Skip to content

Unsupported features

Everything Lace deliberately leaves out, and the gaps it has not closed yet. Anything not listed here behaves as the Kubernetes spec defines.

Lace will not implement these.

  • SCTP — the data plane carries TCP, UDP and ICMP. SCTP ports on a Service are ignored.
  • spec.externalIPs — addresses listed there are never translated to the Service’s endpoints. The field is deprecated as of Kubernetes 1.36 and scheduled for removal in 1.43; use LoadBalancer, NodePort or the Gateway API instead.
  • LoadBalancer Services of another implementation — a Service whose spec.loadBalancerClass names another implementation is left untouched, so no VIP is assigned. One that names no class is adopted only where a Lace class is marked as the cluster default. See LoadBalancer.
  • NodePorts dialled from the node itself, on that node’s own address — traffic a node addresses to itself never leaves its network namespace, so no Lace hook sees it and it reaches a port nothing listens on. Every other combination works: a node reaches any other node’s NodePort, Pods reach every node’s, and the Service’s ClusterIP is reachable from the node. See Node traffic.

Known gaps, intended to close.

  • hostPort — a port declared on a Pod is never published on its node, so nothing answers there.
  • Refusing a node port no Service claims — the connection is dropped rather than reset, so the client waits out its own timeout instead of failing immediately. A Service with no endpoints is refused correctly; this is the case where nothing claims the port at all.
  • Fragmented datagrams — a datagram large enough to be fragmented, or one carrying IP options, is dropped rather than forwarded, because the transport ports are not where the data plane expects them. Requests above roughly the interface MTU are affected; TCP is not, since it never fragments.