From e28af3ce45648a7b633e93f89c474b39ff88305b Mon Sep 17 00:00:00 2001 From: Scot Wells Date: Thu, 27 Aug 2026 17:28:43 -0500 Subject: [PATCH] fix: make the VRF sidecar's NET_ADMIN effective Kubernetes does not set ambient capabilities, so an added capability only enters the effective set for uid 0. The sidecar image is distroless:nonroot, so NET_ADMIN was declared and inert, and creating the VRF device failed with EPERM. Match the staging channel, which carries the same fix, so dev and e2e do not diverge from what the edge runs. Key changes: - Run the sidecar as uid 0 in the dev and e2e downstream configs --- config/dev/downstream_resources/downstream-gateway.yaml | 1 + config/e2e-downstream/envoyproxy.yaml | 1 + 2 files changed, 2 insertions(+) diff --git a/config/dev/downstream_resources/downstream-gateway.yaml b/config/dev/downstream_resources/downstream-gateway.yaml index 98c2dfaf..66f50159 100644 --- a/config/dev/downstream_resources/downstream-gateway.yaml +++ b/config/dev/downstream_resources/downstream-gateway.yaml @@ -84,6 +84,7 @@ spec: args: - --metrics-port=9182 securityContext: + runAsUser: 0 capabilities: drop: - ALL diff --git a/config/e2e-downstream/envoyproxy.yaml b/config/e2e-downstream/envoyproxy.yaml index 56935d12..07c007d6 100644 --- a/config/e2e-downstream/envoyproxy.yaml +++ b/config/e2e-downstream/envoyproxy.yaml @@ -35,6 +35,7 @@ spec: args: - --metrics-port=9182 securityContext: + runAsUser: 0 capabilities: drop: - ALL