You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: pkg/preflights/host-preflight.yaml
+65-1Lines changed: 65 additions & 1 deletion
Original file line number
Diff line number
Diff line change
@@ -14,6 +14,7 @@ spec:
14
14
- cpu: {}
15
15
- time: {}
16
16
- ipv4Interfaces: {}
17
+
- kernelModules: {}
17
18
- run:
18
19
collectorName: 'ip-route-table'
19
20
command: 'ip'
@@ -927,8 +928,71 @@ spec:
927
928
when: 'net.ipv4.ip_forward == 0'
928
929
message: "IP forwarding must be enabled. To enable it, edit /etc/sysctl.conf, add or uncomment the line 'net.ipv4.ip_forward=1', and run 'sudo sysctl -p'."
929
930
- pass:
930
-
when: 'net.ipv4.ip_forward > 0'
931
+
when: 'net.ipv4.ip_forward == 1'
931
932
message: "IP forwarding is enabled."
933
+
- sysctl:
934
+
checkName: "IP forwarding for all interfaces"
935
+
outcomes:
936
+
- fail:
937
+
when: 'net.ipv4.conf.all.forwarding == 0'
938
+
message: "IP forwarding must be enabled. To enable it, edit /etc/sysctl.conf, add or uncomment the line 'net.ipv4.conf.all.forwarding=1', and run 'sudo sysctl -p'."
939
+
- pass:
940
+
when: 'net.ipv4.conf.all.forwarding == 1'
941
+
message: "IP forwarding is enabled."
942
+
- sysctl:
943
+
checkName: "IP forwarding for the default interface"
944
+
outcomes:
945
+
- fail:
946
+
when: 'net.ipv4.conf.default.forwarding == 0'
947
+
message: "IP forwarding must be enabled. To enable it, edit /etc/sysctl.conf, add or uncomment the line 'net.ipv4.conf.default.forwarding=1', and run 'sudo sysctl -p'."
948
+
- pass:
949
+
when: 'net.ipv4.conf.default.forwarding == 1'
950
+
message: "IP forwarding is enabled."
951
+
- sysctl:
952
+
checkName: "Bridge netfilter call iptables"
953
+
outcomes:
954
+
- fail:
955
+
when: 'net.bridge.bridge-nf-call-iptables == 0'
956
+
message: "Bridge netfilter call iptables must be enabled. To enable it, edit /etc/sysctl.conf, add or uncomment the line 'net.bridge.bridge-nf-call-iptables=1', and run 'sudo sysctl -p'."
957
+
- pass:
958
+
when: 'net.bridge.bridge-nf-call-iptables == 1'
959
+
message: "Bridge netfilter call iptables is enabled."
960
+
- kernelModules:
961
+
checkName: "Overlay kernel module"
962
+
outcomes:
963
+
- fail:
964
+
when: "overlay != loaded,loadable"
965
+
message: The 'overlay' kernel module is not loaded or loadable
966
+
- pass:
967
+
when: "overlay == loaded,loadable"
968
+
message: The 'overlay' kernel module is loaded or loadable
969
+
- kernelModules:
970
+
checkName: "IP tables kernel module"
971
+
outcomes:
972
+
- fail:
973
+
when: "ip_tables != loaded,loadable"
974
+
message: The 'ip_tables' kernel module is not loaded or loadable
975
+
- pass:
976
+
when: "ip_tables == loaded,loadable"
977
+
message: The 'ip_tables' kernel module is loaded or loadable
978
+
- kernelModules:
979
+
checkName: "BR Netfilter kernel module"
980
+
outcomes:
981
+
- fail:
982
+
when: "br_netfilter != loaded,loadable"
983
+
message: The 'br_netfilter' kernel module is not loaded or loadable
984
+
- pass:
985
+
when: "br_netfilter == loaded,loadable"
986
+
message: The 'br_netfilter' kernel module is loaded or loadable
987
+
- kernelModules:
988
+
checkName: "NF Conntrack kernel module"
989
+
outcomes:
990
+
- fail:
991
+
when: "nf_conntrack != loaded,loadable"
992
+
message: The 'nf_conntrack' kernel module is not loaded or loadable
993
+
- pass:
994
+
when: "nf_conntrack == loaded,loadable"
995
+
message: The 'nf_conntrack' kernel module is loaded or loadable
0 commit comments