=info msg=" --identity-change-grace-period='5s'" subsys=daemon level=info msg=" --identity-gc-interval='15m0s'" subsys=daemon level=info msg=" --identity-heartbeat-timeout='30m0s'" subsys=daemon level=info msg=" --identity-restore-grace-period='10m0s'" subsys=daemon level=info msg=" --install-egress-gateway-routes='false'" subsys=daemon level=info msg=" --install-iptables-rules='true'" subsys=daemon level=info msg=" --install-no-conntrack-iptables-rules='false'" subsys=daemon level=info msg=" --ip-allocation-timeout='2m0s'" subsys=daemon level=info msg=" --ip-masq-agent-config-path='/etc/config/ip-masq-agent'" subsys=daemon level=info msg=" --ipam='cluster-pool'" subsys=daemon level=info msg=" --ipam-cilium-node-update-rate='15s'" subsys=daemon level=info msg=" --ipam-multi-pool-pre-allocation='default=8'" subsys=daemon level=info msg=" --ipsec-key-file=''" subsys=daemon level=info msg=" --ipsec-key-rotation-duration='5m0s'" subsys=daemon level=info msg=" --iptables-lock-timeout='5s'" subsys=daemon level=info msg=" --iptables-random-fully='false'" subsys=daemon level=info msg=" --ipv4-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv4-node='auto'" subsys=daemon level=info msg=" --ipv4-pod-subnets=''" subsys=daemon level=info msg=" --ipv4-range='auto'" subsys=daemon level=info msg=" --ipv4-service-loopback-address='169.254.42.1'" subsys=daemon level=info msg=" --ipv4-service-range='auto'" subsys=daemon level=info msg=" --ipv6-cluster-alloc-cidr='f00d::/64'" subsys=daemon level=info msg=" --ipv6-mcast-device=''" subsys=daemon level=info msg=" --ipv6-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv6-node='auto'" subsys=daemon level=info msg=" --ipv6-pod-subnets=''" subsys=daemon level=info msg=" --ipv6-range='auto'" subsys=daemon level=info msg=" --ipv6-service-range='auto'" subsys=daemon level=info msg=" --join-cluster='false'" subsys=daemon level=info msg=" --k8s-api-server=''" subsys=daemon level=info msg=" --k8s-client-burst='10'" subsys=daemon level=info msg=" --k8s-client-qps='5'" subsys=daemon level=info msg=" --k8s-heartbeat-timeout='30s'" subsys=daemon level=info msg=" --k8s-kubeconfig-path=''" subsys=daemon level=info msg=" --k8s-namespace='kube-system'" subsys=daemon level=info msg=" --k8s-require-ipv4-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-require-ipv6-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-service-cache-size='128'" subsys=daemon level=info msg=" --k8s-service-proxy-name=''" subsys=daemon level=info msg=" --k8s-sync-timeout='3m0s'" subsys=daemon level=info msg=" --k8s-watcher-endpoint-selector='metadata.name!=kube-scheduler,metadata.name!=kube-controller-manager,metadata.name!=etcd-operator,metadata.name!=gcp-controller-manager'" subsys=daemon level=info msg=" --keep-config='false'" subsys=daemon level=info msg=" --kube-proxy-replacement='disabled'" subsys=daemon level=info msg=" --kube-proxy-replacement-healthz-bind-address=''" subsys=daemon level=info msg=" --kvstore=''" subsys=daemon level=info msg=" --kvstore-connectivity-timeout='2m0s'" subsys=daemon level=info msg=" --kvstore-lease-ttl='15m0s'" subsys=daemon level=info msg=" --kvstore-max-consecutive-quorum-errors='2'" subsys=daemon level=info msg=" --kvstore-opt=''" subsys=daemon level=info msg=" --kvstore-periodic-sync='5m0s'" subsys=daemon level=info msg=" --l2-announcements-lease-duration='15s'" subsys=daemon level=info msg=" --l2-announcements-renew-deadline='5s'" subsys=daemon level=info msg=" --l2-announcements-retry-period='2s'" subsys=daemon level=info msg=" --l2-pod-announcements-interface=''" subsys=daemon level=info msg=" --label-prefix-file=''" subsys=daemon level=info msg=" --labels=''" subsys=daemon level=info msg=" --lib-dir='/var/lib/cilium'" subsys=daemon level=info msg=" --local-max-addr-scope='252'" subsys=daemon level=info msg=" --local-router-ipv4=''" subsys=daemon level=info msg=" --local-router-ipv6=''" subsys=daemon level=info msg=" --log-driver=''" subsys=daemon level=info msg=" --log-opt=''" subsys=daemon level=info msg=" --log-system-load='false'" subsys=daemon level=info msg=" --max-controller-interval='0'" subsys=daemon level=info msg=" --mesh-auth-enabled='true'" subsys=daemon level=info msg=" --mesh-auth-gc-interval='5m0s'" subsys=daemon level=info msg=" --mesh-auth-mutual-listener-port='0'" subsys=daemon level=info msg=" --mesh-auth-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-rotated-identities-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-signal-backoff-duration='1s'" subsys=daemon level=info msg=" --mesh-auth-spiffe-trust-domain='spiffe.cilium'" subsys=daemon level=info msg=" --mesh-auth-spire-admin-socket=''" subsys=daemon level=info msg=" --metrics=''" subsys=daemon level=info msg=" --mke-cgroup-mount=''" subsys=daemon level=info msg=" --monitor-aggregation='medium'" subsys=daemon level=info msg=" --monitor-aggregation-flags='all'" subsys=daemon level=info msg=" --monitor-aggregation-interval='5s'" subsys=daemon level=info msg=" --monitor-queue-size='0'" subsys=daemon level=info msg=" --mtu='0'" subsys=daemon level=info msg=" --node-encryption-opt-out-labels='node-role.kubernetes.io/control-plane'" subsys=daemon level=info msg=" --node-port-acceleration='disabled'" subsys=daemon level=info msg=" --node-port-algorithm='random'" subsys=daemon level=info msg=" --node-port-bind-protection='true'" subsys=daemon level=info msg=" --node-port-mode='snat'" subsys=daemon level=info msg=" --node-port-range='30000,32767'" subsys=daemon level=info msg=" --nodes-gc-interval='5m0s'" subsys=daemon level=info msg=" --operator-api-serve-addr='127.0.0.1:9234'" subsys=daemon level=info msg=" --policy-audit-mode='false'" subsys=daemon level=info msg=" --policy-queue-size='100'" subsys=daemon level=info msg=" --policy-trigger-interval='1s'" subsys=daemon level=info msg=" --pprof='false'" subsys=daemon level=info msg=" --pprof-address='localhost'" subsys=daemon level=info msg=" --pprof-port='6060'" subsys=daemon level=info msg=" --preallocate-bpf-maps='false'" subsys=daemon level=info msg=" --prepend-iptables-chains='true'" subsys=daemon level=info msg=" --procfs='/host/proc'" subsys=daemon level=info msg=" --prometheus-serve-addr=':9962'" subsys=daemon level=info msg=" --proxy-connect-timeout='2'" subsys=daemon level=info msg=" --proxy-gid='1337'" subsys=daemon level=info msg=" --proxy-idle-timeout-seconds='60'" subsys=daemon level=info msg=" --proxy-max-connection-duration-seconds='0'" subsys=daemon level=info msg=" --proxy-max-requests-per-connection='0'" subsys=daemon level=info msg=" --proxy-prometheus-port='9964'" subsys=daemon level=info msg=" --read-cni-conf=''" subsys=daemon level=info msg=" --remove-cilium-node-taints='true'" subsys=daemon level=info msg=" --restore='true'" subsys=daemon level=info msg=" --route-metric='0'" subsys=daemon level=info msg=" --routing-mode='tunnel'" subsys=daemon level=info msg=" --set-cilium-is-up-condition='true'" subsys=daemon level=info msg=" --set-cilium-node-taints='true'" subsys=daemon level=info msg=" --sidecar-istio-proxy-image='cilium/istio_proxy'" subsys=daemon level=info msg=" --single-cluster-route='false'" subsys=daemon level=info msg=" --skip-cnp-status-startup-clean='false'" subsys=daemon level=info msg=" --socket-path='/var/run/cilium/cilium.sock'" subsys=daemon level=info msg=" --srv6-encap-mode='reduced'" subsys=daemon level=info msg=" --state-dir='/var/run/cilium'" subsys=daemon level=info msg=" --synchronize-k8s-nodes='true'" subsys=daemon level=info msg=" --tofqdns-dns-reject-response-code='refused'" subsys=daemon level=info msg=" --tofqdns-enable-dns-compression='true'" subsys=daemon level=info msg=" --tofqdns-endpoint-max-ip-per-hostname='50'" subsys=daemon level=info msg=" --tofqdns-idle-connection-grace-period='0s'" subsys=daemon level=info msg=" --tofqdns-max-deferred-connection-deletes='10000'" subsys=daemon level=info msg=" --tofqdns-min-ttl='0'" subsys=daemon level=info msg=" --tofqdns-pre-cache=''" subsys=daemon level=info msg=" --tofqdns-proxy-port='0'" subsys=daemon level=info msg=" --tofqdns-proxy-response-max-delay='100ms'" subsys=daemon level=info msg=" --trace-payloadlen='128'" subsys=daemon level=info msg=" --trace-sock='true'" subsys=daemon level=info msg=" --tunnel=''" subsys=daemon level=info msg=" --tunnel-port='6082'" subsys=daemon level=info msg=" --tunnel-protocol='geneve'" subsys=daemon level=info msg=" --unmanaged-pod-watcher-interval='15'" subsys=daemon level=info msg=" --use-cilium-internal-ip-for-ipsec='false'" subsys=daemon level=info msg=" --version='false'" subsys=daemon level=info msg=" --vlan-bpf-bypass=''" subsys=daemon level=info msg=" --vtep-cidr=''" subsys=daemon level=info msg=" --vtep-endpoint=''" subsys=daemon level=info msg=" --vtep-mac=''" subsys=daemon level=info msg=" --vtep-mask=''" subsys=daemon level=info msg=" --wireguard-encapsulate='false'" subsys=daemon level=info msg=" --write-cni-conf-when-ready='/host/etc/cni/net.d/05-cilium.conflist'" subsys=daemon level=info msg=" _ _ _" subsys=daemon level=info msg=" ___|_| |_|_ _ _____" subsys=daemon level=info msg="| _| | | | | | |" subsys=daemon level=info msg="|___|_|_|_|___|_|_|_|" subsys=daemon level=info msg="Cilium 1.14.8 cf6e022e 2024-03-13T12:23:35-04:00 go version go1.21.8 linux/amd64" subsys=daemon level=info msg="clang (10.0.0) and kernel (5.15.0) versions: OK!" subsys=linux-datapath level=info msg="linking environment: OK!" subsys=linux-datapath level=info msg="Kernel config file not found: if the agent fails to start, check the system requirements at https://docs.cilium.io/en/stable/operations/system_requirements" subsys=probes level=info msg="Detected mounted BPF filesystem at /sys/fs/bpf" subsys=bpf level=info msg="Mounted cgroupv2 filesystem at /run/cilium/cgroupv2" subsys=cgroups level=info msg="Parsing base label prefixes from default label list" subsys=labels-filter level=info msg="Parsing additional label prefixes from user inputs: []" subsys=labels-filter level=info msg="Final label prefixes to be used for identity evaluation:" subsys=labels-filter level=info msg=" - reserved:.*" subsys=labels-filter level=info msg=" - :io\\.kubernetes\\.pod\\.namespace" subsys=labels-filter level=info msg=" - :io\\.cilium\\.k8s\\.namespace\\.labels" subsys=labels-filter level=info msg=" - :app\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:io\\.kubernetes" subsys=labels-filter level=info msg=" - !:kubernetes\\.io" subsys=labels-filter level=info msg=" - !:.*beta\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:k8s\\.io" subsys=labels-filter level=info msg=" - !:pod-template-generation" subsys=labels-filter level=info msg=" - !:pod-template-hash" subsys=labels-filter level=info msg=" - !:controller-revision-hash" subsys=labels-filter level=info msg=" - !:annotation.*" subsys=labels-filter level=info msg=" - !:etcd_node" subsys=labels-filter level=info msg=Invoked duration=1.088427ms function="pprof.glob..func1 (cell.go:50)" subsys=hive level=info msg=Invoked duration="58.132µs" function="gops.registerGopsHooks (cell.go:38)" subsys=hive level=info msg=Invoked duration=1.115928ms function="metrics.NewRegistry (registry.go:65)" subsys=hive level=info msg=Invoked duration="18.16µs" function="metrics.glob..func1 (cell.go:12)" subsys=hive level=info msg="Spire Delegate API Client is disabled as no socket path is configured" subsys=spire-delegate level=info msg="Mutual authentication handler is disabled as no port is configured" subsys=auth level=info msg=Invoked duration=87.577666ms function="cmd.glob..func4 (daemon_main.go:1607)" subsys=hive level=info msg=Invoked duration="14.1µs" function="gc.registerSignalHandler (cell.go:47)" subsys=hive level=info msg=Invoked duration="35.401µs" function="utime.initUtimeSync (cell.go:29)" subsys=hive level=info msg=Invoked duration="76.112µs" function="agentliveness.newAgentLivenessUpdater (agent_liveness.go:43)" subsys=hive level=info msg=Invoked duration="53.682µs" function="l2responder.NewL2ResponderReconciler (l2responder.go:63)" subsys=hive level=info msg=Invoked duration="68.981µs" function="garp.newGARPProcessor (processor.go:27)" subsys=hive level=info msg=Starting subsys=hive level=info msg="Started gops server" address="127.0.0.1:9890" subsys=gops level=info msg="Start hook executed" duration="427.2µs" function="gops.registerGopsHooks.func1 (cell.go:43)" subsys=hive level=info msg="Start hook executed" duration="1.79µs" function="metrics.NewRegistry.func1 (registry.go:86)" subsys=hive level=info msg="Establishing connection to apiserver" host="https://10.96.0.1:443" subsys=k8s-client level=info msg="Serving prometheus metrics on :9962" subsys=metrics level=info msg="Connected to apiserver" subsys=k8s-client level=info msg="Start hook executed" duration=8.134093ms function="client.(*compositeClientset).onStart" subsys=hive level=info msg="Start hook executed" duration=9.076487ms function="authmap.newAuthMap.func1 (cell.go:27)" subsys=hive level=info msg="Start hook executed" duration="34.701µs" function="configmap.newMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="71.031µs" function="signalmap.newMap.func1 (cell.go:44)" subsys=hive level=info msg="Start hook executed" duration="297.607µs" function="nodemap.newNodeMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="93.272µs" function="eventsmap.newEventsMap.func1 (cell.go:35)" subsys=hive level=info msg="Start hook executed" duration="54.181µs" function="*cni.cniConfigManager.Start" subsys=hive level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Wrote CNI configuration file to /host/etc/cni/net.d/05-cilium.conflist" subsys=cni-config level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Start hook executed" duration=39.656069ms function="datapath.newDatapath.func1 (cells.go:113)" subsys=hive level=info msg="Restored 0 node IDs from the BPF map" subsys=linux-datapath level=info msg="Start hook executed" duration="93.143µs" function="datapath.newDatapath.func2 (cells.go:126)" subsys=hive level=info msg="Start hook executed" duration="13.51µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Node].Start" subsys=hive level=info msg="Start hook executed" duration="3.7µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNode].Start" subsys=hive level=info msg="Using autogenerated IPv4 allocation range" subsys=node v4Prefix=10.169.0.0/16 level=info msg="no local ciliumnode found, will not restore cilium internal ips from k8s" subsys=daemon level=info msg="Start hook executed" duration=103.039342ms function="node.NewLocalNodeStore.func1 (local_node_store.go:76)" subsys=hive level=info msg="Start hook executed" duration="4.16µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration=101.008892ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration="14.52µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Using discoveryv1.EndpointSlice" subsys=k8s level=info msg="Start hook executed" duration=200.442824ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Start hook executed" duration="3.43µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Pod].Start" subsys=hive level=info msg="Start hook executed" duration="1.521µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Namespace].Start" subsys=hive level=info msg="Start hook executed" duration="2.361µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="2.02µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumClusterwideNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="1.44µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumCIDRGroup].Start" subsys=hive level=info msg="Start hook executed" duration="32.771µs" function="endpointmanager.newDefaultEndpointManager.func1 (cell.go:203)" subsys=hive level=info msg="Start hook executed" duration="31.731µs" function="cmd.newPolicyTrifecta.func1 (policy.go:135)" subsys=hive level=info msg="Start hook executed" duration="39.871µs" function="*manager.manager.Start" subsys=hive level=info msg="Serving cilium node monitor v1.2 API at unix:///var/run/cilium/monitor1_2.sock" subsys=monitor-agent level=info msg="Start hook executed" duration="260.297µs" function="agent.newMonitorAgent.func1 (cell.go:61)" subsys=hive level=info msg="Start hook executed" duration="2.6µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumL2AnnouncementPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="7.86µs" function="*job.group.Start" subsys=hive level=info msg="Start hook executed" duration="196.054µs" function="proxy.newProxy.func1 (cell.go:55)" subsys=hive level=info msg="Envoy: Starting xDS gRPC server listening on /var/run/cilium/envoy/sockets/xds.sock" subsys=envoy-manager level=info msg="Start hook executed" duration="356.419µs" function="signal.provideSignalManager.func1 (cell.go:25)" subsys=hive level=info msg="Datapath signal listener running" subsys=signal level=info msg="Start hook executed" duration="896.932µs" function="auth.registerAuthManager.func1 (cell.go:109)" subsys=hive level=info msg="Start hook executed" duration="3.6µs" function="auth.registerGCJobs.func1 (cell.go:158)" subsys=hive level=info msg="Start hook executed" duration="17.94µs" function="*job.group.Start" subsys=hive level=warning msg="Deprecated value for --kube-proxy-replacement: disabled (use either \"true\", or \"false\")" subsys=daemon level=info msg="Auto-disabling \"enable-node-port\", \"enable-external-ips\", \"bpf-lb-sock\", \"enable-host-port\" features and falling back to \"enable-host-legacy-routing\"" subsys=daemon level=info msg="Inheriting MTU from external network interface" device=ens3 ipAddr=199.204.45.169 mtu=1500 subsys=mtu level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_ipcache, recreating and re-pinning map cilium_ipcache" file-path=/sys/fs/bpf/tc/globals/cilium_ipcache name=cilium_ipcache subsys=bpf level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_tunnel_map, recreating and re-pinning map cilium_tunnel_map" file-path=/sys/fs/bpf/tc/globals/cilium_tunnel_map name=cilium_tunnel_map subsys=bpf level=info msg="Restored services from maps" failedServices=0 restoredServices=0 subsys=service level=info msg="Restored backends from maps" failedBackends=0 restoredBackends=0 skippedBackends=0 subsys=service level=info msg="Reading old endpoints..." subsys=daemon level=info msg="No old endpoints found." subsys=daemon level=info msg="Waiting until all Cilium CRDs are available" subsys=k8s level=info msg="All Cilium CRDs have been found and are available" subsys=k8s level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=info msg="Successfully created CiliumNode resource" subsys=nodediscovery level=warning msg="Unable to create CiliumNode resource, will retry" error="ciliumnodes.cilium.io \"instance\" already exists" subsys=nodediscovery level=info msg="Retrieved node information from cilium node" nodeName=instance subsys=k8s level=warning msg="Waiting for k8s node information" error="required IPv4 PodCIDR not available" subsys=k8s level=info msg="Retrieved node information from cilium node" nodeName=instance subsys=k8s level=info msg="Received own node information from API server" ipAddr.ipv4=199.204.45.169 ipAddr.ipv6="" k8sNodeIP=199.204.45.169 labels="map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:]" nodeName=instance subsys=k8s v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="k8s mode: Allowing localhost to reach local endpoints" subsys=daemon level=info msg="Detected devices" devices="[]" subsys=linux-datapath level=info msg="Enabling k8s event listener" subsys=k8s-watcher level=info msg="Removing stale endpoint interfaces" subsys=daemon level=info msg="Skipping kvstore configuration" subsys=daemon level=info msg="Waiting until local node addressing before starting watchers depending on it" subsys=k8s-watcher level=info msg="Initializing node addressing" subsys=daemon level=info msg="Initializing cluster-pool IPAM" subsys=ipam v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="Restoring endpoints..." subsys=daemon level=info msg="Endpoints restored" failed=0 restored=0 subsys=daemon level=info msg="Addressing information:" subsys=daemon level=info msg=" Cluster-Name: default" subsys=daemon level=info msg=" Cluster-ID: 0" subsys=daemon level=info msg=" Local node-name: instance" subsys=daemon level=info msg=" Node-IPv6: " subsys=daemon level=info msg=" External-Node IPv4: 199.204.45.169" subsys=daemon level=info msg=" Internal-Node IPv4: 10.0.0.2" subsys=daemon level=info msg=" IPv4 allocation prefix: 10.0.0.0/24" subsys=daemon level=info msg=" Loopback IPv4: 169.254.42.1" subsys=daemon level=info msg=" Local IPv4 addresses:" subsys=daemon level=info msg=" - 199.204.45.169" subsys=daemon level=info msg=" - 172.17.0.100" subsys=daemon level=info msg="Node updated" clusterName=default nodeName=instance subsys=nodemanager level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Adding local node to cluster" node="{instance default [{InternalIP 199.204.45.169} {CiliumInternalIP 10.0.0.2}] 10.0.0.0/24 [] [] 10.0.0.22 0 local 0 map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:] map[] 1 }" subsys=nodediscovery level=info msg="Waiting until all pre-existing resources have been received" subsys=k8s-watcher level=info msg="Initializing identity allocator" subsys=identity-cache level=info msg="Allocating identities between range" cluster-id=0 max=65535 min=256 subsys=identity-cache level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.core.bpf_jit_enable sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.all.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.fib_multipath_use_neigh sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.unprivileged_bpf_disabled sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.timer_migration sysParamValue=0 level=info msg="Setting up BPF datapath" bpfClockSource=ktime bpfInsnSet="" subsys=datapath-loader level=info msg="Iptables rules installed" subsys=iptables level=info msg="Adding new proxy port rules for cilium-dns-egress:37897" id=cilium-dns-egress subsys=proxy level=info msg="Iptables proxy rules installed" subsys=iptables level=info msg="Start hook executed" duration=2.302691382s function="cmd.newDaemonPromise.func1 (daemon_main.go:1663)" subsys=hive level=info msg="Start hook executed" duration="13.76µs" function="utime.initUtimeSync.func1 (cell.go:33)" subsys=hive level=info msg="Start hook executed" duration="6.08µs" function="*job.group.Start" subsys=hive level=info msg="Starting IP identity watcher" subsys=ipcache level=info msg="Start hook executed" duration="32.42µs" function="l2respondermap.newMap.func1 (l2_responder_map4.go:44)" subsys=hive level=info msg="Start hook executed" duration="14.23µs" function="*job.group.Start" subsys=hive level=info msg="Initializing daemon" subsys=daemon level=info msg="Validating configured node address ranges" subsys=daemon level=info msg="Starting connection tracking garbage collector" subsys=daemon level=info msg="Initial scan of connection tracking completed" subsys=ct-gc level=info msg="Regenerating restored endpoints" numRestored=0 subsys=daemon level=info msg="Creating host endpoint" subsys=daemon level=info msg="Deleted orphan backends" orphanBackends=0 subsys=service level=info msg="Finished regenerating restored endpoints" regenerated=0 subsys=daemon total=0 level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1298 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1298 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1298 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="Launching Cilium health daemon" subsys=daemon level=info msg="Launching Cilium health endpoint" subsys=daemon level=info msg="Started healthz status API server" address="127.0.0.1:9879" subsys=daemon level=info msg="Processing queued endpoint deletion requests from /var/run/cilium/deleteQueue" subsys=daemon level=info msg="processing 0 queued deletion requests" subsys=daemon level=info msg="Initializing Cilium API" subsys=daemon level=info msg="Daemon initialization completed" bootstrapTime=3.31480187s subsys=daemon level=info msg="Hubble server is disabled" subsys=hubble level=info msg="Serving cilium API at unix:///var/run/cilium/cilium.sock" subsys=daemon level=info msg="Compiled new BPF template" BPFCompilationTime=295.076377ms file-path=/var/run/cilium/state/templates/579957b4c3151b493e9306eb680fe80de8b8fe82c92c35e18cd5ab2b38c17a11/bpf_host.o subsys=datapath-loader level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1298 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=546 ipv4=10.0.0.22 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=546 identityLabels="reserved:health" ipv4=10.0.0.22 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=546 identity=4 identityLabels="reserved:health" ipv4=10.0.0.22 ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.88 21913a05-dfab-4f4f-92a7-8a2c918fb613 default }" containerID=828409f4081096e9c8b0769019263cdfaa4057c1d8f7bcaa77c954e17cf4af50 datapathConfiguration="&{false false false false false }" interface=lxc1dd39c013883 k8sPodName=kube-system/coredns-7c96b6546b-qwj2k labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=828409f408 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2071 ipv4=10.0.0.88 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qwj2k subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=828409f408 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2071 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.88 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qwj2k subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:kube-system]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=828409f408 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2071 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.88 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qwj2k line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=coredns;k8s:io.kubernetes.pod.namespace=kube-system;k8s:k8s-app=kube-dns;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=828409f408 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2071 identity=22482 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.88 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qwj2k oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=828409f408 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2071 identity=22482 ipv4=10.0.0.88 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qwj2k subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.135 a6910ac7-1dcd-4c4b-9fe3-15f4de4529d2 default }" containerID=e904658a8a37daf83746ce83b29124534c1d298cbc9848558ad44fb18976e24d datapathConfiguration="&{false false false false false }" interface=lxc5f2f92bd78a0 k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-m5v25 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e904658a8a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1389 ipv4=10.0.0.135 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-m5v25 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e904658a8a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1389 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=b442e26b-6f25-4cdc-95ef-5e254a471922,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=b442e26b-6f25-4cdc-95ef-5e254a471922,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.135 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-m5v25 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=certgen;k8s:batch.kubernetes.io/controller-uid=b442e26b-6f25-4cdc-95ef-5e254a471922;k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen;k8s:controller-uid=b442e26b-6f25-4cdc-95ef-5e254a471922;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;k8s:job-name=envoy-gateway-gateway-helm-certgen;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e904658a8a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1389 identity=11024 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=b442e26b-6f25-4cdc-95ef-5e254a471922,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=b442e26b-6f25-4cdc-95ef-5e254a471922,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.135 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-m5v25 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e904658a8a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1389 identity=11024 ipv4=10.0.0.135 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-m5v25 subsys=endpoint level=info msg="Serving cilium health API at unix:///var/run/cilium/health.sock" subsys=health-server level=info msg="Compiled new BPF template" BPFCompilationTime=1.057258818s file-path=/var/run/cilium/state/templates/56650d775771e553d4f4333fd679ac467ca9d198ff6830510c4d37ff59150550/bpf_lxc.o subsys=datapath-loader level=info msg="Rewrote endpoint BPF program" containerID=e904658a8a datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1389 identity=11024 ipv4=10.0.0.135 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-m5v25 subsys=endpoint level=info msg="Successful endpoint creation" containerID=e904658a8a datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1389 identity=11024 ipv4=10.0.0.135 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-m5v25 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=828409f408 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2071 identity=22482 ipv4=10.0.0.88 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qwj2k subsys=endpoint level=info msg="Successful endpoint creation" containerID=828409f408 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2071 identity=22482 ipv4=10.0.0.88 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qwj2k subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=546 identity=4 ipv4=10.0.0.22 ipv6= k8sPodName=/ subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=e904658a8a endpointID=1389 k8sNamespace=envoy-gateway-system k8sPodName=envoy-gateway-gateway-helm-certgen-m5v25 subsys=daemon level=info msg="Releasing key" key="[k8s:app=certgen k8s:batch.kubernetes.io/controller-uid=b442e26b-6f25-4cdc-95ef-5e254a471922 k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen k8s:controller-uid=b442e26b-6f25-4cdc-95ef-5e254a471922 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen k8s:io.kubernetes.pod.namespace=envoy-gateway-system k8s:job-name=envoy-gateway-gateway-helm-certgen]" subsys=allocator level=info msg="Removed endpoint" containerID=e904658a8a datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1389 identity=11024 ipv4=10.0.0.135 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-m5v25 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.191 1a2db0bc-df32-45fd-a976-867b8cc07ad9 default }" containerID=a4eb847462292929271433da19cbdfcb58559a7e72dbdf5fe7c2d4bce571e860 datapathConfiguration="&{false false false false false }" interface=lxcb27e3c7c88f6 k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-mz7cx labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=a4eb847462 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1092 ipv4=10.0.0.191 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-mz7cx subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=a4eb847462 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1092 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.191 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-mz7cx subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=envoy-gateway;k8s:app.kubernetes.io/name=gateway-helm;k8s:control-plane=envoy-gateway;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=a4eb847462 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1092 identity=9596 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.191 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-mz7cx oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=a4eb847462 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1092 identity=9596 ipv4=10.0.0.191 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-mz7cx subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=a4eb847462 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1092 identity=9596 ipv4=10.0.0.191 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-mz7cx subsys=endpoint level=info msg="Successful endpoint creation" containerID=a4eb847462 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1092 identity=9596 ipv4=10.0.0.191 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-mz7cx subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1298 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,k8s:openstack-compute-node=enabled,k8s:openstack-control-plane=enabled,k8s:openvswitch=enabled,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_hostns_01298 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_hostns_01298 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_hostns_01298 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_hostns_01298:pending" subsys=bpf level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_netdev_00003 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_netdev_00003 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003:pending" subsys=bpf level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1298 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.98 95c602b3-b104-47ae-b726-ca5619b7bae8 default }" containerID=5cbeb898b067c6f5da86817b4000e9871fed95985a1dd6fe25bb7cc8b441a9de datapathConfiguration="&{false false false false false }" interface=lxc2b59518165ce k8sPodName=kube-system/coredns-67659f764b-ht45b labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=5cbeb898b0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1762 ipv4=10.0.0.98 ipv6= k8sPodName=kube-system/coredns-67659f764b-ht45b subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=5cbeb898b0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1762 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.98 ipv6= k8sPodName=kube-system/coredns-67659f764b-ht45b subsys=endpoint level=info msg="Identity of endpoint changed" containerID=5cbeb898b0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1762 identity=22482 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.98 ipv6= k8sPodName=kube-system/coredns-67659f764b-ht45b oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=5cbeb898b0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1762 identity=22482 ipv4=10.0.0.98 ipv6= k8sPodName=kube-system/coredns-67659f764b-ht45b subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.207 d1600513-c52c-46f8-a1dd-7f2afd3da045 default }" containerID=3ee3d3c31e654cbd7539a9e9de73032f64e5ae8075bd06ff5e55ad57f3e113d8 datapathConfiguration="&{false false false false false }" interface=lxc5654bf08d059 k8sPodName=kube-system/coredns-67659f764b-fl46w labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=3ee3d3c31e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=924 ipv4=10.0.0.207 ipv6= k8sPodName=kube-system/coredns-67659f764b-fl46w subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=3ee3d3c31e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=924 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.207 ipv6= k8sPodName=kube-system/coredns-67659f764b-fl46w subsys=endpoint level=info msg="Identity of endpoint changed" containerID=3ee3d3c31e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=924 identity=22482 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.207 ipv6= k8sPodName=kube-system/coredns-67659f764b-fl46w oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=3ee3d3c31e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=924 identity=22482 ipv4=10.0.0.207 ipv6= k8sPodName=kube-system/coredns-67659f764b-fl46w subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=5cbeb898b0 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1762 identity=22482 ipv4=10.0.0.98 ipv6= k8sPodName=kube-system/coredns-67659f764b-ht45b subsys=endpoint level=info msg="Successful endpoint creation" containerID=5cbeb898b0 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1762 identity=22482 ipv4=10.0.0.98 ipv6= k8sPodName=kube-system/coredns-67659f764b-ht45b subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=3ee3d3c31e datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=924 identity=22482 ipv4=10.0.0.207 ipv6= k8sPodName=kube-system/coredns-67659f764b-fl46w subsys=endpoint level=info msg="Successful endpoint creation" containerID=3ee3d3c31e datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=924 identity=22482 ipv4=10.0.0.207 ipv6= k8sPodName=kube-system/coredns-67659f764b-fl46w subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.44 a440ec93-cdde-4869-88be-24a4c88c35da default }" containerID=81d044b019a453466695623bb2c122c6cc2a0b6abc33cb49071b59a70d9b0b06 datapathConfiguration="&{false false false false false }" interface=lxca5b1352fa6d8 k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wnrvz labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=81d044b019 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2486 ipv4=10.0.0.44 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wnrvz subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=81d044b019 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2486 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.44 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wnrvz subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=local-path-provisioner;k8s:app.kubernetes.io/name=local-path-provisioner;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=81d044b019 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2486 identity=39383 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.44 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wnrvz oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=81d044b019 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2486 identity=39383 ipv4=10.0.0.44 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wnrvz subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=81d044b019 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2486 identity=39383 ipv4=10.0.0.44 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wnrvz subsys=endpoint level=info msg="Successful endpoint creation" containerID=81d044b019 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2486 identity=39383 ipv4=10.0.0.44 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wnrvz subsys=daemon level=info msg="Delete endpoint request" containerID=828409f408 endpointID=2071 k8sNamespace=kube-system k8sPodName=coredns-7c96b6546b-qwj2k subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=coredns k8s:io.kubernetes.pod.namespace=kube-system k8s:k8s-app=kube-dns]" subsys=allocator level=info msg="Removed endpoint" containerID=828409f408 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2071 identity=22482 ipv4=10.0.0.88 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qwj2k subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.203 baaed813-ed46-4c91-9a98-a31f4ff1a0d5 default }" containerID=e9ee49f9f0d41fba17cb154d9d1fb006d2632bd0330d5c25d1061d940fa0d6e8 datapathConfiguration="&{false false false false false }" interface=lxc374c387dc28d k8sPodName=openstack/memcached-memcached-cf56b6468-h8gwn labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e9ee49f9f0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3916 ipv4=10.0.0.203 ipv6= k8sPodName=openstack/memcached-memcached-cf56b6468-h8gwn subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e9ee49f9f0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3916 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.203 ipv6= k8sPodName=openstack/memcached-memcached-cf56b6468-h8gwn subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=e9ee49f9f0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3916 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.203 ipv6= k8sPodName=openstack/memcached-memcached-cf56b6468-h8gwn line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=memcached;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=memcached;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e9ee49f9f0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3916 identity=58576 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.203 ipv6= k8sPodName=openstack/memcached-memcached-cf56b6468-h8gwn oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e9ee49f9f0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3916 identity=58576 ipv4=10.0.0.203 ipv6= k8sPodName=openstack/memcached-memcached-cf56b6468-h8gwn subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=e9ee49f9f0 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=3916 identity=58576 ipv4=10.0.0.203 ipv6= k8sPodName=openstack/memcached-memcached-cf56b6468-h8gwn subsys=endpoint level=info msg="Successful endpoint creation" containerID=e9ee49f9f0 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3916 identity=58576 ipv4=10.0.0.203 ipv6= k8sPodName=openstack/memcached-memcached-cf56b6468-h8gwn subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.121 ba5cd4ad-f314-4886-9feb-0c65602d9a36 default }" containerID=2fd51fc79c28ac0ddd66ee0ebff7929ad3ce811c77b3cb2d848e0f5b64f63ac9 datapathConfiguration="&{false false false false false }" interface=lxc90b0d7930cad k8sPodName=cert-manager/cert-manager-webhook-548949fc64-dcnwz labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=2fd51fc79c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1674 ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-dcnwz subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=2fd51fc79c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1674 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-dcnwz subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=webhook;k8s:app.kubernetes.io/component=webhook;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=webhook;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=2fd51fc79c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1674 identity=4922 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-dcnwz oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=2fd51fc79c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1674 identity=4922 ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-dcnwz subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.190 e9de38ee-dec9-497f-9ea0-08cb1c68b47e default }" containerID=622b4a44839b7ba193853e60f8cc2fcb81581306720c591c2dc4e4c809a17227 datapathConfiguration="&{false false false false false }" interface=lxcdbb92d190a24 k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-qdsr6 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=622b4a4483 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2346 ipv4=10.0.0.190 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-qdsr6 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=622b4a4483 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2346 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.190 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-qdsr6 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=cainjector;k8s:app.kubernetes.io/component=cainjector;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cainjector;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=622b4a4483 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2346 identity=4467 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.190 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-qdsr6 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=622b4a4483 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2346 identity=4467 ipv4=10.0.0.190 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-qdsr6 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.51 4c76b3dc-5a72-4b97-9afe-d9f79c22224d default }" containerID=8b8a71f712dae969327c3e1e400287aa4a671b1021e4be8e5c8481630e10aad3 datapathConfiguration="&{false false false false false }" interface=lxcdf1b048431a5 k8sPodName=ingress-nginx/ingress-nginx-admission-create-s2bsb labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=8b8a71f712 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1088 ipv4=10.0.0.51 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-s2bsb subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=8b8a71f712 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1088 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=1578ca22-1352-45fb-9b81-9207a0990ece,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=1578ca22-1352-45fb-9b81-9207a0990ece,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.51 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-s2bsb subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=1578ca22-1352-45fb-9b81-9207a0990ece;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create;k8s:controller-uid=1578ca22-1352-45fb-9b81-9207a0990ece;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-create;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=8b8a71f712 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1088 identity=55683 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=1578ca22-1352-45fb-9b81-9207a0990ece,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=1578ca22-1352-45fb-9b81-9207a0990ece,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.51 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-s2bsb oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=8b8a71f712 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1088 identity=55683 ipv4=10.0.0.51 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-s2bsb subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.209 33abf9eb-b9a5-4414-a1b4-795cac7eae48 default }" containerID=8ddc923afe21a99aa090ddd2a715a9e836c65a8b84b8bb530af7bbb76c004b83 datapathConfiguration="&{false false false false false }" interface=lxc93f7037ad7dc k8sPodName=cert-manager/cert-manager-75c4c745bc-nkpgx labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=8ddc923afe datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2832 ipv4=10.0.0.209 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-nkpgx subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=8ddc923afe datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2832 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.209 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-nkpgx subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=cert-manager;k8s:app.kubernetes.io/component=controller;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cert-manager;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=8ddc923afe datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2832 identity=37512 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.209 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-nkpgx oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=8ddc923afe datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2832 identity=37512 ipv4=10.0.0.209 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-nkpgx subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=2fd51fc79c datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1674 identity=4922 ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-dcnwz subsys=endpoint level=info msg="Successful endpoint creation" containerID=2fd51fc79c datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1674 identity=4922 ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-dcnwz subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=622b4a4483 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2346 identity=4467 ipv4=10.0.0.190 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-qdsr6 subsys=endpoint level=info msg="Successful endpoint creation" containerID=622b4a4483 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2346 identity=4467 ipv4=10.0.0.190 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-qdsr6 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=8b8a71f712 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1088 identity=55683 ipv4=10.0.0.51 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-s2bsb subsys=endpoint level=info msg="Successful endpoint creation" containerID=8b8a71f712 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1088 identity=55683 ipv4=10.0.0.51 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-s2bsb subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=8ddc923afe datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2832 identity=37512 ipv4=10.0.0.209 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-nkpgx subsys=endpoint level=info msg="Successful endpoint creation" containerID=8ddc923afe datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2832 identity=37512 ipv4=10.0.0.209 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-nkpgx subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.156 51843ed6-eb8c-420b-8e66-af2e862454b2 default }" containerID=2364ddc07ce38ef650b3adb5c024d64b29f307a30c0ab3b475664b80e2d544a7 datapathConfiguration="&{false false false false false }" interface=lxc228c9ebb9fdc k8sPodName=cert-manager/cert-manager-startupapicheck-dm8ks labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=2364ddc07c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3663 ipv4=10.0.0.156 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-dm8ks subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=2364ddc07c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3663 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=c27e4ca3-4249-40e4-a3d1-45b8bbbed1a1,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=c27e4ca3-4249-40e4-a3d1-45b8bbbed1a1,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.156 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-dm8ks subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=startupapicheck;k8s:app.kubernetes.io/component=startupapicheck;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=startupapicheck;k8s:app.kubernetes.io/version=v1.11.5;k8s:batch.kubernetes.io/controller-uid=c27e4ca3-4249-40e4-a3d1-45b8bbbed1a1;k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck;k8s:controller-uid=c27e4ca3-4249-40e4-a3d1-45b8bbbed1a1;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck;k8s:io.kubernetes.pod.namespace=cert-manager;k8s:job-name=cert-manager-startupapicheck;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=2364ddc07c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3663 identity=10157 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=c27e4ca3-4249-40e4-a3d1-45b8bbbed1a1,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=c27e4ca3-4249-40e4-a3d1-45b8bbbed1a1,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.156 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-dm8ks oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=2364ddc07c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3663 identity=10157 ipv4=10.0.0.156 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-dm8ks subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=2364ddc07c datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=3663 identity=10157 ipv4=10.0.0.156 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-dm8ks subsys=endpoint level=info msg="Successful endpoint creation" containerID=2364ddc07c datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3663 identity=10157 ipv4=10.0.0.156 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-dm8ks subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=8b8a71f712 endpointID=1088 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-create-s2bsb subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=1578ca22-1352-45fb-9b81-9207a0990ece k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create k8s:controller-uid=1578ca22-1352-45fb-9b81-9207a0990ece k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-create]" subsys=allocator level=info msg="Removed endpoint" containerID=8b8a71f712 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1088 identity=55683 ipv4=10.0.0.51 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-s2bsb subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.49 e6339883-9c5f-43a6-be84-cfe75e64fbf1 default }" containerID=423785ef46b78e4764a44ad1c3e0b406dd320487bcc15f5d0704e233ea43e0af datapathConfiguration="&{false false false false false }" interface=lxc2b8b68e25fc3 k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-vb9jb labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=423785ef46 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3818 ipv4=10.0.0.49 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-vb9jb subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=423785ef46 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3818 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.49 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-vb9jb subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=default-backend;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend;k8s:io.kubernetes.pod.namespace=ingress-nginx;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=423785ef46 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3818 identity=28324 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.49 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-vb9jb oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=423785ef46 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3818 identity=28324 ipv4=10.0.0.49 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-vb9jb subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=423785ef46 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=3818 identity=28324 ipv4=10.0.0.49 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-vb9jb subsys=endpoint level=info msg="Successful endpoint creation" containerID=423785ef46 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3818 identity=28324 ipv4=10.0.0.49 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-vb9jb subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.95 f1f76842-3625-46fe-94e1-bbdf9e1fa5d3 default }" containerID=dbd656ae7c6e5a735cac4cf345a07302b44998b23a68781b4eda76613501a74a datapathConfiguration="&{false false false false false }" interface=lxc61cf63547825 k8sPodName=ingress-nginx/ingress-nginx-admission-patch-7pl7v labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=dbd656ae7c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=895 ipv4=10.0.0.95 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-7pl7v subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=dbd656ae7c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=895 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=d4475c98-7cdf-4779-98d9-dbc9b2426b77,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=d4475c98-7cdf-4779-98d9-dbc9b2426b77,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.95 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-7pl7v subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=d4475c98-7cdf-4779-98d9-dbc9b2426b77;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch;k8s:controller-uid=d4475c98-7cdf-4779-98d9-dbc9b2426b77;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-patch;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=dbd656ae7c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=895 identity=54080 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=d4475c98-7cdf-4779-98d9-dbc9b2426b77,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=d4475c98-7cdf-4779-98d9-dbc9b2426b77,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.95 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-7pl7v oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=dbd656ae7c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=895 identity=54080 ipv4=10.0.0.95 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-7pl7v subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=dbd656ae7c datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=895 identity=54080 ipv4=10.0.0.95 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-7pl7v subsys=endpoint level=info msg="Successful endpoint creation" containerID=dbd656ae7c datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=895 identity=54080 ipv4=10.0.0.95 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-7pl7v subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=dbd656ae7c endpointID=895 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-patch-7pl7v subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=d4475c98-7cdf-4779-98d9-dbc9b2426b77 k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch k8s:controller-uid=d4475c98-7cdf-4779-98d9-dbc9b2426b77 k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-patch]" subsys=allocator level=info msg="Removed endpoint" containerID=dbd656ae7c datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=895 identity=54080 ipv4=10.0.0.95 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-7pl7v subsys=endpoint level=info msg="Delete endpoint request" containerID=2364ddc07c endpointID=3663 k8sNamespace=cert-manager k8sPodName=cert-manager-startupapicheck-dm8ks subsys=daemon level=info msg="Releasing key" key="[k8s:app=startupapicheck k8s:app.kubernetes.io/component=startupapicheck k8s:app.kubernetes.io/instance=cert-manager k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=startupapicheck k8s:app.kubernetes.io/version=v1.11.5 k8s:batch.kubernetes.io/controller-uid=c27e4ca3-4249-40e4-a3d1-45b8bbbed1a1 k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck k8s:controller-uid=c27e4ca3-4249-40e4-a3d1-45b8bbbed1a1 k8s:helm.sh/chart=cert-manager-v1.11.5 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager k8s:io.cilium.k8s.namespace.labels.name=cert-manager k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck k8s:io.kubernetes.pod.namespace=cert-manager k8s:job-name=cert-manager-startupapicheck]" subsys=allocator level=info msg="Removed endpoint" containerID=2364ddc07c datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3663 identity=10157 ipv4=10.0.0.156 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-dm8ks subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.158 44de5bbd-837a-4dc0-8021-03927c608cc9 default }" containerID=f7bb8b93708cdd701f6ce30523d1065c5d6f6ed961c0af5d896378a71fa437a2 datapathConfiguration="&{false false false false false }" interface=lxc7228bc3cf9b0 k8sPodName=openstack/pxc-operator-69cb5bbdb9-wzsd8 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f7bb8b9370 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=246 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-wzsd8 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f7bb8b9370 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=246 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.158 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-wzsd8 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=f7bb8b9370 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=246 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.158 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-wzsd8 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=operator;k8s:app.kubernetes.io/instance=pxc-operator;k8s:app.kubernetes.io/name=pxc-operator;k8s:app.kubernetes.io/part-of=pxc-operator;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=f7bb8b9370 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=246 identity=35921 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.158 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-wzsd8 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f7bb8b9370 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=246 identity=35921 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-wzsd8 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=f7bb8b9370 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=246 identity=35921 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-wzsd8 subsys=endpoint level=info msg="Successful endpoint creation" containerID=f7bb8b9370 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=246 identity=35921 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-wzsd8 subsys=daemon level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"rabbitmq-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-cluster-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=ed9316d7-0322-42fe-8340-0ea23d675932] Description:}]" policyAddRequest=3da09172-edb1-4c59-90eb-7ae2e29b52da subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=3da09172-edb1-4c59-90eb-7ae2e29b52da policyRevision=2 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-cluster-operator subsys=k8s-watcher level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"messaging-topology-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:9443 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-messaging-topology-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=80141ee2-d565-4b38-88f4-86d527aa8957] Description:}]" policyAddRequest=6ec541c6-1a42-401f-beb0-68d79dcae542 subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=6ec541c6-1a42-401f-beb0-68d79dcae542 policyRevision=3 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-messaging-topology-operator subsys=k8s-watcher level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.120 7b651192-6192-4b23-bf5b-05cd302430d3 default }" containerID=f83e813655e0ffd3941c364dee70ea7c8e2796d3097c04412cb76a34711cb3f1 datapathConfiguration="&{false false false false false }" interface=lxca857fbed0f1e k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-dwdpp labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f83e813655 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1440 ipv4=10.0.0.120 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-dwdpp subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f83e813655 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1440 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.16.1,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.120 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-dwdpp subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=2.16.1;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=f83e813655 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1440 identity=7101 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.16.1,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.120 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-dwdpp oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f83e813655 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1440 identity=7101 ipv4=10.0.0.120 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-dwdpp subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.208 1afc5aab-2c93-465b-93cd-0d686e3bad88 default }" containerID=8606a8fbe3f9a71b4b1ff0d04ae6da33c083003d9f26b3c20fd4b9c52a8a9443 datapathConfiguration="&{false false false false false }" interface=lxc986fe35e7b9f k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-txkps labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=8606a8fbe3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3742 ipv4=10.0.0.208 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-txkps subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=8606a8fbe3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3742 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.17.4,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.208 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-txkps subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Rewrote endpoint BPF program" containerID=f83e813655 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=1440 identity=7101 ipv4=10.0.0.120 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-dwdpp subsys=endpoint level=info msg="Successful endpoint creation" containerID=f83e813655 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=1440 identity=7101 ipv4=10.0.0.120 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-dwdpp subsys=daemon level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=messaging-topology-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=1.17.4;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=8606a8fbe3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3742 identity=16379 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.17.4,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.208 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-txkps oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=8606a8fbe3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3742 identity=16379 ipv4=10.0.0.208 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-txkps subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=8606a8fbe3 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=3742 identity=16379 ipv4=10.0.0.208 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-txkps subsys=endpoint level=info msg="Successful endpoint creation" containerID=8606a8fbe3 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=3742 identity=16379 ipv4=10.0.0.208 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-txkps subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.36 9c701b14-d449-4402-8c3e-ba0afdc31ecd default }" containerID=74f841044638a4cfdc27c39d4646e306b8166481e8034aa798a71e2d15e84749 datapathConfiguration="&{false false false false false }" interface=lxc97de1b935203 k8sPodName=openstack/percona-xtradb-haproxy-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=74f8410446 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2106 ipv4=10.0.0.36 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=74f8410446 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2106 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.36 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=74f8410446 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2106 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.36 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=haproxy;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=74f8410446 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2106 identity=52988 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.36 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=74f8410446 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2106 identity=52988 ipv4=10.0.0.36 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/instance\":\"valkey\",\"k8s:app.kubernetes.io/name\":\"valkey\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:6379 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:} {Ports:[{Port:26379 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:} {IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:9121 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=valkey k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=c8357e9f-7a80-4fff-82e5-e76765647f2d] Description:}]" policyAddRequest=0546fbb6-16f4-4779-8470-267147d7abfe subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=valkey subsys=k8s-watcher level=info msg="Policy imported via API, recalculating..." policyAddRequest=0546fbb6-16f4-4779-8470-267147d7abfe policyRevision=4 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=74f8410446 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=2106 identity=52988 ipv4=10.0.0.36 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=74f8410446 datapathPolicyRevision=4 desiredPolicyRevision=3 endpointID=2106 identity=52988 ipv4=10.0.0.36 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.63 8157590f-0f1e-454c-ae8c-78948dece8e1 default }" containerID=1d625bb69369ed268674ee285e3f150b73bfabea96ce5a2cedd961c83f26ba8e datapathConfiguration="&{false false false false false }" interface=lxcbc72fb352468 k8sPodName=local-path-storage/helper-pod-create-pvc-e9c5aaec-0877-4b0c-8bc9-16abc67332e4 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=1d625bb693 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2676 ipv4=10.0.0.63 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-e9c5aaec-0877-4b0c-8bc9-16abc67332e4 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=1d625bb693 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2676 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.63 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-e9c5aaec-0877-4b0c-8bc9-16abc67332e4 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=1d625bb693 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2676 identity=7254 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.63 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-e9c5aaec-0877-4b0c-8bc9-16abc67332e4 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=1d625bb693 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2676 identity=7254 ipv4=10.0.0.63 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-e9c5aaec-0877-4b0c-8bc9-16abc67332e4 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=1d625bb693 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2676 identity=7254 ipv4=10.0.0.63 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-e9c5aaec-0877-4b0c-8bc9-16abc67332e4 subsys=endpoint level=info msg="Successful endpoint creation" containerID=1d625bb693 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2676 identity=7254 ipv4=10.0.0.63 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-e9c5aaec-0877-4b0c-8bc9-16abc67332e4 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.97 1ddb497a-6709-4650-a141-daf813ff5e97 default }" containerID=05a19cbd4158763721eed0e7592daaea152de8eab9e6498d2db5c802a7f009c6 datapathConfiguration="&{false false false false false }" interface=lxc7bfbb007671b k8sPodName=local-path-storage/helper-pod-create-pvc-97df8939-1669-4426-8b66-e4625423dd14 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=05a19cbd41 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3717 ipv4=10.0.0.97 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-97df8939-1669-4426-8b66-e4625423dd14 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=05a19cbd41 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3717 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.97 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-97df8939-1669-4426-8b66-e4625423dd14 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=05a19cbd41 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3717 identity=7254 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.97 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-97df8939-1669-4426-8b66-e4625423dd14 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=05a19cbd41 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3717 identity=7254 ipv4=10.0.0.97 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-97df8939-1669-4426-8b66-e4625423dd14 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=05a19cbd41 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3717 identity=7254 ipv4=10.0.0.97 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-97df8939-1669-4426-8b66-e4625423dd14 subsys=endpoint level=info msg="Successful endpoint creation" containerID=05a19cbd41 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3717 identity=7254 ipv4=10.0.0.97 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-97df8939-1669-4426-8b66-e4625423dd14 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=1d625bb693 endpointID=2676 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-e9c5aaec-0877-4b0c-8bc9-16abc67332e4 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=1d625bb693 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2676 identity=7254 ipv4=10.0.0.63 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-e9c5aaec-0877-4b0c-8bc9-16abc67332e4 subsys=endpoint level=info msg="Delete endpoint request" containerID=05a19cbd41 endpointID=3717 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-97df8939-1669-4426-8b66-e4625423dd14 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=05a19cbd41 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3717 identity=7254 ipv4=10.0.0.97 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-97df8939-1669-4426-8b66-e4625423dd14 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.117 66c9115d-11af-4573-bca5-56fb235a12fa default }" containerID=238d5228b7fa55c5090bf8445a01932ce74267aa55a2ef7a73ce3bb602af2811 datapathConfiguration="&{false false false false false }" interface=lxc4d6397719954 k8sPodName=openstack/percona-xtradb-pxc-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=238d5228b7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2787 ipv4=10.0.0.117 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=238d5228b7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2787 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.117 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=pxc;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0;" subsys=allocator level=info msg="Invalid state transition skipped" containerID=238d5228b7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2787 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.117 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 line=611 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=238d5228b7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2787 identity=22579 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.117 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=238d5228b7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2787 identity=22579 ipv4=10.0.0.117 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=238d5228b7 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2787 identity=22579 ipv4=10.0.0.117 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=238d5228b7 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2787 identity=22579 ipv4=10.0.0.117 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.161 19cba676-81ca-4adc-b997-a6739129022e default }" containerID=d0ffabe5882cc1190c8b933f7f9f8af1cf26fe8bb0bc7905ce5c9105463feef8 datapathConfiguration="&{false false false false false }" interface=lxc153a8794a04f k8sPodName=openstack/valkey-node-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d0ffabe588 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3089 ipv4=10.0.0.161 ipv6= k8sPodName=openstack/valkey-node-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d0ffabe588 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3089 identityLabels="k8s:app.kubernetes.io/component=node,k8s:app.kubernetes.io/instance=valkey,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=valkey,k8s:app.kubernetes.io/version=8.0.2,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=valkey-2.4.6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=valkey,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=valkey-node-0" ipv4=10.0.0.161 ipv6= k8sPodName=openstack/valkey-node-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=node;k8s:app.kubernetes.io/instance=valkey;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=valkey;k8s:app.kubernetes.io/version=8.0.2;k8s:apps.kubernetes.io/pod-index=0;k8s:helm.sh/chart=valkey-2.4.6;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=valkey;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=valkey-node-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d0ffabe588 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3089 identity=3784 identityLabels="k8s:app.kubernetes.io/component=node,k8s:app.kubernetes.io/instance=valkey,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=valkey,k8s:app.kubernetes.io/version=8.0.2,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=valkey-2.4.6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=valkey,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=valkey-node-0" ipv4=10.0.0.161 ipv6= k8sPodName=openstack/valkey-node-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d0ffabe588 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3089 identity=3784 ipv4=10.0.0.161 ipv6= k8sPodName=openstack/valkey-node-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=d0ffabe588 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3089 identity=3784 ipv4=10.0.0.161 ipv6= k8sPodName=openstack/valkey-node-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=d0ffabe588 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3089 identity=3784 ipv4=10.0.0.161 ipv6= k8sPodName=openstack/valkey-node-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"keycloak\",\"k8s:app.kubernetes.io/instance\":\"keycloak\",\"k8s:app.kubernetes.io/name\":\"keycloak\",\"k8s:io.kubernetes.pod.namespace\":\"auth-system\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:7800 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:} {Ports:[{Port:8080 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=keycloak k8s:io.cilium.k8s.policy.namespace=auth-system k8s:io.cilium.k8s.policy.uid=15045d3a-1e24-4997-b452-6757963d0c75] Description:}]" policyAddRequest=d2e46060-bb69-4e14-b416-a3f7e7be58ef subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=d2e46060-bb69-4e14-b416-a3f7e7be58ef policyRevision=5 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=keycloak subsys=k8s-watcher level=info msg="Create endpoint request" addressing="&{10.0.0.248 947ed3e9-2a33-461e-90a1-40ca4e3f58e5 default }" containerID=5e8ec0c93d66a8d60af7da2a5fbb1f29f605e43120a7ad738180eb04ef7b6a06 datapathConfiguration="&{false false false false false }" interface=lxc0179caed278e k8sPodName=auth-system/keycloak-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=5e8ec0c93d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3938 ipv4=10.0.0.248 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=5e8ec0c93d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3938 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=24.0.5,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-21.4.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.248 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:auth-system k8s:io.cilium.k8s.namespace.labels.name:auth-system]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=keycloak;k8s:app.kubernetes.io/instance=keycloak;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=keycloak;k8s:app.kubernetes.io/version=24.0.5;k8s:apps.kubernetes.io/pod-index=0;k8s:helm.sh/chart=keycloak-21.4.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system;k8s:io.cilium.k8s.namespace.labels.name=auth-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keycloak;k8s:io.kubernetes.pod.namespace=auth-system;k8s:statefulset.kubernetes.io/pod-name=keycloak-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=5e8ec0c93d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3938 identity=12030 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=24.0.5,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-21.4.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.248 ipv6= k8sPodName=auth-system/keycloak-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=5e8ec0c93d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3938 identity=12030 ipv4=10.0.0.248 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=5e8ec0c93d datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=3938 identity=12030 ipv4=10.0.0.248 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=5e8ec0c93d datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3938 identity=12030 ipv4=10.0.0.248 ipv6= k8sPodName=auth-system/keycloak-0 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.229 fb17cbf7-f764-44f4-b4ac-bbfd05092340 default }" containerID=e03c4031328b40e6540f64790124d74a41d80f85f1d7d771e2ce7fb8dd965b59 datapathConfiguration="&{false false false false false }" interface=lxcead9a3c89004 k8sPodName=local-path-storage/helper-pod-create-pvc-ed9bcf34-bbfc-4ecb-8f70-46176d632c82 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e03c403132 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=286 ipv4=10.0.0.229 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-ed9bcf34-bbfc-4ecb-8f70-46176d632c82 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e03c403132 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=286 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.229 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-ed9bcf34-bbfc-4ecb-8f70-46176d632c82 subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e03c403132 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=286 identity=7254 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.229 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-ed9bcf34-bbfc-4ecb-8f70-46176d632c82 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e03c403132 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=286 identity=7254 ipv4=10.0.0.229 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-ed9bcf34-bbfc-4ecb-8f70-46176d632c82 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=e03c403132 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=286 identity=7254 ipv4=10.0.0.229 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-ed9bcf34-bbfc-4ecb-8f70-46176d632c82 subsys=endpoint level=info msg="Successful endpoint creation" containerID=e03c403132 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=286 identity=7254 ipv4=10.0.0.229 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-ed9bcf34-bbfc-4ecb-8f70-46176d632c82 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=e03c403132 endpointID=286 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-ed9bcf34-bbfc-4ecb-8f70-46176d632c82 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=e03c403132 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=286 identity=7254 ipv4=10.0.0.229 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-ed9bcf34-bbfc-4ecb-8f70-46176d632c82 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.45 48ad68f1-3a94-45df-9f39-b8ce53fe744d default }" containerID=993f1eb06ff46bb827ba2e8183d0ef3bdbe55853861e2442d2b20b002299798d datapathConfiguration="&{false false false false false }" interface=lxc770837dfd14e k8sPodName=openstack/rabbitmq-keystone-server-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=993f1eb06f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=403 ipv4=10.0.0.45 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=993f1eb06f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=403 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.45 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq;k8s:app.kubernetes.io/name=rabbitmq-keystone;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=993f1eb06f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=403 identity=15034 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.45 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=993f1eb06f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=403 identity=15034 ipv4=10.0.0.45 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=993f1eb06f datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=403 identity=15034 ipv4=10.0.0.45 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=993f1eb06f datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=403 identity=15034 ipv4=10.0.0.45 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.80 83059f98-8f0e-469e-83ee-df4e667649f1 default }" containerID=0608b251243bea17fa9886f72102fd4359f6abd61bb7aaf34d51dbb26bb5f098 datapathConfiguration="&{false false false false false }" interface=lxc2a0a055593fd k8sPodName=openstack/keystone-credential-setup-rtk4m labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=0608b25124 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=207 ipv4=10.0.0.80 ipv6= k8sPodName=openstack/keystone-credential-setup-rtk4m subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=0608b25124 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=207 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=9f09745c-ed24-4bee-9ae9-eeec4deffc51,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=9f09745c-ed24-4bee-9ae9-eeec4deffc51,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.80 ipv6= k8sPodName=openstack/keystone-credential-setup-rtk4m subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=0608b25124 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=207 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.80 ipv6= k8sPodName=openstack/keystone-credential-setup-rtk4m line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=9f09745c-ed24-4bee-9ae9-eeec4deffc51;k8s:batch.kubernetes.io/job-name=keystone-credential-setup;k8s:component=credential-setup;k8s:controller-uid=9f09745c-ed24-4bee-9ae9-eeec4deffc51;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-credential-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=0608b25124 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=207 identity=639 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=9f09745c-ed24-4bee-9ae9-eeec4deffc51,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=9f09745c-ed24-4bee-9ae9-eeec4deffc51,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.80 ipv6= k8sPodName=openstack/keystone-credential-setup-rtk4m oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=0608b25124 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=207 identity=639 ipv4=10.0.0.80 ipv6= k8sPodName=openstack/keystone-credential-setup-rtk4m subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=0608b25124 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=207 identity=639 ipv4=10.0.0.80 ipv6= k8sPodName=openstack/keystone-credential-setup-rtk4m subsys=endpoint level=info msg="Successful endpoint creation" containerID=0608b25124 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=207 identity=639 ipv4=10.0.0.80 ipv6= k8sPodName=openstack/keystone-credential-setup-rtk4m subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Conntrack garbage collector interval recalculated" deleteRatio=0.017611859105127158 newInterval=7m30s subsys=map-ct level=info msg="Delete endpoint request" containerID=0608b25124 endpointID=207 k8sNamespace=openstack k8sPodName=keystone-credential-setup-rtk4m subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=9f09745c-ed24-4bee-9ae9-eeec4deffc51 k8s:batch.kubernetes.io/job-name=keystone-credential-setup k8s:component=credential-setup k8s:controller-uid=9f09745c-ed24-4bee-9ae9-eeec4deffc51 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-credential-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=0608b25124 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=207 identity=639 ipv4=10.0.0.80 ipv6= k8sPodName=openstack/keystone-credential-setup-rtk4m subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.56 ef61f7df-a931-4f19-81a6-8804410dee40 default }" containerID=0e18876e8a86a1185584b6dd125e064574faad7cd4103ae065b206f43ec9ed08 datapathConfiguration="&{false false false false false }" interface=lxccdea8f75a7ec k8sPodName=openstack/keystone-db-init-nnxtd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=0e18876e8a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3803 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-db-init-nnxtd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=0e18876e8a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3803 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=bc6377f9-538b-4557-a63b-e120817ea5fe,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=bc6377f9-538b-4557-a63b-e120817ea5fe,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-db-init-nnxtd subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=bc6377f9-538b-4557-a63b-e120817ea5fe;k8s:batch.kubernetes.io/job-name=keystone-db-init;k8s:component=db-init;k8s:controller-uid=bc6377f9-538b-4557-a63b-e120817ea5fe;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-init;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=0e18876e8a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3803 identity=46774 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=bc6377f9-538b-4557-a63b-e120817ea5fe,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=bc6377f9-538b-4557-a63b-e120817ea5fe,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-db-init-nnxtd oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=0e18876e8a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3803 identity=46774 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-db-init-nnxtd subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=0e18876e8a datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=3803 identity=46774 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-db-init-nnxtd subsys=endpoint level=info msg="Successful endpoint creation" containerID=0e18876e8a datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3803 identity=46774 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-db-init-nnxtd subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=0e18876e8a endpointID=3803 k8sNamespace=openstack k8sPodName=keystone-db-init-nnxtd subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=bc6377f9-538b-4557-a63b-e120817ea5fe k8s:batch.kubernetes.io/job-name=keystone-db-init k8s:component=db-init k8s:controller-uid=bc6377f9-538b-4557-a63b-e120817ea5fe k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=0e18876e8a datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3803 identity=46774 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-db-init-nnxtd subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.136 3bdf4aaa-29d3-498c-80d6-0b89594d2bfd default }" containerID=c098fa2be09b6b3b9ea1b4e83146de0300ad1ea83eeb1b75a6399c596e4bf66c datapathConfiguration="&{false false false false false }" interface=lxc5cf88e81c99a k8sPodName=openstack/keystone-fernet-setup-ph4r2 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c098fa2be0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3198 ipv4=10.0.0.136 ipv6= k8sPodName=openstack/keystone-fernet-setup-ph4r2 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c098fa2be0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3198 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=6388ba1e-4c2e-435c-b63a-6fbcc974155a,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=6388ba1e-4c2e-435c-b63a-6fbcc974155a,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.136 ipv6= k8sPodName=openstack/keystone-fernet-setup-ph4r2 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=c098fa2be0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3198 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.136 ipv6= k8sPodName=openstack/keystone-fernet-setup-ph4r2 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=6388ba1e-4c2e-435c-b63a-6fbcc974155a;k8s:batch.kubernetes.io/job-name=keystone-fernet-setup;k8s:component=fernet-setup;k8s:controller-uid=6388ba1e-4c2e-435c-b63a-6fbcc974155a;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-fernet-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=c098fa2be0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3198 identity=13115 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=6388ba1e-4c2e-435c-b63a-6fbcc974155a,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=6388ba1e-4c2e-435c-b63a-6fbcc974155a,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.136 ipv6= k8sPodName=openstack/keystone-fernet-setup-ph4r2 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c098fa2be0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3198 identity=13115 ipv4=10.0.0.136 ipv6= k8sPodName=openstack/keystone-fernet-setup-ph4r2 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=c098fa2be0 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=3198 identity=13115 ipv4=10.0.0.136 ipv6= k8sPodName=openstack/keystone-fernet-setup-ph4r2 subsys=endpoint level=info msg="Successful endpoint creation" containerID=c098fa2be0 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3198 identity=13115 ipv4=10.0.0.136 ipv6= k8sPodName=openstack/keystone-fernet-setup-ph4r2 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=c098fa2be0 endpointID=3198 k8sNamespace=openstack k8sPodName=keystone-fernet-setup-ph4r2 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=6388ba1e-4c2e-435c-b63a-6fbcc974155a k8s:batch.kubernetes.io/job-name=keystone-fernet-setup k8s:component=fernet-setup k8s:controller-uid=6388ba1e-4c2e-435c-b63a-6fbcc974155a k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-fernet-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=c098fa2be0 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3198 identity=13115 ipv4=10.0.0.136 ipv6= k8sPodName=openstack/keystone-fernet-setup-ph4r2 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.53 36280d9e-d167-41ec-9888-d8824fd95b24 default }" containerID=0340583669a3579ea35fbe1732fa1e4adb376420ed9382ca51cf8664ce77910c datapathConfiguration="&{false false false false false }" interface=lxcd6cdc5594053 k8sPodName=openstack/keystone-db-sync-xhsqg labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=0340583669 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1172 ipv4=10.0.0.53 ipv6= k8sPodName=openstack/keystone-db-sync-xhsqg subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=0340583669 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1172 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=acea4b6f-9eb7-475c-be28-ac2049ad80e2,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=acea4b6f-9eb7-475c-be28-ac2049ad80e2,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.53 ipv6= k8sPodName=openstack/keystone-db-sync-xhsqg subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=0340583669 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1172 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.53 ipv6= k8sPodName=openstack/keystone-db-sync-xhsqg line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=acea4b6f-9eb7-475c-be28-ac2049ad80e2;k8s:batch.kubernetes.io/job-name=keystone-db-sync;k8s:component=db-sync;k8s:controller-uid=acea4b6f-9eb7-475c-be28-ac2049ad80e2;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-sync;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=0340583669 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1172 identity=55793 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=acea4b6f-9eb7-475c-be28-ac2049ad80e2,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=acea4b6f-9eb7-475c-be28-ac2049ad80e2,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.53 ipv6= k8sPodName=openstack/keystone-db-sync-xhsqg oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=0340583669 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1172 identity=55793 ipv4=10.0.0.53 ipv6= k8sPodName=openstack/keystone-db-sync-xhsqg subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=0340583669 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=1172 identity=55793 ipv4=10.0.0.53 ipv6= k8sPodName=openstack/keystone-db-sync-xhsqg subsys=endpoint level=info msg="Successful endpoint creation" containerID=0340583669 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=1172 identity=55793 ipv4=10.0.0.53 ipv6= k8sPodName=openstack/keystone-db-sync-xhsqg subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=0340583669 endpointID=1172 k8sNamespace=openstack k8sPodName=keystone-db-sync-xhsqg subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=acea4b6f-9eb7-475c-be28-ac2049ad80e2 k8s:batch.kubernetes.io/job-name=keystone-db-sync k8s:component=db-sync k8s:controller-uid=acea4b6f-9eb7-475c-be28-ac2049ad80e2 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-sync k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=0340583669 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=1172 identity=55793 ipv4=10.0.0.53 ipv6= k8sPodName=openstack/keystone-db-sync-xhsqg subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.134 434de45b-c36b-4bbf-961c-7be849d0adb2 default }" containerID=c4985df81e7f5377ff4c2c4e9140e7b65270b25de8cd29e483995895e6fe053c datapathConfiguration="&{false false false false false }" interface=lxcb4104ff2c471 k8sPodName=openstack/keystone-rabbit-init-rj86p labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c4985df81e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2637 ipv4=10.0.0.134 ipv6= k8sPodName=openstack/keystone-rabbit-init-rj86p subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c4985df81e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2637 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=44bfd6e5-d063-4da0-b079-36a7ab925b7a,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=44bfd6e5-d063-4da0-b079-36a7ab925b7a,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.134 ipv6= k8sPodName=openstack/keystone-rabbit-init-rj86p subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=44bfd6e5-d063-4da0-b079-36a7ab925b7a;k8s:batch.kubernetes.io/job-name=keystone-rabbit-init;k8s:component=rabbit-init;k8s:controller-uid=44bfd6e5-d063-4da0-b079-36a7ab925b7a;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-rabbit-init;k8s:release_group=keystone;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=c4985df81e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2637 identity=1917 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=44bfd6e5-d063-4da0-b079-36a7ab925b7a,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=44bfd6e5-d063-4da0-b079-36a7ab925b7a,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.134 ipv6= k8sPodName=openstack/keystone-rabbit-init-rj86p oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c4985df81e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2637 identity=1917 ipv4=10.0.0.134 ipv6= k8sPodName=openstack/keystone-rabbit-init-rj86p subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=c4985df81e datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=2637 identity=1917 ipv4=10.0.0.134 ipv6= k8sPodName=openstack/keystone-rabbit-init-rj86p subsys=endpoint level=info msg="Successful endpoint creation" containerID=c4985df81e datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=2637 identity=1917 ipv4=10.0.0.134 ipv6= k8sPodName=openstack/keystone-rabbit-init-rj86p subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=c4985df81e endpointID=2637 k8sNamespace=openstack k8sPodName=keystone-rabbit-init-rj86p subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=44bfd6e5-d063-4da0-b079-36a7ab925b7a k8s:batch.kubernetes.io/job-name=keystone-rabbit-init k8s:component=rabbit-init k8s:controller-uid=44bfd6e5-d063-4da0-b079-36a7ab925b7a k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-rabbit-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=c4985df81e datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=2637 identity=1917 ipv4=10.0.0.134 ipv6= k8sPodName=openstack/keystone-rabbit-init-rj86p subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.74 534a3768-1632-40aa-aa16-552c16c9708f default }" containerID=e764b84540290fdc124f77cac810cacf62ac8e2e313ad804d8b398e8ee3c579d datapathConfiguration="&{false false false false false }" interface=lxce8b3e8d04274 k8sPodName=openstack/keystone-domain-manage-488fb labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e764b84540 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=248 ipv4=10.0.0.74 ipv6= k8sPodName=openstack/keystone-domain-manage-488fb subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e764b84540 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=248 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=b89e1e6c-bede-48a9-a620-e2e4f9bc8d03,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=b89e1e6c-bede-48a9-a620-e2e4f9bc8d03,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.74 ipv6= k8sPodName=openstack/keystone-domain-manage-488fb subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=b89e1e6c-bede-48a9-a620-e2e4f9bc8d03;k8s:batch.kubernetes.io/job-name=keystone-domain-manage;k8s:component=domain-manage;k8s:controller-uid=b89e1e6c-bede-48a9-a620-e2e4f9bc8d03;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-domain-manage;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e764b84540 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=248 identity=56364 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=b89e1e6c-bede-48a9-a620-e2e4f9bc8d03,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=b89e1e6c-bede-48a9-a620-e2e4f9bc8d03,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.74 ipv6= k8sPodName=openstack/keystone-domain-manage-488fb oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e764b84540 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=248 identity=56364 ipv4=10.0.0.74 ipv6= k8sPodName=openstack/keystone-domain-manage-488fb subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=e764b84540 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=248 identity=56364 ipv4=10.0.0.74 ipv6= k8sPodName=openstack/keystone-domain-manage-488fb subsys=endpoint level=info msg="Successful endpoint creation" containerID=e764b84540 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=248 identity=56364 ipv4=10.0.0.74 ipv6= k8sPodName=openstack/keystone-domain-manage-488fb subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.76 7ede5b74-44e5-4340-b648-75e38e474abf default }" containerID=01af3101f50ea247781220cf7c4e9f2f74c19acb181e3a940674e2f609e59e12 datapathConfiguration="&{false false false false false }" interface=lxc4b10323e8dd8 k8sPodName=openstack/keystone-api-6dc8d5fcd8-hp59s labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=01af3101f5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=843 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-api-6dc8d5fcd8-hp59s subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=01af3101f5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=843 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-api-6dc8d5fcd8-hp59s subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:component=api;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-api;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=keystone;" subsys=allocator level=info msg="Invalid state transition skipped" containerID=01af3101f5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=843 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-api-6dc8d5fcd8-hp59s line=611 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=01af3101f5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=843 identity=17290 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-api-6dc8d5fcd8-hp59s oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=01af3101f5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=843 identity=17290 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-api-6dc8d5fcd8-hp59s subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=01af3101f5 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=843 identity=17290 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-api-6dc8d5fcd8-hp59s subsys=endpoint level=info msg="Successful endpoint creation" containerID=01af3101f5 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=843 identity=17290 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-api-6dc8d5fcd8-hp59s subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=e764b84540 endpointID=248 k8sNamespace=openstack k8sPodName=keystone-domain-manage-488fb subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=b89e1e6c-bede-48a9-a620-e2e4f9bc8d03 k8s:batch.kubernetes.io/job-name=keystone-domain-manage k8s:component=domain-manage k8s:controller-uid=b89e1e6c-bede-48a9-a620-e2e4f9bc8d03 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-domain-manage k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=e764b84540 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=248 identity=56364 ipv4=10.0.0.74 ipv6= k8sPodName=openstack/keystone-domain-manage-488fb subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.56 2b7e29a2-488a-4dcc-824e-9f72aeee3d24 default }" containerID=c43a9ca2418a7bb44725c335cb971a9382794678ee8fddb24db18d3f5cd3b0a8 datapathConfiguration="&{false false false false false }" interface=lxcc4ba38ed2393 k8sPodName=openstack/keystone-bootstrap-7fwjs labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c43a9ca241 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3924 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-bootstrap-7fwjs subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c43a9ca241 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3924 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=9a2bba8f-bdd3-4b91-b078-b82fe4a5d100,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=9a2bba8f-bdd3-4b91-b078-b82fe4a5d100,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-bootstrap-7fwjs subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=c43a9ca241 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3924 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-bootstrap-7fwjs line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=9a2bba8f-bdd3-4b91-b078-b82fe4a5d100;k8s:batch.kubernetes.io/job-name=keystone-bootstrap;k8s:component=bootstrap;k8s:controller-uid=9a2bba8f-bdd3-4b91-b078-b82fe4a5d100;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-bootstrap;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=c43a9ca241 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3924 identity=21835 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=9a2bba8f-bdd3-4b91-b078-b82fe4a5d100,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=9a2bba8f-bdd3-4b91-b078-b82fe4a5d100,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-bootstrap-7fwjs oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c43a9ca241 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3924 identity=21835 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-bootstrap-7fwjs subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=c43a9ca241 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=3924 identity=21835 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-bootstrap-7fwjs subsys=endpoint level=info msg="Successful endpoint creation" containerID=c43a9ca241 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3924 identity=21835 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-bootstrap-7fwjs subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=c43a9ca241 endpointID=3924 k8sNamespace=openstack k8sPodName=keystone-bootstrap-7fwjs subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=9a2bba8f-bdd3-4b91-b078-b82fe4a5d100 k8s:batch.kubernetes.io/job-name=keystone-bootstrap k8s:component=bootstrap k8s:controller-uid=9a2bba8f-bdd3-4b91-b078-b82fe4a5d100 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-bootstrap k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=c43a9ca241 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3924 identity=21835 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/keystone-bootstrap-7fwjs subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.210 9c9644c1-1f51-4230-8e7b-949c52944da3 default }" containerID=196e6f60668cf88272995f67693669d347923426f5b768d1c2b590983cb616cd datapathConfiguration="&{false false false false false }" interface=lxc8dbd47ee538d k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-kxgmx labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=196e6f6066 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3238 ipv4=10.0.0.210 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-kxgmx subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=196e6f6066 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3238 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.210 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-kxgmx subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:secretgen-controller]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=secretgen-controller;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa;k8s:io.kubernetes.pod.namespace=secretgen-controller;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=196e6f6066 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3238 identity=21286 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.210 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-kxgmx oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=196e6f6066 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3238 identity=21286 ipv4=10.0.0.210 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-kxgmx subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=196e6f6066 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=3238 identity=21286 ipv4=10.0.0.210 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-kxgmx subsys=endpoint level=info msg="Successful endpoint creation" containerID=196e6f6066 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3238 identity=21286 ipv4=10.0.0.210 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-kxgmx subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.77 9b7b783c-51ef-40a8-ad26-7722ab976d97 default }" containerID=80a4560bd4e424182e22f12741830c6d2f3c6e3f52408bc9a016ab9380fb9bd1 datapathConfiguration="&{false false false false false }" interface=lxc3460c8d14ec0 k8sPodName=openstack/horizon-df8745658-2mpzg labels="[]" subsys=daemon sync-build=true level=info msg="Create endpoint request" addressing="&{10.0.0.176 fd9ceab1-a687-4d9f-8c79-dd377000059e default }" containerID=c7c03ba738aa8fd8c1ca5f04781b126a240c844ef4dfbd86b33f2e68df49a78d datapathConfiguration="&{false false false false false }" interface=lxc36f8a35e31f3 k8sPodName=openstack/horizon-df8745658-lklr5 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=80a4560bd4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3043 ipv4=10.0.0.77 ipv6= k8sPodName=openstack/horizon-df8745658-2mpzg subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=80a4560bd4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3043 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.77 ipv6= k8sPodName=openstack/horizon-df8745658-2mpzg subsys=endpoint level=info msg="New endpoint" containerID=c7c03ba738 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=280 ipv4=10.0.0.176 ipv6= k8sPodName=openstack/horizon-df8745658-lklr5 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Resolving identity labels (blocking)" containerID=c7c03ba738 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=280 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.176 ipv6= k8sPodName=openstack/horizon-df8745658-lklr5 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=80a4560bd4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3043 identity=46050 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.77 ipv6= k8sPodName=openstack/horizon-df8745658-2mpzg oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=80a4560bd4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3043 identity=46050 ipv4=10.0.0.77 ipv6= k8sPodName=openstack/horizon-df8745658-2mpzg subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=c7c03ba738 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=280 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.176 ipv6= k8sPodName=openstack/horizon-df8745658-lklr5 line=611 subsys=endpoint level=info msg="Reusing existing global key" key="k8s:application=horizon;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=c7c03ba738 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=280 identity=46050 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.176 ipv6= k8sPodName=openstack/horizon-df8745658-lklr5 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c7c03ba738 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=280 identity=46050 ipv4=10.0.0.176 ipv6= k8sPodName=openstack/horizon-df8745658-lklr5 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.147 2e23b36a-9c9b-4f85-90d9-bad0d178ab1e default }" containerID=e7257388a6f64d909c958b03a78c20d0453462417e34ac5cfb90c07b8c4e0780 datapathConfiguration="&{false false false false false }" interface=lxc90cfc36a5bd3 k8sPodName=openstack/horizon-db-init-ng67z labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e7257388a6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=647 ipv4=10.0.0.147 ipv6= k8sPodName=openstack/horizon-db-init-ng67z subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e7257388a6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=647 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=d0f504ef-0fcd-4708-93c1-38a50290c463,k8s:batch.kubernetes.io/job-name=horizon-db-init,k8s:component=db-init,k8s:controller-uid=d0f504ef-0fcd-4708-93c1-38a50290c463,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-init,k8s:release_group=horizon" ipv4=10.0.0.147 ipv6= k8sPodName=openstack/horizon-db-init-ng67z subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Create endpoint request" addressing="&{10.0.0.92 51416827-ea51-40f8-bc3d-bada3c8f8b68 default }" containerID=6ccf430749f2c41cb315b6b707ec529d7896282cb45bdc78731cb91b56052bff datapathConfiguration="&{false false false false false }" interface=lxcc293e24a8c7a k8sPodName=openstack/horizon-df8745658-7bm9t labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=6ccf430749 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2218 ipv4=10.0.0.92 ipv6= k8sPodName=openstack/horizon-df8745658-7bm9t subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=6ccf430749 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2218 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.92 ipv6= k8sPodName=openstack/horizon-df8745658-7bm9t subsys=endpoint level=info msg="Identity of endpoint changed" containerID=6ccf430749 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2218 identity=46050 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.92 ipv6= k8sPodName=openstack/horizon-df8745658-7bm9t oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=6ccf430749 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2218 identity=46050 ipv4=10.0.0.92 ipv6= k8sPodName=openstack/horizon-df8745658-7bm9t subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:batch.kubernetes.io/controller-uid=d0f504ef-0fcd-4708-93c1-38a50290c463;k8s:batch.kubernetes.io/job-name=horizon-db-init;k8s:component=db-init;k8s:controller-uid=d0f504ef-0fcd-4708-93c1-38a50290c463;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=horizon-db-init;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e7257388a6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=647 identity=18216 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=d0f504ef-0fcd-4708-93c1-38a50290c463,k8s:batch.kubernetes.io/job-name=horizon-db-init,k8s:component=db-init,k8s:controller-uid=d0f504ef-0fcd-4708-93c1-38a50290c463,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-init,k8s:release_group=horizon" ipv4=10.0.0.147 ipv6= k8sPodName=openstack/horizon-db-init-ng67z oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e7257388a6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=647 identity=18216 ipv4=10.0.0.147 ipv6= k8sPodName=openstack/horizon-db-init-ng67z subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=80a4560bd4 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=3043 identity=46050 ipv4=10.0.0.77 ipv6= k8sPodName=openstack/horizon-df8745658-2mpzg subsys=endpoint level=info msg="Successful endpoint creation" containerID=80a4560bd4 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3043 identity=46050 ipv4=10.0.0.77 ipv6= k8sPodName=openstack/horizon-df8745658-2mpzg subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=c7c03ba738 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=280 identity=46050 ipv4=10.0.0.176 ipv6= k8sPodName=openstack/horizon-df8745658-lklr5 subsys=endpoint level=info msg="Successful endpoint creation" containerID=c7c03ba738 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=280 identity=46050 ipv4=10.0.0.176 ipv6= k8sPodName=openstack/horizon-df8745658-lklr5 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=e7257388a6 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=647 identity=18216 ipv4=10.0.0.147 ipv6= k8sPodName=openstack/horizon-db-init-ng67z subsys=endpoint level=info msg="Successful endpoint creation" containerID=e7257388a6 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=647 identity=18216 ipv4=10.0.0.147 ipv6= k8sPodName=openstack/horizon-db-init-ng67z subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=6ccf430749 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=2218 identity=46050 ipv4=10.0.0.92 ipv6= k8sPodName=openstack/horizon-df8745658-7bm9t subsys=endpoint level=info msg="Successful endpoint creation" containerID=6ccf430749 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=2218 identity=46050 ipv4=10.0.0.92 ipv6= k8sPodName=openstack/horizon-df8745658-7bm9t subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=e7257388a6 endpointID=647 k8sNamespace=openstack k8sPodName=horizon-db-init-ng67z subsys=daemon level=info msg="Releasing key" key="[k8s:application=horizon k8s:batch.kubernetes.io/controller-uid=d0f504ef-0fcd-4708-93c1-38a50290c463 k8s:batch.kubernetes.io/job-name=horizon-db-init k8s:component=db-init k8s:controller-uid=d0f504ef-0fcd-4708-93c1-38a50290c463 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=horizon-db-init k8s:release_group=horizon]" subsys=allocator level=info msg="Removed endpoint" containerID=e7257388a6 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=647 identity=18216 ipv4=10.0.0.147 ipv6= k8sPodName=openstack/horizon-db-init-ng67z subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.60 282b7052-ab43-42d6-adfb-112958417e3c default }" containerID=c99efd3ca253c6d6cf5a536037e8731a5815946d98b8f34403b324d7f38a7fa5 datapathConfiguration="&{false false false false false }" interface=lxce90edc0712b7 k8sPodName=openstack/horizon-db-sync-4qx2s labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c99efd3ca2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=897 ipv4=10.0.0.60 ipv6= k8sPodName=openstack/horizon-db-sync-4qx2s subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c99efd3ca2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=897 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=105ae4d7-3528-4c93-8291-8396e145d1c9,k8s:batch.kubernetes.io/job-name=horizon-db-sync,k8s:component=db-sync,k8s:controller-uid=105ae4d7-3528-4c93-8291-8396e145d1c9,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-sync,k8s:release_group=horizon" ipv4=10.0.0.60 ipv6= k8sPodName=openstack/horizon-db-sync-4qx2s subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:batch.kubernetes.io/controller-uid=105ae4d7-3528-4c93-8291-8396e145d1c9;k8s:batch.kubernetes.io/job-name=horizon-db-sync;k8s:component=db-sync;k8s:controller-uid=105ae4d7-3528-4c93-8291-8396e145d1c9;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=horizon-db-sync;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=c99efd3ca2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=897 identity=20109 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=105ae4d7-3528-4c93-8291-8396e145d1c9,k8s:batch.kubernetes.io/job-name=horizon-db-sync,k8s:component=db-sync,k8s:controller-uid=105ae4d7-3528-4c93-8291-8396e145d1c9,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-sync,k8s:release_group=horizon" ipv4=10.0.0.60 ipv6= k8sPodName=openstack/horizon-db-sync-4qx2s oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c99efd3ca2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=897 identity=20109 ipv4=10.0.0.60 ipv6= k8sPodName=openstack/horizon-db-sync-4qx2s subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=c99efd3ca2 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=897 identity=20109 ipv4=10.0.0.60 ipv6= k8sPodName=openstack/horizon-db-sync-4qx2s subsys=endpoint level=info msg="Successful endpoint creation" containerID=c99efd3ca2 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=897 identity=20109 ipv4=10.0.0.60 ipv6= k8sPodName=openstack/horizon-db-sync-4qx2s subsys=daemon level=info msg="Delete endpoint request" containerID=c99efd3ca2 endpointID=897 k8sNamespace=openstack k8sPodName=horizon-db-sync-4qx2s subsys=daemon level=info msg="Releasing key" key="[k8s:application=horizon k8s:batch.kubernetes.io/controller-uid=105ae4d7-3528-4c93-8291-8396e145d1c9 k8s:batch.kubernetes.io/job-name=horizon-db-sync k8s:component=db-sync k8s:controller-uid=105ae4d7-3528-4c93-8291-8396e145d1c9 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=horizon-db-sync k8s:release_group=horizon]" subsys=allocator level=info msg="Removed endpoint" containerID=c99efd3ca2 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=897 identity=20109 ipv4=10.0.0.60 ipv6= k8sPodName=openstack/horizon-db-sync-4qx2s subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.50 3a309b16-fc67-414d-816b-6a7fd1659cfe default }" containerID=505977f72470d83f3768c724cfb0f0b8f98041d0eb087ebc2af09250bc4dcd7d datapathConfiguration="&{false false false false false }" interface=lxcc2131b26ce80 k8sPodName=monitoring/kube-prometheus-stack-admission-create-c767k labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=505977f724 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=572 ipv4=10.0.0.50 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-c767k subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=505977f724 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=572 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=fcb495df-a18a-4bab-969e-a6f4f9effe68,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=fcb495df-a18a-4bab-969e-a6f4f9effe68,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.50 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-c767k subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=505977f724 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=572 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.50 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-c767k line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-create;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:batch.kubernetes.io/controller-uid=fcb495df-a18a-4bab-969e-a6f4f9effe68;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create;k8s:chart=kube-prometheus-stack-60.2.0;k8s:controller-uid=fcb495df-a18a-4bab-969e-a6f4f9effe68;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-create;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=505977f724 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=572 identity=17595 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=fcb495df-a18a-4bab-969e-a6f4f9effe68,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=fcb495df-a18a-4bab-969e-a6f4f9effe68,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.50 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-c767k oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=505977f724 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=572 identity=17595 ipv4=10.0.0.50 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-c767k subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=505977f724 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=572 identity=17595 ipv4=10.0.0.50 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-c767k subsys=endpoint level=info msg="Successful endpoint creation" containerID=505977f724 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=572 identity=17595 ipv4=10.0.0.50 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-c767k subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=505977f724 endpointID=572 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-create-c767k subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-create k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=60.2.0 k8s:batch.kubernetes.io/controller-uid=fcb495df-a18a-4bab-969e-a6f4f9effe68 k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create k8s:chart=kube-prometheus-stack-60.2.0 k8s:controller-uid=fcb495df-a18a-4bab-969e-a6f4f9effe68 k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-create k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=505977f724 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=572 identity=17595 ipv4=10.0.0.50 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-c767k subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.71 e2bdf0e0-d825-4bf9-98c7-c131238df123 default }" containerID=07bd28eacc93f13525a43ba226d5fda9b8d34fc0cae50e5ce0794e048b258768 datapathConfiguration="&{false false false false false }" interface=lxc07ca1e44c320 k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-cf76d labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=07bd28eacc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2571 ipv4=10.0.0.71 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-cf76d subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=07bd28eacc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2571 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-60.2.0,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.71 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-cf76d subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-operator;k8s:app.kubernetes.io/component=prometheus-operator;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:chart=kube-prometheus-stack-60.2.0;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=07bd28eacc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2571 identity=36756 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-60.2.0,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.71 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-cf76d oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=07bd28eacc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2571 identity=36756 ipv4=10.0.0.71 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-cf76d subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.110 828ddd8d-4dcd-47e4-9e3d-55f0a4ada7be default }" containerID=b80a0ee86653056640b186d162d157da62b2fbca64ea87efdea1be81df59b0f3 datapathConfiguration="&{false false false false false }" interface=lxc082b154a8fb0 k8sPodName=monitoring/kube-prometheus-stack-grafana-7b6c69f85d-v26ct labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b80a0ee866 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3196 ipv4=10.0.0.110 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-7b6c69f85d-v26ct subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b80a0ee866 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3196 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.110 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-7b6c69f85d-v26ct subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/name=grafana;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana;k8s:io.kubernetes.pod.namespace=monitoring;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=b80a0ee866 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3196 identity=20061 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.110 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-7b6c69f85d-v26ct oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b80a0ee866 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3196 identity=20061 ipv4=10.0.0.110 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-7b6c69f85d-v26ct subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.228 a6876fc4-25b2-488e-abc8-017df7d0807a default }" containerID=280081af40f325cd05f87785547d5e761f873577af0f5b1e7d9c7fc19e6d7699 datapathConfiguration="&{false false false false false }" interface=lxcfc87f93ac0da k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-6fm2n labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=280081af40 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3248 ipv4=10.0.0.228 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-6fm2n subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=280081af40 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3248 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.20.0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.228 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-6fm2n subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=metrics;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-state-metrics;k8s:app.kubernetes.io/part-of=kube-state-metrics;k8s:app.kubernetes.io/version=2.12.0;k8s:helm.sh/chart=kube-state-metrics-5.20.0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=280081af40 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3248 identity=23874 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.20.0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.228 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-6fm2n oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=280081af40 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3248 identity=23874 ipv4=10.0.0.228 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-6fm2n subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=07bd28eacc datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=2571 identity=36756 ipv4=10.0.0.71 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-cf76d subsys=endpoint level=info msg="Successful endpoint creation" containerID=07bd28eacc datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=2571 identity=36756 ipv4=10.0.0.71 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-cf76d subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=b80a0ee866 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=3196 identity=20061 ipv4=10.0.0.110 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-7b6c69f85d-v26ct subsys=endpoint level=info msg="Successful endpoint creation" containerID=b80a0ee866 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3196 identity=20061 ipv4=10.0.0.110 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-7b6c69f85d-v26ct subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=280081af40 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=3248 identity=23874 ipv4=10.0.0.228 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-6fm2n subsys=endpoint level=info msg="Successful endpoint creation" containerID=280081af40 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3248 identity=23874 ipv4=10.0.0.228 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-6fm2n subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.4 3bf37869-cb9c-48e8-b3ac-3a1cef34caac default }" containerID=d2ab7edfa556ef6d515562e0877c814a800a3a4626a3b0978b9b4c3959eb25ee datapathConfiguration="&{false false false false false }" interface=lxc4cb6031ebb08 k8sPodName=monitoring/kube-prometheus-stack-admission-patch-srlh6 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d2ab7edfa5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=647 ipv4=10.0.0.4 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-srlh6 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d2ab7edfa5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=647 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=2449d4be-164c-4d44-b58d-9dfd599abf6a,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=2449d4be-164c-4d44-b58d-9dfd599abf6a,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.4 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-srlh6 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-patch;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:batch.kubernetes.io/controller-uid=2449d4be-164c-4d44-b58d-9dfd599abf6a;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch;k8s:chart=kube-prometheus-stack-60.2.0;k8s:controller-uid=2449d4be-164c-4d44-b58d-9dfd599abf6a;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-patch;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d2ab7edfa5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=647 identity=19902 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=2449d4be-164c-4d44-b58d-9dfd599abf6a,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=2449d4be-164c-4d44-b58d-9dfd599abf6a,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.4 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-srlh6 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d2ab7edfa5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=647 identity=19902 ipv4=10.0.0.4 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-srlh6 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=d2ab7edfa5 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=647 identity=19902 ipv4=10.0.0.4 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-srlh6 subsys=endpoint level=info msg="Successful endpoint creation" containerID=d2ab7edfa5 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=647 identity=19902 ipv4=10.0.0.4 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-srlh6 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.74 f39e319a-f75a-49bc-8527-e8cda57eb46b default }" containerID=fac6977e1d14650dd90eb3784b7ba2bd57afa78360e4615467291781eb828e54 datapathConfiguration="&{false false false false false }" interface=lxc64d25840416c k8sPodName=local-path-storage/helper-pod-create-pvc-f66e0827-8323-4ae4-8bd3-920074af85a1 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=fac6977e1d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2662 ipv4=10.0.0.74 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f66e0827-8323-4ae4-8bd3-920074af85a1 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=fac6977e1d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2662 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.74 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f66e0827-8323-4ae4-8bd3-920074af85a1 subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=fac6977e1d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2662 identity=7254 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.74 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f66e0827-8323-4ae4-8bd3-920074af85a1 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=fac6977e1d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2662 identity=7254 ipv4=10.0.0.74 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f66e0827-8323-4ae4-8bd3-920074af85a1 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=fac6977e1d datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=2662 identity=7254 ipv4=10.0.0.74 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f66e0827-8323-4ae4-8bd3-920074af85a1 subsys=endpoint level=info msg="Successful endpoint creation" containerID=fac6977e1d datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=2662 identity=7254 ipv4=10.0.0.74 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f66e0827-8323-4ae4-8bd3-920074af85a1 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.37 5ffcbb91-c10c-433e-896f-d63f8cda621b default }" containerID=720318466368ed33d5e86f79bcc5754c9e887919fddfad9ea7a8732a9daeb7dd datapathConfiguration="&{false false false false false }" interface=lxcc8ad141dde5b k8sPodName=local-path-storage/helper-pod-create-pvc-42723bf7-f4c0-4886-9d02-08b66b2d92b3 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=7203184663 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=781 ipv4=10.0.0.37 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-42723bf7-f4c0-4886-9d02-08b66b2d92b3 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=7203184663 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=781 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.37 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-42723bf7-f4c0-4886-9d02-08b66b2d92b3 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=7203184663 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=781 identity=7254 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.37 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-42723bf7-f4c0-4886-9d02-08b66b2d92b3 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=7203184663 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=781 identity=7254 ipv4=10.0.0.37 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-42723bf7-f4c0-4886-9d02-08b66b2d92b3 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=7203184663 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=781 identity=7254 ipv4=10.0.0.37 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-42723bf7-f4c0-4886-9d02-08b66b2d92b3 subsys=endpoint level=info msg="Successful endpoint creation" containerID=7203184663 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=781 identity=7254 ipv4=10.0.0.37 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-42723bf7-f4c0-4886-9d02-08b66b2d92b3 subsys=daemon level=info msg="Delete endpoint request" containerID=d2ab7edfa5 endpointID=647 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-patch-srlh6 subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-patch k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=60.2.0 k8s:batch.kubernetes.io/controller-uid=2449d4be-164c-4d44-b58d-9dfd599abf6a k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch k8s:chart=kube-prometheus-stack-60.2.0 k8s:controller-uid=2449d4be-164c-4d44-b58d-9dfd599abf6a k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-patch k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=d2ab7edfa5 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=647 identity=19902 ipv4=10.0.0.4 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-srlh6 subsys=endpoint level=info msg="Delete endpoint request" containerID=fac6977e1d endpointID=2662 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-f66e0827-8323-4ae4-8bd3-920074af85a1 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=fac6977e1d datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=2662 identity=7254 ipv4=10.0.0.74 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f66e0827-8323-4ae4-8bd3-920074af85a1 subsys=endpoint level=info msg="Delete endpoint request" containerID=7203184663 endpointID=781 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-42723bf7-f4c0-4886-9d02-08b66b2d92b3 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=7203184663 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=781 identity=7254 ipv4=10.0.0.37 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-42723bf7-f4c0-4886-9d02-08b66b2d92b3 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.18 52d90a51-c028-4b82-a960-4ead6c9611f3 default }" containerID=58656e4be3545a6986c35d05bf980620c1fe543ae90295fb582cad209a1bdf10 datapathConfiguration="&{false false false false false }" interface=lxc5ddad0bd3c1a k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=58656e4be3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3907 ipv4=10.0.0.18 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=58656e4be3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3907 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.18 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:alertmanager=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=alertmanager;k8s:app.kubernetes.io/version=0.27.0;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager;k8s:io.kubernetes.pod.namespace=monitoring;k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=58656e4be3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3907 identity=54455 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.18 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=58656e4be3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3907 identity=54455 ipv4=10.0.0.18 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=58656e4be3 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=3907 identity=54455 ipv4=10.0.0.18 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=58656e4be3 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=3907 identity=54455 ipv4=10.0.0.18 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.211 a35910f7-e34d-4dc3-8cd7-a2aca3fff6a9 default }" containerID=9646ad57763e8d25b015c0ad54dadad1342f9740578b6ecf57e4d7a530764b8a datapathConfiguration="&{false false false false false }" interface=lxc493ad11f93b9 k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=9646ad5776 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1810 ipv4=10.0.0.211 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=9646ad5776 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1810 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.211 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=prometheus;k8s:app.kubernetes.io/version=2.51.2;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus;k8s:io.kubernetes.pod.namespace=monitoring;k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus;k8s:operator.prometheus.io/shard=0;k8s:prometheus=kube-prometheus-stack-prometheus;k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=9646ad5776 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1810 identity=32101 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.211 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=9646ad5776 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1810 identity=32101 ipv4=10.0.0.211 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=9646ad5776 datapathPolicyRevision=0 desiredPolicyRevision=5 endpointID=1810 identity=32101 ipv4=10.0.0.211 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=9646ad5776 datapathPolicyRevision=5 desiredPolicyRevision=5 endpointID=1810 identity=32101 ipv4=10.0.0.211 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager