Enabling multicast for a project
In OpenShift Container Platform with OVN-Kubernetes, you can enable IP multicast on a per-project basis so pods can send and receive multicast traffic.
About multicast
With IP multicast in OpenShift Container Platform, data is broadcast to many IP addresses simultaneously. With OVN-Kubernetes, multicast is off by default and is not affected by network policies when you enable it in a project.
- At this time, multicast is best used for low-bandwidth coordination or service discovery and not a high-bandwidth solution.
- By default, network policies affect all connections in a namespace. However, multicast is unaffected by network policies. If multicast is enabled in the same namespace as your network policies, it is always allowed, even if there is a
deny-allnetwork policy. - Cluster administrators must consider the implications of the exemption of multicast from network policies before enabling it.
Multicast traffic between OpenShift Container Platform pods is disabled by default. If you are using the OVN-Kubernetes network plugin, you can enable multicast on a per-project basis.
Enable multicast between pods
To enable multicast between pods in a project, you can add the k8s.ovn.org/multicast-enabled annotation to the namespace by using the oc annotate command or a namespace manifest.
Prerequisites
- Install the OpenShift CLI (
oc). - You must log in to the cluster with a user that has the
cluster-adminrole.
Procedure
-
Run the following command to enable multicast for a project. Replace
<namespace>with the namespace for the project you want to enable multicast for.$ oc annotate namespace <namespace> \k8s.ovn.org/multicast-enabled=truetipYou can alternatively apply the following YAML to add the annotation:
apiVersion: v1kind: Namespacemetadata:name: <namespace>annotations:k8s.ovn.org/multicast-enabled: "true"
Verification
To verify that multicast is enabled for a project, complete the following procedure:
- Change your current project to the project that you enabled multicast for. Replace
<project>with the project name.$ oc project <project> - Create a pod to act as a multicast receiver:
$ cat <<EOF| oc create -f -apiVersion: v1kind: Podmetadata:name: mlistenerlabels:app: multicast-verifyspec:containers:- name: mlistenerimage: registry.access.redhat.com/ubi9command: ["/bin/sh", "-c"]args:["dnf -y install socat hostname && sleep inf"]ports:- containerPort: 30102name: mlistenerprotocol: UDPEOF
- Create a pod to act as a multicast sender:
$ cat <<EOF| oc create -f -apiVersion: v1kind: Podmetadata:name: msenderlabels:app: multicast-verifyspec:containers:- name: msenderimage: registry.access.redhat.com/ubi9command: ["/bin/sh", "-c"]args:["dnf -y install socat && sleep inf"]EOF
- In a new terminal window or tab, start the multicast listener.
- Get the IP address for the Pod:
$ POD_IP=$(oc get pods mlistener -o jsonpath='{.status.podIP}')
- Start the multicast listener by entering the following command:
$ oc exec mlistener -i -t -- \socat UDP4-RECVFROM:30102,ip-add-membership=224.1.0.1:$POD_IP,fork EXEC:hostname
- Get the IP address for the Pod:
- Start the multicast transmitter.
-
Get the pod network IP address range:
$ CIDR=$(oc get Network.config.openshift.io cluster \-o jsonpath='{.status.clusterNetwork[0].cidr}') -
To send a multicast message, enter the following command:
$ oc exec msender -i -t -- \/bin/bash -c "echo | socat STDIO UDP4-DATAGRAM:224.1.0.1:30102,range=$CIDR,ip-multicast-ttl=64"If multicast is working, the previous command returns the following output:
mlistener
-