Cutting TCP 7800 leaves cross-node refresh working (200), confirming sessions travel through PostgreSQL rather than the cluster transport. Logout is the opposite: the database row is deleted but the other node answers from its stale local cache, so the A-0 conclusion that invalidation rides the database is corrected here. Two things the plan did not anticipate: a NetworkPolicy cannot sever an established connection because conntrack accepts it before policy evaluation, and Keycloak reports the partition through its readiness probe so the split node removes itself from the Service. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
9 lines
302 B
Plaintext
9 lines
302 B
Plaintext
=== 차단 적용 ===
|
|
networkpolicy.networking.k8s.io/a1-block-jgroups-transport created
|
|
a1-block-jgroups-transport map[app:keycloak]
|
|
|
|
적용 시각: 11:38:08
|
|
=== FD_SOCK2 가 상대를 의심하기까지 기다린다 (15초 간격, 최대 3분) ===
|
|
+15초 suspected(k0 k1) =
|
|
→ 변화 감지
|