Repository navigation
netlink List implementation - #38
Conversation
fcd74dc to
93119c2
Compare
5dd8893 to
f66b4f6
Compare
In general if you are listing large numbers of rules, you're probably doing something wrong anyway, in terms of good nftables architecture. (kube-proxy never calls We could optimize the This would be less memory-efficient than the current system in the case where someone lists a lot of rules and then keeps a handle to just one of them, but again, "probably doing something wrong anyway". (Despite what the comment says, neither the old nor the new code sets |
87ac32d to
45d427b
Compare
41f4670 to
94c2b8e
Compare
|
@danwinship what do we want to do with this? do we wait? |
|
I think we should backport the |
|
I see you already tagged itv0.0.21 with the terse fix |
Implement List() and ListAll() methods using netlink to avoid the overhead of calling the nft user space progam and parsing its output. Also, reducing the exposure to bugs or problems caused by skew versions of the binary when running inside containers. hack/benchmark.sh Running benchmarks in a new network namespace... goos: linux goarch: amd64 pkg: sigs.k8s.io/knftables cpu: Intel(R) Xeon(R) CPU @ 2.60GHz BenchmarkListChains_NFT_10-48 470 2478369 ns/op 66330 B/op 355 allocs/op BenchmarkListChains_NFT_100-48 387 3078343 ns/op 194767 B/op 2528 allocs/op BenchmarkListChains_NFT_1000-48 132 9170438 ns/op 1426811 B/op 24140 allocs/op BenchmarkListChains_NFT_10000-48 15 72816515 ns/op 13834120 B/op 240164 allocs/op BenchmarkListChains_Netlink_10-48 15865 70282 ns/op 23651 B/op 185 allocs/op BenchmarkListChains_Netlink_100-48 6636 171288 ns/op 84800 B/op 1059 allocs/op BenchmarkListChains_Netlink_1000-48 1080 1139143 ns/op 747940 B/op 9727 allocs/op BenchmarkListChains_Netlink_10000-48 60 22861672 ns/op 8053831 B/op 96576 allocs/op PASS ok sigs.k8s.io/knftables 14.964s
|
@danwinship finally get to it, addressed your comments and bumped dependencies, there is some work needed to fix the jobs with the golang update |
| on: [pull_request] | ||
| name: Test | ||
| env: | ||
| GO_VERSION: 1.25.x |
There was a problem hiding this comment.
should we be doing the .go-version thing like other repos?
|
/lgtm we can do .go-version later if we want |
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: aojea, danwinship The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
Implement List() method using netlink directly to avoid the overhead of
calling the nft user space progam and parsing its output. Also, reducing
the exposure to bugs or problems caused by skew versions of the binary
when running inside containers.