Fixes
- Hardens the node-local edge proxy for large uploads from Apple Container VMs.
- Clamps the proxy's backend TCP MSS so the proxy does not recreate the same TSO/veth checksum stall on its node-to-pod leg.
- Redirects node-originated LoadBalancer traffic through a lightweight OUTPUT hook, so
curl $LB_IPfrom another cluster node follows the same safe path. - Maps LoadBalancer service ports to their allocated NodePorts internally, keeping kube-proxy as the backend selector while avoiding the problematic service-port forwarding path.
Verified
Fresh 1 control-plane + 3 worker cluster with --observability --gateway:
- 1 MiB NodePort uploads from worker-2 and worker-3: HTTP 200, full byte count
- 1 MiB LoadBalancer uploads from worker-2 and worker-3: HTTP 200, full byte count
- 1 MiB NodePort and LoadBalancer uploads from a non-cluster Apple Container VM with TSO on: HTTP 200, full byte count
- Gateway API HTTPRoute curl succeeds
- Grafana health succeeds
- Prometheus scraped the annotated sample app
kubectl top nodesreports all four nodes- local-path StatefulSet PVCs bind and pods run on workers
Full Changelog: v0.3.1...v0.3.2