Description
--make-iptables-util-chains=false disables kubelet management of iptables utility chains. Connectivity can be affected when network components depend on those chains.
The managed chains vary by Kubernetes version. The current KubeletConfiguration reference describes makeIPTablesUtilChains as creating KUBE-IPTABLES-HINT to inform other components about the iptables configuration. Check the network plugin and firewall policies separately.
Potential impact
- Missing utility chains can affect components that depend on them.
- Differences between nodes can cause operational network issues.
Remediation
- Check the node version and network plugin requirements, and retain
makeIPTablesUtilChains: truewhere it is needed. - The equivalent legacy command-line option is
--make-iptables-util-chains=true. Review both effective configuration and startup arguments. - After changes, verify that required communication works and unwanted access is blocked.
Examples
These excerpts compare command arguments. foo/bar is a placeholder image; deploying this Pod does not reconfigure the node’s kubelet. Apply the setting through the supported configuration method for the actual node version.
Before
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: foo/bar
command: ["kubelet"]
args: ["--make-iptables-util-chains=false"]
After
apiVersion: v1
kind: Pod
metadata:
name: command-demo
spec:
containers:
- name: command-demo-container
image: foo/bar
command: ["kubelet"]
args: ["--make-iptables-util-chains=true"]
Explanation:
- Before: Utility-chain management is disabled. The actual effect depends on the node version and network configuration.
- After: Utility-chain management is enabled. This option alone does not establish a complete firewall or NetworkPolicy.