level=info msg="Memory available for map entries (0.003% of 16764968960B): 41912422B" subsys=config level=info msg="option bpf-ct-global-tcp-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-ct-global-any-max set by dynamic sizing to 73530" subsys=config level=info msg="option bpf-nat-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-neigh-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-sock-rev-map-max set by dynamic sizing to 73530" subsys=config level=info msg=" --agent-health-port='9879'" subsys=daemon level=info msg=" --agent-labels=''" subsys=daemon level=info msg=" --agent-liveness-update-interval='1s'" subsys=daemon level=info msg=" --agent-not-ready-taint-key='node.cilium.io/agent-not-ready'" subsys=daemon level=info msg=" --allocator-list-timeout='3m0s'" subsys=daemon level=info msg=" --allow-icmp-frag-needed='true'" subsys=daemon level=info msg=" --allow-localhost='auto'" subsys=daemon level=info msg=" --annotate-k8s-node='false'" subsys=daemon level=info msg=" --api-rate-limit=''" subsys=daemon level=info msg=" --arping-refresh-period='30s'" subsys=daemon level=info msg=" --auto-create-cilium-node-resource='true'" subsys=daemon level=info msg=" --auto-direct-node-routes='false'" subsys=daemon level=info msg=" --bgp-announce-lb-ip='false'" subsys=daemon level=info msg=" --bgp-announce-pod-cidr='false'" subsys=daemon level=info msg=" --bgp-config-path='/var/lib/cilium/bgp/config.yaml'" subsys=daemon level=info msg=" --bpf-auth-map-max='524288'" subsys=daemon level=info msg=" --bpf-ct-global-any-max='262144'" subsys=daemon level=info msg=" --bpf-ct-global-tcp-max='524288'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-fin='10s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-syn='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp-grace='1m0s'" subsys=daemon level=info msg=" --bpf-filter-priority='1'" subsys=daemon level=info msg=" --bpf-fragments-map-max='8192'" subsys=daemon level=info msg=" --bpf-lb-acceleration='disabled'" subsys=daemon level=info msg=" --bpf-lb-affinity-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-algorithm='random'" subsys=daemon level=info msg=" --bpf-lb-dev-ip-addr-inherit=''" subsys=daemon level=info msg=" --bpf-lb-dsr-dispatch='opt'" subsys=daemon level=info msg=" --bpf-lb-dsr-l4-xlate='frontend'" subsys=daemon level=info msg=" --bpf-lb-external-clusterip='false'" subsys=daemon level=info msg=" --bpf-lb-maglev-hash-seed='JLfvgnHc2kaSUFaI'" subsys=daemon level=info msg=" --bpf-lb-maglev-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-maglev-table-size='16381'" subsys=daemon level=info msg=" --bpf-lb-map-max='65536'" subsys=daemon level=info msg=" --bpf-lb-mode='snat'" subsys=daemon level=info msg=" --bpf-lb-rev-nat-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-rss-ipv4-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-rss-ipv6-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-service-backend-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-service-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-sock='false'" subsys=daemon level=info msg=" --bpf-lb-sock-hostns-only='false'" subsys=daemon level=info msg=" --bpf-lb-source-range-map-max='0'" subsys=daemon level=info msg=" --bpf-map-dynamic-size-ratio='0.0025'" subsys=daemon level=info msg=" --bpf-map-event-buffers=''" subsys=daemon level=info msg=" --bpf-nat-global-max='524288'" subsys=daemon level=info msg=" --bpf-neigh-global-max='524288'" subsys=daemon level=info msg=" --bpf-policy-map-full-reconciliation-interval='15m0s'" subsys=daemon level=info msg=" --bpf-policy-map-max='16384'" subsys=daemon level=info msg=" --bpf-root='/sys/fs/bpf'" subsys=daemon level=info msg=" --bpf-sock-rev-map-max='262144'" subsys=daemon level=info msg=" --bypass-ip-availability-upon-restore='false'" subsys=daemon level=info msg=" --certificates-directory='/var/run/cilium/certs'" subsys=daemon level=info msg=" --cflags=''" subsys=daemon level=info msg=" --cgroup-root='/run/cilium/cgroupv2'" subsys=daemon level=info msg=" --cilium-endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --cluster-health-port='4240'" subsys=daemon level=info msg=" --cluster-id='0'" subsys=daemon level=info msg=" --cluster-name='default'" subsys=daemon level=info msg=" --cluster-pool-ipv4-cidr='10.0.0.0/8'" subsys=daemon level=info msg=" --cluster-pool-ipv4-mask-size='24'" subsys=daemon level=info msg=" --clustermesh-config='/var/lib/cilium/clustermesh/'" subsys=daemon level=info msg=" --clustermesh-ip-identities-sync-timeout='1m0s'" subsys=daemon level=info msg=" --cmdref=''" subsys=daemon level=info msg=" --cni-chaining-mode='none'" subsys=daemon level=info msg=" --cni-chaining-target=''" subsys=daemon level=info msg=" --cni-exclusive='true'" subsys=daemon level=info msg=" --cni-external-routing='false'" subsys=daemon level=info msg=" --cni-log-file='/var/run/cilium/cilium-cni.log'" subsys=daemon level=info msg=" --cnp-node-status-gc-interval='0s'" subsys=daemon level=info msg=" --config=''" subsys=daemon level=info msg=" --config-dir='/tmp/cilium/config-map'" subsys=daemon level=info msg=" --config-sources='config-map:kube-system/cilium-config'" subsys=daemon level=info msg=" --conntrack-gc-interval='0s'" subsys=daemon level=info msg=" --conntrack-gc-max-interval='0s'" subsys=daemon level=info msg=" --crd-wait-timeout='5m0s'" subsys=daemon level=info msg=" --custom-cni-conf='false'" subsys=daemon level=info msg=" --datapath-mode='veth'" subsys=daemon level=info msg=" --debug='false'" subsys=daemon level=info msg=" --debug-verbose=''" subsys=daemon level=info msg=" --derive-masquerade-ip-addr-from-device=''" subsys=daemon level=info msg=" --devices=''" subsys=daemon level=info msg=" --direct-routing-device=''" subsys=daemon level=info msg=" --disable-cnp-status-updates='true'" subsys=daemon level=info msg=" --disable-endpoint-crd='false'" subsys=daemon level=info msg=" --disable-envoy-version-check='false'" subsys=daemon level=info msg=" --disable-iptables-feeder-rules=''" subsys=daemon level=info msg=" --dns-max-ips-per-restored-rule='1000'" subsys=daemon level=info msg=" --dns-policy-unload-on-shutdown='false'" subsys=daemon level=info msg=" --dnsproxy-concurrency-limit='0'" subsys=daemon level=info msg=" --dnsproxy-concurrency-processing-grace-period='0s'" subsys=daemon level=info msg=" --dnsproxy-enable-transparent-mode='true'" subsys=daemon level=info msg=" --dnsproxy-lock-count='128'" subsys=daemon level=info msg=" --dnsproxy-lock-timeout='500ms'" subsys=daemon level=info msg=" --egress-gateway-policy-map-max='16384'" subsys=daemon level=info msg=" --egress-gateway-reconciliation-trigger-interval='1s'" subsys=daemon level=info msg=" --egress-masquerade-interfaces=''" subsys=daemon level=info msg=" --egress-multi-home-ip-rule-compat='false'" subsys=daemon level=info msg=" --enable-auto-protect-node-port-range='true'" subsys=daemon level=info msg=" --enable-bandwidth-manager='false'" subsys=daemon level=info msg=" --enable-bbr='false'" subsys=daemon level=info msg=" --enable-bgp-control-plane='false'" subsys=daemon level=info msg=" --enable-bpf-clock-probe='false'" subsys=daemon level=info msg=" --enable-bpf-masquerade='false'" subsys=daemon level=info msg=" --enable-bpf-tproxy='false'" subsys=daemon level=info msg=" --enable-cilium-api-server-access='*'" subsys=daemon level=info msg=" --enable-cilium-endpoint-slice='false'" subsys=daemon level=info msg=" --enable-cilium-health-api-server-access='*'" subsys=daemon level=info msg=" --enable-custom-calls='false'" subsys=daemon level=info msg=" --enable-endpoint-health-checking='true'" subsys=daemon level=info msg=" --enable-endpoint-routes='false'" subsys=daemon level=info msg=" --enable-envoy-config='false'" subsys=daemon level=info msg=" --enable-external-ips='false'" subsys=daemon level=info msg=" --enable-health-check-nodeport='true'" subsys=daemon level=info msg=" --enable-health-checking='true'" subsys=daemon level=info msg=" --enable-high-scale-ipcache='false'" subsys=daemon level=info msg=" --enable-host-firewall='false'" subsys=daemon level=info msg=" --enable-host-legacy-routing='false'" subsys=daemon level=info msg=" --enable-host-port='false'" subsys=daemon level=info msg=" --enable-hubble='false'" subsys=daemon level=info msg=" --enable-hubble-recorder-api='true'" subsys=daemon level=info msg=" --enable-icmp-rules='true'" subsys=daemon level=info msg=" --enable-identity-mark='true'" subsys=daemon level=info msg=" --enable-ip-masq-agent='false'" subsys=daemon level=info msg=" --enable-ipsec='false'" subsys=daemon level=info msg=" --enable-ipsec-key-watcher='true'" subsys=daemon level=info msg=" --enable-ipv4='true'" subsys=daemon level=info msg=" --enable-ipv4-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv4-egress-gateway='false'" subsys=daemon level=info msg=" --enable-ipv4-fragment-tracking='true'" subsys=daemon level=info msg=" --enable-ipv4-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6='false'" subsys=daemon level=info msg=" --enable-ipv6-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv6-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6-ndp='false'" subsys=daemon level=info msg=" --enable-k8s='true'" subsys=daemon level=info msg=" --enable-k8s-api-discovery='false'" subsys=daemon level=info msg=" --enable-k8s-endpoint-slice='true'" subsys=daemon level=info msg=" --enable-k8s-event-handover='false'" subsys=daemon level=info msg=" --enable-k8s-networkpolicy='true'" subsys=daemon level=info msg=" --enable-k8s-terminating-endpoint='true'" subsys=daemon level=info msg=" --enable-l2-announcements='false'" subsys=daemon level=info msg=" --enable-l2-neigh-discovery='true'" subsys=daemon level=info msg=" --enable-l2-pod-announcements='false'" subsys=daemon level=info msg=" --enable-l7-proxy='true'" subsys=daemon level=info msg=" --enable-local-node-route='true'" subsys=daemon level=info msg=" --enable-local-redirect-policy='false'" subsys=daemon level=info msg=" --enable-mke='false'" subsys=daemon level=info msg=" --enable-monitor='true'" subsys=daemon level=info msg=" --enable-nat46x64-gateway='false'" subsys=daemon level=info msg=" --enable-node-port='false'" subsys=daemon level=info msg=" --enable-pmtu-discovery='false'" subsys=daemon level=info msg=" --enable-policy='default'" subsys=daemon level=info msg=" --enable-recorder='false'" subsys=daemon level=info msg=" --enable-remote-node-identity='true'" subsys=daemon level=info msg=" --enable-runtime-device-detection='false'" subsys=daemon level=info msg=" --enable-sctp='false'" subsys=daemon level=info msg=" --enable-service-topology='false'" subsys=daemon level=info msg=" --enable-session-affinity='false'" subsys=daemon level=info msg=" --enable-srv6='false'" subsys=daemon level=info msg=" --enable-stale-cilium-endpoint-cleanup='true'" subsys=daemon level=info msg=" --enable-svc-source-range-check='true'" subsys=daemon level=info msg=" --enable-tracing='false'" subsys=daemon level=info msg=" --enable-unreachable-routes='false'" subsys=daemon level=info msg=" --enable-vtep='false'" subsys=daemon level=info msg=" --enable-well-known-identities='false'" subsys=daemon level=info msg=" --enable-wireguard='false'" subsys=daemon level=info msg=" --enable-wireguard-userspace-fallback='false'" subsys=daemon level=info msg=" --enable-xdp-prefilter='false'" subsys=daemon level=info msg=" --enable-xt-socket-fallback='true'" subsys=daemon level=info msg=" --encrypt-interface=''" subsys=daemon level=info msg=" --encrypt-node='false'" subsys=daemon level=info msg=" --endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --endpoint-queue-size='25'" subsys=daemon level=info msg=" --endpoint-status=''" subsys=daemon level=info msg=" --envoy-config-timeout='2m0s'" subsys=daemon level=info msg=" --envoy-log=''" subsys=daemon level=info msg=" --exclude-local-address=''" subsys=daemon level=info msg=" --external-envoy-proxy='false'" subsys=daemon level=info msg=" --fixed-identity-mapping=''" subsys=daemon level=info msg=" --fqdn-regex-compile-lru-size='1024'" subsys=daemon level=info msg=" --gops-port='9890'" subsys=daemon level=info msg=" --http-403-msg=''" subsys=daemon level=info msg=" --http-idle-timeout='0'" subsys=daemon level=info msg=" --http-max-grpc-timeout='0'" subsys=daemon level=info msg=" --http-normalize-path='true'" subsys=daemon level=info msg=" --http-request-timeout='3600'" subsys=daemon level=info msg=" --http-retry-count='3'" subsys=daemon level=info msg=" --http-retry-timeout='0'" subsys=daemon level=info msg=" --hubble-disable-tls='false'" subsys=daemon level=info msg=" --hubble-event-buffer-capacity='4095'" subsys=daemon level=info msg=" --hubble-event-queue-size='0'" subsys=daemon level=info msg=" --hubble-export-file-compress='false'" subsys=daemon level=info msg=" --hubble-export-file-max-backups='5'" subsys=daemon level=info msg=" --hubble-export-file-max-size-mb='10'" subsys=daemon level=info msg=" --hubble-export-file-path=''" subsys=daemon level=info msg=" --hubble-listen-address=''" subsys=daemon level=info msg=" --hubble-metrics=''" subsys=daemon level=info msg=" --hubble-metrics-server=''" subsys=daemon level=info msg=" --hubble-monitor-events=''" subsys=daemon level=info msg=" --hubble-prefer-ipv6='false'" subsys=daemon level=info msg=" --hubble-recorder-sink-queue-size='1024'" subsys=daemon level=info msg=" --hubble-recorder-storage-path='/var/run/cilium/pcaps'" subsys=daemon level=info msg=" --hubble-skip-unknown-cgroup-ids='true'" subsys=daemon level=info msg=" --hubble-socket-path='/var/run/cilium/hubble.sock'" subsys=daemon level=info msg=" --hubble-tls-cert-file=''" subsys=daemon level=info msg=" --hubble-tls-client-ca-files=''" subsys=daemon level=info msg=" --hubble-tls-key-file=''" subsys=daemon level=info msg=" --identity-allocation-mode='crd'" subsys=daemon level=info msg=" --identity-change-grace-period='5s'" subsys=daemon level=info msg=" --identity-gc-interval='15m0s'" subsys=daemon level=info msg=" --identity-heartbeat-timeout='30m0s'" subsys=daemon level=info msg=" --identity-restore-grace-period='10m0s'" subsys=daemon level=info msg=" --install-egress-gateway-routes='false'" subsys=daemon level=info msg=" --install-iptables-rules='true'" subsys=daemon level=info msg=" --install-no-conntrack-iptables-rules='false'" subsys=daemon level=info msg=" --ip-allocation-timeout='2m0s'" subsys=daemon level=info msg=" --ip-masq-agent-config-path='/etc/config/ip-masq-agent'" subsys=daemon level=info msg=" --ipam='cluster-pool'" subsys=daemon level=info msg=" --ipam-cilium-node-update-rate='15s'" subsys=daemon level=info msg=" --ipam-multi-pool-pre-allocation='default=8'" subsys=daemon level=info msg=" --ipsec-key-file=''" subsys=daemon level=info msg=" --ipsec-key-rotation-duration='5m0s'" subsys=daemon level=info msg=" --iptables-lock-timeout='5s'" subsys=daemon level=info msg=" --iptables-random-fully='false'" subsys=daemon level=info msg=" --ipv4-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv4-node='auto'" subsys=daemon level=info msg=" --ipv4-pod-subnets=''" subsys=daemon level=info msg=" --ipv4-range='auto'" subsys=daemon level=info msg=" --ipv4-service-loopback-address='169.254.42.1'" subsys=daemon level=info msg=" --ipv4-service-range='auto'" subsys=daemon level=info msg=" --ipv6-cluster-alloc-cidr='f00d::/64'" subsys=daemon level=info msg=" --ipv6-mcast-device=''" subsys=daemon level=info msg=" --ipv6-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv6-node='auto'" subsys=daemon level=info msg=" --ipv6-pod-subnets=''" subsys=daemon level=info msg=" --ipv6-range='auto'" subsys=daemon level=info msg=" --ipv6-service-range='auto'" subsys=daemon level=info msg=" --join-cluster='false'" subsys=daemon level=info msg=" --k8s-api-server=''" subsys=daemon level=info msg=" --k8s-client-burst='10'" subsys=daemon level=info msg=" --k8s-client-qps='5'" subsys=daemon level=info msg=" --k8s-heartbeat-timeout='30s'" subsys=daemon level=info msg=" --k8s-kubeconfig-path=''" subsys=daemon level=info msg=" --k8s-namespace='kube-system'" subsys=daemon level=info msg=" --k8s-require-ipv4-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-require-ipv6-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-service-cache-size='128'" subsys=daemon level=info msg=" --k8s-service-proxy-name=''" subsys=daemon level=info msg=" --k8s-sync-timeout='3m0s'" subsys=daemon level=info msg=" --k8s-watcher-endpoint-selector='metadata.name!=kube-scheduler,metadata.name!=kube-controller-manager,metadata.name!=etcd-operator,metadata.name!=gcp-controller-manager'" subsys=daemon level=info msg=" --keep-config='false'" subsys=daemon level=info msg=" --kube-proxy-replacement='disabled'" subsys=daemon level=info msg=" --kube-proxy-replacement-healthz-bind-address=''" subsys=daemon level=info msg=" --kvstore=''" subsys=daemon level=info msg=" --kvstore-connectivity-timeout='2m0s'" subsys=daemon level=info msg=" --kvstore-lease-ttl='15m0s'" subsys=daemon level=info msg=" --kvstore-max-consecutive-quorum-errors='2'" subsys=daemon level=info msg=" --kvstore-opt=''" subsys=daemon level=info msg=" --kvstore-periodic-sync='5m0s'" subsys=daemon level=info msg=" --l2-announcements-lease-duration='15s'" subsys=daemon level=info msg=" --l2-announcements-renew-deadline='5s'" subsys=daemon level=info msg=" --l2-announcements-retry-period='2s'" subsys=daemon level=info msg=" --l2-pod-announcements-interface=''" subsys=daemon level=info msg=" --label-prefix-file=''" subsys=daemon level=info msg=" --labels=''" subsys=daemon level=info msg=" --lib-dir='/var/lib/cilium'" subsys=daemon level=info msg=" --local-max-addr-scope='252'" subsys=daemon level=info msg=" --local-router-ipv4=''" subsys=daemon level=info msg=" --local-router-ipv6=''" subsys=daemon level=info msg=" --log-driver=''" subsys=daemon level=info msg=" --log-opt=''" subsys=daemon level=info msg=" --log-system-load='false'" subsys=daemon level=info msg=" --max-controller-interval='0'" subsys=daemon level=info msg=" --mesh-auth-enabled='true'" subsys=daemon level=info msg=" --mesh-auth-gc-interval='5m0s'" subsys=daemon level=info msg=" --mesh-auth-mutual-listener-port='0'" subsys=daemon level=info msg=" --mesh-auth-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-rotated-identities-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-signal-backoff-duration='1s'" subsys=daemon level=info msg=" --mesh-auth-spiffe-trust-domain='spiffe.cilium'" subsys=daemon level=info msg=" --mesh-auth-spire-admin-socket=''" subsys=daemon level=info msg=" --metrics=''" subsys=daemon level=info msg=" --mke-cgroup-mount=''" subsys=daemon level=info msg=" --monitor-aggregation='medium'" subsys=daemon level=info msg=" --monitor-aggregation-flags='all'" subsys=daemon level=info msg=" --monitor-aggregation-interval='5s'" subsys=daemon level=info msg=" --monitor-queue-size='0'" subsys=daemon level=info msg=" --mtu='0'" subsys=daemon level=info msg=" --node-encryption-opt-out-labels='node-role.kubernetes.io/control-plane'" subsys=daemon level=info msg=" --node-port-acceleration='disabled'" subsys=daemon level=info msg=" --node-port-algorithm='random'" subsys=daemon level=info msg=" --node-port-bind-protection='true'" subsys=daemon level=info msg=" --node-port-mode='snat'" subsys=daemon level=info msg=" --node-port-range='30000,32767'" subsys=daemon level=info msg=" --nodes-gc-interval='5m0s'" subsys=daemon level=info msg=" --operator-api-serve-addr='127.0.0.1:9234'" subsys=daemon level=info msg=" --policy-audit-mode='false'" subsys=daemon level=info msg=" --policy-queue-size='100'" subsys=daemon level=info msg=" --policy-trigger-interval='1s'" subsys=daemon level=info msg=" --pprof='false'" subsys=daemon level=info msg=" --pprof-address='localhost'" subsys=daemon level=info msg=" --pprof-port='6060'" subsys=daemon level=info msg=" --preallocate-bpf-maps='false'" subsys=daemon level=info msg=" --prepend-iptables-chains='true'" subsys=daemon level=info msg=" --procfs='/host/proc'" subsys=daemon level=info msg=" --prometheus-serve-addr=':9962'" subsys=daemon level=info msg=" --proxy-connect-timeout='2'" subsys=daemon level=info msg=" --proxy-gid='1337'" subsys=daemon level=info msg=" --proxy-idle-timeout-seconds='60'" subsys=daemon level=info msg=" --proxy-max-connection-duration-seconds='0'" subsys=daemon level=info msg=" --proxy-max-requests-per-connection='0'" subsys=daemon level=info msg=" --proxy-prometheus-port='9964'" subsys=daemon level=info msg=" --read-cni-conf=''" subsys=daemon level=info msg=" --remove-cilium-node-taints='true'" subsys=daemon level=info msg=" --restore='true'" subsys=daemon level=info msg=" --route-metric='0'" subsys=daemon level=info msg=" --routing-mode='tunnel'" subsys=daemon level=info msg=" --set-cilium-is-up-condition='true'" subsys=daemon level=info msg=" --set-cilium-node-taints='true'" subsys=daemon level=info msg=" --sidecar-istio-proxy-image='cilium/istio_proxy'" subsys=daemon level=info msg=" --single-cluster-route='false'" subsys=daemon level=info msg=" --skip-cnp-status-startup-clean='false'" subsys=daemon level=info msg=" --socket-path='/var/run/cilium/cilium.sock'" subsys=daemon level=info msg=" --srv6-encap-mode='reduced'" subsys=daemon level=info msg=" --state-dir='/var/run/cilium'" subsys=daemon level=info msg=" --synchronize-k8s-nodes='true'" subsys=daemon level=info msg=" --tofqdns-dns-reject-response-code='refused'" subsys=daemon level=info msg=" --tofqdns-enable-dns-compression='true'" subsys=daemon level=info msg=" --tofqdns-endpoint-max-ip-per-hostname='50'" subsys=daemon level=info msg=" --tofqdns-idle-connection-grace-period='0s'" subsys=daemon level=info msg=" --tofqdns-max-deferred-connection-deletes='10000'" subsys=daemon level=info msg=" --tofqdns-min-ttl='0'" subsys=daemon level=info msg=" --tofqdns-pre-cache=''" subsys=daemon level=info msg=" --tofqdns-proxy-port='0'" subsys=daemon level=info msg=" --tofqdns-proxy-response-max-delay='100ms'" subsys=daemon level=info msg=" --trace-payloadlen='128'" subsys=daemon level=info msg=" --trace-sock='true'" subsys=daemon level=info msg=" --tunnel=''" subsys=daemon level=info msg=" --tunnel-port='6082'" subsys=daemon level=info msg=" --tunnel-protocol='geneve'" subsys=daemon level=info msg=" --unmanaged-pod-watcher-interval='15'" subsys=daemon level=info msg=" --use-cilium-internal-ip-for-ipsec='false'" subsys=daemon level=info msg=" --version='false'" subsys=daemon level=info msg=" --vlan-bpf-bypass=''" subsys=daemon level=info msg=" --vtep-cidr=''" subsys=daemon level=info msg=" --vtep-endpoint=''" subsys=daemon level=info msg=" --vtep-mac=''" subsys=daemon level=info msg=" --vtep-mask=''" subsys=daemon level=info msg=" --wireguard-encapsulate='false'" subsys=daemon level=info msg=" --write-cni-conf-when-ready='/host/etc/cni/net.d/05-cilium.conflist'" subsys=daemon level=info msg=" _ _ _" subsys=daemon level=info msg=" ___|_| |_|_ _ _____" subsys=daemon level=info msg="| _| | | | | | |" subsys=daemon level=info msg="|___|_|_|_|___|_|_|_|" subsys=daemon level=info msg="Cilium 1.14.8 cf6e022e 2024-03-13T12:23:35-04:00 go version go1.21.8 linux/amd64" subsys=daemon level=info msg="clang (10.0.0) and kernel (5.15.0) versions: OK!" subsys=linux-datapath level=info msg="linking environment: OK!" subsys=linux-datapath level=info msg="Kernel config file not found: if the agent fails to start, check the system requirements at https://docs.cilium.io/en/stable/operations/system_requirements" subsys=probes level=info msg="Detected mounted BPF filesystem at /sys/fs/bpf" subsys=bpf level=info msg="Mounted cgroupv2 filesystem at /run/cilium/cgroupv2" subsys=cgroups level=info msg="Parsing base label prefixes from default label list" subsys=labels-filter level=info msg="Parsing additional label prefixes from user inputs: []" subsys=labels-filter level=info msg="Final label prefixes to be used for identity evaluation:" subsys=labels-filter level=info msg=" - reserved:.*" subsys=labels-filter level=info msg=" - :io\\.kubernetes\\.pod\\.namespace" subsys=labels-filter level=info msg=" - :io\\.cilium\\.k8s\\.namespace\\.labels" subsys=labels-filter level=info msg=" - :app\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:io\\.kubernetes" subsys=labels-filter level=info msg=" - !:kubernetes\\.io" subsys=labels-filter level=info msg=" - !:.*beta\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:k8s\\.io" subsys=labels-filter level=info msg=" - !:pod-template-generation" subsys=labels-filter level=info msg=" - !:pod-template-hash" subsys=labels-filter level=info msg=" - !:controller-revision-hash" subsys=labels-filter level=info msg=" - !:annotation.*" subsys=labels-filter level=info msg=" - !:etcd_node" subsys=labels-filter level=info msg=Invoked duration="735.116µs" function="pprof.glob..func1 (cell.go:50)" subsys=hive level=info msg=Invoked duration="48.371µs" function="gops.registerGopsHooks (cell.go:38)" subsys=hive level=info msg=Invoked duration="767.016µs" function="metrics.NewRegistry (registry.go:65)" subsys=hive level=info msg=Invoked duration="7.9µs" function="metrics.glob..func1 (cell.go:12)" subsys=hive level=info msg="Spire Delegate API Client is disabled as no socket path is configured" subsys=spire-delegate level=info msg="Mutual authentication handler is disabled as no port is configured" subsys=auth level=info msg=Invoked duration=99.545677ms function="cmd.glob..func4 (daemon_main.go:1607)" subsys=hive level=info msg=Invoked duration="12.66µs" function="gc.registerSignalHandler (cell.go:47)" subsys=hive level=info msg=Invoked duration="16.25µs" function="utime.initUtimeSync (cell.go:29)" subsys=hive level=info msg=Invoked duration="53.8µs" function="agentliveness.newAgentLivenessUpdater (agent_liveness.go:43)" subsys=hive level=info msg=Invoked duration="59.821µs" function="l2responder.NewL2ResponderReconciler (l2responder.go:63)" subsys=hive level=info msg=Invoked duration="66.06µs" function="garp.newGARPProcessor (processor.go:27)" subsys=hive level=info msg=Starting subsys=hive level=info msg="Started gops server" address="127.0.0.1:9890" subsys=gops level=info msg="Start hook executed" duration="393.593µs" function="gops.registerGopsHooks.func1 (cell.go:43)" subsys=hive level=info msg="Start hook executed" duration="1.25µs" function="metrics.NewRegistry.func1 (registry.go:86)" subsys=hive level=info msg="Establishing connection to apiserver" host="https://10.96.0.1:443" subsys=k8s-client level=info msg="Serving prometheus metrics on :9962" subsys=metrics level=info msg="Connected to apiserver" subsys=k8s-client level=info msg="Start hook executed" duration=9.349881ms function="client.(*compositeClientset).onStart" subsys=hive level=info msg="Start hook executed" duration=6.561795ms function="authmap.newAuthMap.func1 (cell.go:27)" subsys=hive level=info msg="Start hook executed" duration="58.35µs" function="configmap.newMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="62.151µs" function="signalmap.newMap.func1 (cell.go:44)" subsys=hive level=info msg="Start hook executed" duration="312.033µs" function="nodemap.newNodeMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="166.891µs" function="eventsmap.newEventsMap.func1 (cell.go:35)" subsys=hive level=info msg="Start hook executed" duration="75.671µs" function="*cni.cniConfigManager.Start" subsys=hive level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Wrote CNI configuration file to /host/etc/cni/net.d/05-cilium.conflist" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Start hook executed" duration=42.709853ms function="datapath.newDatapath.func1 (cells.go:113)" subsys=hive level=info msg="Restored 0 node IDs from the BPF map" subsys=linux-datapath level=info msg="Start hook executed" duration="200.792µs" function="datapath.newDatapath.func2 (cells.go:126)" subsys=hive level=info msg="Start hook executed" duration="10.88µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Node].Start" subsys=hive level=info msg="Start hook executed" duration="3.03µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNode].Start" subsys=hive level=info msg="Using autogenerated IPv4 allocation range" subsys=node v4Prefix=10.74.0.0/16 level=info msg="no local ciliumnode found, will not restore cilium internal ips from k8s" subsys=daemon level=info msg="Start hook executed" duration=103.503121ms function="node.NewLocalNodeStore.func1 (local_node_store.go:76)" subsys=hive level=info msg="Start hook executed" duration="200.592µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration=100.780421ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration="5.87µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Using discoveryv1.EndpointSlice" subsys=k8s level=info msg="Start hook executed" duration=201.058155ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Start hook executed" duration="4.19µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Pod].Start" subsys=hive level=info msg="Start hook executed" duration="2.9µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Namespace].Start" subsys=hive level=info msg="Start hook executed" duration="2.66µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="2.01µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumClusterwideNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="1.86µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumCIDRGroup].Start" subsys=hive level=info msg="Start hook executed" duration="29.67µs" function="endpointmanager.newDefaultEndpointManager.func1 (cell.go:203)" subsys=hive level=info msg="Start hook executed" duration="17.78µs" function="cmd.newPolicyTrifecta.func1 (policy.go:135)" subsys=hive level=info msg="Start hook executed" duration="28.63µs" function="*manager.manager.Start" subsys=hive level=info msg="Serving cilium node monitor v1.2 API at unix:///var/run/cilium/monitor1_2.sock" subsys=monitor-agent level=info msg="Start hook executed" duration="356.413µs" function="agent.newMonitorAgent.func1 (cell.go:61)" subsys=hive level=info msg="Start hook executed" duration="3.52µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumL2AnnouncementPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="10.08µs" function="*job.group.Start" subsys=hive level=info msg="Start hook executed" duration="261.062µs" function="proxy.newProxy.func1 (cell.go:55)" subsys=hive level=info msg="Envoy: Starting xDS gRPC server listening on /var/run/cilium/envoy/sockets/xds.sock" subsys=envoy-manager level=info msg="Start hook executed" duration="596.535µs" function="signal.provideSignalManager.func1 (cell.go:25)" subsys=hive level=info msg="Datapath signal listener running" subsys=signal level=info msg="Start hook executed" duration=1.291841ms function="auth.registerAuthManager.func1 (cell.go:109)" subsys=hive level=info msg="Start hook executed" duration="3.74µs" function="auth.registerGCJobs.func1 (cell.go:158)" subsys=hive level=info msg="Start hook executed" duration="21.45µs" function="*job.group.Start" subsys=hive level=warning msg="Deprecated value for --kube-proxy-replacement: disabled (use either \"true\", or \"false\")" subsys=daemon level=info msg="Auto-disabling \"enable-node-port\", \"enable-external-ips\", \"bpf-lb-sock\", \"enable-host-port\" features and falling back to \"enable-host-legacy-routing\"" subsys=daemon level=info msg="Inheriting MTU from external network interface" device=ens3 ipAddr=199.204.45.74 mtu=1500 subsys=mtu level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_ipcache, recreating and re-pinning map cilium_ipcache" file-path=/sys/fs/bpf/tc/globals/cilium_ipcache name=cilium_ipcache subsys=bpf level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_tunnel_map, recreating and re-pinning map cilium_tunnel_map" file-path=/sys/fs/bpf/tc/globals/cilium_tunnel_map name=cilium_tunnel_map subsys=bpf level=info msg="Restored services from maps" failedServices=0 restoredServices=0 subsys=service level=info msg="Restored backends from maps" failedBackends=0 restoredBackends=0 skippedBackends=0 subsys=service level=info msg="Reading old endpoints..." subsys=daemon level=info msg="No old endpoints found." subsys=daemon level=info msg="Waiting until all Cilium CRDs are available" subsys=k8s level=info msg="All Cilium CRDs have been found and are available" subsys=k8s level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=info msg="Successfully created CiliumNode resource" subsys=nodediscovery level=warning msg="Unable to create CiliumNode resource, will retry" error="ciliumnodes.cilium.io \"instance\" already exists" subsys=nodediscovery level=info msg="Retrieved node information from cilium node" nodeName=instance subsys=k8s level=warning msg="Waiting for k8s node information" error="required IPv4 PodCIDR not available" subsys=k8s level=info msg="Retrieved node information from cilium node" nodeName=instance subsys=k8s level=info msg="Received own node information from API server" ipAddr.ipv4=199.204.45.74 ipAddr.ipv6="" k8sNodeIP=199.204.45.74 labels="map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:]" nodeName=instance subsys=k8s v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="k8s mode: Allowing localhost to reach local endpoints" subsys=daemon level=info msg="Detected devices" devices="[]" subsys=linux-datapath level=info msg="Enabling k8s event listener" subsys=k8s-watcher level=info msg="Removing stale endpoint interfaces" subsys=daemon level=info msg="Waiting until local node addressing before starting watchers depending on it" subsys=k8s-watcher level=info msg="Skipping kvstore configuration" subsys=daemon level=info msg="Initializing node addressing" subsys=daemon level=info msg="Initializing cluster-pool IPAM" subsys=ipam v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="Restoring endpoints..." subsys=daemon level=info msg="Endpoints restored" failed=0 restored=0 subsys=daemon level=info msg="Addressing information:" subsys=daemon level=info msg=" Cluster-Name: default" subsys=daemon level=info msg=" Cluster-ID: 0" subsys=daemon level=info msg=" Local node-name: instance" subsys=daemon level=info msg=" Node-IPv6: " subsys=daemon level=info msg=" External-Node IPv4: 199.204.45.74" subsys=daemon level=info msg=" Internal-Node IPv4: 10.0.0.28" subsys=daemon level=info msg=" IPv4 allocation prefix: 10.0.0.0/24" subsys=daemon level=info msg=" Loopback IPv4: 169.254.42.1" subsys=daemon level=info msg=" Local IPv4 addresses:" subsys=daemon level=info msg=" - 199.204.45.74" subsys=daemon level=info msg=" - 172.17.0.100" subsys=daemon level=info msg="Node updated" clusterName=default nodeName=instance subsys=nodemanager level=info msg="Adding local node to cluster" node="{instance default [{InternalIP 199.204.45.74} {CiliumInternalIP 10.0.0.28}] 10.0.0.0/24 [] [] 10.0.0.182 0 local 0 map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:] map[] 1 }" subsys=nodediscovery level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Waiting until all pre-existing resources have been received" subsys=k8s-watcher level=info msg="Initializing identity allocator" subsys=identity-cache level=info msg="Allocating identities between range" cluster-id=0 max=65535 min=256 subsys=identity-cache level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.core.bpf_jit_enable sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.all.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.fib_multipath_use_neigh sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.unprivileged_bpf_disabled sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.timer_migration sysParamValue=0 level=info msg="Setting up BPF datapath" bpfClockSource=ktime bpfInsnSet="" subsys=datapath-loader level=info msg="Iptables rules installed" subsys=iptables level=info msg="Adding new proxy port rules for cilium-dns-egress:40883" id=cilium-dns-egress subsys=proxy level=info msg="Iptables proxy rules installed" subsys=iptables level=info msg="Start hook executed" duration=2.354198143s function="cmd.newDaemonPromise.func1 (daemon_main.go:1663)" subsys=hive level=info msg="Starting IP identity watcher" subsys=ipcache level=info msg="Start hook executed" duration="13.921µs" function="utime.initUtimeSync.func1 (cell.go:33)" subsys=hive level=info msg="Start hook executed" duration="6.15µs" function="*job.group.Start" subsys=hive level=info msg="Initializing daemon" subsys=daemon level=info msg="Validating configured node address ranges" subsys=daemon level=info msg="Start hook executed" duration="30.99µs" function="l2respondermap.newMap.func1 (l2_responder_map4.go:44)" subsys=hive level=info msg="Start hook executed" duration="3.46µs" function="*job.group.Start" subsys=hive level=info msg="Starting connection tracking garbage collector" subsys=daemon level=info msg="Initial scan of connection tracking completed" subsys=ct-gc level=info msg="Regenerating restored endpoints" numRestored=0 subsys=daemon level=info msg="Creating host endpoint" subsys=daemon level=info msg="Finished regenerating restored endpoints" regenerated=0 subsys=daemon total=0 level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3377 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Deleted orphan backends" orphanBackends=0 subsys=service level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3377 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3377 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="Launching Cilium health daemon" subsys=daemon level=info msg="Launching Cilium health endpoint" subsys=daemon level=info msg="Started healthz status API server" address="127.0.0.1:9879" subsys=daemon level=info msg="Processing queued endpoint deletion requests from /var/run/cilium/deleteQueue" subsys=daemon level=info msg="processing 0 queued deletion requests" subsys=daemon level=info msg="Initializing Cilium API" subsys=daemon level=info msg="Daemon initialization completed" bootstrapTime=3.405729745s subsys=daemon level=info msg="Hubble server is disabled" subsys=hubble level=info msg="Serving cilium API at unix:///var/run/cilium/cilium.sock" subsys=daemon level=info msg="Compiled new BPF template" BPFCompilationTime=297.235878ms file-path=/var/run/cilium/state/templates/a5c2550d5dd41acd8ae60e6156f45d34b4e76e92db1ac1a1ad7abcc061659348/bpf_host.o subsys=datapath-loader level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=3377 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1026 ipv4=10.0.0.182 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1026 identityLabels="reserved:health" ipv4=10.0.0.182 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1026 identity=4 identityLabels="reserved:health" ipv4=10.0.0.182 ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.114 18602caa-34cd-4afd-a37f-d4555ea94a72 default }" containerID=e5b1869c7fea665ec1ec21ace31bcb4ed43c9702039a6b6d0055922717cfab3e datapathConfiguration="&{false false false false false }" interface=lxc262079c98e5b k8sPodName=kube-system/coredns-7c96b6546b-qfswr labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e5b1869c7f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1020 ipv4=10.0.0.114 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qfswr subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e5b1869c7f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1020 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.114 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qfswr subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:kube-system]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=e5b1869c7f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1020 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.114 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qfswr line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=coredns;k8s:io.kubernetes.pod.namespace=kube-system;k8s:k8s-app=kube-dns;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e5b1869c7f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1020 identity=18437 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.114 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qfswr oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e5b1869c7f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1020 identity=18437 ipv4=10.0.0.114 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qfswr subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.206 744a1690-098a-4f12-8068-cd0c001c12c0 default }" containerID=f2ad0d1879fd50d6bd065d13a43d428d0016a720770f777f1cf9b7357c3127e2 datapathConfiguration="&{false false false false false }" interface=lxc7683a78075a0 k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-ttzx2 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f2ad0d1879 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2674 ipv4=10.0.0.206 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-ttzx2 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f2ad0d1879 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2674 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=2b1de71e-ec34-4e8a-9fd7-48e331fd5df9,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=2b1de71e-ec34-4e8a-9fd7-48e331fd5df9,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.206 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-ttzx2 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=certgen;k8s:batch.kubernetes.io/controller-uid=2b1de71e-ec34-4e8a-9fd7-48e331fd5df9;k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen;k8s:controller-uid=2b1de71e-ec34-4e8a-9fd7-48e331fd5df9;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;k8s:job-name=envoy-gateway-gateway-helm-certgen;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=f2ad0d1879 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2674 identity=33154 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=2b1de71e-ec34-4e8a-9fd7-48e331fd5df9,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=2b1de71e-ec34-4e8a-9fd7-48e331fd5df9,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.206 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-ttzx2 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f2ad0d1879 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2674 identity=33154 ipv4=10.0.0.206 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-ttzx2 subsys=endpoint level=info msg="Serving cilium health API at unix:///var/run/cilium/health.sock" subsys=health-server level=info msg="Compiled new BPF template" BPFCompilationTime=1.096738574s file-path=/var/run/cilium/state/templates/9b082b10b28b6f6f89f3b04a8d99b65b81c78501386a36fd295b10a8cd9bfc85/bpf_lxc.o subsys=datapath-loader level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1026 identity=4 ipv4=10.0.0.182 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=e5b1869c7f datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1020 identity=18437 ipv4=10.0.0.114 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qfswr subsys=endpoint level=info msg="Successful endpoint creation" containerID=e5b1869c7f datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1020 identity=18437 ipv4=10.0.0.114 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qfswr subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=f2ad0d1879 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2674 identity=33154 ipv4=10.0.0.206 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-ttzx2 subsys=endpoint level=info msg="Successful endpoint creation" containerID=f2ad0d1879 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2674 identity=33154 ipv4=10.0.0.206 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-ttzx2 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=f2ad0d1879 endpointID=2674 k8sNamespace=envoy-gateway-system k8sPodName=envoy-gateway-gateway-helm-certgen-ttzx2 subsys=daemon level=info msg="Releasing key" key="[k8s:app=certgen k8s:batch.kubernetes.io/controller-uid=2b1de71e-ec34-4e8a-9fd7-48e331fd5df9 k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen k8s:controller-uid=2b1de71e-ec34-4e8a-9fd7-48e331fd5df9 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen k8s:io.kubernetes.pod.namespace=envoy-gateway-system k8s:job-name=envoy-gateway-gateway-helm-certgen]" subsys=allocator level=info msg="Removed endpoint" containerID=f2ad0d1879 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2674 identity=33154 ipv4=10.0.0.206 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-ttzx2 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.74 66db4147-9f59-4cbf-b453-fb56c3bafeab default }" containerID=125ace3d41c43efe5a46370cd6782922939afe38147501cbd1b09d5c52b2fb4d datapathConfiguration="&{false false false false false }" interface=lxc47ea2d0d5dae k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zm7wl labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=125ace3d41 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2005 ipv4=10.0.0.74 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zm7wl subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=125ace3d41 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2005 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.74 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zm7wl subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=125ace3d41 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2005 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.74 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zm7wl line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=envoy-gateway;k8s:app.kubernetes.io/name=gateway-helm;k8s:control-plane=envoy-gateway;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=125ace3d41 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2005 identity=20937 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.74 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zm7wl oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=125ace3d41 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2005 identity=20937 ipv4=10.0.0.74 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zm7wl subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=125ace3d41 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2005 identity=20937 ipv4=10.0.0.74 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zm7wl subsys=endpoint level=info msg="Successful endpoint creation" containerID=125ace3d41 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2005 identity=20937 ipv4=10.0.0.74 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-zm7wl subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3377 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,k8s:openstack-compute-node=enabled,k8s:openstack-control-plane=enabled,k8s:openvswitch=enabled,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_hostns_03377 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_hostns_03377 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_hostns_03377 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_hostns_03377:pending" subsys=bpf level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_netdev_00003 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_netdev_00003 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003:pending" subsys=bpf level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3377 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.221 508d8df5-1b68-4f18-a961-9d6604d8ec36 default }" containerID=2f67c9b98d2917fd211df6e5f799a8169b09c14b1d082625c7050b52daa7fb56 datapathConfiguration="&{false false false false false }" interface=lxcc687270de111 k8sPodName=kube-system/coredns-67659f764b-j4vfx labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=2f67c9b98d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=973 ipv4=10.0.0.221 ipv6= k8sPodName=kube-system/coredns-67659f764b-j4vfx subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.13 0b30e64c-58d0-4458-9f23-f7fc2e8990d3 default }" containerID=f86515d8a888772e3941ba5d1c0554ec7f35e33bc030051acc37b3d31307ec21 datapathConfiguration="&{false false false false false }" interface=lxcfd5cf2df5b4f k8sPodName=kube-system/coredns-67659f764b-qxwlc labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f86515d8a8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=537 ipv4=10.0.0.13 ipv6= k8sPodName=kube-system/coredns-67659f764b-qxwlc subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=2f67c9b98d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=973 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.221 ipv6= k8sPodName=kube-system/coredns-67659f764b-j4vfx subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f86515d8a8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=537 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.13 ipv6= k8sPodName=kube-system/coredns-67659f764b-qxwlc subsys=endpoint level=info msg="Identity of endpoint changed" containerID=2f67c9b98d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=973 identity=18437 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.221 ipv6= k8sPodName=kube-system/coredns-67659f764b-j4vfx oldIdentity="no identity" subsys=endpoint level=info msg="Identity of endpoint changed" containerID=f86515d8a8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=537 identity=18437 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.13 ipv6= k8sPodName=kube-system/coredns-67659f764b-qxwlc oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=2f67c9b98d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=973 identity=18437 ipv4=10.0.0.221 ipv6= k8sPodName=kube-system/coredns-67659f764b-j4vfx subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f86515d8a8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=537 identity=18437 ipv4=10.0.0.13 ipv6= k8sPodName=kube-system/coredns-67659f764b-qxwlc subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=2f67c9b98d datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=973 identity=18437 ipv4=10.0.0.221 ipv6= k8sPodName=kube-system/coredns-67659f764b-j4vfx subsys=endpoint level=info msg="Successful endpoint creation" containerID=2f67c9b98d datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=973 identity=18437 ipv4=10.0.0.221 ipv6= k8sPodName=kube-system/coredns-67659f764b-j4vfx subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=f86515d8a8 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=537 identity=18437 ipv4=10.0.0.13 ipv6= k8sPodName=kube-system/coredns-67659f764b-qxwlc subsys=endpoint level=info msg="Successful endpoint creation" containerID=f86515d8a8 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=537 identity=18437 ipv4=10.0.0.13 ipv6= k8sPodName=kube-system/coredns-67659f764b-qxwlc subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.140 bad7ef7a-4d3f-4425-aa88-86f889dc991f default }" containerID=b651b69a17fb7ade2257b080ff1d84ebd1632f1f47f4560d17fca55c7a7e8d07 datapathConfiguration="&{false false false false false }" interface=lxcaf4e1fb83761 k8sPodName=local-path-storage/local-path-provisioner-679c578f5-g6rgm labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b651b69a17 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=236 ipv4=10.0.0.140 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-g6rgm subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b651b69a17 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=236 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.140 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-g6rgm subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=b651b69a17 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=236 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.140 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-g6rgm line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=local-path-provisioner;k8s:app.kubernetes.io/name=local-path-provisioner;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=b651b69a17 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=236 identity=4303 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.140 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-g6rgm oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b651b69a17 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=236 identity=4303 ipv4=10.0.0.140 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-g6rgm subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=b651b69a17 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=236 identity=4303 ipv4=10.0.0.140 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-g6rgm subsys=endpoint level=info msg="Successful endpoint creation" containerID=b651b69a17 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=236 identity=4303 ipv4=10.0.0.140 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-g6rgm subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=e5b1869c7f endpointID=1020 k8sNamespace=kube-system k8sPodName=coredns-7c96b6546b-qfswr subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=coredns k8s:io.kubernetes.pod.namespace=kube-system k8s:k8s-app=kube-dns]" subsys=allocator level=info msg="Removed endpoint" containerID=e5b1869c7f datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1020 identity=18437 ipv4=10.0.0.114 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-qfswr subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.220 e31b104d-1fc4-47b3-b6ee-95a8689b91e2 default }" containerID=70bfe2651e83889dc2e4206b1b94cb0b2247906a250024c01a4cbeacb7777fdf datapathConfiguration="&{false false false false false }" interface=lxc3bf595220243 k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-d56hg labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=70bfe2651e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2434 ipv4=10.0.0.220 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-d56hg subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=70bfe2651e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2434 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.220 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-d56hg subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=70bfe2651e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2434 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.220 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-d56hg line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=cainjector;k8s:app.kubernetes.io/component=cainjector;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cainjector;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=70bfe2651e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2434 identity=31495 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.220 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-d56hg oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=70bfe2651e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2434 identity=31495 ipv4=10.0.0.220 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-d56hg subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.148 7aeb8e94-b382-46c1-821a-f62afea0d9bc default }" containerID=1844c6557020e84e17b3f98865a9b85316a5bbc4bb2d22cc2699ac9eca89272f datapathConfiguration="&{false false false false false }" interface=lxc4a8d9b66fbae k8sPodName=cert-manager/cert-manager-75c4c745bc-99bm5 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=1844c65570 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3928 ipv4=10.0.0.148 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-99bm5 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=1844c65570 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3928 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.148 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-99bm5 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=cert-manager;k8s:app.kubernetes.io/component=controller;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cert-manager;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=1844c65570 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3928 identity=3770 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.148 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-99bm5 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=1844c65570 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3928 identity=3770 ipv4=10.0.0.148 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-99bm5 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=70bfe2651e datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2434 identity=31495 ipv4=10.0.0.220 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-d56hg subsys=endpoint level=info msg="Successful endpoint creation" containerID=70bfe2651e datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2434 identity=31495 ipv4=10.0.0.220 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-d56hg subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.33 70fd6ffa-6040-4016-9c5c-0317c6bfd4d0 default }" containerID=50ef29d3701f79cbc559978388e08dd04766cdbb78895f853ad58c5d8c62e7cb datapathConfiguration="&{false false false false false }" interface=lxc4bd7ad282412 k8sPodName=cert-manager/cert-manager-webhook-548949fc64-wxnzt labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=50ef29d370 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=681 ipv4=10.0.0.33 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-wxnzt subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=50ef29d370 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=681 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.33 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-wxnzt subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=webhook;k8s:app.kubernetes.io/component=webhook;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=webhook;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=50ef29d370 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=681 identity=26168 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.33 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-wxnzt oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=50ef29d370 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=681 identity=26168 ipv4=10.0.0.33 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-wxnzt subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=50ef29d370 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=681 identity=26168 ipv4=10.0.0.33 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-wxnzt subsys=endpoint level=info msg="Successful endpoint creation" containerID=50ef29d370 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=681 identity=26168 ipv4=10.0.0.33 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-wxnzt subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=1844c65570 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=3928 identity=3770 ipv4=10.0.0.148 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-99bm5 subsys=endpoint level=info msg="Successful endpoint creation" containerID=1844c65570 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3928 identity=3770 ipv4=10.0.0.148 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-99bm5 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.16 8e421094-fa79-416c-9dd7-91f27e4362e7 default }" containerID=289450bde02872a3dd6821544f5f93ab8c2e7c81a6bee58ae072ae339bfc8cdf datapathConfiguration="&{false false false false false }" interface=lxcc3e2f16fb5b5 k8sPodName=cert-manager/cert-manager-startupapicheck-tgxfx labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=289450bde0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1306 ipv4=10.0.0.16 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tgxfx subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=289450bde0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1306 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=90ea6897-c123-43b1-9901-dc22b4179a65,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=90ea6897-c123-43b1-9901-dc22b4179a65,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.16 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tgxfx subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=startupapicheck;k8s:app.kubernetes.io/component=startupapicheck;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=startupapicheck;k8s:app.kubernetes.io/version=v1.11.5;k8s:batch.kubernetes.io/controller-uid=90ea6897-c123-43b1-9901-dc22b4179a65;k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck;k8s:controller-uid=90ea6897-c123-43b1-9901-dc22b4179a65;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck;k8s:io.kubernetes.pod.namespace=cert-manager;k8s:job-name=cert-manager-startupapicheck;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=289450bde0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1306 identity=38701 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=90ea6897-c123-43b1-9901-dc22b4179a65,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=90ea6897-c123-43b1-9901-dc22b4179a65,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.16 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tgxfx oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=289450bde0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1306 identity=38701 ipv4=10.0.0.16 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tgxfx subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=289450bde0 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1306 identity=38701 ipv4=10.0.0.16 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tgxfx subsys=endpoint level=info msg="Successful endpoint creation" containerID=289450bde0 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1306 identity=38701 ipv4=10.0.0.16 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tgxfx subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=289450bde0 endpointID=1306 k8sNamespace=cert-manager k8sPodName=cert-manager-startupapicheck-tgxfx subsys=daemon level=info msg="Releasing key" key="[k8s:app=startupapicheck k8s:app.kubernetes.io/component=startupapicheck k8s:app.kubernetes.io/instance=cert-manager k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=startupapicheck k8s:app.kubernetes.io/version=v1.11.5 k8s:batch.kubernetes.io/controller-uid=90ea6897-c123-43b1-9901-dc22b4179a65 k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck k8s:controller-uid=90ea6897-c123-43b1-9901-dc22b4179a65 k8s:helm.sh/chart=cert-manager-v1.11.5 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager k8s:io.cilium.k8s.namespace.labels.name=cert-manager k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck k8s:io.kubernetes.pod.namespace=cert-manager k8s:job-name=cert-manager-startupapicheck]" subsys=allocator level=info msg="Removed endpoint" containerID=289450bde0 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1306 identity=38701 ipv4=10.0.0.16 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tgxfx subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.198 49658006-4985-4e2b-af0a-ad58895d7eb2 default }" containerID=4f3c8f011742d271b7174e6b3bc0b61ea3d908f0d6d6551d5e3e37d497141298 datapathConfiguration="&{false false false false false }" interface=lxc75819c8438bc k8sPodName=ingress-nginx/ingress-nginx-admission-create-xk5cc labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=4f3c8f0117 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1431 ipv4=10.0.0.198 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-xk5cc subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=4f3c8f0117 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1431 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=33846e99-ee88-4a67-b663-584feab3d598,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=33846e99-ee88-4a67-b663-584feab3d598,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.198 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-xk5cc subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=33846e99-ee88-4a67-b663-584feab3d598;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create;k8s:controller-uid=33846e99-ee88-4a67-b663-584feab3d598;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-create;" subsys=allocator level=info msg="Invalid state transition skipped" containerID=4f3c8f0117 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1431 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.198 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-xk5cc line=611 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=4f3c8f0117 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1431 identity=63237 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=33846e99-ee88-4a67-b663-584feab3d598,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=33846e99-ee88-4a67-b663-584feab3d598,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.198 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-xk5cc oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=4f3c8f0117 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1431 identity=63237 ipv4=10.0.0.198 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-xk5cc subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=4f3c8f0117 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1431 identity=63237 ipv4=10.0.0.198 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-xk5cc subsys=endpoint level=info msg="Successful endpoint creation" containerID=4f3c8f0117 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1431 identity=63237 ipv4=10.0.0.198 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-xk5cc subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=4f3c8f0117 endpointID=1431 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-create-xk5cc subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=33846e99-ee88-4a67-b663-584feab3d598 k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create k8s:controller-uid=33846e99-ee88-4a67-b663-584feab3d598 k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-create]" subsys=allocator level=info msg="Removed endpoint" containerID=4f3c8f0117 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1431 identity=63237 ipv4=10.0.0.198 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-xk5cc subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.104 c964767e-e581-4a11-8ef5-aef9dafc2075 default }" containerID=706807b823a5d63aabdb516d1b679aa1dd365405fdb20fbd2aef55afde5373c6 datapathConfiguration="&{false false false false false }" interface=lxc34a367da1b47 k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-r784n labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=706807b823 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=875 ipv4=10.0.0.104 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-r784n subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=706807b823 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=875 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.104 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-r784n subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=default-backend;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend;k8s:io.kubernetes.pod.namespace=ingress-nginx;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=706807b823 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=875 identity=9914 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.104 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-r784n oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=706807b823 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=875 identity=9914 ipv4=10.0.0.104 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-r784n subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=706807b823 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=875 identity=9914 ipv4=10.0.0.104 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-r784n subsys=endpoint level=info msg="Successful endpoint creation" containerID=706807b823 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=875 identity=9914 ipv4=10.0.0.104 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-r784n subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.83 91c469ed-4421-45ba-bd8b-21aa31d4e1c1 default }" containerID=5f5c1b92e3ae9df46a175eb8ad7fa214f69dff6c08c328e6074ff05192346e4c datapathConfiguration="&{false false false false false }" interface=lxc42e1b8e1753d k8sPodName=ingress-nginx/ingress-nginx-admission-patch-crqkr labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=5f5c1b92e3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2725 ipv4=10.0.0.83 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-crqkr subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=5f5c1b92e3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2725 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=4ffaae60-1505-4c43-ae40-0c4d02782b27,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=4ffaae60-1505-4c43-ae40-0c4d02782b27,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.83 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-crqkr subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=4ffaae60-1505-4c43-ae40-0c4d02782b27;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch;k8s:controller-uid=4ffaae60-1505-4c43-ae40-0c4d02782b27;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-patch;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=5f5c1b92e3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2725 identity=24358 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=4ffaae60-1505-4c43-ae40-0c4d02782b27,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=4ffaae60-1505-4c43-ae40-0c4d02782b27,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.83 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-crqkr oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=5f5c1b92e3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2725 identity=24358 ipv4=10.0.0.83 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-crqkr subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=5f5c1b92e3 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2725 identity=24358 ipv4=10.0.0.83 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-crqkr subsys=endpoint level=info msg="Successful endpoint creation" containerID=5f5c1b92e3 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2725 identity=24358 ipv4=10.0.0.83 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-crqkr subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=5f5c1b92e3 endpointID=2725 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-patch-crqkr subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=4ffaae60-1505-4c43-ae40-0c4d02782b27 k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch k8s:controller-uid=4ffaae60-1505-4c43-ae40-0c4d02782b27 k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-patch]" subsys=allocator level=info msg="Removed endpoint" containerID=5f5c1b92e3 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2725 identity=24358 ipv4=10.0.0.83 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-crqkr subsys=endpoint level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"rabbitmq-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-cluster-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=0e2ea643-1dad-444d-a5ff-d0f38162b1e8] Description:}]" policyAddRequest=f60d00d6-0762-42f2-b1fb-bfe4c00d7097 subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=f60d00d6-0762-42f2-b1fb-bfe4c00d7097 policyRevision=2 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-cluster-operator subsys=k8s-watcher level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"messaging-topology-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:9443 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-messaging-topology-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=dbd6a3f9-df25-4d16-8032-a212091d1c2a] Description:}]" policyAddRequest=e3f8bf81-228e-46f6-8b90-fb57c113dd7b subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=e3f8bf81-228e-46f6-8b90-fb57c113dd7b policyRevision=3 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-messaging-topology-operator subsys=k8s-watcher level=info msg="Create endpoint request" addressing="&{10.0.0.101 a1509d0a-ce43-4da0-80f5-4970a30eeed9 default }" containerID=4102fd741f157b4cd8c7e757f1f3c0eadd126c2e9d3b89dceddc1a0d5ee472f5 datapathConfiguration="&{false false false false false }" interface=lxc0b0b47a07764 k8sPodName=openstack/rabbitmq-cluster-operator-5448d56d95-dws2r labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=4102fd741f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2172 ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-5448d56d95-dws2r subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=4102fd741f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2172 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.9.0,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-5448d56d95-dws2r subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=4102fd741f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2172 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-5448d56d95-dws2r line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=2.9.0;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=4102fd741f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2172 identity=4489 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.9.0,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-5448d56d95-dws2r oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=4102fd741f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2172 identity=4489 ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-5448d56d95-dws2r subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=4102fd741f datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=2172 identity=4489 ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-5448d56d95-dws2r subsys=endpoint level=info msg="Successful endpoint creation" containerID=4102fd741f datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=2172 identity=4489 ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-5448d56d95-dws2r subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.174 d1dd1f75-6874-4171-8a51-d5d11af3e3af default }" containerID=ec2e5c68eb7c7741ae0e91878fa7a37c1c02b553fc91113c78d578af96c60a99 datapathConfiguration="&{false false false false false }" interface=lxc9511676ae893 k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-w7pb5 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=ec2e5c68eb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1264 ipv4=10.0.0.174 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-w7pb5 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=ec2e5c68eb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1264 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.14.1,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.174 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-w7pb5 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=messaging-topology-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=1.14.1;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=ec2e5c68eb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1264 identity=45460 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.14.1,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.3.6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.174 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-w7pb5 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=ec2e5c68eb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1264 identity=45460 ipv4=10.0.0.174 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-w7pb5 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=ec2e5c68eb datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=1264 identity=45460 ipv4=10.0.0.174 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-w7pb5 subsys=endpoint level=info msg="Successful endpoint creation" containerID=ec2e5c68eb datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=1264 identity=45460 ipv4=10.0.0.174 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-7f8596f788-w7pb5 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.80 e70b9902-44d2-4d74-893c-3ef86270d566 default }" containerID=0ab80b42630f41f0fcabed958ca1de9cec8abb126024c622a466abfc92711ace datapathConfiguration="&{false false false false false }" interface=lxce1e8cdde1331 k8sPodName=openstack/pxc-operator-7cff949c8b-2qs6v labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=0ab80b4263 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=621 ipv4=10.0.0.80 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-2qs6v subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=0ab80b4263 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=621 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.80 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-2qs6v subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=operator;k8s:app.kubernetes.io/instance=pxc-operator;k8s:app.kubernetes.io/name=pxc-operator;k8s:app.kubernetes.io/part-of=pxc-operator;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Invalid state transition skipped" containerID=0ab80b4263 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=621 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.80 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-2qs6v line=611 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=0ab80b4263 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=621 identity=30352 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.80 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-2qs6v oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=0ab80b4263 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=621 identity=30352 ipv4=10.0.0.80 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-2qs6v subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=0ab80b4263 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=621 identity=30352 ipv4=10.0.0.80 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-2qs6v subsys=endpoint level=info msg="Successful endpoint creation" containerID=0ab80b4263 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=621 identity=30352 ipv4=10.0.0.80 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-2qs6v subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.47 d30dbdfc-7a39-40d7-aef3-141da07527ee default }" containerID=0016eaaf2932521c26d832b2a87655a32a28f92174120024e35c1a0a6deba984 datapathConfiguration="&{false false false false false }" interface=lxc692fae60dbd1 k8sPodName=openstack/percona-xtradb-haproxy-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=0016eaaf29 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3667 ipv4=10.0.0.47 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=0016eaaf29 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3667 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.47 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=0016eaaf29 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3667 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.47 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=haproxy;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=0016eaaf29 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3667 identity=36277 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.47 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=0016eaaf29 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3667 identity=36277 ipv4=10.0.0.47 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.243 c771bc44-1b06-4b1d-a1fb-292d815e687e default }" containerID=8d7cec9713a0b9ba980bb6939de8c2491112e593de331c058ff20815b0235458 datapathConfiguration="&{false false false false false }" interface=lxc58034c2f8fe5 k8sPodName=local-path-storage/helper-pod-create-pvc-19b555a2-b5e4-444f-9dd7-cdb0756ea353 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=8d7cec9713 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3086 ipv4=10.0.0.243 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-19b555a2-b5e4-444f-9dd7-cdb0756ea353 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=8d7cec9713 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3086 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.243 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-19b555a2-b5e4-444f-9dd7-cdb0756ea353 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=8d7cec9713 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3086 identity=56965 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.243 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-19b555a2-b5e4-444f-9dd7-cdb0756ea353 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=8d7cec9713 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3086 identity=56965 ipv4=10.0.0.243 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-19b555a2-b5e4-444f-9dd7-cdb0756ea353 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=0016eaaf29 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=3667 identity=36277 ipv4=10.0.0.47 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=0016eaaf29 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=3667 identity=36277 ipv4=10.0.0.47 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=8d7cec9713 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=3086 identity=56965 ipv4=10.0.0.243 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-19b555a2-b5e4-444f-9dd7-cdb0756ea353 subsys=endpoint level=info msg="Successful endpoint creation" containerID=8d7cec9713 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=3086 identity=56965 ipv4=10.0.0.243 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-19b555a2-b5e4-444f-9dd7-cdb0756ea353 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=8d7cec9713 endpointID=3086 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-19b555a2-b5e4-444f-9dd7-cdb0756ea353 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=8d7cec9713 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=3086 identity=56965 ipv4=10.0.0.243 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-19b555a2-b5e4-444f-9dd7-cdb0756ea353 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.76 f4e88ba7-a969-4772-bbcb-f0a398e98c81 default }" containerID=7105ff3e4bbdf0a6d8ef0ec4c244102881383466aad17313eeb52af878e25597 datapathConfiguration="&{false false false false false }" interface=lxc0e9a33cde30a k8sPodName=openstack/percona-xtradb-pxc-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=7105ff3e4b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=506 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=7105ff3e4b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=506 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.76 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=pxc;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=7105ff3e4b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=506 identity=55662 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.76 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=7105ff3e4b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=506 identity=55662 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=7105ff3e4b datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=506 identity=55662 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=7105ff3e4b datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=506 identity=55662 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.145 db571552-f673-420c-ab74-73a91e5b0c89 default }" containerID=8dbceaec2f0e980ffcfacbc91c8d50ad98d3b899f4b6b98787ed76ed1508221b datapathConfiguration="&{false false false false false }" interface=lxc6b684cc24a20 k8sPodName=openstack/memcached-memcached-6479589586-6sbvt labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=8dbceaec2f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2045 ipv4=10.0.0.145 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-6sbvt subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=8dbceaec2f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2045 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.145 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-6sbvt subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=memcached;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=memcached;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=8dbceaec2f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2045 identity=2396 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.145 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-6sbvt oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=8dbceaec2f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2045 identity=2396 ipv4=10.0.0.145 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-6sbvt subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=8dbceaec2f datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=2045 identity=2396 ipv4=10.0.0.145 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-6sbvt subsys=endpoint level=info msg="Successful endpoint creation" containerID=8dbceaec2f datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=2045 identity=2396 ipv4=10.0.0.145 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-6sbvt subsys=daemon level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"keycloak\",\"k8s:app.kubernetes.io/instance\":\"keycloak\",\"k8s:app.kubernetes.io/name\":\"keycloak\",\"k8s:io.kubernetes.pod.namespace\":\"auth-system\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:7800 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:} {Ports:[{Port:8080 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=keycloak k8s:io.cilium.k8s.policy.namespace=auth-system k8s:io.cilium.k8s.policy.uid=c6589664-5b3e-4981-a20e-513a958fefde] Description:}]" policyAddRequest=db2410f6-0ae6-446b-9bfa-86fa85aec83d subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=db2410f6-0ae6-446b-9bfa-86fa85aec83d policyRevision=4 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=keycloak subsys=k8s-watcher level=info msg="Create endpoint request" addressing="&{10.0.0.37 d372be80-3780-4ddf-8a6b-cfcc62e5e6ad default }" containerID=4534956f599762f3ddd50e65462a3da765795889319fe8f176c34c3c8287b4ca datapathConfiguration="&{false false false false false }" interface=lxce1ca0f707698 k8sPodName=auth-system/keycloak-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=4534956f59 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=832 ipv4=10.0.0.37 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=4534956f59 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=832 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=24.0.5,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-21.4.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.37 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:auth-system k8s:io.cilium.k8s.namespace.labels.name:auth-system]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=keycloak;k8s:app.kubernetes.io/instance=keycloak;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=keycloak;k8s:app.kubernetes.io/version=24.0.5;k8s:apps.kubernetes.io/pod-index=0;k8s:helm.sh/chart=keycloak-21.4.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system;k8s:io.cilium.k8s.namespace.labels.name=auth-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keycloak;k8s:io.kubernetes.pod.namespace=auth-system;k8s:statefulset.kubernetes.io/pod-name=keycloak-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=4534956f59 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=832 identity=33733 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=24.0.5,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-21.4.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.37 ipv6= k8sPodName=auth-system/keycloak-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=4534956f59 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=832 identity=33733 ipv4=10.0.0.37 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=4534956f59 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=832 identity=33733 ipv4=10.0.0.37 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=4534956f59 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=832 identity=33733 ipv4=10.0.0.37 ipv6= k8sPodName=auth-system/keycloak-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Conntrack garbage collector interval recalculated" deleteRatio=0.04077247382020944 newInterval=7m30s subsys=map-ct level=info msg="Create endpoint request" addressing="&{10.0.0.208 758f69e2-597d-41ef-b547-6186d92aa9ea default }" containerID=a1a1a638dec5546a517fbf17b2adbf3f0e4bbf57a1ef8c3c34386fbb18aa5a9f datapathConfiguration="&{false false false false false }" interface=lxc148b2b3cedbd k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-2pv4j labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=a1a1a638de datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=900 ipv4=10.0.0.208 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-2pv4j subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=a1a1a638de datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=900 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.208 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-2pv4j subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:secretgen-controller]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=a1a1a638de datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=900 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.208 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-2pv4j line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=secretgen-controller;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa;k8s:io.kubernetes.pod.namespace=secretgen-controller;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=a1a1a638de datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=900 identity=17310 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.208 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-2pv4j oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=a1a1a638de datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=900 identity=17310 ipv4=10.0.0.208 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-2pv4j subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=a1a1a638de datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=900 identity=17310 ipv4=10.0.0.208 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-2pv4j subsys=endpoint level=info msg="Successful endpoint creation" containerID=a1a1a638de datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=900 identity=17310 ipv4=10.0.0.208 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-2pv4j subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.31 661765db-8261-4cc9-a32c-b6f7ffbd5cf5 default }" containerID=ed005f5935c7e9cbe71cc718917573e423f04ee01bf9b41f76230cf3f8d65fe3 datapathConfiguration="&{false false false false false }" interface=lxcfbef0376e68f k8sPodName=monitoring/kube-prometheus-stack-admission-create-ftbtc labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=ed005f5935 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1782 ipv4=10.0.0.31 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-ftbtc subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=ed005f5935 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1782 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=dd301402-9f74-4890-bb3e-eb24374100e4,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=dd301402-9f74-4890-bb3e-eb24374100e4,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.31 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-ftbtc subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-create;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:batch.kubernetes.io/controller-uid=dd301402-9f74-4890-bb3e-eb24374100e4;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create;k8s:chart=kube-prometheus-stack-60.2.0;k8s:controller-uid=dd301402-9f74-4890-bb3e-eb24374100e4;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-create;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=ed005f5935 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1782 identity=8079 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=dd301402-9f74-4890-bb3e-eb24374100e4,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=dd301402-9f74-4890-bb3e-eb24374100e4,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.31 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-ftbtc oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=ed005f5935 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1782 identity=8079 ipv4=10.0.0.31 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-ftbtc subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=ed005f5935 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1782 identity=8079 ipv4=10.0.0.31 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-ftbtc subsys=endpoint level=info msg="Successful endpoint creation" containerID=ed005f5935 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1782 identity=8079 ipv4=10.0.0.31 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-ftbtc subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=ed005f5935 endpointID=1782 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-create-ftbtc subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-create k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=60.2.0 k8s:batch.kubernetes.io/controller-uid=dd301402-9f74-4890-bb3e-eb24374100e4 k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create k8s:chart=kube-prometheus-stack-60.2.0 k8s:controller-uid=dd301402-9f74-4890-bb3e-eb24374100e4 k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-create k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=ed005f5935 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1782 identity=8079 ipv4=10.0.0.31 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-ftbtc subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.21 8d363f19-50d5-4d0e-bb89-13a3e2699064 default }" containerID=389de7eca54b2d4dd63dde8bc66ede071e499a454abc3f2ba1781408209383d4 datapathConfiguration="&{false false false false false }" interface=lxc8301fd0150eb k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-2jxzn labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=389de7eca5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=574 ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-2jxzn subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=389de7eca5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=574 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.20.0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-2jxzn subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=metrics;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-state-metrics;k8s:app.kubernetes.io/part-of=kube-state-metrics;k8s:app.kubernetes.io/version=2.12.0;k8s:helm.sh/chart=kube-state-metrics-5.20.0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=389de7eca5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=574 identity=29280 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.20.0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-2jxzn oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=389de7eca5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=574 identity=29280 ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-2jxzn subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.180 94f264b6-f046-498c-8b63-4b8c2793b942 default }" containerID=d637c0f1f8d9e09ef61cca64827b11c029e89f6f75dd88d81fec9b1f522cd5a7 datapathConfiguration="&{false false false false false }" interface=lxcef16e4b190f2 k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-njzzq labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d637c0f1f8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1956 ipv4=10.0.0.180 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-njzzq subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d637c0f1f8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1956 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-60.2.0,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.180 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-njzzq subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Create endpoint request" addressing="&{10.0.0.254 bc617ae0-939a-4029-87ad-d396ffdeed8d default }" containerID=23fe2698a316766437d6995139076884fbe0cbe6b040d03d4d7042012857f927 datapathConfiguration="&{false false false false false }" interface=lxc2b2067ec34ca k8sPodName=monitoring/kube-prometheus-stack-grafana-6f9bbbdffb-v5wm6 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=23fe2698a3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1714 ipv4=10.0.0.254 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-6f9bbbdffb-v5wm6 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=23fe2698a3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1714 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.254 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-6f9bbbdffb-v5wm6 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-operator;k8s:app.kubernetes.io/component=prometheus-operator;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:chart=kube-prometheus-stack-60.2.0;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d637c0f1f8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1956 identity=54106 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-60.2.0,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.180 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-njzzq oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d637c0f1f8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1956 identity=54106 ipv4=10.0.0.180 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-njzzq subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/name=grafana;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana;k8s:io.kubernetes.pod.namespace=monitoring;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=23fe2698a3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1714 identity=41131 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.254 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-6f9bbbdffb-v5wm6 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=23fe2698a3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1714 identity=41131 ipv4=10.0.0.254 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-6f9bbbdffb-v5wm6 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=389de7eca5 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=574 identity=29280 ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-2jxzn subsys=endpoint level=info msg="Successful endpoint creation" containerID=389de7eca5 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=574 identity=29280 ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-2jxzn subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=d637c0f1f8 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1956 identity=54106 ipv4=10.0.0.180 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-njzzq subsys=endpoint level=info msg="Successful endpoint creation" containerID=d637c0f1f8 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1956 identity=54106 ipv4=10.0.0.180 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-njzzq subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=23fe2698a3 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1714 identity=41131 ipv4=10.0.0.254 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-6f9bbbdffb-v5wm6 subsys=endpoint level=info msg="Successful endpoint creation" containerID=23fe2698a3 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1714 identity=41131 ipv4=10.0.0.254 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-6f9bbbdffb-v5wm6 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.246 8431730a-0f92-4603-a01b-ddec5e5fe4f0 default }" containerID=0d48f64ab7bd8d9ad5f9e613d8f1945175821359e860c57c4c9f4da8b4b92784 datapathConfiguration="&{false false false false false }" interface=lxcd5b294fcbd54 k8sPodName=monitoring/kube-prometheus-stack-admission-patch-bxkwz labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=0d48f64ab7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=486 ipv4=10.0.0.246 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-bxkwz subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=0d48f64ab7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=486 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=2eb161fc-3582-4c4f-9d8b-622124f99586,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=2eb161fc-3582-4c4f-9d8b-622124f99586,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.246 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-bxkwz subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-patch;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:batch.kubernetes.io/controller-uid=2eb161fc-3582-4c4f-9d8b-622124f99586;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch;k8s:chart=kube-prometheus-stack-60.2.0;k8s:controller-uid=2eb161fc-3582-4c4f-9d8b-622124f99586;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-patch;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=0d48f64ab7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=486 identity=25059 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=2eb161fc-3582-4c4f-9d8b-622124f99586,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=2eb161fc-3582-4c4f-9d8b-622124f99586,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.246 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-bxkwz oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=0d48f64ab7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=486 identity=25059 ipv4=10.0.0.246 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-bxkwz subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=0d48f64ab7 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=486 identity=25059 ipv4=10.0.0.246 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-bxkwz subsys=endpoint level=info msg="Successful endpoint creation" containerID=0d48f64ab7 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=486 identity=25059 ipv4=10.0.0.246 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-bxkwz subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=0d48f64ab7 endpointID=486 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-patch-bxkwz subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-patch k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=60.2.0 k8s:batch.kubernetes.io/controller-uid=2eb161fc-3582-4c4f-9d8b-622124f99586 k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch k8s:chart=kube-prometheus-stack-60.2.0 k8s:controller-uid=2eb161fc-3582-4c4f-9d8b-622124f99586 k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-patch k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=0d48f64ab7 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=486 identity=25059 ipv4=10.0.0.246 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-bxkwz subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.168 d5de8531-8bc7-4d57-bab7-384250c947bb default }" containerID=4e5861d31361a370724228abfa85524f159fe935e05c3390c168ed9856486a72 datapathConfiguration="&{false false false false false }" interface=lxc96e2da1a7c2a k8sPodName=local-path-storage/helper-pod-create-pvc-9962d3df-ac88-4678-89ad-115ba45b857e labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=4e5861d313 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3932 ipv4=10.0.0.168 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9962d3df-ac88-4678-89ad-115ba45b857e subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=4e5861d313 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3932 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.168 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9962d3df-ac88-4678-89ad-115ba45b857e subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=4e5861d313 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3932 identity=56965 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.168 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9962d3df-ac88-4678-89ad-115ba45b857e oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=4e5861d313 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3932 identity=56965 ipv4=10.0.0.168 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9962d3df-ac88-4678-89ad-115ba45b857e subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=4e5861d313 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3932 identity=56965 ipv4=10.0.0.168 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9962d3df-ac88-4678-89ad-115ba45b857e subsys=endpoint level=info msg="Successful endpoint creation" containerID=4e5861d313 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3932 identity=56965 ipv4=10.0.0.168 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9962d3df-ac88-4678-89ad-115ba45b857e subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.90 a7f95edf-48bd-4878-bf55-6914ae12392c default }" containerID=2dcc093d45adc9f373b8729ff5d9cb357f14939ba53435af2349d535dec2363a datapathConfiguration="&{false false false false false }" interface=lxc415792bda006 k8sPodName=local-path-storage/helper-pod-create-pvc-9375dfce-bc64-494d-8951-ac2fcab46169 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=2dcc093d45 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=869 ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9375dfce-bc64-494d-8951-ac2fcab46169 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=2dcc093d45 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=869 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9375dfce-bc64-494d-8951-ac2fcab46169 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=2dcc093d45 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=869 identity=56965 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9375dfce-bc64-494d-8951-ac2fcab46169 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=2dcc093d45 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=869 identity=56965 ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9375dfce-bc64-494d-8951-ac2fcab46169 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=2dcc093d45 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=869 identity=56965 ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9375dfce-bc64-494d-8951-ac2fcab46169 subsys=endpoint level=info msg="Successful endpoint creation" containerID=2dcc093d45 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=869 identity=56965 ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9375dfce-bc64-494d-8951-ac2fcab46169 subsys=daemon level=info msg="Delete endpoint request" containerID=2dcc093d45 endpointID=869 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-9375dfce-bc64-494d-8951-ac2fcab46169 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Delete endpoint request" containerID=4e5861d313 endpointID=3932 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-9962d3df-ac88-4678-89ad-115ba45b857e subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=2dcc093d45 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=869 identity=56965 ipv4=10.0.0.90 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9375dfce-bc64-494d-8951-ac2fcab46169 subsys=endpoint level=info msg="Removed endpoint" containerID=4e5861d313 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3932 identity=56965 ipv4=10.0.0.168 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-9962d3df-ac88-4678-89ad-115ba45b857e subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.66 c4e4fa09-db7f-4761-a242-fa644e35c4d8 default }" containerID=b93cf3b989f25f22f25d16ccdc94ab46292def583139240b85df08fcf8e809af datapathConfiguration="&{false false false false false }" interface=lxce0e5b342fa16 k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b93cf3b989 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=753 ipv4=10.0.0.66 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b93cf3b989 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=753 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.66 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=prometheus;k8s:app.kubernetes.io/version=2.51.2;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus;k8s:io.kubernetes.pod.namespace=monitoring;k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus;k8s:operator.prometheus.io/shard=0;k8s:prometheus=kube-prometheus-stack-prometheus;k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=b93cf3b989 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=753 identity=7804 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.66 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b93cf3b989 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=753 identity=7804 ipv4=10.0.0.66 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=b93cf3b989 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=753 identity=7804 ipv4=10.0.0.66 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=b93cf3b989 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=753 identity=7804 ipv4=10.0.0.66 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.128 07767462-4da5-4d1a-8b59-ab1be962e930 default }" containerID=158cefccf799f24610ea65a2795ee541065f089c29fa75807293ff2b7785eb43 datapathConfiguration="&{false false false false false }" interface=lxced2783805506 k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=158cefccf7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=694 ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=158cefccf7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=694 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:alertmanager=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=alertmanager;k8s:app.kubernetes.io/version=0.27.0;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager;k8s:io.kubernetes.pod.namespace=monitoring;k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=158cefccf7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=694 identity=30113 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=158cefccf7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=694 identity=30113 ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=158cefccf7 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=694 identity=30113 ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=158cefccf7 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=694 identity=30113 ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.109 7dadac05-7b4c-408b-b0ee-b9a23e33e3f4 default }" containerID=7fefcce7312d7f80e1cd89ccb83e41962983e8e3b128f8b96a80eadc366b0c91 datapathConfiguration="&{false false false false false }" interface=lxcedb7f2514ced k8sPodName=local-path-storage/helper-pod-create-pvc-d95ca8a1-74e3-4012-a327-f0910970abcd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=7fefcce731 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2074 ipv4=10.0.0.109 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d95ca8a1-74e3-4012-a327-f0910970abcd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=7fefcce731 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2074 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.109 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d95ca8a1-74e3-4012-a327-f0910970abcd subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=7fefcce731 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2074 identity=56965 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.109 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d95ca8a1-74e3-4012-a327-f0910970abcd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=7fefcce731 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2074 identity=56965 ipv4=10.0.0.109 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d95ca8a1-74e3-4012-a327-f0910970abcd subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=7fefcce731 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2074 identity=56965 ipv4=10.0.0.109 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d95ca8a1-74e3-4012-a327-f0910970abcd subsys=endpoint level=info msg="Successful endpoint creation" containerID=7fefcce731 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2074 identity=56965 ipv4=10.0.0.109 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d95ca8a1-74e3-4012-a327-f0910970abcd subsys=daemon level=info msg="Delete endpoint request" containerID=7fefcce731 endpointID=2074 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-d95ca8a1-74e3-4012-a327-f0910970abcd subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=7fefcce731 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2074 identity=56965 ipv4=10.0.0.109 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d95ca8a1-74e3-4012-a327-f0910970abcd subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.219 d9c19046-4251-44b7-8efc-2714cc103bbf default }" containerID=1b40b1760bef2f03ce4338058e5a476044ecd80508726af7474192bad8b4c79a datapathConfiguration="&{false false false false false }" interface=lxce979eb9116c5 k8sPodName=openstack/rabbitmq-keystone-server-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=1b40b1760b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=34 ipv4=10.0.0.219 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=1b40b1760b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=34 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.219 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=1b40b1760b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=34 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.219 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq;k8s:app.kubernetes.io/name=rabbitmq-keystone;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=1b40b1760b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=34 identity=2690 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.219 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=1b40b1760b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=34 identity=2690 ipv4=10.0.0.219 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=1b40b1760b datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=34 identity=2690 ipv4=10.0.0.219 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=1b40b1760b datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=34 identity=2690 ipv4=10.0.0.219 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.183 dd5fc6fa-b0f7-4619-a9bb-18d308c7ce9a default }" containerID=f2c322fafc9f83b8b556a05a2cde29ed02f8ddcd60070ace266b1fcf4c61e6e6 datapathConfiguration="&{false false false false false }" interface=lxcfabd6863a4e4 k8sPodName=openstack/keystone-api-54cb5b5984-z28q7 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f2c322fafc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1847 ipv4=10.0.0.183 ipv6= k8sPodName=openstack/keystone-api-54cb5b5984-z28q7 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f2c322fafc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1847 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.183 ipv6= k8sPodName=openstack/keystone-api-54cb5b5984-z28q7 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:component=api;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-api;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=f2c322fafc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1847 identity=10449 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.183 ipv6= k8sPodName=openstack/keystone-api-54cb5b5984-z28q7 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f2c322fafc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1847 identity=10449 ipv4=10.0.0.183 ipv6= k8sPodName=openstack/keystone-api-54cb5b5984-z28q7 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.73 4694bc82-95f7-4e88-ba8f-fe21677bb1bd default }" containerID=3d9711241f2b875b6a411999bd78f585ac5b782f4913573b4778e1d9823275a1 datapathConfiguration="&{false false false false false }" interface=lxc475d7bca309c k8sPodName=openstack/keystone-credential-setup-sqns5 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=3d9711241f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1073 ipv4=10.0.0.73 ipv6= k8sPodName=openstack/keystone-credential-setup-sqns5 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=3d9711241f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1073 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=9047dd7c-6822-4e10-82e2-7a73d39c4950,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=9047dd7c-6822-4e10-82e2-7a73d39c4950,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.73 ipv6= k8sPodName=openstack/keystone-credential-setup-sqns5 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=9047dd7c-6822-4e10-82e2-7a73d39c4950;k8s:batch.kubernetes.io/job-name=keystone-credential-setup;k8s:component=credential-setup;k8s:controller-uid=9047dd7c-6822-4e10-82e2-7a73d39c4950;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-credential-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=3d9711241f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1073 identity=22140 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=9047dd7c-6822-4e10-82e2-7a73d39c4950,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=9047dd7c-6822-4e10-82e2-7a73d39c4950,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.73 ipv6= k8sPodName=openstack/keystone-credential-setup-sqns5 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=3d9711241f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1073 identity=22140 ipv4=10.0.0.73 ipv6= k8sPodName=openstack/keystone-credential-setup-sqns5 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=f2c322fafc datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1847 identity=10449 ipv4=10.0.0.183 ipv6= k8sPodName=openstack/keystone-api-54cb5b5984-z28q7 subsys=endpoint level=info msg="Successful endpoint creation" containerID=f2c322fafc datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1847 identity=10449 ipv4=10.0.0.183 ipv6= k8sPodName=openstack/keystone-api-54cb5b5984-z28q7 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=3d9711241f datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1073 identity=22140 ipv4=10.0.0.73 ipv6= k8sPodName=openstack/keystone-credential-setup-sqns5 subsys=endpoint level=info msg="Successful endpoint creation" containerID=3d9711241f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1073 identity=22140 ipv4=10.0.0.73 ipv6= k8sPodName=openstack/keystone-credential-setup-sqns5 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=3d9711241f endpointID=1073 k8sNamespace=openstack k8sPodName=keystone-credential-setup-sqns5 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=9047dd7c-6822-4e10-82e2-7a73d39c4950 k8s:batch.kubernetes.io/job-name=keystone-credential-setup k8s:component=credential-setup k8s:controller-uid=9047dd7c-6822-4e10-82e2-7a73d39c4950 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-credential-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=3d9711241f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1073 identity=22140 ipv4=10.0.0.73 ipv6= k8sPodName=openstack/keystone-credential-setup-sqns5 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.50 3047954e-9871-426c-a56d-10d7545ec824 default }" containerID=f6c188aacd9950b2f5bb673b4efd5c26528b82f66ce993f69ff0c18bbad50021 datapathConfiguration="&{false false false false false }" interface=lxc78a9264f5377 k8sPodName=openstack/keystone-db-init-g75qk labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f6c188aacd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4004 ipv4=10.0.0.50 ipv6= k8sPodName=openstack/keystone-db-init-g75qk subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f6c188aacd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4004 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=ffd48424-ea4e-4547-8a47-249a2a8e4c75,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=ffd48424-ea4e-4547-8a47-249a2a8e4c75,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.50 ipv6= k8sPodName=openstack/keystone-db-init-g75qk subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=ffd48424-ea4e-4547-8a47-249a2a8e4c75;k8s:batch.kubernetes.io/job-name=keystone-db-init;k8s:component=db-init;k8s:controller-uid=ffd48424-ea4e-4547-8a47-249a2a8e4c75;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-init;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=f6c188aacd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4004 identity=8852 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=ffd48424-ea4e-4547-8a47-249a2a8e4c75,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=ffd48424-ea4e-4547-8a47-249a2a8e4c75,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.50 ipv6= k8sPodName=openstack/keystone-db-init-g75qk oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f6c188aacd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4004 identity=8852 ipv4=10.0.0.50 ipv6= k8sPodName=openstack/keystone-db-init-g75qk subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=f6c188aacd datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=4004 identity=8852 ipv4=10.0.0.50 ipv6= k8sPodName=openstack/keystone-db-init-g75qk subsys=endpoint level=info msg="Successful endpoint creation" containerID=f6c188aacd datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=4004 identity=8852 ipv4=10.0.0.50 ipv6= k8sPodName=openstack/keystone-db-init-g75qk subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=f6c188aacd endpointID=4004 k8sNamespace=openstack k8sPodName=keystone-db-init-g75qk subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=ffd48424-ea4e-4547-8a47-249a2a8e4c75 k8s:batch.kubernetes.io/job-name=keystone-db-init k8s:component=db-init k8s:controller-uid=ffd48424-ea4e-4547-8a47-249a2a8e4c75 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=f6c188aacd datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=4004 identity=8852 ipv4=10.0.0.50 ipv6= k8sPodName=openstack/keystone-db-init-g75qk subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.7 0553bf9f-387c-4548-a4d5-64a6dd297034 default }" containerID=263c1db93fa7dffac76e43605a2e472956042c03549d57f8cb7c1e1aae537d7f datapathConfiguration="&{false false false false false }" interface=lxc5b31863d056a k8sPodName=openstack/keystone-fernet-setup-5w8tv labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=263c1db93f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3985 ipv4=10.0.0.7 ipv6= k8sPodName=openstack/keystone-fernet-setup-5w8tv subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=263c1db93f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3985 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=1716e086-e0c0-447f-b29c-86ecb42cc94d,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=1716e086-e0c0-447f-b29c-86ecb42cc94d,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.7 ipv6= k8sPodName=openstack/keystone-fernet-setup-5w8tv subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=263c1db93f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3985 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.7 ipv6= k8sPodName=openstack/keystone-fernet-setup-5w8tv line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=1716e086-e0c0-447f-b29c-86ecb42cc94d;k8s:batch.kubernetes.io/job-name=keystone-fernet-setup;k8s:component=fernet-setup;k8s:controller-uid=1716e086-e0c0-447f-b29c-86ecb42cc94d;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-fernet-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=263c1db93f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3985 identity=36311 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=1716e086-e0c0-447f-b29c-86ecb42cc94d,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=1716e086-e0c0-447f-b29c-86ecb42cc94d,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.7 ipv6= k8sPodName=openstack/keystone-fernet-setup-5w8tv oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=263c1db93f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3985 identity=36311 ipv4=10.0.0.7 ipv6= k8sPodName=openstack/keystone-fernet-setup-5w8tv subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=263c1db93f datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3985 identity=36311 ipv4=10.0.0.7 ipv6= k8sPodName=openstack/keystone-fernet-setup-5w8tv subsys=endpoint level=info msg="Successful endpoint creation" containerID=263c1db93f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3985 identity=36311 ipv4=10.0.0.7 ipv6= k8sPodName=openstack/keystone-fernet-setup-5w8tv subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=263c1db93f endpointID=3985 k8sNamespace=openstack k8sPodName=keystone-fernet-setup-5w8tv subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=1716e086-e0c0-447f-b29c-86ecb42cc94d k8s:batch.kubernetes.io/job-name=keystone-fernet-setup k8s:component=fernet-setup k8s:controller-uid=1716e086-e0c0-447f-b29c-86ecb42cc94d k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-fernet-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=263c1db93f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3985 identity=36311 ipv4=10.0.0.7 ipv6= k8sPodName=openstack/keystone-fernet-setup-5w8tv subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.192 fb0998a6-ae3f-4119-a6f9-6406bbefcbe7 default }" containerID=83493d9a4d29d6a01881c108e37a09ce84f5e0e2a28cda9a6caacc6ccf7abc30 datapathConfiguration="&{false false false false false }" interface=lxc4310bd9bbed9 k8sPodName=openstack/keystone-db-sync-7nzzb labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=83493d9a4d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=351 ipv4=10.0.0.192 ipv6= k8sPodName=openstack/keystone-db-sync-7nzzb subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=83493d9a4d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=351 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=e4eff91b-f08e-4c8a-9d0a-54f3786ca22e,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=e4eff91b-f08e-4c8a-9d0a-54f3786ca22e,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.192 ipv6= k8sPodName=openstack/keystone-db-sync-7nzzb subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=e4eff91b-f08e-4c8a-9d0a-54f3786ca22e;k8s:batch.kubernetes.io/job-name=keystone-db-sync;k8s:component=db-sync;k8s:controller-uid=e4eff91b-f08e-4c8a-9d0a-54f3786ca22e;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-sync;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=83493d9a4d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=351 identity=7756 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=e4eff91b-f08e-4c8a-9d0a-54f3786ca22e,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=e4eff91b-f08e-4c8a-9d0a-54f3786ca22e,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.192 ipv6= k8sPodName=openstack/keystone-db-sync-7nzzb oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=83493d9a4d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=351 identity=7756 ipv4=10.0.0.192 ipv6= k8sPodName=openstack/keystone-db-sync-7nzzb subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=83493d9a4d datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=351 identity=7756 ipv4=10.0.0.192 ipv6= k8sPodName=openstack/keystone-db-sync-7nzzb subsys=endpoint level=info msg="Successful endpoint creation" containerID=83493d9a4d datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=351 identity=7756 ipv4=10.0.0.192 ipv6= k8sPodName=openstack/keystone-db-sync-7nzzb subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=83493d9a4d endpointID=351 k8sNamespace=openstack k8sPodName=keystone-db-sync-7nzzb subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=e4eff91b-f08e-4c8a-9d0a-54f3786ca22e k8s:batch.kubernetes.io/job-name=keystone-db-sync k8s:component=db-sync k8s:controller-uid=e4eff91b-f08e-4c8a-9d0a-54f3786ca22e k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-sync k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=83493d9a4d datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=351 identity=7756 ipv4=10.0.0.192 ipv6= k8sPodName=openstack/keystone-db-sync-7nzzb subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.155 c70a4a3a-6dd4-4bc5-8af6-ba7c7ddfd973 default }" containerID=556c539588c0e5d5000d72445aad064cbac4d10a85fb30b5db1dfabb701535a7 datapathConfiguration="&{false false false false false }" interface=lxcfd3ba189b09c k8sPodName=openstack/keystone-rabbit-init-7n86s labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=556c539588 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3847 ipv4=10.0.0.155 ipv6= k8sPodName=openstack/keystone-rabbit-init-7n86s subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=556c539588 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3847 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=1d3027ed-9898-4010-832c-9e2b905d4e7c,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=1d3027ed-9898-4010-832c-9e2b905d4e7c,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.155 ipv6= k8sPodName=openstack/keystone-rabbit-init-7n86s subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=1d3027ed-9898-4010-832c-9e2b905d4e7c;k8s:batch.kubernetes.io/job-name=keystone-rabbit-init;k8s:component=rabbit-init;k8s:controller-uid=1d3027ed-9898-4010-832c-9e2b905d4e7c;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-rabbit-init;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=556c539588 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3847 identity=11910 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=1d3027ed-9898-4010-832c-9e2b905d4e7c,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=1d3027ed-9898-4010-832c-9e2b905d4e7c,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.155 ipv6= k8sPodName=openstack/keystone-rabbit-init-7n86s oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=556c539588 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3847 identity=11910 ipv4=10.0.0.155 ipv6= k8sPodName=openstack/keystone-rabbit-init-7n86s subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=556c539588 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3847 identity=11910 ipv4=10.0.0.155 ipv6= k8sPodName=openstack/keystone-rabbit-init-7n86s subsys=endpoint level=info msg="Successful endpoint creation" containerID=556c539588 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3847 identity=11910 ipv4=10.0.0.155 ipv6= k8sPodName=openstack/keystone-rabbit-init-7n86s subsys=daemon level=info msg="Delete endpoint request" containerID=556c539588 endpointID=3847 k8sNamespace=openstack k8sPodName=keystone-rabbit-init-7n86s subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=1d3027ed-9898-4010-832c-9e2b905d4e7c k8s:batch.kubernetes.io/job-name=keystone-rabbit-init k8s:component=rabbit-init k8s:controller-uid=1d3027ed-9898-4010-832c-9e2b905d4e7c k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-rabbit-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=556c539588 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3847 identity=11910 ipv4=10.0.0.155 ipv6= k8sPodName=openstack/keystone-rabbit-init-7n86s subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.203 bc08a725-cd3b-4038-8a33-c85ea4952f31 default }" containerID=57ab2b8c53c1803d614df5af68e3c2a3cea903a3bed953a6a8becab2127094c0 datapathConfiguration="&{false false false false false }" interface=lxca0b5e75554e4 k8sPodName=openstack/keystone-domain-manage-rrgfs labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=57ab2b8c53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3847 ipv4=10.0.0.203 ipv6= k8sPodName=openstack/keystone-domain-manage-rrgfs subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=57ab2b8c53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3847 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=cec69cdd-bb00-47f2-b733-6e252f945740,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=cec69cdd-bb00-47f2-b733-6e252f945740,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.203 ipv6= k8sPodName=openstack/keystone-domain-manage-rrgfs subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=cec69cdd-bb00-47f2-b733-6e252f945740;k8s:batch.kubernetes.io/job-name=keystone-domain-manage;k8s:component=domain-manage;k8s:controller-uid=cec69cdd-bb00-47f2-b733-6e252f945740;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-domain-manage;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=57ab2b8c53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3847 identity=10172 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=cec69cdd-bb00-47f2-b733-6e252f945740,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=cec69cdd-bb00-47f2-b733-6e252f945740,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.203 ipv6= k8sPodName=openstack/keystone-domain-manage-rrgfs oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=57ab2b8c53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3847 identity=10172 ipv4=10.0.0.203 ipv6= k8sPodName=openstack/keystone-domain-manage-rrgfs subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=57ab2b8c53 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3847 identity=10172 ipv4=10.0.0.203 ipv6= k8sPodName=openstack/keystone-domain-manage-rrgfs subsys=endpoint level=info msg="Successful endpoint creation" containerID=57ab2b8c53 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3847 identity=10172 ipv4=10.0.0.203 ipv6= k8sPodName=openstack/keystone-domain-manage-rrgfs subsys=daemon level=info msg="Delete endpoint request" containerID=57ab2b8c53 endpointID=3847 k8sNamespace=openstack k8sPodName=keystone-domain-manage-rrgfs subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=cec69cdd-bb00-47f2-b733-6e252f945740 k8s:batch.kubernetes.io/job-name=keystone-domain-manage k8s:component=domain-manage k8s:controller-uid=cec69cdd-bb00-47f2-b733-6e252f945740 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-domain-manage k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=57ab2b8c53 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3847 identity=10172 ipv4=10.0.0.203 ipv6= k8sPodName=openstack/keystone-domain-manage-rrgfs subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.120 9ffb5b76-a0b1-4a5a-8a91-df1edaeba2b3 default }" containerID=48e4007ca53ce8b0b74c9de210eabfb922822bcb3bea4737c8b2f6fe027ff079 datapathConfiguration="&{false false false false false }" interface=lxcbe73fdebc68d k8sPodName=openstack/keystone-bootstrap-q8blf labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=48e4007ca5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=64 ipv4=10.0.0.120 ipv6= k8sPodName=openstack/keystone-bootstrap-q8blf subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=48e4007ca5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=64 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=304117f4-c569-46a9-9418-624aa068a990,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=304117f4-c569-46a9-9418-624aa068a990,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.120 ipv6= k8sPodName=openstack/keystone-bootstrap-q8blf subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=304117f4-c569-46a9-9418-624aa068a990;k8s:batch.kubernetes.io/job-name=keystone-bootstrap;k8s:component=bootstrap;k8s:controller-uid=304117f4-c569-46a9-9418-624aa068a990;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-bootstrap;k8s:release_group=keystone;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=48e4007ca5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=64 identity=54181 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=304117f4-c569-46a9-9418-624aa068a990,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=304117f4-c569-46a9-9418-624aa068a990,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.120 ipv6= k8sPodName=openstack/keystone-bootstrap-q8blf oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=48e4007ca5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=64 identity=54181 ipv4=10.0.0.120 ipv6= k8sPodName=openstack/keystone-bootstrap-q8blf subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=48e4007ca5 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=64 identity=54181 ipv4=10.0.0.120 ipv6= k8sPodName=openstack/keystone-bootstrap-q8blf subsys=endpoint level=info msg="Successful endpoint creation" containerID=48e4007ca5 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=64 identity=54181 ipv4=10.0.0.120 ipv6= k8sPodName=openstack/keystone-bootstrap-q8blf subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=48e4007ca5 endpointID=64 k8sNamespace=openstack k8sPodName=keystone-bootstrap-q8blf subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=304117f4-c569-46a9-9418-624aa068a990 k8s:batch.kubernetes.io/job-name=keystone-bootstrap k8s:component=bootstrap k8s:controller-uid=304117f4-c569-46a9-9418-624aa068a990 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-bootstrap k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=48e4007ca5 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=64 identity=54181 ipv4=10.0.0.120 ipv6= k8sPodName=openstack/keystone-bootstrap-q8blf subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.49 175d448e-9599-4b2c-a8e5-c79ea9c8a1a3 default }" containerID=8d9180d33e28309fe31e1a1b04a18d7140ae5ec117f41c63929801cce6fe3775 datapathConfiguration="&{false false false false false }" interface=lxc3ddeb34fd862 k8sPodName=openstack/horizon-db-init-vtc4r labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=8d9180d33e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2731 ipv4=10.0.0.49 ipv6= k8sPodName=openstack/horizon-db-init-vtc4r subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=8d9180d33e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2731 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=2c314a44-9a5f-4eed-a74d-025a10b547e4,k8s:batch.kubernetes.io/job-name=horizon-db-init,k8s:component=db-init,k8s:controller-uid=2c314a44-9a5f-4eed-a74d-025a10b547e4,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-init,k8s:release_group=horizon" ipv4=10.0.0.49 ipv6= k8sPodName=openstack/horizon-db-init-vtc4r subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:batch.kubernetes.io/controller-uid=2c314a44-9a5f-4eed-a74d-025a10b547e4;k8s:batch.kubernetes.io/job-name=horizon-db-init;k8s:component=db-init;k8s:controller-uid=2c314a44-9a5f-4eed-a74d-025a10b547e4;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=horizon-db-init;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=8d9180d33e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2731 identity=36444 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=2c314a44-9a5f-4eed-a74d-025a10b547e4,k8s:batch.kubernetes.io/job-name=horizon-db-init,k8s:component=db-init,k8s:controller-uid=2c314a44-9a5f-4eed-a74d-025a10b547e4,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-init,k8s:release_group=horizon" ipv4=10.0.0.49 ipv6= k8sPodName=openstack/horizon-db-init-vtc4r oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=8d9180d33e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2731 identity=36444 ipv4=10.0.0.49 ipv6= k8sPodName=openstack/horizon-db-init-vtc4r subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=8d9180d33e datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2731 identity=36444 ipv4=10.0.0.49 ipv6= k8sPodName=openstack/horizon-db-init-vtc4r subsys=endpoint level=info msg="Successful endpoint creation" containerID=8d9180d33e datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2731 identity=36444 ipv4=10.0.0.49 ipv6= k8sPodName=openstack/horizon-db-init-vtc4r subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.251 31f82370-1611-44f6-b267-9aea24b115d8 default }" containerID=feb053e17d955004d74b9937d6d75789c5eb22ee4fc92dce94ac831bf8bc6d99 datapathConfiguration="&{false false false false false }" interface=lxc37ac556f89ad k8sPodName=openstack/horizon-b8f8c546b-ft4rz labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=feb053e17d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3613 ipv4=10.0.0.251 ipv6= k8sPodName=openstack/horizon-b8f8c546b-ft4rz subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=feb053e17d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3613 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.251 ipv6= k8sPodName=openstack/horizon-b8f8c546b-ft4rz subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=feb053e17d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3613 identity=63688 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.251 ipv6= k8sPodName=openstack/horizon-b8f8c546b-ft4rz oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=feb053e17d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3613 identity=63688 ipv4=10.0.0.251 ipv6= k8sPodName=openstack/horizon-b8f8c546b-ft4rz subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.200 d8d73fa9-524e-408c-8a93-32f45b32ef5a default }" containerID=4b26b10b912ab66b064b7702991fc4d658416b74ead313ee3fd2fb14cac960db datapathConfiguration="&{false false false false false }" interface=lxc12a61ec3285e k8sPodName=openstack/horizon-b8f8c546b-hf6wd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=4b26b10b91 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2401 ipv4=10.0.0.200 ipv6= k8sPodName=openstack/horizon-b8f8c546b-hf6wd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=4b26b10b91 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2401 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.200 ipv6= k8sPodName=openstack/horizon-b8f8c546b-hf6wd subsys=endpoint level=info msg="Identity of endpoint changed" containerID=4b26b10b91 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2401 identity=63688 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.200 ipv6= k8sPodName=openstack/horizon-b8f8c546b-hf6wd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=4b26b10b91 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2401 identity=63688 ipv4=10.0.0.200 ipv6= k8sPodName=openstack/horizon-b8f8c546b-hf6wd subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.230 b4bc4059-cb88-439b-8da3-f29ada305fd2 default }" containerID=8068c68b9ffe90b06d5bead2c6a91f7d4c3e9c3ca489885cd699d2996415e0a5 datapathConfiguration="&{false false false false false }" interface=lxcbda19ac6d37e k8sPodName=openstack/horizon-b8f8c546b-2nxkd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=8068c68b9f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1954 ipv4=10.0.0.230 ipv6= k8sPodName=openstack/horizon-b8f8c546b-2nxkd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=8068c68b9f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1954 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.230 ipv6= k8sPodName=openstack/horizon-b8f8c546b-2nxkd subsys=endpoint level=info msg="Identity of endpoint changed" containerID=8068c68b9f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1954 identity=63688 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.230 ipv6= k8sPodName=openstack/horizon-b8f8c546b-2nxkd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=8068c68b9f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1954 identity=63688 ipv4=10.0.0.230 ipv6= k8sPodName=openstack/horizon-b8f8c546b-2nxkd subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=feb053e17d datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3613 identity=63688 ipv4=10.0.0.251 ipv6= k8sPodName=openstack/horizon-b8f8c546b-ft4rz subsys=endpoint level=info msg="Successful endpoint creation" containerID=feb053e17d datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3613 identity=63688 ipv4=10.0.0.251 ipv6= k8sPodName=openstack/horizon-b8f8c546b-ft4rz subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=4b26b10b91 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2401 identity=63688 ipv4=10.0.0.200 ipv6= k8sPodName=openstack/horizon-b8f8c546b-hf6wd subsys=endpoint level=info msg="Successful endpoint creation" containerID=4b26b10b91 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2401 identity=63688 ipv4=10.0.0.200 ipv6= k8sPodName=openstack/horizon-b8f8c546b-hf6wd subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=8068c68b9f datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1954 identity=63688 ipv4=10.0.0.230 ipv6= k8sPodName=openstack/horizon-b8f8c546b-2nxkd subsys=endpoint level=info msg="Successful endpoint creation" containerID=8068c68b9f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1954 identity=63688 ipv4=10.0.0.230 ipv6= k8sPodName=openstack/horizon-b8f8c546b-2nxkd subsys=daemon level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=8d9180d33e endpointID=2731 k8sNamespace=openstack k8sPodName=horizon-db-init-vtc4r subsys=daemon level=info msg="Releasing key" key="[k8s:application=horizon k8s:batch.kubernetes.io/controller-uid=2c314a44-9a5f-4eed-a74d-025a10b547e4 k8s:batch.kubernetes.io/job-name=horizon-db-init k8s:component=db-init k8s:controller-uid=2c314a44-9a5f-4eed-a74d-025a10b547e4 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=horizon-db-init k8s:release_group=horizon]" subsys=allocator level=info msg="Removed endpoint" containerID=8d9180d33e datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2731 identity=36444 ipv4=10.0.0.49 ipv6= k8sPodName=openstack/horizon-db-init-vtc4r subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.184 55b68a17-3d98-4f15-be10-68df21b170cb default }" containerID=3f351c177527085fecf4261d2430b75b84a843c09cd1329456a037d97c1d4e66 datapathConfiguration="&{false false false false false }" interface=lxc544a4c592a1b k8sPodName=openstack/horizon-db-sync-xpzzr labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=3f351c1775 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2870 ipv4=10.0.0.184 ipv6= k8sPodName=openstack/horizon-db-sync-xpzzr subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=3f351c1775 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2870 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=8db2d4f0-615e-4a30-af22-de513100effa,k8s:batch.kubernetes.io/job-name=horizon-db-sync,k8s:component=db-sync,k8s:controller-uid=8db2d4f0-615e-4a30-af22-de513100effa,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-sync,k8s:release_group=horizon" ipv4=10.0.0.184 ipv6= k8sPodName=openstack/horizon-db-sync-xpzzr subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:batch.kubernetes.io/controller-uid=8db2d4f0-615e-4a30-af22-de513100effa;k8s:batch.kubernetes.io/job-name=horizon-db-sync;k8s:component=db-sync;k8s:controller-uid=8db2d4f0-615e-4a30-af22-de513100effa;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=horizon-db-sync;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=3f351c1775 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2870 identity=772 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=8db2d4f0-615e-4a30-af22-de513100effa,k8s:batch.kubernetes.io/job-name=horizon-db-sync,k8s:component=db-sync,k8s:controller-uid=8db2d4f0-615e-4a30-af22-de513100effa,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-sync,k8s:release_group=horizon" ipv4=10.0.0.184 ipv6= k8sPodName=openstack/horizon-db-sync-xpzzr oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=3f351c1775 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2870 identity=772 ipv4=10.0.0.184 ipv6= k8sPodName=openstack/horizon-db-sync-xpzzr subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=3f351c1775 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2870 identity=772 ipv4=10.0.0.184 ipv6= k8sPodName=openstack/horizon-db-sync-xpzzr subsys=endpoint level=info msg="Successful endpoint creation" containerID=3f351c1775 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2870 identity=772 ipv4=10.0.0.184 ipv6= k8sPodName=openstack/horizon-db-sync-xpzzr subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=3f351c1775 endpointID=2870 k8sNamespace=openstack k8sPodName=horizon-db-sync-xpzzr subsys=daemon level=info msg="Releasing key" key="[k8s:application=horizon k8s:batch.kubernetes.io/controller-uid=8db2d4f0-615e-4a30-af22-de513100effa k8s:batch.kubernetes.io/job-name=horizon-db-sync k8s:component=db-sync k8s:controller-uid=8db2d4f0-615e-4a30-af22-de513100effa k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=horizon-db-sync k8s:release_group=horizon]" subsys=allocator level=info msg="Removed endpoint" containerID=3f351c1775 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2870 identity=772 ipv4=10.0.0.184 ipv6= k8sPodName=openstack/horizon-db-sync-xpzzr subsys=endpoint