In a k8s pod with istio injected, why envoy call localhost,the packets pass PREROUTING chain

Viewed 405

as I know, when a process send packets, the packets should only pass iptables OUTPUT and POSTROUTING.

but when I tested in pod with istio injected. I found when envoy call localhost:xxx ,the packets truely pass PREROUTING and INPUT. why does this happend?

1 Answers

As mentioned in the istio iptables script.


INPUT is used to drop all inbound traffic except established connections.


PREROUTING is used to handle inbound ports. Traffic will be redirected to Envoy, which will process and forward to the local service. If not set, no inbound port will be intercepted by istio iptables.

According to proxy-redirection on github

Inbound

The iptable rule for inbound redirection is straightforward assuming all traffic needs to be redirected to the proxy. Additional rules are needed if inbound traffic needs to bypass the proxy, e.g. ssh.

iptables -t nat -A PREROUTING -p tcp -j REDIRECT --to-port ${ISTIO_PROXY_PORT}


There is the whole iptables schematic for istio, so you might actually check what PREROUTING and INPUT exactly does.

enter image description here


Additionally there is blog on medium about Understanding How Envoy Sidecar Intercept and Route Traffic in Istio Service Mesh. Worth to take a look if you want to understand the whole process.

Related