Skip to content

policy: Hold listeners until the first network policy update - #2084

Open
firecow wants to merge 2 commits into
cilium:mainfrom
firecow:first-policy-gates-listener-main
Open

firecow wants to merge 2 commits into
cilium:mainfrom
firecow:first-policy-gates-listener-main

Conversation

@firecow

@firecow firecow commented Oct 9, 2026

Copy link
Copy Markdown

After a cilium-envoy restart the L7 listeners start accepting connections before the first NetworkPolicy update is installed, so a connection accepted in that window gets no policy filter state and every request on it answers 500 for as long as the client keeps it open, which this fixes by holding each listener's initialization until the first policy update is installed, or for at most 5 seconds so a stalled policy stream cannot keep listeners down.

Listeners started accepting connections before the first NetworkPolicy
update was installed, so connections accepted in that window had no
policy for local endpoints and every request on them failed with 500
for the lifetime of the connection. Each listener now waits for the
first policy update, or 5 seconds at most.

Signed-off-by: Mads Jon Nielsen <madsjon@gmail.com>
@firecow
firecow requested a review from a team as a code owner October 9, 2026 08:34
@firecow
firecow requested a review from nezdolik October 9, 2026 08:34
@moberghammer

Copy link
Copy Markdown

👍🏻

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants