iptables-restore high cpu usage in OpenShift

Solution Verified - Updated -

Issue

OpenShift nodes have a very high load average and top output reports the iptables-restore process is using most CPU. For example:

# top
   PID USER      PR  NI    VIRT    RES    SHR S  %CPU %MEM     TIME+ COMMAND
 99226 root      20   0   62180  18080    976 R 100.0  0.0   0:05.58 iptables-restor
121061 root      20   0 6014480 520156  38272 S  41.5  0.1  18136:02 openshift
103066 root      20   0 38.003g 1.948g  17444 S  19.8  0.4  14173:02 dockerd-current
 89157 root      20   0 2674184  58408   3480 S  15.2  0.0   3435:29 rhel-push-plugi
 ...

Environment

  • Red Hat OpenShift Container Platform 3.5 and earlier

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content