Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

AKS Containerd localhost behavior different than upstream? #3303

Closed
jeff-mccoy opened this issue Nov 3, 2022 · 21 comments
Closed

AKS Containerd localhost behavior different than upstream? #3303

jeff-mccoy opened this issue Nov 3, 2022 · 21 comments
Labels
action-required Needs Attention 👋 Issues needs attention/assignee/owner question stale Stale issue

Comments

@jeff-mccoy
Copy link

Zarf uses a NodePort bound to 127.0.0.1 to connect to a local registry. On all other containerd-based clusters this allows us to point to 127.0.0.1 and containerd will use http instead of https. It seems there is something different happening on the azure version of containerd, even running crictl pull in a debug node on AKS demonstrates this behavior. Previously, this was not on an issue on AKS, but that was early this year. Is there something special that the Azure version of containerd is doing with localhost that differs from the upstream? Also is there a way to change this behavior or specify an insecure registry for localhost?

Related issues for zarf:

Screenshot 2022-11-02 at 7 07 08 PM
Screenshot 2022-11-02 at 7 06 14 PM
Screenshot 2022-11-02 at 7 05 54 PM

@jeff-mccoy
Copy link
Author

Update: looks like this was a bug that is now fixed in Containerd.

containerd/containerd#7438

@ghost
Copy link

ghost commented Dec 8, 2022

Action required from @Azure/aks-pm

@ghost ghost added the Needs Attention 👋 Issues needs attention/assignee/owner label Dec 8, 2022
@ghost
Copy link

ghost commented Dec 23, 2022

Issue needing attention of @Azure/aks-leads

2 similar comments
@ghost
Copy link

ghost commented Jan 7, 2023

Issue needing attention of @Azure/aks-leads

@ghost
Copy link

ghost commented Jan 22, 2023

Issue needing attention of @Azure/aks-leads

@jeff-mccoy
Copy link
Author

Also may be a security concern: GHSA-2qjp-425j-52j9.

@ghost
Copy link

ghost commented Feb 16, 2023

Issue needing attention of @Azure/aks-leads

11 similar comments
@ghost
Copy link

ghost commented Mar 3, 2023

Issue needing attention of @Azure/aks-leads

@ghost
Copy link

ghost commented Mar 18, 2023

Issue needing attention of @Azure/aks-leads

@ghost
Copy link

ghost commented Apr 2, 2023

Issue needing attention of @Azure/aks-leads

@ghost
Copy link

ghost commented Apr 18, 2023

Issue needing attention of @Azure/aks-leads

@ghost
Copy link

ghost commented May 4, 2023

Issue needing attention of @Azure/aks-leads

@ghost
Copy link

ghost commented May 19, 2023

Issue needing attention of @Azure/aks-leads

@ghost
Copy link

ghost commented Jun 3, 2023

Issue needing attention of @Azure/aks-leads

@ghost
Copy link

ghost commented Jun 18, 2023

Issue needing attention of @Azure/aks-leads

@ghost
Copy link

ghost commented Jul 4, 2023

Issue needing attention of @Azure/aks-leads

@ghost
Copy link

ghost commented Jul 19, 2023

Issue needing attention of @Azure/aks-leads

@ghost
Copy link

ghost commented Aug 3, 2023

Issue needing attention of @Azure/aks-leads

@microsoft-github-policy-service microsoft-github-policy-service bot added the stale Stale issue label Feb 2, 2024
Copy link
Contributor

This issue has been automatically marked as stale because it has not had any activity for 60 days. It will be closed if no further activity occurs within 15 days of this comment.

Copy link
Contributor

Issue needing attention of @Azure/aks-leads

Copy link
Contributor

This issue will now be closed because it hasn't had any activity for 7 days after stale. jeff-mccoy feel free to comment again on the next 7 days to reopen or open a new issue after that time if you still have a question/issue or suggestion.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
action-required Needs Attention 👋 Issues needs attention/assignee/owner question stale Stale issue
Projects
None yet
Development

No branches or pull requests

1 participant