DOCS-3001: Add the kernel 5.15 eBPF known issue for 3.33 - #3042
Merged
Merged
Conversation
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The workaround omits that AKS versions before 1.32 cannot use Ubuntu 24.04 without first upgrading Kubernetes.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Adds a Calico 3.33 known issue documenting an eBPF regression on Linux kernel 5.15.
Changes:
- Documents symptoms, affected AKS versions, and kernel scope.
- Provides upgrade or rollback guidance.
| File | Description |
|---|---|
calico_versioned_docs/version-3.33/release-notes/index.mdx |
Adds the kernel 5.15 eBPF known issue. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
||
| This affects AKS clusters running Kubernetes 1.25 through 1.34, whose default node image is Ubuntu 22.04 with kernel 5.15. | ||
| AKS 1.35 and later use Ubuntu 24.04 with kernel 6.8. | ||
| If you run the eBPF data plane on an affected cluster, move to a node image with kernel 6.8 or later, or stay on 3.32 until this is fixed. |
This was referenced Sep 28, 2026
ctauchen
force-pushed
the
publish/oss-3.33-known-issue
branch
from
September 29, 2026 20:12
d156326 to
9a35c11
Compare
danudey
added this pull request to stack #3049
October 2, 2026 00:19
✅ Deploy Preview for calico-docs-preview-next ready!
To edit notification comments on pull requests, go to your Netlify project configuration. |
✅ Deploy Preview succeeded!
To edit notification comments on pull requests, go to your Netlify project configuration. |
On kernel 5.15 the eBPF host endpoint program no longer fits inside the verifier's instruction limit, so it fails to load and calico-node restarts on some nodes. 5.15 is within the documented minimum of 5.10 and 3.32 loads on the same kernel, so this is a regression. It matters because 5.15 is the default node image kernel on AKS for Kubernetes 1.25 through 1.34, so the eBPF data plane does not start on a stock AKS cluster of those versions. Kept on its own branch so it can be dropped if the fix lands before the release.
Same facts, split so a reader can stop at the part they need: the symptom they would recognise, why it happens, and what to do about it. Previously all three were interleaved across three paragraphs.
danudey
force-pushed
the
publish/oss-3.33-known-issue
branch
from
October 2, 2026 00:24
9a35c11 to
b7a9ec1
Compare
| Felix reports `BPF program load failed permanently` for `from_hep_no_log.o`, and `calico-node` restarts on some nodes. | ||
|
|
||
| **Cause.** | ||
| The eBPF host endpoint program has grown past the kernel BPF verifier's limit of one million instructions, and Felix's fallback of disabling the optional programs does not bring it back under. |
| ### Calico Open Source 3.33.0 general availability release | ||
|
|
||
| September 29, 2026 | ||
| October 01, 2026 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Adds the one known issue for 3.33.
On kernel 5.15 the eBPF host endpoint program exceeds the verifier's one million instruction limit and does not load, and disabling the optional programs does not bring it back under. 5.15 is within the documented 5.10 minimum, and 3.32 loads the same program on the same kernel. It matters because 5.15 is the default AKS node image kernel for Kubernetes 1.25 through 1.34.
Kept on its own branch so it can be dropped if a fix lands first.
The note states only what is observed, and records that kernels between 5.10 and 6.8 other than 5.15 are untested.
Preview