Skip to main content

Illumio Segmentation for Kubernetes

Resolved Issues in 5.3.1

This section provides a list of resolved issues in Release 5.3.1.

Resolved Issues

Issue

Description

E-123084

Kubelink: wrong LabelMap feature flag for older 24.x PCE versions

Kubelink incorrectly interpreted some older PCE versions as higher (more recent) than 24.5, which enabled the LabelMap feature for PCE versions that do not support it. This caused Kubelink 5.3.0 to be incompatible with many older 24.x PCE versions.

E-123080

Kubelink: labels defined by Container Workload Profile are ignored when Kubelink restarts

Kubelink was not receiving accurate data for workloads using managed Container Workload Profiles. So when Kubelink restarted, it might use out-of-date Container Workload Profile data and improperly remove or mislabel some workloads, causing incorrect policies.

E-122830

Kubelink: skip of ACK of unknown workload causes repeated policy calculations and sets ACK 

Part of the policy Kubelink received from the PCE for disconnected C-VENs was not being acknowledged back to the PCE, which caused unnecessary policy calculations and high PCE load.

E-122553

C-VEN 23.4.x fw_tampering_revert_failure after upgrade 

False-positive firewall tamper alerts ("VEN firewall tampered") appeared after upgrading to C-VEN 23.x, because of the old and unused Illumio iptables chain.

E-122422

C-VEN activation failing 

In some cases, attempts to bring onboard and pair a second Kubernetes AWS EKS cluster were failing to activate the C-VENs.

E-122306

Kubelink: One service appears multiple times in service update 

Kubelink was sending one service multiple times in an update request to PCE, which caused multiple duplicates of Service Backends, and slowed PCE responsiveness. Older Kubelink 3.1.x and 4.x also have this issue and should be upgraded to Kubelink 5.3.0, either using Helm chart 5.3.0, or by using YAML files generated from this Helm chart version. Kubelink 5.3.0 in non-CLAS mode is backward compatible with all currently supported PCE versions.

E-121122

C-VEN: False positive vulnerability detection on Quay 

The Quay vulnerability scanner falsely detected C-VEN as having high severity vulnerabilities.

E-120773

Increasing memory use and "out of memory errors" occur on 22.5.14 C-VEN nodes

Resolved intermittent "out of memory" occurrences in C-VEN 22.5.14.