level=info msg="Memory available for map entries (0.003% of 16764960768B): 41912401B" subsys=config level=info msg="option bpf-ct-global-tcp-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-ct-global-any-max set by dynamic sizing to 73530" subsys=config level=info msg="option bpf-nat-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-neigh-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-sock-rev-map-max set by dynamic sizing to 73530" subsys=config level=info msg=" --agent-health-port='9879'" subsys=daemon level=info msg=" --agent-labels=''" subsys=daemon level=info msg=" --agent-liveness-update-interval='1s'" subsys=daemon level=info msg=" --agent-not-ready-taint-key='node.cilium.io/agent-not-ready'" subsys=daemon level=info msg=" --allocator-list-timeout='3m0s'" subsys=daemon level=info msg=" --allow-icmp-frag-needed='true'" subsys=daemon level=info msg=" --allow-localhost='auto'" subsys=daemon level=info msg=" --annotate-k8s-node='false'" subsys=daemon level=info msg=" --api-rate-limit=''" subsys=daemon level=info msg=" --arping-refresh-period='30s'" subsys=daemon level=info msg=" --auto-create-cilium-node-resource='true'" subsys=daemon level=info msg=" --auto-direct-node-routes='false'" subsys=daemon level=info msg=" --bgp-announce-lb-ip='false'" subsys=daemon level=info msg=" --bgp-announce-pod-cidr='false'" subsys=daemon level=info msg=" --bgp-config-path='/var/lib/cilium/bgp/config.yaml'" subsys=daemon level=info msg=" --bpf-auth-map-max='524288'" subsys=daemon level=info msg=" --bpf-ct-global-any-max='262144'" subsys=daemon level=info msg=" --bpf-ct-global-tcp-max='524288'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-fin='10s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-syn='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp-grace='1m0s'" subsys=daemon level=info msg=" --bpf-filter-priority='1'" subsys=daemon level=info msg=" --bpf-fragments-map-max='8192'" subsys=daemon level=info msg=" --bpf-lb-acceleration='disabled'" subsys=daemon level=info msg=" --bpf-lb-affinity-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-algorithm='random'" subsys=daemon level=info msg=" --bpf-lb-dev-ip-addr-inherit=''" subsys=daemon level=info msg=" --bpf-lb-dsr-dispatch='opt'" subsys=daemon level=info msg=" --bpf-lb-dsr-l4-xlate='frontend'" subsys=daemon level=info msg=" --bpf-lb-external-clusterip='false'" subsys=daemon level=info msg=" --bpf-lb-maglev-hash-seed='JLfvgnHc2kaSUFaI'" subsys=daemon level=info msg=" --bpf-lb-maglev-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-maglev-table-size='16381'" subsys=daemon level=info msg=" --bpf-lb-map-max='65536'" subsys=daemon level=info msg=" --bpf-lb-mode='snat'" subsys=daemon level=info msg=" --bpf-lb-rev-nat-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-rss-ipv4-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-rss-ipv6-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-service-backend-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-service-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-sock='false'" subsys=daemon level=info msg=" --bpf-lb-sock-hostns-only='false'" subsys=daemon level=info msg=" --bpf-lb-source-range-map-max='0'" subsys=daemon level=info msg=" --bpf-map-dynamic-size-ratio='0.0025'" subsys=daemon level=info msg=" --bpf-map-event-buffers=''" subsys=daemon level=info msg=" --bpf-nat-global-max='524288'" subsys=daemon level=info msg=" --bpf-neigh-global-max='524288'" subsys=daemon level=info msg=" --bpf-policy-map-full-reconciliation-interval='15m0s'" subsys=daemon level=info msg=" --bpf-policy-map-max='16384'" subsys=daemon level=info msg=" --bpf-root='/sys/fs/bpf'" subsys=daemon level=info msg=" --bpf-sock-rev-map-max='262144'" subsys=daemon level=info msg=" --bypass-ip-availability-upon-restore='false'" subsys=daemon level=info msg=" --certificates-directory='/var/run/cilium/certs'" subsys=daemon level=info msg=" --cflags=''" subsys=daemon level=info msg=" --cgroup-root='/run/cilium/cgroupv2'" subsys=daemon level=info msg=" --cilium-endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --cluster-health-port='4240'" subsys=daemon level=info msg=" --cluster-id='0'" subsys=daemon level=info msg=" --cluster-name='default'" subsys=daemon level=info msg=" --cluster-pool-ipv4-cidr='10.0.0.0/8'" subsys=daemon level=info msg=" --cluster-pool-ipv4-mask-size='24'" subsys=daemon level=info msg=" --clustermesh-config='/var/lib/cilium/clustermesh/'" subsys=daemon level=info msg=" --clustermesh-ip-identities-sync-timeout='1m0s'" subsys=daemon level=info msg=" --cmdref=''" subsys=daemon level=info msg=" --cni-chaining-mode='none'" subsys=daemon level=info msg=" --cni-chaining-target=''" subsys=daemon level=info msg=" --cni-exclusive='true'" subsys=daemon level=info msg=" --cni-external-routing='false'" subsys=daemon level=info msg=" --cni-log-file='/var/run/cilium/cilium-cni.log'" subsys=daemon level=info msg=" --cnp-node-status-gc-interval='0s'" subsys=daemon level=info msg=" --config=''" subsys=daemon level=info msg=" --config-dir='/tmp/cilium/config-map'" subsys=daemon level=info msg=" --config-sources='config-map:kube-system/cilium-config'" subsys=daemon level=info msg=" --conntrack-gc-interval='0s'" subsys=daemon level=info msg=" --conntrack-gc-max-interval='0s'" subsys=daemon level=info msg=" --crd-wait-timeout='5m0s'" subsys=daemon level=info msg=" --custom-cni-conf='false'" subsys=daemon level=info msg=" --datapath-mode='veth'" subsys=daemon level=info msg=" --debug='false'" subsys=daemon level=info msg=" --debug-verbose=''" subsys=daemon level=info msg=" --derive-masquerade-ip-addr-from-device=''" subsys=daemon level=info msg=" --devices=''" subsys=daemon level=info msg=" --direct-routing-device=''" subsys=daemon level=info msg=" --disable-cnp-status-updates='true'" subsys=daemon level=info msg=" --disable-endpoint-crd='false'" subsys=daemon level=info msg=" --disable-envoy-version-check='false'" subsys=daemon level=info msg=" --disable-iptables-feeder-rules=''" subsys=daemon level=info msg=" --dns-max-ips-per-restored-rule='1000'" subsys=daemon level=info msg=" --dns-policy-unload-on-shutdown='false'" subsys=daemon level=info msg=" --dnsproxy-concurrency-limit='0'" subsys=daemon level=info msg=" --dnsproxy-concurrency-processing-grace-period='0s'" subsys=daemon level=info msg=" --dnsproxy-enable-transparent-mode='true'" subsys=daemon level=info msg=" --dnsproxy-lock-count='128'" subsys=daemon level=info msg=" --dnsproxy-lock-timeout='500ms'" subsys=daemon level=info msg=" --egress-gateway-policy-map-max='16384'" subsys=daemon level=info msg=" --egress-gateway-reconciliation-trigger-interval='1s'" subsys=daemon level=info msg=" --egress-masquerade-interfaces=''" subsys=daemon level=info msg=" --egress-multi-home-ip-rule-compat='false'" subsys=daemon level=info msg=" --enable-auto-protect-node-port-range='true'" subsys=daemon level=info msg=" --enable-bandwidth-manager='false'" subsys=daemon level=info msg=" --enable-bbr='false'" subsys=daemon level=info msg=" --enable-bgp-control-plane='false'" subsys=daemon level=info msg=" --enable-bpf-clock-probe='false'" subsys=daemon level=info msg=" --enable-bpf-masquerade='false'" subsys=daemon level=info msg=" --enable-bpf-tproxy='false'" subsys=daemon level=info msg=" --enable-cilium-api-server-access='*'" subsys=daemon level=info msg=" --enable-cilium-endpoint-slice='false'" subsys=daemon level=info msg=" --enable-cilium-health-api-server-access='*'" subsys=daemon level=info msg=" --enable-custom-calls='false'" subsys=daemon level=info msg=" --enable-endpoint-health-checking='true'" subsys=daemon level=info msg=" --enable-endpoint-routes='false'" subsys=daemon level=info msg=" --enable-envoy-config='false'" subsys=daemon level=info msg=" --enable-external-ips='false'" subsys=daemon level=info msg=" --enable-health-check-nodeport='true'" subsys=daemon level=info msg=" --enable-health-checking='true'" subsys=daemon level=info msg=" --enable-high-scale-ipcache='false'" subsys=daemon level=info msg=" --enable-host-firewall='false'" subsys=daemon level=info msg=" --enable-host-legacy-routing='false'" subsys=daemon level=info msg=" --enable-host-port='false'" subsys=daemon level=info msg=" --enable-hubble='false'" subsys=daemon level=info msg=" --enable-hubble-recorder-api='true'" subsys=daemon level=info msg=" --enable-icmp-rules='true'" subsys=daemon level=info msg=" --enable-identity-mark='true'" subsys=daemon level=info msg=" --enable-ip-masq-agent='false'" subsys=daemon level=info msg=" --enable-ipsec='false'" subsys=daemon level=info msg=" --enable-ipsec-key-watcher='true'" subsys=daemon level=info msg=" --enable-ipv4='true'" subsys=daemon level=info msg=" --enable-ipv4-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv4-egress-gateway='false'" subsys=daemon level=info msg=" --enable-ipv4-fragment-tracking='true'" subsys=daemon level=info msg=" --enable-ipv4-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6='false'" subsys=daemon level=info msg=" --enable-ipv6-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv6-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6-ndp='false'" subsys=daemon level=info msg=" --enable-k8s='true'" subsys=daemon level=info msg=" --enable-k8s-api-discovery='false'" subsys=daemon level=info msg=" --enable-k8s-endpoint-slice='true'" subsys=daemon level=info msg=" --enable-k8s-event-handover='false'" subsys=daemon level=info msg=" --enable-k8s-networkpolicy='true'" subsys=daemon level=info msg=" --enable-k8s-terminating-endpoint='true'" subsys=daemon level=info msg=" --enable-l2-announcements='false'" subsys=daemon level=info msg=" --enable-l2-neigh-discovery='true'" subsys=daemon level=info msg=" --enable-l2-pod-announcements='false'" subsys=daemon level=info msg=" --enable-l7-proxy='true'" subsys=daemon level=info msg=" --enable-local-node-route='true'" subsys=daemon level=info msg=" --enable-local-redirect-policy='false'" subsys=daemon level=info msg=" --enable-mke='false'" subsys=daemon level=info msg=" --enable-monitor='true'" subsys=daemon level=info msg=" --enable-nat46x64-gateway='false'" subsys=daemon level=info msg=" --enable-node-port='false'" subsys=daemon level=info msg=" --enable-pmtu-discovery='false'" subsys=daemon level=info msg=" --enable-policy='default'" subsys=daemon level=info msg=" --enable-recorder='false'" subsys=daemon level=info msg=" --enable-remote-node-identity='true'" subsys=daemon level=info msg=" --enable-runtime-device-detection='false'" subsys=daemon level=info msg=" --enable-sctp='false'" subsys=daemon level=info msg=" --enable-service-topology='false'" subsys=daemon level=info msg=" --enable-session-affinity='false'" subsys=daemon level=info msg=" --enable-srv6='false'" subsys=daemon level=info msg=" --enable-stale-cilium-endpoint-cleanup='true'" subsys=daemon level=info msg=" --enable-svc-source-range-check='true'" subsys=daemon level=info msg=" --enable-tracing='false'" subsys=daemon level=info msg=" --enable-unreachable-routes='false'" subsys=daemon level=info msg=" --enable-vtep='false'" subsys=daemon level=info msg=" --enable-well-known-identities='false'" subsys=daemon level=info msg=" --enable-wireguard='false'" subsys=daemon level=info msg=" --enable-wireguard-userspace-fallback='false'" subsys=daemon level=info msg=" --enable-xdp-prefilter='false'" subsys=daemon level=info msg=" --enable-xt-socket-fallback='true'" subsys=daemon level=info msg=" --encrypt-interface=''" subsys=daemon level=info msg=" --encrypt-node='false'" subsys=daemon level=info msg=" --endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --endpoint-queue-size='25'" subsys=daemon level=info msg=" --endpoint-status=''" subsys=daemon level=info msg=" --envoy-config-timeout='2m0s'" subsys=daemon level=info msg=" --envoy-log=''" subsys=daemon level=info msg=" --exclude-local-address=''" subsys=daemon level=info msg=" --external-envoy-proxy='false'" subsys=daemon level=info msg=" --fixed-identity-mapping=''" subsys=daemon level=info msg=" --fqdn-regex-compile-lru-size='1024'" subsys=daemon level=info msg=" --gops-port='9890'" subsys=daemon level=info msg=" --http-403-msg=''" subsys=daemon level=info msg=" --http-idle-timeout='0'" subsys=daemon level=info msg=" --http-max-grpc-timeout='0'" subsys=daemon level=info msg=" --http-normalize-path='true'" subsys=daemon level=info msg=" --http-request-timeout='3600'" subsys=daemon level=info msg=" --http-retry-count='3'" subsys=daemon level=info msg=" --http-retry-timeout='0'" subsys=daemon level=info msg=" --hubble-disable-tls='false'" subsys=daemon level=info msg=" --hubble-event-buffer-capacity='4095'" subsys=daemon level=info msg=" --hubble-event-queue-size='0'" subsys=daemon level=info msg=" --hubble-export-file-compress='false'" subsys=daemon level=info msg=" --hubble-export-file-max-backups='5'" subsys=daemon level=info msg=" --hubble-export-file-max-size-mb='10'" subsys=daemon level=info msg=" --hubble-export-file-path=''" subsys=daemon level=info msg=" --hubble-listen-address=''" subsys=daemon level=info msg=" --hubble-metrics=''" subsys=daemon level=info msg=" --hubble-metrics-server=''" subsys=daemon level=info msg=" --hubble-monitor-events=''" subsys=daemon level=info msg=" --hubble-prefer-ipv6='false'" subsys=daemon level=info msg=" --hubble-recorder-sink-queue-size='1024'" subsys=daemon level=info msg=" --hubble-recorder-storage-path='/var/run/cilium/pcaps'" subsys=daemon level=info msg=" --hubble-skip-unknown-cgroup-ids='true'" subsys=daemon level=info msg=" --hubble-socket-path='/var/run/cilium/hubble.sock'" subsys=daemon level=info msg=" --hubble-tls-cert-file=''" subsys=daemon level=info msg=" --hubble-tls-client-ca-files=''" subsys=daemon level=info msg=" --hubble-tls-key-file=''" subsys=daemon level=info msg=" --identity-allocation-mode='crd'" subsys=daemon level=info msg=" --identity-change-grace-period='5s'" subsys=daemon level=info msg=" --identity-gc-interval='15m0s'" subsys=daemon level=info msg=" --identity-heartbeat-timeout='30m0s'" subsys=daemon level=info msg=" --identity-restore-grace-period='10m0s'" subsys=daemon level=info msg=" --install-egress-gateway-routes='false'" subsys=daemon level=info msg=" --install-iptables-rules='true'" subsys=daemon level=info msg=" --install-no-conntrack-iptables-rules='false'" subsys=daemon level=info msg=" --ip-allocation-timeout='2m0s'" subsys=daemon level=info msg=" --ip-masq-agent-config-path='/etc/config/ip-masq-agent'" subsys=daemon level=info msg=" --ipam='cluster-pool'" subsys=daemon level=info msg=" --ipam-cilium-node-update-rate='15s'" subsys=daemon level=info msg=" --ipam-multi-pool-pre-allocation='default=8'" subsys=daemon level=info msg=" --ipsec-key-file=''" subsys=daemon level=info msg=" --ipsec-key-rotation-duration='5m0s'" subsys=daemon level=info msg=" --iptables-lock-timeout='5s'" subsys=daemon level=info msg=" --iptables-random-fully='false'" subsys=daemon level=info msg=" --ipv4-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv4-node='auto'" subsys=daemon level=info msg=" --ipv4-pod-subnets=''" subsys=daemon level=info msg=" --ipv4-range='auto'" subsys=daemon level=info msg=" --ipv4-service-loopback-address='169.254.42.1'" subsys=daemon level=info msg=" --ipv4-service-range='auto'" subsys=daemon level=info msg=" --ipv6-cluster-alloc-cidr='f00d::/64'" subsys=daemon level=info msg=" --ipv6-mcast-device=''" subsys=daemon level=info msg=" --ipv6-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv6-node='auto'" subsys=daemon level=info msg=" --ipv6-pod-subnets=''" subsys=daemon level=info msg=" --ipv6-range='auto'" subsys=daemon level=info msg=" --ipv6-service-range='auto'" subsys=daemon level=info msg=" --join-cluster='false'" subsys=daemon level=info msg=" --k8s-api-server=''" subsys=daemon level=info msg=" --k8s-client-burst='10'" subsys=daemon level=info msg=" --k8s-client-qps='5'" subsys=daemon level=info msg=" --k8s-heartbeat-timeout='30s'" subsys=daemon level=info msg=" --k8s-kubeconfig-path=''" subsys=daemon level=info msg=" --k8s-namespace='kube-system'" subsys=daemon level=info msg=" --k8s-require-ipv4-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-require-ipv6-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-service-cache-size='128'" subsys=daemon level=info msg=" --k8s-service-proxy-name=''" subsys=daemon level=info msg=" --k8s-sync-timeout='3m0s'" subsys=daemon level=info msg=" --k8s-watcher-endpoint-selector='metadata.name!=kube-scheduler,metadata.name!=kube-controller-manager,metadata.name!=etcd-operator,metadata.name!=gcp-controller-manager'" subsys=daemon level=info msg=" --keep-config='false'" subsys=daemon level=info msg=" --kube-proxy-replacement='disabled'" subsys=daemon level=info msg=" --kube-proxy-replacement-healthz-bind-address=''" subsys=daemon level=info msg=" --kvstore=''" subsys=daemon level=info msg=" --kvstore-connectivity-timeout='2m0s'" subsys=daemon level=info msg=" --kvstore-lease-ttl='15m0s'" subsys=daemon level=info msg=" --kvstore-max-consecutive-quorum-errors='2'" subsys=daemon level=info msg=" --kvstore-opt=''" subsys=daemon level=info msg=" --kvstore-periodic-sync='5m0s'" subsys=daemon level=info msg=" --l2-announcements-lease-duration='15s'" subsys=daemon level=info msg=" --l2-announcements-renew-deadline='5s'" subsys=daemon level=info msg=" --l2-announcements-retry-period='2s'" subsys=daemon level=info msg=" --l2-pod-announcements-interface=''" subsys=daemon level=info msg=" --label-prefix-file=''" subsys=daemon level=info msg=" --labels=''" subsys=daemon level=info msg=" --lib-dir='/var/lib/cilium'" subsys=daemon level=info msg=" --local-max-addr-scope='252'" subsys=daemon level=info msg=" --local-router-ipv4=''" subsys=daemon level=info msg=" --local-router-ipv6=''" subsys=daemon level=info msg=" --log-driver=''" subsys=daemon level=info msg=" --log-opt=''" subsys=daemon level=info msg=" --log-system-load='false'" subsys=daemon level=info msg=" --max-controller-interval='0'" subsys=daemon level=info msg=" --mesh-auth-enabled='true'" subsys=daemon level=info msg=" --mesh-auth-gc-interval='5m0s'" subsys=daemon level=info msg=" --mesh-auth-mutual-listener-port='0'" subsys=daemon level=info msg=" --mesh-auth-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-rotated-identities-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-signal-backoff-duration='1s'" subsys=daemon level=info msg=" --mesh-auth-spiffe-trust-domain='spiffe.cilium'" subsys=daemon level=info msg=" --mesh-auth-spire-admin-socket=''" subsys=daemon level=info msg=" --metrics=''" subsys=daemon level=info msg=" --mke-cgroup-mount=''" subsys=daemon level=info msg=" --monitor-aggregation='medium'" subsys=daemon level=info msg=" --monitor-aggregation-flags='all'" subsys=daemon level=info msg=" --monitor-aggregation-interval='5s'" subsys=daemon level=info msg=" --monitor-queue-size='0'" subsys=daemon level=info msg=" --mtu='0'" subsys=daemon level=info msg=" --node-encryption-opt-out-labels='node-role.kubernetes.io/control-plane'" subsys=daemon level=info msg=" --node-port-acceleration='disabled'" subsys=daemon level=info msg=" --node-port-algorithm='random'" subsys=daemon level=info msg=" --node-port-bind-protection='true'" subsys=daemon level=info msg=" --node-port-mode='snat'" subsys=daemon level=info msg=" --node-port-range='30000,32767'" subsys=daemon level=info msg=" --nodes-gc-interval='5m0s'" subsys=daemon level=info msg=" --operator-api-serve-addr='127.0.0.1:9234'" subsys=daemon level=info msg=" --policy-audit-mode='false'" subsys=daemon level=info msg=" --policy-queue-size='100'" subsys=daemon level=info msg=" --policy-trigger-interval='1s'" subsys=daemon level=info msg=" --pprof='false'" subsys=daemon level=info msg=" --pprof-address='localhost'" subsys=daemon level=info msg=" --pprof-port='6060'" subsys=daemon level=info msg=" --preallocate-bpf-maps='false'" subsys=daemon level=info msg=" --prepend-iptables-chains='true'" subsys=daemon level=info msg=" --procfs='/host/proc'" subsys=daemon level=info msg=" --prometheus-serve-addr=':9962'" subsys=daemon level=info msg=" --proxy-connect-timeout='2'" subsys=daemon level=info msg=" --proxy-gid='1337'" subsys=daemon level=info msg=" --proxy-idle-timeout-seconds='60'" subsys=daemon level=info msg=" --proxy-max-connection-duration-seconds='0'" subsys=daemon level=info msg=" --proxy-max-requests-per-connection='0'" subsys=daemon level=info msg=" --proxy-prometheus-port='9964'" subsys=daemon level=info msg=" --read-cni-conf=''" subsys=daemon level=info msg=" --remove-cilium-node-taints='true'" subsys=daemon level=info msg=" --restore='true'" subsys=daemon level=info msg=" --route-metric='0'" subsys=daemon level=info msg=" --routing-mode='tunnel'" subsys=daemon level=info msg=" --set-cilium-is-up-condition='true'" subsys=daemon level=info msg=" --set-cilium-node-taints='true'" subsys=daemon level=info msg=" --sidecar-istio-proxy-image='cilium/istio_proxy'" subsys=daemon level=info msg=" --single-cluster-route='false'" subsys=daemon level=info msg=" --skip-cnp-status-startup-clean='false'" subsys=daemon level=info msg=" --socket-path='/var/run/cilium/cilium.sock'" subsys=daemon level=info msg=" --srv6-encap-mode='reduced'" subsys=daemon level=info msg=" --state-dir='/var/run/cilium'" subsys=daemon level=info msg=" --synchronize-k8s-nodes='true'" subsys=daemon level=info msg=" --tofqdns-dns-reject-response-code='refused'" subsys=daemon level=info msg=" --tofqdns-enable-dns-compression='true'" subsys=daemon level=info msg=" --tofqdns-endpoint-max-ip-per-hostname='50'" subsys=daemon level=info msg=" --tofqdns-idle-connection-grace-period='0s'" subsys=daemon level=info msg=" --tofqdns-max-deferred-connection-deletes='10000'" subsys=daemon level=info msg=" --tofqdns-min-ttl='0'" subsys=daemon level=info msg=" --tofqdns-pre-cache=''" subsys=daemon level=info msg=" --tofqdns-proxy-port='0'" subsys=daemon level=info msg=" --tofqdns-proxy-response-max-delay='100ms'" subsys=daemon level=info msg=" --trace-payloadlen='128'" subsys=daemon level=info msg=" --trace-sock='true'" subsys=daemon level=info msg=" --tunnel=''" subsys=daemon level=info msg=" --tunnel-port='6082'" subsys=daemon level=info msg=" --tunnel-protocol='geneve'" subsys=daemon level=info msg=" --unmanaged-pod-watcher-interval='15'" subsys=daemon level=info msg=" --use-cilium-internal-ip-for-ipsec='false'" subsys=daemon level=info msg=" --version='false'" subsys=daemon level=info msg=" --vlan-bpf-bypass=''" subsys=daemon level=info msg=" --vtep-cidr=''" subsys=daemon level=info msg=" --vtep-endpoint=''" subsys=daemon level=info msg=" --vtep-mac=''" subsys=daemon level=info msg=" --vtep-mask=''" subsys=daemon level=info msg=" --wireguard-encapsulate='false'" subsys=daemon level=info msg=" --write-cni-conf-when-ready='/host/etc/cni/net.d/05-cilium.conflist'" subsys=daemon level=info msg=" _ _ _" subsys=daemon level=info msg=" ___|_| |_|_ _ _____" subsys=daemon level=info msg="| _| | | | | | |" subsys=daemon level=info msg="|___|_|_|_|___|_|_|_|" subsys=daemon level=info msg="Cilium 1.14.8 cf6e022e 2024-03-13T12:23:35-04:00 go version go1.21.8 linux/amd64" subsys=daemon level=info msg="clang (10.0.0) and kernel (5.15.0) versions: OK!" subsys=linux-datapath level=info msg="linking environment: OK!" subsys=linux-datapath level=info msg="Kernel config file not found: if the agent fails to start, check the system requirements at https://docs.cilium.io/en/stable/operations/system_requirements" subsys=probes level=info msg="Detected mounted BPF filesystem at /sys/fs/bpf" subsys=bpf level=info msg="Mounted cgroupv2 filesystem at /run/cilium/cgroupv2" subsys=cgroups level=info msg="Parsing base label prefixes from default label list" subsys=labels-filter level=info msg="Parsing additional label prefixes from user inputs: []" subsys=labels-filter level=info msg="Final label prefixes to be used for identity evaluation:" subsys=labels-filter level=info msg=" - reserved:.*" subsys=labels-filter level=info msg=" - :io\\.kubernetes\\.pod\\.namespace" subsys=labels-filter level=info msg=" - :io\\.cilium\\.k8s\\.namespace\\.labels" subsys=labels-filter level=info msg=" - :app\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:io\\.kubernetes" subsys=labels-filter level=info msg=" - !:kubernetes\\.io" subsys=labels-filter level=info msg=" - !:.*beta\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:k8s\\.io" subsys=labels-filter level=info msg=" - !:pod-template-generation" subsys=labels-filter level=info msg=" - !:pod-template-hash" subsys=labels-filter level=info msg=" - !:controller-revision-hash" subsys=labels-filter level=info msg=" - !:annotation.*" subsys=labels-filter level=info msg=" - !:etcd_node" subsys=labels-filter level=info msg=Invoked duration=2.513921ms function="pprof.glob..func1 (cell.go:50)" subsys=hive level=info msg=Invoked duration="152.636µs" function="gops.registerGopsHooks (cell.go:38)" subsys=hive level=info msg=Invoked duration="978.599µs" function="metrics.NewRegistry (registry.go:65)" subsys=hive level=info msg=Invoked duration="7.88µs" function="metrics.glob..func1 (cell.go:12)" subsys=hive level=info msg="Spire Delegate API Client is disabled as no socket path is configured" subsys=spire-delegate level=info msg="Mutual authentication handler is disabled as no port is configured" subsys=auth level=info msg=Invoked duration=98.787677ms function="cmd.glob..func4 (daemon_main.go:1607)" subsys=hive level=info msg=Invoked duration="12.971µs" function="gc.registerSignalHandler (cell.go:47)" subsys=hive level=info msg=Invoked duration="17.371µs" function="utime.initUtimeSync (cell.go:29)" subsys=hive level=info msg=Invoked duration="52.902µs" function="agentliveness.newAgentLivenessUpdater (agent_liveness.go:43)" subsys=hive level=info msg=Invoked duration="59.172µs" function="l2responder.NewL2ResponderReconciler (l2responder.go:63)" subsys=hive level=info msg=Invoked duration="68.303µs" function="garp.newGARPProcessor (processor.go:27)" subsys=hive level=info msg=Starting subsys=hive level=info msg="Started gops server" address="127.0.0.1:9890" subsys=gops level=info msg="Start hook executed" duration="471.209µs" function="gops.registerGopsHooks.func1 (cell.go:43)" subsys=hive level=info msg="Start hook executed" duration="1.821µs" function="metrics.NewRegistry.func1 (registry.go:86)" subsys=hive level=info msg="Establishing connection to apiserver" host="https://10.96.0.1:443" subsys=k8s-client level=info msg="Serving prometheus metrics on :9962" subsys=metrics level=info msg="Connected to apiserver" subsys=k8s-client level=info msg="Start hook executed" duration=8.305804ms function="client.(*compositeClientset).onStart" subsys=hive level=info msg="Start hook executed" duration=8.527553ms function="authmap.newAuthMap.func1 (cell.go:27)" subsys=hive level=info msg="Start hook executed" duration="40.612µs" function="configmap.newMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="43.572µs" function="signalmap.newMap.func1 (cell.go:44)" subsys=hive level=info msg="Start hook executed" duration="212.589µs" function="nodemap.newNodeMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="96.674µs" function="eventsmap.newEventsMap.func1 (cell.go:35)" subsys=hive level=info msg="Start hook executed" duration="85.314µs" function="*cni.cniConfigManager.Start" subsys=hive level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Wrote CNI configuration file to /host/etc/cni/net.d/05-cilium.conflist" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Start hook executed" duration=37.139155ms function="datapath.newDatapath.func1 (cells.go:113)" subsys=hive level=info msg="Restored 0 node IDs from the BPF map" subsys=linux-datapath level=info msg="Start hook executed" duration="87.713µs" function="datapath.newDatapath.func2 (cells.go:126)" subsys=hive level=info msg="Start hook executed" duration="13.041µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Node].Start" subsys=hive level=info msg="Start hook executed" duration="7.88µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNode].Start" subsys=hive level=info msg="Using autogenerated IPv4 allocation range" subsys=node v4Prefix=10.216.0.0/16 level=warning msg="github.com/cilium/cilium/pkg/k8s/resource/resource.go:305: failed to list *v2.CiliumNode: the server could not find the requested resource (get ciliumnodes.cilium.io)" subsys=klog level=error msg=k8sError error="github.com/cilium/cilium/pkg/k8s/resource/resource.go:305: Failed to watch *v2.CiliumNode: failed to list *v2.CiliumNode: the server could not find the requested resource (get ciliumnodes.cilium.io)" subsys=k8s level=info msg="no local ciliumnode found, will not restore cilium internal ips from k8s" subsys=daemon level=info msg="Start hook executed" duration=1.603602568s function="node.NewLocalNodeStore.func1 (local_node_store.go:76)" subsys=hive level=info msg="Start hook executed" duration="4.32µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration=100.530724ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration="11.7µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Using discoveryv1.EndpointSlice" subsys=k8s level=info msg="Start hook executed" duration=100.572576ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Start hook executed" duration="2.49µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Pod].Start" subsys=hive level=info msg="Start hook executed" duration="1.051µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Namespace].Start" subsys=hive level=info msg="Start hook executed" duration="2.51µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="1.24µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumClusterwideNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="1.06µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumCIDRGroup].Start" subsys=hive level=info msg="Start hook executed" duration="16.97µs" function="endpointmanager.newDefaultEndpointManager.func1 (cell.go:203)" subsys=hive level=info msg="Start hook executed" duration="12.39µs" function="cmd.newPolicyTrifecta.func1 (policy.go:135)" subsys=hive level=info msg="Start hook executed" duration="57.672µs" function="*manager.manager.Start" subsys=hive level=info msg="Serving cilium node monitor v1.2 API at unix:///var/run/cilium/monitor1_2.sock" subsys=monitor-agent level=info msg="Start hook executed" duration="299.322µs" function="agent.newMonitorAgent.func1 (cell.go:61)" subsys=hive level=info msg="Start hook executed" duration="2.18µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumL2AnnouncementPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="6.03µs" function="*job.group.Start" subsys=hive level=info msg="Envoy: Starting xDS gRPC server listening on /var/run/cilium/envoy/sockets/xds.sock" subsys=envoy-manager level=info msg="Start hook executed" duration="313.943µs" function="proxy.newProxy.func1 (cell.go:55)" subsys=hive level=info msg="Start hook executed" duration="440.487µs" function="signal.provideSignalManager.func1 (cell.go:25)" subsys=hive level=info msg="Datapath signal listener running" subsys=signal level=info msg="Start hook executed" duration="961.389µs" function="auth.registerAuthManager.func1 (cell.go:109)" subsys=hive level=info msg="Start hook executed" duration="3.04µs" function="auth.registerGCJobs.func1 (cell.go:158)" subsys=hive level=info msg="Start hook executed" duration="31.142µs" function="*job.group.Start" subsys=hive level=warning msg="Deprecated value for --kube-proxy-replacement: disabled (use either \"true\", or \"false\")" subsys=daemon level=info msg="Auto-disabling \"enable-node-port\", \"enable-external-ips\", \"bpf-lb-sock\", \"enable-host-port\" features and falling back to \"enable-host-legacy-routing\"" subsys=daemon level=info msg="Inheriting MTU from external network interface" device=ens3 ipAddr=199.204.45.216 mtu=1500 subsys=mtu level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_ipcache, recreating and re-pinning map cilium_ipcache" file-path=/sys/fs/bpf/tc/globals/cilium_ipcache name=cilium_ipcache subsys=bpf level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_tunnel_map, recreating and re-pinning map cilium_tunnel_map" file-path=/sys/fs/bpf/tc/globals/cilium_tunnel_map name=cilium_tunnel_map subsys=bpf level=info msg="Restored services from maps" failedServices=0 restoredServices=0 subsys=service level=info msg="Restored backends from maps" failedBackends=0 restoredBackends=0 skippedBackends=0 subsys=service level=info msg="Reading old endpoints..." subsys=daemon level=info msg="No old endpoints found." subsys=daemon level=info msg="Waiting until all Cilium CRDs are available" subsys=k8s level=info msg="All Cilium CRDs have been found and are available" subsys=k8s level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=info msg="Successfully created CiliumNode resource" subsys=nodediscovery level=warning msg="Unable to create CiliumNode resource, will retry" error="ciliumnodes.cilium.io \"instance\" already exists" subsys=nodediscovery level=info msg="Retrieved node information from cilium node" nodeName=instance subsys=k8s level=warning msg="Waiting for k8s node information" error="required IPv4 PodCIDR not available" subsys=k8s level=info msg="Retrieved node information from cilium node" nodeName=instance subsys=k8s level=info msg="Received own node information from API server" ipAddr.ipv4=199.204.45.216 ipAddr.ipv6="" k8sNodeIP=199.204.45.216 labels="map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:]" nodeName=instance subsys=k8s v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="k8s mode: Allowing localhost to reach local endpoints" subsys=daemon level=info msg="Detected devices" devices="[]" subsys=linux-datapath level=info msg="Enabling k8s event listener" subsys=k8s-watcher level=info msg="Removing stale endpoint interfaces" subsys=daemon level=info msg="Waiting until local node addressing before starting watchers depending on it" subsys=k8s-watcher level=info msg="Skipping kvstore configuration" subsys=daemon level=info msg="Initializing node addressing" subsys=daemon level=info msg="Initializing cluster-pool IPAM" subsys=ipam v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="Restoring endpoints..." subsys=daemon level=info msg="Endpoints restored" failed=0 restored=0 subsys=daemon level=info msg="Addressing information:" subsys=daemon level=info msg=" Cluster-Name: default" subsys=daemon level=info msg=" Cluster-ID: 0" subsys=daemon level=info msg=" Local node-name: instance" subsys=daemon level=info msg=" Node-IPv6: " subsys=daemon level=info msg=" External-Node IPv4: 199.204.45.216" subsys=daemon level=info msg=" Internal-Node IPv4: 10.0.0.68" subsys=daemon level=info msg=" IPv4 allocation prefix: 10.0.0.0/24" subsys=daemon level=info msg=" Loopback IPv4: 169.254.42.1" subsys=daemon level=info msg=" Local IPv4 addresses:" subsys=daemon level=info msg=" - 199.204.45.216" subsys=daemon level=info msg=" - 172.17.0.100" subsys=daemon level=info msg="Node updated" clusterName=default nodeName=instance subsys=nodemanager level=info msg="Adding local node to cluster" node="{instance default [{InternalIP 199.204.45.216} {CiliumInternalIP 10.0.0.68}] 10.0.0.0/24 [] [] 10.0.0.51 0 local 0 map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:] map[] 1 }" subsys=nodediscovery level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Waiting until all pre-existing resources have been received" subsys=k8s-watcher level=info msg="Initializing identity allocator" subsys=identity-cache level=info msg="Allocating identities between range" cluster-id=0 max=65535 min=256 subsys=identity-cache level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.core.bpf_jit_enable sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.all.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.fib_multipath_use_neigh sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.unprivileged_bpf_disabled sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.timer_migration sysParamValue=0 level=info msg="Setting up BPF datapath" bpfClockSource=ktime bpfInsnSet="" subsys=datapath-loader level=info msg="Iptables rules installed" subsys=iptables level=info msg="Adding new proxy port rules for cilium-dns-egress:46165" id=cilium-dns-egress subsys=proxy level=info msg="Iptables proxy rules installed" subsys=iptables level=info msg="Start hook executed" duration=2.3810976s function="cmd.newDaemonPromise.func1 (daemon_main.go:1663)" subsys=hive level=info msg="Start hook executed" duration="16.631µs" function="utime.initUtimeSync.func1 (cell.go:33)" subsys=hive level=info msg="Initializing daemon" subsys=daemon level=info msg="Validating configured node address ranges" subsys=daemon level=info msg="Start hook executed" duration="51.802µs" function="*job.group.Start" subsys=hive level=info msg="Starting IP identity watcher" subsys=ipcache level=info msg="Start hook executed" duration="66.292µs" function="l2respondermap.newMap.func1 (l2_responder_map4.go:44)" subsys=hive level=info msg="Start hook executed" duration="13.24µs" function="*job.group.Start" subsys=hive level=info msg="Starting connection tracking garbage collector" subsys=daemon level=info msg="Initial scan of connection tracking completed" subsys=ct-gc level=info msg="Regenerating restored endpoints" numRestored=0 subsys=daemon level=info msg="Creating host endpoint" subsys=daemon level=info msg="Finished regenerating restored endpoints" regenerated=0 subsys=daemon total=0 level=info msg="Deleted orphan backends" orphanBackends=0 subsys=service level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1758 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1758 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1758 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="Launching Cilium health daemon" subsys=daemon level=info msg="Launching Cilium health endpoint" subsys=daemon level=info msg="Started healthz status API server" address="127.0.0.1:9879" subsys=daemon level=info msg="Processing queued endpoint deletion requests from /var/run/cilium/deleteQueue" subsys=daemon level=info msg="processing 0 queued deletion requests" subsys=daemon level=info msg="Initializing Cilium API" subsys=daemon level=info msg="Daemon initialization completed" bootstrapTime=4.824213366s subsys=daemon level=info msg="Hubble server is disabled" subsys=hubble level=info msg="Serving cilium API at unix:///var/run/cilium/cilium.sock" subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.165 2da4391b-8353-4d20-86b3-60d5058a46af default }" containerID=ee6645eb5ed96af8c24a3cad5b2066a0dfd37576a39eae81eb463075d9e2ad72 datapathConfiguration="&{false false false false false }" interface=lxc8b74ac132b8b k8sPodName=kube-system/coredns-7c96b6546b-zjnzd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=ee6645eb5e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=476 ipv4=10.0.0.165 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-zjnzd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=ee6645eb5e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=476 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.165 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-zjnzd subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:kube-system]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=coredns;k8s:io.kubernetes.pod.namespace=kube-system;k8s:k8s-app=kube-dns;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=ee6645eb5e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=476 identity=38258 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.165 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-zjnzd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=ee6645eb5e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=476 identity=38258 ipv4=10.0.0.165 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-zjnzd subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.20 8a65452d-77f3-40b3-a892-5c2b7081fca9 default }" containerID=427ff102d044508998ea8dc542060c5bff5e125eec850db4e17954b46757dabb datapathConfiguration="&{false false false false false }" interface=lxc35c05fd4667f k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bw66n labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=427ff102d0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3875 ipv4=10.0.0.20 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bw66n subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=427ff102d0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3875 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=f3c66c5f-0afc-4997-bb40-3a17ac9333ae,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=f3c66c5f-0afc-4997-bb40-3a17ac9333ae,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.20 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bw66n subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="Compiled new BPF template" BPFCompilationTime=353.690298ms file-path=/var/run/cilium/state/templates/85c08f11dae2c72315cf93554b5fd130117a14da2ce4a8a16072fd595b3f3267/bpf_host.o subsys=datapath-loader level=info msg="Allocated new global key" key="k8s:app=certgen;k8s:batch.kubernetes.io/controller-uid=f3c66c5f-0afc-4997-bb40-3a17ac9333ae;k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen;k8s:controller-uid=f3c66c5f-0afc-4997-bb40-3a17ac9333ae;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;k8s:job-name=envoy-gateway-gateway-helm-certgen;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=427ff102d0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3875 identity=38749 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=f3c66c5f-0afc-4997-bb40-3a17ac9333ae,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=f3c66c5f-0afc-4997-bb40-3a17ac9333ae,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.20 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bw66n oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=427ff102d0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3875 identity=38749 ipv4=10.0.0.20 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bw66n subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1758 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=191 ipv4=10.0.0.51 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=191 identityLabels="reserved:health" ipv4=10.0.0.51 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=191 identity=4 identityLabels="reserved:health" ipv4=10.0.0.51 ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Compiled new BPF template" BPFCompilationTime=1.182226943s file-path=/var/run/cilium/state/templates/67bd73434fb4064e84eee14f0b0dff37410c09fed6d7053c00b11c04a3c44331/bpf_lxc.o subsys=datapath-loader level=info msg="Rewrote endpoint BPF program" containerID=427ff102d0 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=3875 identity=38749 ipv4=10.0.0.20 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bw66n subsys=endpoint level=info msg="Successful endpoint creation" containerID=427ff102d0 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3875 identity=38749 ipv4=10.0.0.20 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bw66n subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=191 identity=4 ipv4=10.0.0.51 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=ee6645eb5e datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=476 identity=38258 ipv4=10.0.0.165 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-zjnzd subsys=endpoint level=info msg="Successful endpoint creation" containerID=ee6645eb5e datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=476 identity=38258 ipv4=10.0.0.165 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-zjnzd subsys=daemon level=info msg="Serving cilium health API at unix:///var/run/cilium/health.sock" subsys=health-server level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=427ff102d0 endpointID=3875 k8sNamespace=envoy-gateway-system k8sPodName=envoy-gateway-gateway-helm-certgen-bw66n subsys=daemon level=info msg="Releasing key" key="[k8s:app=certgen k8s:batch.kubernetes.io/controller-uid=f3c66c5f-0afc-4997-bb40-3a17ac9333ae k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen k8s:controller-uid=f3c66c5f-0afc-4997-bb40-3a17ac9333ae k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen k8s:io.kubernetes.pod.namespace=envoy-gateway-system k8s:job-name=envoy-gateway-gateway-helm-certgen]" subsys=allocator level=info msg="Removed endpoint" containerID=427ff102d0 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3875 identity=38749 ipv4=10.0.0.20 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bw66n subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.31 29e83497-48ef-4b09-acee-1805896753eb default }" containerID=d0dd7772fc480c82e62c248f98414361ef92783b980cefb1bad6ae6d2835779b datapathConfiguration="&{false false false false false }" interface=lxc9c3547daeb03 k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-485fn labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d0dd7772fc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1238 ipv4=10.0.0.31 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-485fn subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d0dd7772fc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1238 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.31 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-485fn subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=envoy-gateway;k8s:app.kubernetes.io/name=gateway-helm;k8s:control-plane=envoy-gateway;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d0dd7772fc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1238 identity=57916 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.31 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-485fn oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d0dd7772fc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1238 identity=57916 ipv4=10.0.0.31 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-485fn subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=d0dd7772fc datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1238 identity=57916 ipv4=10.0.0.31 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-485fn subsys=endpoint level=info msg="Successful endpoint creation" containerID=d0dd7772fc datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1238 identity=57916 ipv4=10.0.0.31 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-485fn subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1758 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,k8s:openstack-compute-node=enabled,k8s:openstack-control-plane=enabled,k8s:openvswitch=enabled,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_hostns_01758 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_hostns_01758 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_hostns_01758 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_hostns_01758:pending" subsys=bpf level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_netdev_00003 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_netdev_00003 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003:pending" subsys=bpf level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1758 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.226 bd8e9e74-0039-45a1-a8b3-4da4d220bc8c default }" containerID=7b301bc3d50101155061de90c0bed0fdf3664bc334553cc2bff4300a3493ca98 datapathConfiguration="&{false false false false false }" interface=lxc0067d0584f4b k8sPodName=kube-system/coredns-67659f764b-m28hk labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=7b301bc3d5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=981 ipv4=10.0.0.226 ipv6= k8sPodName=kube-system/coredns-67659f764b-m28hk subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=7b301bc3d5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=981 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.226 ipv6= k8sPodName=kube-system/coredns-67659f764b-m28hk subsys=endpoint level=info msg="Identity of endpoint changed" containerID=7b301bc3d5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=981 identity=38258 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.226 ipv6= k8sPodName=kube-system/coredns-67659f764b-m28hk oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=7b301bc3d5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=981 identity=38258 ipv4=10.0.0.226 ipv6= k8sPodName=kube-system/coredns-67659f764b-m28hk subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=7b301bc3d5 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=981 identity=38258 ipv4=10.0.0.226 ipv6= k8sPodName=kube-system/coredns-67659f764b-m28hk subsys=endpoint level=info msg="Successful endpoint creation" containerID=7b301bc3d5 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=981 identity=38258 ipv4=10.0.0.226 ipv6= k8sPodName=kube-system/coredns-67659f764b-m28hk subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.92 b36cada3-551f-4270-8493-6b69ca1766f4 default }" containerID=7f3f92d2c50766cc4151a153473a62dd38e2b1f1b1e012f551eba2f11dc04a86 datapathConfiguration="&{false false false false false }" interface=lxc39734656af43 k8sPodName=kube-system/coredns-67659f764b-mf4mt labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=7f3f92d2c5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=261 ipv4=10.0.0.92 ipv6= k8sPodName=kube-system/coredns-67659f764b-mf4mt subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=7f3f92d2c5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=261 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.92 ipv6= k8sPodName=kube-system/coredns-67659f764b-mf4mt subsys=endpoint level=info msg="Identity of endpoint changed" containerID=7f3f92d2c5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=261 identity=38258 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.92 ipv6= k8sPodName=kube-system/coredns-67659f764b-mf4mt oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=7f3f92d2c5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=261 identity=38258 ipv4=10.0.0.92 ipv6= k8sPodName=kube-system/coredns-67659f764b-mf4mt subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=7f3f92d2c5 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=261 identity=38258 ipv4=10.0.0.92 ipv6= k8sPodName=kube-system/coredns-67659f764b-mf4mt subsys=endpoint level=info msg="Successful endpoint creation" containerID=7f3f92d2c5 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=261 identity=38258 ipv4=10.0.0.92 ipv6= k8sPodName=kube-system/coredns-67659f764b-mf4mt subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.132 6a2362c5-a9ff-4bee-b31a-01d0934bacc9 default }" containerID=d3259ff30a76d2172293d2d9fcc0532e4c0ae46d4ebc66f90d1f8473904c186c datapathConfiguration="&{false false false false false }" interface=lxcb3c57f16a0c1 k8sPodName=local-path-storage/local-path-provisioner-679c578f5-cjjqx labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d3259ff30a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1088 ipv4=10.0.0.132 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-cjjqx subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d3259ff30a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1088 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.132 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-cjjqx subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=local-path-provisioner;k8s:app.kubernetes.io/name=local-path-provisioner;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d3259ff30a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1088 identity=1601 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.132 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-cjjqx oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d3259ff30a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1088 identity=1601 ipv4=10.0.0.132 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-cjjqx subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=d3259ff30a datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1088 identity=1601 ipv4=10.0.0.132 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-cjjqx subsys=endpoint level=info msg="Successful endpoint creation" containerID=d3259ff30a datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1088 identity=1601 ipv4=10.0.0.132 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-cjjqx subsys=daemon level=info msg="Delete endpoint request" containerID=ee6645eb5e endpointID=476 k8sNamespace=kube-system k8sPodName=coredns-7c96b6546b-zjnzd subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=coredns k8s:io.kubernetes.pod.namespace=kube-system k8s:k8s-app=kube-dns]" subsys=allocator level=info msg="Removed endpoint" containerID=ee6645eb5e datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=476 identity=38258 ipv4=10.0.0.165 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-zjnzd subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.24 a871ba4a-516d-4f90-95ac-3f984dd68834 default }" containerID=e9d1d21a351356e585eb9de7afaa728a2128cbea169f08c8a819d85ae55942ec datapathConfiguration="&{false false false false false }" interface=lxcab56491c4567 k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-9zdp7 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e9d1d21a35 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3776 ipv4=10.0.0.24 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-9zdp7 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e9d1d21a35 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3776 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.24 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-9zdp7 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=cainjector;k8s:app.kubernetes.io/component=cainjector;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cainjector;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e9d1d21a35 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3776 identity=62506 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.24 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-9zdp7 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e9d1d21a35 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3776 identity=62506 ipv4=10.0.0.24 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-9zdp7 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.200 f9e1bc0a-ea66-497d-a1f6-de3ed1ec6b56 default }" containerID=b578e1da5bd12520ed6e14895b4954c3996f6aa63df573b2003224cbd3316688 datapathConfiguration="&{false false false false false }" interface=lxcc6edb9bbe8f4 k8sPodName=cert-manager/cert-manager-75c4c745bc-248sp labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b578e1da5b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=124 ipv4=10.0.0.200 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-248sp subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b578e1da5b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=124 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.200 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-248sp subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Create endpoint request" addressing="&{10.0.0.37 3dc90c3d-c0a8-45df-accf-26b2b5e9919b default }" containerID=223aa1ddd7045b72fa6bd9445f06ce61b45c5c8749a134c609fc60a7b8eead5d datapathConfiguration="&{false false false false false }" interface=lxc58debd760c97 k8sPodName=cert-manager/cert-manager-webhook-548949fc64-vj7nl labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=223aa1ddd7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1252 ipv4=10.0.0.37 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-vj7nl subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=223aa1ddd7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1252 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.37 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-vj7nl subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=cert-manager;k8s:app.kubernetes.io/component=controller;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cert-manager;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=b578e1da5b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=124 identity=29666 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.200 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-248sp oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b578e1da5b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=124 identity=29666 ipv4=10.0.0.200 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-248sp subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=webhook;k8s:app.kubernetes.io/component=webhook;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=webhook;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=223aa1ddd7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1252 identity=24397 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.37 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-vj7nl oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=223aa1ddd7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1252 identity=24397 ipv4=10.0.0.37 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-vj7nl subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=e9d1d21a35 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=3776 identity=62506 ipv4=10.0.0.24 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-9zdp7 subsys=endpoint level=info msg="Successful endpoint creation" containerID=e9d1d21a35 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3776 identity=62506 ipv4=10.0.0.24 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-9zdp7 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=b578e1da5b datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=124 identity=29666 ipv4=10.0.0.200 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-248sp subsys=endpoint level=info msg="Successful endpoint creation" containerID=b578e1da5b datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=124 identity=29666 ipv4=10.0.0.200 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-248sp subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=223aa1ddd7 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1252 identity=24397 ipv4=10.0.0.37 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-vj7nl subsys=endpoint level=info msg="Successful endpoint creation" containerID=223aa1ddd7 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1252 identity=24397 ipv4=10.0.0.37 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-vj7nl subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.3 5ea6a01b-c269-40d7-a173-5fd17d7e1055 default }" containerID=c3d432d3af998b34b89349b9abd9a02b657bfcc99a77e508ad2ce97934bd2292 datapathConfiguration="&{false false false false false }" interface=lxc838a5d520ee0 k8sPodName=cert-manager/cert-manager-startupapicheck-vdq4n labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c3d432d3af datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1910 ipv4=10.0.0.3 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-vdq4n subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c3d432d3af datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1910 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=13029326-c049-428e-8ebc-7e10b1d6f5dc,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=13029326-c049-428e-8ebc-7e10b1d6f5dc,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.3 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-vdq4n subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=startupapicheck;k8s:app.kubernetes.io/component=startupapicheck;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=startupapicheck;k8s:app.kubernetes.io/version=v1.11.5;k8s:batch.kubernetes.io/controller-uid=13029326-c049-428e-8ebc-7e10b1d6f5dc;k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck;k8s:controller-uid=13029326-c049-428e-8ebc-7e10b1d6f5dc;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck;k8s:io.kubernetes.pod.namespace=cert-manager;k8s:job-name=cert-manager-startupapicheck;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=c3d432d3af datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1910 identity=9512 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=13029326-c049-428e-8ebc-7e10b1d6f5dc,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=13029326-c049-428e-8ebc-7e10b1d6f5dc,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.3 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-vdq4n oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c3d432d3af datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1910 identity=9512 ipv4=10.0.0.3 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-vdq4n subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=c3d432d3af datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1910 identity=9512 ipv4=10.0.0.3 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-vdq4n subsys=endpoint level=info msg="Successful endpoint creation" containerID=c3d432d3af datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1910 identity=9512 ipv4=10.0.0.3 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-vdq4n subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=c3d432d3af endpointID=1910 k8sNamespace=cert-manager k8sPodName=cert-manager-startupapicheck-vdq4n subsys=daemon level=info msg="Releasing key" key="[k8s:app=startupapicheck k8s:app.kubernetes.io/component=startupapicheck k8s:app.kubernetes.io/instance=cert-manager k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=startupapicheck k8s:app.kubernetes.io/version=v1.11.5 k8s:batch.kubernetes.io/controller-uid=13029326-c049-428e-8ebc-7e10b1d6f5dc k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck k8s:controller-uid=13029326-c049-428e-8ebc-7e10b1d6f5dc k8s:helm.sh/chart=cert-manager-v1.11.5 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager k8s:io.cilium.k8s.namespace.labels.name=cert-manager k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck k8s:io.kubernetes.pod.namespace=cert-manager k8s:job-name=cert-manager-startupapicheck]" subsys=allocator level=info msg="Removed endpoint" containerID=c3d432d3af datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1910 identity=9512 ipv4=10.0.0.3 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-vdq4n subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.217 9c916200-fe8c-4916-bf48-181746b3ab63 default }" containerID=1150cb76ccbdb30531f5fe761d55598079d47afede656ae7c101f202c869c025 datapathConfiguration="&{false false false false false }" interface=lxc53b732a009ed k8sPodName=ingress-nginx/ingress-nginx-admission-create-8hvg4 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=1150cb76cc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=541 ipv4=10.0.0.217 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-8hvg4 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=1150cb76cc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=541 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=2a2f663d-f472-4f40-8763-d96222e4a56e,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=2a2f663d-f472-4f40-8763-d96222e4a56e,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.217 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-8hvg4 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=2a2f663d-f472-4f40-8763-d96222e4a56e;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create;k8s:controller-uid=2a2f663d-f472-4f40-8763-d96222e4a56e;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-create;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=1150cb76cc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=541 identity=45853 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=2a2f663d-f472-4f40-8763-d96222e4a56e,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=2a2f663d-f472-4f40-8763-d96222e4a56e,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.217 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-8hvg4 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=1150cb76cc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=541 identity=45853 ipv4=10.0.0.217 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-8hvg4 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=1150cb76cc datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=541 identity=45853 ipv4=10.0.0.217 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-8hvg4 subsys=endpoint level=info msg="Successful endpoint creation" containerID=1150cb76cc datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=541 identity=45853 ipv4=10.0.0.217 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-8hvg4 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=1150cb76cc endpointID=541 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-create-8hvg4 subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=2a2f663d-f472-4f40-8763-d96222e4a56e k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create k8s:controller-uid=2a2f663d-f472-4f40-8763-d96222e4a56e k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-create]" subsys=allocator level=info msg="Removed endpoint" containerID=1150cb76cc datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=541 identity=45853 ipv4=10.0.0.217 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-8hvg4 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.18 40d032fc-e51f-4e23-9a4a-3a464c3d8403 default }" containerID=1c3c9306d5be6ffc931c7eabf5126d89a2e7285304a9c3cc75f5ca5371f47b5a datapathConfiguration="&{false false false false false }" interface=lxca92c055e438c k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-mg9tb labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=1c3c9306d5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3800 ipv4=10.0.0.18 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-mg9tb subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=1c3c9306d5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3800 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.18 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-mg9tb subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=1c3c9306d5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3800 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.18 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-mg9tb line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=default-backend;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend;k8s:io.kubernetes.pod.namespace=ingress-nginx;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=1c3c9306d5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3800 identity=26751 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.18 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-mg9tb oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=1c3c9306d5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3800 identity=26751 ipv4=10.0.0.18 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-mg9tb subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=1c3c9306d5 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=3800 identity=26751 ipv4=10.0.0.18 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-mg9tb subsys=endpoint level=info msg="Successful endpoint creation" containerID=1c3c9306d5 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3800 identity=26751 ipv4=10.0.0.18 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-mg9tb subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.93 8579b2eb-7b87-44c9-9f85-76db831a1a77 default }" containerID=eaf97446957a33f3dbdff6931f4c217bdf5ad432a1b1225abca1df40a2b0a691 datapathConfiguration="&{false false false false false }" interface=lxc1cdc68239e30 k8sPodName=ingress-nginx/ingress-nginx-admission-patch-tmskz labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=eaf9744695 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4027 ipv4=10.0.0.93 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-tmskz subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=eaf9744695 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4027 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=2cb422ba-1a49-4771-8ef7-451694a67462,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=2cb422ba-1a49-4771-8ef7-451694a67462,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.93 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-tmskz subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=2cb422ba-1a49-4771-8ef7-451694a67462;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch;k8s:controller-uid=2cb422ba-1a49-4771-8ef7-451694a67462;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-patch;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=eaf9744695 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4027 identity=64134 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=2cb422ba-1a49-4771-8ef7-451694a67462,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=2cb422ba-1a49-4771-8ef7-451694a67462,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.93 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-tmskz oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=eaf9744695 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4027 identity=64134 ipv4=10.0.0.93 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-tmskz subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=eaf9744695 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=4027 identity=64134 ipv4=10.0.0.93 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-tmskz subsys=endpoint level=info msg="Successful endpoint creation" containerID=eaf9744695 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=4027 identity=64134 ipv4=10.0.0.93 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-tmskz subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=eaf9744695 endpointID=4027 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-patch-tmskz subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=2cb422ba-1a49-4771-8ef7-451694a67462 k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch k8s:controller-uid=2cb422ba-1a49-4771-8ef7-451694a67462 k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-patch]" subsys=allocator level=info msg="Removed endpoint" containerID=eaf9744695 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=4027 identity=64134 ipv4=10.0.0.93 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-tmskz subsys=endpoint level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"messaging-topology-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:9443 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-messaging-topology-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=06b24352-f1f8-4773-87f5-7cfbd0901004] Description:}]" policyAddRequest=560ae2bb-b9bd-4ba6-b684-53908c9cb864 subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=560ae2bb-b9bd-4ba6-b684-53908c9cb864 policyRevision=2 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-messaging-topology-operator subsys=k8s-watcher level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"rabbitmq-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-cluster-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=373d413b-b15e-4902-9b5a-8f9ad4d85f8e] Description:}]" policyAddRequest=4a26ae29-deab-4284-a336-a0c350d7ae36 subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=4a26ae29-deab-4284-a336-a0c350d7ae36 policyRevision=3 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-cluster-operator subsys=k8s-watcher level=info msg="Create endpoint request" addressing="&{10.0.0.194 585eac4b-a314-4017-8ad2-31ea083acf50 default }" containerID=2722aacc9e8dcc961e146be36e655a0f95792c5159d9678946449873910c5502 datapathConfiguration="&{false false false false false }" interface=lxcaa985d023fb5 k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-hwx7b labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=2722aacc9e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1225 ipv4=10.0.0.194 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-hwx7b subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=2722aacc9e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1225 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.16.1,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.194 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-hwx7b subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=2.16.1;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=2722aacc9e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1225 identity=3201 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.16.1,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.194 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-hwx7b oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=2722aacc9e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1225 identity=3201 ipv4=10.0.0.194 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-hwx7b subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=2722aacc9e datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=1225 identity=3201 ipv4=10.0.0.194 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-hwx7b subsys=endpoint level=info msg="Successful endpoint creation" containerID=2722aacc9e datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=1225 identity=3201 ipv4=10.0.0.194 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-hwx7b subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.221 6de89995-c7d6-48db-b8b4-4c4644dd8427 default }" containerID=c64bd6ea2d1ab757fa5ac6b9838cd733398c0dc10301b6514c804694b3e61f98 datapathConfiguration="&{false false false false false }" interface=lxc2a38538c30e4 k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-kdhk6 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c64bd6ea2d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=548 ipv4=10.0.0.221 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-kdhk6 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c64bd6ea2d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=548 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.17.4,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.221 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-kdhk6 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=messaging-topology-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=1.17.4;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=c64bd6ea2d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=548 identity=23601 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.17.4,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.221 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-kdhk6 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c64bd6ea2d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=548 identity=23601 ipv4=10.0.0.221 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-kdhk6 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=c64bd6ea2d datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=548 identity=23601 ipv4=10.0.0.221 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-kdhk6 subsys=endpoint level=info msg="Successful endpoint creation" containerID=c64bd6ea2d datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=548 identity=23601 ipv4=10.0.0.221 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-kdhk6 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.219 c6ec0f8b-01ac-427f-9278-88de39e15818 default }" containerID=b937c6676b8de3e59421decaa70b45e10ce7b69a853ef5d319ac717e823fef08 datapathConfiguration="&{false false false false false }" interface=lxc67f9d6bceb1f k8sPodName=openstack/pxc-operator-69cb5bbdb9-dqvd5 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b937c6676b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=190 ipv4=10.0.0.219 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-dqvd5 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b937c6676b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=190 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.219 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-dqvd5 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=b937c6676b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=190 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.219 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-dqvd5 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=operator;k8s:app.kubernetes.io/instance=pxc-operator;k8s:app.kubernetes.io/name=pxc-operator;k8s:app.kubernetes.io/part-of=pxc-operator;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=b937c6676b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=190 identity=20935 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.219 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-dqvd5 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b937c6676b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=190 identity=20935 ipv4=10.0.0.219 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-dqvd5 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=b937c6676b datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=190 identity=20935 ipv4=10.0.0.219 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-dqvd5 subsys=endpoint level=info msg="Successful endpoint creation" containerID=b937c6676b datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=190 identity=20935 ipv4=10.0.0.219 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-dqvd5 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.38 e546f662-0f08-45ef-b94d-9b3318ff60db default }" containerID=09d92c639a45da5a09bb522d1eeb8aeea8510c93759a0d11a2012b632846aba2 datapathConfiguration="&{false false false false false }" interface=lxcc52fd2b259da k8sPodName=openstack/percona-xtradb-haproxy-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=09d92c639a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2305 ipv4=10.0.0.38 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=09d92c639a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2305 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.38 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=haproxy;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=09d92c639a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2305 identity=5766 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.38 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=09d92c639a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2305 identity=5766 ipv4=10.0.0.38 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.11 e850c4a6-89dc-4ef8-afd3-d248778fa58f default }" containerID=04128fabbd067bca1a52beebf00af871ad925a83a2e72ca00785174af36b9fd5 datapathConfiguration="&{false false false false false }" interface=lxcd07a3dcaeebd k8sPodName=local-path-storage/helper-pod-create-pvc-190b2e9e-76e7-4ac3-b1cc-b894d85e57d8 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=04128fabbd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1980 ipv4=10.0.0.11 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-190b2e9e-76e7-4ac3-b1cc-b894d85e57d8 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=04128fabbd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1980 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.11 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-190b2e9e-76e7-4ac3-b1cc-b894d85e57d8 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=04128fabbd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1980 identity=47355 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.11 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-190b2e9e-76e7-4ac3-b1cc-b894d85e57d8 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=04128fabbd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1980 identity=47355 ipv4=10.0.0.11 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-190b2e9e-76e7-4ac3-b1cc-b894d85e57d8 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=09d92c639a datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=2305 identity=5766 ipv4=10.0.0.38 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=09d92c639a datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=2305 identity=5766 ipv4=10.0.0.38 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=04128fabbd datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=1980 identity=47355 ipv4=10.0.0.11 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-190b2e9e-76e7-4ac3-b1cc-b894d85e57d8 subsys=endpoint level=info msg="Successful endpoint creation" containerID=04128fabbd datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=1980 identity=47355 ipv4=10.0.0.11 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-190b2e9e-76e7-4ac3-b1cc-b894d85e57d8 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=04128fabbd endpointID=1980 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-190b2e9e-76e7-4ac3-b1cc-b894d85e57d8 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=04128fabbd datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=1980 identity=47355 ipv4=10.0.0.11 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-190b2e9e-76e7-4ac3-b1cc-b894d85e57d8 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.10 2db635f9-0ed0-40ba-9f5d-783d1c53cd54 default }" containerID=aadb21230aedead5f28b9ae9796568e6a1e3f09b6d824b0862874aca951d00da datapathConfiguration="&{false false false false false }" interface=lxcc5be54901f48 k8sPodName=openstack/percona-xtradb-pxc-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=aadb21230a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1007 ipv4=10.0.0.10 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=aadb21230a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1007 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.10 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=pxc;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=aadb21230a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1007 identity=13431 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.10 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=aadb21230a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1007 identity=13431 ipv4=10.0.0.10 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=aadb21230a datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=1007 identity=13431 ipv4=10.0.0.10 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=aadb21230a datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=1007 identity=13431 ipv4=10.0.0.10 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.3 a7bb1f00-3c7a-4288-ac8e-3566c3007dc1 default }" containerID=e10d0484cc4a160eab1fd8f4aa9e054de771d93fb078593bdc7e1cc2ae105353 datapathConfiguration="&{false false false false false }" interface=lxcb0a53d529124 k8sPodName=openstack/memcached-memcached-6479589586-lg299 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e10d0484cc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2989 ipv4=10.0.0.3 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-lg299 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e10d0484cc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2989 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.3 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-lg299 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=memcached;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=memcached;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e10d0484cc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2989 identity=44443 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.3 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-lg299 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e10d0484cc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2989 identity=44443 ipv4=10.0.0.3 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-lg299 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=e10d0484cc datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=2989 identity=44443 ipv4=10.0.0.3 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-lg299 subsys=endpoint level=info msg="Successful endpoint creation" containerID=e10d0484cc datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=2989 identity=44443 ipv4=10.0.0.3 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-lg299 subsys=daemon level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"keycloak\",\"k8s:app.kubernetes.io/instance\":\"keycloak\",\"k8s:app.kubernetes.io/name\":\"keycloak\",\"k8s:io.kubernetes.pod.namespace\":\"auth-system\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:7800 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:} {Ports:[{Port:8080 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=keycloak k8s:io.cilium.k8s.policy.namespace=auth-system k8s:io.cilium.k8s.policy.uid=66e75366-f82a-4d3f-a8e4-051cd32c3aec] Description:}]" policyAddRequest=3fc606ae-03f2-43f8-bf39-315eaa6f6b4c subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=3fc606ae-03f2-43f8-bf39-315eaa6f6b4c policyRevision=4 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=keycloak subsys=k8s-watcher level=info msg="Create endpoint request" addressing="&{10.0.0.227 62c0a580-3e15-4048-aa4f-1d440eff1fe6 default }" containerID=4caae02e66ad0d3cc6828e95b3fe2e8864b3d76972e50dbd648b93833fd6b4b5 datapathConfiguration="&{false false false false false }" interface=lxccde05937b0f6 k8sPodName=auth-system/keycloak-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=4caae02e66 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1130 ipv4=10.0.0.227 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=4caae02e66 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1130 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=24.0.5,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-21.4.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.227 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:auth-system k8s:io.cilium.k8s.namespace.labels.name:auth-system]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=keycloak;k8s:app.kubernetes.io/instance=keycloak;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=keycloak;k8s:app.kubernetes.io/version=24.0.5;k8s:apps.kubernetes.io/pod-index=0;k8s:helm.sh/chart=keycloak-21.4.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system;k8s:io.cilium.k8s.namespace.labels.name=auth-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keycloak;k8s:io.kubernetes.pod.namespace=auth-system;k8s:statefulset.kubernetes.io/pod-name=keycloak-0;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=4caae02e66 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1130 identity=9810 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=24.0.5,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-21.4.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.227 ipv6= k8sPodName=auth-system/keycloak-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=4caae02e66 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1130 identity=9810 ipv4=10.0.0.227 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=4caae02e66 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1130 identity=9810 ipv4=10.0.0.227 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=4caae02e66 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1130 identity=9810 ipv4=10.0.0.227 ipv6= k8sPodName=auth-system/keycloak-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Conntrack garbage collector interval recalculated" deleteRatio=0.027036583707330343 newInterval=7m30s subsys=map-ct level=info msg="Create endpoint request" addressing="&{10.0.0.126 dc7c9649-68c3-4029-8332-1072e6dba359 default }" containerID=618e3bf158a34c34783b2d71a087981e318eb4df4015c7d568242538104bac16 datapathConfiguration="&{false false false false false }" interface=lxcfeac52223b56 k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-mt77g labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=618e3bf158 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1606 ipv4=10.0.0.126 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-mt77g subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=618e3bf158 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1606 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.126 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-mt77g subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:secretgen-controller]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app=secretgen-controller;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa;k8s:io.kubernetes.pod.namespace=secretgen-controller;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=618e3bf158 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1606 identity=32043 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.126 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-mt77g oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=618e3bf158 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1606 identity=32043 ipv4=10.0.0.126 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-mt77g subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=618e3bf158 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1606 identity=32043 ipv4=10.0.0.126 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-mt77g subsys=endpoint level=info msg="Successful endpoint creation" containerID=618e3bf158 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1606 identity=32043 ipv4=10.0.0.126 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-mt77g subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.72 e698c0e9-2500-42b0-ad8c-969f4e24fd15 default }" containerID=827fb062f28dfac5fa1c846bb54697f5f0927791cacc3a0b826816414451dd3e datapathConfiguration="&{false false false false false }" interface=lxcd7d8a7fda87d k8sPodName=monitoring/kube-prometheus-stack-admission-create-tbzkr labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=827fb062f2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=909 ipv4=10.0.0.72 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-tbzkr subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=827fb062f2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=909 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=4ce30321-d086-4161-8010-d55a32f17b78,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=4ce30321-d086-4161-8010-d55a32f17b78,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.72 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-tbzkr subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-create;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:batch.kubernetes.io/controller-uid=4ce30321-d086-4161-8010-d55a32f17b78;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create;k8s:chart=kube-prometheus-stack-60.2.0;k8s:controller-uid=4ce30321-d086-4161-8010-d55a32f17b78;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-create;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=827fb062f2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=909 identity=9533 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=4ce30321-d086-4161-8010-d55a32f17b78,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=4ce30321-d086-4161-8010-d55a32f17b78,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.72 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-tbzkr oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=827fb062f2 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=909 identity=9533 ipv4=10.0.0.72 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-tbzkr subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=827fb062f2 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=909 identity=9533 ipv4=10.0.0.72 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-tbzkr subsys=endpoint level=info msg="Successful endpoint creation" containerID=827fb062f2 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=909 identity=9533 ipv4=10.0.0.72 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-tbzkr subsys=daemon level=info msg="Delete endpoint request" containerID=827fb062f2 endpointID=909 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-create-tbzkr subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-create k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=60.2.0 k8s:batch.kubernetes.io/controller-uid=4ce30321-d086-4161-8010-d55a32f17b78 k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create k8s:chart=kube-prometheus-stack-60.2.0 k8s:controller-uid=4ce30321-d086-4161-8010-d55a32f17b78 k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-create k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=827fb062f2 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=909 identity=9533 ipv4=10.0.0.72 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-tbzkr subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.216 d4e97291-20f4-44d4-8748-12e713182ddd default }" containerID=e3f1b901aadbbd9adb10b7487abfd4dc3a536a4caaf558d6f448588e040d2d84 datapathConfiguration="&{false false false false false }" interface=lxcade388baccee k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-gq2gn labels="[]" subsys=daemon sync-build=true level=info msg="Create endpoint request" addressing="&{10.0.0.133 142459c7-39a1-4d6c-a038-676ae78a7224 default }" containerID=7561185698eeea18d4be782c048f30a6fbf2ebd933ff00045a3b2eb7d8c88b7e datapathConfiguration="&{false false false false false }" interface=lxc25a52a0a8af5 k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-4psdn labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e3f1b901aa datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2822 ipv4=10.0.0.216 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-gq2gn subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e3f1b901aa datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2822 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-60.2.0,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.216 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-gq2gn subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="New endpoint" containerID=7561185698 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1006 ipv4=10.0.0.133 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-4psdn subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=7561185698 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1006 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.20.0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.133 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-4psdn subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=7561185698 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1006 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.133 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-4psdn line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-operator;k8s:app.kubernetes.io/component=prometheus-operator;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:chart=kube-prometheus-stack-60.2.0;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Invalid state transition skipped" containerID=e3f1b901aa datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2822 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.216 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-gq2gn line=611 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=e3f1b901aa datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2822 identity=18104 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-60.2.0,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.216 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-gq2gn oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e3f1b901aa datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2822 identity=18104 ipv4=10.0.0.216 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-gq2gn subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=metrics;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-state-metrics;k8s:app.kubernetes.io/part-of=kube-state-metrics;k8s:app.kubernetes.io/version=2.12.0;k8s:helm.sh/chart=kube-state-metrics-5.20.0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=7561185698 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1006 identity=53656 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.20.0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.133 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-4psdn oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=7561185698 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1006 identity=53656 ipv4=10.0.0.133 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-4psdn subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.32 9e4d98a5-fb64-4c5a-92de-3d9bc1e7a7ba default }" containerID=c2733c2f53dbb633334e0be4c18d3663c171479c0c7ba0c9d701b433235d053d datapathConfiguration="&{false false false false false }" interface=lxc814c58a0ed25 k8sPodName=monitoring/kube-prometheus-stack-grafana-86d94f8755-qlq6k labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c2733c2f53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1011 ipv4=10.0.0.32 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-86d94f8755-qlq6k subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c2733c2f53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1011 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.32 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-86d94f8755-qlq6k subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/name=grafana;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana;k8s:io.kubernetes.pod.namespace=monitoring;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=c2733c2f53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1011 identity=37412 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.32 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-86d94f8755-qlq6k oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c2733c2f53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1011 identity=37412 ipv4=10.0.0.32 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-86d94f8755-qlq6k subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=e3f1b901aa datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2822 identity=18104 ipv4=10.0.0.216 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-gq2gn subsys=endpoint level=info msg="Successful endpoint creation" containerID=e3f1b901aa datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2822 identity=18104 ipv4=10.0.0.216 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-gq2gn subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=7561185698 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1006 identity=53656 ipv4=10.0.0.133 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-4psdn subsys=endpoint level=info msg="Successful endpoint creation" containerID=7561185698 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1006 identity=53656 ipv4=10.0.0.133 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-4psdn subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=c2733c2f53 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1011 identity=37412 ipv4=10.0.0.32 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-86d94f8755-qlq6k subsys=endpoint level=info msg="Successful endpoint creation" containerID=c2733c2f53 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1011 identity=37412 ipv4=10.0.0.32 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-86d94f8755-qlq6k subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.63 943c979a-5808-43f7-9531-9498c9982710 default }" containerID=10787776fb7de09b6256eaf5343b97ac18248c2d23f5a82920372d6df1401663 datapathConfiguration="&{false false false false false }" interface=lxc6a5e1d5ea89e k8sPodName=monitoring/kube-prometheus-stack-admission-patch-p9x6n labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=10787776fb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=914 ipv4=10.0.0.63 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-p9x6n subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=10787776fb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=914 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=7fe2b1a2-a602-4f7f-b336-e8c055f3c8c1,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=7fe2b1a2-a602-4f7f-b336-e8c055f3c8c1,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.63 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-p9x6n subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=10787776fb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=914 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.63 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-p9x6n line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-patch;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:batch.kubernetes.io/controller-uid=7fe2b1a2-a602-4f7f-b336-e8c055f3c8c1;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch;k8s:chart=kube-prometheus-stack-60.2.0;k8s:controller-uid=7fe2b1a2-a602-4f7f-b336-e8c055f3c8c1;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-patch;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=10787776fb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=914 identity=23104 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=7fe2b1a2-a602-4f7f-b336-e8c055f3c8c1,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=7fe2b1a2-a602-4f7f-b336-e8c055f3c8c1,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.63 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-p9x6n oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=10787776fb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=914 identity=23104 ipv4=10.0.0.63 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-p9x6n subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=10787776fb datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=914 identity=23104 ipv4=10.0.0.63 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-p9x6n subsys=endpoint level=info msg="Successful endpoint creation" containerID=10787776fb datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=914 identity=23104 ipv4=10.0.0.63 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-p9x6n subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.184 7862b3f6-8052-4db5-8780-ae96a93cd1b4 default }" containerID=3cc12f2bf544ae12c272928b4f506eaeec807107673ba97b04a4b1528e90a205 datapathConfiguration="&{false false false false false }" interface=lxcc36a26b8f219 k8sPodName=local-path-storage/helper-pod-create-pvc-d680299e-13c0-4dab-aa0e-0d8bcf2f34bd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=3cc12f2bf5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3634 ipv4=10.0.0.184 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d680299e-13c0-4dab-aa0e-0d8bcf2f34bd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=3cc12f2bf5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3634 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.184 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d680299e-13c0-4dab-aa0e-0d8bcf2f34bd subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=3cc12f2bf5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3634 identity=47355 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.184 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d680299e-13c0-4dab-aa0e-0d8bcf2f34bd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=3cc12f2bf5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3634 identity=47355 ipv4=10.0.0.184 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d680299e-13c0-4dab-aa0e-0d8bcf2f34bd subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=3cc12f2bf5 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3634 identity=47355 ipv4=10.0.0.184 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d680299e-13c0-4dab-aa0e-0d8bcf2f34bd subsys=endpoint level=info msg="Successful endpoint creation" containerID=3cc12f2bf5 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3634 identity=47355 ipv4=10.0.0.184 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d680299e-13c0-4dab-aa0e-0d8bcf2f34bd subsys=daemon level=info msg="Delete endpoint request" containerID=10787776fb endpointID=914 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-patch-p9x6n subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-patch k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=60.2.0 k8s:batch.kubernetes.io/controller-uid=7fe2b1a2-a602-4f7f-b336-e8c055f3c8c1 k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch k8s:chart=kube-prometheus-stack-60.2.0 k8s:controller-uid=7fe2b1a2-a602-4f7f-b336-e8c055f3c8c1 k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-patch k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=10787776fb datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=914 identity=23104 ipv4=10.0.0.63 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-p9x6n subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.142 d67f9e86-7083-4fa8-a495-a5d6ecc36e97 default }" containerID=d107ec0b136053996eba458fa9d1e297a4da5b7230fdb40bda6d9baf792bee5b datapathConfiguration="&{false false false false false }" interface=lxc49660d3931b7 k8sPodName=local-path-storage/helper-pod-create-pvc-bfd53df1-4a71-440a-b9bb-666bee3f3808 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d107ec0b13 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1239 ipv4=10.0.0.142 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-bfd53df1-4a71-440a-b9bb-666bee3f3808 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d107ec0b13 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1239 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.142 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-bfd53df1-4a71-440a-b9bb-666bee3f3808 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=d107ec0b13 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1239 identity=47355 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.142 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-bfd53df1-4a71-440a-b9bb-666bee3f3808 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d107ec0b13 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1239 identity=47355 ipv4=10.0.0.142 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-bfd53df1-4a71-440a-b9bb-666bee3f3808 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=d107ec0b13 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1239 identity=47355 ipv4=10.0.0.142 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-bfd53df1-4a71-440a-b9bb-666bee3f3808 subsys=endpoint level=info msg="Successful endpoint creation" containerID=d107ec0b13 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1239 identity=47355 ipv4=10.0.0.142 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-bfd53df1-4a71-440a-b9bb-666bee3f3808 subsys=daemon level=info msg="Delete endpoint request" containerID=d107ec0b13 endpointID=1239 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-bfd53df1-4a71-440a-b9bb-666bee3f3808 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Delete endpoint request" containerID=3cc12f2bf5 endpointID=3634 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-d680299e-13c0-4dab-aa0e-0d8bcf2f34bd subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=d107ec0b13 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1239 identity=47355 ipv4=10.0.0.142 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-bfd53df1-4a71-440a-b9bb-666bee3f3808 subsys=endpoint level=info msg="Removed endpoint" containerID=3cc12f2bf5 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3634 identity=47355 ipv4=10.0.0.184 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d680299e-13c0-4dab-aa0e-0d8bcf2f34bd subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.170 41a656dd-0b2b-4b3a-9d1c-f73ec074bd20 default }" containerID=e18f5fbe9eb6135fc5409d872fde75c5bf508a43cc6b28176c3b79cb05c08953 datapathConfiguration="&{false false false false false }" interface=lxc6762678414f6 k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e18f5fbe9e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=534 ipv4=10.0.0.170 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e18f5fbe9e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=534 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.170 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=prometheus;k8s:app.kubernetes.io/version=2.51.2;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus;k8s:io.kubernetes.pod.namespace=monitoring;k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus;k8s:operator.prometheus.io/shard=0;k8s:prometheus=kube-prometheus-stack-prometheus;k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e18f5fbe9e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=534 identity=4009 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.170 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e18f5fbe9e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=534 identity=4009 ipv4=10.0.0.170 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=e18f5fbe9e datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=534 identity=4009 ipv4=10.0.0.170 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=e18f5fbe9e datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=534 identity=4009 ipv4=10.0.0.170 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.40 735d306f-a0e3-46c4-9551-430d7759ce84 default }" containerID=7cb625ef4e5ff627ae95c00adbf8a33e072e3032e578ea8e95a921a09f60e372 datapathConfiguration="&{false false false false false }" interface=lxca4c06c613816 k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=7cb625ef4e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2968 ipv4=10.0.0.40 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=7cb625ef4e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2968 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.40 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:alertmanager=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=alertmanager;k8s:app.kubernetes.io/version=0.27.0;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager;k8s:io.kubernetes.pod.namespace=monitoring;k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=7cb625ef4e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2968 identity=38549 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.40 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=7cb625ef4e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2968 identity=38549 ipv4=10.0.0.40 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=7cb625ef4e datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2968 identity=38549 ipv4=10.0.0.40 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=7cb625ef4e datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2968 identity=38549 ipv4=10.0.0.40 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.39 6e63a3f7-48e6-496e-9f33-5b0e5eceba09 default }" containerID=a268f0134b22d1b5abc721db75d6229c698e114fc1946d3397c06323a612c3b4 datapathConfiguration="&{false false false false false }" interface=lxc66184cf36057 k8sPodName=local-path-storage/helper-pod-create-pvc-7d5232d3-8197-40d8-a97e-a722c401285a labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=a268f0134b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1432 ipv4=10.0.0.39 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7d5232d3-8197-40d8-a97e-a722c401285a subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=a268f0134b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1432 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.39 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7d5232d3-8197-40d8-a97e-a722c401285a subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=a268f0134b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1432 identity=47355 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.39 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7d5232d3-8197-40d8-a97e-a722c401285a oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=a268f0134b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1432 identity=47355 ipv4=10.0.0.39 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7d5232d3-8197-40d8-a97e-a722c401285a subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=a268f0134b datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1432 identity=47355 ipv4=10.0.0.39 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7d5232d3-8197-40d8-a97e-a722c401285a subsys=endpoint level=info msg="Successful endpoint creation" containerID=a268f0134b datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1432 identity=47355 ipv4=10.0.0.39 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7d5232d3-8197-40d8-a97e-a722c401285a subsys=daemon level=info msg="Delete endpoint request" containerID=a268f0134b endpointID=1432 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-7d5232d3-8197-40d8-a97e-a722c401285a subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=a268f0134b datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1432 identity=47355 ipv4=10.0.0.39 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-7d5232d3-8197-40d8-a97e-a722c401285a subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.125 f0ce68fc-3c21-4ae6-8b3b-76942b9c70dd default }" containerID=70ad15504edd6483afb0d5d81d1f78427c10c4fb13c4d4dae8cef18446d93b46 datapathConfiguration="&{false false false false false }" interface=lxcc970106f6ec7 k8sPodName=openstack/rabbitmq-keystone-server-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=70ad15504e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3228 ipv4=10.0.0.125 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=70ad15504e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3228 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.125 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq;k8s:app.kubernetes.io/name=rabbitmq-keystone;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=70ad15504e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3228 identity=43195 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.125 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=70ad15504e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3228 identity=43195 ipv4=10.0.0.125 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=70ad15504e datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3228 identity=43195 ipv4=10.0.0.125 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=70ad15504e datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3228 identity=43195 ipv4=10.0.0.125 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.26 fecc64e7-93f3-4e23-b43f-78b286b2642e default }" containerID=f356a6617b20d89b1db8c4a37e51a762f2992816e534d4636e77fde1534af0d4 datapathConfiguration="&{false false false false false }" interface=lxc52262a679ebb k8sPodName=openstack/keystone-api-59bd7ff894-ddfx2 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f356a6617b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3534 ipv4=10.0.0.26 ipv6= k8sPodName=openstack/keystone-api-59bd7ff894-ddfx2 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f356a6617b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3534 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.26 ipv6= k8sPodName=openstack/keystone-api-59bd7ff894-ddfx2 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:component=api;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-api;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=keystone;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=f356a6617b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3534 identity=25700 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.26 ipv6= k8sPodName=openstack/keystone-api-59bd7ff894-ddfx2 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f356a6617b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3534 identity=25700 ipv4=10.0.0.26 ipv6= k8sPodName=openstack/keystone-api-59bd7ff894-ddfx2 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.249 d5437480-cc2a-4cae-a08c-94ed5a4a207c default }" containerID=f576f73de70f7c10e618004fea8043fbd29dbed20fd5c8956ec3ff868e9705b5 datapathConfiguration="&{false false false false false }" interface=lxceaeb5e43b06d k8sPodName=openstack/keystone-credential-setup-pr28h labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f576f73de7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=925 ipv4=10.0.0.249 ipv6= k8sPodName=openstack/keystone-credential-setup-pr28h subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f576f73de7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=925 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=90985a7f-dbbb-4bdf-8e24-02fd176ad10c,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=90985a7f-dbbb-4bdf-8e24-02fd176ad10c,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.249 ipv6= k8sPodName=openstack/keystone-credential-setup-pr28h subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=90985a7f-dbbb-4bdf-8e24-02fd176ad10c;k8s:batch.kubernetes.io/job-name=keystone-credential-setup;k8s:component=credential-setup;k8s:controller-uid=90985a7f-dbbb-4bdf-8e24-02fd176ad10c;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-credential-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=f576f73de7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=925 identity=1577 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=90985a7f-dbbb-4bdf-8e24-02fd176ad10c,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=90985a7f-dbbb-4bdf-8e24-02fd176ad10c,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.249 ipv6= k8sPodName=openstack/keystone-credential-setup-pr28h oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f576f73de7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=925 identity=1577 ipv4=10.0.0.249 ipv6= k8sPodName=openstack/keystone-credential-setup-pr28h subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=f356a6617b datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3534 identity=25700 ipv4=10.0.0.26 ipv6= k8sPodName=openstack/keystone-api-59bd7ff894-ddfx2 subsys=endpoint level=info msg="Successful endpoint creation" containerID=f356a6617b datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3534 identity=25700 ipv4=10.0.0.26 ipv6= k8sPodName=openstack/keystone-api-59bd7ff894-ddfx2 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=f576f73de7 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=925 identity=1577 ipv4=10.0.0.249 ipv6= k8sPodName=openstack/keystone-credential-setup-pr28h subsys=endpoint level=info msg="Successful endpoint creation" containerID=f576f73de7 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=925 identity=1577 ipv4=10.0.0.249 ipv6= k8sPodName=openstack/keystone-credential-setup-pr28h subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=f576f73de7 endpointID=925 k8sNamespace=openstack k8sPodName=keystone-credential-setup-pr28h subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=90985a7f-dbbb-4bdf-8e24-02fd176ad10c k8s:batch.kubernetes.io/job-name=keystone-credential-setup k8s:component=credential-setup k8s:controller-uid=90985a7f-dbbb-4bdf-8e24-02fd176ad10c k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-credential-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=f576f73de7 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=925 identity=1577 ipv4=10.0.0.249 ipv6= k8sPodName=openstack/keystone-credential-setup-pr28h subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.217 e8cfad6d-e598-4620-8fcf-ebff393cefc8 default }" containerID=f19602de9844f62051577ec659f1bd95ae07dbf97f7277652001eea475db163e datapathConfiguration="&{false false false false false }" interface=lxcd9fb10c8e9f3 k8sPodName=openstack/keystone-db-init-hg8pw labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f19602de98 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3179 ipv4=10.0.0.217 ipv6= k8sPodName=openstack/keystone-db-init-hg8pw subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f19602de98 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3179 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=65c11dfa-52c9-45ac-94bf-1496dda10a50,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=65c11dfa-52c9-45ac-94bf-1496dda10a50,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.217 ipv6= k8sPodName=openstack/keystone-db-init-hg8pw subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=65c11dfa-52c9-45ac-94bf-1496dda10a50;k8s:batch.kubernetes.io/job-name=keystone-db-init;k8s:component=db-init;k8s:controller-uid=65c11dfa-52c9-45ac-94bf-1496dda10a50;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-init;k8s:release_group=keystone;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=f19602de98 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3179 identity=2607 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=65c11dfa-52c9-45ac-94bf-1496dda10a50,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=65c11dfa-52c9-45ac-94bf-1496dda10a50,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.217 ipv6= k8sPodName=openstack/keystone-db-init-hg8pw oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f19602de98 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3179 identity=2607 ipv4=10.0.0.217 ipv6= k8sPodName=openstack/keystone-db-init-hg8pw subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=f19602de98 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3179 identity=2607 ipv4=10.0.0.217 ipv6= k8sPodName=openstack/keystone-db-init-hg8pw subsys=endpoint level=info msg="Successful endpoint creation" containerID=f19602de98 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3179 identity=2607 ipv4=10.0.0.217 ipv6= k8sPodName=openstack/keystone-db-init-hg8pw subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=f19602de98 endpointID=3179 k8sNamespace=openstack k8sPodName=keystone-db-init-hg8pw subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=65c11dfa-52c9-45ac-94bf-1496dda10a50 k8s:batch.kubernetes.io/job-name=keystone-db-init k8s:component=db-init k8s:controller-uid=65c11dfa-52c9-45ac-94bf-1496dda10a50 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=f19602de98 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3179 identity=2607 ipv4=10.0.0.217 ipv6= k8sPodName=openstack/keystone-db-init-hg8pw subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.76 9571530b-e49f-4ed0-b054-5b5d251e68de default }" containerID=d2746d46e4b922f8b1c3706016ae8ac467f1e90e68195fc454a76752091fe405 datapathConfiguration="&{false false false false false }" interface=lxcd68d05b47bc4 k8sPodName=openstack/keystone-fernet-setup-24djk labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d2746d46e4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1065 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-fernet-setup-24djk subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d2746d46e4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1065 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=bd8e89f5-3738-4d91-bb56-8f8b527da97d,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=bd8e89f5-3738-4d91-bb56-8f8b527da97d,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-fernet-setup-24djk subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=bd8e89f5-3738-4d91-bb56-8f8b527da97d;k8s:batch.kubernetes.io/job-name=keystone-fernet-setup;k8s:component=fernet-setup;k8s:controller-uid=bd8e89f5-3738-4d91-bb56-8f8b527da97d;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-fernet-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d2746d46e4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1065 identity=18756 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=bd8e89f5-3738-4d91-bb56-8f8b527da97d,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=bd8e89f5-3738-4d91-bb56-8f8b527da97d,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-fernet-setup-24djk oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=d2746d46e4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1065 identity=18756 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-fernet-setup-24djk subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=d2746d46e4 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1065 identity=18756 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-fernet-setup-24djk subsys=endpoint level=info msg="Successful endpoint creation" containerID=d2746d46e4 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1065 identity=18756 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-fernet-setup-24djk subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=d2746d46e4 endpointID=1065 k8sNamespace=openstack k8sPodName=keystone-fernet-setup-24djk subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=bd8e89f5-3738-4d91-bb56-8f8b527da97d k8s:batch.kubernetes.io/job-name=keystone-fernet-setup k8s:component=fernet-setup k8s:controller-uid=bd8e89f5-3738-4d91-bb56-8f8b527da97d k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-fernet-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=d2746d46e4 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1065 identity=18756 ipv4=10.0.0.76 ipv6= k8sPodName=openstack/keystone-fernet-setup-24djk subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.186 eb1c11bf-6ac3-456f-9e99-edd2ca60bb3f default }" containerID=e1114927e4bb19c0ad3a89a43fa44ff3b20143cbddbd6ee120b832030f8045ca datapathConfiguration="&{false false false false false }" interface=lxcd43883743ee7 k8sPodName=openstack/keystone-db-sync-rp6hs labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e1114927e4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2329 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-db-sync-rp6hs subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e1114927e4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2329 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=4836056a-f66d-4089-8e90-8c913e9dc88d,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=4836056a-f66d-4089-8e90-8c913e9dc88d,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-db-sync-rp6hs subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=e1114927e4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2329 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-db-sync-rp6hs line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=4836056a-f66d-4089-8e90-8c913e9dc88d;k8s:batch.kubernetes.io/job-name=keystone-db-sync;k8s:component=db-sync;k8s:controller-uid=4836056a-f66d-4089-8e90-8c913e9dc88d;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-sync;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e1114927e4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2329 identity=10339 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=4836056a-f66d-4089-8e90-8c913e9dc88d,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=4836056a-f66d-4089-8e90-8c913e9dc88d,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-db-sync-rp6hs oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e1114927e4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2329 identity=10339 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-db-sync-rp6hs subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=e1114927e4 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2329 identity=10339 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-db-sync-rp6hs subsys=endpoint level=info msg="Successful endpoint creation" containerID=e1114927e4 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2329 identity=10339 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-db-sync-rp6hs subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=e1114927e4 endpointID=2329 k8sNamespace=openstack k8sPodName=keystone-db-sync-rp6hs subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=4836056a-f66d-4089-8e90-8c913e9dc88d k8s:batch.kubernetes.io/job-name=keystone-db-sync k8s:component=db-sync k8s:controller-uid=4836056a-f66d-4089-8e90-8c913e9dc88d k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-sync k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=e1114927e4 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2329 identity=10339 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-db-sync-rp6hs subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.186 7a9875a5-87ab-4e1b-908f-f27baf0b7952 default }" containerID=4b9c523a1a0256dd7a1f6b1efaaf1be4f357ab391d80cb251394e1870256b001 datapathConfiguration="&{false false false false false }" interface=lxc97530b4581df k8sPodName=openstack/keystone-rabbit-init-ct5k5 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=4b9c523a1a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=622 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-rabbit-init-ct5k5 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=4b9c523a1a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=622 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=91035e8f-a95e-4bb6-af7e-132114f2ab16,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=91035e8f-a95e-4bb6-af7e-132114f2ab16,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-rabbit-init-ct5k5 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=91035e8f-a95e-4bb6-af7e-132114f2ab16;k8s:batch.kubernetes.io/job-name=keystone-rabbit-init;k8s:component=rabbit-init;k8s:controller-uid=91035e8f-a95e-4bb6-af7e-132114f2ab16;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-rabbit-init;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=4b9c523a1a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=622 identity=28719 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=91035e8f-a95e-4bb6-af7e-132114f2ab16,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=91035e8f-a95e-4bb6-af7e-132114f2ab16,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-rabbit-init-ct5k5 oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=4b9c523a1a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=622 identity=28719 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-rabbit-init-ct5k5 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=4b9c523a1a datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=622 identity=28719 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-rabbit-init-ct5k5 subsys=endpoint level=info msg="Successful endpoint creation" containerID=4b9c523a1a datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=622 identity=28719 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-rabbit-init-ct5k5 subsys=daemon level=info msg="Delete endpoint request" containerID=4b9c523a1a endpointID=622 k8sNamespace=openstack k8sPodName=keystone-rabbit-init-ct5k5 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=91035e8f-a95e-4bb6-af7e-132114f2ab16 k8s:batch.kubernetes.io/job-name=keystone-rabbit-init k8s:component=rabbit-init k8s:controller-uid=91035e8f-a95e-4bb6-af7e-132114f2ab16 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-rabbit-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=4b9c523a1a datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=622 identity=28719 ipv4=10.0.0.186 ipv6= k8sPodName=openstack/keystone-rabbit-init-ct5k5 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.195 586aa657-c5fc-4099-8e83-8829bcee88bc default }" containerID=5c6254931ebaddcc8d762d1e200972086ca18e8f40808993ebf46cf24e12228c datapathConfiguration="&{false false false false false }" interface=lxc9099b6ddf1bd k8sPodName=openstack/keystone-domain-manage-pwrx9 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=5c6254931e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=725 ipv4=10.0.0.195 ipv6= k8sPodName=openstack/keystone-domain-manage-pwrx9 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=5c6254931e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=725 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=0f9eda3d-271c-46ed-9a0d-072ce3f62d56,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=0f9eda3d-271c-46ed-9a0d-072ce3f62d56,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.195 ipv6= k8sPodName=openstack/keystone-domain-manage-pwrx9 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=5c6254931e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=725 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.195 ipv6= k8sPodName=openstack/keystone-domain-manage-pwrx9 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=0f9eda3d-271c-46ed-9a0d-072ce3f62d56;k8s:batch.kubernetes.io/job-name=keystone-domain-manage;k8s:component=domain-manage;k8s:controller-uid=0f9eda3d-271c-46ed-9a0d-072ce3f62d56;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-domain-manage;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=5c6254931e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=725 identity=36928 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=0f9eda3d-271c-46ed-9a0d-072ce3f62d56,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=0f9eda3d-271c-46ed-9a0d-072ce3f62d56,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.195 ipv6= k8sPodName=openstack/keystone-domain-manage-pwrx9 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=5c6254931e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=725 identity=36928 ipv4=10.0.0.195 ipv6= k8sPodName=openstack/keystone-domain-manage-pwrx9 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=5c6254931e datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=725 identity=36928 ipv4=10.0.0.195 ipv6= k8sPodName=openstack/keystone-domain-manage-pwrx9 subsys=endpoint level=info msg="Successful endpoint creation" containerID=5c6254931e datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=725 identity=36928 ipv4=10.0.0.195 ipv6= k8sPodName=openstack/keystone-domain-manage-pwrx9 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=5c6254931e endpointID=725 k8sNamespace=openstack k8sPodName=keystone-domain-manage-pwrx9 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=0f9eda3d-271c-46ed-9a0d-072ce3f62d56 k8s:batch.kubernetes.io/job-name=keystone-domain-manage k8s:component=domain-manage k8s:controller-uid=0f9eda3d-271c-46ed-9a0d-072ce3f62d56 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-domain-manage k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=5c6254931e datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=725 identity=36928 ipv4=10.0.0.195 ipv6= k8sPodName=openstack/keystone-domain-manage-pwrx9 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.191 84b2d534-327f-405c-a097-94d159bf34aa default }" containerID=f2b9afa2ca4f58ecf256031c92a937cb2672a1b9a43924079767b220e843046e datapathConfiguration="&{false false false false false }" interface=lxc3c96e31ab12c k8sPodName=openstack/keystone-bootstrap-j8z8q labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f2b9afa2ca datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=33 ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-bootstrap-j8z8q subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f2b9afa2ca datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=33 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=7c3b6e9b-dbe7-4253-a7b7-f0b0838f4720,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=7c3b6e9b-dbe7-4253-a7b7-f0b0838f4720,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-bootstrap-j8z8q subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=7c3b6e9b-dbe7-4253-a7b7-f0b0838f4720;k8s:batch.kubernetes.io/job-name=keystone-bootstrap;k8s:component=bootstrap;k8s:controller-uid=7c3b6e9b-dbe7-4253-a7b7-f0b0838f4720;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-bootstrap;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=f2b9afa2ca datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=33 identity=34050 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=7c3b6e9b-dbe7-4253-a7b7-f0b0838f4720,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=7c3b6e9b-dbe7-4253-a7b7-f0b0838f4720,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-bootstrap-j8z8q oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f2b9afa2ca datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=33 identity=34050 ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-bootstrap-j8z8q subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=f2b9afa2ca datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=33 identity=34050 ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-bootstrap-j8z8q subsys=endpoint level=info msg="Successful endpoint creation" containerID=f2b9afa2ca datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=33 identity=34050 ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-bootstrap-j8z8q subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=f2b9afa2ca endpointID=33 k8sNamespace=openstack k8sPodName=keystone-bootstrap-j8z8q subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=7c3b6e9b-dbe7-4253-a7b7-f0b0838f4720 k8s:batch.kubernetes.io/job-name=keystone-bootstrap k8s:component=bootstrap k8s:controller-uid=7c3b6e9b-dbe7-4253-a7b7-f0b0838f4720 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-bootstrap k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=f2b9afa2ca datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=33 identity=34050 ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-bootstrap-j8z8q subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.62 8a02afbc-3c92-46ea-b01c-d2acc02aeae5 default }" containerID=9bf99634a43de796c5f191696fbd1e53ee0f694d0646dec92c7e7c05ae2bcb7a datapathConfiguration="&{false false false false false }" interface=lxca37272ef452c k8sPodName=openstack/horizon-56b4ffd8cc-xlnct labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=9bf99634a4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2010 ipv4=10.0.0.62 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-xlnct subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=9bf99634a4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2010 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.62 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-xlnct subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=9bf99634a4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2010 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.62 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-xlnct line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=9bf99634a4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2010 identity=34947 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.62 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-xlnct oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=9bf99634a4 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2010 identity=34947 ipv4=10.0.0.62 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-xlnct subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.56 6225863b-bb64-429d-a662-c0889e81a5f6 default }" containerID=d23d97e1342f5ef3b85d82cfce9f11631fc229d8462f121c87590c1d2f989ec3 datapathConfiguration="&{false false false false false }" interface=lxc125ee574047b k8sPodName=openstack/horizon-db-init-stk8c labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d23d97e134 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1369 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/horizon-db-init-stk8c subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d23d97e134 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1369 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=ab2c5d28-99db-4208-a41c-2babb4ba7a47,k8s:batch.kubernetes.io/job-name=horizon-db-init,k8s:component=db-init,k8s:controller-uid=ab2c5d28-99db-4208-a41c-2babb4ba7a47,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-init,k8s:release_group=horizon" ipv4=10.0.0.56 ipv6= k8sPodName=openstack/horizon-db-init-stk8c subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:batch.kubernetes.io/controller-uid=ab2c5d28-99db-4208-a41c-2babb4ba7a47;k8s:batch.kubernetes.io/job-name=horizon-db-init;k8s:component=db-init;k8s:controller-uid=ab2c5d28-99db-4208-a41c-2babb4ba7a47;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=horizon-db-init;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d23d97e134 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1369 identity=11056 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=ab2c5d28-99db-4208-a41c-2babb4ba7a47,k8s:batch.kubernetes.io/job-name=horizon-db-init,k8s:component=db-init,k8s:controller-uid=ab2c5d28-99db-4208-a41c-2babb4ba7a47,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-init,k8s:release_group=horizon" ipv4=10.0.0.56 ipv6= k8sPodName=openstack/horizon-db-init-stk8c oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d23d97e134 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1369 identity=11056 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/horizon-db-init-stk8c subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=9bf99634a4 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2010 identity=34947 ipv4=10.0.0.62 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-xlnct subsys=endpoint level=info msg="Successful endpoint creation" containerID=9bf99634a4 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2010 identity=34947 ipv4=10.0.0.62 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-xlnct subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=d23d97e134 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1369 identity=11056 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/horizon-db-init-stk8c subsys=endpoint level=info msg="Successful endpoint creation" containerID=d23d97e134 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1369 identity=11056 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/horizon-db-init-stk8c subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.168 cfb0828a-9387-451f-99b6-df5e5c6de026 default }" containerID=25c387461a3627c8d5b9c92f340870c48673fe6101fcdbba9698a6af955fd780 datapathConfiguration="&{false false false false false }" interface=lxc5291e2dd9873 k8sPodName=openstack/horizon-56b4ffd8cc-r2r5h labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=25c387461a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=694 ipv4=10.0.0.168 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-r2r5h subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=25c387461a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=694 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.168 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-r2r5h subsys=endpoint level=info msg="Identity of endpoint changed" containerID=25c387461a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=694 identity=34947 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.168 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-r2r5h oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=25c387461a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=694 identity=34947 ipv4=10.0.0.168 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-r2r5h subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.154 2c96485d-5f58-4d6e-8cf2-0128c7865904 default }" containerID=6062a4f5799ecaa0fe7f17a995169f158777962caaef82b799c83a623994a7aa datapathConfiguration="&{false false false false false }" interface=lxc5e5930c45db9 k8sPodName=openstack/horizon-56b4ffd8cc-79zd7 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=6062a4f579 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3375 ipv4=10.0.0.154 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-79zd7 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=6062a4f579 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3375 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.154 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-79zd7 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=6062a4f579 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3375 identity=34947 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.154 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-79zd7 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=6062a4f579 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3375 identity=34947 ipv4=10.0.0.154 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-79zd7 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=25c387461a datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=694 identity=34947 ipv4=10.0.0.168 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-r2r5h subsys=endpoint level=info msg="Successful endpoint creation" containerID=25c387461a datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=694 identity=34947 ipv4=10.0.0.168 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-r2r5h subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=6062a4f579 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3375 identity=34947 ipv4=10.0.0.154 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-79zd7 subsys=endpoint level=info msg="Successful endpoint creation" containerID=6062a4f579 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3375 identity=34947 ipv4=10.0.0.154 ipv6= k8sPodName=openstack/horizon-56b4ffd8cc-79zd7 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=d23d97e134 endpointID=1369 k8sNamespace=openstack k8sPodName=horizon-db-init-stk8c subsys=daemon level=info msg="Releasing key" key="[k8s:application=horizon k8s:batch.kubernetes.io/controller-uid=ab2c5d28-99db-4208-a41c-2babb4ba7a47 k8s:batch.kubernetes.io/job-name=horizon-db-init k8s:component=db-init k8s:controller-uid=ab2c5d28-99db-4208-a41c-2babb4ba7a47 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=horizon-db-init k8s:release_group=horizon]" subsys=allocator level=info msg="Removed endpoint" containerID=d23d97e134 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1369 identity=11056 ipv4=10.0.0.56 ipv6= k8sPodName=openstack/horizon-db-init-stk8c subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.148 39a29edd-6eea-4e5a-8fee-f451ade3270f default }" containerID=604ff4cd84eef9716c6dd8bf9d8515433965bef8503eb038350252bb4d665ef7 datapathConfiguration="&{false false false false false }" interface=lxc359ea43398e3 k8sPodName=openstack/horizon-db-sync-cx5xk labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=604ff4cd84 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2395 ipv4=10.0.0.148 ipv6= k8sPodName=openstack/horizon-db-sync-cx5xk subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=604ff4cd84 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2395 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=41465305-6f40-4499-ba16-9c813bf44f0a,k8s:batch.kubernetes.io/job-name=horizon-db-sync,k8s:component=db-sync,k8s:controller-uid=41465305-6f40-4499-ba16-9c813bf44f0a,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-sync,k8s:release_group=horizon" ipv4=10.0.0.148 ipv6= k8sPodName=openstack/horizon-db-sync-cx5xk subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:batch.kubernetes.io/controller-uid=41465305-6f40-4499-ba16-9c813bf44f0a;k8s:batch.kubernetes.io/job-name=horizon-db-sync;k8s:component=db-sync;k8s:controller-uid=41465305-6f40-4499-ba16-9c813bf44f0a;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=horizon-db-sync;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=604ff4cd84 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2395 identity=25188 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=41465305-6f40-4499-ba16-9c813bf44f0a,k8s:batch.kubernetes.io/job-name=horizon-db-sync,k8s:component=db-sync,k8s:controller-uid=41465305-6f40-4499-ba16-9c813bf44f0a,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-sync,k8s:release_group=horizon" ipv4=10.0.0.148 ipv6= k8sPodName=openstack/horizon-db-sync-cx5xk oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=604ff4cd84 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2395 identity=25188 ipv4=10.0.0.148 ipv6= k8sPodName=openstack/horizon-db-sync-cx5xk subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=604ff4cd84 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2395 identity=25188 ipv4=10.0.0.148 ipv6= k8sPodName=openstack/horizon-db-sync-cx5xk subsys=endpoint level=info msg="Successful endpoint creation" containerID=604ff4cd84 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2395 identity=25188 ipv4=10.0.0.148 ipv6= k8sPodName=openstack/horizon-db-sync-cx5xk subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=604ff4cd84 endpointID=2395 k8sNamespace=openstack k8sPodName=horizon-db-sync-cx5xk subsys=daemon level=info msg="Releasing key" key="[k8s:application=horizon k8s:batch.kubernetes.io/controller-uid=41465305-6f40-4499-ba16-9c813bf44f0a k8s:batch.kubernetes.io/job-name=horizon-db-sync k8s:component=db-sync k8s:controller-uid=41465305-6f40-4499-ba16-9c813bf44f0a k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=horizon-db-sync k8s:release_group=horizon]" subsys=allocator level=info msg="Removed endpoint" containerID=604ff4cd84 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2395 identity=25188 ipv4=10.0.0.148 ipv6= k8sPodName=openstack/horizon-db-sync-cx5xk subsys=endpoint