Skip to content

Commit 8816a85

Browse files
committed
adjust doc mark
Signed-off-by: aicee <hhbin2000@foxmail.com>
1 parent 300e594 commit 8816a85

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

docs/proposal/kmesh_support_encrypt.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -246,9 +246,9 @@ CRD数据结构定义如下:
246246

247247
# policy配置
248248

249-
ip xfrm policy add src 0.0.0.0/0 dst {\$对端CIDR} dir out tmpl src 7.6.122.84 dst 7.6.122.220 proto esp spi 0x1 reqid 1 mode tunnel mark 0x000000e0 mask 0xffff
250-
ip xfrm policy add src 0.0.0.0/0 dst {\$本端CIDR} dir in tmpl src 7.6.122.220 dst 7.6.122.84 proto esp reqid 1 mode tunnel mark 0x000000d0 mask 0xfffffff
251-
ip xfrm policy add src 0.0.0.0/0 dst {\$本端CIDR} dir fwd tmpl src 7.6.122.220 dst 7.6.122.84 proto esp reqid 1 mode tunnel mark 0x000000d0 mask 0xfffffff
249+
ip xfrm policy add src 0.0.0.0/0 dst {\$对端CIDR} dir out tmpl src 7.6.122.84 dst 7.6.122.220 proto esp spi 0x1 reqid 1 mode tunnel mark 0x000000e0 mask 0xffffffff
250+
ip xfrm policy add src 0.0.0.0/0 dst {\$本端CIDR} dir in tmpl src 7.6.122.220 dst 7.6.122.84 proto esp reqid 1 mode tunnel mark 0x000000d0 mask 0xffffffff
251+
ip xfrm policy add src 0.0.0.0/0 dst {\$本端CIDR} dir fwd tmpl src 7.6.122.220 dst 7.6.122.84 proto esp reqid 1 mode tunnel mark 0x000000d0 mask 0xffffffff
252252

253253
- 更新lpm前缀树map,key为对端CIDR地址,value当前全部设置为1,tc根据目标pod ip在前缀树找到记录,确定对端pod为Kmesh纳管,为流量打上对应的加密标签
254254
- Kmesh-daemon将本端的spi、IPsec设备ip、podCIDRs更新到api-server中,触发其他节点更新机器上的IPsec配置

0 commit comments

Comments
 (0)