level=info msg="Memory available for map entries (0.003% of 16764964864B): 41912412B" subsys=config level=info msg="option bpf-ct-global-tcp-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-ct-global-any-max set by dynamic sizing to 73530" subsys=config level=info msg="option bpf-nat-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-neigh-global-max set by dynamic sizing to 147061" subsys=config level=info msg="option bpf-sock-rev-map-max set by dynamic sizing to 73530" subsys=config level=info msg=" --agent-health-port='9879'" subsys=daemon level=info msg=" --agent-labels=''" subsys=daemon level=info msg=" --agent-liveness-update-interval='1s'" subsys=daemon level=info msg=" --agent-not-ready-taint-key='node.cilium.io/agent-not-ready'" subsys=daemon level=info msg=" --allocator-list-timeout='3m0s'" subsys=daemon level=info msg=" --allow-icmp-frag-needed='true'" subsys=daemon level=info msg=" --allow-localhost='auto'" subsys=daemon level=info msg=" --annotate-k8s-node='false'" subsys=daemon level=info msg=" --api-rate-limit=''" subsys=daemon level=info msg=" --arping-refresh-period='30s'" subsys=daemon level=info msg=" --auto-create-cilium-node-resource='true'" subsys=daemon level=info msg=" --auto-direct-node-routes='false'" subsys=daemon level=info msg=" --bgp-announce-lb-ip='false'" subsys=daemon level=info msg=" --bgp-announce-pod-cidr='false'" subsys=daemon level=info msg=" --bgp-config-path='/var/lib/cilium/bgp/config.yaml'" subsys=daemon level=info msg=" --bpf-auth-map-max='524288'" subsys=daemon level=info msg=" --bpf-ct-global-any-max='262144'" subsys=daemon level=info msg=" --bpf-ct-global-tcp-max='524288'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-fin='10s'" subsys=daemon level=info msg=" --bpf-ct-timeout-regular-tcp-syn='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-any='1m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp='6h0m0s'" subsys=daemon level=info msg=" --bpf-ct-timeout-service-tcp-grace='1m0s'" subsys=daemon level=info msg=" --bpf-filter-priority='1'" subsys=daemon level=info msg=" --bpf-fragments-map-max='8192'" subsys=daemon level=info msg=" --bpf-lb-acceleration='disabled'" subsys=daemon level=info msg=" --bpf-lb-affinity-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-algorithm='random'" subsys=daemon level=info msg=" --bpf-lb-dev-ip-addr-inherit=''" subsys=daemon level=info msg=" --bpf-lb-dsr-dispatch='opt'" subsys=daemon level=info msg=" --bpf-lb-dsr-l4-xlate='frontend'" subsys=daemon level=info msg=" --bpf-lb-external-clusterip='false'" subsys=daemon level=info msg=" --bpf-lb-maglev-hash-seed='JLfvgnHc2kaSUFaI'" subsys=daemon level=info msg=" --bpf-lb-maglev-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-maglev-table-size='16381'" subsys=daemon level=info msg=" --bpf-lb-map-max='65536'" subsys=daemon level=info msg=" --bpf-lb-mode='snat'" subsys=daemon level=info msg=" --bpf-lb-rev-nat-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-rss-ipv4-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-rss-ipv6-src-cidr=''" subsys=daemon level=info msg=" --bpf-lb-service-backend-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-service-map-max='0'" subsys=daemon level=info msg=" --bpf-lb-sock='false'" subsys=daemon level=info msg=" --bpf-lb-sock-hostns-only='false'" subsys=daemon level=info msg=" --bpf-lb-source-range-map-max='0'" subsys=daemon level=info msg=" --bpf-map-dynamic-size-ratio='0.0025'" subsys=daemon level=info msg=" --bpf-map-event-buffers=''" subsys=daemon level=info msg=" --bpf-nat-global-max='524288'" subsys=daemon level=info msg=" --bpf-neigh-global-max='524288'" subsys=daemon level=info msg=" --bpf-policy-map-full-reconciliation-interval='15m0s'" subsys=daemon level=info msg=" --bpf-policy-map-max='16384'" subsys=daemon level=info msg=" --bpf-root='/sys/fs/bpf'" subsys=daemon level=info msg=" --bpf-sock-rev-map-max='262144'" subsys=daemon level=info msg=" --bypass-ip-availability-upon-restore='false'" subsys=daemon level=info msg=" --certificates-directory='/var/run/cilium/certs'" subsys=daemon level=info msg=" --cflags=''" subsys=daemon level=info msg=" --cgroup-root='/run/cilium/cgroupv2'" subsys=daemon level=info msg=" --cilium-endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --cluster-health-port='4240'" subsys=daemon level=info msg=" --cluster-id='0'" subsys=daemon level=info msg=" --cluster-name='default'" subsys=daemon level=info msg=" --cluster-pool-ipv4-cidr='10.0.0.0/8'" subsys=daemon level=info msg=" --cluster-pool-ipv4-mask-size='24'" subsys=daemon level=info msg=" --clustermesh-config='/var/lib/cilium/clustermesh/'" subsys=daemon level=info msg=" --clustermesh-ip-identities-sync-timeout='1m0s'" subsys=daemon level=info msg=" --cmdref=''" subsys=daemon level=info msg=" --cni-chaining-mode='none'" subsys=daemon level=info msg=" --cni-chaining-target=''" subsys=daemon level=info msg=" --cni-exclusive='true'" subsys=daemon level=info msg=" --cni-external-routing='false'" subsys=daemon level=info msg=" --cni-log-file='/var/run/cilium/cilium-cni.log'" subsys=daemon level=info msg=" --cnp-node-status-gc-interval='0s'" subsys=daemon level=info msg=" --config=''" subsys=daemon level=info msg=" --config-dir='/tmp/cilium/config-map'" subsys=daemon level=info msg=" --config-sources='config-map:kube-system/cilium-config'" subsys=daemon level=info msg=" --conntrack-gc-interval='0s'" subsys=daemon level=info msg=" --conntrack-gc-max-interval='0s'" subsys=daemon level=info msg=" --crd-wait-timeout='5m0s'" subsys=daemon level=info msg=" --custom-cni-conf='false'" subsys=daemon level=info msg=" --datapath-mode='veth'" subsys=daemon level=info msg=" --debug='false'" subsys=daemon level=info msg=" --debug-verbose=''" subsys=daemon level=info msg=" --derive-masquerade-ip-addr-from-device=''" subsys=daemon level=info msg=" --devices=''" subsys=daemon level=info msg=" --direct-routing-device=''" subsys=daemon level=info msg=" --disable-cnp-status-updates='true'" subsys=daemon level=info msg=" --disable-endpoint-crd='false'" subsys=daemon level=info msg=" --disable-envoy-version-check='false'" subsys=daemon level=info msg=" --disable-iptables-feeder-rules=''" subsys=daemon level=info msg=" --dns-max-ips-per-restored-rule='1000'" subsys=daemon level=info msg=" --dns-policy-unload-on-shutdown='false'" subsys=daemon level=info msg=" --dnsproxy-concurrency-limit='0'" subsys=daemon level=info msg=" --dnsproxy-concurrency-processing-grace-period='0s'" subsys=daemon level=info msg=" --dnsproxy-enable-transparent-mode='true'" subsys=daemon level=info msg=" --dnsproxy-lock-count='128'" subsys=daemon level=info msg=" --dnsproxy-lock-timeout='500ms'" subsys=daemon level=info msg=" --egress-gateway-policy-map-max='16384'" subsys=daemon level=info msg=" --egress-gateway-reconciliation-trigger-interval='1s'" subsys=daemon level=info msg=" --egress-masquerade-interfaces=''" subsys=daemon level=info msg=" --egress-multi-home-ip-rule-compat='false'" subsys=daemon level=info msg=" --enable-auto-protect-node-port-range='true'" subsys=daemon level=info msg=" --enable-bandwidth-manager='false'" subsys=daemon level=info msg=" --enable-bbr='false'" subsys=daemon level=info msg=" --enable-bgp-control-plane='false'" subsys=daemon level=info msg=" --enable-bpf-clock-probe='false'" subsys=daemon level=info msg=" --enable-bpf-masquerade='false'" subsys=daemon level=info msg=" --enable-bpf-tproxy='false'" subsys=daemon level=info msg=" --enable-cilium-api-server-access='*'" subsys=daemon level=info msg=" --enable-cilium-endpoint-slice='false'" subsys=daemon level=info msg=" --enable-cilium-health-api-server-access='*'" subsys=daemon level=info msg=" --enable-custom-calls='false'" subsys=daemon level=info msg=" --enable-endpoint-health-checking='true'" subsys=daemon level=info msg=" --enable-endpoint-routes='false'" subsys=daemon level=info msg=" --enable-envoy-config='false'" subsys=daemon level=info msg=" --enable-external-ips='false'" subsys=daemon level=info msg=" --enable-health-check-nodeport='true'" subsys=daemon level=info msg=" --enable-health-checking='true'" subsys=daemon level=info msg=" --enable-high-scale-ipcache='false'" subsys=daemon level=info msg=" --enable-host-firewall='false'" subsys=daemon level=info msg=" --enable-host-legacy-routing='false'" subsys=daemon level=info msg=" --enable-host-port='false'" subsys=daemon level=info msg=" --enable-hubble='false'" subsys=daemon level=info msg=" --enable-hubble-recorder-api='true'" subsys=daemon level=info msg=" --enable-icmp-rules='true'" subsys=daemon level=info msg=" --enable-identity-mark='true'" subsys=daemon level=info msg=" --enable-ip-masq-agent='false'" subsys=daemon level=info msg=" --enable-ipsec='false'" subsys=daemon level=info msg=" --enable-ipsec-key-watcher='true'" subsys=daemon level=info msg=" --enable-ipv4='true'" subsys=daemon level=info msg=" --enable-ipv4-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv4-egress-gateway='false'" subsys=daemon level=info msg=" --enable-ipv4-fragment-tracking='true'" subsys=daemon level=info msg=" --enable-ipv4-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6='false'" subsys=daemon level=info msg=" --enable-ipv6-big-tcp='false'" subsys=daemon level=info msg=" --enable-ipv6-masquerade='true'" subsys=daemon level=info msg=" --enable-ipv6-ndp='false'" subsys=daemon level=info msg=" --enable-k8s='true'" subsys=daemon level=info msg=" --enable-k8s-api-discovery='false'" subsys=daemon level=info msg=" --enable-k8s-endpoint-slice='true'" subsys=daemon level=info msg=" --enable-k8s-event-handover='false'" subsys=daemon level=info msg=" --enable-k8s-networkpolicy='true'" subsys=daemon level=info msg=" --enable-k8s-terminating-endpoint='true'" subsys=daemon level=info msg=" --enable-l2-announcements='false'" subsys=daemon level=info msg=" --enable-l2-neigh-discovery='true'" subsys=daemon level=info msg=" --enable-l2-pod-announcements='false'" subsys=daemon level=info msg=" --enable-l7-proxy='true'" subsys=daemon level=info msg=" --enable-local-node-route='true'" subsys=daemon level=info msg=" --enable-local-redirect-policy='false'" subsys=daemon level=info msg=" --enable-mke='false'" subsys=daemon level=info msg=" --enable-monitor='true'" subsys=daemon level=info msg=" --enable-nat46x64-gateway='false'" subsys=daemon level=info msg=" --enable-node-port='false'" subsys=daemon level=info msg=" --enable-pmtu-discovery='false'" subsys=daemon level=info msg=" --enable-policy='default'" subsys=daemon level=info msg=" --enable-recorder='false'" subsys=daemon level=info msg=" --enable-remote-node-identity='true'" subsys=daemon level=info msg=" --enable-runtime-device-detection='false'" subsys=daemon level=info msg=" --enable-sctp='false'" subsys=daemon level=info msg=" --enable-service-topology='false'" subsys=daemon level=info msg=" --enable-session-affinity='false'" subsys=daemon level=info msg=" --enable-srv6='false'" subsys=daemon level=info msg=" --enable-stale-cilium-endpoint-cleanup='true'" subsys=daemon level=info msg=" --enable-svc-source-range-check='true'" subsys=daemon level=info msg=" --enable-tracing='false'" subsys=daemon level=info msg=" --enable-unreachable-routes='false'" subsys=daemon level=info msg=" --enable-vtep='false'" subsys=daemon level=info msg=" --enable-well-known-identities='false'" subsys=daemon level=info msg=" --enable-wireguard='false'" subsys=daemon level=info msg=" --enable-wireguard-userspace-fallback='false'" subsys=daemon level=info msg=" --enable-xdp-prefilter='false'" subsys=daemon level=info msg=" --enable-xt-socket-fallback='true'" subsys=daemon level=info msg=" --encrypt-interface=''" subsys=daemon level=info msg=" --encrypt-node='false'" subsys=daemon level=info msg=" --endpoint-gc-interval='5m0s'" subsys=daemon level=info msg=" --endpoint-queue-size='25'" subsys=daemon level=info msg=" --endpoint-status=''" subsys=daemon level=info msg=" --envoy-config-timeout='2m0s'" subsys=daemon level=info msg=" --envoy-log=''" subsys=daemon level=info msg=" --exclude-local-address=''" subsys=daemon level=info msg=" --external-envoy-proxy='false'" subsys=daemon level=info msg=" --fixed-identity-mapping=''" subsys=daemon level=info msg=" --fqdn-regex-compile-lru-size='1024'" subsys=daemon level=info msg=" --gops-port='9890'" subsys=daemon level=info msg=" --http-403-msg=''" subsys=daemon level=info msg=" --http-idle-timeout='0'" subsys=daemon level=info msg=" --http-max-grpc-timeout='0'" subsys=daemon level=info msg=" --http-normalize-path='true'" subsys=daemon level=info msg=" --http-request-timeout='3600'" subsys=daemon level=info msg=" --http-retry-count='3'" subsys=daemon level=info msg=" --http-retry-timeout='0'" subsys=daemon level=info msg=" --hubble-disable-tls='false'" subsys=daemon level=info msg=" --hubble-event-buffer-capacity='4095'" subsys=daemon level=info msg=" --hubble-event-queue-size='0'" subsys=daemon level=info msg=" --hubble-export-file-compress='false'" subsys=daemon level=info msg=" --hubble-export-file-max-backups='5'" subsys=daemon level=info msg=" --hubble-export-file-max-size-mb='10'" subsys=daemon level=info msg=" --hubble-export-file-path=''" subsys=daemon level=info msg=" --hubble-listen-address=''" subsys=daemon level=info msg=" --hubble-metrics=''" subsys=daemon level=info msg=" --hubble-metrics-server=''" subsys=daemon level=info msg=" --hubble-monitor-events=''" subsys=daemon level=info msg=" --hubble-prefer-ipv6='false'" subsys=daemon level=info msg=" --hubble-recorder-sink-queue-size='1024'" subsys=daemon level=info msg=" --hubble-recorder-storage-path='/var/run/cilium/pcaps'" subsys=daemon level=info msg=" --hubble-skip-unknown-cgroup-ids='true'" subsys=daemon level=info msg=" --hubble-socket-path='/var/run/cilium/hubble.sock'" subsys=daemon level=info msg=" --hubble-tls-cert-file=''" subsys=daemon level=info msg=" --hubble-tls-client-ca-files=''" subsys=daemon level=info msg=" --hubble-tls-key-file=''" subsys=daemon level=info msg=" --identity-allocation-mode='crd'" subsys=daemon level=info msg=" --identity-change-grace-period='5s'" subsys=daemon level=info msg=" --identity-gc-interval='15m0s'" subsys=daemon level=info msg=" --identity-heartbeat-timeout='30m0s'" subsys=daemon level=info msg=" --identity-restore-grace-period='10m0s'" subsys=daemon level=info msg=" --install-egress-gateway-routes='false'" subsys=daemon level=info msg=" --install-iptables-rules='true'" subsys=daemon level=info msg=" --install-no-conntrack-iptables-rules='false'" subsys=daemon level=info msg=" --ip-allocation-timeout='2m0s'" subsys=daemon level=info msg=" --ip-masq-agent-config-path='/etc/config/ip-masq-agent'" subsys=daemon level=info msg=" --ipam='cluster-pool'" subsys=daemon level=info msg=" --ipam-cilium-node-update-rate='15s'" subsys=daemon level=info msg=" --ipam-multi-pool-pre-allocation='default=8'" subsys=daemon level=info msg=" --ipsec-key-file=''" subsys=daemon level=info msg=" --ipsec-key-rotation-duration='5m0s'" subsys=daemon level=info msg=" --iptables-lock-timeout='5s'" subsys=daemon level=info msg=" --iptables-random-fully='false'" subsys=daemon level=info msg=" --ipv4-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv4-node='auto'" subsys=daemon level=info msg=" --ipv4-pod-subnets=''" subsys=daemon level=info msg=" --ipv4-range='auto'" subsys=daemon level=info msg=" --ipv4-service-loopback-address='169.254.42.1'" subsys=daemon level=info msg=" --ipv4-service-range='auto'" subsys=daemon level=info msg=" --ipv6-cluster-alloc-cidr='f00d::/64'" subsys=daemon level=info msg=" --ipv6-mcast-device=''" subsys=daemon level=info msg=" --ipv6-native-routing-cidr=''" subsys=daemon level=info msg=" --ipv6-node='auto'" subsys=daemon level=info msg=" --ipv6-pod-subnets=''" subsys=daemon level=info msg=" --ipv6-range='auto'" subsys=daemon level=info msg=" --ipv6-service-range='auto'" subsys=daemon level=info msg=" --join-cluster='false'" subsys=daemon level=info msg=" --k8s-api-server=''" subsys=daemon level=info msg=" --k8s-client-burst='10'" subsys=daemon level=info msg=" --k8s-client-qps='5'" subsys=daemon level=info msg=" --k8s-heartbeat-timeout='30s'" subsys=daemon level=info msg=" --k8s-kubeconfig-path=''" subsys=daemon level=info msg=" --k8s-namespace='kube-system'" subsys=daemon level=info msg=" --k8s-require-ipv4-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-require-ipv6-pod-cidr='false'" subsys=daemon level=info msg=" --k8s-service-cache-size='128'" subsys=daemon level=info msg=" --k8s-service-proxy-name=''" subsys=daemon level=info msg=" --k8s-sync-timeout='3m0s'" subsys=daemon level=info msg=" --k8s-watcher-endpoint-selector='metadata.name!=kube-scheduler,metadata.name!=kube-controller-manager,metadata.name!=etcd-operator,metadata.name!=gcp-controller-manager'" subsys=daemon level=info msg=" --keep-config='false'" subsys=daemon level=info msg=" --kube-proxy-replacement='disabled'" subsys=daemon level=info msg=" --kube-proxy-replacement-healthz-bind-address=''" subsys=daemon level=info msg=" --kvstore=''" subsys=daemon level=info msg=" --kvstore-connectivity-timeout='2m0s'" subsys=daemon level=info msg=" --kvstore-lease-ttl='15m0s'" subsys=daemon level=info msg=" --kvstore-max-consecutive-quorum-errors='2'" subsys=daemon level=info msg=" --kvstore-opt=''" subsys=daemon level=info msg=" --kvstore-periodic-sync='5m0s'" subsys=daemon level=info msg=" --l2-announcements-lease-duration='15s'" subsys=daemon level=info msg=" --l2-announcements-renew-deadline='5s'" subsys=daemon level=info msg=" --l2-announcements-retry-period='2s'" subsys=daemon level=info msg=" --l2-pod-announcements-interface=''" subsys=daemon level=info msg=" --label-prefix-file=''" subsys=daemon level=info msg=" --labels=''" subsys=daemon level=info msg=" --lib-dir='/var/lib/cilium'" subsys=daemon level=info msg=" --local-max-addr-scope='252'" subsys=daemon level=info msg=" --local-router-ipv4=''" subsys=daemon level=info msg=" --local-router-ipv6=''" subsys=daemon level=info msg=" --log-driver=''" subsys=daemon level=info msg=" --log-opt=''" subsys=daemon level=info msg=" --log-system-load='false'" subsys=daemon level=info msg=" --max-controller-interval='0'" subsys=daemon level=info msg=" --mesh-auth-enabled='true'" subsys=daemon level=info msg=" --mesh-auth-gc-interval='5m0s'" subsys=daemon level=info msg=" --mesh-auth-mutual-listener-port='0'" subsys=daemon level=info msg=" --mesh-auth-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-rotated-identities-queue-size='1024'" subsys=daemon level=info msg=" --mesh-auth-signal-backoff-duration='1s'" subsys=daemon level=info msg=" --mesh-auth-spiffe-trust-domain='spiffe.cilium'" subsys=daemon level=info msg=" --mesh-auth-spire-admin-socket=''" subsys=daemon level=info msg=" --metrics=''" subsys=daemon level=info msg=" --mke-cgroup-mount=''" subsys=daemon level=info msg=" --monitor-aggregation='medium'" subsys=daemon level=info msg=" --monitor-aggregation-flags='all'" subsys=daemon level=info msg=" --monitor-aggregation-interval='5s'" subsys=daemon level=info msg=" --monitor-queue-size='0'" subsys=daemon level=info msg=" --mtu='0'" subsys=daemon level=info msg=" --node-encryption-opt-out-labels='node-role.kubernetes.io/control-plane'" subsys=daemon level=info msg=" --node-port-acceleration='disabled'" subsys=daemon level=info msg=" --node-port-algorithm='random'" subsys=daemon level=info msg=" --node-port-bind-protection='true'" subsys=daemon level=info msg=" --node-port-mode='snat'" subsys=daemon level=info msg=" --node-port-range='30000,32767'" subsys=daemon level=info msg=" --nodes-gc-interval='5m0s'" subsys=daemon level=info msg=" --operator-api-serve-addr='127.0.0.1:9234'" subsys=daemon level=info msg=" --policy-audit-mode='false'" subsys=daemon level=info msg=" --policy-queue-size='100'" subsys=daemon level=info msg=" --policy-trigger-interval='1s'" subsys=daemon level=info msg=" --pprof='false'" subsys=daemon level=info msg=" --pprof-address='localhost'" subsys=daemon level=info msg=" --pprof-port='6060'" subsys=daemon level=info msg=" --preallocate-bpf-maps='false'" subsys=daemon level=info msg=" --prepend-iptables-chains='true'" subsys=daemon level=info msg=" --procfs='/host/proc'" subsys=daemon level=info msg=" --prometheus-serve-addr=':9962'" subsys=daemon level=info msg=" --proxy-connect-timeout='2'" subsys=daemon level=info msg=" --proxy-gid='1337'" subsys=daemon level=info msg=" --proxy-idle-timeout-seconds='60'" subsys=daemon level=info msg=" --proxy-max-connection-duration-seconds='0'" subsys=daemon level=info msg=" --proxy-max-requests-per-connection='0'" subsys=daemon level=info msg=" --proxy-prometheus-port='9964'" subsys=daemon level=info msg=" --read-cni-conf=''" subsys=daemon level=info msg=" --remove-cilium-node-taints='true'" subsys=daemon level=info msg=" --restore='true'" subsys=daemon level=info msg=" --route-metric='0'" subsys=daemon level=info msg=" --routing-mode='tunnel'" subsys=daemon level=info msg=" --set-cilium-is-up-condition='true'" subsys=daemon level=info msg=" --set-cilium-node-taints='true'" subsys=daemon level=info msg=" --sidecar-istio-proxy-image='cilium/istio_proxy'" subsys=daemon level=info msg=" --single-cluster-route='false'" subsys=daemon level=info msg=" --skip-cnp-status-startup-clean='false'" subsys=daemon level=info msg=" --socket-path='/var/run/cilium/cilium.sock'" subsys=daemon level=info msg=" --srv6-encap-mode='reduced'" subsys=daemon level=info msg=" --state-dir='/var/run/cilium'" subsys=daemon level=info msg=" --synchronize-k8s-nodes='true'" subsys=daemon level=info msg=" --tofqdns-dns-reject-response-code='refused'" subsys=daemon level=info msg=" --tofqdns-enable-dns-compression='true'" subsys=daemon level=info msg=" --tofqdns-endpoint-max-ip-per-hostname='50'" subsys=daemon level=info msg=" --tofqdns-idle-connection-grace-period='0s'" subsys=daemon level=info msg=" --tofqdns-max-deferred-connection-deletes='10000'" subsys=daemon level=info msg=" --tofqdns-min-ttl='0'" subsys=daemon level=info msg=" --tofqdns-pre-cache=''" subsys=daemon level=info msg=" --tofqdns-proxy-port='0'" subsys=daemon level=info msg=" --tofqdns-proxy-response-max-delay='100ms'" subsys=daemon level=info msg=" --trace-payloadlen='128'" subsys=daemon level=info msg=" --trace-sock='true'" subsys=daemon level=info msg=" --tunnel=''" subsys=daemon level=info msg=" --tunnel-port='6082'" subsys=daemon level=info msg=" --tunnel-protocol='geneve'" subsys=daemon level=info msg=" --unmanaged-pod-watcher-interval='15'" subsys=daemon level=info msg=" --use-cilium-internal-ip-for-ipsec='false'" subsys=daemon level=info msg=" --version='false'" subsys=daemon level=info msg=" --vlan-bpf-bypass=''" subsys=daemon level=info msg=" --vtep-cidr=''" subsys=daemon level=info msg=" --vtep-endpoint=''" subsys=daemon level=info msg=" --vtep-mac=''" subsys=daemon level=info msg=" --vtep-mask=''" subsys=daemon level=info msg=" --wireguard-encapsulate='false'" subsys=daemon level=info msg=" --write-cni-conf-when-ready='/host/etc/cni/net.d/05-cilium.conflist'" subsys=daemon level=info msg=" _ _ _" subsys=daemon level=info msg=" ___|_| |_|_ _ _____" subsys=daemon level=info msg="| _| | | | | | |" subsys=daemon level=info msg="|___|_|_|_|___|_|_|_|" subsys=daemon level=info msg="Cilium 1.14.8 cf6e022e 2024-03-13T12:23:35-04:00 go version go1.21.8 linux/amd64" subsys=daemon level=info msg="clang (10.0.0) and kernel (5.15.0) versions: OK!" subsys=linux-datapath level=info msg="linking environment: OK!" subsys=linux-datapath level=info msg="Kernel config file not found: if the agent fails to start, check the system requirements at https://docs.cilium.io/en/stable/operations/system_requirements" subsys=probes level=info msg="Detected mounted BPF filesystem at /sys/fs/bpf" subsys=bpf level=info msg="Mounted cgroupv2 filesystem at /run/cilium/cgroupv2" subsys=cgroups level=info msg="Parsing base label prefixes from default label list" subsys=labels-filter level=info msg="Parsing additional label prefixes from user inputs: []" subsys=labels-filter level=info msg="Final label prefixes to be used for identity evaluation:" subsys=labels-filter level=info msg=" - reserved:.*" subsys=labels-filter level=info msg=" - :io\\.kubernetes\\.pod\\.namespace" subsys=labels-filter level=info msg=" - :io\\.cilium\\.k8s\\.namespace\\.labels" subsys=labels-filter level=info msg=" - :app\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:io\\.kubernetes" subsys=labels-filter level=info msg=" - !:kubernetes\\.io" subsys=labels-filter level=info msg=" - !:.*beta\\.kubernetes\\.io" subsys=labels-filter level=info msg=" - !:k8s\\.io" subsys=labels-filter level=info msg=" - !:pod-template-generation" subsys=labels-filter level=info msg=" - !:pod-template-hash" subsys=labels-filter level=info msg=" - !:controller-revision-hash" subsys=labels-filter level=info msg=" - !:annotation.*" subsys=labels-filter level=info msg=" - !:etcd_node" subsys=labels-filter level=info msg=Invoked duration=1.059402ms function="pprof.glob..func1 (cell.go:50)" subsys=hive level=info msg=Invoked duration="44.249µs" function="gops.registerGopsHooks (cell.go:38)" subsys=hive level=info msg=Invoked duration=1.120531ms function="metrics.NewRegistry (registry.go:65)" subsys=hive level=info msg=Invoked duration="9.349µs" function="metrics.glob..func1 (cell.go:12)" subsys=hive level=info msg="Spire Delegate API Client is disabled as no socket path is configured" subsys=spire-delegate level=info msg="Mutual authentication handler is disabled as no port is configured" subsys=auth level=info msg=Invoked duration=99.960326ms function="cmd.glob..func4 (daemon_main.go:1607)" subsys=hive level=info msg=Invoked duration="11.35µs" function="gc.registerSignalHandler (cell.go:47)" subsys=hive level=info msg=Invoked duration="16.88µs" function="utime.initUtimeSync (cell.go:29)" subsys=hive level=info msg=Invoked duration="61.128µs" function="agentliveness.newAgentLivenessUpdater (agent_liveness.go:43)" subsys=hive level=info msg=Invoked duration="72.488µs" function="l2responder.NewL2ResponderReconciler (l2responder.go:63)" subsys=hive level=info msg=Invoked duration="63.108µs" function="garp.newGARPProcessor (processor.go:27)" subsys=hive level=info msg=Starting subsys=hive level=info msg="Started gops server" address="127.0.0.1:9890" subsys=gops level=info msg="Start hook executed" duration="417.576µs" function="gops.registerGopsHooks.func1 (cell.go:43)" subsys=hive level=info msg="Start hook executed" duration="1.599µs" function="metrics.NewRegistry.func1 (registry.go:86)" subsys=hive level=info msg="Establishing connection to apiserver" host="https://10.96.0.1:443" subsys=k8s-client level=info msg="Serving prometheus metrics on :9962" subsys=metrics level=info msg="Connected to apiserver" subsys=k8s-client level=info msg="Start hook executed" duration=12.529617ms function="client.(*compositeClientset).onStart" subsys=hive level=info msg="Start hook executed" duration=8.308217ms function="authmap.newAuthMap.func1 (cell.go:27)" subsys=hive level=info msg="Start hook executed" duration="45.218µs" function="configmap.newMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="37.009µs" function="signalmap.newMap.func1 (cell.go:44)" subsys=hive level=info msg="Start hook executed" duration="202.913µs" function="nodemap.newNodeMap.func1 (cell.go:23)" subsys=hive level=info msg="Start hook executed" duration="97.936µs" function="eventsmap.newEventsMap.func1 (cell.go:35)" subsys=hive level=info msg="Start hook executed" duration="65.267µs" function="*cni.cniConfigManager.Start" subsys=hive level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Wrote CNI configuration file to /host/etc/cni/net.d/05-cilium.conflist" subsys=cni-config level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Activity in /host/etc/cni/net.d/, re-generating CNI configuration" subsys=cni-config level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Generating CNI configuration file with mode none" subsys=cni-config level=info msg="Start hook executed" duration=44.993329ms function="datapath.newDatapath.func1 (cells.go:113)" subsys=hive level=info msg="Restored 0 node IDs from the BPF map" subsys=linux-datapath level=info msg="Start hook executed" duration="104.097µs" function="datapath.newDatapath.func2 (cells.go:126)" subsys=hive level=info msg="Start hook executed" duration="15.209µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Node].Start" subsys=hive level=info msg="Start hook executed" duration="2.17µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNode].Start" subsys=hive level=info msg="Using autogenerated IPv4 allocation range" subsys=node v4Prefix=10.43.0.0/16 level=info msg="no local ciliumnode found, will not restore cilium internal ips from k8s" subsys=daemon level=info msg="Start hook executed" duration=103.400395ms function="node.NewLocalNodeStore.func1 (local_node_store.go:76)" subsys=hive level=info msg="Start hook executed" duration="15.889µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration=101.261532ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Service].Start" subsys=hive level=info msg="Start hook executed" duration="3.63µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Using discoveryv1.EndpointSlice" subsys=k8s level=info msg="Start hook executed" duration=100.300244ms function="*manager.diffStore[*github.com/cilium/cilium/pkg/k8s.Endpoints].Start" subsys=hive level=info msg="Start hook executed" duration="5.49µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Pod].Start" subsys=hive level=info msg="Start hook executed" duration="1.98µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/slim/k8s/api/core/v1.Namespace].Start" subsys=hive level=info msg="Start hook executed" duration="3.34µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="1.67µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2.CiliumClusterwideNetworkPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="1.64µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumCIDRGroup].Start" subsys=hive level=info msg="Start hook executed" duration="25.269µs" function="endpointmanager.newDefaultEndpointManager.func1 (cell.go:203)" subsys=hive level=info msg="Start hook executed" duration="17.56µs" function="cmd.newPolicyTrifecta.func1 (policy.go:135)" subsys=hive level=info msg="Start hook executed" duration="86.047µs" function="*manager.manager.Start" subsys=hive level=info msg="Serving cilium node monitor v1.2 API at unix:///var/run/cilium/monitor1_2.sock" subsys=monitor-agent level=info msg="Start hook executed" duration="388.706µs" function="agent.newMonitorAgent.func1 (cell.go:61)" subsys=hive level=info msg="Start hook executed" duration="2.71µs" function="*resource.resource[*github.com/cilium/cilium/pkg/k8s/apis/cilium.io/v2alpha1.CiliumL2AnnouncementPolicy].Start" subsys=hive level=info msg="Start hook executed" duration="8.22µs" function="*job.group.Start" subsys=hive level=info msg="Start hook executed" duration="318.619µs" function="proxy.newProxy.func1 (cell.go:55)" subsys=hive level=info msg="Envoy: Starting xDS gRPC server listening on /var/run/cilium/envoy/sockets/xds.sock" subsys=envoy-manager level=info msg="Start hook executed" duration="433.305µs" function="signal.provideSignalManager.func1 (cell.go:25)" subsys=hive level=info msg="Datapath signal listener running" subsys=signal level=info msg="Start hook executed" duration=1.242696ms function="auth.registerAuthManager.func1 (cell.go:109)" subsys=hive level=info msg="Start hook executed" duration="4.06µs" function="auth.registerGCJobs.func1 (cell.go:158)" subsys=hive level=info msg="Start hook executed" duration="24.639µs" function="*job.group.Start" subsys=hive level=warning msg="Deprecated value for --kube-proxy-replacement: disabled (use either \"true\", or \"false\")" subsys=daemon level=info msg="Auto-disabling \"enable-node-port\", \"enable-external-ips\", \"bpf-lb-sock\", \"enable-host-port\" features and falling back to \"enable-host-legacy-routing\"" subsys=daemon level=info msg="Inheriting MTU from external network interface" device=ens3 ipAddr=199.19.213.43 mtu=1500 subsys=mtu level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_ipcache, recreating and re-pinning map cilium_ipcache" file-path=/sys/fs/bpf/tc/globals/cilium_ipcache name=cilium_ipcache subsys=bpf level=info msg="Removed map pin at /sys/fs/bpf/tc/globals/cilium_tunnel_map, recreating and re-pinning map cilium_tunnel_map" file-path=/sys/fs/bpf/tc/globals/cilium_tunnel_map name=cilium_tunnel_map subsys=bpf level=info msg="Restored services from maps" failedServices=0 restoredServices=0 subsys=service level=info msg="Restored backends from maps" failedBackends=0 restoredBackends=0 skippedBackends=0 subsys=service level=info msg="Reading old endpoints..." subsys=daemon level=info msg="No old endpoints found." subsys=daemon level=info msg="Waiting until all Cilium CRDs are available" subsys=k8s level=info msg="All Cilium CRDs have been found and are available" subsys=k8s level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=warning msg="Unable to get node resource" error="ciliumnodes.cilium.io \"instance\" not found" subsys=nodediscovery level=info msg="Successfully created CiliumNode resource" subsys=nodediscovery level=warning msg="Unable to create CiliumNode resource, will retry" error="ciliumnodes.cilium.io \"instance\" already exists" subsys=nodediscovery level=info msg="Retrieved node information from cilium node" nodeName=instance subsys=k8s level=warning msg="Waiting for k8s node information" error="required IPv4 PodCIDR not available" subsys=k8s level=info msg="Retrieved node information from cilium node" nodeName=instance subsys=k8s level=info msg="Received own node information from API server" ipAddr.ipv4=199.19.213.43 ipAddr.ipv6="" k8sNodeIP=199.19.213.43 labels="map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:]" nodeName=instance subsys=k8s v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="k8s mode: Allowing localhost to reach local endpoints" subsys=daemon level=info msg="Detected devices" devices="[]" subsys=linux-datapath level=info msg="Enabling k8s event listener" subsys=k8s-watcher level=info msg="Removing stale endpoint interfaces" subsys=daemon level=info msg="Skipping kvstore configuration" subsys=daemon level=info msg="Waiting until local node addressing before starting watchers depending on it" subsys=k8s-watcher level=info msg="Initializing node addressing" subsys=daemon level=info msg="Initializing cluster-pool IPAM" subsys=ipam v4Prefix=10.0.0.0/24 v6Prefix="" level=info msg="Restoring endpoints..." subsys=daemon level=info msg="Endpoints restored" failed=0 restored=0 subsys=daemon level=info msg="Addressing information:" subsys=daemon level=info msg=" Cluster-Name: default" subsys=daemon level=info msg=" Cluster-ID: 0" subsys=daemon level=info msg=" Local node-name: instance" subsys=daemon level=info msg=" Node-IPv6: " subsys=daemon level=info msg=" External-Node IPv4: 199.19.213.43" subsys=daemon level=info msg=" Internal-Node IPv4: 10.0.0.35" subsys=daemon level=info msg=" IPv4 allocation prefix: 10.0.0.0/24" subsys=daemon level=info msg=" Loopback IPv4: 169.254.42.1" subsys=daemon level=info msg=" Local IPv4 addresses:" subsys=daemon level=info msg=" - 199.19.213.43" subsys=daemon level=info msg=" - 172.17.0.100" subsys=daemon level=info msg="Node updated" clusterName=default nodeName=instance subsys=nodemanager level=info msg="Adding local node to cluster" node="{instance default [{InternalIP 199.19.213.43} {CiliumInternalIP 10.0.0.35}] 10.0.0.0/24 [] [] 10.0.0.187 0 local 0 map[beta.kubernetes.io/arch:amd64 beta.kubernetes.io/os:linux kubernetes.io/arch:amd64 kubernetes.io/hostname:instance kubernetes.io/os:linux node-role.kubernetes.io/control-plane: node.kubernetes.io/exclude-from-external-load-balancers:] map[] 1 }" subsys=nodediscovery level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Waiting until all pre-existing resources have been received" subsys=k8s-watcher level=info msg="Initializing identity allocator" subsys=identity-cache level=info msg="Allocating identities between range" cluster-id=0 max=65535 min=256 subsys=identity-cache level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_host.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.forwarding sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.accept_local sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.cilium_net.send_redirects sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.core.bpf_jit_enable sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.conf.all.rp_filter sysParamValue=0 level=info msg="Setting sysctl" subsys=sysctl sysParamName=net.ipv4.fib_multipath_use_neigh sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.unprivileged_bpf_disabled sysParamValue=1 level=info msg="Setting sysctl" subsys=sysctl sysParamName=kernel.timer_migration sysParamValue=0 level=info msg="Setting up BPF datapath" bpfClockSource=ktime bpfInsnSet="" subsys=datapath-loader level=info msg="Iptables rules installed" subsys=iptables level=info msg="Adding new proxy port rules for cilium-dns-egress:44223" id=cilium-dns-egress subsys=proxy level=info msg="Iptables proxy rules installed" subsys=iptables level=info msg="Start hook executed" duration=2.317980475s function="cmd.newDaemonPromise.func1 (daemon_main.go:1663)" subsys=hive level=info msg="Initializing daemon" subsys=daemon level=info msg="Validating configured node address ranges" subsys=daemon level=info msg="Starting connection tracking garbage collector" subsys=daemon level=info msg="Start hook executed" duration="50.278µs" function="utime.initUtimeSync.func1 (cell.go:33)" subsys=hive level=info msg="Start hook executed" duration="11.16µs" function="*job.group.Start" subsys=hive level=info msg="Starting IP identity watcher" subsys=ipcache level=info msg="Start hook executed" duration="234.322µs" function="l2respondermap.newMap.func1 (l2_responder_map4.go:44)" subsys=hive level=info msg="Start hook executed" duration="35.089µs" function="*job.group.Start" subsys=hive level=info msg="Initial scan of connection tracking completed" subsys=ct-gc level=info msg="Regenerating restored endpoints" numRestored=0 subsys=daemon level=info msg="Creating host endpoint" subsys=daemon level=info msg="Finished regenerating restored endpoints" regenerated=0 subsys=daemon total=0 level=info msg="Deleted orphan backends" orphanBackends=0 subsys=service level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1083 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1083 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1083 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,reserved:host" ipv4= ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="Launching Cilium health daemon" subsys=daemon level=info msg="Launching Cilium health endpoint" subsys=daemon level=info msg="Started healthz status API server" address="127.0.0.1:9879" subsys=daemon level=info msg="Processing queued endpoint deletion requests from /var/run/cilium/deleteQueue" subsys=daemon level=info msg="processing 0 queued deletion requests" subsys=daemon level=info msg="Initializing Cilium API" subsys=daemon level=info msg="Daemon initialization completed" bootstrapTime=3.251813784s subsys=daemon level=info msg="Hubble server is disabled" subsys=hubble level=info msg="Serving cilium API at unix:///var/run/cilium/cilium.sock" subsys=daemon level=info msg="Compiled new BPF template" BPFCompilationTime=300.628037ms file-path=/var/run/cilium/state/templates/c9fe201a1e880a945531579b14b795c9618d4147502fa354b01386f4e2ab925b/bpf_host.o subsys=datapath-loader level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1083 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.39 6363cd1b-2318-4f13-8d6c-b8d0fe98a117 default }" containerID=022dd0ced15c91e1cfce8664eb580ab83da4aa29a581737862104e47682ed675 datapathConfiguration="&{false false false false false }" interface=lxc8b073fb50930 k8sPodName=kube-system/coredns-7c96b6546b-6zc59 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=022dd0ced1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=608 ipv4=10.0.0.39 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-6zc59 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=022dd0ced1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=608 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.39 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-6zc59 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:kube-system]" subsys=crd-allocator level=info msg="Create endpoint request" addressing="&{10.0.0.123 b8a611fc-e803-4d39-91b5-c3350dd708f4 default }" containerID=470a28839c57056f40d9cb6895368f70068c779c522003f7683b1fef0d72d8c2 datapathConfiguration="&{false false false false false }" interface=lxc1ddefafa145d k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-cd2mm labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=470a28839c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1115 ipv4=10.0.0.123 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-cd2mm subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=470a28839c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1115 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=84cd0a54-dd07-4e96-ac69-ce9b1e057e91,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=84cd0a54-dd07-4e96-ac69-ce9b1e057e91,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.123 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-cd2mm subsys=endpoint level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=coredns;k8s:io.kubernetes.pod.namespace=kube-system;k8s:k8s-app=kube-dns;" subsys=allocator level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="Identity of endpoint changed" containerID=022dd0ced1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=608 identity=9105 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.39 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-6zc59 oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=470a28839c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1115 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.123 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-cd2mm line=611 subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=022dd0ced1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=608 identity=9105 ipv4=10.0.0.39 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-6zc59 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=certgen;k8s:batch.kubernetes.io/controller-uid=84cd0a54-dd07-4e96-ac69-ce9b1e057e91;k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen;k8s:controller-uid=84cd0a54-dd07-4e96-ac69-ce9b1e057e91;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;k8s:job-name=envoy-gateway-gateway-helm-certgen;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=470a28839c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1115 identity=4308 identityLabels="k8s:app=certgen,k8s:batch.kubernetes.io/controller-uid=84cd0a54-dd07-4e96-ac69-ce9b1e057e91,k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen,k8s:controller-uid=84cd0a54-dd07-4e96-ac69-ce9b1e057e91,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen,k8s:io.kubernetes.pod.namespace=envoy-gateway-system,k8s:job-name=envoy-gateway-gateway-helm-certgen" ipv4=10.0.0.123 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-cd2mm oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=470a28839c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1115 identity=4308 ipv4=10.0.0.123 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-cd2mm subsys=endpoint level=info msg="New endpoint" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1108 ipv4=10.0.0.187 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1108 identityLabels="reserved:health" ipv4=10.0.0.187 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Identity of endpoint changed" containerID= datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1108 identity=4 identityLabels="reserved:health" ipv4=10.0.0.187 ipv6= k8sPodName=/ oldIdentity="no identity" subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Compiled new BPF template" BPFCompilationTime=1.071882667s file-path=/var/run/cilium/state/templates/e54cda105e9c183b36a228c09dfea4d8e1c6cd928a332842dc9d3a82f9c2abc0/bpf_lxc.o subsys=datapath-loader level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1108 identity=4 ipv4=10.0.0.187 ipv6= k8sPodName=/ subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=022dd0ced1 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=608 identity=9105 ipv4=10.0.0.39 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-6zc59 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=470a28839c datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1115 identity=4308 ipv4=10.0.0.123 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-cd2mm subsys=endpoint level=info msg="Successful endpoint creation" containerID=022dd0ced1 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=608 identity=9105 ipv4=10.0.0.39 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-6zc59 subsys=daemon level=info msg="Successful endpoint creation" containerID=470a28839c datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1115 identity=4308 ipv4=10.0.0.123 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-cd2mm subsys=daemon level=info msg="Serving cilium health API at unix:///var/run/cilium/health.sock" subsys=health-server level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=470a28839c endpointID=1115 k8sNamespace=envoy-gateway-system k8sPodName=envoy-gateway-gateway-helm-certgen-cd2mm subsys=daemon level=info msg="Releasing key" key="[k8s:app=certgen k8s:batch.kubernetes.io/controller-uid=84cd0a54-dd07-4e96-ac69-ce9b1e057e91 k8s:batch.kubernetes.io/job-name=envoy-gateway-gateway-helm-certgen k8s:controller-uid=84cd0a54-dd07-4e96-ac69-ce9b1e057e91 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway-gateway-helm-certgen k8s:io.kubernetes.pod.namespace=envoy-gateway-system k8s:job-name=envoy-gateway-gateway-helm-certgen]" subsys=allocator level=info msg="Removed endpoint" containerID=470a28839c datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1115 identity=4308 ipv4=10.0.0.123 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-gateway-helm-certgen-cd2mm subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.85 d34d9962-3153-4c84-81cc-e4aceccf90c5 default }" containerID=3344245df754e7f8aa02847e6873d4dcf1519288945a6b3c17490b5df39f388a datapathConfiguration="&{false false false false false }" interface=lxce74816e29364 k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-gsx6r labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=3344245df7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=47 ipv4=10.0.0.85 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-gsx6r subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=3344245df7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=47 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.85 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-gsx6r subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:envoy-gateway-system k8s:io.cilium.k8s.namespace.labels.name:envoy-gateway-system]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=3344245df7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=47 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.85 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-gsx6r line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=envoy-gateway;k8s:app.kubernetes.io/name=gateway-helm;k8s:control-plane=envoy-gateway;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system;k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway;k8s:io.kubernetes.pod.namespace=envoy-gateway-system;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=3344245df7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=47 identity=5061 identityLabels="k8s:app.kubernetes.io/instance=envoy-gateway,k8s:app.kubernetes.io/name=gateway-helm,k8s:control-plane=envoy-gateway,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=envoy-gateway-system,k8s:io.cilium.k8s.namespace.labels.name=envoy-gateway-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=envoy-gateway,k8s:io.kubernetes.pod.namespace=envoy-gateway-system" ipv4=10.0.0.85 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-gsx6r oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=3344245df7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=47 identity=5061 ipv4=10.0.0.85 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-gsx6r subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=3344245df7 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=47 identity=5061 ipv4=10.0.0.85 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-gsx6r subsys=endpoint level=info msg="Successful endpoint creation" containerID=3344245df7 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=47 identity=5061 ipv4=10.0.0.85 ipv6= k8sPodName=envoy-gateway-system/envoy-gateway-78446f96c9-gsx6r subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Resolving identity labels (blocking)" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1083 identity=1 identityLabels="k8s:node-role.kubernetes.io/control-plane,k8s:node.kubernetes.io/exclude-from-external-load-balancers,k8s:openstack-compute-node=enabled,k8s:openstack-control-plane=enabled,k8s:openvswitch=enabled,reserved:host" ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Creating or updating CiliumNode resource" node=instance subsys=nodediscovery level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_hostns_01083 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_hostns_01083 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_hostns_01083 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_hostns_01083:pending" subsys=bpf level=info msg="Re-pinning map with ':pending' suffix" bpfMapName=cilium_calls_netdev_00003 bpfMapPath=/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003 subsys=bpf level=info msg="Unpinning map after successful recreation" bpfMapName=cilium_calls_netdev_00003 bpfMapPath="/sys/fs/bpf/tc/globals/cilium_calls_netdev_00003:pending" subsys=bpf level=info msg="Rewrote endpoint BPF program" containerID= datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1083 identity=1 ipv4= ipv6= k8sPodName=/ subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.179 3e468e45-1c97-4732-8cb5-911e7e683197 default }" containerID=b70a34733e5f4f822ecd71e2367436e72f7f089e992379147ea479e1bc61fda3 datapathConfiguration="&{false false false false false }" interface=lxcdde5270fd773 k8sPodName=kube-system/coredns-67659f764b-slmq5 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b70a34733e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=726 ipv4=10.0.0.179 ipv6= k8sPodName=kube-system/coredns-67659f764b-slmq5 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b70a34733e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=726 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.179 ipv6= k8sPodName=kube-system/coredns-67659f764b-slmq5 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=b70a34733e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=726 identity=9105 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.179 ipv6= k8sPodName=kube-system/coredns-67659f764b-slmq5 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b70a34733e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=726 identity=9105 ipv4=10.0.0.179 ipv6= k8sPodName=kube-system/coredns-67659f764b-slmq5 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=b70a34733e datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=726 identity=9105 ipv4=10.0.0.179 ipv6= k8sPodName=kube-system/coredns-67659f764b-slmq5 subsys=endpoint level=info msg="Successful endpoint creation" containerID=b70a34733e datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=726 identity=9105 ipv4=10.0.0.179 ipv6= k8sPodName=kube-system/coredns-67659f764b-slmq5 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.160 91fc1a35-e6a2-4566-b415-e8ce821f20dd default }" containerID=1e012abb54dc3fac43d292e223294e34e1ead516eb78f13928c1d23409738cdb datapathConfiguration="&{false false false false false }" interface=lxc749e68122b13 k8sPodName=kube-system/coredns-67659f764b-mlzvb labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=1e012abb54 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=255 ipv4=10.0.0.160 ipv6= k8sPodName=kube-system/coredns-67659f764b-mlzvb subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=1e012abb54 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=255 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.160 ipv6= k8sPodName=kube-system/coredns-67659f764b-mlzvb subsys=endpoint level=info msg="Identity of endpoint changed" containerID=1e012abb54 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=255 identity=9105 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=coredns,k8s:io.kubernetes.pod.namespace=kube-system,k8s:k8s-app=kube-dns" ipv4=10.0.0.160 ipv6= k8sPodName=kube-system/coredns-67659f764b-mlzvb oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=1e012abb54 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=255 identity=9105 ipv4=10.0.0.160 ipv6= k8sPodName=kube-system/coredns-67659f764b-mlzvb subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=1e012abb54 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=255 identity=9105 ipv4=10.0.0.160 ipv6= k8sPodName=kube-system/coredns-67659f764b-mlzvb subsys=endpoint level=info msg="Successful endpoint creation" containerID=1e012abb54 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=255 identity=9105 ipv4=10.0.0.160 ipv6= k8sPodName=kube-system/coredns-67659f764b-mlzvb subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.169 7a9028b1-3c63-47f0-af1f-f480a7953a5d default }" containerID=1aab1924cf62995e0e46776181641fe73cb1f3b1d7fb9e277c599b21ce474244 datapathConfiguration="&{false false false false false }" interface=lxc96b3359e629b k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wp6lr labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=1aab1924cf datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=513 ipv4=10.0.0.169 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wp6lr subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=1aab1924cf datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=513 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.169 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wp6lr subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=local-path-provisioner;k8s:app.kubernetes.io/name=local-path-provisioner;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=1aab1924cf datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=513 identity=61396 identityLabels="k8s:app.kubernetes.io/instance=local-path-provisioner,k8s:app.kubernetes.io/name=local-path-provisioner,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.169 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wp6lr oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=1aab1924cf datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=513 identity=61396 ipv4=10.0.0.169 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wp6lr subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=1aab1924cf datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=513 identity=61396 ipv4=10.0.0.169 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wp6lr subsys=endpoint level=info msg="Successful endpoint creation" containerID=1aab1924cf datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=513 identity=61396 ipv4=10.0.0.169 ipv6= k8sPodName=local-path-storage/local-path-provisioner-679c578f5-wp6lr subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=022dd0ced1 endpointID=608 k8sNamespace=kube-system k8sPodName=coredns-7c96b6546b-6zc59 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=kube-system k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=coredns k8s:io.kubernetes.pod.namespace=kube-system k8s:k8s-app=kube-dns]" subsys=allocator level=info msg="Removed endpoint" containerID=022dd0ced1 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=608 identity=9105 ipv4=10.0.0.39 ipv6= k8sPodName=kube-system/coredns-7c96b6546b-6zc59 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.32 07b7e2a2-63e2-4464-bd1e-8594140c57de default }" containerID=c88e3d0d1e52ca8260832b38899e38ddb577a0b80f5ca85219a35d308fa165ad datapathConfiguration="&{false false false false false }" interface=lxc51c7c3c66f69 k8sPodName=cert-manager/cert-manager-75c4c745bc-dzmbd labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c88e3d0d1e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1143 ipv4=10.0.0.32 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-dzmbd subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c88e3d0d1e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1143 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.32 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-dzmbd subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=cert-manager;k8s:app.kubernetes.io/component=controller;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cert-manager;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=c88e3d0d1e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1143 identity=19585 identityLabels="k8s:app.kubernetes.io/component=controller,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cert-manager,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cert-manager,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.32 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-dzmbd oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c88e3d0d1e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1143 identity=19585 ipv4=10.0.0.32 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-dzmbd subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.168 8bd5ae96-bc70-48ac-adc3-2611db08b070 default }" containerID=b3f18ecb5bf3735c800ca520fb4dcea95d5d4e01d48d89399e8adb43dd262058 datapathConfiguration="&{false false false false false }" interface=lxc904212e9ac00 k8sPodName=cert-manager/cert-manager-webhook-548949fc64-w2qdc labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b3f18ecb5b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=628 ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-w2qdc subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b3f18ecb5b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=628 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-w2qdc subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Create endpoint request" addressing="&{10.0.0.100 22b27cde-9aba-4898-9f96-f69a88863113 default }" containerID=643f49d58324a24eac0f61b3792e9dadce3acaa0fb9a18ddc029768dea21e1f9 datapathConfiguration="&{false false false false false }" interface=lxc1fe197135fac k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-2l494 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=643f49d583 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=314 ipv4=10.0.0.100 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-2l494 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=643f49d583 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=314 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.100 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-2l494 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=webhook;k8s:app.kubernetes.io/component=webhook;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=webhook;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=b3f18ecb5b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=628 identity=44234 identityLabels="k8s:app.kubernetes.io/component=webhook,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=webhook,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=webhook,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-webhook,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-w2qdc oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b3f18ecb5b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=628 identity=44234 ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-w2qdc subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=cainjector;k8s:app.kubernetes.io/component=cainjector;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=cainjector;k8s:app.kubernetes.io/version=v1.11.5;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector;k8s:io.kubernetes.pod.namespace=cert-manager;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=643f49d583 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=314 identity=3776 identityLabels="k8s:app.kubernetes.io/component=cainjector,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=cainjector,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=cainjector,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-cainjector,k8s:io.kubernetes.pod.namespace=cert-manager" ipv4=10.0.0.100 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-2l494 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=643f49d583 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=314 identity=3776 ipv4=10.0.0.100 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-2l494 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=c88e3d0d1e datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1143 identity=19585 ipv4=10.0.0.32 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-dzmbd subsys=endpoint level=info msg="Successful endpoint creation" containerID=c88e3d0d1e datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1143 identity=19585 ipv4=10.0.0.32 ipv6= k8sPodName=cert-manager/cert-manager-75c4c745bc-dzmbd subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=b3f18ecb5b datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=628 identity=44234 ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-w2qdc subsys=endpoint level=info msg="Successful endpoint creation" containerID=b3f18ecb5b datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=628 identity=44234 ipv4=10.0.0.168 ipv6= k8sPodName=cert-manager/cert-manager-webhook-548949fc64-w2qdc subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=643f49d583 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=314 identity=3776 ipv4=10.0.0.100 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-2l494 subsys=endpoint level=info msg="Successful endpoint creation" containerID=643f49d583 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=314 identity=3776 ipv4=10.0.0.100 ipv6= k8sPodName=cert-manager/cert-manager-cainjector-64b59ddb75-2l494 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.121 fd40b585-87be-46ab-9717-ee4d39c070e6 default }" containerID=754f74fa6973ba4e965f2042478748a22bf19191a79e65453ffe64aadfeddd55 datapathConfiguration="&{false false false false false }" interface=lxc08808aae9e8e k8sPodName=cert-manager/cert-manager-startupapicheck-l8gjv labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=754f74fa69 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1092 ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-l8gjv subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=754f74fa69 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1092 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=556fbc11-299b-4e8f-8e19-fc14b5100464,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=556fbc11-299b-4e8f-8e19-fc14b5100464,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-l8gjv subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:cert-manager k8s:io.cilium.k8s.namespace.labels.name:cert-manager]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=startupapicheck;k8s:app.kubernetes.io/component=startupapicheck;k8s:app.kubernetes.io/instance=cert-manager;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=startupapicheck;k8s:app.kubernetes.io/version=v1.11.5;k8s:batch.kubernetes.io/controller-uid=556fbc11-299b-4e8f-8e19-fc14b5100464;k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck;k8s:controller-uid=556fbc11-299b-4e8f-8e19-fc14b5100464;k8s:helm.sh/chart=cert-manager-v1.11.5;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager;k8s:io.cilium.k8s.namespace.labels.name=cert-manager;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck;k8s:io.kubernetes.pod.namespace=cert-manager;k8s:job-name=cert-manager-startupapicheck;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=754f74fa69 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1092 identity=24964 identityLabels="k8s:app.kubernetes.io/component=startupapicheck,k8s:app.kubernetes.io/instance=cert-manager,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=startupapicheck,k8s:app.kubernetes.io/version=v1.11.5,k8s:app=startupapicheck,k8s:batch.kubernetes.io/controller-uid=556fbc11-299b-4e8f-8e19-fc14b5100464,k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck,k8s:controller-uid=556fbc11-299b-4e8f-8e19-fc14b5100464,k8s:helm.sh/chart=cert-manager-v1.11.5,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager,k8s:io.cilium.k8s.namespace.labels.name=cert-manager,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck,k8s:io.kubernetes.pod.namespace=cert-manager,k8s:job-name=cert-manager-startupapicheck" ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-l8gjv oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=754f74fa69 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1092 identity=24964 ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-l8gjv subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=754f74fa69 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=1092 identity=24964 ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-l8gjv subsys=endpoint level=info msg="Successful endpoint creation" containerID=754f74fa69 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1092 identity=24964 ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-l8gjv subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=754f74fa69 endpointID=1092 k8sNamespace=cert-manager k8sPodName=cert-manager-startupapicheck-l8gjv subsys=daemon level=info msg="Releasing key" key="[k8s:app=startupapicheck k8s:app.kubernetes.io/component=startupapicheck k8s:app.kubernetes.io/instance=cert-manager k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=startupapicheck k8s:app.kubernetes.io/version=v1.11.5 k8s:batch.kubernetes.io/controller-uid=556fbc11-299b-4e8f-8e19-fc14b5100464 k8s:batch.kubernetes.io/job-name=cert-manager-startupapicheck k8s:controller-uid=556fbc11-299b-4e8f-8e19-fc14b5100464 k8s:helm.sh/chart=cert-manager-v1.11.5 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=cert-manager k8s:io.cilium.k8s.namespace.labels.name=cert-manager k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=cert-manager-startupapicheck k8s:io.kubernetes.pod.namespace=cert-manager k8s:job-name=cert-manager-startupapicheck]" subsys=allocator level=info msg="Removed endpoint" containerID=754f74fa69 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=1092 identity=24964 ipv4=10.0.0.121 ipv6= k8sPodName=cert-manager/cert-manager-startupapicheck-l8gjv subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.47 972439f8-87ca-4dce-af30-2214bdcc5ff4 default }" containerID=79cf8c49a7eb43372ed156d4f86ab83ea791bea8874937ac4486b688f2772a85 datapathConfiguration="&{false false false false false }" interface=lxc61b7da0a5ff7 k8sPodName=ingress-nginx/ingress-nginx-admission-create-qts67 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=79cf8c49a7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=481 ipv4=10.0.0.47 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-qts67 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=79cf8c49a7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=481 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=7cc86fc2-2948-47af-8e5e-830c04304645,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=7cc86fc2-2948-47af-8e5e-830c04304645,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.47 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-qts67 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=79cf8c49a7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=481 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.47 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-qts67 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=7cc86fc2-2948-47af-8e5e-830c04304645;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create;k8s:controller-uid=7cc86fc2-2948-47af-8e5e-830c04304645;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-create;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=79cf8c49a7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=481 identity=40056 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=7cc86fc2-2948-47af-8e5e-830c04304645,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create,k8s:controller-uid=7cc86fc2-2948-47af-8e5e-830c04304645,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-create" ipv4=10.0.0.47 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-qts67 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=79cf8c49a7 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=481 identity=40056 ipv4=10.0.0.47 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-qts67 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=79cf8c49a7 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=481 identity=40056 ipv4=10.0.0.47 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-qts67 subsys=endpoint level=info msg="Successful endpoint creation" containerID=79cf8c49a7 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=481 identity=40056 ipv4=10.0.0.47 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-qts67 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=79cf8c49a7 endpointID=481 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-create-qts67 subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=7cc86fc2-2948-47af-8e5e-830c04304645 k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-create k8s:controller-uid=7cc86fc2-2948-47af-8e5e-830c04304645 k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-create]" subsys=allocator level=info msg="Removed endpoint" containerID=79cf8c49a7 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=481 identity=40056 ipv4=10.0.0.47 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-create-qts67 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.23 e95ad22f-a719-4895-8bdd-9640ef5b5b05 default }" containerID=3a252bf12958ddc0380a88e406b362337f4abc70fb818271eb03c7b0a396ccb6 datapathConfiguration="&{false false false false false }" interface=lxc67e1f2ee43ae k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-p8khj labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=3a252bf129 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2387 ipv4=10.0.0.23 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-p8khj subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=3a252bf129 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2387 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.23 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-p8khj subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=3a252bf129 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2387 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.23 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-p8khj line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=default-backend;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend;k8s:io.kubernetes.pod.namespace=ingress-nginx;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=3a252bf129 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2387 identity=65431 identityLabels="k8s:app.kubernetes.io/component=default-backend,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-backend,k8s:io.kubernetes.pod.namespace=ingress-nginx" ipv4=10.0.0.23 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-p8khj oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=3a252bf129 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2387 identity=65431 ipv4=10.0.0.23 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-p8khj subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=3a252bf129 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2387 identity=65431 ipv4=10.0.0.23 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-p8khj subsys=endpoint level=info msg="Successful endpoint creation" containerID=3a252bf129 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2387 identity=65431 ipv4=10.0.0.23 ipv6= k8sPodName=ingress-nginx/ingress-nginx-defaultbackend-6987ff55cf-p8khj subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.148 e2d4b56d-6b05-48c9-bcbb-732192ad6ba1 default }" containerID=8d16caf10364e44f82833766f8b0a6d2edab840189e72c8e12d1c1c41eb0b660 datapathConfiguration="&{false false false false false }" interface=lxc57a4be87dd61 k8sPodName=ingress-nginx/ingress-nginx-admission-patch-mzrbm labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=8d16caf103 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2916 ipv4=10.0.0.148 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-mzrbm subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=8d16caf103 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2916 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=8fea1bd6-f1dd-499d-b0aa-fbadd7539a8e,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=8fea1bd6-f1dd-499d-b0aa-fbadd7539a8e,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.148 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-mzrbm subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:ingress-nginx k8s:io.cilium.k8s.namespace.labels.name:ingress-nginx]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=admission-webhook;k8s:app.kubernetes.io/instance=ingress-nginx;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=ingress-nginx;k8s:app.kubernetes.io/part-of=ingress-nginx;k8s:app.kubernetes.io/version=1.12.1;k8s:batch.kubernetes.io/controller-uid=8fea1bd6-f1dd-499d-b0aa-fbadd7539a8e;k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch;k8s:controller-uid=8fea1bd6-f1dd-499d-b0aa-fbadd7539a8e;k8s:helm.sh/chart=ingress-nginx-4.12.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx;k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission;k8s:io.kubernetes.pod.namespace=ingress-nginx;k8s:job-name=ingress-nginx-admission-patch;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=8d16caf103 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2916 identity=4631 identityLabels="k8s:app.kubernetes.io/component=admission-webhook,k8s:app.kubernetes.io/instance=ingress-nginx,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=ingress-nginx,k8s:app.kubernetes.io/part-of=ingress-nginx,k8s:app.kubernetes.io/version=1.12.1,k8s:batch.kubernetes.io/controller-uid=8fea1bd6-f1dd-499d-b0aa-fbadd7539a8e,k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch,k8s:controller-uid=8fea1bd6-f1dd-499d-b0aa-fbadd7539a8e,k8s:helm.sh/chart=ingress-nginx-4.12.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx,k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission,k8s:io.kubernetes.pod.namespace=ingress-nginx,k8s:job-name=ingress-nginx-admission-patch" ipv4=10.0.0.148 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-mzrbm oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=8d16caf103 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2916 identity=4631 ipv4=10.0.0.148 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-mzrbm subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=8d16caf103 datapathPolicyRevision=0 desiredPolicyRevision=1 endpointID=2916 identity=4631 ipv4=10.0.0.148 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-mzrbm subsys=endpoint level=info msg="Successful endpoint creation" containerID=8d16caf103 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2916 identity=4631 ipv4=10.0.0.148 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-mzrbm subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=8d16caf103 endpointID=2916 k8sNamespace=ingress-nginx k8sPodName=ingress-nginx-admission-patch-mzrbm subsys=daemon level=info msg="Releasing key" key="[k8s:app.kubernetes.io/component=admission-webhook k8s:app.kubernetes.io/instance=ingress-nginx k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=ingress-nginx k8s:app.kubernetes.io/part-of=ingress-nginx k8s:app.kubernetes.io/version=1.12.1 k8s:batch.kubernetes.io/controller-uid=8fea1bd6-f1dd-499d-b0aa-fbadd7539a8e k8s:batch.kubernetes.io/job-name=ingress-nginx-admission-patch k8s:controller-uid=8fea1bd6-f1dd-499d-b0aa-fbadd7539a8e k8s:helm.sh/chart=ingress-nginx-4.12.1 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=ingress-nginx k8s:io.cilium.k8s.namespace.labels.name=ingress-nginx k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=ingress-nginx-admission k8s:io.kubernetes.pod.namespace=ingress-nginx k8s:job-name=ingress-nginx-admission-patch]" subsys=allocator level=info msg="Removed endpoint" containerID=8d16caf103 datapathPolicyRevision=1 desiredPolicyRevision=1 endpointID=2916 identity=4631 ipv4=10.0.0.148 ipv6= k8sPodName=ingress-nginx/ingress-nginx-admission-patch-mzrbm subsys=endpoint level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"messaging-topology-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:9443 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-messaging-topology-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=693a04d3-3672-4354-988e-e11b67f93cfd] Description:}]" policyAddRequest=301e3c06-fe68-4814-832e-435a8d40ab52 subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=301e3c06-fe68-4814-832e-435a8d40ab52 policyRevision=2 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-messaging-topology-operator subsys=k8s-watcher level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"rabbitmq-operator\",\"k8s:app.kubernetes.io/instance\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/name\":\"rabbitmq-cluster-operator\",\"k8s:app.kubernetes.io/part-of\":\"rabbitmq\",\"k8s:io.kubernetes.pod.namespace\":\"openstack\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=rabbitmq-cluster-operator k8s:io.cilium.k8s.policy.namespace=openstack k8s:io.cilium.k8s.policy.uid=3d756fff-39d2-408c-bfb8-0937b215d786] Description:}]" policyAddRequest=b913ac74-8e5e-47bb-b873-8bec41e722bc subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=rabbitmq-cluster-operator subsys=k8s-watcher level=info msg="Policy imported via API, recalculating..." policyAddRequest=b913ac74-8e5e-47bb-b873-8bec41e722bc policyRevision=3 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.101 c12d2df4-18ff-48d8-aa1b-a185f202a3c9 default }" containerID=75113670be5cc29846804262f4c765c0f4fddbeef15bfc9f3cafe48b08e66162 datapathConfiguration="&{false false false false false }" interface=lxc8a4873377899 k8sPodName=openstack/rabbitmq-cluster-operator-67fdb85b4f-lf25z labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=75113670be datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=321 ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-67fdb85b4f-lf25z subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=75113670be datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=321 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.8.0,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.2.4,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-67fdb85b4f-lf25z subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=2.8.0;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.2.4;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=75113670be datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=321 identity=43542 identityLabels="k8s:app.kubernetes.io/component=rabbitmq-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=2.8.0,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.2.4,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-cluster-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-67fdb85b4f-lf25z oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=75113670be datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=321 identity=43542 ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-67fdb85b4f-lf25z subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=75113670be datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=321 identity=43542 ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-67fdb85b4f-lf25z subsys=endpoint level=info msg="Successful endpoint creation" containerID=75113670be datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=321 identity=43542 ipv4=10.0.0.101 ipv6= k8sPodName=openstack/rabbitmq-cluster-operator-67fdb85b4f-lf25z subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.184 eb4532be-bb2c-4bce-989d-a9cabe1744f2 default }" containerID=7de64bce8dd9e366f5bc82c31eebca5ffb9b32032c4884a36ee33701e3bcb920 datapathConfiguration="&{false false false false false }" interface=lxc5ff5edcf5e86 k8sPodName=openstack/rabbitmq-messaging-topology-operator-5c9876cc97-h48xs labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=7de64bce8d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=807 ipv4=10.0.0.184 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-5c9876cc97-h48xs subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=7de64bce8d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=807 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.13.0,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.2.4,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.184 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-5c9876cc97-h48xs subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=messaging-topology-operator;k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=rabbitmq-cluster-operator;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:app.kubernetes.io/version=1.13.0;k8s:helm.sh/chart=rabbitmq-cluster-operator-4.2.4;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=7de64bce8d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=807 identity=21664 identityLabels="k8s:app.kubernetes.io/component=messaging-topology-operator,k8s:app.kubernetes.io/instance=rabbitmq-cluster-operator,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=rabbitmq-cluster-operator,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:app.kubernetes.io/version=1.13.0,k8s:helm.sh/chart=rabbitmq-cluster-operator-4.2.4,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-messaging-topology-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.184 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-5c9876cc97-h48xs oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=7de64bce8d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=807 identity=21664 ipv4=10.0.0.184 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-5c9876cc97-h48xs subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=7de64bce8d datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=807 identity=21664 ipv4=10.0.0.184 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-5c9876cc97-h48xs subsys=endpoint level=info msg="Successful endpoint creation" containerID=7de64bce8d datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=807 identity=21664 ipv4=10.0.0.184 ipv6= k8sPodName=openstack/rabbitmq-messaging-topology-operator-5c9876cc97-h48xs subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.214 0d2cb9ec-2a03-4ca5-8718-3335623cfaac default }" containerID=ad4281d64297babf5aaf16d095d754059ea81efbf84999f4bf9fafde94ab626e datapathConfiguration="&{false false false false false }" interface=lxcb47fcb8ecc1d k8sPodName=openstack/pxc-operator-7cff949c8b-24dml labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=ad4281d642 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=808 ipv4=10.0.0.214 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-24dml subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=ad4281d642 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=808 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.214 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-24dml subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=operator;k8s:app.kubernetes.io/instance=pxc-operator;k8s:app.kubernetes.io/name=pxc-operator;k8s:app.kubernetes.io/part-of=pxc-operator;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator;k8s:io.kubernetes.pod.namespace=openstack;" subsys=allocator level=info msg="Invalid state transition skipped" containerID=ad4281d642 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=808 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.214 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-24dml line=611 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=ad4281d642 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=808 identity=16070 identityLabels="k8s:app.kubernetes.io/component=operator,k8s:app.kubernetes.io/instance=pxc-operator,k8s:app.kubernetes.io/name=pxc-operator,k8s:app.kubernetes.io/part-of=pxc-operator,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=pxc-operator,k8s:io.kubernetes.pod.namespace=openstack" ipv4=10.0.0.214 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-24dml oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=ad4281d642 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=808 identity=16070 ipv4=10.0.0.214 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-24dml subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=ad4281d642 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=808 identity=16070 ipv4=10.0.0.214 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-24dml subsys=endpoint level=info msg="Successful endpoint creation" containerID=ad4281d642 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=808 identity=16070 ipv4=10.0.0.214 ipv6= k8sPodName=openstack/pxc-operator-7cff949c8b-24dml subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.170 5c800421-192f-413e-82a3-451ba7e5ea9f default }" containerID=85e556b429dac235a052416512b3179bf888145a90925898f67371d02814f387 datapathConfiguration="&{false false false false false }" interface=lxcbdc90bf267c5 k8sPodName=local-path-storage/helper-pod-create-pvc-c8a6a40f-4a65-4932-bd53-3e158399c629 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=85e556b429 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4056 ipv4=10.0.0.170 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-c8a6a40f-4a65-4932-bd53-3e158399c629 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=85e556b429 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4056 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.170 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-c8a6a40f-4a65-4932-bd53-3e158399c629 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:local-path-storage k8s:io.cilium.k8s.namespace.labels.name:local-path-storage]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=85e556b429 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4056 identity=61599 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.170 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-c8a6a40f-4a65-4932-bd53-3e158399c629 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=85e556b429 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=4056 identity=61599 ipv4=10.0.0.170 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-c8a6a40f-4a65-4932-bd53-3e158399c629 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=85e556b429 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=4056 identity=61599 ipv4=10.0.0.170 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-c8a6a40f-4a65-4932-bd53-3e158399c629 subsys=endpoint level=info msg="Successful endpoint creation" containerID=85e556b429 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=4056 identity=61599 ipv4=10.0.0.170 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-c8a6a40f-4a65-4932-bd53-3e158399c629 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.45 dee41fbf-8199-493c-9a8d-47ecaa653bf0 default }" containerID=834b5cc382801cc6d10694640181eb80281c5b59fd153d94705ac4691432f66d datapathConfiguration="&{false false false false false }" interface=lxc15c4caae777f k8sPodName=openstack/percona-xtradb-haproxy-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=834b5cc382 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3472 ipv4=10.0.0.45 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=834b5cc382 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3472 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.45 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=haproxy;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=834b5cc382 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3472 identity=3442 identityLabels="k8s:app.kubernetes.io/component=haproxy,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-haproxy-0" ipv4=10.0.0.45 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=834b5cc382 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3472 identity=3442 ipv4=10.0.0.45 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=834b5cc382 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=3472 identity=3442 ipv4=10.0.0.45 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=834b5cc382 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=3472 identity=3442 ipv4=10.0.0.45 ipv6= k8sPodName=openstack/percona-xtradb-haproxy-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=85e556b429 endpointID=4056 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-c8a6a40f-4a65-4932-bd53-3e158399c629 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=85e556b429 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=4056 identity=61599 ipv4=10.0.0.170 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-c8a6a40f-4a65-4932-bd53-3e158399c629 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.220 d8743f35-00a7-4d18-a9ae-43a5fffe6523 default }" containerID=6d2c934db826a825598bcb6681b7324110fdee881574c43cac7280cee7772983 datapathConfiguration="&{false false false false false }" interface=lxcae4c9be5e902 k8sPodName=openstack/percona-xtradb-pxc-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=6d2c934db8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1118 ipv4=10.0.0.220 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=6d2c934db8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1118 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.220 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=6d2c934db8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1118 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.220 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=pxc;k8s:app.kubernetes.io/instance=percona-xtradb;k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator;k8s:app.kubernetes.io/name=percona-xtradb-cluster;k8s:app.kubernetes.io/part-of=percona-xtradb-cluster;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=default;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=6d2c934db8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1118 identity=7223 identityLabels="k8s:app.kubernetes.io/component=pxc,k8s:app.kubernetes.io/instance=percona-xtradb,k8s:app.kubernetes.io/managed-by=percona-xtradb-cluster-operator,k8s:app.kubernetes.io/name=percona-xtradb-cluster,k8s:app.kubernetes.io/part-of=percona-xtradb-cluster,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=default,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=percona-xtradb-pxc-0" ipv4=10.0.0.220 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=6d2c934db8 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1118 identity=7223 ipv4=10.0.0.220 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=6d2c934db8 datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=1118 identity=7223 ipv4=10.0.0.220 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=6d2c934db8 datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=1118 identity=7223 ipv4=10.0.0.220 ipv6= k8sPodName=openstack/percona-xtradb-pxc-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.98 1e42a8e2-ce4e-43b1-923b-c1d726a9347f default }" containerID=136c231f6e1b528d9302fa5e7c7aa6804f3d2c108acb526f6412513ff371891a datapathConfiguration="&{false false false false false }" interface=lxc10c3408f7078 k8sPodName=openstack/memcached-memcached-6479589586-msw85 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=136c231f6e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2326 ipv4=10.0.0.98 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-msw85 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=136c231f6e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2326 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.98 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-msw85 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=136c231f6e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2326 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.98 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-msw85 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=memcached;k8s:component=server;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=memcached;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=136c231f6e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2326 identity=20124 identityLabels="k8s:application=memcached,k8s:component=server,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=memcached-memcached,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=memcached" ipv4=10.0.0.98 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-msw85 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=136c231f6e datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2326 identity=20124 ipv4=10.0.0.98 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-msw85 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=136c231f6e datapathPolicyRevision=0 desiredPolicyRevision=3 endpointID=2326 identity=20124 ipv4=10.0.0.98 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-msw85 subsys=endpoint level=info msg="Successful endpoint creation" containerID=136c231f6e datapathPolicyRevision=3 desiredPolicyRevision=3 endpointID=2326 identity=20124 ipv4=10.0.0.98 ipv6= k8sPodName=openstack/memcached-memcached-6479589586-msw85 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Policy Add Request" ciliumNetworkPolicy="[&{EndpointSelector:{\"matchLabels\":{\"k8s:app.kubernetes.io/component\":\"keycloak\",\"k8s:app.kubernetes.io/instance\":\"keycloak\",\"k8s:app.kubernetes.io/name\":\"keycloak\",\"k8s:io.kubernetes.pod.namespace\":\"auth-system\"}} NodeSelector:{} Ingress:[{IngressCommonRule:{FromEndpoints:[{}] FromRequires:[] FromCIDR: FromCIDRSet:[] FromEntities:[] aggregatedSelectors:[]} ToPorts:[{Ports:[{Port:7800 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:} {Ports:[{Port:8080 Protocol:TCP}] TerminatingTLS: OriginatingTLS: ServerNames:[] Listener: Rules:}] ICMPs:[] Authentication:}] IngressDeny:[] Egress:[{EgressCommonRule:{ToEndpoints:[{}] ToRequires:[] ToCIDR: ToCIDRSet:[] ToEntities:[] ToServices:[] ToGroups:[] aggregatedSelectors:[]} ToPorts:[] ToFQDNs:[] ICMPs:[] Authentication:}] EgressDeny:[] Labels:[k8s:io.cilium.k8s.policy.derived-from=NetworkPolicy k8s:io.cilium.k8s.policy.name=keycloak k8s:io.cilium.k8s.policy.namespace=auth-system k8s:io.cilium.k8s.policy.uid=6850b051-c0ab-4957-8bdd-0ba7005214f5] Description:}]" policyAddRequest=7f332640-2469-4919-8836-e1368419589c subsys=daemon level=info msg="Policy imported via API, recalculating..." policyAddRequest=7f332640-2469-4919-8836-e1368419589c policyRevision=4 subsys=daemon level=info msg="NetworkPolicy successfully added" k8sApiVersion= k8sNetworkPolicyName=keycloak subsys=k8s-watcher level=info msg="Create endpoint request" addressing="&{10.0.0.146 d65f2978-73b8-42e8-8b1c-b6e2112093bf default }" containerID=f9da0a606f306afcd9f64432fabfb4dc359a5a48289303d33fd6687bac43a2a2 datapathConfiguration="&{false false false false false }" interface=lxce784f51b9c07 k8sPodName=auth-system/keycloak-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f9da0a606f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=26 ipv4=10.0.0.146 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f9da0a606f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=26 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=23.0.7,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-20.0.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.146 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:auth-system k8s:io.cilium.k8s.namespace.labels.name:auth-system]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=f9da0a606f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=26 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.146 ipv6= k8sPodName=auth-system/keycloak-0 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=keycloak;k8s:app.kubernetes.io/instance=keycloak;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=keycloak;k8s:app.kubernetes.io/version=23.0.7;k8s:apps.kubernetes.io/pod-index=0;k8s:helm.sh/chart=keycloak-20.0.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system;k8s:io.cilium.k8s.namespace.labels.name=auth-system;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keycloak;k8s:io.kubernetes.pod.namespace=auth-system;k8s:statefulset.kubernetes.io/pod-name=keycloak-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=f9da0a606f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=26 identity=22066 identityLabels="k8s:app.kubernetes.io/component=keycloak,k8s:app.kubernetes.io/instance=keycloak,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=keycloak,k8s:app.kubernetes.io/version=23.0.7,k8s:apps.kubernetes.io/pod-index=0,k8s:helm.sh/chart=keycloak-20.0.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=auth-system,k8s:io.cilium.k8s.namespace.labels.name=auth-system,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keycloak,k8s:io.kubernetes.pod.namespace=auth-system,k8s:statefulset.kubernetes.io/pod-name=keycloak-0" ipv4=10.0.0.146 ipv6= k8sPodName=auth-system/keycloak-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f9da0a606f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=26 identity=22066 ipv4=10.0.0.146 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=f9da0a606f datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=26 identity=22066 ipv4=10.0.0.146 ipv6= k8sPodName=auth-system/keycloak-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=f9da0a606f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=26 identity=22066 ipv4=10.0.0.146 ipv6= k8sPodName=auth-system/keycloak-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Conntrack garbage collector interval recalculated" deleteRatio=0.035835713314293485 newInterval=7m30s subsys=map-ct level=info msg="Create endpoint request" addressing="&{10.0.0.36 9ba12e0f-64f7-4aba-85c7-477f1142eb68 default }" containerID=e0d63d1b83da36b124d3447b790942a1e1cfa721edf82f4574335acb3fcf0c9e datapathConfiguration="&{false false false false false }" interface=lxce5b34d9b07d5 k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-4whbq labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=e0d63d1b83 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=877 ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-4whbq subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=e0d63d1b83 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=877 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-4whbq subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:secretgen-controller]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app=secretgen-controller;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa;k8s:io.kubernetes.pod.namespace=secretgen-controller;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=e0d63d1b83 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=877 identity=43070 identityLabels="k8s:app=secretgen-controller,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=secretgen-controller,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=secretgen-controller-sa,k8s:io.kubernetes.pod.namespace=secretgen-controller" ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-4whbq oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=e0d63d1b83 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=877 identity=43070 ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-4whbq subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=e0d63d1b83 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=877 identity=43070 ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-4whbq subsys=endpoint level=info msg="Successful endpoint creation" containerID=e0d63d1b83 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=877 identity=43070 ipv4=10.0.0.36 ipv6= k8sPodName=secretgen-controller/secretgen-controller-5cf976ccc7-4whbq subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.233 2f736d50-7951-4986-89bd-039f385167ba default }" containerID=eaa4fe05ddd052939d6db3e6f285fbbba29c502e684e201347995c74c6174465 datapathConfiguration="&{false false false false false }" interface=lxc27b6e8f5d44d k8sPodName=monitoring/kube-prometheus-stack-admission-create-vklq4 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=eaa4fe05dd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=87 ipv4=10.0.0.233 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-vklq4 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=eaa4fe05dd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=87 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=58.2.1,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=25cbfddd-640c-4332-a32f-12b7f9b651b2,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-58.2.1,k8s:controller-uid=25cbfddd-640c-4332-a32f-12b7f9b651b2,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.233 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-vklq4 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=eaa4fe05dd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=87 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.233 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-vklq4 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-create;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=58.2.1;k8s:batch.kubernetes.io/controller-uid=25cbfddd-640c-4332-a32f-12b7f9b651b2;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create;k8s:chart=kube-prometheus-stack-58.2.1;k8s:controller-uid=25cbfddd-640c-4332-a32f-12b7f9b651b2;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-create;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=eaa4fe05dd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=87 identity=8841 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=58.2.1,k8s:app=kube-prometheus-stack-admission-create,k8s:batch.kubernetes.io/controller-uid=25cbfddd-640c-4332-a32f-12b7f9b651b2,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create,k8s:chart=kube-prometheus-stack-58.2.1,k8s:controller-uid=25cbfddd-640c-4332-a32f-12b7f9b651b2,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-create,k8s:release=kube-prometheus-stack" ipv4=10.0.0.233 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-vklq4 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=eaa4fe05dd datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=87 identity=8841 ipv4=10.0.0.233 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-vklq4 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=eaa4fe05dd datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=87 identity=8841 ipv4=10.0.0.233 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-vklq4 subsys=endpoint level=info msg="Successful endpoint creation" containerID=eaa4fe05dd datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=87 identity=8841 ipv4=10.0.0.233 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-vklq4 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=eaa4fe05dd endpointID=87 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-create-vklq4 subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-create k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=58.2.1 k8s:batch.kubernetes.io/controller-uid=25cbfddd-640c-4332-a32f-12b7f9b651b2 k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-create k8s:chart=kube-prometheus-stack-58.2.1 k8s:controller-uid=25cbfddd-640c-4332-a32f-12b7f9b651b2 k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-create k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=eaa4fe05dd datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=87 identity=8841 ipv4=10.0.0.233 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-create-vklq4 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.158 7f301b3d-7b50-4c95-bf61-038e47003a1a default }" containerID=420ad40d1f029727402bc4d4b059ed3919917b4a7d1af9b1c02b37f6ee8916dd datapathConfiguration="&{false false false false false }" interface=lxcf74a0c23521b k8sPodName=monitoring/kube-prometheus-stack-operator-7d58f4b66c-fmdsb labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=420ad40d1f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1583 ipv4=10.0.0.158 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-7d58f4b66c-fmdsb subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=420ad40d1f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1583 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=58.2.1,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-58.2.1,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.158 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-7d58f4b66c-fmdsb subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=420ad40d1f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1583 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.158 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-7d58f4b66c-fmdsb line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-operator;k8s:app.kubernetes.io/component=prometheus-operator;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=58.2.1;k8s:chart=kube-prometheus-stack-58.2.1;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=420ad40d1f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1583 identity=13712 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=58.2.1,k8s:app=kube-prometheus-stack-operator,k8s:chart=kube-prometheus-stack-58.2.1,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-operator,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.158 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-7d58f4b66c-fmdsb oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=420ad40d1f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1583 identity=13712 ipv4=10.0.0.158 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-7d58f4b66c-fmdsb subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=420ad40d1f datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1583 identity=13712 ipv4=10.0.0.158 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-7d58f4b66c-fmdsb subsys=endpoint level=info msg="Successful endpoint creation" containerID=420ad40d1f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1583 identity=13712 ipv4=10.0.0.158 ipv6= k8sPodName=monitoring/kube-prometheus-stack-operator-7d58f4b66c-fmdsb subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.140 67b694e1-826e-489c-ae03-ea543fcb81b8 default }" containerID=9719ffabca7c0482779682050451dfa87357b1aeda2fbe17333bb25ed7df1f9e datapathConfiguration="&{false false false false false }" interface=lxcd2faf84ee8ca k8sPodName=monitoring/kube-prometheus-stack-grafana-84966fff85-5xrts labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=9719ffabca datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2396 ipv4=10.0.0.140 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-84966fff85-5xrts subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=9719ffabca datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2396 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.140 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-84966fff85-5xrts subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Create endpoint request" addressing="&{10.0.0.128 70be0801-f138-4d1c-b030-d9523982565f default }" containerID=f770d39a5fcfc7f1cdc4e0fe1611e905333654605a0a1121ecda5073b05bb170 datapathConfiguration="&{false false false false false }" interface=lxc67cd11fff3cf k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-c7bd54d7-gfhj5 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f770d39a5f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2805 ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-c7bd54d7-gfhj5 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f770d39a5f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2805 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.18.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-c7bd54d7-gfhj5 subsys=endpoint level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/name=grafana;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana;k8s:io.kubernetes.pod.namespace=monitoring;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=9719ffabca datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2396 identity=23003 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/name=grafana,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-grafana,k8s:io.kubernetes.pod.namespace=monitoring" ipv4=10.0.0.140 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-84966fff85-5xrts oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=9719ffabca datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2396 identity=23003 ipv4=10.0.0.140 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-84966fff85-5xrts subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=metrics;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-state-metrics;k8s:app.kubernetes.io/part-of=kube-state-metrics;k8s:app.kubernetes.io/version=2.12.0;k8s:helm.sh/chart=kube-state-metrics-5.18.1;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics;k8s:io.kubernetes.pod.namespace=monitoring;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=f770d39a5f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2805 identity=64475 identityLabels="k8s:app.kubernetes.io/component=metrics,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-state-metrics,k8s:app.kubernetes.io/part-of=kube-state-metrics,k8s:app.kubernetes.io/version=2.12.0,k8s:helm.sh/chart=kube-state-metrics-5.18.1,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-kube-state-metrics,k8s:io.kubernetes.pod.namespace=monitoring,k8s:release=kube-prometheus-stack" ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-c7bd54d7-gfhj5 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f770d39a5f datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2805 identity=64475 ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-c7bd54d7-gfhj5 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=9719ffabca datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2396 identity=23003 ipv4=10.0.0.140 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-84966fff85-5xrts subsys=endpoint level=info msg="Successful endpoint creation" containerID=9719ffabca datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2396 identity=23003 ipv4=10.0.0.140 ipv6= k8sPodName=monitoring/kube-prometheus-stack-grafana-84966fff85-5xrts subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=f770d39a5f datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2805 identity=64475 ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-c7bd54d7-gfhj5 subsys=endpoint level=info msg="Successful endpoint creation" containerID=f770d39a5f datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2805 identity=64475 ipv4=10.0.0.128 ipv6= k8sPodName=monitoring/kube-prometheus-stack-kube-state-metrics-c7bd54d7-gfhj5 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.231 30ed691f-6805-473c-a4ee-87736f5a6969 default }" containerID=fbe2d2294d48bf00caf38e461b13ca01db3b71e846f0a4884c057426a3f782cf datapathConfiguration="&{false false false false false }" interface=lxc95279ce93f3e k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n4xbt labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=fbe2d2294d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1180 ipv4=10.0.0.231 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n4xbt subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=fbe2d2294d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1180 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=58.2.1,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=faedd395-085f-45ff-8307-0c887336d5b3,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-58.2.1,k8s:controller-uid=faedd395-085f-45ff-8307-0c887336d5b3,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.231 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n4xbt subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app=kube-prometheus-stack-admission-patch;k8s:app.kubernetes.io/component=prometheus-operator-webhook;k8s:app.kubernetes.io/instance=kube-prometheus-stack;k8s:app.kubernetes.io/managed-by=Helm;k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator;k8s:app.kubernetes.io/part-of=kube-prometheus-stack;k8s:app.kubernetes.io/version=58.2.1;k8s:batch.kubernetes.io/controller-uid=faedd395-085f-45ff-8307-0c887336d5b3;k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch;k8s:chart=kube-prometheus-stack-58.2.1;k8s:controller-uid=faedd395-085f-45ff-8307-0c887336d5b3;k8s:heritage=Helm;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission;k8s:io.kubernetes.pod.namespace=monitoring;k8s:job-name=kube-prometheus-stack-admission-patch;k8s:release=kube-prometheus-stack;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=fbe2d2294d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1180 identity=20246 identityLabels="k8s:app.kubernetes.io/component=prometheus-operator-webhook,k8s:app.kubernetes.io/instance=kube-prometheus-stack,k8s:app.kubernetes.io/managed-by=Helm,k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator,k8s:app.kubernetes.io/part-of=kube-prometheus-stack,k8s:app.kubernetes.io/version=58.2.1,k8s:app=kube-prometheus-stack-admission-patch,k8s:batch.kubernetes.io/controller-uid=faedd395-085f-45ff-8307-0c887336d5b3,k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch,k8s:chart=kube-prometheus-stack-58.2.1,k8s:controller-uid=faedd395-085f-45ff-8307-0c887336d5b3,k8s:heritage=Helm,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission,k8s:io.kubernetes.pod.namespace=monitoring,k8s:job-name=kube-prometheus-stack-admission-patch,k8s:release=kube-prometheus-stack" ipv4=10.0.0.231 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n4xbt oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=fbe2d2294d datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1180 identity=20246 ipv4=10.0.0.231 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n4xbt subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=fbe2d2294d datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1180 identity=20246 ipv4=10.0.0.231 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n4xbt subsys=endpoint level=info msg="Successful endpoint creation" containerID=fbe2d2294d datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1180 identity=20246 ipv4=10.0.0.231 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n4xbt subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.226 24887897-b512-42a3-b290-1f4b031b0704 default }" containerID=8fef53c22c327ecac3e45ec7fd255ffd04ad28d2d02c379c1254e20cd9aefab2 datapathConfiguration="&{false false false false false }" interface=lxcd5687e628e72 k8sPodName=local-path-storage/helper-pod-create-pvc-26c8798b-fbf2-482c-9fa6-3ee6dd86053e labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=8fef53c22c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=149 ipv4=10.0.0.226 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-26c8798b-fbf2-482c-9fa6-3ee6dd86053e subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=8fef53c22c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=149 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.226 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-26c8798b-fbf2-482c-9fa6-3ee6dd86053e subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=8fef53c22c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=149 identity=61599 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.226 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-26c8798b-fbf2-482c-9fa6-3ee6dd86053e oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=8fef53c22c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=149 identity=61599 ipv4=10.0.0.226 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-26c8798b-fbf2-482c-9fa6-3ee6dd86053e subsys=endpoint level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=8fef53c22c datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=149 identity=61599 ipv4=10.0.0.226 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-26c8798b-fbf2-482c-9fa6-3ee6dd86053e subsys=endpoint level=info msg="Successful endpoint creation" containerID=8fef53c22c datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=149 identity=61599 ipv4=10.0.0.226 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-26c8798b-fbf2-482c-9fa6-3ee6dd86053e subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.151 a15058b3-6a8a-4b03-a04d-fd03b430b90c default }" containerID=f2e73af12c1c61de8cf45df87d65573f648ead9b28d2e777931333a5c2b0ad29 datapathConfiguration="&{false false false false false }" interface=lxc5888a8d922c4 k8sPodName=local-path-storage/helper-pod-create-pvc-cde533eb-760a-4f01-94ae-a30ed3c94fc8 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=f2e73af12c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1310 ipv4=10.0.0.151 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-cde533eb-760a-4f01-94ae-a30ed3c94fc8 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=f2e73af12c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1310 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.151 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-cde533eb-760a-4f01-94ae-a30ed3c94fc8 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=f2e73af12c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1310 identity=61599 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.151 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-cde533eb-760a-4f01-94ae-a30ed3c94fc8 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=f2e73af12c datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1310 identity=61599 ipv4=10.0.0.151 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-cde533eb-760a-4f01-94ae-a30ed3c94fc8 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=f2e73af12c datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1310 identity=61599 ipv4=10.0.0.151 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-cde533eb-760a-4f01-94ae-a30ed3c94fc8 subsys=endpoint level=info msg="Successful endpoint creation" containerID=f2e73af12c datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1310 identity=61599 ipv4=10.0.0.151 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-cde533eb-760a-4f01-94ae-a30ed3c94fc8 subsys=daemon level=info msg="Delete endpoint request" containerID=fbe2d2294d endpointID=1180 k8sNamespace=monitoring k8sPodName=kube-prometheus-stack-admission-patch-n4xbt subsys=daemon level=info msg="Releasing key" key="[k8s:app=kube-prometheus-stack-admission-patch k8s:app.kubernetes.io/component=prometheus-operator-webhook k8s:app.kubernetes.io/instance=kube-prometheus-stack k8s:app.kubernetes.io/managed-by=Helm k8s:app.kubernetes.io/name=kube-prometheus-stack-prometheus-operator k8s:app.kubernetes.io/part-of=kube-prometheus-stack k8s:app.kubernetes.io/version=58.2.1 k8s:batch.kubernetes.io/controller-uid=faedd395-085f-45ff-8307-0c887336d5b3 k8s:batch.kubernetes.io/job-name=kube-prometheus-stack-admission-patch k8s:chart=kube-prometheus-stack-58.2.1 k8s:controller-uid=faedd395-085f-45ff-8307-0c887336d5b3 k8s:heritage=Helm k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-admission k8s:io.kubernetes.pod.namespace=monitoring k8s:job-name=kube-prometheus-stack-admission-patch k8s:release=kube-prometheus-stack]" subsys=allocator level=info msg="Removed endpoint" containerID=fbe2d2294d datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1180 identity=20246 ipv4=10.0.0.231 ipv6= k8sPodName=monitoring/kube-prometheus-stack-admission-patch-n4xbt subsys=endpoint level=info msg="Delete endpoint request" containerID=8fef53c22c endpointID=149 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-26c8798b-fbf2-482c-9fa6-3ee6dd86053e subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Delete endpoint request" containerID=f2e73af12c endpointID=1310 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-cde533eb-760a-4f01-94ae-a30ed3c94fc8 subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=8fef53c22c datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=149 identity=61599 ipv4=10.0.0.226 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-26c8798b-fbf2-482c-9fa6-3ee6dd86053e subsys=endpoint level=info msg="Removed endpoint" containerID=f2e73af12c datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1310 identity=61599 ipv4=10.0.0.151 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-cde533eb-760a-4f01-94ae-a30ed3c94fc8 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.26 0e031ffd-4f08-4c3f-bb17-9a4c14b878f9 default }" containerID=159aa6e6855a29c77f1e866e2044a384ba154b90d6d9f86fd54b6fa789626a05 datapathConfiguration="&{false false false false false }" interface=lxc449099ea5364 k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=159aa6e685 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=692 ipv4=10.0.0.26 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=159aa6e685 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=692 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.26 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:alertmanager=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=alertmanager;k8s:app.kubernetes.io/version=0.27.0;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager;k8s:io.kubernetes.pod.namespace=monitoring;k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=159aa6e685 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=692 identity=10155 identityLabels="k8s:alertmanager=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/instance=kube-prometheus-stack-alertmanager,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=alertmanager,k8s:app.kubernetes.io/version=0.27.0,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-alertmanager,k8s:io.kubernetes.pod.namespace=monitoring,k8s:statefulset.kubernetes.io/pod-name=alertmanager-kube-prometheus-stack-alertmanager-0" ipv4=10.0.0.26 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=159aa6e685 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=692 identity=10155 ipv4=10.0.0.26 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=159aa6e685 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=692 identity=10155 ipv4=10.0.0.26 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=159aa6e685 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=692 identity=10155 ipv4=10.0.0.26 ipv6= k8sPodName=monitoring/alertmanager-kube-prometheus-stack-alertmanager-0 subsys=daemon level=info msg="Create endpoint request" addressing="&{10.0.0.29 69f07d37-ecec-470a-94cc-98aaf0241b74 default }" containerID=3d752aa39949374a62e847f0b3ce879d035eea560c26b8ef6d2643ce5bd7992e datapathConfiguration="&{false false false false false }" interface=lxc585e3d70aacb k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=3d752aa399 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=180 ipv4=10.0.0.29 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=3d752aa399 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=180 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.29 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:monitoring]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus;k8s:app.kubernetes.io/managed-by=prometheus-operator;k8s:app.kubernetes.io/name=prometheus;k8s:app.kubernetes.io/version=2.51.2;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus;k8s:io.kubernetes.pod.namespace=monitoring;k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus;k8s:operator.prometheus.io/shard=0;k8s:prometheus=kube-prometheus-stack-prometheus;k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=3d752aa399 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=180 identity=16097 identityLabels="k8s:app.kubernetes.io/instance=kube-prometheus-stack-prometheus,k8s:app.kubernetes.io/managed-by=prometheus-operator,k8s:app.kubernetes.io/name=prometheus,k8s:app.kubernetes.io/version=2.51.2,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=monitoring,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=kube-prometheus-stack-prometheus,k8s:io.kubernetes.pod.namespace=monitoring,k8s:operator.prometheus.io/name=kube-prometheus-stack-prometheus,k8s:operator.prometheus.io/shard=0,k8s:prometheus=kube-prometheus-stack-prometheus,k8s:statefulset.kubernetes.io/pod-name=prometheus-kube-prometheus-stack-prometheus-0" ipv4=10.0.0.29 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=3d752aa399 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=180 identity=16097 ipv4=10.0.0.29 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=3d752aa399 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=180 identity=16097 ipv4=10.0.0.29 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=3d752aa399 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=180 identity=16097 ipv4=10.0.0.29 ipv6= k8sPodName=monitoring/prometheus-kube-prometheus-stack-prometheus-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.30 6f7f53ec-ba75-4a84-bc6a-030a86597aab default }" containerID=43152fe75b214db81d27eac5be103b37dac0aacc64a2052b05aa718b546b6f77 datapathConfiguration="&{false false false false false }" interface=lxce5aee315264f k8sPodName=local-path-storage/helper-pod-create-pvc-b0dba8f4-15a4-4bc0-bad1-c40791d13a8d labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=43152fe75b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=366 ipv4=10.0.0.30 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-b0dba8f4-15a4-4bc0-bad1-c40791d13a8d subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=43152fe75b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=366 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.30 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-b0dba8f4-15a4-4bc0-bad1-c40791d13a8d subsys=endpoint level=info msg="Reusing existing global key" key="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage;k8s:io.cilium.k8s.namespace.labels.name=local-path-storage;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner;k8s:io.kubernetes.pod.namespace=local-path-storage;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=43152fe75b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=366 identity=61599 identityLabels="k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage,k8s:io.cilium.k8s.namespace.labels.name=local-path-storage,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner,k8s:io.kubernetes.pod.namespace=local-path-storage" ipv4=10.0.0.30 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-b0dba8f4-15a4-4bc0-bad1-c40791d13a8d oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=43152fe75b datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=366 identity=61599 ipv4=10.0.0.30 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-b0dba8f4-15a4-4bc0-bad1-c40791d13a8d subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=43152fe75b datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=366 identity=61599 ipv4=10.0.0.30 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-b0dba8f4-15a4-4bc0-bad1-c40791d13a8d subsys=endpoint level=info msg="Successful endpoint creation" containerID=43152fe75b datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=366 identity=61599 ipv4=10.0.0.30 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-b0dba8f4-15a4-4bc0-bad1-c40791d13a8d subsys=daemon level=info msg="Delete endpoint request" containerID=43152fe75b endpointID=366 k8sNamespace=local-path-storage k8sPodName=helper-pod-create-pvc-b0dba8f4-15a4-4bc0-bad1-c40791d13a8d subsys=daemon level=info msg="Releasing key" key="[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=local-path-storage k8s:io.cilium.k8s.namespace.labels.name=local-path-storage k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=local-path-provisioner k8s:io.kubernetes.pod.namespace=local-path-storage]" subsys=allocator level=info msg="Removed endpoint" containerID=43152fe75b datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=366 identity=61599 ipv4=10.0.0.30 ipv6= k8sPodName=local-path-storage/helper-pod-create-pvc-b0dba8f4-15a4-4bc0-bad1-c40791d13a8d subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.189 e37a5355-0fb9-48cb-b4a0-dc94424fcd48 default }" containerID=39a51fdc537a2ecdf760a00ca2c298ad54ef916579dad1baf37962d5f93bbeb9 datapathConfiguration="&{false false false false false }" interface=lxcdde4fb13e631 k8sPodName=openstack/rabbitmq-keystone-server-0 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=39a51fdc53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=885 ipv4=10.0.0.189 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=39a51fdc53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=885 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.189 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:app.kubernetes.io/component=rabbitmq;k8s:app.kubernetes.io/name=rabbitmq-keystone;k8s:app.kubernetes.io/part-of=rabbitmq;k8s:apps.kubernetes.io/pod-index=0;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server;k8s:io.kubernetes.pod.namespace=openstack;k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0;" subsys=allocator level=info msg="Invalid state transition skipped" containerID=39a51fdc53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=885 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.189 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 line=611 subsys=endpoint level=info msg="Identity of endpoint changed" containerID=39a51fdc53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=885 identity=56523 identityLabels="k8s:app.kubernetes.io/component=rabbitmq,k8s:app.kubernetes.io/name=rabbitmq-keystone,k8s:app.kubernetes.io/part-of=rabbitmq,k8s:apps.kubernetes.io/pod-index=0,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=rabbitmq-keystone-server,k8s:io.kubernetes.pod.namespace=openstack,k8s:statefulset.kubernetes.io/pod-name=rabbitmq-keystone-server-0" ipv4=10.0.0.189 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=39a51fdc53 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=885 identity=56523 ipv4=10.0.0.189 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=39a51fdc53 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=885 identity=56523 ipv4=10.0.0.189 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=endpoint level=info msg="Successful endpoint creation" containerID=39a51fdc53 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=885 identity=56523 ipv4=10.0.0.189 ipv6= k8sPodName=openstack/rabbitmq-keystone-server-0 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Create endpoint request" addressing="&{10.0.0.58 44f7f2ed-0232-490d-8d82-24ee06275bc5 default }" containerID=d798a5652a91c4408766deedda51c122a487889cb66b8775e2f4ae5cd10e4679 datapathConfiguration="&{false false false false false }" interface=lxc2e44339ab70a k8sPodName=openstack/keystone-api-776d8f4444-gjlh7 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=d798a5652a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1948 ipv4=10.0.0.58 ipv6= k8sPodName=openstack/keystone-api-776d8f4444-gjlh7 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=d798a5652a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1948 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.58 ipv6= k8sPodName=openstack/keystone-api-776d8f4444-gjlh7 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=d798a5652a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1948 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.58 ipv6= k8sPodName=openstack/keystone-api-776d8f4444-gjlh7 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:component=api;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-api;k8s:io.kubernetes.pod.namespace=openstack;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=d798a5652a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1948 identity=12296 identityLabels="k8s:application=keystone,k8s:component=api,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-api,k8s:io.kubernetes.pod.namespace=openstack,k8s:release_group=keystone" ipv4=10.0.0.58 ipv6= k8sPodName=openstack/keystone-api-776d8f4444-gjlh7 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=d798a5652a datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=1948 identity=12296 ipv4=10.0.0.58 ipv6= k8sPodName=openstack/keystone-api-776d8f4444-gjlh7 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.252 9f1c6215-b5e6-4422-bb70-29001f30fb0e default }" containerID=9644b979f227f2ed29c2e881811196b5643fe06873a7503ce77d200f7d4c120b datapathConfiguration="&{false false false false false }" interface=lxc141c0afd11df k8sPodName=openstack/keystone-credential-setup-4x4st labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=9644b979f2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2785 ipv4=10.0.0.252 ipv6= k8sPodName=openstack/keystone-credential-setup-4x4st subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=9644b979f2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2785 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=c66caa13-7e16-4226-959b-8e955f002a93,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=c66caa13-7e16-4226-959b-8e955f002a93,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.252 ipv6= k8sPodName=openstack/keystone-credential-setup-4x4st subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=c66caa13-7e16-4226-959b-8e955f002a93;k8s:batch.kubernetes.io/job-name=keystone-credential-setup;k8s:component=credential-setup;k8s:controller-uid=c66caa13-7e16-4226-959b-8e955f002a93;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-credential-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=9644b979f2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2785 identity=45537 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=c66caa13-7e16-4226-959b-8e955f002a93,k8s:batch.kubernetes.io/job-name=keystone-credential-setup,k8s:component=credential-setup,k8s:controller-uid=c66caa13-7e16-4226-959b-8e955f002a93,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-credential-setup,k8s:release_group=keystone" ipv4=10.0.0.252 ipv6= k8sPodName=openstack/keystone-credential-setup-4x4st oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=9644b979f2 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2785 identity=45537 ipv4=10.0.0.252 ipv6= k8sPodName=openstack/keystone-credential-setup-4x4st subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=d798a5652a datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=1948 identity=12296 ipv4=10.0.0.58 ipv6= k8sPodName=openstack/keystone-api-776d8f4444-gjlh7 subsys=endpoint level=info msg="Successful endpoint creation" containerID=d798a5652a datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=1948 identity=12296 ipv4=10.0.0.58 ipv6= k8sPodName=openstack/keystone-api-776d8f4444-gjlh7 subsys=daemon level=info msg="Rewrote endpoint BPF program" containerID=9644b979f2 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2785 identity=45537 ipv4=10.0.0.252 ipv6= k8sPodName=openstack/keystone-credential-setup-4x4st subsys=endpoint level=info msg="Successful endpoint creation" containerID=9644b979f2 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2785 identity=45537 ipv4=10.0.0.252 ipv6= k8sPodName=openstack/keystone-credential-setup-4x4st subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="regenerating all endpoints" reason= subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=9644b979f2 endpointID=2785 k8sNamespace=openstack k8sPodName=keystone-credential-setup-4x4st subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=c66caa13-7e16-4226-959b-8e955f002a93 k8s:batch.kubernetes.io/job-name=keystone-credential-setup k8s:component=credential-setup k8s:controller-uid=c66caa13-7e16-4226-959b-8e955f002a93 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-credential-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-credential-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=9644b979f2 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2785 identity=45537 ipv4=10.0.0.252 ipv6= k8sPodName=openstack/keystone-credential-setup-4x4st subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.234 ccfbb45c-466f-4dd2-9a90-d3ac385b7da3 default }" containerID=c0f0e92220c3864e0e2a61184719ad966352cf6580d8f59696b961aaa1951cd7 datapathConfiguration="&{false false false false false }" interface=lxcc58ce391ed63 k8sPodName=openstack/keystone-db-init-xx5jw labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=c0f0e92220 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3300 ipv4=10.0.0.234 ipv6= k8sPodName=openstack/keystone-db-init-xx5jw subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=c0f0e92220 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3300 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=744dc0d6-e13c-4b9d-8284-a4ac126642ab,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=744dc0d6-e13c-4b9d-8284-a4ac126642ab,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.234 ipv6= k8sPodName=openstack/keystone-db-init-xx5jw subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=744dc0d6-e13c-4b9d-8284-a4ac126642ab;k8s:batch.kubernetes.io/job-name=keystone-db-init;k8s:component=db-init;k8s:controller-uid=744dc0d6-e13c-4b9d-8284-a4ac126642ab;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-init;k8s:release_group=keystone;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=c0f0e92220 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3300 identity=12780 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=744dc0d6-e13c-4b9d-8284-a4ac126642ab,k8s:batch.kubernetes.io/job-name=keystone-db-init,k8s:component=db-init,k8s:controller-uid=744dc0d6-e13c-4b9d-8284-a4ac126642ab,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-init,k8s:release_group=keystone" ipv4=10.0.0.234 ipv6= k8sPodName=openstack/keystone-db-init-xx5jw oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=c0f0e92220 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=3300 identity=12780 ipv4=10.0.0.234 ipv6= k8sPodName=openstack/keystone-db-init-xx5jw subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=c0f0e92220 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=3300 identity=12780 ipv4=10.0.0.234 ipv6= k8sPodName=openstack/keystone-db-init-xx5jw subsys=endpoint level=info msg="Successful endpoint creation" containerID=c0f0e92220 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3300 identity=12780 ipv4=10.0.0.234 ipv6= k8sPodName=openstack/keystone-db-init-xx5jw subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=c0f0e92220 endpointID=3300 k8sNamespace=openstack k8sPodName=keystone-db-init-xx5jw subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=744dc0d6-e13c-4b9d-8284-a4ac126642ab k8s:batch.kubernetes.io/job-name=keystone-db-init k8s:component=db-init k8s:controller-uid=744dc0d6-e13c-4b9d-8284-a4ac126642ab k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=c0f0e92220 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=3300 identity=12780 ipv4=10.0.0.234 ipv6= k8sPodName=openstack/keystone-db-init-xx5jw subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.248 cf036ccb-cb06-462a-b45c-a746ba5c0e73 default }" containerID=9153d41b58349365952ee02ebfa138fb5a23f0bb3f8d9892e90c209976bf8c9c datapathConfiguration="&{false false false false false }" interface=lxcdf52af9d1f04 k8sPodName=openstack/keystone-fernet-setup-hzvvl labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=9153d41b58 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=379 ipv4=10.0.0.248 ipv6= k8sPodName=openstack/keystone-fernet-setup-hzvvl subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=9153d41b58 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=379 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=481a0035-19db-4c53-aee9-8a139a6922e8,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=481a0035-19db-4c53-aee9-8a139a6922e8,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.248 ipv6= k8sPodName=openstack/keystone-fernet-setup-hzvvl subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=9153d41b58 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=379 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.248 ipv6= k8sPodName=openstack/keystone-fernet-setup-hzvvl line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=481a0035-19db-4c53-aee9-8a139a6922e8;k8s:batch.kubernetes.io/job-name=keystone-fernet-setup;k8s:component=fernet-setup;k8s:controller-uid=481a0035-19db-4c53-aee9-8a139a6922e8;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-fernet-setup;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=9153d41b58 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=379 identity=2849 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=481a0035-19db-4c53-aee9-8a139a6922e8,k8s:batch.kubernetes.io/job-name=keystone-fernet-setup,k8s:component=fernet-setup,k8s:controller-uid=481a0035-19db-4c53-aee9-8a139a6922e8,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-fernet-setup,k8s:release_group=keystone" ipv4=10.0.0.248 ipv6= k8sPodName=openstack/keystone-fernet-setup-hzvvl oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=9153d41b58 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=379 identity=2849 ipv4=10.0.0.248 ipv6= k8sPodName=openstack/keystone-fernet-setup-hzvvl subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=9153d41b58 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=379 identity=2849 ipv4=10.0.0.248 ipv6= k8sPodName=openstack/keystone-fernet-setup-hzvvl subsys=endpoint level=info msg="Successful endpoint creation" containerID=9153d41b58 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=379 identity=2849 ipv4=10.0.0.248 ipv6= k8sPodName=openstack/keystone-fernet-setup-hzvvl subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=9153d41b58 endpointID=379 k8sNamespace=openstack k8sPodName=keystone-fernet-setup-hzvvl subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=481a0035-19db-4c53-aee9-8a139a6922e8 k8s:batch.kubernetes.io/job-name=keystone-fernet-setup k8s:component=fernet-setup k8s:controller-uid=481a0035-19db-4c53-aee9-8a139a6922e8 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-fernet-setup k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-fernet-setup k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=9153d41b58 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=379 identity=2849 ipv4=10.0.0.248 ipv6= k8sPodName=openstack/keystone-fernet-setup-hzvvl subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.250 1932d2ee-e211-4dbe-a721-587bcfc42dea default }" containerID=32dbcab8f63a301a4ba74f072ad7ddc470cf482d04751e85abe2a765994eed5d datapathConfiguration="&{false false false false false }" interface=lxc5eb8b9931b93 k8sPodName=openstack/keystone-db-sync-j85m9 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=32dbcab8f6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=782 ipv4=10.0.0.250 ipv6= k8sPodName=openstack/keystone-db-sync-j85m9 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=32dbcab8f6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=782 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=fc402bc0-9f79-4cdc-9c93-b82194f9c238,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=fc402bc0-9f79-4cdc-9c93-b82194f9c238,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.250 ipv6= k8sPodName=openstack/keystone-db-sync-j85m9 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=fc402bc0-9f79-4cdc-9c93-b82194f9c238;k8s:batch.kubernetes.io/job-name=keystone-db-sync;k8s:component=db-sync;k8s:controller-uid=fc402bc0-9f79-4cdc-9c93-b82194f9c238;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-db-sync;k8s:release_group=keystone;" subsys=allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Identity of endpoint changed" containerID=32dbcab8f6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=782 identity=3511 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=fc402bc0-9f79-4cdc-9c93-b82194f9c238,k8s:batch.kubernetes.io/job-name=keystone-db-sync,k8s:component=db-sync,k8s:controller-uid=fc402bc0-9f79-4cdc-9c93-b82194f9c238,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-db-sync,k8s:release_group=keystone" ipv4=10.0.0.250 ipv6= k8sPodName=openstack/keystone-db-sync-j85m9 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=32dbcab8f6 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=782 identity=3511 ipv4=10.0.0.250 ipv6= k8sPodName=openstack/keystone-db-sync-j85m9 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=32dbcab8f6 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=782 identity=3511 ipv4=10.0.0.250 ipv6= k8sPodName=openstack/keystone-db-sync-j85m9 subsys=endpoint level=info msg="Successful endpoint creation" containerID=32dbcab8f6 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=782 identity=3511 ipv4=10.0.0.250 ipv6= k8sPodName=openstack/keystone-db-sync-j85m9 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=32dbcab8f6 endpointID=782 k8sNamespace=openstack k8sPodName=keystone-db-sync-j85m9 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=fc402bc0-9f79-4cdc-9c93-b82194f9c238 k8s:batch.kubernetes.io/job-name=keystone-db-sync k8s:component=db-sync k8s:controller-uid=fc402bc0-9f79-4cdc-9c93-b82194f9c238 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-db-sync k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-db-sync k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=32dbcab8f6 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=782 identity=3511 ipv4=10.0.0.250 ipv6= k8sPodName=openstack/keystone-db-sync-j85m9 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.215 50047efc-d3f6-40e7-8d91-5f536d10d389 default }" containerID=b15fc5c632ef691fd288d61f0752a7d49712b5efb3293352c3e7e6c4e6d300f4 datapathConfiguration="&{false false false false false }" interface=lxc6f076f2505a7 k8sPodName=openstack/keystone-rabbit-init-cq546 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=b15fc5c632 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=107 ipv4=10.0.0.215 ipv6= k8sPodName=openstack/keystone-rabbit-init-cq546 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=b15fc5c632 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=107 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=04f79a0d-e77a-4e8a-9e9b-8ddb3a256cc9,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=04f79a0d-e77a-4e8a-9e9b-8ddb3a256cc9,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.215 ipv6= k8sPodName=openstack/keystone-rabbit-init-cq546 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=04f79a0d-e77a-4e8a-9e9b-8ddb3a256cc9;k8s:batch.kubernetes.io/job-name=keystone-rabbit-init;k8s:component=rabbit-init;k8s:controller-uid=04f79a0d-e77a-4e8a-9e9b-8ddb3a256cc9;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-rabbit-init;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=b15fc5c632 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=107 identity=2473 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=04f79a0d-e77a-4e8a-9e9b-8ddb3a256cc9,k8s:batch.kubernetes.io/job-name=keystone-rabbit-init,k8s:component=rabbit-init,k8s:controller-uid=04f79a0d-e77a-4e8a-9e9b-8ddb3a256cc9,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-rabbit-init,k8s:release_group=keystone" ipv4=10.0.0.215 ipv6= k8sPodName=openstack/keystone-rabbit-init-cq546 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=b15fc5c632 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=107 identity=2473 ipv4=10.0.0.215 ipv6= k8sPodName=openstack/keystone-rabbit-init-cq546 subsys=endpoint level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Rewrote endpoint BPF program" containerID=b15fc5c632 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=107 identity=2473 ipv4=10.0.0.215 ipv6= k8sPodName=openstack/keystone-rabbit-init-cq546 subsys=endpoint level=info msg="Successful endpoint creation" containerID=b15fc5c632 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=107 identity=2473 ipv4=10.0.0.215 ipv6= k8sPodName=openstack/keystone-rabbit-init-cq546 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=b15fc5c632 endpointID=107 k8sNamespace=openstack k8sPodName=keystone-rabbit-init-cq546 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=04f79a0d-e77a-4e8a-9e9b-8ddb3a256cc9 k8s:batch.kubernetes.io/job-name=keystone-rabbit-init k8s:component=rabbit-init k8s:controller-uid=04f79a0d-e77a-4e8a-9e9b-8ddb3a256cc9 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-rabbit-init k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-rabbit-init k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=b15fc5c632 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=107 identity=2473 ipv4=10.0.0.215 ipv6= k8sPodName=openstack/keystone-rabbit-init-cq546 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.221 cffd19c8-602c-48f3-9616-1e0b0a81c6dc default }" containerID=564d3f8806722809e8a076ff9011a705641781bc07bfa23e5727d993268df06b datapathConfiguration="&{false false false false false }" interface=lxc765a5be2ebfe k8sPodName=openstack/keystone-domain-manage-s67m5 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=564d3f8806 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2954 ipv4=10.0.0.221 ipv6= k8sPodName=openstack/keystone-domain-manage-s67m5 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=564d3f8806 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2954 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=3690fa22-413e-4a0c-9d10-1365d8f9c72e,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=3690fa22-413e-4a0c-9d10-1365d8f9c72e,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.221 ipv6= k8sPodName=openstack/keystone-domain-manage-s67m5 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=3690fa22-413e-4a0c-9d10-1365d8f9c72e;k8s:batch.kubernetes.io/job-name=keystone-domain-manage;k8s:component=domain-manage;k8s:controller-uid=3690fa22-413e-4a0c-9d10-1365d8f9c72e;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-domain-manage;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=564d3f8806 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2954 identity=58734 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=3690fa22-413e-4a0c-9d10-1365d8f9c72e,k8s:batch.kubernetes.io/job-name=keystone-domain-manage,k8s:component=domain-manage,k8s:controller-uid=3690fa22-413e-4a0c-9d10-1365d8f9c72e,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-domain-manage,k8s:release_group=keystone" ipv4=10.0.0.221 ipv6= k8sPodName=openstack/keystone-domain-manage-s67m5 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=564d3f8806 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=2954 identity=58734 ipv4=10.0.0.221 ipv6= k8sPodName=openstack/keystone-domain-manage-s67m5 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=564d3f8806 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=2954 identity=58734 ipv4=10.0.0.221 ipv6= k8sPodName=openstack/keystone-domain-manage-s67m5 subsys=endpoint level=info msg="Successful endpoint creation" containerID=564d3f8806 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2954 identity=58734 ipv4=10.0.0.221 ipv6= k8sPodName=openstack/keystone-domain-manage-s67m5 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=564d3f8806 endpointID=2954 k8sNamespace=openstack k8sPodName=keystone-domain-manage-s67m5 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=3690fa22-413e-4a0c-9d10-1365d8f9c72e k8s:batch.kubernetes.io/job-name=keystone-domain-manage k8s:component=domain-manage k8s:controller-uid=3690fa22-413e-4a0c-9d10-1365d8f9c72e k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-domain-manage k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-domain-manage k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=564d3f8806 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=2954 identity=58734 ipv4=10.0.0.221 ipv6= k8sPodName=openstack/keystone-domain-manage-s67m5 subsys=endpoint level=info msg="Create endpoint request" addressing="&{10.0.0.123 abc2ea60-78fd-4599-b714-8876dc8dfe1b default }" containerID=3d405332d1c769b910d1ab14725075b2103c68adb571a2beecd9f0a346087c08 datapathConfiguration="&{false false false false false }" interface=lxc44b3f7859926 k8sPodName=openstack/keystone-bootstrap-sc8x4 labels="[]" subsys=daemon sync-build=true level=info msg="New endpoint" containerID=3d405332d1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=257 ipv4=10.0.0.123 ipv6= k8sPodName=openstack/keystone-bootstrap-sc8x4 subsys=endpoint level=info msg="Resolving identity labels (blocking)" containerID=3d405332d1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=257 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=f77659d7-3c02-4f63-a279-bc2449dd6103,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=f77659d7-3c02-4f63-a279-bc2449dd6103,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.123 ipv6= k8sPodName=openstack/keystone-bootstrap-sc8x4 subsys=endpoint level=info msg="Skipped non-kubernetes labels when labelling ciliumidentity. All labels will still be used in identity determination" labels="map[k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name:openstack k8s:io.cilium.k8s.namespace.labels.name:openstack]" subsys=crd-allocator level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Invalid state transition skipped" containerID=3d405332d1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=257 endpointState.from=waiting-for-identity endpointState.to=waiting-to-regenerate file=/go/src/github.com/cilium/cilium/pkg/endpoint/policy.go ipv4=10.0.0.123 ipv6= k8sPodName=openstack/keystone-bootstrap-sc8x4 line=611 subsys=endpoint level=info msg="Allocated new global key" key="k8s:application=keystone;k8s:batch.kubernetes.io/controller-uid=f77659d7-3c02-4f63-a279-bc2449dd6103;k8s:batch.kubernetes.io/job-name=keystone-bootstrap;k8s:component=bootstrap;k8s:controller-uid=f77659d7-3c02-4f63-a279-bc2449dd6103;k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack;k8s:io.cilium.k8s.namespace.labels.name=openstack;k8s:io.cilium.k8s.policy.cluster=default;k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap;k8s:io.kubernetes.pod.namespace=openstack;k8s:job-name=keystone-bootstrap;k8s:release_group=keystone;" subsys=allocator level=info msg="Identity of endpoint changed" containerID=3d405332d1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=257 identity=9083 identityLabels="k8s:application=keystone,k8s:batch.kubernetes.io/controller-uid=f77659d7-3c02-4f63-a279-bc2449dd6103,k8s:batch.kubernetes.io/job-name=keystone-bootstrap,k8s:component=bootstrap,k8s:controller-uid=f77659d7-3c02-4f63-a279-bc2449dd6103,k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack,k8s:io.cilium.k8s.namespace.labels.name=openstack,k8s:io.cilium.k8s.policy.cluster=default,k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap,k8s:io.kubernetes.pod.namespace=openstack,k8s:job-name=keystone-bootstrap,k8s:release_group=keystone" ipv4=10.0.0.123 ipv6= k8sPodName=openstack/keystone-bootstrap-sc8x4 oldIdentity="no identity" subsys=endpoint level=info msg="Waiting for endpoint to be generated" containerID=3d405332d1 datapathPolicyRevision=0 desiredPolicyRevision=0 endpointID=257 identity=9083 ipv4=10.0.0.123 ipv6= k8sPodName=openstack/keystone-bootstrap-sc8x4 subsys=endpoint level=info msg="Rewrote endpoint BPF program" containerID=3d405332d1 datapathPolicyRevision=0 desiredPolicyRevision=4 endpointID=257 identity=9083 ipv4=10.0.0.123 ipv6= k8sPodName=openstack/keystone-bootstrap-sc8x4 subsys=endpoint level=info msg="Successful endpoint creation" containerID=3d405332d1 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=257 identity=9083 ipv4=10.0.0.123 ipv6= k8sPodName=openstack/keystone-bootstrap-sc8x4 subsys=daemon level=info msg="regenerating all endpoints" reason="one or more identities created or deleted" subsys=endpoint-manager level=info msg="Delete endpoint request" containerID=3d405332d1 endpointID=257 k8sNamespace=openstack k8sPodName=keystone-bootstrap-sc8x4 subsys=daemon level=info msg="Releasing key" key="[k8s:application=keystone k8s:batch.kubernetes.io/controller-uid=f77659d7-3c02-4f63-a279-bc2449dd6103 k8s:batch.kubernetes.io/job-name=keystone-bootstrap k8s:component=bootstrap k8s:controller-uid=f77659d7-3c02-4f63-a279-bc2449dd6103 k8s:io.cilium.k8s.namespace.labels.kubernetes.io/metadata.name=openstack k8s:io.cilium.k8s.namespace.labels.name=openstack k8s:io.cilium.k8s.policy.cluster=default k8s:io.cilium.k8s.policy.serviceaccount=keystone-bootstrap k8s:io.kubernetes.pod.namespace=openstack k8s:job-name=keystone-bootstrap k8s:release_group=keystone]" subsys=allocator level=info msg="Removed endpoint" containerID=3d405332d1 datapathPolicyRevision=4 desiredPolicyRevision=4 endpointID=257 identity=9083 ipv4=10.0.0.123 ipv6= k8sPodName=openstack/keystone-bootstrap-sc8x4 subsys=endpoint