- no logs for ziti-edge-tunnel
- no logs for ziti-router
- no ideas, what is going on.
- chatgpt is hallucinating
- I tried restarting the routers and the ziti-edge-tunnel, but it didn’t help.
How to reproduce?
I will use vault for example. It doesn’t matter.
host v2
ziti edge create config "vault.ziti@host2" host.v2 '{"terminators": [{"protocol":"tcp","address":"vault-active.vault.svc.cluster.local","port":8200}]}'
New config vault.ziti@host2 created with id: 6UN2wD8S6ef6ERulSruau3
host v1
For host.v1 everything is ok. Terminators will create automatically!
ziti edge create config "vault.ziti@host" host.v1 '{"protocol":"tcp","address":"vault-active.vault.svc.cluster.local","port":8200}'
New config vault.ziti@host created with id: ll8GaeRL4pJG4LQqgOGNv
intercept
ziti edge create config "vault.ziti@intercept" intercept.v1 '{"protocols":["tcp"],"addresses":["vault.ziti"],"portRanges":[{"low":8200,"high":8200}]}'
New config vault.ziti@intercept created with id: 7bM20F6CFAIHYonNnXymFv
Service
ziti edge create service "vault.ziti" --configs 'vault.ziti@host2,vault.ziti@intercept'
New service vault.ziti created with id: 6g3qxQFMN3nJjadv0WJ4Gi
Dial
ziti edge create service-policy "vault.ziti@dial" Dial --service-roles '@vault.ziti' --identity-roles '#all'
New service policy vault.ziti@dial created with id: 36qa1hThM9Mrn82oDStnbA
Bind
ziti edge create service-policy "vault.ziti@bind" Bind --service-roles '@vault.ziti' --identity-roles '#prod-xxx'
New service policy vault.ziti@bind created with id: 5SbRbfaekqUStnZqOs1lwq
Results
Host V2
Host V1
Lets try to switch to Host V1. For host.v1 everything is ok. Terminators will create automatically!

