Hi Serguei, On Wed, Nov 27, 2019 at 02:36:07PM +0000, Serguei Bezverkhi (sbezverk) wrote: > Thanks a lot for your reply, my ultimate goal is to develop kube-proxy which is building nftables rules instead of iptables, in addition the goal is to use direct API calls to netlink without any external dependencies and of course to try to leverage nftables' advanced features to achieve the best performance. > > I am in the process of identifying gaps in functionality available in github.com/google/nftables and github.com/sbezverk/nftableslib libraries, example yesterday I found out that neither of these libraries supports "numgen", which would be a mandatory feature to support load balancing between service's multiple end points. I will have to add it to both to be able to move forward. > I use iptables from a working cluster and try to build a code which would program nftables the same way (with optimization). Once it is done, then it can be arranged into a controller listening for svc/endpoints and program into nftables accordingly. > > I am looking for people interested in the same topic to be able to discuss different approaches, like it was done yesterday with Phil and select the best approach to make nftables to shine ( > > Please let me know if you are interested in further discussions. Yes, we're definitely interested further discussion/cooperation. You're using the JSON API for nftableslib, right? Cheers, Phil