aws / aws/amazon-vpc-resource-controller-k8s

Allow debugging of trunk and branch interfaces using port mirroring and VPC flow logs

Open
#347 1 comment 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Go
Stars
106
Forks
71
Avg merge
10h 28m
Merged PRs (30d)
6

Description

**What would you like to be enhanced**:

1. AWS docs “[What is Traffic Mirroring?](https://docs.aws.amazon.com/vpc/latest/mirroring/what-is-traffic-mirroring.html)” states that only ENI of type “interface” are supported.
2. When Security Groups for Pods are enabled, trunk interfaces on supported instance types will be created and a correspomnding CloudWatch Log stream for the trunk ENI will be created. But there is no log stream for branch interfaces.

**Why is the change needed and what use case will it solve**:

1. Customer would like to debug trunk and branch interfaces using port mirroring
2. Customer would like to debug branch ENI by having a dedicated CW log stream for it.

Contributor guide

Open the contributing guide

Research direction

No files or tests are named. Start by tracing how Security Groups for Pods creates trunk and branch interfaces and their VPC flow-log streams; done means trunk and branch interfaces can be debugged with AWS Traffic Mirroring and branch ENIs receive dedicated CloudWatch log streams.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, go, kubernetes
Domain
cloud, networking, observability
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.