level=info msg="Memory available for map entries (0.003% of 16764968960B): 41912422B" subsys=config level=info msg="option bpf-ct-global-tcp-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-ct-global-any-max set by dynamic sizing to 73530" subsys=config level=info msg="option bpf-nat-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-neigh-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-sock-rev-map-max set by dynamic sizing to 73530" subsys=config level=info msg=" --agent-health-port='9879'" subsys=daemon level=info msg=" --agent-labels=''" subsys=daemon level=info msg=" --agent-liveness-update-interval='1s'" subsys=daemon level=info msg=" --agent-not-ready-taint-key='node.cilium.io/agent-not-ready'" subsys=daemon level=info msg=" --allocator-list-timeout='3m0s'" subsys=daemon level=info msg=" --allow-icmp-frag-needed='true'" subsys=daemon level=info msg=" --allow-localhost='auto'" subsys=daemon level=info msg=" --annotate-k8s-node='false'" subsys=daemon level=info msg=" --api-rate-limit=''" subsys=daemon level=info msg=" --arping-refresh-period='30s'" subsys=daemon level=info msg=" --auto-create-cilium-node-resource='true'" subsys=daemon level=info msg=" --auto-direct-node-routes='false'" subsys=daemon level=info msg=" --bgp-announce-lb-ip='false'" subsys=daemon level=info msg=" --bgp-announce-pod-cidr='false'" subsys=daemon level=info msg=" --bgp-config-path='/var/lib/cilium/bgp/config.yaml'" subsys=daemon level=info msg=" --bpf-auth-map-max='524288'" subsys=daemon level=info msg=" --bpf-ct-global-any-max='262144'" subsys=daemon level=info msg=" --bpf-ct-global-tcp-max='524288'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-fin='10s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-syn='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp-grace='1m0s'" subsys=daemon level=info msg=" --bpf-filter-priority='1'" subsys=daemon level=info msg=" --bpf-fragments-map-max='8192'" subsys=daemon level=info msg=" --bpf-lb-acceleration='disabled'" subsys=daemon level=info msg=" --bpf-lb-affinity-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-algorithm='random'" subsys=daemon level=info msg=" --bpf-lb-dev-ip-addr-inherit=''" subsys=daemon level=info msg=" --bpf-lb-dsr-dispatch='opt'" subsys=daemon level=info msg=" --bpf-lb-dsr-l4-xlate='frontend'" subsys=daemon level=info msg=" --bpf-lb-external-clusterip='false'" subsys=daemon level=info msg=" --bpf-lb-maglev-hash-seed='JLfvgnHc2kaSUFaI'" subsys=daemon level=info msg=" --bpf-lb-maglev-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-maglev-table-size='16381'" subsys=daemon level=info msg=" --bpf-lb-map-max='65536'" subsys=daemon level=info msg=" --bpf-lb-mode='snat'" subsys=daemon level=info msg=" --bpf-lb-rev-nat-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-rss-ipv4-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-rss-ipv6-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-service-backend-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-service-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-sock='false'" subsys=daemon level=info msg=" --bpf-lb-sock-hostns-only='false'" subsys=daemon level=info msg=" --bpf-lb-source-range-map-max='0'" subsys=daemon level=info msg=" --bpf-map-dynamic-size-ratio='0.0025'" subsys=daemon level=info msg=" --bpf-map-event-buffers=''" subsys=daemon level=info msg=" --bpf-nat-global-max='524288'" subsys=daemon level=info msg=" --bpf-neigh-global-max='524288'" subsys=daemon level=info msg=" --bpf-policy-map-full-reconciliation-interval='15m0s'" subsys=daemon level=info msg=" --bpf-policy-map-max='16384'" subsys=daemon level=info msg=" --bpf-root='/sys/fs/bpf'" subsys=daemon level=info msg=" --bpf-sock-rev-map-max='262144'" subsys=daemon level=info msg=" --bypass-ip-availability-upon-restore='false'" subsys=daemon level=info msg=" --certificates-directory='/var/run/cilium/certs'" subsys=daemon level=info msg=" --cflags=''" subsys=daemon level=info msg=" --cgroup-root='/run/cilium/cgroupv2'" subsys=daemon level=info msg=" --cilium-endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --cluster-health-port='4240'" subsys=daemon level=info msg=" --cluster-id='0'" subsys=daemon level=info msg=" --cluster-name='default'" subsys=daemon level=info msg=" --cluster-pool-ipv4-cidr='10.0.0.0/8'" subsys=daemon level=info msg=" --cluster-pool-ipv4-mask-size='24'" subsys=daemon level=info msg=" --clustermesh-config='/var/lib/cilium/clustermesh/'" subsys=daemon level=info msg=" --clustermesh-ip-identities-sync-timeout='1m0s'" subsys=daemon level=info msg=" --cmdref=''" subsys=daemon level=info msg=" --cni-chaining-mode='none'" subsys=daemon level=info msg=" --cni-chaining-target=''" subsys=daemon level=info msg=" --cni-exclusive='true'" subsys=daemon level=info msg=" --cni-external-routing='false'" subsys=daemon level=info msg=" --cni-log-file='/var/run/cilium/cilium-cni.log'" subsys=daemon level=info msg=" --cnp-node-status-gc-interval='0s'" subsys=daemon level=info msg=" --config=''" subsys=daemon level=info msg=" --config-dir='/tmp/cilium/config-map'" subsys=daemon level=info msg=" --config-sources='config-map:kube-system/cilium-config'" subsys=daemon level=info msg=" --conntrack-gc-interval='0s'" subsys=daemon level=info msg=" --conntrack-gc-max-interval='0s'" subsys=daemon level=info msg=" --crd-wait-timeout='5m0s'" subsys=daemon level=info msg=" --custom-cni-conf='false'" subsys=daemon level=info msg=" --datapath-mode='veth'" subsys=daemon level=info msg=" --debug='false'" subsys=daemon level=info msg=" --debug-verbose=''" subsys=daemon level=info msg=" --derive-masquerade-ip-addr-from-device=''" subsys=daemon level=info msg=" --devices=''" subsys=daemon level=info msg=" --direct-routing-device=''" subsys=daemon level=info msg=" --disable-cnp-status-updates='true'" subsys=daemon level=info msg=" --disable-endpoint-crd='false'" subsys=daemon level=info msg=" --disable-envoy-version-check='false'" subsys=daemon level=info msg=" --disable-iptables-feeder-rules=''" subsys=daemon level=info msg=" --dns-max-ips-per-restored-rule='1000'" subsys=daemon level=info msg=" --dns-policy-unload-on-shutdown='false'" subsys=daemon level=info msg=" --dnsproxy-concurrency-limit='0'" subsys=daemon level=info msg=" --dnsproxy-concurrency-processing-grace-period='0s'" subsys=daemon level=info msg=" --dnsproxy-enable-transparent-mode='true'" subsys=daemon level=info msg=" --dnsproxy-lock-count='128'" subsys=daemon level=info msg=" --dnsproxy-lock-timeout='500ms'" subsys=daemon level=info msg=" --egress-gateway-policy-map-max='16384'" subsys=daemon level=info msg=" --egress-gateway-reconciliation-trigger-interval='1s'" subsys=daemon level=info msg=" --egress-masquerade-interfaces=''" subsys=daemon level=info msg=" --egress-multi-home-ip-rule-compat='false'" subsys=daemon level=info msg=" --enable-auto-protect-node-port-range='true'" subsys=daemon level=info msg=" --enable-bandwidth-manager='false'" subsys=daemon level=info msg=" --enable-bbr='false'" subsys=daemon level=info msg=" --enable-bgp-control-plane='false'" subsys=daemon level=info msg=" --enable-bpf-clock-probe='false'" subsys=daemon level=info msg=" --enable-bpf-masquerade='false'" subsys=daemon level=info msg=" --enable-bpf-tproxy='false'" subsys=daemon level=info msg=" --enable-cilium-api-server-access='*'" subsys=daemon level=info msg=" --enable-cilium-endpoint-slice='false'" subsys=daemon level=info msg=" --enable-cilium-health-api-server-access='*'" subsys=daemon level=info msg=" --enable-custom-calls='false'" subsys=daemon level=info msg=" --enable-endpoint-health-checking='true'" subsys=daemon level=info msg=" --enable-endpoint-routes='false'" subsys=daemon level=info msg=" --enable-envoy-config='false'" subsys=daemon level=info msg=" --enable-external-ips='false'" subsys=daemon level=info msg=" --enable-health-check-nodeport='true'" subsys=daemon level=info msg=" --enable-health-checking='true'" subsys=daemon level=info msg=" --enable-high-scale-ipcache='false'" subsys=daemon level=info msg=" --enable-host-firewall='false'" subsys=daemon level=info msg=" --enable-host-legacy-routing='false'" subsys=daemon level=info msg=" --enable-host-port='false'" subsys=daemon level=info msg=" --enable-hubble='false'" subsys=daemon level=info msg=" --enable-hubble-recorder-api='true'" subsys=daemon level=info msg=" --enable-icmp-rules='true'" subsys=daemon level=info msg=" --enable-identity-mark='true'" subsys=daemon level=info msg=" --enable-ip-masq-agent='false'" subsys=daemon level=info msg=" --enable-ipsec='false'" subsys=daemon level=info msg=" --enable-ipsec-key-watcher='true'" subsys=daemon level=info msg=" --enable-ipv4='true'" subsys=daemon level=info msg=" --enable-ipv4-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv4-egress-gateway='false'" subsys=daemon level=info msg=" --enable-ipv4-fragment-tracking='true'" subsys=daemon level=info msg=" --enable-ipv4-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6='false'" subsys=daemon level=info msg=" --enable-ipv6-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv6-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6-ndp='false'" subsys=daemon level=info msg=" --enable-k8s='true'" subsys=daemon level=info msg=" --enable-k8s-api-discovery='false'" subsys=daemon level=info msg=" --enable-k8s-endpoint-slice='true'" subsys=daemon level=info msg=" --enable-k8s-event-handover='false'" subsys=daemon level=info msg=" --enable-k8s-networkpolicy='true'" subsys=daemon level=info msg=" --enable-k8s-terminating-endpoint='true'" subsys=daemon level=info msg=" --enable-l2-announcements='false'" subsys=daemon level=info msg=" --enable-l2-neigh-discovery='true'" subsys=daemon level=info msg=" --enable-l2-pod-announcements='false'" subsys=daemon level=info msg=" --enable-l7-proxy='true'" subsys=daemon level=info msg=" --enable-local-node-route='true'" subsys=daemon level=info msg=" --enable-local-redirect-policy='false'" subsys=daemon level=info msg=" --enable-mke='false'" subsys=daemon level=info msg=" --enable-monitor='true'" subsys=daemon level=info msg=" --enable-nat46x64-gateway='false'" subsys=daemon level=info msg=" --enable-node-port='false'" subsys=daemon level=info msg=" --enable-pmtu-discovery='false'" subsys=daemon level=info msg=" --enable-policy='default'" subsys=daemon level=info msg=" --enable-recorder='false'" subsys=daemon level=info msg=" --enable-remote-node-identity='true'" subsys=daemon level=info msg=" --enable-runtime-device-detection='false'" subsys=daemon level=info msg=" --enable-sctp='false'" subsys=daemon level=info msg=" --enable-service-topology='false'" subsys=daemon level=info msg=" --enable-session-affinity='false'" subsys=daemon level=info msg=" --enable-srv6='false'" subsys=daemon level=info msg=" --enable-stale-cilium-endpoint-cleanup='true'" subsys=daemon level=info msg=" --enable-svc-source-range-check='true'" subsys=daemon level=info msg=" --enable-tracing='false'" subsys=daemon level=info msg=" --enable-unreachable-routes='false'" subsys=daemon level=info msg=" --enable-vtep='false'" subsys=daemon level=info msg=" --enable-well-known-identities='false'" subsys=daemon level=info msg=" --enable-wireguard='false'" subsys=daemon level=info msg=" --enable-wireguard-userspace-fallback='false'" subsys=daemon level=info msg=" --enable-xdp-prefilter='false'" subsys=daemon level=info msg=" --enable-xt-socket-fallback='true'" subsys=daemon level=info msg=" --encrypt-interface=''" subsys=daemon level=info msg=" --encrypt-node='false'" subsys=daemon level=info msg=" --endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --endpoint-queue-size='25'" subsys=daemon level=info msg=" --endpoint-status=''" subsys=daemon level=info msg=" --envoy-config-timeout='2m0s'" subsys=daemon level=info msg=" --envoy-log=''" subsys=daemon level=info msg=" --exclude-local-address=''" subsys=daemon level=info msg=" --external-envoy-proxy='false'" subsys=daemon level=info msg=" --fixed-identity-mapping=''" subsys=daemon level=info msg=" --fqdn-regex-compile-lru-size='1024'" subsys=daemon level=info msg=" --gops-port='9890'" subsys=daemon level=info msg=" --http-403-msg=''" subsys=daemon level=info msg=" --http-idle-timeout='0'" subsys=daemon level=info msg=" --http-max-grpc-timeout='0'" subsys=daemon level=info msg=" --http-normalize-path='true'" subsys=daemon level=info msg=" --http-request-timeout='3600'" subsys=daemon level=info msg=" --http-retry-count='3'" subsys=daemon level=info msg=" --http-retry-timeout='0'" subsys=daemon level=info msg=" --hubble-disable-tls='false'" subsys=daemon level=info msg=" --hubble-event-buffer-capacity='4095'" subsys=daemon level=info msg=" --hubble-event-queue-size='0'" subsys=daemon level=info msg=" --hubble-export-file-compress='false'" subsys=daemon level=info msg=" --hubble-export-file-max-backups='5'" subsys=daemon level=info msg=" --hubble-export-file-max-size-mb='10'" subsys=daemon level=info msg=" --hubble-export-file-path=''" subsys=daemon level=info msg=" --hubble-listen-address=''" subsys=daemon level=info msg=" --hubble-metrics=''" subsys=daemon level=info msg=" --hubble-metrics-server=''" subsys=daemon level=info msg=" --hubble-monitor-events=''" subsys=daemon level=info msg=" --hubble-prefer-ipv6='false'" subsys=daemon level=info msg=" --hubble-recorder-sink-queue-size='1024'" subsys=daemon level=info msg=" --hubble-recorder-storage-path='/var/run/cilium/pcaps'" subsys=daemon level=info msg=" --hubble-skip-unknown-cgroup-ids='true'" subsys=daemon level=info msg=" --hubble-socket-path='/var/run/cilium/hubble.sock'" subsys=daemon level=info msg=" --hubble-tls-cert-file=''" subsys=daemon level=info msg=" --hubble-tls-client-ca-files=''" subsys=daemon level=info msg=" --hubble-tls-key-file=''" subsys=daemon level=info msg=" --identity-allocation-mode='crd'" subsys=daemon level=info msg=" --identity-change-grace-period='5s'" subsys=daemon level=info msg=" --identity-gc-interval='15m0s'" subsys=daemon level=info msg=" --identity-heartbeat-timeout='30m0s'" subsys=daemon level=info msg=" --identity-restore-grace-period='10m0s'" subsys=daemon level=info msg=" --install-egress-gateway-routes='false'" subsys=daemon level=info msg=" --install-iptables-rules='true'" subsys=daemon level=info msg=" --install-no-conntrack-iptables-rules='false'" subsys=daemon level=info msg=" --ip-allocation-timeout='2m0s'" subsys=daemon level=info msg=" --ip-masq-agent-config-path='/etc/config/ip-masq-agent'" subsys=daemon level=info msg=" --ipam='cluster-pool'" subsys=daemon level=info msg=" --ipam-cilium-node-update-rate='15s'" subsys=daemon level=info msg=" --ipam-multi-pool-pre-allocation='default=8'" subsys=daemon level=info msg=" --ipsec-key-file=''" subsys=daemon level=info msg=" --ipsec-key-rotation-duration='5m0s'" subsys=daemon level=info msg=" --iptables-lock-timeout='5s'" subsys=daemon level=info msg=" --iptables-random-fully='false'" subsys=daemon level=info msg=" --ipv4-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv4-node='auto'" subsys=daemon level=info msg=" --ipv4-pod-subnets=''" subsys=daemon level=info msg=" --ipv4-range='auto'" subsys=daemon level=info msg=" --ipv4-service-loopback-address='169.254.42.1'" subsys=daemon level=info msg=" --ipv4-service-range='auto'" subsys=daemon level=info msg=" --ipv6-cluster-alloc-cidr='f00d::/64'" subsys=daemon level=info msg=" --ipv6-mcast-device=''" subsys=daemon level=info msg=" --ipv6-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv6-node='auto'" subsys=daemon level=info msg=" --ipv6-pod-subnets=''" subsys=daemon level=info msg=" --ipv6-range='auto'" subsys=daemon level=info msg=" --ipv6-service-range='auto'" subsys=daemon level=info msg=" --join-cluster='false'" subsys=daemon level=info msg=" --k8s-api-server=''" subsys=daemon level=info msg=" --k8s-client-burst='10'" subsys=daemon level=info msg=" --k8s-client-qps='5'" subsys=daemon level=info msg=" --k8s-heartbeat-timeout='30s'" subsys=daemon level=info msg=" --k8s-kubeconfig-path=''" subsys=daemon level=info msg=" --k8s-namespace='kube-system'" subsys=daemon level=info msg=" --k8s-require-ipv4-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-require-ipv6-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-service-cache-size='128'" subsys=daemon level=info msg=" --k8s-service-proxy-name=''" subsys=daemon level=info msg=" --k8s-sync-timeout='3m0s'" subsys=daemon level=info msg=" --k8s-watcher-endpoint-selector='metadata.name!=kube-scheduler,metadata.name!=kube-controller-manager,metadata.name!=etcd-operator,metadata.name!=gcp-controller-manager'" subsys=daemon level=info msg=" --keep-config='false'" subsys=daemon level=info msg=" --kube-proxy-replacement='disabled'" subsys=daemon level=info msg=" --kube-proxy-replacement-healthz-bind-address=''" subsys=daemon level=info msg=" --kvstore=''" subsys=daemon level=info msg=" --kvstore-connectivity-timeout='2m0s'" subsys=daemon level=info msg=" --kvstore-lease-ttl='15m0s'" subsys=daemon level=info msg=" --kvstore-max-consecutive-quorum-errors='2'" subsys=daemon level=info msg=" --kvstore-opt=''" subsys=daemon level=info msg=" --kvstore-periodic-sync='5m0s'" subsys=daemon level=info msg=" --l2-announcements-lease-duration='15s'" subsys=daemon level=info msg=" --l2-announcements-renew-deadline='5s'" subsys=daemon level=info msg=" --l2-announcements-retry-period='2s'" subsys=daemon level=info msg=" --l2-pod-announcements-interface=''" subsys=daemon level=info msg=" --label-prefix-file=''" subsys=daemon level=info msg=" --labels=''" subsys=daemon level=info msg=" --lib-dir='/var/lib/cilium'" subsys=daemon level=info msg=" --local-max-addr-scope='252'" subsys=daemon level=info msg=" --local-router-ipv4=''" subsys=daemon level=info msg=" --local-router-ipv6=''" subsys=daemon level=info msg=" --log-driver=''" subsys=daemon level=info msg=" --log-opt=''" subsys=daemon level=info msg=" --log-system-load='false'" subsys=daemon level=info msg=" --max-controller-interval='0'" subsys=daemon level=info msg=" --mesh-auth-enabled='true'" subsys=daemon level=info msg=" --mesh-auth-gc-interval='5m0s'" subsys=daemon level=info msg=" --mesh-auth-mutual-listener-port='0'" subsys=daemon level=info msg=" --mesh-auth-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-rotated-identities-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-signal-backoff-duration='1s'" subsys=daemon level=info msg=" --mesh-auth-spiffe-trust-domain='spiffe.cilium'" subsys=daemon level=info msg=" --mesh-auth-spire-admin-socket=''" subsys=daemon level=info msg=" --metrics=''" subsys=daemon level=info msg=" --mke-cgroup-mount=''" subsys=daemon level=info msg=" --monitor-aggregation='medium'" subsys=daemon level=info msg=" --monitor-aggregation-flags='all'" subsys=daemon level=info msg=" --monitor-aggregation-interval='5s'" subsys=daemon level=info msg=" --monitor-queue-size='0'" subsys=daemon level=info msg=" --mtu='0'" subsys=daemon level=info msg=" --node-encryption-opt-out-labels='node-role.kubernetes.io/control-plane'" subsys=daemon level=info msg=" --node-port-acceleration='disabled'" subsys=daemon level=info msg=" --node-port-algorithm='random'" subsys=daemon level=info msg=" --node-port-bind-protection='true'" subsys=daemon level=info msg=" --node-port-mode='snat'" subsys=daemon level=info msg=" --node-port-range='30000,32767'" subsys=daemon level=info msg=" --nodes-gc-interval='5m0s'" subsys=daemon level=info msg=" --operator-api-serve-addr='127.0.0.1:9234'" subsys=daemon level=info msg=" --policy-audit-mode='false'" subsys=daemon level=info msg=" --policy-queue-size='100'" subsys=daemon level=info msg=" --policy-trigger-interval='1s'" subsys=daemon level=info msg=" --pprof='false'" subsys=daemon level=info msg=" --pprof-address='localhost'" subsys=daemon level=info msg=" --pprof-port='6060'" subsys=daemon level=info msg=" --preallocate-bpf-maps='false'" subsys=daemon level=info msg=" --prepend-iptables-chains='true'" subsys=daemon level=info msg=" --procfs='/host/proc'" subsys=daemon level=info msg=" --prometheus-serve-addr=':9962'" subsys=daemon level=info msg=" --proxy-connect-timeout='2'" subsys=daemon level=info msg=" --proxy-gid='1337'" subsys=daemon level=info msg=" --proxy-idle-timeout-seconds='60'" subsys=daemon level=info msg=" --proxy-max-connection-duration-seconds='0'" subsys=daemon level=info msg=" --proxy-max-requests-per-connection='0'" subsys=daemon level=info msg=" --proxy-prometheus-port='9964'" subsys=daemon level=info msg=" --read-cni-conf=''" subsys=daemon level=info msg=" --remove-cilium-node-taints='true'" subsys=daemon level=info msg=" --restore='true'" subsys=daemon level=info msg=" --route-metric='0'" subsys=daemon level=info msg=" --routing-mode='tunnel'" subsys=daemon level=info msg=" --set-cilium-is-up-condition='true'" subsys=daemon level=info msg=" --set-cilium-node-taints='true'" subsys=daemon level=info msg=" --sidecar-istio-proxy-image='cilium/istio_proxy'" subsys=daemon level=info msg=" --single-cluster-route='false'" subsys=daemon level=info msg=" --skip-cnp-status-startup-clean='false'" subsys=daemon level=info msg=" --socket-path='/var/run/cilium/cilium.sock'" subsys=daemon level=info msg=" --srv6-encap-mode='reduced'" subsys=daemon level=info msg=" --state-dir='/var/run/cilium'" subsys=daemon level=info msg=" --synchronize-k8s-nodes='true'" subsys=daemon level=info msg=" --tofqdns-dns-reject-response-code='refused'" subsys=daemon level=info msg=" --tofqdns-enable-dns-compression='true'" subsys=daemon level=info msg=" --tofqdns-endpoint-max-ip-per-hostname='50'" subsys=daemon level=info msg=" --tofqdns-idle-connection-grace-period='0s'" subsys=daemon level=info msg=" --tofqdns-max-deferred-connection-deletes='10000'" subsys=daemon level=info msg=" --tofqdns-min-ttl='0'" subsys=daemon level=info msg=" --tofqdns-pre-cache=''" subsys=daemon level=info msg=" --tofqdns-proxy-port='0'" subsys=daemon level=info msg=" --tofqdns-proxy-response-max-delay='100ms'" subsys=daemon level=info msg=" --trace-payloadlen='128'" subsys=daemon level=info msg=" --trace-sock='true'" subsys=daemon level=info msg=" --tunnel=''" subsys=daemon level=info msg=" --tunnel-port='6082'" subsys=daemon level=info msg=" --tunnel-protocol='geneve'" subsys=daemon level=info msg=" --unmanaged-pod-watcher-interval='15'" subsys=daemon level=info msg=" --use-cilium-internal-ip-for-ipsec='false'" subsys=daemon level=info msg=" --version='false'" subsys=daemon level=info msg=" --vlan-bpf-bypass=''" subsys=daemon level=info msg=" --vtep-cidr=''" subsys=daemon level=info msg=" --vtep-endpoint=''" subsys=daemon level=info msg=" --vtep-mac=''" subsys=daemon level=info msg=" --vtep-mask=''" subsys=daemon level=info msg=" --wireguard-encapsulate='false'" subsys=daemon level=info msg=" --write-cni-conf-when-ready='/host/etc/cni/net.d/05-cilium.conflist'" subsys=daemon level=info msg=" _ _ _" subsys=daemon level=info msg=" ___|_| |_|_ _ _____" subsys=daemon level=info msg="| _| | | | | | |" subsys=daemon level=info msg="|___|_|_|_|___|_|_|_|" subsys=daemon level=info msg="Cilium 1.14.8 cf6e022e 2024-03-13T12:23:35-04:00 go version go1.21.8 linux/amd64" subsys=daemon level=info msg="clang (10.0.0) and kernel (5.15.0) versions: OK!" subsys=linux-datapath level=info msg="linking environment: OK!" subsys=linux-datapath level=info msg="Kernel config file not found: if the agent fails to start, check the system requirements at https://docs.cilium.io/en/stable/operations/system_requirements" subsys=probes level=info msg="Detected mounted BPF filesystem at /sys/fs/bpf" subsys=bpf level=info msg="Mounted cgroupv2 filesystem at /run/cilium/cgroupv2" subsys=cgroups level=info msg="Parsing base label prefixes from default label list" subsys=labels-filter level=info msg="Parsing additional label prefixes from user inputs: []" subsys=labels-filter level=info msg="Final label prefixes to be used for identity evaluation:" subsys=labels-filter level=info msg=" - reserved:.*" subsys=labels-filter level=info msg=" - :io\\.kubernetes\\.pod\\.namespace" subsys=labels-filter level=info msg=" - :io\\.cilium\\.k8s\\.namespace\\.labels" subsys=labels-filter level=info msg=" - :app\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:io\\.kubernetes" subsys=labels-filter level=info msg=" - !:kubernetes\\.io" subsys=labels-filter level=info msg=" - !:.*beta\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:k8s\\.io" subsys=labels-filter level=info msg=" - !:pod-template-generation" subsys=labels-filter level=info msg=" - !:pod-template-hash" subsys=labels-filter level=info msg=" - !:controller-revision-hash" subsys=labels-filter level=info msg=" - !:annotation.*" subsys=labels-filter level=info msg=" - !:etcd_node" subsys=labels-filter level=info msg=Invoked duration=5.339149ms function="pprof.glob..func1 (cell.go:50)" subsys=hive level=info msg=Invoked duration="160.433µs" function="gops.registerGopsHooks (cell.go:38)" subsys=hive level=info msg=Invoked duration=1.782289ms function="metrics.NewRegistry (registry.go:65)" subsys=hive level=info msg=Invoked duration="15.261µs" function="metrics.glob..func1 (cell.go:12)" subsys=hive level=info msg="Spire Delegate API Client is disabled as no socket path is configured" subsys=spire-delegate level=info msg="Mutual authentication handler is disabled as no port is configured" subsys=auth level=info msg=Invoked duration=96.451998ms function="cmd.glob..func4 (daemon_main.go:1607)" subsys=hive level=info msg=Invoked duration="15.551µs" function="gc.registerSignalHandler (cell.go:47)" subsys=hive level=info msg=Invoked duration="20.352µs" function="utime.initUtimeSync (cell.go:29)" subsys=hive level=info msg=Invoked duration="90.037µs" function="agentliveness.newAgentLivenessUpdater (agent_liveness.go:43)" subsys=hive level=info msg=Invoked duration="93.387µs" function="l2responder.NewL2ResponderReconciler (l2responder.go:63)" subsys=hive level=info msg=Invoked duration="141.671µs" function="garp.newGARPProcessor (processor.go:27)" subsys=hive level=info msg=Starting subsys=hive level=info msg="Started gops server" address="127.0.0.1:9890" subsys=gops level=info msg="Start hook executed" duration="593.846µs" function="gops.registerGopsHooks.func1 (cell.go:43)" subsys=hive level=info msg="Start hook executed" duration="1.78µs" function="metrics.NewRegistry.func1 (registry.go:86)" subsys=hive level=info msg="Establishing connection to apiserver" host="https://10.96.0.1:443" subsys=k8s-client level=info msg="Serving prometheus metrics on :9962" subsys=metrics level=info msg="Connected to apiserver" subsys=k8s-client level=info msg="Start hook executed" duration=10.141126ms function="client.(*compositeClientset).onStart" subsys=hive level=info msg="Start hook executed" duration=8.831383ms function="authmap.newAuthMap.func1 (cell.go:27)" subsys=hive level=info msg="Start hook executed" duration="43.953µs" function="configmap.newMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="129.94µs" function="signalmap.newMap.func1 (cell.go:44)" subsys=hive level=info msg="Start hook executed" duration="392.741µs" function="nodemap.newNodeMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="100.038µs" function="eventsmap.newEventsMap.func1 (cell.go:35)" subsys=hive level=info msg="Start hook executed" duration="78.316µs" function="*cni.cniConfigManager.Start" subsys=hive level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Wrote CNI configuration file to /host/etc/cni/net.d/05-cilium.conflist" subsys=cni-config level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Start hook executed" duration=45.595708ms function="datapath.newDatapath.func1 (cells.go:113)" subsys=hive level=info msg="Restored 0 node IDs from the BPF map" subsys=linux-datapath level=info msg="Start hook executed" duration="105.658µs" function="datapath.newDatapath.func2 (cells.go:126)" subsys=hive level=info msg="Start hook executed" duration="12.151µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Node].Start" subsys=hive level=info msg="Start hook executed" duration="1.97µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNode].Start" subsys=hive level=info msg="Using autogenerated IPv4 allocation range" subsys=node v4Prefix=10.102.0.0/16 level=info msg="no local ciliumnode found, will not restore cilium internal ips from k8s" subsys=daemon level=info msg="Start hook executed" duration=102.909887ms function="node.NewLocalNodeStore.func1 (local_node_store.go:76)" subsys=hive level=info msg="Start hook executed" duration="5.18µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration=100.529397ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration="12.001µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Using discoveryv1.EndpointSlice" subsys=k8s level=info msg="Start hook executed" duration=100.399359ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Start hook executed" duration="1.87µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Pod].Start" subsys=hive level=info msg="Start hook executed" duration="1.02µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Namespace].Start" subsys=hive level=info msg="Start hook executed" duration="4.611µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="1.1µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumClusterwideNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="1.321µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumCIDRGroup].Start" subsys=hive level=info msg="Start hook executed" duration="34.222µs" function="endpointmanager.newDefaultEndpointManager.func1 (cell.go:203)" subsys=hive level=info msg="Start hook executed" duration="10.21µs" function="cmd.newPolicyTrifecta.func1 (policy.go:135)" subsys=hive level=info msg="Start hook executed" duration="42.883µs" function="*manager.manager.Start" subsys=hive level=info msg="Serving cilium node monitor v1.2 API at unix:///var/run/cilium/monitor1_2.sock" subsys=monitor-agent level=info msg="Start hook executed" duration="290.183µs" function="agent.newMonitorAgent.func1 (cell.go:61)" subsys=hive level=info msg="Start hook executed" duration="3.061µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumL2AnnouncementPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="11.441µs" function="*job.group.Start" subsys=hive level=info msg="Start hook executed" duration="232.859µs" function="proxy.newProxy.func1 (cell.go:55)" subsys=hive level=info msg="Envoy: Starting xDS gRPC server listening on /var/run/cilium/envoy/sockets/xds.sock" subsys=envoy-manager level=info msg="Start hook executed" duration="311.364µs" function="signal.provideSignalManager.func1 (cell.go:25)" subsys=hive level=info msg="Datapath signal listener running" subsys=signal level=info msg="Start hook executed" duration=1.243067ms function="auth.registerAuthManager.func1 (cell.go:109)" subsys=hive level=info msg="Start hook executed" duration="8.791µs" function="auth.registerGCJobs.func1 (cell.go:158)" subsys=hive level=info msg="Start hook executed" duration="23.472µs" function="*job.group.Start" subsys=hive level=warning msg="Deprecated value for --kube-proxy-replacement: disabled (use either \"true\", or \"false\")" subsys=daemon level=info msg="Auto-disabling \"enable-node-port\", \"enable-external-ips\", \"bpf-lb-sock\", \"enable-host-port\" features and falling back to \"enable-host-legacy-routing\"" subsys=daemon level=info msg="Inheriting MTU from external network interface" device=ens3 ipAddr=199.204.45.102 mtu=1500 subsys=mtu level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_ipcache, recreating and re-pinning map cilium_ipcache" file-path=/sys/fs/bpf/tc/globals/cilium_ipcache name=cilium_ipcache subsys=bpf level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_tunnel_map, recreating and re-pinning map cilium_tunnel_map" file-path=/sys/fs/bpf/tc/globals/cilium_tunnel_map name=cilium_tunnel_map subsys=bpf level=info msg="Restored services from maps" failedServices=0 restoredServices=0 subsys=service level=info msg="Restored backends from maps" failedBackends=0 restoredBackends=0 skippedBackends=0 subsys=service level=info msg="Reading old endpoints..." subsys=daemon level=info msg="No old endpoints found." subsys=daemon level=info msg="Waiting until all Cilium CRDs are available" subsys=k8s level=info msg="All Cilium CRDs have been found and are available" subsys=k8s level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=info msg="Successfully created CiliumNode resource" subsys=nodediscovery level=warning msg="Unable to create CiliumNode resource, will retry" error="ciliumnodes.cilium.io \"instance\" already exists" subsys=nodediscovery level=info msg="Retrieved node information from cilium node" nodeName=instance subsys=k8s level=warning msg="Waiting for k8s node information" error="required IPv4 PodCIDR not available" subsys=k8s level=info msg="Retrieved node information from cilium node" nodeName=instance subsys=k8s level=info msg="Received own node information from API server" ipAddr.ipv4=199.204.45.102 ipAddr.ipv6="" k8sNodeIP=199.204.45.102 labels="map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:]" nodeName=instance subsys=k8s v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="k8s mode: Allowing localhost to reach local endpoints" subsys=daemon level=info msg="Detected devices" devices="[]" subsys=linux-datapath level=info msg="Enabling k8s event listener" subsys=k8s-watcher level=info msg="Removing stale endpoint interfaces" subsys=daemon level=info msg="Skipping kvstore configuration" subsys=daemon level=info msg="Initializing node addressing" subsys=daemon level=info msg="Initializing cluster-pool IPAM" subsys=ipam v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="Waiting until local node addressing before starting watchers depending on it" subsys=k8s-watcher level=info msg="Restoring endpoints..." subsys=daemon level=info msg="Endpoints restored" failed=0 restored=0 subsys=daemon level=info msg="Addressing information:" subsys=daemon level=info msg=" Cluster-Name: default" subsys=daemon level=info msg=" Cluster-ID: 0" subsys=daemon level=info msg=" Local node-name: instance" subsys=daemon level=info msg=" Node-IPv6: " subsys=daemon level=info msg=" External-Node IPv4: 199.204.45.102" subsys=daemon level=info msg=" Internal-Node IPv4: 10.0.0.132" subsys=daemon level=info msg=" IPv4 allocation prefix: 10.0.0.0/24" subsys=daemon level=info msg=" Loopback IPv4: 169.254.42.1" subsys=daemon level=info msg=" Local IPv4 addresses:" subsys=daemon level=info msg=" - 199.204.45.102" subsys=daemon level=info msg=" - 172.17.0.100" subsys=daemon level=info msg="Node updated" clusterName=default nodeName=instance subsys=nodemanager level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Adding local node to cluster" node="{instance default [{InternalIP 199.204.45.102} {CiliumInternalIP 10.0.0.132}] 10.0.0.0/24 [] [] 10.0.0.150 0 local 0 map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:] map[] 1 }" subsys=nodediscovery level=info msg="Waiting until all pre-existing resources have been received" subsys=k8s-watcher level=info msg="Initializing identity allocator" subsys=identity-cache level=info msg="Allocating identities between range" cluster-id=0 max=65535 min=256 subsys=identity-cache level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.core.bpf_jit_enable sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.all.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.fib_multipath_use_neigh sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.unprivileged_bpf_disabled sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.timer_migration sysParamValue=0 level=info msg="Setting up BPF datapath" bpfClockSource=ktime bpfInsnSet="" subsys=datapath-loader level=info msg="Iptables rules installed" subsys=iptables level=info msg="Adding new proxy port rules for cilium-dns-egress:35537" id=cilium-dns-egress subsys=proxy level=info msg="Iptables proxy rules installed" subsys=iptables level=info msg="Start hook executed" duration=2.297157943s function="cmd.newDaemonPromise.func1 (daemon_main.go:1663)" subsys=hive level=info msg="Starting IP identity watcher" subsys=ipcache level=info msg="Initializing daemon" subsys=daemon level=info msg="Validating configured node address ranges" subsys=daemon level=info msg="Start hook executed" duration="44.864µs" function="utime.initUtimeSync.func1 (cell.go:33)" subsys=hive level=info msg="Starting connection tracking garbage collector" subsys=daemon level=info msg="Start hook executed" duration="8.08µs" function="*job.group.Start" subsys=hive level=info msg="Start hook executed" duration="38.813µs" function="l2respondermap.newMap.func1 (l2_responder_map4.go:44)" subsys=hive level=info msg="Start hook executed" duration="15.661µs" function="*job.group.Start" subsys=hive level=info msg="Initial scan of connection tracking completed" subsys=ct-gc level=info msg="Regenerating restored endpoints" numRestored=0 subsys=daemon level=info msg="Creating host endpoint" subsys=daemon level=info msg="Finished regenerating restored endpoints" regenerated=0 subsys=daemon total=0 level=info msg="Deleted orphan backends" orphanBackends=0 subsys=service level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2650 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2650 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2650 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="Launching Cilium health daemon" subsys=daemon level=info msg="Launching Cilium health endpoint" subsys=daemon level=info msg="Started healthz status API server" address="127.0.0.1:9879" subsys=daemon level=info msg="Processing queued endpoint deletion requests from /var/run/cilium/deleteQueue" subsys=daemon level=info msg="processing 0 queued deletion requests" subsys=daemon level=info msg="Initializing Cilium API" subsys=daemon level=info msg="Daemon initialization completed" bootstrapTime=3.226024125s subsys=daemon level=info msg="Hubble server is disabled" subsys=hubble level=info msg="Serving cilium API at unix:///var/run/cilium/cilium.sock" subsys=daemon level=info msg="Compiled new BPF template" BPFCompilationTime=303.184042ms file-path=/var/run/cilium/state/templates/ec955712ddb4e9798c3fec3b438b5a343fa39a950cd9cec8d969d7f9994c6157/bpf_host.o subsys=datapath-loader level=info msg="Create endpoint request" addressing="&{10.0.0.73 618f4723-0615-4277-a480-dcfb9653d4b0 default }" containerID=d57a427cd726cb43e3bace9cabd6f0b49e7593251d1c884d463e755746ee1baf datapathConfiguration="&{false false false false false }" interface=lxcc269bfb5176b k8sPodName=kube-system/coredns-7c96b6546b-hkjcb labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d57a427cd7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3770 ipv4=10.0.0.73 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-hkjcb subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d57a427cd7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3770 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.73 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-hkjcb subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:kube-system]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=d57a427cd7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3770 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.73 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-hkjcb line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=coredns;k8s:io.kubernetes.pod.namespace=kube-system;k8s:k8s-app=kube-dns;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d57a427cd7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3770 identity=42719 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.73 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-hkjcb oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d57a427cd7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3770 identity=42719 ipv4=10.0.0.73 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-hkjcb subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2650 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.13 3cad2dcb-324e-4b74-b707-400e133cf214 default }" containerID=8b9129cc5eb8a6520ae725a3421f83e8d6b9f00218faef1bd7d0ca0437d84777 datapathConfiguration="&{false false false false false }" interface=lxc7493348ae4ab k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-852cm labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=8b9129cc5e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3411 ipv4=10.0.0.13 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-852cm subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=8b9129cc5e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3411 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=bf5cf0cc-65fe-4935-9939-67c43356de06,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=bf5cf0cc-65fe-4935-9939-67c43356de06,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.13 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-852cm subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=certgen;k8s:batch.kubernetes.io/controller-uid=bf5cf0cc-65fe-4935-9939-67c43356de06;k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen;k8s:controller-uid=bf5cf0cc-65fe-4935-9939-67c43356de06;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;k8s:job-name=envoy-gateway-gateway-helm-certgen;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=8b9129cc5e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3411 identity=17109 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=bf5cf0cc-65fe-4935-9939-67c43356de06,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=bf5cf0cc-65fe-4935-9939-67c43356de06,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.13 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-852cm oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=8b9129cc5e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3411 identity=17109 ipv4=10.0.0.13 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-852cm subsys=endpoint level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=941 ipv4=10.0.0.150 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=941 identityLabels="reserved:health" ipv4=10.0.0.150 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=941 identity=4 identityLabels="reserved:health" ipv4=10.0.0.150 ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Compiled new BPF template" BPFCompilationTime=1.059572947s file-path=/var/run/cilium/state/templates/6f4f4896bb224cfd4b1bb69b16f21a4fa006e331764d8ab59d5200f0cf25a576/bpf_lxc.o subsys=datapath-loader level=info msg="Rewrote endpoint BPF program" containerID=8b9129cc5e datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=3411 identity=17109 ipv4=10.0.0.13 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-852cm subsys=endpoint level=info msg="Successful endpoint creation" containerID=8b9129cc5e datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3411 identity=17109 ipv4=10.0.0.13 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-852cm subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=d57a427cd7 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=3770 identity=42719 ipv4=10.0.0.73 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-hkjcb subsys=endpoint level=info msg="Successful endpoint creation" containerID=d57a427cd7 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3770 identity=42719 ipv4=10.0.0.73 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-hkjcb subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=941 identity=4 ipv4=10.0.0.150 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Serving cilium health API at unix:///var/run/cilium/health.sock" subsys=health-server level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=8b9129cc5e endpointID=3411 k8sNamespace=envoy-gateway-system k8sPodName=envoy-gateway-gateway-helm-certgen-852cm subsys=daemon level=info msg="Releasing key" key="[k8s:app=certgen k8s:batch.kubernetes.io/controller-uid=bf5cf0cc-65fe-4935-9939-67c43356de06 k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen k8s:controller-uid=bf5cf0cc-65fe-4935-9939-67c43356de06 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen k8s:io.kubernetes.pod.namespace=envoy-gateway-system k8s:job-name=envoy-gateway-gateway-helm-certgen]" subsys=allocator level=info msg="Removed endpoint" containerID=8b9129cc5e datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3411 identity=17109 ipv4=10.0.0.13 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-852cm subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.88 ff6eace5-72d1-4a4f-8e74-f183cc513ef3 default }" containerID=eab32914e8f02d5b8c320be099d173b7f1dc65e0aa5f812e919e55049ae664fd datapathConfiguration="&{false false false false false }" interface=lxc2b5f1a7f7375 k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zwhkx labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=eab32914e8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=436 ipv4=10.0.0.88 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zwhkx subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=eab32914e8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=436 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.88 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zwhkx subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=envoy-gateway;k8s:app.kubernetes.io/name=gateway-helm;k8s:control-plane=envoy-gateway;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=eab32914e8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=436 identity=34181 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.88 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zwhkx oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=eab32914e8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=436 identity=34181 ipv4=10.0.0.88 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zwhkx subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=eab32914e8 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=436 identity=34181 ipv4=10.0.0.88 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zwhkx subsys=endpoint level=info msg="Successful endpoint creation" containerID=eab32914e8 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=436 identity=34181 ipv4=10.0.0.88 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zwhkx subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2650 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,k8s:openstack-compute-node=enabled,k8s:openstack-control-plane=enabled,k8s:openvswitch=enabled,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_hostns_02650 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_hostns_02650 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_hostns_02650 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_hostns_02650:pending" subsys=bpf level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_netdev_00003 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_netdev_00003 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003:pending" subsys=bpf level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2650 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.149 080d8393-6b91-44f9-84fa-bcb12758748d default }" containerID=a64e67adc8bb0a2a7b29d89429346fcb81fce7ca30daf0f937622b9933e647dd datapathConfiguration="&{false false false false false }" interface=lxc92e2e1535887 k8sPodName=kube-system/coredns-67659f764b-z8rnz labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=a64e67adc8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1607 ipv4=10.0.0.149 ipv6= k8sPodName=kube-system/coredns-67659f764b-z8rnz subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=a64e67adc8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1607 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.149 ipv6= k8sPodName=kube-system/coredns-67659f764b-z8rnz subsys=endpoint level=info msg="Identity of endpoint changed" containerID=a64e67adc8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1607 identity=42719 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.149 ipv6= k8sPodName=kube-system/coredns-67659f764b-z8rnz oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=a64e67adc8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1607 identity=42719 ipv4=10.0.0.149 ipv6= k8sPodName=kube-system/coredns-67659f764b-z8rnz subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.121 0bbb84f3-65a3-41b4-8a3e-e5dce45fca93 default }" containerID=e40d1a14220ee226e30e3aac289b3985e306473fcbba7bd01321235f341a45ea datapathConfiguration="&{false false false false false }" interface=lxcbea709d1c224 k8sPodName=kube-system/coredns-67659f764b-5hk5l labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e40d1a1422 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=377 ipv4=10.0.0.121 ipv6= k8sPodName=kube-system/coredns-67659f764b-5hk5l subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e40d1a1422 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=377 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.121 ipv6= k8sPodName=kube-system/coredns-67659f764b-5hk5l subsys=endpoint level=info msg="Identity of endpoint changed" containerID=e40d1a1422 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=377 identity=42719 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.121 ipv6= k8sPodName=kube-system/coredns-67659f764b-5hk5l oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e40d1a1422 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=377 identity=42719 ipv4=10.0.0.121 ipv6= k8sPodName=kube-system/coredns-67659f764b-5hk5l subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=a64e67adc8 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1607 identity=42719 ipv4=10.0.0.149 ipv6= k8sPodName=kube-system/coredns-67659f764b-z8rnz subsys=endpoint level=info msg="Successful endpoint creation" containerID=a64e67adc8 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1607 identity=42719 ipv4=10.0.0.149 ipv6= k8sPodName=kube-system/coredns-67659f764b-z8rnz subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=e40d1a1422 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=377 identity=42719 ipv4=10.0.0.121 ipv6= k8sPodName=kube-system/coredns-67659f764b-5hk5l subsys=endpoint level=info msg="Successful endpoint creation" containerID=e40d1a1422 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=377 identity=42719 ipv4=10.0.0.121 ipv6= k8sPodName=kube-system/coredns-67659f764b-5hk5l subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.136 ef7bf093-0fcc-4f4b-b65f-674597a63af5 default }" containerID=f8fbeb4febaafc38ddd4c3b1e0f3bec9f9946766347a294637a9221e6d32fc69 datapathConfiguration="&{false false false false false }" interface=lxc4169c452dd5d k8sPodName=local-path-storage/local-path-provisioner-679c578f5-7xrf7 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f8fbeb4feb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=14 ipv4=10.0.0.136 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-7xrf7 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f8fbeb4feb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=14 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.136 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-7xrf7 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=local-path-provisioner;k8s:app.kubernetes.io/name=local-path-provisioner;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=f8fbeb4feb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=14 identity=5204 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.136 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-7xrf7 oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=f8fbeb4feb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=14 identity=5204 ipv4=10.0.0.136 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-7xrf7 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=f8fbeb4feb datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=14 identity=5204 ipv4=10.0.0.136 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-7xrf7 subsys=endpoint level=info msg="Successful endpoint creation" containerID=f8fbeb4feb datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=14 identity=5204 ipv4=10.0.0.136 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-7xrf7 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=d57a427cd7 endpointID=3770 k8sNamespace=kube-system k8sPodName=coredns-7c96b6546b-hkjcb subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=coredns k8s:io.kubernetes.pod.namespace=kube-system k8s:k8s-app=kube-dns]" subsys=allocator level=info msg="Removed endpoint" containerID=d57a427cd7 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3770 identity=42719 ipv4=10.0.0.73 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-hkjcb subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.235 badaa78c-7da2-417c-9e20-2b245cb715a7 default }" containerID=acc762533e1dda7cc70209275770a16a5f2f45066a1dad25cf0816c16ad690da datapathConfiguration="&{false false false false false }" interface=lxc4fc010ad5219 k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-sd86p labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=acc762533e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=842 ipv4=10.0.0.235 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-sd86p subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=acc762533e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=842 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.235 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-sd86p subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Create endpoint request" addressing="&{10.0.0.176 1f7f54d6-06e7-4f49-8527-29b1387af91e default }" containerID=55d50098de1287ab42d1894e6f5716aa274d40f9356804091df0d6990a7a5566 datapathConfiguration="&{false false false false false }" interface=lxc5f070d476670 k8sPodName=cert-manager/cert-manager-75c4c745bc-8m6s6 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=55d50098de datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=438 ipv4=10.0.0.176 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-8m6s6 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=55d50098de datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=438 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.176 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-8m6s6 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=55d50098de datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=438 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.176 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-8m6s6 line=611 subsys=endpoint level=info msg="Invalid state transition skipped" containerID=acc762533e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=842 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.235 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-sd86p line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=cainjector;k8s:app.kubernetes.io/component=cainjector;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cainjector;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=acc762533e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=842 identity=6265 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.235 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-sd86p oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=acc762533e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=842 identity=6265 ipv4=10.0.0.235 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-sd86p subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=cert-manager;k8s:app.kubernetes.io/component=controller;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cert-manager;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=55d50098de datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=438 identity=58135 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.176 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-8m6s6 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=55d50098de datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=438 identity=58135 ipv4=10.0.0.176 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-8m6s6 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.164 7ed32d6d-bca6-4d9b-9c8e-4f90c70ad8bb default }" containerID=630c0d9120af5efdbfdffedf3138fa23fa6bf3a3ae29601a6d0fb1fd20705159 datapathConfiguration="&{false false false false false }" interface=lxcf15daa8b46a0 k8sPodName=cert-manager/cert-manager-webhook-548949fc64-ss65r labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=630c0d9120 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=20 ipv4=10.0.0.164 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-ss65r subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=630c0d9120 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=20 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.164 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-ss65r subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=webhook;k8s:app.kubernetes.io/component=webhook;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=webhook;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=630c0d9120 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=20 identity=7970 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.164 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-ss65r oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=630c0d9120 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=20 identity=7970 ipv4=10.0.0.164 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-ss65r subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=acc762533e datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=842 identity=6265 ipv4=10.0.0.235 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-sd86p subsys=endpoint level=info msg="Successful endpoint creation" containerID=acc762533e datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=842 identity=6265 ipv4=10.0.0.235 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-sd86p subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=630c0d9120 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=20 identity=7970 ipv4=10.0.0.164 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-ss65r subsys=endpoint level=info msg="Successful endpoint creation" containerID=630c0d9120 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=20 identity=7970 ipv4=10.0.0.164 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-ss65r subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=55d50098de datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=438 identity=58135 ipv4=10.0.0.176 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-8m6s6 subsys=endpoint level=info msg="Successful endpoint creation" containerID=55d50098de datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=438 identity=58135 ipv4=10.0.0.176 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-8m6s6 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.198 6cba8ade-72ac-45b9-8855-f83bceeb7602 default }" containerID=a955440e67a65ee2c0ff0a8a88e2461a3d739f78e65ee393b944f66f515128d7 datapathConfiguration="&{false false false false false }" interface=lxc8b0e4c3bd019 k8sPodName=cert-manager/cert-manager-startupapicheck-6z5ql labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=a955440e67 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2065 ipv4=10.0.0.198 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-6z5ql subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=a955440e67 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2065 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=2be4e822-38a3-498f-9a26-08f75d7cd155,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=2be4e822-38a3-498f-9a26-08f75d7cd155,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.198 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-6z5ql subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=startupapicheck;k8s:app.kubernetes.io/component=startupapicheck;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=startupapicheck;k8s:app.kubernetes.io/version=v1.11.5;k8s:batch.kubernetes.io/controller-uid=2be4e822-38a3-498f-9a26-08f75d7cd155;k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck;k8s:controller-uid=2be4e822-38a3-498f-9a26-08f75d7cd155;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck;k8s:io.kubernetes.pod.namespace=cert-manager;k8s:job-name=cert-manager-startupapicheck;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=a955440e67 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2065 identity=31177 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=2be4e822-38a3-498f-9a26-08f75d7cd155,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=2be4e822-38a3-498f-9a26-08f75d7cd155,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.198 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-6z5ql oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=a955440e67 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2065 identity=31177 ipv4=10.0.0.198 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-6z5ql subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=a955440e67 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2065 identity=31177 ipv4=10.0.0.198 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-6z5ql subsys=endpoint level=info msg="Successful endpoint creation" containerID=a955440e67 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2065 identity=31177 ipv4=10.0.0.198 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-6z5ql subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=a955440e67 endpointID=2065 k8sNamespace=cert-manager k8sPodName=cert-manager-startupapicheck-6z5ql subsys=daemon level=info msg="Releasing key" key="[k8s:app=startupapicheck k8s:app.kubernetes.io/component=startupapicheck k8s:app.kubernetes.io/instance=cert-manager k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=startupapicheck k8s:app.kubernetes.io/version=v1.11.5 k8s:batch.kubernetes.io/controller-uid=2be4e822-38a3-498f-9a26-08f75d7cd155 k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck k8s:controller-uid=2be4e822-38a3-498f-9a26-08f75d7cd155 k8s:helm.sh/chart=cert-manager-v1.11.5 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager k8s:io.cilium.k8s.namespace.labels.name=cert-manager k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck k8s:io.kubernetes.pod.namespace=cert-manager k8s:job-name=cert-manager-startupapicheck]" subsys=allocator level=info msg="Removed endpoint" containerID=a955440e67 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2065 identity=31177 ipv4=10.0.0.198 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-6z5ql subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.146 cc4d972b-7211-453b-9dfb-d4c672c14b8a default }" containerID=180ce497142fd827d2ec434b437d86f24f097ce5d6b88bc8e9e0f3feed421a3a datapathConfiguration="&{false false false false false }" interface=lxcc860f2e36c28 k8sPodName=ingress-nginx/ingress-nginx-admission-create-6klxz labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=180ce49714 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=402 ipv4=10.0.0.146 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-6klxz subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=180ce49714 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=402 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=1a6a12e5-9547-4ec7-b9bc-dd0def867772,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=1a6a12e5-9547-4ec7-b9bc-dd0def867772,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.146 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-6klxz subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=1a6a12e5-9547-4ec7-b9bc-dd0def867772;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create;k8s:controller-uid=1a6a12e5-9547-4ec7-b9bc-dd0def867772;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-create;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=180ce49714 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=402 identity=18737 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=1a6a12e5-9547-4ec7-b9bc-dd0def867772,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=1a6a12e5-9547-4ec7-b9bc-dd0def867772,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.146 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-6klxz oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=180ce49714 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=402 identity=18737 ipv4=10.0.0.146 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-6klxz subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=180ce49714 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=402 identity=18737 ipv4=10.0.0.146 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-6klxz subsys=endpoint level=info msg="Successful endpoint creation" containerID=180ce49714 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=402 identity=18737 ipv4=10.0.0.146 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-6klxz subsys=daemon level=info msg="Delete endpoint request" containerID=180ce49714 endpointID=402 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-create-6klxz subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=1a6a12e5-9547-4ec7-b9bc-dd0def867772 k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create k8s:controller-uid=1a6a12e5-9547-4ec7-b9bc-dd0def867772 k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-create]" subsys=allocator level=info msg="Removed endpoint" containerID=180ce49714 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=402 identity=18737 ipv4=10.0.0.146 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-6klxz subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.1 294ee245-4fe9-4d26-a939-7c282e334713 default }" containerID=97e87ed81555102720f54fc1f6e3e625a6b3b681716e253b7a6e4b18a649f62e datapathConfiguration="&{false false false false false }" interface=lxca220fd9d15f3 k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-m4ctk labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=97e87ed815 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1178 ipv4=10.0.0.1 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-m4ctk subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=97e87ed815 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1178 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.1 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-m4ctk subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=97e87ed815 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1178 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.1 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-m4ctk line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=default-backend;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend;k8s:io.kubernetes.pod.namespace=ingress-nginx;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=97e87ed815 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1178 identity=16498 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.1 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-m4ctk oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=97e87ed815 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1178 identity=16498 ipv4=10.0.0.1 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-m4ctk subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=97e87ed815 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1178 identity=16498 ipv4=10.0.0.1 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-m4ctk subsys=endpoint level=info msg="Successful endpoint creation" containerID=97e87ed815 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1178 identity=16498 ipv4=10.0.0.1 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-m4ctk subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.75 21fd4cbd-6141-4e82-863c-b439fdfe6015 default }" containerID=efcb4bb4a38cb4eea47bcffa6dca76e12bd469c0424f150c0e34877ec5dbccfd datapathConfiguration="&{false false false false false }" interface=lxc73b69678d878 k8sPodName=ingress-nginx/ingress-nginx-admission-patch-wpswj labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=efcb4bb4a3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1482 ipv4=10.0.0.75 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-wpswj subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=efcb4bb4a3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1482 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=bfa24324-8310-4702-967b-d6713e551155,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=bfa24324-8310-4702-967b-d6713e551155,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.75 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-wpswj subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=bfa24324-8310-4702-967b-d6713e551155;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch;k8s:controller-uid=bfa24324-8310-4702-967b-d6713e551155;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-patch;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=efcb4bb4a3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1482 identity=14706 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=bfa24324-8310-4702-967b-d6713e551155,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=bfa24324-8310-4702-967b-d6713e551155,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.75 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-wpswj oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=efcb4bb4a3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1482 identity=14706 ipv4=10.0.0.75 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-wpswj subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=efcb4bb4a3 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1482 identity=14706 ipv4=10.0.0.75 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-wpswj subsys=endpoint level=info msg="Successful endpoint creation" containerID=efcb4bb4a3 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1482 identity=14706 ipv4=10.0.0.75 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-wpswj subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=efcb4bb4a3 endpointID=1482 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-patch-wpswj subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=bfa24324-8310-4702-967b-d6713e551155 k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch k8s:controller-uid=bfa24324-8310-4702-967b-d6713e551155 k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-patch]" subsys=allocator level=info msg="Removed endpoint" containerID=efcb4bb4a3 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1482 identity=14706 ipv4=10.0.0.75 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-wpswj subsys=endpoint level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"rabbitmq-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-cluster-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=3b7a75f1-51f8-4f1b-9033-2ff3e5c2dbb4] Description:}]" policyAddRequest=42fa7169-52b3-4749-8507-fe78076398d6 subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=42fa7169-52b3-4749-8507-fe78076398d6 policyRevision=2 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-cluster-operator subsys=k8s-watcher level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"messaging-topology-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:9443 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-messaging-topology-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=b66d7e07-9ada-4f8a-83f7-fbf025f4ceed] Description:}]" policyAddRequest=9b3a1f72-1bff-4541-933f-ce19a845d9d2 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-messaging-topology-operator subsys=k8s-watcher level=info msg="Policy imported via API, recalculating..." policyAddRequest=9b3a1f72-1bff-4541-933f-ce19a845d9d2 policyRevision=3 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.229 524cb8a3-6d2a-47e6-b55f-11f49dbc74c9 default }" containerID=7edfd70964a22c63a9c22e1015b74543b8120d71485f9c52a8390219d4c540ad datapathConfiguration="&{false false false false false }" interface=lxc4f037e08957d k8sPodName=openstack/rabbitmq-cluster-operator-7fcdcd478-hvhq7 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=7edfd70964 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1042 ipv4=10.0.0.229 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-7fcdcd478-hvhq7 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=7edfd70964 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1042 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.9.0,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.229 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-7fcdcd478-hvhq7 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=2.9.0;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=7edfd70964 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1042 identity=6080 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.9.0,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.229 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-7fcdcd478-hvhq7 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=7edfd70964 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1042 identity=6080 ipv4=10.0.0.229 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-7fcdcd478-hvhq7 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=7edfd70964 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=1042 identity=6080 ipv4=10.0.0.229 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-7fcdcd478-hvhq7 subsys=endpoint level=info msg="Successful endpoint creation" containerID=7edfd70964 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=1042 identity=6080 ipv4=10.0.0.229 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-7fcdcd478-hvhq7 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.190 35a13273-8978-4cd0-928a-8f8098326cf6 default }" containerID=9547a50cd20c01159ea6b50a7f26177daca8772d2a7b2dbab0b79576bdd37357 datapathConfiguration="&{false false false false false }" interface=lxcda78d2c23bc0 k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-5vpg4 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=9547a50cd2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3077 ipv4=10.0.0.190 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-5vpg4 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=9547a50cd2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3077 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.14.1,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.190 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-5vpg4 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=messaging-topology-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=1.14.1;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=9547a50cd2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3077 identity=35551 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.14.1,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.190 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-5vpg4 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=9547a50cd2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3077 identity=35551 ipv4=10.0.0.190 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-5vpg4 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=9547a50cd2 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=3077 identity=35551 ipv4=10.0.0.190 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-5vpg4 subsys=endpoint level=info msg="Successful endpoint creation" containerID=9547a50cd2 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=3077 identity=35551 ipv4=10.0.0.190 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-5vpg4 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.67 20375ac1-49dc-4acf-9672-d1b60d9dd0c6 default }" containerID=d6b919e8839b8f2939f2467232d20f3a334416396455e77b739e6549a9e45fb2 datapathConfiguration="&{false false false false false }" interface=lxc09eba7af9814 k8sPodName=openstack/pxc-operator-7cff949c8b-pp4vl labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d6b919e883 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1456 ipv4=10.0.0.67 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-pp4vl subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d6b919e883 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1456 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.67 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-pp4vl subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=operator;k8s:app.kubernetes.io/instance=pxc-operator;k8s:app.kubernetes.io/name=pxc-operator;k8s:app.kubernetes.io/part-of=pxc-operator;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d6b919e883 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1456 identity=54865 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.67 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-pp4vl oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d6b919e883 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1456 identity=54865 ipv4=10.0.0.67 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-pp4vl subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=d6b919e883 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=1456 identity=54865 ipv4=10.0.0.67 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-pp4vl subsys=endpoint level=info msg="Successful endpoint creation" containerID=d6b919e883 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=1456 identity=54865 ipv4=10.0.0.67 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-pp4vl subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.222 34f9aa39-7d59-447f-8e33-89cebff8ee40 default }" containerID=c0da57948513e0e027293f5e6001e0fbf7bb4e29cdf43c0771c659593bcd7e1d datapathConfiguration="&{false false false false false }" interface=lxc970bd2287821 k8sPodName=openstack/percona-xtradb-haproxy-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c0da579485 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3920 ipv4=10.0.0.222 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c0da579485 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3920 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.222 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=haproxy;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=c0da579485 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3920 identity=46256 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.222 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=c0da579485 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3920 identity=46256 ipv4=10.0.0.222 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=c0da579485 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=3920 identity=46256 ipv4=10.0.0.222 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=c0da579485 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=3920 identity=46256 ipv4=10.0.0.222 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.173 f0a1e965-f298-4123-a3d4-8efebe467caf default }" containerID=066a536ccb1df0aef73b117334e979c1feffb6b88a3730785cacc9e2565b391e datapathConfiguration="&{false false false false false }" interface=lxcf6a56ea95a31 k8sPodName=local-path-storage/helper-pod-create-pvc-8df794f7-1d29-4225-a717-97384b2f23df labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=066a536ccb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=152 ipv4=10.0.0.173 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-8df794f7-1d29-4225-a717-97384b2f23df subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=066a536ccb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=152 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.173 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-8df794f7-1d29-4225-a717-97384b2f23df subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=066a536ccb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=152 identity=43487 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.173 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-8df794f7-1d29-4225-a717-97384b2f23df oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=066a536ccb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=152 identity=43487 ipv4=10.0.0.173 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-8df794f7-1d29-4225-a717-97384b2f23df subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=066a536ccb datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=152 identity=43487 ipv4=10.0.0.173 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-8df794f7-1d29-4225-a717-97384b2f23df subsys=endpoint level=info msg="Successful endpoint creation" containerID=066a536ccb datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=152 identity=43487 ipv4=10.0.0.173 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-8df794f7-1d29-4225-a717-97384b2f23df subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=066a536ccb endpointID=152 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-8df794f7-1d29-4225-a717-97384b2f23df subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=066a536ccb datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=152 identity=43487 ipv4=10.0.0.173 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-8df794f7-1d29-4225-a717-97384b2f23df subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.107 eb71a255-2304-4bd9-8cb5-64f0e41c5ff6 default }" containerID=8e81bb12e6359009e58f5c336cf8e433a5295fdada2ee63ab32f53bc80a3b846 datapathConfiguration="&{false false false false false }" interface=lxc73b3fded4751 k8sPodName=openstack/percona-xtradb-pxc-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=8e81bb12e6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=11 ipv4=10.0.0.107 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=8e81bb12e6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=11 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.107 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=pxc;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=8e81bb12e6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=11 identity=523 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.107 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=8e81bb12e6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=11 identity=523 ipv4=10.0.0.107 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=8e81bb12e6 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=11 identity=523 ipv4=10.0.0.107 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=8e81bb12e6 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=11 identity=523 ipv4=10.0.0.107 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.92 c42b4a24-4553-4691-8116-26aa6958162a default }" containerID=88cd017e5dd1ee03d1862f059579c0f46b6bae5f3925b278a83440496fde70c1 datapathConfiguration="&{false false false false false }" interface=lxc623317d8e925 k8sPodName=openstack/memcached-memcached-6479589586-9sw8n labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=88cd017e5d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=841 ipv4=10.0.0.92 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-9sw8n subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=88cd017e5d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=841 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.92 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-9sw8n subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=memcached;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=memcached;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=88cd017e5d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=841 identity=13727 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.92 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-9sw8n oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=88cd017e5d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=841 identity=13727 ipv4=10.0.0.92 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-9sw8n subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=88cd017e5d datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=841 identity=13727 ipv4=10.0.0.92 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-9sw8n subsys=endpoint level=info msg="Successful endpoint creation" containerID=88cd017e5d datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=841 identity=13727 ipv4=10.0.0.92 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-9sw8n subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"keycloak\",\"k8s:app.kubernetes.io/instance\":\"keycloak\",\"k8s:app.kubernetes.io/name\":\"keycloak\",\"k8s:io.kubernetes.pod.namespace\":\"auth-system\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:7800 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:} {Ports:[{Port:8080 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=keycloak k8s:io.cilium.k8s.policy.namespace=auth-system k8s:io.cilium.k8s.policy.uid=21dcfeaa-71f3-41e3-9606-327882e723e0] Description:}]" policyAddRequest=228b7e5c-b6c9-4657-9004-df04bcec2083 subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=228b7e5c-b6c9-4657-9004-df04bcec2083 policyRevision=4 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=keycloak subsys=k8s-watcher level=info msg="Create endpoint request" addressing="&{10.0.0.249 f2dbc492-c066-4c6d-9443-a78016c3c473 default }" containerID=16c2436eee51b2314345a418c61ff7cd6f502d6a3eeffc8bc94c747a433b10d3 datapathConfiguration="&{false false false false false }" interface=lxc729af94e96f8 k8sPodName=auth-system/keycloak-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=16c2436eee datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3217 ipv4=10.0.0.249 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=16c2436eee datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3217 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=24.0.5,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-21.4.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.249 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:auth-system k8s:io.cilium.k8s.namespace.labels.name:auth-system]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=keycloak;k8s:app.kubernetes.io/instance=keycloak;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=keycloak;k8s:app.kubernetes.io/version=24.0.5;k8s:apps.kubernetes.io/pod-index=0;k8s:helm.sh/chart=keycloak-21.4.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system;k8s:io.cilium.k8s.namespace.labels.name=auth-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keycloak;k8s:io.kubernetes.pod.namespace=auth-system;k8s:statefulset.kubernetes.io/pod-name=keycloak-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=16c2436eee datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3217 identity=8131 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=24.0.5,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-21.4.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.249 ipv6= k8sPodName=auth-system/keycloak-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=16c2436eee datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3217 identity=8131 ipv4=10.0.0.249 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=16c2436eee datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3217 identity=8131 ipv4=10.0.0.249 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=16c2436eee datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3217 identity=8131 ipv4=10.0.0.249 ipv6= k8sPodName=auth-system/keycloak-0 subsys=daemon level=info msg="Conntrack garbage collector interval recalculated" deleteRatio=0.038650890792873656 newInterval=7m30s subsys=map-ct level=info msg="Create endpoint request" addressing="&{10.0.0.188 a10daac5-eb9a-463e-9bb2-655fa72eb8ef default }" containerID=4245a9fd4e7b19540898ee2005c98abc54ba737d7e6c21ad74f36deb3456a49c datapathConfiguration="&{false false false false false }" interface=lxcfa589e7aeb32 k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-8ml9l labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=4245a9fd4e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2310 ipv4=10.0.0.188 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-8ml9l subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=4245a9fd4e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2310 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.188 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-8ml9l subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:secretgen-controller]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=4245a9fd4e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2310 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.188 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-8ml9l line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=secretgen-controller;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa;k8s:io.kubernetes.pod.namespace=secretgen-controller;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=4245a9fd4e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2310 identity=39888 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.188 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-8ml9l oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=4245a9fd4e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2310 identity=39888 ipv4=10.0.0.188 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-8ml9l subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=4245a9fd4e datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2310 identity=39888 ipv4=10.0.0.188 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-8ml9l subsys=endpoint level=info msg="Successful endpoint creation" containerID=4245a9fd4e datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2310 identity=39888 ipv4=10.0.0.188 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-8ml9l subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.236 84a0413c-3a30-4844-85d9-0af151520107 default }" containerID=eb3ac79d117606c0880d8a997ad5a8ed251ba1537431324bb30164420f456c00 datapathConfiguration="&{false false false false false }" interface=lxc5cf977e24a05 k8sPodName=monitoring/kube-prometheus-stack-admission-create-f4psw labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=eb3ac79d11 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1376 ipv4=10.0.0.236 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-f4psw subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=eb3ac79d11 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1376 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=5c0a8b37-83b4-4164-8d17-c072a8666d0b,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=5c0a8b37-83b4-4164-8d17-c072a8666d0b,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.236 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-f4psw subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-create;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:batch.kubernetes.io/controller-uid=5c0a8b37-83b4-4164-8d17-c072a8666d0b;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create;k8s:chart=kube-prometheus-stack-60.2.0;k8s:controller-uid=5c0a8b37-83b4-4164-8d17-c072a8666d0b;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-create;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=eb3ac79d11 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1376 identity=14254 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=5c0a8b37-83b4-4164-8d17-c072a8666d0b,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=5c0a8b37-83b4-4164-8d17-c072a8666d0b,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.236 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-f4psw oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=eb3ac79d11 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1376 identity=14254 ipv4=10.0.0.236 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-f4psw subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=eb3ac79d11 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1376 identity=14254 ipv4=10.0.0.236 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-f4psw subsys=endpoint level=info msg="Successful endpoint creation" containerID=eb3ac79d11 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1376 identity=14254 ipv4=10.0.0.236 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-f4psw subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=eb3ac79d11 endpointID=1376 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-create-f4psw subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-create k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=60.2.0 k8s:batch.kubernetes.io/controller-uid=5c0a8b37-83b4-4164-8d17-c072a8666d0b k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create k8s:chart=kube-prometheus-stack-60.2.0 k8s:controller-uid=5c0a8b37-83b4-4164-8d17-c072a8666d0b k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-create k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=eb3ac79d11 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1376 identity=14254 ipv4=10.0.0.236 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-f4psw subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.165 3523373f-c682-4d00-b80c-6e9496ede4d1 default }" containerID=d9173add0606aa5986858a34f7ae437354bc1c2734627ff70f164fed1d38a4bb datapathConfiguration="&{false false false false false }" interface=lxc300f2111af23 k8sPodName=monitoring/kube-prometheus-stack-grafana-85bb79dc4b-j45fj labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d9173add06 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=824 ipv4=10.0.0.165 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-85bb79dc4b-j45fj subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d9173add06 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=824 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.165 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-85bb79dc4b-j45fj subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=d9173add06 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=824 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.165 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-85bb79dc4b-j45fj line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/name=grafana;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana;k8s:io.kubernetes.pod.namespace=monitoring;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d9173add06 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=824 identity=19232 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.165 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-85bb79dc4b-j45fj oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d9173add06 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=824 identity=19232 ipv4=10.0.0.165 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-85bb79dc4b-j45fj subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.52 339b8ae9-c39f-4739-bd7d-b4807ca58a5a default }" containerID=406254176733de8299d89454caec3a77d24b99b5dc24bdaba5712dbfc70fb856 datapathConfiguration="&{false false false false false }" interface=lxcbd5f018afb40 k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-64n7g labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=4062541767 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3307 ipv4=10.0.0.52 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-64n7g subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=4062541767 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3307 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-60.2.0,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.52 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-64n7g subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Create endpoint request" addressing="&{10.0.0.191 bdfab6f2-8902-4d43-9310-ec9ae8951af0 default }" containerID=0bcc44acc0026314b733c6e32cf727886001084de5d965a83c48fcbf52c46c8f datapathConfiguration="&{false false false false false }" interface=lxc2064998e86b1 k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-pnfxv labels="[]" subsys=daemon sync-build=true level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-operator;k8s:app.kubernetes.io/component=prometheus-operator;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:chart=kube-prometheus-stack-60.2.0;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=4062541767 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3307 identity=33753 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-60.2.0,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.52 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-64n7g oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=4062541767 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3307 identity=33753 ipv4=10.0.0.52 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-64n7g subsys=endpoint level=info msg="New endpoint" containerID=0bcc44acc0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3991 ipv4=10.0.0.191 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-pnfxv subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=0bcc44acc0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3991 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.20.0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.191 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-pnfxv subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=metrics;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-state-metrics;k8s:app.kubernetes.io/part-of=kube-state-metrics;k8s:app.kubernetes.io/version=2.12.0;k8s:helm.sh/chart=kube-state-metrics-5.20.0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=0bcc44acc0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3991 identity=44881 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.20.0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.191 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-pnfxv oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=0bcc44acc0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3991 identity=44881 ipv4=10.0.0.191 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-pnfxv subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=d9173add06 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=824 identity=19232 ipv4=10.0.0.165 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-85bb79dc4b-j45fj subsys=endpoint level=info msg="Successful endpoint creation" containerID=d9173add06 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=824 identity=19232 ipv4=10.0.0.165 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-85bb79dc4b-j45fj subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=4062541767 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3307 identity=33753 ipv4=10.0.0.52 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-64n7g subsys=endpoint level=info msg="Successful endpoint creation" containerID=4062541767 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3307 identity=33753 ipv4=10.0.0.52 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-64n7g subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=0bcc44acc0 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3991 identity=44881 ipv4=10.0.0.191 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-pnfxv subsys=endpoint level=info msg="Successful endpoint creation" containerID=0bcc44acc0 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3991 identity=44881 ipv4=10.0.0.191 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-pnfxv subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.127 34e7fabc-da6e-4d93-b130-de2c63158e21 default }" containerID=98076ef36a024cada9d9c74e3680f37c79f74dc7f300b55e2e53c895d1499e48 datapathConfiguration="&{false false false false false }" interface=lxcb69d517e278b k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n26zh labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=98076ef36a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3367 ipv4=10.0.0.127 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n26zh subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=98076ef36a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3367 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=e14b6ab7-d32c-41f5-ac94-75353aa1b3f4,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=e14b6ab7-d32c-41f5-ac94-75353aa1b3f4,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.127 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n26zh subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-patch;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:batch.kubernetes.io/controller-uid=e14b6ab7-d32c-41f5-ac94-75353aa1b3f4;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch;k8s:chart=kube-prometheus-stack-60.2.0;k8s:controller-uid=e14b6ab7-d32c-41f5-ac94-75353aa1b3f4;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-patch;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=98076ef36a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3367 identity=25526 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=e14b6ab7-d32c-41f5-ac94-75353aa1b3f4,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=e14b6ab7-d32c-41f5-ac94-75353aa1b3f4,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.127 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n26zh oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=98076ef36a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3367 identity=25526 ipv4=10.0.0.127 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n26zh subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=98076ef36a datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3367 identity=25526 ipv4=10.0.0.127 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n26zh subsys=endpoint level=info msg="Successful endpoint creation" containerID=98076ef36a datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3367 identity=25526 ipv4=10.0.0.127 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n26zh subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=98076ef36a endpointID=3367 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-patch-n26zh subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-patch k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=60.2.0 k8s:batch.kubernetes.io/controller-uid=e14b6ab7-d32c-41f5-ac94-75353aa1b3f4 k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch k8s:chart=kube-prometheus-stack-60.2.0 k8s:controller-uid=e14b6ab7-d32c-41f5-ac94-75353aa1b3f4 k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-patch k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=98076ef36a datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3367 identity=25526 ipv4=10.0.0.127 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n26zh subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.90 f2dcafb9-8a5d-4730-8833-ceebb0c0c018 default }" containerID=822756866cacb36e5d07ed39d3962b1b62c5a8e7d320b33b447c4d9d71488293 datapathConfiguration="&{false false false false false }" interface=lxc3fef2db509c4 k8sPodName=local-path-storage/helper-pod-create-pvc-f68b5deb-eef5-40fc-8963-ade945122b61 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=822756866c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=876 ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f68b5deb-eef5-40fc-8963-ade945122b61 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=822756866c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=876 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f68b5deb-eef5-40fc-8963-ade945122b61 subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=822756866c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=876 identity=43487 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f68b5deb-eef5-40fc-8963-ade945122b61 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=822756866c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=876 identity=43487 ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f68b5deb-eef5-40fc-8963-ade945122b61 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=822756866c datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=876 identity=43487 ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f68b5deb-eef5-40fc-8963-ade945122b61 subsys=endpoint level=info msg="Successful endpoint creation" containerID=822756866c datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=876 identity=43487 ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f68b5deb-eef5-40fc-8963-ade945122b61 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.12 28efb5d3-3b4f-43b7-bf8d-006ccdcb20f7 default }" containerID=0d4ed05f03163d9dafc0df83aa82585cdbbb12d3f94148a18092b8c921328ae6 datapathConfiguration="&{false false false false false }" interface=lxccef2693341a9 k8sPodName=local-path-storage/helper-pod-create-pvc-862a7a1e-242d-441e-8f3a-c14ae7af3972 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=0d4ed05f03 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1011 ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-862a7a1e-242d-441e-8f3a-c14ae7af3972 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=0d4ed05f03 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1011 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-862a7a1e-242d-441e-8f3a-c14ae7af3972 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=0d4ed05f03 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1011 identity=43487 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-862a7a1e-242d-441e-8f3a-c14ae7af3972 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=0d4ed05f03 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1011 identity=43487 ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-862a7a1e-242d-441e-8f3a-c14ae7af3972 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=0d4ed05f03 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1011 identity=43487 ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-862a7a1e-242d-441e-8f3a-c14ae7af3972 subsys=endpoint level=info msg="Successful endpoint creation" containerID=0d4ed05f03 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1011 identity=43487 ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-862a7a1e-242d-441e-8f3a-c14ae7af3972 subsys=daemon level=info msg="Delete endpoint request" containerID=822756866c endpointID=876 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-f68b5deb-eef5-40fc-8963-ade945122b61 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=822756866c datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=876 identity=43487 ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f68b5deb-eef5-40fc-8963-ade945122b61 subsys=endpoint level=info msg="Delete endpoint request" containerID=0d4ed05f03 endpointID=1011 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-862a7a1e-242d-441e-8f3a-c14ae7af3972 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=0d4ed05f03 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1011 identity=43487 ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-862a7a1e-242d-441e-8f3a-c14ae7af3972 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.82 8817c145-0173-422c-aad8-88298262d352 default }" containerID=6cf999bffc24fca0ceb3556274b02097c6213d2b76cdd1f64188af8c710399f1 datapathConfiguration="&{false false false false false }" interface=lxc87a2856d0b1c k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=6cf999bffc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1372 ipv4=10.0.0.82 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=6cf999bffc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1372 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.82 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:alertmanager=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=alertmanager;k8s:app.kubernetes.io/version=0.27.0;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager;k8s:io.kubernetes.pod.namespace=monitoring;k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=6cf999bffc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1372 identity=31874 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.82 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=6cf999bffc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1372 identity=31874 ipv4=10.0.0.82 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=6cf999bffc datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1372 identity=31874 ipv4=10.0.0.82 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=6cf999bffc datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1372 identity=31874 ipv4=10.0.0.82 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.103 48fde431-c859-4452-bf2d-34e2191c0c91 default }" containerID=b598896e4c289a454d6d281a2c6396075620835c800df88a8b2c1fb9c79dba4c datapathConfiguration="&{false false false false false }" interface=lxc9d711ca02b25 k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b598896e4c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=99 ipv4=10.0.0.103 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b598896e4c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=99 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.103 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=prometheus;k8s:app.kubernetes.io/version=2.51.2;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus;k8s:io.kubernetes.pod.namespace=monitoring;k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus;k8s:operator.prometheus.io/shard=0;k8s:prometheus=kube-prometheus-stack-prometheus;k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=b598896e4c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=99 identity=50882 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.103 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b598896e4c datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=99 identity=50882 ipv4=10.0.0.103 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=b598896e4c datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=99 identity=50882 ipv4=10.0.0.103 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=b598896e4c datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=99 identity=50882 ipv4=10.0.0.103 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.160 02080530-6fe9-4e93-8e49-34fd7f585c0b default }" containerID=9b61921edb0754305a242b4e6feb661a563625c22e33a613cec7ef84ca971ae5 datapathConfiguration="&{false false false false false }" interface=lxc945e00cbf8d1 k8sPodName=local-path-storage/helper-pod-create-pvc-7443b844-07d9-407a-b718-9e71181e989d labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=9b61921edb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=723 ipv4=10.0.0.160 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7443b844-07d9-407a-b718-9e71181e989d subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=9b61921edb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=723 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.160 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7443b844-07d9-407a-b718-9e71181e989d subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=9b61921edb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=723 identity=43487 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.160 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7443b844-07d9-407a-b718-9e71181e989d oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=9b61921edb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=723 identity=43487 ipv4=10.0.0.160 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7443b844-07d9-407a-b718-9e71181e989d subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=9b61921edb datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=723 identity=43487 ipv4=10.0.0.160 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7443b844-07d9-407a-b718-9e71181e989d subsys=endpoint level=info msg="Successful endpoint creation" containerID=9b61921edb datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=723 identity=43487 ipv4=10.0.0.160 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7443b844-07d9-407a-b718-9e71181e989d subsys=daemon level=info msg="Delete endpoint request" containerID=9b61921edb endpointID=723 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-7443b844-07d9-407a-b718-9e71181e989d subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=9b61921edb datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=723 identity=43487 ipv4=10.0.0.160 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7443b844-07d9-407a-b718-9e71181e989d subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.166 f5084f7d-156d-4d42-b4c0-64a8afbdb93d default }" containerID=3972a7ed590ea14e299cb80e752c5b186061ffddacf394c11ed07df90992e636 datapathConfiguration="&{false false false false false }" interface=lxc5f58db0a537a k8sPodName=openstack/rabbitmq-keystone-server-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=3972a7ed59 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2876 ipv4=10.0.0.166 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=3972a7ed59 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2876 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.166 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq;k8s:app.kubernetes.io/name=rabbitmq-keystone;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=3972a7ed59 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2876 identity=30276 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.166 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=3972a7ed59 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2876 identity=30276 ipv4=10.0.0.166 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=3972a7ed59 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2876 identity=30276 ipv4=10.0.0.166 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=3972a7ed59 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2876 identity=30276 ipv4=10.0.0.166 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.186 b5d53563-2a10-44cf-9ccf-e98190aed8ce default }" containerID=ca4de9156953a13d504dac26d3a43525c69a03b63a66c343035e39ee0b566207 datapathConfiguration="&{false false false false false }" interface=lxc37fcd9243ee3 k8sPodName=openstack/keystone-api-5b5c7bc466-m5fkd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=ca4de91569 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1604 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-api-5b5c7bc466-m5fkd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=ca4de91569 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1604 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-api-5b5c7bc466-m5fkd subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:component=api;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-api;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=ca4de91569 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1604 identity=50680 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-api-5b5c7bc466-m5fkd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=ca4de91569 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1604 identity=50680 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-api-5b5c7bc466-m5fkd subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.251 aab4a9e3-ae4a-444e-941b-3821141c09eb default }" containerID=c240a2281ea7db2796679b23cbbf67bb40e7978b7172b6643f617d80121d0c8d datapathConfiguration="&{false false false false false }" interface=lxc62bf73777d76 k8sPodName=openstack/keystone-credential-setup-4x2tl labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c240a2281e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2110 ipv4=10.0.0.251 ipv6= k8sPodName=openstack/keystone-credential-setup-4x2tl subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c240a2281e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2110 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=4dcd477d-4569-47c8-87d9-37552fa75efa,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=4dcd477d-4569-47c8-87d9-37552fa75efa,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.251 ipv6= k8sPodName=openstack/keystone-credential-setup-4x2tl subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=4dcd477d-4569-47c8-87d9-37552fa75efa;k8s:batch.kubernetes.io/job-name=keystone-credential-setup;k8s:component=credential-setup;k8s:controller-uid=4dcd477d-4569-47c8-87d9-37552fa75efa;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-credential-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=c240a2281e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2110 identity=7706 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=4dcd477d-4569-47c8-87d9-37552fa75efa,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=4dcd477d-4569-47c8-87d9-37552fa75efa,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.251 ipv6= k8sPodName=openstack/keystone-credential-setup-4x2tl oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c240a2281e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2110 identity=7706 ipv4=10.0.0.251 ipv6= k8sPodName=openstack/keystone-credential-setup-4x2tl subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=ca4de91569 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1604 identity=50680 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-api-5b5c7bc466-m5fkd subsys=endpoint level=info msg="Successful endpoint creation" containerID=ca4de91569 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1604 identity=50680 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-api-5b5c7bc466-m5fkd subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=c240a2281e datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2110 identity=7706 ipv4=10.0.0.251 ipv6= k8sPodName=openstack/keystone-credential-setup-4x2tl subsys=endpoint level=info msg="Successful endpoint creation" containerID=c240a2281e datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2110 identity=7706 ipv4=10.0.0.251 ipv6= k8sPodName=openstack/keystone-credential-setup-4x2tl subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=c240a2281e endpointID=2110 k8sNamespace=openstack k8sPodName=keystone-credential-setup-4x2tl subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=4dcd477d-4569-47c8-87d9-37552fa75efa k8s:batch.kubernetes.io/job-name=keystone-credential-setup k8s:component=credential-setup k8s:controller-uid=4dcd477d-4569-47c8-87d9-37552fa75efa k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-credential-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=c240a2281e datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2110 identity=7706 ipv4=10.0.0.251 ipv6= k8sPodName=openstack/keystone-credential-setup-4x2tl subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.75 2853b160-cfa0-45ed-9250-519e574bfe3f default }" containerID=4ce31e69b21492fb3858c86e8b7b0ec611b000e776691aa161fab7c2012d40c5 datapathConfiguration="&{false false false false false }" interface=lxc6ab3bc8fb6bd k8sPodName=openstack/keystone-db-init-wqdfp labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=4ce31e69b2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2692 ipv4=10.0.0.75 ipv6= k8sPodName=openstack/keystone-db-init-wqdfp subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=4ce31e69b2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2692 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=025a9229-93a8-446a-8c64-70e87375d19d,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=025a9229-93a8-446a-8c64-70e87375d19d,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.75 ipv6= k8sPodName=openstack/keystone-db-init-wqdfp subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=025a9229-93a8-446a-8c64-70e87375d19d;k8s:batch.kubernetes.io/job-name=keystone-db-init;k8s:component=db-init;k8s:controller-uid=025a9229-93a8-446a-8c64-70e87375d19d;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-init;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=4ce31e69b2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2692 identity=1029 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=025a9229-93a8-446a-8c64-70e87375d19d,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=025a9229-93a8-446a-8c64-70e87375d19d,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.75 ipv6= k8sPodName=openstack/keystone-db-init-wqdfp oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=4ce31e69b2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2692 identity=1029 ipv4=10.0.0.75 ipv6= k8sPodName=openstack/keystone-db-init-wqdfp subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=4ce31e69b2 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2692 identity=1029 ipv4=10.0.0.75 ipv6= k8sPodName=openstack/keystone-db-init-wqdfp subsys=endpoint level=info msg="Successful endpoint creation" containerID=4ce31e69b2 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2692 identity=1029 ipv4=10.0.0.75 ipv6= k8sPodName=openstack/keystone-db-init-wqdfp subsys=daemon level=info msg="Delete endpoint request" containerID=4ce31e69b2 endpointID=2692 k8sNamespace=openstack k8sPodName=keystone-db-init-wqdfp subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=025a9229-93a8-446a-8c64-70e87375d19d k8s:batch.kubernetes.io/job-name=keystone-db-init k8s:component=db-init k8s:controller-uid=025a9229-93a8-446a-8c64-70e87375d19d k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=4ce31e69b2 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2692 identity=1029 ipv4=10.0.0.75 ipv6= k8sPodName=openstack/keystone-db-init-wqdfp subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.54 f6fc03a1-2a42-4d6d-86ff-b58362a96054 default }" containerID=64954b09eebd65e3b3edb2cbea4c14e9a47068dfbdab42c336b10e98bdd37ed3 datapathConfiguration="&{false false false false false }" interface=lxc18ff862b7320 k8sPodName=openstack/keystone-fernet-setup-h8nnm labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=64954b09ee datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2552 ipv4=10.0.0.54 ipv6= k8sPodName=openstack/keystone-fernet-setup-h8nnm subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=64954b09ee datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2552 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=236b25e6-b896-4b21-a85e-f8f56932eeae,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=236b25e6-b896-4b21-a85e-f8f56932eeae,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.54 ipv6= k8sPodName=openstack/keystone-fernet-setup-h8nnm subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=236b25e6-b896-4b21-a85e-f8f56932eeae;k8s:batch.kubernetes.io/job-name=keystone-fernet-setup;k8s:component=fernet-setup;k8s:controller-uid=236b25e6-b896-4b21-a85e-f8f56932eeae;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-fernet-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=64954b09ee datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2552 identity=38640 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=236b25e6-b896-4b21-a85e-f8f56932eeae,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=236b25e6-b896-4b21-a85e-f8f56932eeae,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.54 ipv6= k8sPodName=openstack/keystone-fernet-setup-h8nnm oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=64954b09ee datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2552 identity=38640 ipv4=10.0.0.54 ipv6= k8sPodName=openstack/keystone-fernet-setup-h8nnm subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=64954b09ee datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2552 identity=38640 ipv4=10.0.0.54 ipv6= k8sPodName=openstack/keystone-fernet-setup-h8nnm subsys=endpoint level=info msg="Successful endpoint creation" containerID=64954b09ee datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2552 identity=38640 ipv4=10.0.0.54 ipv6= k8sPodName=openstack/keystone-fernet-setup-h8nnm subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=64954b09ee endpointID=2552 k8sNamespace=openstack k8sPodName=keystone-fernet-setup-h8nnm subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=236b25e6-b896-4b21-a85e-f8f56932eeae k8s:batch.kubernetes.io/job-name=keystone-fernet-setup k8s:component=fernet-setup k8s:controller-uid=236b25e6-b896-4b21-a85e-f8f56932eeae k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-fernet-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=64954b09ee datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2552 identity=38640 ipv4=10.0.0.54 ipv6= k8sPodName=openstack/keystone-fernet-setup-h8nnm subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.90 976081e0-df88-45b2-b05d-9a5bd48edf13 default }" containerID=1a2b2fec60d4b160f04780b7be6153cecbe102e38b197cd426addf87e80d76fc datapathConfiguration="&{false false false false false }" interface=lxc35c98d85acea k8sPodName=openstack/keystone-db-sync-gkqh7 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=1a2b2fec60 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1595 ipv4=10.0.0.90 ipv6= k8sPodName=openstack/keystone-db-sync-gkqh7 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=1a2b2fec60 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1595 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=8618b1de-d38e-4e22-975d-d6f1ae81f2c4,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=8618b1de-d38e-4e22-975d-d6f1ae81f2c4,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.90 ipv6= k8sPodName=openstack/keystone-db-sync-gkqh7 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=8618b1de-d38e-4e22-975d-d6f1ae81f2c4;k8s:batch.kubernetes.io/job-name=keystone-db-sync;k8s:component=db-sync;k8s:controller-uid=8618b1de-d38e-4e22-975d-d6f1ae81f2c4;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-sync;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=1a2b2fec60 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1595 identity=58322 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=8618b1de-d38e-4e22-975d-d6f1ae81f2c4,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=8618b1de-d38e-4e22-975d-d6f1ae81f2c4,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.90 ipv6= k8sPodName=openstack/keystone-db-sync-gkqh7 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=1a2b2fec60 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1595 identity=58322 ipv4=10.0.0.90 ipv6= k8sPodName=openstack/keystone-db-sync-gkqh7 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=1a2b2fec60 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1595 identity=58322 ipv4=10.0.0.90 ipv6= k8sPodName=openstack/keystone-db-sync-gkqh7 subsys=endpoint level=info msg="Successful endpoint creation" containerID=1a2b2fec60 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1595 identity=58322 ipv4=10.0.0.90 ipv6= k8sPodName=openstack/keystone-db-sync-gkqh7 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=1a2b2fec60 endpointID=1595 k8sNamespace=openstack k8sPodName=keystone-db-sync-gkqh7 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=8618b1de-d38e-4e22-975d-d6f1ae81f2c4 k8s:batch.kubernetes.io/job-name=keystone-db-sync k8s:component=db-sync k8s:controller-uid=8618b1de-d38e-4e22-975d-d6f1ae81f2c4 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-sync k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=1a2b2fec60 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1595 identity=58322 ipv4=10.0.0.90 ipv6= k8sPodName=openstack/keystone-db-sync-gkqh7 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.205 9bcb98c5-1f5b-4ea6-8d5d-ccd02629de62 default }" containerID=b119292ae4b5945d5b7423adc73dff01fc5fc417401f4b533c74dc2db905e2e7 datapathConfiguration="&{false false false false false }" interface=lxc61fb8177459d k8sPodName=openstack/keystone-rabbit-init-52qgd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b119292ae4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=516 ipv4=10.0.0.205 ipv6= k8sPodName=openstack/keystone-rabbit-init-52qgd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b119292ae4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=516 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=523fd1c0-2912-4015-972b-56455632e465,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=523fd1c0-2912-4015-972b-56455632e465,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.205 ipv6= k8sPodName=openstack/keystone-rabbit-init-52qgd subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=523fd1c0-2912-4015-972b-56455632e465;k8s:batch.kubernetes.io/job-name=keystone-rabbit-init;k8s:component=rabbit-init;k8s:controller-uid=523fd1c0-2912-4015-972b-56455632e465;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-rabbit-init;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=b119292ae4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=516 identity=31412 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=523fd1c0-2912-4015-972b-56455632e465,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=523fd1c0-2912-4015-972b-56455632e465,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.205 ipv6= k8sPodName=openstack/keystone-rabbit-init-52qgd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b119292ae4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=516 identity=31412 ipv4=10.0.0.205 ipv6= k8sPodName=openstack/keystone-rabbit-init-52qgd subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=b119292ae4 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=516 identity=31412 ipv4=10.0.0.205 ipv6= k8sPodName=openstack/keystone-rabbit-init-52qgd subsys=endpoint level=info msg="Successful endpoint creation" containerID=b119292ae4 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=516 identity=31412 ipv4=10.0.0.205 ipv6= k8sPodName=openstack/keystone-rabbit-init-52qgd subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=b119292ae4 endpointID=516 k8sNamespace=openstack k8sPodName=keystone-rabbit-init-52qgd subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=523fd1c0-2912-4015-972b-56455632e465 k8s:batch.kubernetes.io/job-name=keystone-rabbit-init k8s:component=rabbit-init k8s:controller-uid=523fd1c0-2912-4015-972b-56455632e465 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-rabbit-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=b119292ae4 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=516 identity=31412 ipv4=10.0.0.205 ipv6= k8sPodName=openstack/keystone-rabbit-init-52qgd subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.200 731d8402-5ad4-46eb-8e27-7738498ff9c3 default }" containerID=cdee62467031830162e7e7b66e8c2c4e55a92b79c829f61095ddf474ae30f0d3 datapathConfiguration="&{false false false false false }" interface=lxc73be61268063 k8sPodName=openstack/keystone-domain-manage-gf6nk labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=cdee624670 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1149 ipv4=10.0.0.200 ipv6= k8sPodName=openstack/keystone-domain-manage-gf6nk subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=cdee624670 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1149 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=26cccaf2-5dec-4ca8-b250-21a9fc0f559c,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=26cccaf2-5dec-4ca8-b250-21a9fc0f559c,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.200 ipv6= k8sPodName=openstack/keystone-domain-manage-gf6nk subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=cdee624670 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1149 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.200 ipv6= k8sPodName=openstack/keystone-domain-manage-gf6nk line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=26cccaf2-5dec-4ca8-b250-21a9fc0f559c;k8s:batch.kubernetes.io/job-name=keystone-domain-manage;k8s:component=domain-manage;k8s:controller-uid=26cccaf2-5dec-4ca8-b250-21a9fc0f559c;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-domain-manage;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=cdee624670 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1149 identity=14023 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=26cccaf2-5dec-4ca8-b250-21a9fc0f559c,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=26cccaf2-5dec-4ca8-b250-21a9fc0f559c,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.200 ipv6= k8sPodName=openstack/keystone-domain-manage-gf6nk oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=cdee624670 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1149 identity=14023 ipv4=10.0.0.200 ipv6= k8sPodName=openstack/keystone-domain-manage-gf6nk subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=cdee624670 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1149 identity=14023 ipv4=10.0.0.200 ipv6= k8sPodName=openstack/keystone-domain-manage-gf6nk subsys=endpoint level=info msg="Successful endpoint creation" containerID=cdee624670 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1149 identity=14023 ipv4=10.0.0.200 ipv6= k8sPodName=openstack/keystone-domain-manage-gf6nk subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=cdee624670 endpointID=1149 k8sNamespace=openstack k8sPodName=keystone-domain-manage-gf6nk subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=26cccaf2-5dec-4ca8-b250-21a9fc0f559c k8s:batch.kubernetes.io/job-name=keystone-domain-manage k8s:component=domain-manage k8s:controller-uid=26cccaf2-5dec-4ca8-b250-21a9fc0f559c k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-domain-manage k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=cdee624670 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1149 identity=14023 ipv4=10.0.0.200 ipv6= k8sPodName=openstack/keystone-domain-manage-gf6nk subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.68 9266beab-10c0-48d2-8072-281f79f2d358 default }" containerID=9efb3456c12282c13a0e57cd0e69f403a576b02fd63a7db0b3b8e2d23eeb98a1 datapathConfiguration="&{false false false false false }" interface=lxc990226e45cac k8sPodName=openstack/keystone-bootstrap-6wfv8 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=9efb3456c1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=274 ipv4=10.0.0.68 ipv6= k8sPodName=openstack/keystone-bootstrap-6wfv8 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=9efb3456c1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=274 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=139997a3-2045-4a59-af61-08337568dc79,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=139997a3-2045-4a59-af61-08337568dc79,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.68 ipv6= k8sPodName=openstack/keystone-bootstrap-6wfv8 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=139997a3-2045-4a59-af61-08337568dc79;k8s:batch.kubernetes.io/job-name=keystone-bootstrap;k8s:component=bootstrap;k8s:controller-uid=139997a3-2045-4a59-af61-08337568dc79;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-bootstrap;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=9efb3456c1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=274 identity=41357 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=139997a3-2045-4a59-af61-08337568dc79,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=139997a3-2045-4a59-af61-08337568dc79,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.68 ipv6= k8sPodName=openstack/keystone-bootstrap-6wfv8 oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=9efb3456c1 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=274 identity=41357 ipv4=10.0.0.68 ipv6= k8sPodName=openstack/keystone-bootstrap-6wfv8 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=9efb3456c1 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=274 identity=41357 ipv4=10.0.0.68 ipv6= k8sPodName=openstack/keystone-bootstrap-6wfv8 subsys=endpoint level=info msg="Successful endpoint creation" containerID=9efb3456c1 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=274 identity=41357 ipv4=10.0.0.68 ipv6= k8sPodName=openstack/keystone-bootstrap-6wfv8 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=9efb3456c1 endpointID=274 k8sNamespace=openstack k8sPodName=keystone-bootstrap-6wfv8 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=139997a3-2045-4a59-af61-08337568dc79 k8s:batch.kubernetes.io/job-name=keystone-bootstrap k8s:component=bootstrap k8s:controller-uid=139997a3-2045-4a59-af61-08337568dc79 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-bootstrap k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=9efb3456c1 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=274 identity=41357 ipv4=10.0.0.68 ipv6= k8sPodName=openstack/keystone-bootstrap-6wfv8 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.48 e702a1ad-4f9b-4c26-98a4-f5e14ca0584a default }" containerID=5106d70b21604ecadb50e94705dac2fb76a98cba0220c3644b32040bb083cf78 datapathConfiguration="&{false false false false false }" interface=lxc0e104e4b1b64 k8sPodName=openstack/horizon-66986fc785-vlr78 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=5106d70b21 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2639 ipv4=10.0.0.48 ipv6= k8sPodName=openstack/horizon-66986fc785-vlr78 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=5106d70b21 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2639 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.48 ipv6= k8sPodName=openstack/horizon-66986fc785-vlr78 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=5106d70b21 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2639 identity=30126 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.48 ipv6= k8sPodName=openstack/horizon-66986fc785-vlr78 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=5106d70b21 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2639 identity=30126 ipv4=10.0.0.48 ipv6= k8sPodName=openstack/horizon-66986fc785-vlr78 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.158 6a0e539f-3787-4791-83d6-2bc35e86bd03 default }" containerID=1eec6f8a56f8a169526df9bd1cdb1e51af01671886cb1dc9727587b3d932caa1 datapathConfiguration="&{false false false false false }" interface=lxc119209dd2269 k8sPodName=openstack/horizon-66986fc785-kh8c2 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=1eec6f8a56 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=793 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-66986fc785-kh8c2 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=1eec6f8a56 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=793 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-66986fc785-kh8c2 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=1eec6f8a56 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=793 identity=30126 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-66986fc785-kh8c2 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=1eec6f8a56 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=793 identity=30126 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-66986fc785-kh8c2 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=5106d70b21 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2639 identity=30126 ipv4=10.0.0.48 ipv6= k8sPodName=openstack/horizon-66986fc785-vlr78 subsys=endpoint level=info msg="Successful endpoint creation" containerID=5106d70b21 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2639 identity=30126 ipv4=10.0.0.48 ipv6= k8sPodName=openstack/horizon-66986fc785-vlr78 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.8 a99e04ba-9434-48c4-aac0-608bb4b6ade7 default }" containerID=0347fdf910d53db670e8e28daa6a9ccde8d98fd02e80742aa7a5fd94bb236ea8 datapathConfiguration="&{false false false false false }" interface=lxc43305cdd4e5e k8sPodName=openstack/horizon-db-init-85jfd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=0347fdf910 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2299 ipv4=10.0.0.8 ipv6= k8sPodName=openstack/horizon-db-init-85jfd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=0347fdf910 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2299 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=5a88ef6b-15a5-4a0f-a63a-772d75a0b9b9,k8s:batch.kubernetes.io/job-name=horizon-db-init,k8s:component=db-init,k8s:controller-uid=5a88ef6b-15a5-4a0f-a63a-772d75a0b9b9,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-init,k8s:release_group=horizon" ipv4=10.0.0.8 ipv6= k8sPodName=openstack/horizon-db-init-85jfd subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:batch.kubernetes.io/controller-uid=5a88ef6b-15a5-4a0f-a63a-772d75a0b9b9;k8s:batch.kubernetes.io/job-name=horizon-db-init;k8s:component=db-init;k8s:controller-uid=5a88ef6b-15a5-4a0f-a63a-772d75a0b9b9;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=horizon-db-init;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=0347fdf910 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2299 identity=15882 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=5a88ef6b-15a5-4a0f-a63a-772d75a0b9b9,k8s:batch.kubernetes.io/job-name=horizon-db-init,k8s:component=db-init,k8s:controller-uid=5a88ef6b-15a5-4a0f-a63a-772d75a0b9b9,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-init,k8s:release_group=horizon" ipv4=10.0.0.8 ipv6= k8sPodName=openstack/horizon-db-init-85jfd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=0347fdf910 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2299 identity=15882 ipv4=10.0.0.8 ipv6= k8sPodName=openstack/horizon-db-init-85jfd subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.14 7efb1003-cddc-4141-b94c-1375e64a8ed1 default }" containerID=1453c663aeb575c5be47a8e7bcd42bfc777ad366c9c68f68aadb50ed6c234a69 datapathConfiguration="&{false false false false false }" interface=lxc13b67ca21015 k8sPodName=openstack/horizon-66986fc785-mssx2 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=1453c663ae datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3771 ipv4=10.0.0.14 ipv6= k8sPodName=openstack/horizon-66986fc785-mssx2 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=1453c663ae datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3771 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.14 ipv6= k8sPodName=openstack/horizon-66986fc785-mssx2 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=1453c663ae datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3771 identity=30126 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.14 ipv6= k8sPodName=openstack/horizon-66986fc785-mssx2 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=1453c663ae datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3771 identity=30126 ipv4=10.0.0.14 ipv6= k8sPodName=openstack/horizon-66986fc785-mssx2 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=1eec6f8a56 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=793 identity=30126 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-66986fc785-kh8c2 subsys=endpoint level=info msg="Successful endpoint creation" containerID=1eec6f8a56 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=793 identity=30126 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-66986fc785-kh8c2 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=0347fdf910 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2299 identity=15882 ipv4=10.0.0.8 ipv6= k8sPodName=openstack/horizon-db-init-85jfd subsys=endpoint level=info msg="Successful endpoint creation" containerID=0347fdf910 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2299 identity=15882 ipv4=10.0.0.8 ipv6= k8sPodName=openstack/horizon-db-init-85jfd subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=1453c663ae datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3771 identity=30126 ipv4=10.0.0.14 ipv6= k8sPodName=openstack/horizon-66986fc785-mssx2 subsys=endpoint level=info msg="Successful endpoint creation" containerID=1453c663ae datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3771 identity=30126 ipv4=10.0.0.14 ipv6= k8sPodName=openstack/horizon-66986fc785-mssx2 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=0347fdf910 endpointID=2299 k8sNamespace=openstack k8sPodName=horizon-db-init-85jfd subsys=daemon level=info msg="Releasing key" key="[k8s:application=horizon k8s:batch.kubernetes.io/controller-uid=5a88ef6b-15a5-4a0f-a63a-772d75a0b9b9 k8s:batch.kubernetes.io/job-name=horizon-db-init k8s:component=db-init k8s:controller-uid=5a88ef6b-15a5-4a0f-a63a-772d75a0b9b9 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=horizon-db-init k8s:release_group=horizon]" subsys=allocator level=info msg="Removed endpoint" containerID=0347fdf910 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2299 identity=15882 ipv4=10.0.0.8 ipv6= k8sPodName=openstack/horizon-db-init-85jfd subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.24 1ad70e7f-cd62-490c-aa38-af7def3c5bc0 default }" containerID=fb903b5d15d37a4784ee3dbe4a0b8255b5f90c75bdfb6afdd829b96fda58aab4 datapathConfiguration="&{false false false false false }" interface=lxc111ea616c5b7 k8sPodName=openstack/horizon-db-sync-lhnb8 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=fb903b5d15 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=780 ipv4=10.0.0.24 ipv6= k8sPodName=openstack/horizon-db-sync-lhnb8 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=fb903b5d15 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=780 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=b7c1c195-f405-4971-95f0-ab325db32f05,k8s:batch.kubernetes.io/job-name=horizon-db-sync,k8s:component=db-sync,k8s:controller-uid=b7c1c195-f405-4971-95f0-ab325db32f05,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-sync,k8s:release_group=horizon" ipv4=10.0.0.24 ipv6= k8sPodName=openstack/horizon-db-sync-lhnb8 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:batch.kubernetes.io/controller-uid=b7c1c195-f405-4971-95f0-ab325db32f05;k8s:batch.kubernetes.io/job-name=horizon-db-sync;k8s:component=db-sync;k8s:controller-uid=b7c1c195-f405-4971-95f0-ab325db32f05;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=horizon-db-sync;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=fb903b5d15 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=780 identity=40899 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=b7c1c195-f405-4971-95f0-ab325db32f05,k8s:batch.kubernetes.io/job-name=horizon-db-sync,k8s:component=db-sync,k8s:controller-uid=b7c1c195-f405-4971-95f0-ab325db32f05,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-sync,k8s:release_group=horizon" ipv4=10.0.0.24 ipv6= k8sPodName=openstack/horizon-db-sync-lhnb8 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=fb903b5d15 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=780 identity=40899 ipv4=10.0.0.24 ipv6= k8sPodName=openstack/horizon-db-sync-lhnb8 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=fb903b5d15 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=780 identity=40899 ipv4=10.0.0.24 ipv6= k8sPodName=openstack/horizon-db-sync-lhnb8 subsys=endpoint level=info msg="Successful endpoint creation" containerID=fb903b5d15 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=780 identity=40899 ipv4=10.0.0.24 ipv6= k8sPodName=openstack/horizon-db-sync-lhnb8 subsys=daemon level=info msg="Delete endpoint request" containerID=fb903b5d15 endpointID=780 k8sNamespace=openstack k8sPodName=horizon-db-sync-lhnb8 subsys=daemon level=info msg="Releasing key" key="[k8s:application=horizon k8s:batch.kubernetes.io/controller-uid=b7c1c195-f405-4971-95f0-ab325db32f05 k8s:batch.kubernetes.io/job-name=horizon-db-sync k8s:component=db-sync k8s:controller-uid=b7c1c195-f405-4971-95f0-ab325db32f05 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=horizon-db-sync k8s:release_group=horizon]" subsys=allocator level=info msg="Removed endpoint" containerID=fb903b5d15 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=780 identity=40899 ipv4=10.0.0.24 ipv6= k8sPodName=openstack/horizon-db-sync-lhnb8 subsys=endpoint