diff --git a/docs/centos.md b/docs/centos.md index 160e092b1efd156c90a9e76945f3daa91b3b8624..12c27ea667668156eb54447fbd2a88595cbc75e2 100644 --- a/docs/centos.md +++ b/docs/centos.md @@ -9,7 +9,7 @@ Kubespray supports multiple ansible versions but only the default (5.x) gets wid CentOS 8 / Oracle Linux 8 / AlmaLinux 8 / Rocky Linux 8 ship only with iptables-nft (ie without iptables-legacy similar to RHEL8) The only tested configuration for now is using Calico CNI -You need to add `calico_iptables_backend: "NFT"` or `calico_iptables_backend: "Auto"` to your configuration. +You need to add `calico_iptables_backend: "NFT"` to your configuration. If you have containers that are using iptables in the host network namespace (`hostNetwork=true`), you need to ensure they are using iptables-nft.