level=info msg="Memory available for map entries (0.003% of 16764968960B): 41912422B" subsys=config level=info msg="option bpf-ct-global-tcp-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-ct-global-any-max set by dynamic sizing to 73530" subsys=config level=info msg="option bpf-nat-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-neigh-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-sock-rev-map-max set by dynamic sizing to 73530" subsys=config level=info msg=" --agent-health-port='9879'" subsys=daemon level=info msg=" --agent-labels=''" subsys=daemon level=info msg=" --agent-liveness-update-interval='1s'" subsys=daemon level=info msg=" --agent-not-ready-taint-key='node.cilium.io/agent-not-ready'" subsys=daemon level=info msg=" --allocator-list-timeout='3m0s'" subsys=daemon level=info msg=" --allow-icmp-frag-needed='true'" subsys=daemon level=info msg=" --allow-localhost='auto'" subsys=daemon level=info msg=" --annotate-k8s-node='false'" subsys=daemon level=info msg=" --api-rate-limit=''" subsys=daemon level=info msg=" --arping-refresh-period='30s'" subsys=daemon level=info msg=" --auto-create-cilium-node-resource='true'" subsys=daemon level=info msg=" --auto-direct-node-routes='false'" subsys=daemon level=info msg=" --bgp-announce-lb-ip='false'" subsys=daemon level=info msg=" --bgp-announce-pod-cidr='false'" subsys=daemon level=info msg=" --bgp-config-path='/var/lib/cilium/bgp/config.yaml'" subsys=daemon level=info msg=" --bpf-auth-map-max='524288'" subsys=daemon level=info msg=" --bpf-ct-global-any-max='262144'" subsys=daemon level=info msg=" --bpf-ct-global-tcp-max='524288'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-fin='10s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-syn='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp-grace='1m0s'" subsys=daemon level=info msg=" --bpf-filter-priority='1'" subsys=daemon level=info msg=" --bpf-fragments-map-max='8192'" subsys=daemon level=info msg=" --bpf-lb-acceleration='disabled'" subsys=daemon level=info msg=" --bpf-lb-affinity-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-algorithm='random'" subsys=daemon level=info msg=" --bpf-lb-dev-ip-addr-inherit=''" subsys=daemon level=info msg=" --bpf-lb-dsr-dispatch='opt'" subsys=daemon level=info msg=" --bpf-lb-dsr-l4-xlate='frontend'" subsys=daemon level=info msg=" --bpf-lb-external-clusterip='false'" subsys=daemon level=info msg=" --bpf-lb-maglev-hash-seed='JLfvgnHc2kaSUFaI'" subsys=daemon level=info msg=" --bpf-lb-maglev-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-maglev-table-size='16381'" subsys=daemon level=info msg=" --bpf-lb-map-max='65536'" subsys=daemon level=info msg=" --bpf-lb-mode='snat'" subsys=daemon level=info msg=" --bpf-lb-rev-nat-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-rss-ipv4-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-rss-ipv6-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-service-backend-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-service-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-sock='false'" subsys=daemon level=info msg=" --bpf-lb-sock-hostns-only='false'" subsys=daemon level=info msg=" --bpf-lb-source-range-map-max='0'" subsys=daemon level=info msg=" --bpf-map-dynamic-size-ratio='0.0025'" subsys=daemon level=info msg=" --bpf-map-event-buffers=''" subsys=daemon level=info msg=" --bpf-nat-global-max='524288'" subsys=daemon level=info msg=" --bpf-neigh-global-max='524288'" subsys=daemon level=info msg=" --bpf-policy-map-full-reconciliation-interval='15m0s'" subsys=daemon level=info msg=" --bpf-policy-map-max='16384'" subsys=daemon level=info msg=" --bpf-root='/sys/fs/bpf'" subsys=daemon level=info msg=" --bpf-sock-rev-map-max='262144'" subsys=daemon level=info msg=" --bypass-ip-availability-upon-restore='false'" subsys=daemon level=info msg=" --certificates-directory='/var/run/cilium/certs'" subsys=daemon level=info msg=" --cflags=''" subsys=daemon level=info msg=" --cgroup-root='/run/cilium/cgroupv2'" subsys=daemon level=info msg=" --cilium-endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --cluster-health-port='4240'" subsys=daemon level=info msg=" --cluster-id='0'" subsys=daemon level=info msg=" --cluster-name='default'" subsys=daemon level=info msg=" --cluster-pool-ipv4-cidr='10.0.0.0/8'" subsys=daemon level=info msg=" --cluster-pool-ipv4-mask-size='24'" subsys=daemon level=info msg=" --clustermesh-config='/var/lib/cilium/clustermesh/'" subsys=daemon level=info msg=" --clustermesh-ip-identities-sync-timeout='1m0s'" subsys=daemon level=info msg=" --cmdref=''" subsys=daemon level=info msg=" --cni-chaining-mode='none'" subsys=daemon level=info msg=" --cni-chaining-target=''" subsys=daemon level=info msg=" --cni-exclusive='true'" subsys=daemon level=info msg=" --cni-external-routing='false'" subsys=daemon level=info msg=" --cni-log-file='/var/run/cilium/cilium-cni.log'" subsys=daemon level=info msg=" --cnp-node-status-gc-interval='0s'" subsys=daemon level=info msg=" --config=''" subsys=daemon level=info msg=" --config-dir='/tmp/cilium/config-map'" subsys=daemon level=info msg=" --config-sources='config-map:kube-system/cilium-config'" subsys=daemon level=info msg=" --conntrack-gc-interval='0s'" subsys=daemon level=info msg=" --conntrack-gc-max-interval='0s'" subsys=daemon level=info msg=" --crd-wait-timeout='5m0s'" subsys=daemon level=info msg=" --custom-cni-conf='false'" subsys=daemon level=info msg=" --datapath-mode='veth'" subsys=daemon level=info msg=" --debug='false'" subsys=daemon level=info msg=" --debug-verbose=''" subsys=daemon level=info msg=" --derive-masquerade-ip-addr-from-device=''" subsys=daemon level=info msg=" --devices=''" subsys=daemon level=info msg=" --direct-routing-device=''" subsys=daemon level=info msg=" --disable-cnp-status-updates='true'" subsys=daemon level=info msg=" --disable-endpoint-crd='false'" subsys=daemon level=info msg=" --disable-envoy-version-check='false'" subsys=daemon level=info msg=" --disable-iptables-feeder-rules=''" subsys=daemon level=info msg=" --dns-max-ips-per-restored-rule='1000'" subsys=daemon level=info msg=" --dns-policy-unload-on-shutdown='false'" subsys=daemon level=info msg=" --dnsproxy-concurrency-limit='0'" subsys=daemon level=info msg=" --dnsproxy-concurrency-processing-grace-period='0s'" subsys=daemon level=info msg=" --dnsproxy-enable-transparent-mode='true'" subsys=daemon level=info msg=" --dnsproxy-lock-count='128'" subsys=daemon level=info msg=" --dnsproxy-lock-timeout='500ms'" subsys=daemon level=info msg=" --egress-gateway-policy-map-max='16384'" subsys=daemon level=info msg=" --egress-gateway-reconciliation-trigger-interval='1s'" subsys=daemon level=info msg=" --egress-masquerade-interfaces=''" subsys=daemon level=info msg=" --egress-multi-home-ip-rule-compat='false'" subsys=daemon level=info msg=" --enable-auto-protect-node-port-range='true'" subsys=daemon level=info msg=" --enable-bandwidth-manager='false'" subsys=daemon level=info msg=" --enable-bbr='false'" subsys=daemon level=info msg=" --enable-bgp-control-plane='false'" subsys=daemon level=info msg=" --enable-bpf-clock-probe='false'" subsys=daemon level=info msg=" --enable-bpf-masquerade='false'" subsys=daemon level=info msg=" --enable-bpf-tproxy='false'" subsys=daemon level=info msg=" --enable-cilium-api-server-access='*'" subsys=daemon level=info msg=" --enable-cilium-endpoint-slice='false'" subsys=daemon level=info msg=" --enable-cilium-health-api-server-access='*'" subsys=daemon level=info msg=" --enable-custom-calls='false'" subsys=daemon level=info msg=" --enable-endpoint-health-checking='true'" subsys=daemon level=info msg=" --enable-endpoint-routes='false'" subsys=daemon level=info msg=" --enable-envoy-config='false'" subsys=daemon level=info msg=" --enable-external-ips='false'" subsys=daemon level=info msg=" --enable-health-check-nodeport='true'" subsys=daemon level=info msg=" --enable-health-checking='true'" subsys=daemon level=info msg=" --enable-high-scale-ipcache='false'" subsys=daemon level=info msg=" --enable-host-firewall='false'" subsys=daemon level=info msg=" --enable-host-legacy-routing='false'" subsys=daemon level=info msg=" --enable-host-port='false'" subsys=daemon level=info msg=" --enable-hubble='false'" subsys=daemon level=info msg=" --enable-hubble-recorder-api='true'" subsys=daemon level=info msg=" --enable-icmp-rules='true'" subsys=daemon level=info msg=" --enable-identity-mark='true'" subsys=daemon level=info msg=" --enable-ip-masq-agent='false'" subsys=daemon level=info msg=" --enable-ipsec='false'" subsys=daemon level=info msg=" --enable-ipsec-key-watcher='true'" subsys=daemon level=info msg=" --enable-ipv4='true'" subsys=daemon level=info msg=" --enable-ipv4-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv4-egress-gateway='false'" subsys=daemon level=info msg=" --enable-ipv4-fragment-tracking='true'" subsys=daemon level=info msg=" --enable-ipv4-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6='false'" subsys=daemon level=info msg=" --enable-ipv6-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv6-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6-ndp='false'" subsys=daemon level=info msg=" --enable-k8s='true'" subsys=daemon level=info msg=" --enable-k8s-api-discovery='false'" subsys=daemon level=info msg=" --enable-k8s-endpoint-slice='true'" subsys=daemon level=info msg=" --enable-k8s-event-handover='false'" subsys=daemon level=info msg=" --enable-k8s-networkpolicy='true'" subsys=daemon level=info msg=" --enable-k8s-terminating-endpoint='true'" subsys=daemon level=info msg=" --enable-l2-announcements='false'" subsys=daemon level=info msg=" --enable-l2-neigh-discovery='true'" subsys=daemon level=info msg=" --enable-l2-pod-announcements='false'" subsys=daemon level=info msg=" --enable-l7-proxy='true'" subsys=daemon level=info msg=" --enable-local-node-route='true'" subsys=daemon level=info msg=" --enable-local-redirect-policy='false'" subsys=daemon level=info msg=" --enable-mke='false'" subsys=daemon level=info msg=" --enable-monitor='true'" subsys=daemon level=info msg=" --enable-nat46x64-gateway='false'" subsys=daemon level=info msg=" --enable-node-port='false'" subsys=daemon level=info msg=" --enable-pmtu-discovery='false'" subsys=daemon level=info msg=" --enable-policy='default'" subsys=daemon level=info msg=" --enable-recorder='false'" subsys=daemon level=info msg=" --enable-remote-node-identity='true'" subsys=daemon level=info msg=" --enable-runtime-device-detection='false'" subsys=daemon level=info msg=" --enable-sctp='false'" subsys=daemon level=info msg=" --enable-service-topology='false'" subsys=daemon level=info msg=" --enable-session-affinity='false'" subsys=daemon level=info msg=" --enable-srv6='false'" subsys=daemon level=info msg=" --enable-stale-cilium-endpoint-cleanup='true'" subsys=daemon level=info msg=" --enable-svc-source-range-check='true'" subsys=daemon level=info msg=" --enable-tracing='false'" subsys=daemon level=info msg=" --enable-unreachable-routes='false'" subsys=daemon level=info msg=" --enable-vtep='false'" subsys=daemon level=info msg=" --enable-well-known-identities='false'" subsys=daemon level=info msg=" --enable-wireguard='false'" subsys=daemon level=info msg=" --enable-wireguard-userspace-fallback='false'" subsys=daemon level=info msg=" --enable-xdp-prefilter='false'" subsys=daemon level=info msg=" --enable-xt-socket-fallback='true'" subsys=daemon level=info msg=" --encrypt-interface=''" subsys=daemon level=info msg=" --encrypt-node='false'" subsys=daemon level=info msg=" --endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --endpoint-queue-size='25'" subsys=daemon level=info msg=" --endpoint-status=''" subsys=daemon level=info msg=" --envoy-config-timeout='2m0s'" subsys=daemon level=info msg=" --envoy-log=''" subsys=daemon level=info msg=" --exclude-local-address=''" subsys=daemon level=info msg=" --external-envoy-proxy='false'" subsys=daemon level=info msg=" --fixed-identity-mapping=''" subsys=daemon level=info msg=" --fqdn-regex-compile-lru-size='1024'" subsys=daemon level=info msg=" --gops-port='9890'" subsys=daemon level=info msg=" --http-403-msg=''" subsys=daemon level=info msg=" --http-idle-timeout='0'" subsys=daemon level=info msg=" --http-max-grpc-timeout='0'" subsys=daemon level=info msg=" --http-normalize-path='true'" subsys=daemon level=info msg=" --http-request-timeout='3600'" subsys=daemon level=info msg=" --http-retry-count='3'" subsys=daemon level=info msg=" --http-retry-timeout='0'" subsys=daemon level=info msg=" --hubble-disable-tls='false'" subsys=daemon level=info msg=" --hubble-event-buffer-capacity='4095'" subsys=daemon level=info msg=" --hubble-event-queue-size='0'" subsys=daemon level=info msg=" --hubble-export-file-compress='false'" subsys=daemon level=info msg=" --hubble-export-file-max-backups='5'" subsys=daemon level=info msg=" --hubble-export-file-max-size-mb='10'" subsys=daemon level=info msg=" --hubble-export-file-path=''" subsys=daemon level=info msg=" --hubble-listen-address=''" subsys=daemon level=info msg=" --hubble-metrics=''" subsys=daemon level=info msg=" --hubble-metrics-server=''" subsys=daemon level=info msg=" --hubble-monitor-events=''" subsys=daemon level=info msg=" --hubble-prefer-ipv6='false'" subsys=daemon level=info msg=" --hubble-recorder-sink-queue-size='1024'" subsys=daemon level=info msg=" --hubble-recorder-storage-path='/var/run/cilium/pcaps'" subsys=daemon level=info msg=" --hubble-skip-unknown-cgroup-ids='true'" subsys=daemon level=info msg=" --hubble-socket-path='/var/run/cilium/hubble.sock'" subsys=daemon level=info msg=" --hubble-tls-cert-file=''" subsys=daemon level=info msg=" --hubble-tls-client-ca-files=''" subsys=daemon level=info msg=" --hubble-tls-key-file=''" subsys=daemon level=info msg=" --identity-allocation-mode='crd'" subsys=daemon level=info msg=" --identity-change-grace-period='5s'" subsys=daemon level=info msg=" --identity-gc-interval='15m0s'" subsys=daemon level=info msg=" --identity-heartbeat-timeout='30m0s'" subsys=daemon level=info msg=" --identity-restore-grace-period='10m0s'" subsys=daemon level=info msg=" --install-egress-gateway-routes='false'" subsys=daemon level=info msg=" --install-iptables-rules='true'" subsys=daemon level=info msg=" --install-no-conntrack-iptables-rules='false'" subsys=daemon level=info msg=" --ip-allocation-timeout='2m0s'" subsys=daemon level=info msg=" --ip-masq-agent-config-path='/etc/config/ip-masq-agent'" subsys=daemon level=info msg=" --ipam='cluster-pool'" subsys=daemon level=info msg=" --ipam-cilium-node-update-rate='15s'" subsys=daemon level=info msg=" --ipam-multi-pool-pre-allocation='default=8'" subsys=daemon level=info msg=" --ipsec-key-file=''" subsys=daemon level=info msg=" --ipsec-key-rotation-duration='5m0s'" subsys=daemon level=info msg=" --iptables-lock-timeout='5s'" subsys=daemon level=info msg=" --iptables-random-fully='false'" subsys=daemon level=info msg=" --ipv4-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv4-node='auto'" subsys=daemon level=info msg=" --ipv4-pod-subnets=''" subsys=daemon level=info msg=" --ipv4-range='auto'" subsys=daemon level=info msg=" --ipv4-service-loopback-address='169.254.42.1'" subsys=daemon level=info msg=" --ipv4-service-range='auto'" subsys=daemon level=info msg=" --ipv6-cluster-alloc-cidr='f00d::/64'" subsys=daemon level=info msg=" --ipv6-mcast-device=''" subsys=daemon level=info msg=" --ipv6-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv6-node='auto'" subsys=daemon level=info msg=" --ipv6-pod-subnets=''" subsys=daemon level=info msg=" --ipv6-range='auto'" subsys=daemon level=info msg=" --ipv6-service-range='auto'" subsys=daemon level=info msg=" --join-cluster='false'" subsys=daemon level=info msg=" --k8s-api-server=''" subsys=daemon level=info msg=" --k8s-client-burst='10'" subsys=daemon level=info msg=" --k8s-client-qps='5'" subsys=daemon level=info msg=" --k8s-heartbeat-timeout='30s'" subsys=daemon level=info msg=" --k8s-kubeconfig-path=''" subsys=daemon level=info msg=" --k8s-namespace='kube-system'" subsys=daemon level=info msg=" --k8s-require-ipv4-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-require-ipv6-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-service-cache-size='128'" subsys=daemon level=info msg=" --k8s-service-proxy-name=''" subsys=daemon level=info msg=" --k8s-sync-timeout='3m0s'" subsys=daemon level=info msg=" --k8s-watcher-endpoint-selector='metadata.name!=kube-scheduler,metadata.name!=kube-controller-manager,metadata.name!=etcd-operator,metadata.name!=gcp-controller-manager'" subsys=daemon level=info msg=" --keep-config='false'" subsys=daemon level=info msg=" --kube-proxy-replacement='disabled'" subsys=daemon level=info msg=" --kube-proxy-replacement-healthz-bind-address=''" subsys=daemon level=info msg=" --kvstore=''" subsys=daemon level=info msg=" --kvstore-connectivity-timeout='2m0s'" subsys=daemon level=info msg=" --kvstore-lease-ttl='15m0s'" subsys=daemon level=info msg=" --kvstore-max-consecutive-quorum-errors='2'" subsys=daemon level=info msg=" --kvstore-opt=''" subsys=daemon level=info msg=" --kvstore-periodic-sync='5m0s'" subsys=daemon level=info msg=" --l2-announcements-lease-duration='15s'" subsys=daemon level=info msg=" --l2-announcements-renew-deadline='5s'" subsys=daemon level=info msg=" --l2-announcements-retry-period='2s'" subsys=daemon level=info msg=" --l2-pod-announcements-interface=''" subsys=daemon level=info msg=" --label-prefix-file=''" subsys=daemon level=info msg=" --labels=''" subsys=daemon level=info msg=" --lib-dir='/var/lib/cilium'" subsys=daemon level=info msg=" --local-max-addr-scope='252'" subsys=daemon level=info msg=" --local-router-ipv4=''" subsys=daemon level=info msg=" --local-router-ipv6=''" subsys=daemon level=info msg=" --log-driver=''" subsys=daemon level=info msg=" --log-opt=''" subsys=daemon level=info msg=" --log-system-load='false'" subsys=daemon level=info msg=" --max-controller-interval='0'" subsys=daemon level=info msg=" --mesh-auth-enabled='true'" subsys=daemon level=info msg=" --mesh-auth-gc-interval='5m0s'" subsys=daemon level=info msg=" --mesh-auth-mutual-listener-port='0'" subsys=daemon level=info msg=" --mesh-auth-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-rotated-identities-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-signal-backoff-duration='1s'" subsys=daemon level=info msg=" --mesh-auth-spiffe-trust-domain='spiffe.cilium'" subsys=daemon level=info msg=" --mesh-auth-spire-admin-socket=''" subsys=daemon level=info msg=" --metrics=''" subsys=daemon level=info msg=" --mke-cgroup-mount=''" subsys=daemon level=info msg=" --monitor-aggregation='medium'" subsys=daemon level=info msg=" --monitor-aggregation-flags='all'" subsys=daemon level=info msg=" --monitor-aggregation-interval='5s'" subsys=daemon level=info msg=" --monitor-queue-size='0'" subsys=daemon level=info msg=" --mtu='0'" subsys=daemon level=info msg=" --node-encryption-opt-out-labels='node-role.kubernetes.io/control-plane'" subsys=daemon level=info msg=" --node-port-acceleration='disabled'" subsys=daemon level=info msg=" --node-port-algorithm='random'" subsys=daemon level=info msg=" --node-port-bind-protection='true'" subsys=daemon level=info msg=" --node-port-mode='snat'" subsys=daemon level=info msg=" --node-port-range='30000,32767'" subsys=daemon level=info msg=" --nodes-gc-interval='5m0s'" subsys=daemon level=info msg=" --operator-api-serve-addr='127.0.0.1:9234'" subsys=daemon level=info msg=" --policy-audit-mode='false'" subsys=daemon level=info msg=" --policy-queue-size='100'" subsys=daemon level=info msg=" --policy-trigger-interval='1s'" subsys=daemon level=info msg=" --pprof='false'" subsys=daemon level=info msg=" --pprof-address='localhost'" subsys=daemon level=info msg=" --pprof-port='6060'" subsys=daemon level=info msg=" --preallocate-bpf-maps='false'" subsys=daemon level=info msg=" --prepend-iptables-chains='true'" subsys=daemon level=info msg=" --procfs='/host/proc'" subsys=daemon level=info msg=" --prometheus-serve-addr=':9962'" subsys=daemon level=info msg=" --proxy-connect-timeout='2'" subsys=daemon level=info msg=" --proxy-gid='1337'" subsys=daemon level=info msg=" --proxy-idle-timeout-seconds='60'" subsys=daemon level=info msg=" --proxy-max-connection-duration-seconds='0'" subsys=daemon level=info msg=" --proxy-max-requests-per-connection='0'" subsys=daemon level=info msg=" --proxy-prometheus-port='9964'" subsys=daemon level=info msg=" --read-cni-conf=''" subsys=daemon level=info msg=" --remove-cilium-node-taints='true'" subsys=daemon level=info msg=" --restore='true'" subsys=daemon level=info msg=" --route-metric='0'" subsys=daemon level=info msg=" --routing-mode='tunnel'" subsys=daemon level=info msg=" --set-cilium-is-up-condition='true'" subsys=daemon level=info msg=" --set-cilium-node-taints='true'" subsys=daemon level=info msg=" --sidecar-istio-proxy-image='cilium/istio_proxy'" subsys=daemon level=info msg=" --single-cluster-route='false'" subsys=daemon level=info msg=" --skip-cnp-status-startup-clean='false'" subsys=daemon level=info msg=" --socket-path='/var/run/cilium/cilium.sock'" subsys=daemon level=info msg=" --srv6-encap-mode='reduced'" subsys=daemon level=info msg=" --state-dir='/var/run/cilium'" subsys=daemon level=info msg=" --synchronize-k8s-nodes='true'" subsys=daemon level=info msg=" --tofqdns-dns-reject-response-code='refused'" subsys=daemon level=info msg=" --tofqdns-enable-dns-compression='true'" subsys=daemon level=info msg=" --tofqdns-endpoint-max-ip-per-hostname='50'" subsys=daemon level=info msg=" --tofqdns-idle-connection-grace-period='0s'" subsys=daemon level=info msg=" --tofqdns-max-deferred-connection-deletes='10000'" subsys=daemon level=info msg=" --tofqdns-min-ttl='0'" subsys=daemon level=info msg=" --tofqdns-pre-cache=''" subsys=daemon level=info msg=" --tofqdns-proxy-port='0'" subsys=daemon level=info msg=" --tofqdns-proxy-response-max-delay='100ms'" subsys=daemon level=info msg=" --trace-payloadlen='128'" subsys=daemon level=info msg=" --trace-sock='true'" subsys=daemon level=info msg=" --tunnel=''" subsys=daemon level=info msg=" --tunnel-port='6082'" subsys=daemon level=info msg=" --tunnel-protocol='geneve'" subsys=daemon level=info msg=" --unmanaged-pod-watcher-interval='15'" subsys=daemon level=info msg=" --use-cilium-internal-ip-for-ipsec='false'" subsys=daemon level=info msg=" --version='false'" subsys=daemon level=info msg=" --vlan-bpf-bypass=''" subsys=daemon level=info msg=" --vtep-cidr=''" subsys=daemon level=info msg=" --vtep-endpoint=''" subsys=daemon level=info msg=" --vtep-mac=''" subsys=daemon level=info msg=" --vtep-mask=''" subsys=daemon level=info msg=" --wireguard-encapsulate='false'" subsys=daemon level=info msg=" --write-cni-conf-when-ready='/host/etc/cni/net.d/05-cilium.conflist'" subsys=daemon level=info msg=" _ _ _" subsys=daemon level=info msg=" ___|_| |_|_ _ _____" subsys=daemon level=info msg="| _| | | | | | |" subsys=daemon level=info msg="|___|_|_|_|___|_|_|_|" subsys=daemon level=info msg="Cilium 1.14.8 cf6e022e 2024-03-13T12:23:35-04:00 go version go1.21.8 linux/amd64" subsys=daemon level=info msg="clang (10.0.0) and kernel (5.15.0) versions: OK!" subsys=linux-datapath level=info msg="linking environment: OK!" subsys=linux-datapath level=info msg="Kernel config file not found: if the agent fails to start, check the system requirements at https://docs.cilium.io/en/stable/operations/system_requirements" subsys=probes level=info msg="Detected mounted BPF filesystem at /sys/fs/bpf" subsys=bpf level=info msg="Mounted cgroupv2 filesystem at /run/cilium/cgroupv2" subsys=cgroups level=info msg="Parsing base label prefixes from default label list" subsys=labels-filter level=info msg="Parsing additional label prefixes from user inputs: []" subsys=labels-filter level=info msg="Final label prefixes to be used for identity evaluation:" subsys=labels-filter level=info msg=" - reserved:.*" subsys=labels-filter level=info msg=" - :io\\.kubernetes\\.pod\\.namespace" subsys=labels-filter level=info msg=" - :io\\.cilium\\.k8s\\.namespace\\.labels" subsys=labels-filter level=info msg=" - :app\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:io\\.kubernetes" subsys=labels-filter level=info msg=" - !:kubernetes\\.io" subsys=labels-filter level=info msg=" - !:.*beta\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:k8s\\.io" subsys=labels-filter level=info msg=" - !:pod-template-generation" subsys=labels-filter level=info msg=" - !:pod-template-hash" subsys=labels-filter level=info msg=" - !:controller-revision-hash" subsys=labels-filter level=info msg=" - !:annotation.*" subsys=labels-filter level=info msg=" - !:etcd_node" subsys=labels-filter level=info msg=Invoked duration=1.463439ms function="pprof.glob..func1 (cell.go:50)" subsys=hive level=info msg=Invoked duration="45.141µs" function="gops.registerGopsHooks (cell.go:38)" subsys=hive level=info msg=Invoked duration="856.785µs" function="metrics.NewRegistry (registry.go:65)" subsys=hive level=info msg=Invoked duration="10.16µs" function="metrics.glob..func1 (cell.go:12)" subsys=hive level=info msg="Spire Delegate API Client is disabled as no socket path is configured" subsys=spire-delegate level=info msg="Mutual authentication handler is disabled as no port is configured" subsys=auth level=info msg=Invoked duration=100.35673ms function="cmd.glob..func4 (daemon_main.go:1607)" subsys=hive level=info msg=Invoked duration="8.82µs" function="gc.registerSignalHandler (cell.go:47)" subsys=hive level=info msg=Invoked duration="11.61µs" function="utime.initUtimeSync (cell.go:29)" subsys=hive level=info msg=Invoked duration="44.26µs" function="agentliveness.newAgentLivenessUpdater (agent_liveness.go:43)" subsys=hive level=info msg=Invoked duration="45.37µs" function="l2responder.NewL2ResponderReconciler (l2responder.go:63)" subsys=hive level=info msg=Invoked duration="53.651µs" function="garp.newGARPProcessor (processor.go:27)" subsys=hive level=info msg=Starting subsys=hive level=info msg="Started gops server" address="127.0.0.1:9890" subsys=gops level=info msg="Start hook executed" duration="426.152µs" function="gops.registerGopsHooks.func1 (cell.go:43)" subsys=hive level=info msg="Start hook executed" duration="1.45µs" function="metrics.NewRegistry.func1 (registry.go:86)" subsys=hive level=info msg="Establishing connection to apiserver" host="https://10.96.0.1:443" subsys=k8s-client level=info msg="Serving prometheus metrics on :9962" subsys=metrics level=info msg="Connected to apiserver" subsys=k8s-client level=info msg="Start hook executed" duration=8.32057ms function="client.(*compositeClientset).onStart" subsys=hive level=info msg="Start hook executed" duration=6.288607ms function="authmap.newAuthMap.func1 (cell.go:27)" subsys=hive level=info msg="Start hook executed" duration="36.95µs" function="configmap.newMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="40.89µs" function="signalmap.newMap.func1 (cell.go:44)" subsys=hive level=info msg="Start hook executed" duration="235.012µs" function="nodemap.newNodeMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="92.86µs" function="eventsmap.newEventsMap.func1 (cell.go:35)" subsys=hive level=info msg="Start hook executed" duration="75.091µs" function="*cni.cniConfigManager.Start" subsys=hive level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Wrote CNI configuration file to /host/etc/cni/net.d/05-cilium.conflist" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Start hook executed" duration=46.752268ms function="datapath.newDatapath.func1 (cells.go:113)" subsys=hive level=info msg="Restored 0 node IDs from the BPF map" subsys=linux-datapath level=info msg="Start hook executed" duration="57.671µs" function="datapath.newDatapath.func2 (cells.go:126)" subsys=hive level=info msg="Start hook executed" duration="8.01µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Node].Start" subsys=hive level=info msg="Start hook executed" duration="1.25µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNode].Start" subsys=hive level=info msg="Using autogenerated IPv4 allocation range" subsys=node v4Prefix=10.193.0.0/16 level=info msg="no local ciliumnode found, will not restore cilium internal ips from k8s" subsys=daemon level=info msg="Start hook executed" duration=103.70593ms function="node.NewLocalNodeStore.func1 (local_node_store.go:76)" subsys=hive level=info msg="Start hook executed" duration="12.42µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration=100.345118ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration="10.9µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Using discoveryv1.EndpointSlice" subsys=k8s level=info msg="Start hook executed" duration=100.540379ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Start hook executed" duration="5.39µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Pod].Start" subsys=hive level=info msg="Start hook executed" duration="13.611µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Namespace].Start" subsys=hive level=info msg="Start hook executed" duration="2.37µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="2.03µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumClusterwideNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="2.34µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumCIDRGroup].Start" subsys=hive level=info msg="Start hook executed" duration="27.76µs" function="endpointmanager.newDefaultEndpointManager.func1 (cell.go:203)" subsys=hive level=info msg="Start hook executed" duration="19.46µs" function="cmd.newPolicyTrifecta.func1 (policy.go:135)" subsys=hive level=info msg="Start hook executed" duration="51.89µs" function="*manager.manager.Start" subsys=hive level=info msg="Serving cilium node monitor v1.2 API at unix:///var/run/cilium/monitor1_2.sock" subsys=monitor-agent level=info msg="Start hook executed" duration="268.551µs" function="agent.newMonitorAgent.func1 (cell.go:61)" subsys=hive level=info msg="Start hook executed" duration="1.49µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumL2AnnouncementPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="5.32µs" function="*job.group.Start" subsys=hive level=info msg="Start hook executed" duration="207.231µs" function="proxy.newProxy.func1 (cell.go:55)" subsys=hive level=info msg="Envoy: Starting xDS gRPC server listening on /var/run/cilium/envoy/sockets/xds.sock" subsys=envoy-manager level=info msg="Start hook executed" duration="424.663µs" function="signal.provideSignalManager.func1 (cell.go:25)" subsys=hive level=info msg="Datapath signal listener running" subsys=signal level=info msg="Start hook executed" duration="904.225µs" function="auth.registerAuthManager.func1 (cell.go:109)" subsys=hive level=info msg="Start hook executed" duration="2.72µs" function="auth.registerGCJobs.func1 (cell.go:158)" subsys=hive level=info msg="Start hook executed" duration="15.5µs" function="*job.group.Start" subsys=hive level=warning msg="Deprecated value for --kube-proxy-replacement: disabled (use either \"true\", or \"false\")" subsys=daemon level=info msg="Auto-disabling \"enable-node-port\", \"enable-external-ips\", \"bpf-lb-sock\", \"enable-host-port\" features and falling back to \"enable-host-legacy-routing\"" subsys=daemon level=info msg="Inheriting MTU from external network interface" device=ens3 ipAddr=199.19.213.193 mtu=1500 subsys=mtu level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_ipcache, recreating and re-pinning map cilium_ipcache" file-path=/sys/fs/bpf/tc/globals/cilium_ipcache name=cilium_ipcache subsys=bpf level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_tunnel_map, recreating and re-pinning map cilium_tunnel_map" file-path=/sys/fs/bpf/tc/globals/cilium_tunnel_map name=cilium_tunnel_map subsys=bpf level=info msg="Restored services from maps" failedServices=0 restoredServices=0 subsys=service level=info msg="Restored backends from maps" failedBackends=0 restoredBackends=0 skippedBackends=0 subsys=service level=info msg="Reading old endpoints..." subsys=daemon level=info msg="No old endpoints found." subsys=daemon level=info msg="Waiting until all Cilium CRDs are available" subsys=k8s level=info msg="All Cilium CRDs have been found and are available" subsys=k8s level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=info msg="Successfully created CiliumNode resource" subsys=nodediscovery level=warning msg="Unable to create CiliumNode resource, will retry" error="ciliumnodes.cilium.io \"instance\" already exists" subsys=nodediscovery level=info msg="Retrieved node information from cilium node" nodeName=instance subsys=k8s level=info msg="Received own node information from API server" ipAddr.ipv4=199.19.213.193 ipAddr.ipv6="" k8sNodeIP=199.19.213.193 labels="map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:]" nodeName=instance subsys=k8s v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="k8s mode: Allowing localhost to reach local endpoints" subsys=daemon level=info msg="Detected devices" devices="[]" subsys=linux-datapath level=info msg="Enabling k8s event listener" subsys=k8s-watcher level=info msg="Removing stale endpoint interfaces" subsys=daemon level=info msg="Waiting until local node addressing before starting watchers depending on it" subsys=k8s-watcher level=info msg="Skipping kvstore configuration" subsys=daemon level=info msg="Initializing node addressing" subsys=daemon level=info msg="Initializing cluster-pool IPAM" subsys=ipam v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="Restoring endpoints..." subsys=daemon level=info msg="Endpoints restored" failed=0 restored=0 subsys=daemon level=info msg="Addressing information:" subsys=daemon level=info msg=" Cluster-Name: default" subsys=daemon level=info msg=" Cluster-ID: 0" subsys=daemon level=info msg=" Local node-name: instance" subsys=daemon level=info msg=" Node-IPv6: " subsys=daemon level=info msg=" External-Node IPv4: 199.19.213.193" subsys=daemon level=info msg=" Internal-Node IPv4: 10.0.0.213" subsys=daemon level=info msg=" IPv4 allocation prefix: 10.0.0.0/24" subsys=daemon level=info msg=" Loopback IPv4: 169.254.42.1" subsys=daemon level=info msg=" Local IPv4 addresses:" subsys=daemon level=info msg=" - 199.19.213.193" subsys=daemon level=info msg=" - 172.17.0.100" subsys=daemon level=info msg="Node updated" clusterName=default nodeName=instance subsys=nodemanager level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Waiting until all pre-existing resources have been received" subsys=k8s-watcher level=info msg="Adding local node to cluster" node="{instance default [{InternalIP 199.19.213.193} {CiliumInternalIP 10.0.0.213}] 10.0.0.0/24 [] [] 10.0.0.202 0 local 0 map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:] map[] 1 }" subsys=nodediscovery level=info msg="Initializing identity allocator" subsys=identity-cache level=info msg="Allocating identities between range" cluster-id=0 max=65535 min=256 subsys=identity-cache level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.core.bpf_jit_enable sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.all.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.fib_multipath_use_neigh sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.unprivileged_bpf_disabled sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.timer_migration sysParamValue=0 level=info msg="Setting up BPF datapath" bpfClockSource=ktime bpfInsnSet="" subsys=datapath-loader level=info msg="Iptables rules installed" subsys=iptables level=info msg="Adding new proxy port rules for cilium-dns-egress:37459" id=cilium-dns-egress subsys=proxy level=info msg="Iptables proxy rules installed" subsys=iptables level=info msg="Start hook executed" duration=2.499541674s function="cmd.newDaemonPromise.func1 (daemon_main.go:1663)" subsys=hive level=info msg="Start hook executed" duration="23.85µs" function="utime.initUtimeSync.func1 (cell.go:33)" subsys=hive level=info msg="Start hook executed" duration="8.04µs" function="*job.group.Start" subsys=hive level=info msg="Start hook executed" duration="36.53µs" function="l2respondermap.newMap.func1 (l2_responder_map4.go:44)" subsys=hive level=info msg="Start hook executed" duration="4.98µs" function="*job.group.Start" subsys=hive level=info msg="Starting IP identity watcher" subsys=ipcache level=info msg="Initializing daemon" subsys=daemon level=info msg="Validating configured node address ranges" subsys=daemon level=info msg="Starting connection tracking garbage collector" subsys=daemon level=info msg="Initial scan of connection tracking completed" subsys=ct-gc level=info msg="Regenerating restored endpoints" numRestored=0 subsys=daemon level=info msg="Creating host endpoint" subsys=daemon level=info msg="Finished regenerating restored endpoints" regenerated=0 subsys=daemon total=0 level=info msg="Deleted orphan backends" orphanBackends=0 subsys=service level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1919 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1919 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1919 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="Launching Cilium health daemon" subsys=daemon level=info msg="Launching Cilium health endpoint" subsys=daemon level=info msg="Started healthz status API server" address="127.0.0.1:9879" subsys=daemon level=info msg="Processing queued endpoint deletion requests from /var/run/cilium/deleteQueue" subsys=daemon level=info msg="processing 0 queued deletion requests" subsys=daemon level=info msg="Initializing Cilium API" subsys=daemon level=info msg="Daemon initialization completed" bootstrapTime=3.478431348s subsys=daemon level=info msg="Hubble server is disabled" subsys=hubble level=info msg="Serving cilium API at unix:///var/run/cilium/cilium.sock" subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.148 ca2267d3-4051-4f42-bdd2-88eebb80c62c default }" containerID=fb141fca95aec14ca3e2349963b268d0cf5fc93f2bdf1d065ec9f6ae5ea41840 datapathConfiguration="&{false false false false false }" interface=lxc1db37b35232a k8sPodName=kube-system/coredns-7c96b6546b-8l9wh labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=fb141fca95 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3058 ipv4=10.0.0.148 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-8l9wh subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=fb141fca95 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3058 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.148 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-8l9wh subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:kube-system]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=fb141fca95 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3058 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.148 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-8l9wh line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=coredns;k8s:io.kubernetes.pod.namespace=kube-system;k8s:k8s-app=kube-dns;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=fb141fca95 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3058 identity=57178 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.148 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-8l9wh oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=fb141fca95 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3058 identity=57178 ipv4=10.0.0.148 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-8l9wh subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.231 75596a29-a358-4b02-ba2f-aba65214cb90 default }" containerID=5bcb8a7230d4a10206edd8f148f65dcffb6b89acc48644ad52b3721ef1346257 datapathConfiguration="&{false false false false false }" interface=lxc3f1c67e91e6b k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bd5pm labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=5bcb8a7230 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1545 ipv4=10.0.0.231 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bd5pm subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=5bcb8a7230 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1545 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=3dfe511c-e0bc-40d7-bf6e-d5826317b37f,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=3dfe511c-e0bc-40d7-bf6e-d5826317b37f,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.231 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bd5pm subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="Compiled new BPF template" BPFCompilationTime=297.710144ms file-path=/var/run/cilium/state/templates/816e733789f9437aabc4e49db5a0744ee1f3fa82e59575a5dfa876aaa7a346ea/bpf_host.o subsys=datapath-loader level=info msg="Allocated new global key" key="k8s:app=certgen;k8s:batch.kubernetes.io/controller-uid=3dfe511c-e0bc-40d7-bf6e-d5826317b37f;k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen;k8s:controller-uid=3dfe511c-e0bc-40d7-bf6e-d5826317b37f;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;k8s:job-name=envoy-gateway-gateway-helm-certgen;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=5bcb8a7230 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1545 identity=39967 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=3dfe511c-e0bc-40d7-bf6e-d5826317b37f,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=3dfe511c-e0bc-40d7-bf6e-d5826317b37f,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.231 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bd5pm oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=5bcb8a7230 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1545 identity=39967 ipv4=10.0.0.231 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bd5pm subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1919 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1470 ipv4=10.0.0.202 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1470 identityLabels="reserved:health" ipv4=10.0.0.202 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1470 identity=4 identityLabels="reserved:health" ipv4=10.0.0.202 ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Compiled new BPF template" BPFCompilationTime=1.082695805s file-path=/var/run/cilium/state/templates/ad5421c525c545c16022b481c6a5dc102e33465fbf872a53957a6d166e935ad8/bpf_lxc.o subsys=datapath-loader level=info msg="Rewrote endpoint BPF program" containerID=fb141fca95 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=3058 identity=57178 ipv4=10.0.0.148 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-8l9wh subsys=endpoint level=info msg="Successful endpoint creation" containerID=fb141fca95 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3058 identity=57178 ipv4=10.0.0.148 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-8l9wh subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1470 identity=4 ipv4=10.0.0.202 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=5bcb8a7230 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1545 identity=39967 ipv4=10.0.0.231 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bd5pm subsys=endpoint level=info msg="Successful endpoint creation" containerID=5bcb8a7230 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1545 identity=39967 ipv4=10.0.0.231 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bd5pm subsys=daemon level=info msg="Serving cilium health API at unix:///var/run/cilium/health.sock" subsys=health-server level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=5bcb8a7230 endpointID=1545 k8sNamespace=envoy-gateway-system k8sPodName=envoy-gateway-gateway-helm-certgen-bd5pm subsys=daemon level=info msg="Releasing key" key="[k8s:app=certgen k8s:batch.kubernetes.io/controller-uid=3dfe511c-e0bc-40d7-bf6e-d5826317b37f k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen k8s:controller-uid=3dfe511c-e0bc-40d7-bf6e-d5826317b37f k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen k8s:io.kubernetes.pod.namespace=envoy-gateway-system k8s:job-name=envoy-gateway-gateway-helm-certgen]" subsys=allocator level=info msg="Removed endpoint" containerID=5bcb8a7230 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1545 identity=39967 ipv4=10.0.0.231 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-bd5pm subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.4 361a3b2f-862b-4632-9859-0896e331c97c default }" containerID=0fe13ec5e9ba980e3bf4a1dcfdd4f3db8e7169b54fe129856352f388cb052ff0 datapathConfiguration="&{false false false false false }" interface=lxc9bc0a702379c k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-tq9kd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=0fe13ec5e9 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2495 ipv4=10.0.0.4 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-tq9kd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=0fe13ec5e9 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2495 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.4 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-tq9kd subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=0fe13ec5e9 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2495 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.4 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-tq9kd line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=envoy-gateway;k8s:app.kubernetes.io/name=gateway-helm;k8s:control-plane=envoy-gateway;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=0fe13ec5e9 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2495 identity=31084 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.4 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-tq9kd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=0fe13ec5e9 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2495 identity=31084 ipv4=10.0.0.4 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-tq9kd subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=0fe13ec5e9 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2495 identity=31084 ipv4=10.0.0.4 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-tq9kd subsys=endpoint level=info msg="Successful endpoint creation" containerID=0fe13ec5e9 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2495 identity=31084 ipv4=10.0.0.4 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-tq9kd subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1919 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,k8s:openstack-compute-node=enabled,k8s:openstack-control-plane=enabled,k8s:openvswitch=enabled,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_hostns_01919 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_hostns_01919 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_hostns_01919 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_hostns_01919:pending" subsys=bpf level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_netdev_00003 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_netdev_00003 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003:pending" subsys=bpf level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1919 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.155 f0ccf7af-f196-4520-9186-95bf5e9692d6 default }" containerID=6607d4c1fb1b48d22178c36283a0101375ca3e887168afcf9ff44a5a9b5f8796 datapathConfiguration="&{false false false false false }" interface=lxc1afc45ec7654 k8sPodName=kube-system/coredns-67659f764b-whgdc labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=6607d4c1fb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1806 ipv4=10.0.0.155 ipv6= k8sPodName=kube-system/coredns-67659f764b-whgdc subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=6607d4c1fb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1806 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.155 ipv6= k8sPodName=kube-system/coredns-67659f764b-whgdc subsys=endpoint level=info msg="Identity of endpoint changed" containerID=6607d4c1fb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1806 identity=57178 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.155 ipv6= k8sPodName=kube-system/coredns-67659f764b-whgdc oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=6607d4c1fb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1806 identity=57178 ipv4=10.0.0.155 ipv6= k8sPodName=kube-system/coredns-67659f764b-whgdc subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.154 9def6088-782c-4ac5-b000-dfb90df44f0b default }" containerID=96c6c2167fadce387541f09ec9d3ba590fd558023218ce9470afbb393c881265 datapathConfiguration="&{false false false false false }" interface=lxcc878c2281788 k8sPodName=kube-system/coredns-67659f764b-m4tbf labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=96c6c2167f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=579 ipv4=10.0.0.154 ipv6= k8sPodName=kube-system/coredns-67659f764b-m4tbf subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=96c6c2167f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=579 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.154 ipv6= k8sPodName=kube-system/coredns-67659f764b-m4tbf subsys=endpoint level=info msg="Identity of endpoint changed" containerID=96c6c2167f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=579 identity=57178 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.154 ipv6= k8sPodName=kube-system/coredns-67659f764b-m4tbf oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=96c6c2167f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=579 identity=57178 ipv4=10.0.0.154 ipv6= k8sPodName=kube-system/coredns-67659f764b-m4tbf subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=6607d4c1fb datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1806 identity=57178 ipv4=10.0.0.155 ipv6= k8sPodName=kube-system/coredns-67659f764b-whgdc subsys=endpoint level=info msg="Successful endpoint creation" containerID=6607d4c1fb datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1806 identity=57178 ipv4=10.0.0.155 ipv6= k8sPodName=kube-system/coredns-67659f764b-whgdc subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=96c6c2167f datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=579 identity=57178 ipv4=10.0.0.154 ipv6= k8sPodName=kube-system/coredns-67659f764b-m4tbf subsys=endpoint level=info msg="Successful endpoint creation" containerID=96c6c2167f datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=579 identity=57178 ipv4=10.0.0.154 ipv6= k8sPodName=kube-system/coredns-67659f764b-m4tbf subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.5 453355ab-1d62-4694-977b-4d6b94e88331 default }" containerID=b40386689adca7b1ffa64b96abf1f7a17c468a7459e8256331818de0e8927382 datapathConfiguration="&{false false false false false }" interface=lxc99287cb3418e k8sPodName=local-path-storage/local-path-provisioner-679c578f5-8z4qj labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b40386689a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=126 ipv4=10.0.0.5 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-8z4qj subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b40386689a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=126 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.5 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-8z4qj subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=b40386689a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=126 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.5 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-8z4qj line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=local-path-provisioner;k8s:app.kubernetes.io/name=local-path-provisioner;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=b40386689a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=126 identity=3691 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.5 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-8z4qj oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b40386689a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=126 identity=3691 ipv4=10.0.0.5 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-8z4qj subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=b40386689a datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=126 identity=3691 ipv4=10.0.0.5 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-8z4qj subsys=endpoint level=info msg="Successful endpoint creation" containerID=b40386689a datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=126 identity=3691 ipv4=10.0.0.5 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-8z4qj subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=fb141fca95 endpointID=3058 k8sNamespace=kube-system k8sPodName=coredns-7c96b6546b-8l9wh subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=coredns k8s:io.kubernetes.pod.namespace=kube-system k8s:k8s-app=kube-dns]" subsys=allocator level=info msg="Removed endpoint" containerID=fb141fca95 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=3058 identity=57178 ipv4=10.0.0.148 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-8l9wh subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.217 11ff4a76-7765-40c6-83d9-ab6a725547cd default }" containerID=d967f9a9ed29d042b499c0ac2fd104763847d039e6ca6f2691b3b5235c9d06f4 datapathConfiguration="&{false false false false false }" interface=lxccd130cc0d803 k8sPodName=cert-manager/cert-manager-75c4c745bc-2j64t labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d967f9a9ed datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1199 ipv4=10.0.0.217 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-2j64t subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d967f9a9ed datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1199 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.217 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-2j64t subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=d967f9a9ed datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1199 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.217 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-2j64t line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=cert-manager;k8s:app.kubernetes.io/component=controller;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cert-manager;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d967f9a9ed datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1199 identity=9329 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.217 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-2j64t oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d967f9a9ed datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1199 identity=9329 ipv4=10.0.0.217 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-2j64t subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.168 fde08d9b-d62c-412d-9cc3-b2675d9c3eab default }" containerID=4c524218fc6e34edd87d022247e734978adb7e78ebedd43ee8ba335ddd7aacde datapathConfiguration="&{false false false false false }" interface=lxcee81c94ed97e k8sPodName=cert-manager/cert-manager-webhook-548949fc64-q4vm9 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=4c524218fc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=29 ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-q4vm9 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=4c524218fc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=29 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-q4vm9 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=webhook;k8s:app.kubernetes.io/component=webhook;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=webhook;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=4c524218fc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=29 identity=26543 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-q4vm9 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=4c524218fc datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=29 identity=26543 ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-q4vm9 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=d967f9a9ed datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1199 identity=9329 ipv4=10.0.0.217 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-2j64t subsys=endpoint level=info msg="Successful endpoint creation" containerID=d967f9a9ed datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1199 identity=9329 ipv4=10.0.0.217 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-2j64t subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.25 7486b3ca-5fda-4ca8-a1f6-efe39f9dc696 default }" containerID=bab57d54c04fd1c8d32d9b878114d814cc469fb28da6a0dbdf31420c6aec5d77 datapathConfiguration="&{false false false false false }" interface=lxc496a1d145eb0 k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-x4xz6 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=bab57d54c0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=520 ipv4=10.0.0.25 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-x4xz6 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=bab57d54c0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=520 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.25 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-x4xz6 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=cainjector;k8s:app.kubernetes.io/component=cainjector;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cainjector;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=bab57d54c0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=520 identity=24014 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.25 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-x4xz6 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=bab57d54c0 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=520 identity=24014 ipv4=10.0.0.25 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-x4xz6 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=4c524218fc datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=29 identity=26543 ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-q4vm9 subsys=endpoint level=info msg="Successful endpoint creation" containerID=4c524218fc datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=29 identity=26543 ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-q4vm9 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=bab57d54c0 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=520 identity=24014 ipv4=10.0.0.25 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-x4xz6 subsys=endpoint level=info msg="Successful endpoint creation" containerID=bab57d54c0 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=520 identity=24014 ipv4=10.0.0.25 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-x4xz6 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.103 1c02aee8-bb13-4740-be3f-9b1c107f37ca default }" containerID=33ccc74b315fffa6baf7ca7fe6ef1f9ba41986b34b4bc783c8d81861f6e39133 datapathConfiguration="&{false false false false false }" interface=lxcf7aa1ae2dbdb k8sPodName=cert-manager/cert-manager-startupapicheck-tmj6v labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=33ccc74b31 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=765 ipv4=10.0.0.103 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tmj6v subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=33ccc74b31 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=765 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=db15ea3b-ec74-4714-9d2e-3bf8b0d9f37b,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=db15ea3b-ec74-4714-9d2e-3bf8b0d9f37b,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.103 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tmj6v subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=startupapicheck;k8s:app.kubernetes.io/component=startupapicheck;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=startupapicheck;k8s:app.kubernetes.io/version=v1.11.5;k8s:batch.kubernetes.io/controller-uid=db15ea3b-ec74-4714-9d2e-3bf8b0d9f37b;k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck;k8s:controller-uid=db15ea3b-ec74-4714-9d2e-3bf8b0d9f37b;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck;k8s:io.kubernetes.pod.namespace=cert-manager;k8s:job-name=cert-manager-startupapicheck;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=33ccc74b31 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=765 identity=8691 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=db15ea3b-ec74-4714-9d2e-3bf8b0d9f37b,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=db15ea3b-ec74-4714-9d2e-3bf8b0d9f37b,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.103 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tmj6v oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=33ccc74b31 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=765 identity=8691 ipv4=10.0.0.103 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tmj6v subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=33ccc74b31 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=765 identity=8691 ipv4=10.0.0.103 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tmj6v subsys=endpoint level=info msg="Successful endpoint creation" containerID=33ccc74b31 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=765 identity=8691 ipv4=10.0.0.103 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tmj6v subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=33ccc74b31 endpointID=765 k8sNamespace=cert-manager k8sPodName=cert-manager-startupapicheck-tmj6v subsys=daemon level=info msg="Releasing key" key="[k8s:app=startupapicheck k8s:app.kubernetes.io/component=startupapicheck k8s:app.kubernetes.io/instance=cert-manager k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=startupapicheck k8s:app.kubernetes.io/version=v1.11.5 k8s:batch.kubernetes.io/controller-uid=db15ea3b-ec74-4714-9d2e-3bf8b0d9f37b k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck k8s:controller-uid=db15ea3b-ec74-4714-9d2e-3bf8b0d9f37b k8s:helm.sh/chart=cert-manager-v1.11.5 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager k8s:io.cilium.k8s.namespace.labels.name=cert-manager k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck k8s:io.kubernetes.pod.namespace=cert-manager k8s:job-name=cert-manager-startupapicheck]" subsys=allocator level=info msg="Removed endpoint" containerID=33ccc74b31 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=765 identity=8691 ipv4=10.0.0.103 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-tmj6v subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.246 dc825354-9142-482e-9a56-d5e66124be8b default }" containerID=53af5b523e767b4696a517ec88c6458788eff47931a80a93428a232ffe2e0839 datapathConfiguration="&{false false false false false }" interface=lxc7d83fb9b217d k8sPodName=ingress-nginx/ingress-nginx-admission-create-mkvh4 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=53af5b523e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2059 ipv4=10.0.0.246 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-mkvh4 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=53af5b523e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2059 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=31e14ef3-7045-4766-ada4-9e5c4cf93c76,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=31e14ef3-7045-4766-ada4-9e5c4cf93c76,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.246 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-mkvh4 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=31e14ef3-7045-4766-ada4-9e5c4cf93c76;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create;k8s:controller-uid=31e14ef3-7045-4766-ada4-9e5c4cf93c76;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-create;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=53af5b523e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2059 identity=15198 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=31e14ef3-7045-4766-ada4-9e5c4cf93c76,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=31e14ef3-7045-4766-ada4-9e5c4cf93c76,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.246 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-mkvh4 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=53af5b523e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2059 identity=15198 ipv4=10.0.0.246 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-mkvh4 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=53af5b523e datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2059 identity=15198 ipv4=10.0.0.246 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-mkvh4 subsys=endpoint level=info msg="Successful endpoint creation" containerID=53af5b523e datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2059 identity=15198 ipv4=10.0.0.246 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-mkvh4 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=53af5b523e endpointID=2059 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-create-mkvh4 subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=31e14ef3-7045-4766-ada4-9e5c4cf93c76 k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create k8s:controller-uid=31e14ef3-7045-4766-ada4-9e5c4cf93c76 k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-create]" subsys=allocator level=info msg="Removed endpoint" containerID=53af5b523e datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2059 identity=15198 ipv4=10.0.0.246 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-mkvh4 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.242 66802795-f6a0-48ed-a4f3-8b27ecc10db4 default }" containerID=519382c18383d3eccf5d0ae1ee363bd7430390ec1b7a69c132695bd2ef4f94c9 datapathConfiguration="&{false false false false false }" interface=lxc0851818e38f7 k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-n62v5 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=519382c183 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=649 ipv4=10.0.0.242 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-n62v5 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=519382c183 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=649 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.242 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-n62v5 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=519382c183 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=649 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.242 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-n62v5 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=default-backend;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend;k8s:io.kubernetes.pod.namespace=ingress-nginx;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=519382c183 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=649 identity=53347 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.242 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-n62v5 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=519382c183 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=649 identity=53347 ipv4=10.0.0.242 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-n62v5 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=519382c183 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=649 identity=53347 ipv4=10.0.0.242 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-n62v5 subsys=endpoint level=info msg="Successful endpoint creation" containerID=519382c183 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=649 identity=53347 ipv4=10.0.0.242 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-n62v5 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.126 a5b42109-cf3f-48c6-b546-a96cbc6d01d3 default }" containerID=c9ad3d899c4695dc3d2d4372cda0c821f1a46a32a1c46602ac51dadb6c4488f0 datapathConfiguration="&{false false false false false }" interface=lxc284e94d6f236 k8sPodName=ingress-nginx/ingress-nginx-admission-patch-64zrf labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c9ad3d899c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=851 ipv4=10.0.0.126 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-64zrf subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c9ad3d899c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=851 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=61f7cde5-2397-434d-bb58-9843506c9c2c,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=61f7cde5-2397-434d-bb58-9843506c9c2c,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.126 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-64zrf subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=61f7cde5-2397-434d-bb58-9843506c9c2c;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch;k8s:controller-uid=61f7cde5-2397-434d-bb58-9843506c9c2c;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-patch;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=c9ad3d899c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=851 identity=4987 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=61f7cde5-2397-434d-bb58-9843506c9c2c,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=61f7cde5-2397-434d-bb58-9843506c9c2c,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.126 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-64zrf oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c9ad3d899c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=851 identity=4987 ipv4=10.0.0.126 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-64zrf subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=c9ad3d899c datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=851 identity=4987 ipv4=10.0.0.126 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-64zrf subsys=endpoint level=info msg="Successful endpoint creation" containerID=c9ad3d899c datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=851 identity=4987 ipv4=10.0.0.126 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-64zrf subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=c9ad3d899c endpointID=851 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-patch-64zrf subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=61f7cde5-2397-434d-bb58-9843506c9c2c k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch k8s:controller-uid=61f7cde5-2397-434d-bb58-9843506c9c2c k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-patch]" subsys=allocator level=info msg="Removed endpoint" containerID=c9ad3d899c datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=851 identity=4987 ipv4=10.0.0.126 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-64zrf subsys=endpoint level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"rabbitmq-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-cluster-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=16d427ec-5f1e-47e0-8ba3-0136c33ec0ad] Description:}]" policyAddRequest=8ae9f81c-0d38-499c-bdf8-111259dc1dc7 subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=8ae9f81c-0d38-499c-bdf8-111259dc1dc7 policyRevision=2 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-cluster-operator subsys=k8s-watcher level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"messaging-topology-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:9443 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-messaging-topology-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=10d2de1c-f1f4-4d3a-a325-2072348316ef] Description:}]" policyAddRequest=66450e52-c10f-4b5b-8dea-3b19da2a6825 subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=66450e52-c10f-4b5b-8dea-3b19da2a6825 policyRevision=3 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-messaging-topology-operator subsys=k8s-watcher level=info msg="Create endpoint request" addressing="&{10.0.0.51 60c7363a-5fdf-4430-b70e-a4134734dd82 default }" containerID=72b5e45c4036c0698940e7d07d428332c5ca72685a75476af6c0236c6116958a datapathConfiguration="&{false false false false false }" interface=lxcfcfaf4aa5d6e k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-bxgl2 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=72b5e45c40 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=323 ipv4=10.0.0.51 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-bxgl2 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=72b5e45c40 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=323 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.16.1,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.51 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-bxgl2 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=72b5e45c40 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=323 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.51 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-bxgl2 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=2.16.1;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=72b5e45c40 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=323 identity=44120 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.16.1,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.51 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-bxgl2 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=72b5e45c40 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=323 identity=44120 ipv4=10.0.0.51 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-bxgl2 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.180 53bb44b7-5427-4764-8906-aff22a7c7494 default }" containerID=241a23254120bdc253fbfe4ae3c2448d1d8f49d78ef7f5c67dd942c1d42ba536 datapathConfiguration="&{false false false false false }" interface=lxcc7ddd60b1a4f k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-zrrd5 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=241a232541 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2834 ipv4=10.0.0.180 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-zrrd5 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=241a232541 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2834 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.17.4,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.180 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-zrrd5 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=messaging-topology-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=1.17.4;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=241a232541 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2834 identity=50302 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.17.4,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.4.34,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.180 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-zrrd5 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=241a232541 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2834 identity=50302 ipv4=10.0.0.180 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-zrrd5 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=241a232541 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=2834 identity=50302 ipv4=10.0.0.180 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-zrrd5 subsys=endpoint level=info msg="Successful endpoint creation" containerID=241a232541 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=2834 identity=50302 ipv4=10.0.0.180 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-6f465c979f-zrrd5 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=72b5e45c40 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=323 identity=44120 ipv4=10.0.0.51 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-bxgl2 subsys=endpoint level=info msg="Successful endpoint creation" containerID=72b5e45c40 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=323 identity=44120 ipv4=10.0.0.51 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-54f767cff8-bxgl2 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.179 1183b9bd-1a86-47e1-a0f2-0f23f284caeb default }" containerID=f8c03b707f008fafa0e92dd135d552a5203ad1189c956cc97283e29d0454e8a1 datapathConfiguration="&{false false false false false }" interface=lxcd69dd4edf6a6 k8sPodName=openstack/pxc-operator-69cb5bbdb9-rvcfd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f8c03b707f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3739 ipv4=10.0.0.179 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-rvcfd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f8c03b707f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3739 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.179 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-rvcfd subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=operator;k8s:app.kubernetes.io/instance=pxc-operator;k8s:app.kubernetes.io/name=pxc-operator;k8s:app.kubernetes.io/part-of=pxc-operator;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=f8c03b707f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3739 identity=22556 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.179 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-rvcfd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f8c03b707f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3739 identity=22556 ipv4=10.0.0.179 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-rvcfd subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=f8c03b707f datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=3739 identity=22556 ipv4=10.0.0.179 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-rvcfd subsys=endpoint level=info msg="Successful endpoint creation" containerID=f8c03b707f datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=3739 identity=22556 ipv4=10.0.0.179 ipv6= k8sPodName=openstack/pxc-operator-69cb5bbdb9-rvcfd subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.97 0d444eb3-a066-47a9-b894-6423cfb419fe default }" containerID=58681263b5e5613324247df113ea3c287fc2aca116f4b61dba72e66d0d0faf18 datapathConfiguration="&{false false false false false }" interface=lxcff5455a4edd1 k8sPodName=openstack/percona-xtradb-haproxy-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=58681263b5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3292 ipv4=10.0.0.97 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=58681263b5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3292 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.97 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=58681263b5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3292 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.97 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=haproxy;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=58681263b5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3292 identity=2258 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.97 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=58681263b5 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3292 identity=2258 ipv4=10.0.0.97 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=58681263b5 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=3292 identity=2258 ipv4=10.0.0.97 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=58681263b5 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=3292 identity=2258 ipv4=10.0.0.97 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.201 4d202f7a-4d1f-4cda-8dfc-c9910216878f default }" containerID=ee71a18102dbd44c14ca929c99684c0b9a47129f503ba0af7aff6a90b3106c8b datapathConfiguration="&{false false false false false }" interface=lxc01ed5c99a6b1 k8sPodName=local-path-storage/helper-pod-create-pvc-2c979f49-3bef-4aa7-b95a-07bda0295daa labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=ee71a18102 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3993 ipv4=10.0.0.201 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-2c979f49-3bef-4aa7-b95a-07bda0295daa subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=ee71a18102 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3993 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.201 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-2c979f49-3bef-4aa7-b95a-07bda0295daa subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=ee71a18102 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3993 identity=35147 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.201 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-2c979f49-3bef-4aa7-b95a-07bda0295daa oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=ee71a18102 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3993 identity=35147 ipv4=10.0.0.201 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-2c979f49-3bef-4aa7-b95a-07bda0295daa subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=ee71a18102 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=3993 identity=35147 ipv4=10.0.0.201 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-2c979f49-3bef-4aa7-b95a-07bda0295daa subsys=endpoint level=info msg="Successful endpoint creation" containerID=ee71a18102 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=3993 identity=35147 ipv4=10.0.0.201 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-2c979f49-3bef-4aa7-b95a-07bda0295daa subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=ee71a18102 endpointID=3993 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-2c979f49-3bef-4aa7-b95a-07bda0295daa subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=ee71a18102 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=3993 identity=35147 ipv4=10.0.0.201 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-2c979f49-3bef-4aa7-b95a-07bda0295daa subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.137 40060bb0-9e75-4ff8-9c38-7add41268983 default }" containerID=3e2f413252eda71ec044687beeed587c2c9e9dcc0d487de318acb65734d615ac datapathConfiguration="&{false false false false false }" interface=lxc582fbb33574d k8sPodName=openstack/percona-xtradb-pxc-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=3e2f413252 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1778 ipv4=10.0.0.137 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=3e2f413252 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1778 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.137 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=pxc;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=3e2f413252 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1778 identity=4252 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.137 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=3e2f413252 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1778 identity=4252 ipv4=10.0.0.137 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=3e2f413252 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=1778 identity=4252 ipv4=10.0.0.137 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=3e2f413252 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=1778 identity=4252 ipv4=10.0.0.137 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.229 605c8360-c55b-45cd-9258-fb618b3f4511 default }" containerID=c7598329f37f0b9aa4e9db614d595c9106c9611f7e517335ac5eaa816974228f datapathConfiguration="&{false false false false false }" interface=lxce8d942771762 k8sPodName=openstack/memcached-memcached-6479589586-x5qp8 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c7598329f3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=527 ipv4=10.0.0.229 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-x5qp8 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c7598329f3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=527 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.229 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-x5qp8 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=memcached;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=memcached;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=c7598329f3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=527 identity=21646 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.229 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-x5qp8 oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=c7598329f3 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=527 identity=21646 ipv4=10.0.0.229 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-x5qp8 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=c7598329f3 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=527 identity=21646 ipv4=10.0.0.229 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-x5qp8 subsys=endpoint level=info msg="Successful endpoint creation" containerID=c7598329f3 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=527 identity=21646 ipv4=10.0.0.229 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-x5qp8 subsys=daemon level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"keycloak\",\"k8s:app.kubernetes.io/instance\":\"keycloak\",\"k8s:app.kubernetes.io/name\":\"keycloak\",\"k8s:io.kubernetes.pod.namespace\":\"auth-system\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:7800 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:} {Ports:[{Port:8080 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=keycloak k8s:io.cilium.k8s.policy.namespace=auth-system k8s:io.cilium.k8s.policy.uid=ee17f8a1-ed16-4859-8836-ecc035323392] Description:}]" policyAddRequest=3e1222f6-4077-416e-8a14-66ee93bc7cdc subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=3e1222f6-4077-416e-8a14-66ee93bc7cdc policyRevision=4 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=keycloak subsys=k8s-watcher level=info msg="Create endpoint request" addressing="&{10.0.0.239 c1ab586a-d5ee-4ac9-af29-67c71675bf22 default }" containerID=5d2f111003a8300e10edec7ecd7ca1a463a49a71e418e944a0f81060392c94f6 datapathConfiguration="&{false false false false false }" interface=lxc98a4ec3be691 k8sPodName=auth-system/keycloak-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=5d2f111003 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4038 ipv4=10.0.0.239 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=5d2f111003 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4038 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=24.0.5,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-21.4.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.239 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:auth-system k8s:io.cilium.k8s.namespace.labels.name:auth-system]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=keycloak;k8s:app.kubernetes.io/instance=keycloak;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=keycloak;k8s:app.kubernetes.io/version=24.0.5;k8s:apps.kubernetes.io/pod-index=0;k8s:helm.sh/chart=keycloak-21.4.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system;k8s:io.cilium.k8s.namespace.labels.name=auth-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keycloak;k8s:io.kubernetes.pod.namespace=auth-system;k8s:statefulset.kubernetes.io/pod-name=keycloak-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=5d2f111003 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4038 identity=11273 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=24.0.5,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-21.4.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.239 ipv6= k8sPodName=auth-system/keycloak-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=5d2f111003 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4038 identity=11273 ipv4=10.0.0.239 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=5d2f111003 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=4038 identity=11273 ipv4=10.0.0.239 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=5d2f111003 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=4038 identity=11273 ipv4=10.0.0.239 ipv6= k8sPodName=auth-system/keycloak-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Conntrack garbage collector interval recalculated" deleteRatio=0.041398068815449475 newInterval=7m30s subsys=map-ct level=info msg="Create endpoint request" addressing="&{10.0.0.36 218dca83-eb2d-40de-a40a-926dee3ad8fe default }" containerID=67cddda2353c592d369346b9dab04c8895f3ca1d206feac143ed19018d2c2193 datapathConfiguration="&{false false false false false }" interface=lxce6b22b6581dd k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-85dcv labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=67cddda235 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1130 ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-85dcv subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=67cddda235 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1130 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-85dcv subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:secretgen-controller]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=secretgen-controller;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa;k8s:io.kubernetes.pod.namespace=secretgen-controller;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=67cddda235 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1130 identity=7310 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-85dcv oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Waiting for endpoint to be generated" containerID=67cddda235 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1130 identity=7310 ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-85dcv subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=67cddda235 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1130 identity=7310 ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-85dcv subsys=endpoint level=info msg="Successful endpoint creation" containerID=67cddda235 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1130 identity=7310 ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-85dcv subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.138 744b79f0-1778-4b23-92a9-49ec9ed82942 default }" containerID=b4cf21249229c99f3a0154659e3707720e7959fbd8a8394cc3529a56231456a8 datapathConfiguration="&{false false false false false }" interface=lxc33012f49ae1a k8sPodName=monitoring/kube-prometheus-stack-admission-create-fqltn labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b4cf212492 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2017 ipv4=10.0.0.138 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-fqltn subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b4cf212492 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2017 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=1620cae8-e254-4110-915b-25e14b299e30,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=1620cae8-e254-4110-915b-25e14b299e30,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.138 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-fqltn subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-create;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:batch.kubernetes.io/controller-uid=1620cae8-e254-4110-915b-25e14b299e30;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create;k8s:chart=kube-prometheus-stack-60.2.0;k8s:controller-uid=1620cae8-e254-4110-915b-25e14b299e30;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-create;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=b4cf212492 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2017 identity=473 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=1620cae8-e254-4110-915b-25e14b299e30,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=1620cae8-e254-4110-915b-25e14b299e30,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.138 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-fqltn oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b4cf212492 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2017 identity=473 ipv4=10.0.0.138 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-fqltn subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=b4cf212492 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2017 identity=473 ipv4=10.0.0.138 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-fqltn subsys=endpoint level=info msg="Successful endpoint creation" containerID=b4cf212492 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2017 identity=473 ipv4=10.0.0.138 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-fqltn subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=b4cf212492 endpointID=2017 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-create-fqltn subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-create k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=60.2.0 k8s:batch.kubernetes.io/controller-uid=1620cae8-e254-4110-915b-25e14b299e30 k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create k8s:chart=kube-prometheus-stack-60.2.0 k8s:controller-uid=1620cae8-e254-4110-915b-25e14b299e30 k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-create k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=b4cf212492 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2017 identity=473 ipv4=10.0.0.138 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-fqltn subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.119 e68a7e60-44ab-47d1-a672-1b136718b7a2 default }" containerID=10e7612506ed7a6aaa43bd469391c533e3537a44b5f14252dde70a8286a087a0 datapathConfiguration="&{false false false false false }" interface=lxc01a7404b4772 k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-66hqf labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=10e7612506 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3455 ipv4=10.0.0.119 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-66hqf subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=10e7612506 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3455 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.20.0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.119 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-66hqf subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=10e7612506 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3455 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.119 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-66hqf line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=metrics;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-state-metrics;k8s:app.kubernetes.io/part-of=kube-state-metrics;k8s:app.kubernetes.io/version=2.12.0;k8s:helm.sh/chart=kube-state-metrics-5.20.0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=10e7612506 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3455 identity=9092 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.20.0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.119 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-66hqf oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=10e7612506 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3455 identity=9092 ipv4=10.0.0.119 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-66hqf subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.3 f3f00c69-59b7-4ff4-957e-8325ebfa5ec5 default }" containerID=19ac52df35ca83ef28a3bd64b62c0cff4f504277f9ab71e8ce5a330342a67615 datapathConfiguration="&{false false false false false }" interface=lxcb30ca2fbd4f4 k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-hs85f labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=19ac52df35 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=158 ipv4=10.0.0.3 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-hs85f subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=19ac52df35 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=158 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-60.2.0,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.3 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-hs85f subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Create endpoint request" addressing="&{10.0.0.24 d5f7f8b5-6cd8-467a-873b-23ef6c126160 default }" containerID=d4613e6b57a31ee0db1bb57cf1f019c167be508bd9c0c531d4e78a34e84a6dd2 datapathConfiguration="&{false false false false false }" interface=lxcbbf006b57b84 k8sPodName=monitoring/kube-prometheus-stack-grafana-5dfbd4c588-rmx68 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d4613e6b57 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=50 ipv4=10.0.0.24 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-5dfbd4c588-rmx68 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d4613e6b57 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=50 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.24 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-5dfbd4c588-rmx68 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-operator;k8s:app.kubernetes.io/component=prometheus-operator;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:chart=kube-prometheus-stack-60.2.0;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=19ac52df35 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=158 identity=21081 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-60.2.0,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.3 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-hs85f oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=19ac52df35 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=158 identity=21081 ipv4=10.0.0.3 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-hs85f subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/name=grafana;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana;k8s:io.kubernetes.pod.namespace=monitoring;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d4613e6b57 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=50 identity=33144 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.24 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-5dfbd4c588-rmx68 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d4613e6b57 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=50 identity=33144 ipv4=10.0.0.24 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-5dfbd4c588-rmx68 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=10e7612506 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3455 identity=9092 ipv4=10.0.0.119 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-66hqf subsys=endpoint level=info msg="Successful endpoint creation" containerID=10e7612506 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3455 identity=9092 ipv4=10.0.0.119 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-5c97764fc9-66hqf subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=d4613e6b57 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=50 identity=33144 ipv4=10.0.0.24 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-5dfbd4c588-rmx68 subsys=endpoint level=info msg="Successful endpoint creation" containerID=d4613e6b57 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=50 identity=33144 ipv4=10.0.0.24 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-5dfbd4c588-rmx68 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=19ac52df35 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=158 identity=21081 ipv4=10.0.0.3 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-hs85f subsys=endpoint level=info msg="Successful endpoint creation" containerID=19ac52df35 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=158 identity=21081 ipv4=10.0.0.3 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-cd88cf4bf-hs85f subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.6 f7cb34eb-76cc-47d3-98dd-b293733395ea default }" containerID=86d46515f6c5468a28474099a7d33f06afb2af6bfb43a57374728dd88c549912 datapathConfiguration="&{false false false false false }" interface=lxcdbfbcb0ddae1 k8sPodName=monitoring/kube-prometheus-stack-admission-patch-6bq8l labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=86d46515f6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2392 ipv4=10.0.0.6 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-6bq8l subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=86d46515f6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2392 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=e0688ea0-45ce-4076-9e7a-4c518e548cda,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=e0688ea0-45ce-4076-9e7a-4c518e548cda,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.6 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-6bq8l subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-patch;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=60.2.0;k8s:batch.kubernetes.io/controller-uid=e0688ea0-45ce-4076-9e7a-4c518e548cda;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch;k8s:chart=kube-prometheus-stack-60.2.0;k8s:controller-uid=e0688ea0-45ce-4076-9e7a-4c518e548cda;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-patch;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=86d46515f6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2392 identity=31414 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=60.2.0,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=e0688ea0-45ce-4076-9e7a-4c518e548cda,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-60.2.0,k8s:controller-uid=e0688ea0-45ce-4076-9e7a-4c518e548cda,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.6 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-6bq8l oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=86d46515f6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2392 identity=31414 ipv4=10.0.0.6 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-6bq8l subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=86d46515f6 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2392 identity=31414 ipv4=10.0.0.6 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-6bq8l subsys=endpoint level=info msg="Successful endpoint creation" containerID=86d46515f6 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2392 identity=31414 ipv4=10.0.0.6 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-6bq8l subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=86d46515f6 endpointID=2392 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-patch-6bq8l subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-patch k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=60.2.0 k8s:batch.kubernetes.io/controller-uid=e0688ea0-45ce-4076-9e7a-4c518e548cda k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch k8s:chart=kube-prometheus-stack-60.2.0 k8s:controller-uid=e0688ea0-45ce-4076-9e7a-4c518e548cda k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-patch k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=86d46515f6 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2392 identity=31414 ipv4=10.0.0.6 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-6bq8l subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.12 a36a6006-f6ef-4438-a6c0-c415d28ccd6c default }" containerID=e2013fc53b3897cdd7f44f0d6d5c5f4668468bc2dd04db796f169e7f50c4d4a5 datapathConfiguration="&{false false false false false }" interface=lxc91a0c81a7316 k8sPodName=local-path-storage/helper-pod-create-pvc-d3fdf766-9981-44e7-9b40-9878d94bba80 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e2013fc53b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=222 ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d3fdf766-9981-44e7-9b40-9878d94bba80 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e2013fc53b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=222 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d3fdf766-9981-44e7-9b40-9878d94bba80 subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e2013fc53b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=222 identity=35147 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d3fdf766-9981-44e7-9b40-9878d94bba80 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e2013fc53b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=222 identity=35147 ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d3fdf766-9981-44e7-9b40-9878d94bba80 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=e2013fc53b datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=222 identity=35147 ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d3fdf766-9981-44e7-9b40-9878d94bba80 subsys=endpoint level=info msg="Successful endpoint creation" containerID=e2013fc53b datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=222 identity=35147 ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d3fdf766-9981-44e7-9b40-9878d94bba80 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.26 92d52528-0f9d-4bc8-88af-8affd7a2cd68 default }" containerID=a8bd08c140e14065cd37d90fcdee7b8a588c68f9cea669b822a1d2662617ed36 datapathConfiguration="&{false false false false false }" interface=lxc99744bc3fde9 k8sPodName=local-path-storage/helper-pod-create-pvc-f9ad3c20-5f04-4ce3-86f9-5bf1cbf00e06 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=a8bd08c140 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3662 ipv4=10.0.0.26 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f9ad3c20-5f04-4ce3-86f9-5bf1cbf00e06 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=a8bd08c140 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3662 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.26 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f9ad3c20-5f04-4ce3-86f9-5bf1cbf00e06 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=a8bd08c140 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3662 identity=35147 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.26 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f9ad3c20-5f04-4ce3-86f9-5bf1cbf00e06 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=a8bd08c140 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3662 identity=35147 ipv4=10.0.0.26 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f9ad3c20-5f04-4ce3-86f9-5bf1cbf00e06 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=a8bd08c140 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3662 identity=35147 ipv4=10.0.0.26 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f9ad3c20-5f04-4ce3-86f9-5bf1cbf00e06 subsys=endpoint level=info msg="Successful endpoint creation" containerID=a8bd08c140 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3662 identity=35147 ipv4=10.0.0.26 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f9ad3c20-5f04-4ce3-86f9-5bf1cbf00e06 subsys=daemon level=info msg="Delete endpoint request" containerID=e2013fc53b endpointID=222 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-d3fdf766-9981-44e7-9b40-9878d94bba80 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Delete endpoint request" containerID=a8bd08c140 endpointID=3662 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-f9ad3c20-5f04-4ce3-86f9-5bf1cbf00e06 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=e2013fc53b datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=222 identity=35147 ipv4=10.0.0.12 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-d3fdf766-9981-44e7-9b40-9878d94bba80 subsys=endpoint level=info msg="Removed endpoint" containerID=a8bd08c140 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3662 identity=35147 ipv4=10.0.0.26 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-f9ad3c20-5f04-4ce3-86f9-5bf1cbf00e06 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.95 e58b6417-bd38-45bd-983c-5c17ea4300a2 default }" containerID=a4ad2bd4d9a9dab2a1599db1a99be155391aada71338631211687e26f82054ca datapathConfiguration="&{false false false false false }" interface=lxc7d6ad2ecc965 k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=a4ad2bd4d9 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1095 ipv4=10.0.0.95 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=a4ad2bd4d9 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1095 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.95 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:alertmanager=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=alertmanager;k8s:app.kubernetes.io/version=0.27.0;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager;k8s:io.kubernetes.pod.namespace=monitoring;k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=a4ad2bd4d9 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1095 identity=10218 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.95 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=a4ad2bd4d9 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1095 identity=10218 ipv4=10.0.0.95 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=a4ad2bd4d9 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1095 identity=10218 ipv4=10.0.0.95 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=a4ad2bd4d9 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1095 identity=10218 ipv4=10.0.0.95 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.21 7df78e2d-6400-422a-a668-7a219c3a7893 default }" containerID=de28f68fb694438cd99ae5f5703292824aee9a0bda80c82c7da59271e2ff9137 datapathConfiguration="&{false false false false false }" interface=lxc0ae4f5c4d3aa k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=de28f68fb6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=892 ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=de28f68fb6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=892 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=prometheus;k8s:app.kubernetes.io/version=2.51.2;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus;k8s:io.kubernetes.pod.namespace=monitoring;k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus;k8s:operator.prometheus.io/shard=0;k8s:prometheus=kube-prometheus-stack-prometheus;k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=de28f68fb6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=892 identity=62964 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=de28f68fb6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=892 identity=62964 ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=de28f68fb6 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=892 identity=62964 ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=de28f68fb6 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=892 identity=62964 ipv4=10.0.0.21 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.62 f824112c-e982-4900-a43a-eec8b59006e9 default }" containerID=69bafd6e4f968f52df22d78f65c279a1a5202ac7b0ba35ec742476ebbbfc6472 datapathConfiguration="&{false false false false false }" interface=lxc35ef86a294fc k8sPodName=local-path-storage/helper-pod-create-pvc-a75e0fa4-19c8-4ebe-a096-f0cbcab8f139 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=69bafd6e4f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1468 ipv4=10.0.0.62 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-a75e0fa4-19c8-4ebe-a096-f0cbcab8f139 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=69bafd6e4f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1468 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.62 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-a75e0fa4-19c8-4ebe-a096-f0cbcab8f139 subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=69bafd6e4f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1468 identity=35147 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.62 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-a75e0fa4-19c8-4ebe-a096-f0cbcab8f139 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=69bafd6e4f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1468 identity=35147 ipv4=10.0.0.62 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-a75e0fa4-19c8-4ebe-a096-f0cbcab8f139 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=69bafd6e4f datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1468 identity=35147 ipv4=10.0.0.62 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-a75e0fa4-19c8-4ebe-a096-f0cbcab8f139 subsys=endpoint level=info msg="Successful endpoint creation" containerID=69bafd6e4f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1468 identity=35147 ipv4=10.0.0.62 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-a75e0fa4-19c8-4ebe-a096-f0cbcab8f139 subsys=daemon level=info msg="Delete endpoint request" containerID=69bafd6e4f endpointID=1468 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-a75e0fa4-19c8-4ebe-a096-f0cbcab8f139 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=69bafd6e4f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1468 identity=35147 ipv4=10.0.0.62 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-a75e0fa4-19c8-4ebe-a096-f0cbcab8f139 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.26 ad84f75f-6c8f-4125-a598-3542a164a8dc default }" containerID=0af2fb6f38ff71756a4922730f55c07c4f2f79e4e9f9cd658ae2a101198b64ba datapathConfiguration="&{false false false false false }" interface=lxc17609b07c76c k8sPodName=openstack/rabbitmq-keystone-server-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=0af2fb6f38 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1334 ipv4=10.0.0.26 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=0af2fb6f38 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1334 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.26 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq;k8s:app.kubernetes.io/name=rabbitmq-keystone;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=0af2fb6f38 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1334 identity=9991 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.26 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=0af2fb6f38 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1334 identity=9991 ipv4=10.0.0.26 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=0af2fb6f38 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1334 identity=9991 ipv4=10.0.0.26 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=0af2fb6f38 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1334 identity=9991 ipv4=10.0.0.26 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.140 da03742a-1943-47b1-9e0e-9e3311cc3649 default }" containerID=571923fae83e4aab13470af3e5e3bd44c70e7a90888f84685701ccabb6e25990 datapathConfiguration="&{false false false false false }" interface=lxc54e57c9a05c4 k8sPodName=openstack/keystone-api-7b97954775-5t5xx labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=571923fae8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=271 ipv4=10.0.0.140 ipv6= k8sPodName=openstack/keystone-api-7b97954775-5t5xx subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=571923fae8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=271 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.140 ipv6= k8sPodName=openstack/keystone-api-7b97954775-5t5xx subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:component=api;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-api;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=keystone;" subsys=allocator level=info msg="Invalid state transition skipped" containerID=571923fae8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=271 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.140 ipv6= k8sPodName=openstack/keystone-api-7b97954775-5t5xx line=611 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=571923fae8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=271 identity=13112 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.140 ipv6= k8sPodName=openstack/keystone-api-7b97954775-5t5xx oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=571923fae8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=271 identity=13112 ipv4=10.0.0.140 ipv6= k8sPodName=openstack/keystone-api-7b97954775-5t5xx subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=571923fae8 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=271 identity=13112 ipv4=10.0.0.140 ipv6= k8sPodName=openstack/keystone-api-7b97954775-5t5xx subsys=endpoint level=info msg="Successful endpoint creation" containerID=571923fae8 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=271 identity=13112 ipv4=10.0.0.140 ipv6= k8sPodName=openstack/keystone-api-7b97954775-5t5xx subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.165 1320c756-7b61-408d-a071-faf937e8ac6f default }" containerID=651791e9770a23d9238c25deb0d32dec8b5dc3a9b349066de484c35eb7b17d84 datapathConfiguration="&{false false false false false }" interface=lxc757a3a4de998 k8sPodName=openstack/keystone-credential-setup-csjnc labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=651791e977 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=298 ipv4=10.0.0.165 ipv6= k8sPodName=openstack/keystone-credential-setup-csjnc subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=651791e977 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=298 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=730ee26c-b7b0-4d21-b469-d0ad1f797495,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=730ee26c-b7b0-4d21-b469-d0ad1f797495,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.165 ipv6= k8sPodName=openstack/keystone-credential-setup-csjnc subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=730ee26c-b7b0-4d21-b469-d0ad1f797495;k8s:batch.kubernetes.io/job-name=keystone-credential-setup;k8s:component=credential-setup;k8s:controller-uid=730ee26c-b7b0-4d21-b469-d0ad1f797495;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-credential-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=651791e977 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=298 identity=59970 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=730ee26c-b7b0-4d21-b469-d0ad1f797495,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=730ee26c-b7b0-4d21-b469-d0ad1f797495,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.165 ipv6= k8sPodName=openstack/keystone-credential-setup-csjnc oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=651791e977 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=298 identity=59970 ipv4=10.0.0.165 ipv6= k8sPodName=openstack/keystone-credential-setup-csjnc subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=651791e977 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=298 identity=59970 ipv4=10.0.0.165 ipv6= k8sPodName=openstack/keystone-credential-setup-csjnc subsys=endpoint level=info msg="Successful endpoint creation" containerID=651791e977 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=298 identity=59970 ipv4=10.0.0.165 ipv6= k8sPodName=openstack/keystone-credential-setup-csjnc subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=651791e977 endpointID=298 k8sNamespace=openstack k8sPodName=keystone-credential-setup-csjnc subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=730ee26c-b7b0-4d21-b469-d0ad1f797495 k8s:batch.kubernetes.io/job-name=keystone-credential-setup k8s:component=credential-setup k8s:controller-uid=730ee26c-b7b0-4d21-b469-d0ad1f797495 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-credential-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=651791e977 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=298 identity=59970 ipv4=10.0.0.165 ipv6= k8sPodName=openstack/keystone-credential-setup-csjnc subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.131 d1b90a0c-c9d6-4779-99dd-3a1938f9be9b default }" containerID=5252524bb2ef0a196f5b24416f4aa9a4d04786bb4b1b8fcbcfdbc2cab9784048 datapathConfiguration="&{false false false false false }" interface=lxc6acf82af836a k8sPodName=openstack/keystone-db-init-vjjmk labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=5252524bb2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3178 ipv4=10.0.0.131 ipv6= k8sPodName=openstack/keystone-db-init-vjjmk subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=5252524bb2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3178 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=298c6eae-83b5-4bf2-8715-2f6b30af0b74,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=298c6eae-83b5-4bf2-8715-2f6b30af0b74,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.131 ipv6= k8sPodName=openstack/keystone-db-init-vjjmk subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=298c6eae-83b5-4bf2-8715-2f6b30af0b74;k8s:batch.kubernetes.io/job-name=keystone-db-init;k8s:component=db-init;k8s:controller-uid=298c6eae-83b5-4bf2-8715-2f6b30af0b74;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-init;k8s:release_group=keystone;" subsys=allocator level=info msg="Invalid state transition skipped" containerID=5252524bb2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3178 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.131 ipv6= k8sPodName=openstack/keystone-db-init-vjjmk line=611 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=5252524bb2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3178 identity=43294 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=298c6eae-83b5-4bf2-8715-2f6b30af0b74,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=298c6eae-83b5-4bf2-8715-2f6b30af0b74,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.131 ipv6= k8sPodName=openstack/keystone-db-init-vjjmk oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=5252524bb2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3178 identity=43294 ipv4=10.0.0.131 ipv6= k8sPodName=openstack/keystone-db-init-vjjmk subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=5252524bb2 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3178 identity=43294 ipv4=10.0.0.131 ipv6= k8sPodName=openstack/keystone-db-init-vjjmk subsys=endpoint level=info msg="Successful endpoint creation" containerID=5252524bb2 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3178 identity=43294 ipv4=10.0.0.131 ipv6= k8sPodName=openstack/keystone-db-init-vjjmk subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=5252524bb2 endpointID=3178 k8sNamespace=openstack k8sPodName=keystone-db-init-vjjmk subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=298c6eae-83b5-4bf2-8715-2f6b30af0b74 k8s:batch.kubernetes.io/job-name=keystone-db-init k8s:component=db-init k8s:controller-uid=298c6eae-83b5-4bf2-8715-2f6b30af0b74 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=5252524bb2 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3178 identity=43294 ipv4=10.0.0.131 ipv6= k8sPodName=openstack/keystone-db-init-vjjmk subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.191 9ccb0eb3-5993-4285-9738-37fb50539cc2 default }" containerID=35bd59fdf80d91cd894b7ba0997361fad7c190f98affc1fa83f82b392da0f951 datapathConfiguration="&{false false false false false }" interface=lxc93c48395becc k8sPodName=openstack/keystone-fernet-setup-rt2lq labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=35bd59fdf8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=336 ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-fernet-setup-rt2lq subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=35bd59fdf8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=336 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=74261e96-80fd-4cd2-9284-670e7a455cb7,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=74261e96-80fd-4cd2-9284-670e7a455cb7,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-fernet-setup-rt2lq subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=74261e96-80fd-4cd2-9284-670e7a455cb7;k8s:batch.kubernetes.io/job-name=keystone-fernet-setup;k8s:component=fernet-setup;k8s:controller-uid=74261e96-80fd-4cd2-9284-670e7a455cb7;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-fernet-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=35bd59fdf8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=336 identity=52271 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=74261e96-80fd-4cd2-9284-670e7a455cb7,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=74261e96-80fd-4cd2-9284-670e7a455cb7,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-fernet-setup-rt2lq oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=35bd59fdf8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=336 identity=52271 ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-fernet-setup-rt2lq subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=35bd59fdf8 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=336 identity=52271 ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-fernet-setup-rt2lq subsys=endpoint level=info msg="Successful endpoint creation" containerID=35bd59fdf8 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=336 identity=52271 ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-fernet-setup-rt2lq subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=35bd59fdf8 endpointID=336 k8sNamespace=openstack k8sPodName=keystone-fernet-setup-rt2lq subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=74261e96-80fd-4cd2-9284-670e7a455cb7 k8s:batch.kubernetes.io/job-name=keystone-fernet-setup k8s:component=fernet-setup k8s:controller-uid=74261e96-80fd-4cd2-9284-670e7a455cb7 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-fernet-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=35bd59fdf8 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=336 identity=52271 ipv4=10.0.0.191 ipv6= k8sPodName=openstack/keystone-fernet-setup-rt2lq subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.22 c7ed3daf-27af-4a80-a0c0-9e16ea993fde default }" containerID=a6f9e361d7f48edde07af2f534ac3972e9ff970cb2be9b965c61251793448deb datapathConfiguration="&{false false false false false }" interface=lxca681b4e0b3cd k8sPodName=openstack/keystone-db-sync-5hczl labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=a6f9e361d7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1737 ipv4=10.0.0.22 ipv6= k8sPodName=openstack/keystone-db-sync-5hczl subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=a6f9e361d7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1737 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=747f5e49-3f00-4d07-99cd-bfb3ad86d6d6,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=747f5e49-3f00-4d07-99cd-bfb3ad86d6d6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.22 ipv6= k8sPodName=openstack/keystone-db-sync-5hczl subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=747f5e49-3f00-4d07-99cd-bfb3ad86d6d6;k8s:batch.kubernetes.io/job-name=keystone-db-sync;k8s:component=db-sync;k8s:controller-uid=747f5e49-3f00-4d07-99cd-bfb3ad86d6d6;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-sync;k8s:release_group=keystone;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=a6f9e361d7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1737 identity=22745 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=747f5e49-3f00-4d07-99cd-bfb3ad86d6d6,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=747f5e49-3f00-4d07-99cd-bfb3ad86d6d6,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.22 ipv6= k8sPodName=openstack/keystone-db-sync-5hczl oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=a6f9e361d7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1737 identity=22745 ipv4=10.0.0.22 ipv6= k8sPodName=openstack/keystone-db-sync-5hczl subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=a6f9e361d7 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1737 identity=22745 ipv4=10.0.0.22 ipv6= k8sPodName=openstack/keystone-db-sync-5hczl subsys=endpoint level=info msg="Successful endpoint creation" containerID=a6f9e361d7 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1737 identity=22745 ipv4=10.0.0.22 ipv6= k8sPodName=openstack/keystone-db-sync-5hczl subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=a6f9e361d7 endpointID=1737 k8sNamespace=openstack k8sPodName=keystone-db-sync-5hczl subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=747f5e49-3f00-4d07-99cd-bfb3ad86d6d6 k8s:batch.kubernetes.io/job-name=keystone-db-sync k8s:component=db-sync k8s:controller-uid=747f5e49-3f00-4d07-99cd-bfb3ad86d6d6 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-sync k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=a6f9e361d7 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1737 identity=22745 ipv4=10.0.0.22 ipv6= k8sPodName=openstack/keystone-db-sync-5hczl subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.64 16589942-20ba-4d52-99f0-1617ce7c4f4e default }" containerID=34e1e652ebf2949a0c4c5bc4bc836a64c184d9fb56139e174a694cdd5fdd3fc7 datapathConfiguration="&{false false false false false }" interface=lxcf88a34a510d2 k8sPodName=openstack/keystone-rabbit-init-569n9 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=34e1e652eb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=779 ipv4=10.0.0.64 ipv6= k8sPodName=openstack/keystone-rabbit-init-569n9 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=34e1e652eb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=779 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=cdd3a415-d017-4cfe-941d-bb6f1e0c190b,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=cdd3a415-d017-4cfe-941d-bb6f1e0c190b,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.64 ipv6= k8sPodName=openstack/keystone-rabbit-init-569n9 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=cdd3a415-d017-4cfe-941d-bb6f1e0c190b;k8s:batch.kubernetes.io/job-name=keystone-rabbit-init;k8s:component=rabbit-init;k8s:controller-uid=cdd3a415-d017-4cfe-941d-bb6f1e0c190b;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-rabbit-init;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=34e1e652eb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=779 identity=37382 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=cdd3a415-d017-4cfe-941d-bb6f1e0c190b,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=cdd3a415-d017-4cfe-941d-bb6f1e0c190b,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.64 ipv6= k8sPodName=openstack/keystone-rabbit-init-569n9 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=34e1e652eb datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=779 identity=37382 ipv4=10.0.0.64 ipv6= k8sPodName=openstack/keystone-rabbit-init-569n9 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=34e1e652eb datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=779 identity=37382 ipv4=10.0.0.64 ipv6= k8sPodName=openstack/keystone-rabbit-init-569n9 subsys=endpoint level=info msg="Successful endpoint creation" containerID=34e1e652eb datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=779 identity=37382 ipv4=10.0.0.64 ipv6= k8sPodName=openstack/keystone-rabbit-init-569n9 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=34e1e652eb endpointID=779 k8sNamespace=openstack k8sPodName=keystone-rabbit-init-569n9 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=cdd3a415-d017-4cfe-941d-bb6f1e0c190b k8s:batch.kubernetes.io/job-name=keystone-rabbit-init k8s:component=rabbit-init k8s:controller-uid=cdd3a415-d017-4cfe-941d-bb6f1e0c190b k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-rabbit-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=34e1e652eb datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=779 identity=37382 ipv4=10.0.0.64 ipv6= k8sPodName=openstack/keystone-rabbit-init-569n9 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.129 efb6b102-bbe4-4513-b3f1-7ba053992c02 default }" containerID=94848b3d3f45eb0bdc664cd145f9c68f33efdf10c987726f04de970a62c4855b datapathConfiguration="&{false false false false false }" interface=lxc4e54f38584a6 k8sPodName=openstack/keystone-domain-manage-ndck8 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=94848b3d3f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2910 ipv4=10.0.0.129 ipv6= k8sPodName=openstack/keystone-domain-manage-ndck8 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=94848b3d3f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2910 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=d1b18d73-286c-45f5-813d-bb8024f8a2d8,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=d1b18d73-286c-45f5-813d-bb8024f8a2d8,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.129 ipv6= k8sPodName=openstack/keystone-domain-manage-ndck8 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=d1b18d73-286c-45f5-813d-bb8024f8a2d8;k8s:batch.kubernetes.io/job-name=keystone-domain-manage;k8s:component=domain-manage;k8s:controller-uid=d1b18d73-286c-45f5-813d-bb8024f8a2d8;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-domain-manage;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=94848b3d3f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2910 identity=37043 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=d1b18d73-286c-45f5-813d-bb8024f8a2d8,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=d1b18d73-286c-45f5-813d-bb8024f8a2d8,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.129 ipv6= k8sPodName=openstack/keystone-domain-manage-ndck8 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=94848b3d3f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2910 identity=37043 ipv4=10.0.0.129 ipv6= k8sPodName=openstack/keystone-domain-manage-ndck8 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=94848b3d3f datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2910 identity=37043 ipv4=10.0.0.129 ipv6= k8sPodName=openstack/keystone-domain-manage-ndck8 subsys=endpoint level=info msg="Successful endpoint creation" containerID=94848b3d3f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2910 identity=37043 ipv4=10.0.0.129 ipv6= k8sPodName=openstack/keystone-domain-manage-ndck8 subsys=daemon level=info msg="Delete endpoint request" containerID=94848b3d3f endpointID=2910 k8sNamespace=openstack k8sPodName=keystone-domain-manage-ndck8 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=d1b18d73-286c-45f5-813d-bb8024f8a2d8 k8s:batch.kubernetes.io/job-name=keystone-domain-manage k8s:component=domain-manage k8s:controller-uid=d1b18d73-286c-45f5-813d-bb8024f8a2d8 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-domain-manage k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=94848b3d3f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2910 identity=37043 ipv4=10.0.0.129 ipv6= k8sPodName=openstack/keystone-domain-manage-ndck8 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.145 f7c77cce-7033-4338-9781-b9a83b48a237 default }" containerID=a82b592302bf214cb4689f327879ec25093a2e197742f1770d8be7751cd1acfe datapathConfiguration="&{false false false false false }" interface=lxc8a2544584cb3 k8sPodName=openstack/keystone-bootstrap-pttg2 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=a82b592302 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1767 ipv4=10.0.0.145 ipv6= k8sPodName=openstack/keystone-bootstrap-pttg2 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=a82b592302 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1767 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=5d17f4ac-17d2-4a27-b047-5179a48303b4,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=5d17f4ac-17d2-4a27-b047-5179a48303b4,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.145 ipv6= k8sPodName=openstack/keystone-bootstrap-pttg2 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=5d17f4ac-17d2-4a27-b047-5179a48303b4;k8s:batch.kubernetes.io/job-name=keystone-bootstrap;k8s:component=bootstrap;k8s:controller-uid=5d17f4ac-17d2-4a27-b047-5179a48303b4;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-bootstrap;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=a82b592302 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1767 identity=7244 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=5d17f4ac-17d2-4a27-b047-5179a48303b4,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=5d17f4ac-17d2-4a27-b047-5179a48303b4,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.145 ipv6= k8sPodName=openstack/keystone-bootstrap-pttg2 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=a82b592302 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1767 identity=7244 ipv4=10.0.0.145 ipv6= k8sPodName=openstack/keystone-bootstrap-pttg2 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=a82b592302 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1767 identity=7244 ipv4=10.0.0.145 ipv6= k8sPodName=openstack/keystone-bootstrap-pttg2 subsys=endpoint level=info msg="Successful endpoint creation" containerID=a82b592302 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1767 identity=7244 ipv4=10.0.0.145 ipv6= k8sPodName=openstack/keystone-bootstrap-pttg2 subsys=daemon level=info msg="Delete endpoint request" containerID=a82b592302 endpointID=1767 k8sNamespace=openstack k8sPodName=keystone-bootstrap-pttg2 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=5d17f4ac-17d2-4a27-b047-5179a48303b4 k8s:batch.kubernetes.io/job-name=keystone-bootstrap k8s:component=bootstrap k8s:controller-uid=5d17f4ac-17d2-4a27-b047-5179a48303b4 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-bootstrap k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=a82b592302 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1767 identity=7244 ipv4=10.0.0.145 ipv6= k8sPodName=openstack/keystone-bootstrap-pttg2 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.83 295f11bf-8546-4d0a-8434-9506614de16a default }" containerID=941401bd3f4d80d6a13bb75ae2992d64b24dc99f13f9151f71c7fcc37c4028d8 datapathConfiguration="&{false false false false false }" interface=lxcc3b111574b07 k8sPodName=openstack/horizon-5476c59bf5-n6fcz labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=941401bd3f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=585 ipv4=10.0.0.83 ipv6= k8sPodName=openstack/horizon-5476c59bf5-n6fcz subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=941401bd3f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=585 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.83 ipv6= k8sPodName=openstack/horizon-5476c59bf5-n6fcz subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=941401bd3f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=585 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.83 ipv6= k8sPodName=openstack/horizon-5476c59bf5-n6fcz line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=941401bd3f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=585 identity=26396 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.83 ipv6= k8sPodName=openstack/horizon-5476c59bf5-n6fcz oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=941401bd3f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=585 identity=26396 ipv4=10.0.0.83 ipv6= k8sPodName=openstack/horizon-5476c59bf5-n6fcz subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=941401bd3f datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=585 identity=26396 ipv4=10.0.0.83 ipv6= k8sPodName=openstack/horizon-5476c59bf5-n6fcz subsys=endpoint level=info msg="Successful endpoint creation" containerID=941401bd3f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=585 identity=26396 ipv4=10.0.0.83 ipv6= k8sPodName=openstack/horizon-5476c59bf5-n6fcz subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.158 63d2cd68-e1a4-403f-b484-d275aa9918cb default }" containerID=5593e7982ce2fe2160248137bfedbed0373b51c7f54c460b82e9812500d90d11 datapathConfiguration="&{false false false false false }" interface=lxc491bd49dd676 k8sPodName=openstack/horizon-5476c59bf5-4kbpl labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=5593e7982c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=10 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-5476c59bf5-4kbpl subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.196 ce1e7472-8843-4f5b-a3bc-bf2e3fc1e3f3 default }" containerID=69ae98da00fd83f84974faadfeee62698936065b036c4f111ce443aaf1f2f214 datapathConfiguration="&{false false false false false }" interface=lxcf349dc04bdd5 k8sPodName=openstack/horizon-5476c59bf5-gfbr7 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=69ae98da00 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1826 ipv4=10.0.0.196 ipv6= k8sPodName=openstack/horizon-5476c59bf5-gfbr7 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=5593e7982c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=10 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-5476c59bf5-4kbpl subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=69ae98da00 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1826 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.196 ipv6= k8sPodName=openstack/horizon-5476c59bf5-gfbr7 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=5593e7982c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=10 identity=26396 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-5476c59bf5-4kbpl oldIdentity="no identity" subsys=endpoint level=info msg="Identity of endpoint changed" containerID=69ae98da00 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1826 identity=26396 identityLabels="k8s:application=horizon,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=horizon" ipv4=10.0.0.196 ipv6= k8sPodName=openstack/horizon-5476c59bf5-gfbr7 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=5593e7982c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=10 identity=26396 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-5476c59bf5-4kbpl subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=69ae98da00 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1826 identity=26396 ipv4=10.0.0.196 ipv6= k8sPodName=openstack/horizon-5476c59bf5-gfbr7 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.12 a5d88258-feb0-4513-b134-ea820a21a39d default }" containerID=62c889a36a7b8c3c0875558c023b14f8da485fae8066af544a4725fab5242107 datapathConfiguration="&{false false false false false }" interface=lxc6b3bac19e7e8 k8sPodName=openstack/horizon-db-init-lft6z labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=62c889a36a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1640 ipv4=10.0.0.12 ipv6= k8sPodName=openstack/horizon-db-init-lft6z subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=62c889a36a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1640 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=f2c148cd-8c1b-4098-9dd0-021ecda5b075,k8s:batch.kubernetes.io/job-name=horizon-db-init,k8s:component=db-init,k8s:controller-uid=f2c148cd-8c1b-4098-9dd0-021ecda5b075,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-init,k8s:release_group=horizon" ipv4=10.0.0.12 ipv6= k8sPodName=openstack/horizon-db-init-lft6z subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:batch.kubernetes.io/controller-uid=f2c148cd-8c1b-4098-9dd0-021ecda5b075;k8s:batch.kubernetes.io/job-name=horizon-db-init;k8s:component=db-init;k8s:controller-uid=f2c148cd-8c1b-4098-9dd0-021ecda5b075;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=horizon-db-init;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=62c889a36a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1640 identity=9402 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=f2c148cd-8c1b-4098-9dd0-021ecda5b075,k8s:batch.kubernetes.io/job-name=horizon-db-init,k8s:component=db-init,k8s:controller-uid=f2c148cd-8c1b-4098-9dd0-021ecda5b075,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-init,k8s:release_group=horizon" ipv4=10.0.0.12 ipv6= k8sPodName=openstack/horizon-db-init-lft6z oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=62c889a36a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1640 identity=9402 ipv4=10.0.0.12 ipv6= k8sPodName=openstack/horizon-db-init-lft6z subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=5593e7982c datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=10 identity=26396 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-5476c59bf5-4kbpl subsys=endpoint level=info msg="Successful endpoint creation" containerID=5593e7982c datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=10 identity=26396 ipv4=10.0.0.158 ipv6= k8sPodName=openstack/horizon-5476c59bf5-4kbpl subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=69ae98da00 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1826 identity=26396 ipv4=10.0.0.196 ipv6= k8sPodName=openstack/horizon-5476c59bf5-gfbr7 subsys=endpoint level=info msg="Successful endpoint creation" containerID=69ae98da00 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1826 identity=26396 ipv4=10.0.0.196 ipv6= k8sPodName=openstack/horizon-5476c59bf5-gfbr7 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=62c889a36a datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1640 identity=9402 ipv4=10.0.0.12 ipv6= k8sPodName=openstack/horizon-db-init-lft6z subsys=endpoint level=info msg="Successful endpoint creation" containerID=62c889a36a datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1640 identity=9402 ipv4=10.0.0.12 ipv6= k8sPodName=openstack/horizon-db-init-lft6z subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=62c889a36a endpointID=1640 k8sNamespace=openstack k8sPodName=horizon-db-init-lft6z subsys=daemon level=info msg="Releasing key" key="[k8s:application=horizon k8s:batch.kubernetes.io/controller-uid=f2c148cd-8c1b-4098-9dd0-021ecda5b075 k8s:batch.kubernetes.io/job-name=horizon-db-init k8s:component=db-init k8s:controller-uid=f2c148cd-8c1b-4098-9dd0-021ecda5b075 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=horizon-db-init k8s:release_group=horizon]" subsys=allocator level=info msg="Removed endpoint" containerID=62c889a36a datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1640 identity=9402 ipv4=10.0.0.12 ipv6= k8sPodName=openstack/horizon-db-init-lft6z subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.185 878669e1-7125-47c7-a934-4f04d6953b67 default }" containerID=52ad15c49dea4d62d0a4654bb42504740583d0c07565ef6467bb611de0574d8f datapathConfiguration="&{false false false false false }" interface=lxc47b3008bae34 k8sPodName=openstack/horizon-db-sync-vlcfd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=52ad15c49d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=443 ipv4=10.0.0.185 ipv6= k8sPodName=openstack/horizon-db-sync-vlcfd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=52ad15c49d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=443 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=161960b3-25ed-4ce1-9060-59f86d603e66,k8s:batch.kubernetes.io/job-name=horizon-db-sync,k8s:component=db-sync,k8s:controller-uid=161960b3-25ed-4ce1-9060-59f86d603e66,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-sync,k8s:release_group=horizon" ipv4=10.0.0.185 ipv6= k8sPodName=openstack/horizon-db-sync-vlcfd subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=horizon;k8s:batch.kubernetes.io/controller-uid=161960b3-25ed-4ce1-9060-59f86d603e66;k8s:batch.kubernetes.io/job-name=horizon-db-sync;k8s:component=db-sync;k8s:controller-uid=161960b3-25ed-4ce1-9060-59f86d603e66;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=horizon-db-sync;k8s:release_group=horizon;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=52ad15c49d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=443 identity=21425 identityLabels="k8s:application=horizon,k8s:batch.kubernetes.io/controller-uid=161960b3-25ed-4ce1-9060-59f86d603e66,k8s:batch.kubernetes.io/job-name=horizon-db-sync,k8s:component=db-sync,k8s:controller-uid=161960b3-25ed-4ce1-9060-59f86d603e66,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=horizon-db-sync,k8s:release_group=horizon" ipv4=10.0.0.185 ipv6= k8sPodName=openstack/horizon-db-sync-vlcfd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=52ad15c49d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=443 identity=21425 ipv4=10.0.0.185 ipv6= k8sPodName=openstack/horizon-db-sync-vlcfd subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=52ad15c49d datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=443 identity=21425 ipv4=10.0.0.185 ipv6= k8sPodName=openstack/horizon-db-sync-vlcfd subsys=endpoint level=info msg="Successful endpoint creation" containerID=52ad15c49d datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=443 identity=21425 ipv4=10.0.0.185 ipv6= k8sPodName=openstack/horizon-db-sync-vlcfd subsys=daemon level=info msg="Delete endpoint request" containerID=52ad15c49d endpointID=443 k8sNamespace=openstack k8sPodName=horizon-db-sync-vlcfd subsys=daemon level=info msg="Releasing key" key="[k8s:application=horizon k8s:batch.kubernetes.io/controller-uid=161960b3-25ed-4ce1-9060-59f86d603e66 k8s:batch.kubernetes.io/job-name=horizon-db-sync k8s:component=db-sync k8s:controller-uid=161960b3-25ed-4ce1-9060-59f86d603e66 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=horizon-db-sync k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=horizon-db-sync k8s:release_group=horizon]" subsys=allocator level=info msg="Removed endpoint" containerID=52ad15c49d datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=443 identity=21425 ipv4=10.0.0.185 ipv6= k8sPodName=openstack/horizon-db-sync-vlcfd subsys=endpoint