iptables-restore high cpu usage in OpenShift
Issue
OpenShift nodes have a very high load average and top output reports the iptables-restore process is using most CPU. For example:
# top
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
99226 root 20 0 62180 18080 976 R 100.0 0.0 0:05.58 iptables-restor
121061 root 20 0 6014480 520156 38272 S 41.5 0.1 18136:02 openshift
103066 root 20 0 38.003g 1.948g 17444 S 19.8 0.4 14173:02 dockerd-current
89157 root 20 0 2674184 58408 3480 S 15.2 0.0 3435:29 rhel-push-plugi
...
Environment
- Red Hat OpenShift Container Platform 3.5 and earlier
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase of over 48,000 articles and solutions.
Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.
