An Openshift cluster utilizing Antrea CNI (version 2.3.1) and the Antrea Egress feature is experiencing intermittent and unpredictable loss of external network connectivity for specific containers.
VMware Container Networking with Antrea
The root cause is a fundamental design behavior within the Antrea Egress feature when handling multiple, overlapping policies.
The Egress policies must be reconfigured to ensure policy alignment and eliminate the condition that triggers the random selection behavior.
(Choose One)
Note: The lack of an explicit priority system for the Egress resource is a current design limitation. It is recommended to submit a feature request to the Antrea community for the implementation of an egress priority or weighting system to allow for explicit control over policy precedence in the future.