PageSourceSearch

https://archive-os-3-28.netlify.app/assets/js/184a250c.f01166a4.js

js archive-os-3-28.netlify.app collected 2026-10-03 11:36:00 UTC 23,784 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["4502"],{34450:function(e,n,i){i.r(n),i.d(n,{frontMatter:()=>r,toc:()=>t,default:()=>h,metadata:()=>o,assets:()=>a,contentTitle:()=>c});var o=JSON.parse('{"id":"operations/troubleshoot/commands","title":"Troubleshooting commands","description":"Learn basic commands to verify cluster and components are working.","source":"@site/calico_versioned_docs/version-3.28/operations/troubleshoot/commands.mdx","sourceDirName":"operations/troubleshoot","slug":"/operations/troubleshoot/commands","permalink":"/calico/3.28/operations/troubleshoot/commands","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico_versioned_docs/version-3.28/operations/troubleshoot/commands.mdx","tags":[],"version":"3.28","frontMatter":{"description":"Learn basic commands to verify cluster and components are working."},"sidebar":"calicoSidebar","previous":{"title":"Troubleshooting and diagnostics","permalink":"/calico/3.28/operations/troubleshoot/troubleshooting"},"next":{"title":"Component logs","permalink":"/calico/3.28/operations/troubleshoot/component-logs"}}'),s=i(37937),l=i(17869);let r={description:"Learn basic commands to verify cluster and components are working."},c="Troubleshooting commands",a={},t=[{value:"Big picture",id:"big-picture",level:2},{value:"Hosts",id:"hosts",level:2},{value:"Verify number of nodes in a cluster",id:"verify-number-of-nodes-in-a-cluster",level:3},{value:"Verify calico-node pods are running on every node, and are in a healthy state",id:"verify-calico-node-pods-are-running-on-every-node-and-are-in-a-healthy-state",level:3},{value:"Exec into pod for further troubleshooting",id:"exec-into-pod-for-further-troubleshooting",level:3},{value:"Collect Calico diagnostic logs",id:"collect-calico-diagnostic-logs",level:3},{value:"Kubernetes",id:"kubernetes",level:2},{value:"Verify all pods are running",id:"verify-all-pods-are-running",level:3},{value:"Verify Kubernetes API server is running",id:"verify-kubernetes-api-server-is-running",level:3},{value:"Verify Kubernetes kube-dns is working",id:"verify-kubernetes-kube-dns-is-working",level:3},{value:"Verify that kubelet is running on the node with the correct flags",id:"verify-that-kubelet-is-running-on-the-node-with-the-correct-flags",level:3},{value:"Check the status of other system pods",id:"check-the-status-of-other-system-pods",level:3},{value:"Calico components",id:"calico-components",level:2},{value:"View Calico CNI configuration on a node",id:"view-calico-cni-configuration-on-a-node",level:3},{value:"Verify calicoctl matches cluster",id:"verify-calicoctl-matches-cluster",level:3},{value:"Check Tigera Operator status",id:"check-tigera-operator-status",level:3},{value:"Check if operator pod is running",id:"check-if-operator-pod-is-running",level:3},{value:"View calico nodes",id:"view-calico-nodes",level:3},{value:"View Calico installation parameters",id:"view-calico-installation-parameters",level:3},{value:"Run commands across multiple nodes",id:"run-commands-across-multiple-nodes",level:3},{value:"View pod info",id:"view-pod-info",level:3},{value:"View logs of a pod",id:"view-logs-of-a-pod",level:3},{value:"View kubelet logs",id:"view-kubelet-logs",level:3},{value:"Routing",id:"routing",level:2},{value:"Verify routing table on the node",id:"verify-routing-table-on-the-node",level:3},{value:"Verify BGP peer status",id:"verify-bgp-peer-status",level:3},{value:"Verify overlay configuration",id:"verify-overlay-configuration",level:3},{value:"Verify bgp learned routes",id:"verify-bgp-learned-routes",level:3},{value:"Verify BIRD routing table",id:"verify-bird-routing-table",level:3},{value:"Capture traffic",id:"capture-traffic",level:3},{value:"Network policy",id:"network-policy",level:2},{value:"Verify existing Kubernetes network policies",id:"verify-existing-kubernetes-network-policies",level:3},{value:"Verify existing Calico network policies",id:"verify-existing-calico-network-policies",level:3},{value:"Verify existing Calico global network policies",id:"verify-existing-calico-global-network-policies",level:3},{value:"Check policy selectors and order",id:"check-policy-selectors-and-order",level:3}];function d(e){let n={a:"a",admonition:"admonition",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,l.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(n.header,{children:(0,s.jsx)(n.h1,{id:"troubleshooting-commands",children:"Troubleshooting commands"})}),"\n",(0,s.jsx)(n.h2,{id:"big-picture",children:"Big picture"}),"\n",(0,s.jsx)(n.p,{children:"Use command line tools to get status and troubleshoot."}),"\n",(0,s.jsxs)(n.ul,{children:["\n",(0,s.jsx)(n.li,{children:(0,s.jsx)(n.a,{href:"#hosts",children:"Hosts"})}),"\n",(0,s.jsx)(n.li,{children:(0,s.jsx)(n.a,{href:"#kubernetes",children:"Kubernetes"})}),"\n",(0,s.jsx)(n.li,{children:(0,s.jsx)(n.a,{href:"#calico-components",children:"Calico components"})}
1),"\n",(0,s.jsx)(n.li,{children:(0,s.jsx)(n.a,{href:"#routing",children:"Routing"})}),"\n",(0,s.jsx)(n.li,{children:(0,s.jsx)(n.a,{href:"#network-policy",children:"Network policy"})}),"\n"]}),"\n",(0,s.jsx)(n.admonition,{type:"note",children:(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.code,{children:"calico-system"})," is used for operator-based commands and examples; for manifest-based install, use ",(0,s.jsx)(n.code,{children:"kube-system"}),"."]})}),"\n",(0,s.jsxs)(n.p,{children:["See ",(0,s.jsx)(n.a,{href:"/calico/3.28/reference/architecture/overview",children:"Calico architecture and components"})," for help with components."]}),"\n",(0,s.jsx)(n.h2,{id:"hosts",children:"Hosts"}),"\n",(0,s.jsx)(n.h3,{id:"verify-number-of-nodes-in-a-cluster",children:"Verify number of nodes in a cluster"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get nodes\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"\nNAME           STATUS   ROLES    AGE   VERSION\nip-10-0-0-10   Ready    master   27h   v1.18.0\nip-10-0-0-11   Ready    <none>   27h   v1.18.0\nip-10-0-0-12   Ready    <none>   27h   v1.18.0\n\n"})}),"\n",(0,s.jsx)(n.h3,{id:"verify-calico-node-pods-are-running-on-every-node-and-are-in-a-healthy-state",children:"Verify calico-node pods are running on every node, and are in a healthy state"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get pods -n calico-system -o wide\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"NAME                        READY   STATUS    RESTARTS   AGE   IP             NODE\ncalico-node-77zgj           1/1     Running   0          27h   10.0.0.10      ip-10-0-0-10\ncalico-node-nz8k2           1/1     Running   0          27h   10.0.0.11      ip-10-0-0-11\ncalico-node-7trv7           1/1     Running   0          27h   10.0.0.12      ip-10-0-0-12\n"})}),"\n",(0,s.jsx)(n.h3,{id:"exec-into-pod-for-further-troubleshooting",children:"Exec into pod for further troubleshooting"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl run multitool --image=praqma/network-multitool\n\nkubectl exec -it multitool -- bash\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"bash-5.0 ping 8.8.8.8\nPING 8.8.8.8 (8.8.8.8) 56(84) bytes of data.\n64 bytes from 8.8.8.8: icmp_seq=1 ttl=97 time=6.61 ms\n64 bytes from 8.8.8.8: icmp_seq=2 ttl=97 time=6.64 ms\n"})}),"\n",(0,s.jsx)(n.h3,{id:"collect-calico-diagnostic-logs",children:"Collect Calico diagnostic logs"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"sudo calicoctl node diags\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"Collecting diagnostics\nUsing temp dir: /tmp/calico194224816\nDumping netstat\nDumping routes (IPv4)\nDumping routes (IPv6)\nDumping interface info (IPv4)\nDumping interface info (IPv6)\nDumping iptables (IPv4)\nDumping iptables (IPv6)\n\nDiags saved to /tmp/calico194224816/diags-20201127_010117.tar.gz\n"})}),"\n",(0,s.jsx)(n.h2,{id:"kubernetes",children:"Kubernetes"}),"\n",(0,s.jsx)(n.h3,{id:"verify-all-pods-are-running",children:"Verify all pods are running"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get pods -A\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"kube-system       coredns-66bff467f8-dxbtl                   1/1     Running   0          27h\nkube-system       coredns-66bff467f8-n95vq                   1/1     Running   0          27h\nkube-system       etcd-ip-10-0-0-10                          1/1     Running   0          27h\nkube-system       kube-apiserver-ip-10-0-0-10                1/1     Running   0          27h\n"})}),"\n",(0,s.jsx)(n.h3,{id:"verify-kubernetes-api-server-is-running",children:"Verify Kubernetes API server is running"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl cluster-info\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"Kubernetes master is running at https://10.0.0.10:6443\nKubeDNS is running at https://10.0.0.10:6443/api/v1/namespaces/kube-system/services/kube-dns:dns/proxy\nubuntu@master:~$ kubectl get svc\nNAME         TYPE        CLUSTER-IP   EXTERNAL-IP   PORT(S)   AGE\nkubernetes   ClusterIP   10.49.0.1    <none>        443/TCP   2d2h\n"})}),"\n",(0,s.jsx)(n.h3,{id:"verify-kubernetes-kube-dns-is-working",children:"Verify Kubernetes kube-dns is working"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get svc\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"NAME         TYPE        CLUSTER-IP   EXTERNAL-IP   PORT(S)   AGE\nkubernetes   ClusterIP   10.49.0.1    <none>        443/TCP   2d2h\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl exec -it multitool  bash\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"bash-5.0 curl -I -k https://kubernetes\nHTTP/2 403\ncache-control: no-cache, private\ncontent-type: application/json\nx-content-type-options: nosniff\ncontent-length: 234\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"bash-5.0 nslookup google.com\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"Server:         10.49.0.10\nAddress:        10.49.0.10#53\nNon-authoritative answer:\nName:   google.com\nAddress: 172.217.14.238\nName:   google.com\nAddress: 2607:f8b0:400a:804::200e\n"})}),"\n",(0,s.jsx)(n.h3,{id:"verify-that-kubelet-is-running-on-the-node-with-the-correct-flags",children:"Verify that kubelet is running on the node with the correct flags"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"systemctl status kubelet\n"})}),"\n",(0,s.jsx)(n.p,{children:"If there is a problem, check the journal"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"journalctl -u kubelet | head\n"})}),"\n",(0,s.jsx)(n.h3,{id:"check-the-status-of-other-system-pods",children:"Check the status of other system pods"}),"\n",(0,s.jsx)(n.p,{children:"Look especially at coredns; if they are not getting an IP, something is wrong with the CNI"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get pod -n kube-system -o wide\n"})}),"\n",(0,s.jsx)(n.p,{children:"But if other pods fail, it is likely a different issue. Perform normal Kubernetes troubleshooting. For example:"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl describe pod kube-scheduler-ip-10-0-1-20.eu-west-1.compute.internal -n kube-system | tail -15\n"})}),"\n",(0,s.jsx)(n.h2,{id:"calico-components",children:"Calico components"}),"\n",(0,s.jsx)(n.h3,{id:"view-calico-cni-configuration-on-a-node",children:"View Calico CNI configuration on a node"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"cat /etc/cni/net.d/10-calico.conflist\n"})}),"\n",(0,s.jsx)(n.h3,{id:"verify-calicoctl-matches-cluster",children:"Verify calicoctl matches cluster"}),"\n",(0,s.jsx)(n.p,{children:"The cluster version and type must match the calicoctl version."}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"calicoctl version\n"})}),"\n",(0,s.jsx)(n.p,{children:"For syntax:"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"calicoctl version -help\n"})}),"\n",(0,s.jsx)(n.h3,{id:"check-tigera-operator-status",children:"Check Tigera Operator status"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get tigerastatus\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"NAME     AVAILABLE   PROGRESSING   DEGRADED   SINCE\ncalico   True        False         False      27h\n"})}),"\n",(0,s.jsx)(n.h3,{id:"check-if-operator-pod-is-running",children:"Check if operator pod is running"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get pod -n tigera-operator\n"})}),"\n",(0,s.jsx)(n.h3,{id:"view-calico-nodes",children:"View calico nodes"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get pod -n calico-system -o wide\n"})}),"\n",(0,s.jsx)(n.h3,{id:"view-calico-installation-parameters",children:"View Calico installation parameters"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get installation -o yaml\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yaml",children:"apiVersion: v1\nitems:\n- apiVersion: operator.tigera.io/v1\n  kind: Installation\n  metadata:\n    - apiVersion: operator.tigera.io/v1\n  spec:\n    calicoNetwork:\n      bgp: Enabled\n      hostPorts: 
1Enabled\n      ipPools:\n      - blockSize: 26\n        cidr: 10.48.0.0/16\n        encapsulation: VXLANCrossSubnet\n        natOutgoing: Enabled\n        nodeSelector: all()\n      multiInterfaceMode: None\n      nodeAddressAutodetectionV4:\n        firstFound: true\n    cni:\n      ipam:\n        type: Calico\n      type: Calico\n"})}),"\n",(0,s.jsx)(n.h3,{id:"run-commands-across-multiple-nodes",children:"Run commands across multiple nodes"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:'export THE_COMMAND_TO_RUN=date && for calinode in `kubectl get pod -o wide -n calico-system | grep calico-node | awk \'{print $1}\'`; do echo $calinode; echo "-----"; kubectl exec -n calico-system $calinode -- $THE_COMMAND_TO_RUN; printf "\\n"; done\n'})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:'calico-node-87lpx\n-----\nDefaulted container "calico-node" out of: calico-node, flexvol-driver (init), install-cni (init)\nThu Apr 28 13:48:06 UTC 2022\n\ncalico-node-x5fmm\n-----\nDefaulted container "calico-node" out of: calico-node, flexvol-driver (init), install-cni (init)\nThu Apr 28 13:48:07 UTC 2022\n\n'})}),"\n",(0,s.jsx)(n.h3,{id:"view-pod-info",children:"View pod info"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl describe pods `<pod_name>`  -n `<namespace> `\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl describe pods busybox -n default\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:'Events:\n  Type    Reason     Age   From                   Message\n  ----    ------     ----  ----                   -------\n  Normal  Scheduled  21s   default-scheduler      Successfully assigned default/busybox to ip-10-0-0-11\n  Normal  Pulling    20s   kubelet, ip-10-0-0-11  Pulling image "busybox"\n  Normal  Pulled     19s   kubelet, ip-10-0-0-11  Successfully pulled image "busybox"\n  Normal  Created    19s   kubelet, ip-10-0-0-11  Created container busybox\n  Normal  Started    18s   kubelet, ip-10-0-0-11  Started container busybox\n'})}),"\n",(0,s.jsx)(n.h3,{id:"view-logs-of-a-pod",children:"View logs of a pod"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl logs `<pod_name>`  -n `<namespace>`\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl logs busybox -n default\n"})}),"\n",(0,s.jsx)(n.h3,{id:"view-kubelet-logs",children:"View kubelet logs"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"journalctl -u kubelet\n"})}),"\n",(0,s.jsx)(n.h2,{id:"routing",children:"Routing"}),"\n",(0,s.jsx)(n.h3,{id:"verify-routing-table-on-the-node",children:"Verify routing table on the node"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"ip route\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"default via 10.0.0.1 dev eth0 proto dhcp src 10.0.0.10 metric 100\n10.0.0.0/24 dev eth0 proto kernel scope link src 10.0.0.10\n10.0.0.1 dev eth0 proto dhcp scope link src 10.0.0.10 metric 100\n10.48.66.128/26 via 10.0.0.12 dev eth0 proto 80 onlink\n10.48.231.0/26 via 10.0.0.11 dev eth0 proto 80 onlink\n172.17.0.0/16 dev docker0 proto kernel scope link src 172.17.0.1 linkdown\n"})}),"\n",(0,s.jsx)(n.h3,{id:"verify-bgp-peer-status",children:"Verify BGP peer status"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"sudo calicoctl node status\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"Calico process is running.\n\nIPv4 BGP status\n+--------------+-------------------+-------+------------+-------------+\n| PEER ADDRESS |     PEER TYPE     | STATE |   SINCE    |    INFO     |\n+--------------+-------------------+-------+------------+-------------+\n| 10.0.0.12    | node-to-node mesh | up    | 2020-11-25 | Established |\n| 10.0.0.11    | node-to-node mesh | up    | 2020-11-25 | Established |\n+--------------+-------------------+-------+------------+-------------+\n"})}),"\n",(0,s.jsx)(n.h3,{id:"verify-overlay-configuration",children:"Verify overlay configuration"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get ippools default-ipv4-ippo
1ol -o yaml\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-yaml",children:"\n---\nspec:\n  ipipMode: Always\n  vxlanMode: Never\n"})}),"\n",(0,s.jsx)(n.h3,{id:"verify-bgp-learned-routes",children:"Verify bgp learned routes"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"ip r | grep bird\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"192.168.66.128/26 via 10.0.0.12 dev tunl0 proto bird onlink\n192.168.180.192/26 via 10.0.0.10 dev tunl0 proto bird onlink\nblackhole 192.168.231.0/26 proto bird\n"})}),"\n",(0,s.jsx)(n.h3,{id:"verify-bird-routing-table",children:"Verify BIRD routing table"}),"\n",(0,s.jsxs)(n.p,{children:[(0,s.jsx)(n.strong,{children:"Note"}),": The BIRD routing table gets pushed to node routing tables."]}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl exec -it -n calico-system calico-node-8cfc8 -- /bin/bash\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"[root@ip-10-0-0-11 /] birdcl\nBIRD v0.3.3+birdv1.6.8 ready.\nbird> show route\n0.0.0.0/0          via 10.0.0.1 on eth0 [kernel1 18:13:33] * (10)\n10.0.0.0/24        dev eth0 [direct1 18:13:32] * (240)\n10.0.0.1/32        dev eth0 [kernel1 18:13:33] * (10)\n10.48.231.2/32     dev calieb874a8ef0b [kernel1 18:13:41] * (10)\n10.48.231.1/32     dev caliaeaa173109d [kernel1 18:13:35] * (10)\n10.48.231.0/26     blackhole [static1 18:13:32] * (200)\n10.48.231.0/32     dev vxlan.calico [direct1 18:13:32] * (240)\n10.48.180.192/26   via 10.0.0.10 on eth0 [Mesh_10_0_0_10 18:13:34] * (100/0) [i]\n                   via 10.0.0.10 on eth0 [Mesh_10_0_0_12 18:13:41 from 10.0.0.12] (100/0) [i]\n                   via 10.0.0.10 on eth0 [kernel1 18:13:33] (10)\n10.48.66.128/26    via 10.0.0.12 on eth0 [Mesh_10_0_0_10 18:13:36 from 10.0.0.10] * (100/0) [i]\n                   via 10.0.0.12 on eth0 [Mesh_10_0_0_12 18:13:41] (100/0) [i]\n                   via 10.0.0.12 on eth0 [kernel1 18:13:36] (10)\n"})}),"\n",(0,s.jsx)(n.h3,{id:"capture-traffic",children:"Capture traffic"}),"\n",(0,s.jsx)(n.p,{children:"For example,"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"sudo tcpdump -i calicofac0017c3 icmp\n"})}),"\n",(0,s.jsx)(n.h2,{id:"network-policy",children:"Network policy"}),"\n",(0,s.jsx)(n.h3,{id:"verify-existing-kubernetes-network-policies",children:"Verify existing Kubernetes network policies"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get networkpolicy --all-namespaces\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"NAMESPACE   NAME             POD-SELECTOR   AGE\nclient      allow-ui         <none>         20m\nclient      default-deny     <none>         4h51m\nstars       allow-ui         <none>         20m\nstars       backend-policy   role=backend   20m\nstars       default-deny     <none>         4h51m\n"})}),"\n",(0,s.jsx)(n.h3,{id:"verify-existing-calico-network-policies",children:"Verify existing Calico network policies"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"calicoctl get networkpolicy --all-namespaces -o wide\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"NAMESPACE     NAME                         ORDER   SELECTOR\ncalico-demo   allow-busybox                50      app == 'porter'\nclient        knp.default.allow-ui         1000    projectcalico.org/orchestrator == 'k8s'\nclient        knp.default.default-deny     1000    projectcalico.org/orchestrator == 'k8s'\nstars         knp.default.allow-ui         1000    projectcalico.org/orchestrator == 'k8s'\nstars         knp.default.backend-policy   1000    projectcalico.org/orchestrator == 'k8s'\nstars         knp.default.default-deny     1000    projectcalico.org/orchestrator == 'k8s'\n"})}),"\n",(0,s.jsx)(n.h3,{id:"verify-existing-calico-global-network-policies",children:"Verify existing Calico global network policies"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"calicoctl get globalnetworkpolicy -o wide\n"})}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{children:"NAME                  ORDER   SELECTOR\ndefault-app-policy    100\negress-lockdown       600\ndefault-node
1-policy   100     has(kubernetes.io/hostname)\nnodeport-policy       100     has(kubernetes.io/hostname)\n"})}),"\n",(0,s.jsx)(n.h3,{id:"check-policy-selectors-and-order",children:"Check policy selectors and order"}),"\n",(0,s.jsx)(n.p,{children:"For example,"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"calicoctl get np -n yaobank -o wide\n"})}),"\n",(0,s.jsx)(n.p,{children:"If the selectors should match, check the endpoint IP and the node where it is running. For example,"}),"\n",(0,s.jsx)(n.pre,{children:(0,s.jsx)(n.code,{className:"language-bash",children:"kubectl get pod -l app=customer -n yaobank\n"})})]})}function h(e={}){let{wrapper:n}={...(0,l.R)(),...e.components};return n?(0,s.jsx)(n,{...e,children:(0,s.jsx)(d,{...e})}):d(e)}},17869:function(e,n,i){i.d(n,{R:()=>r,x:()=>c});var o=i(82645);let s={},l=o.createContext(s);function r(e){let n=o.useContext(l);return o.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function c(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:r(e.components),o.createElement(l.Provider,{value:n},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.