It turns out nftables is used by default on bottlerocket 1.5x and EKS 1.34 above. It is a good idea to configure kube-proxy and Istio with native nftables to avoid translation cost from iptables to nftables.
Architecturally @IstioMesh does a great job of adapter: integrating with @kubernetesio natively by watching its CRDs, translating them and pushing them via @EnvoyProxy 's data plane via xDS. The beauty of it: neither k8s and envoy realized otherwise.
@aantn Maybe creates a contoller that looks for this type of OOMkill pod, correlates the item, then puts the item on a new queue for further processing such as processing on high memory machine or instance types.
@ikoichi I love GCP for personal projects while use AWS or Azure for work only. I came from a developer bias and learnt a lot on DevOps and kuberbernets.
Learn how to create guardrails for your Amazon EKS clusters with Sentinel and HashiCorp #Terraform Cloud, and use CDK for Terraform to enable self-service workflows for developers to safely deploy EKS workloads to #AWS. https://t.co/hhK7cnrRBi