The VPC peerings are dropping non-VM packets. That's unfortunately
the state of things for now. The solution, as you show here, is to
masquerade. The downside is that you lose the original pod's IP in
the packet.
We've added support for IP aliases, which should be beta in OSS in
v1.7 (and probably alpha in GKE at first), which will remove this
restriction. We're also working on a more configurable way to manage
the masquerade rules, so you can tweak it in small way, instead of the
single kubelet flag we have today.
> --
> You received this message because you are subscribed to the Google Groups
> "Kubernetes user discussion and Q&A" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to
kubernetes-use...@googlegroups.com.
> To post to this group, send email to
kubernet...@googlegroups.com.
> Visit this group at
https://groups.google.com/group/kubernetes-users.
> For more options, visit
https://groups.google.com/d/optout.