ISTIO CNI drops initContainers outgoing traffic



ISTIO-CNI updates the IPTABLES (to route all outbound traffic through istio-proxy port 15001) along with pod network setup. We have initcontainers that make outbound calls, So initContainers outbound traffic are routed to port 15001 and get dropped.

If the outbound traffic is destined to particular set of CIDRs, we can workaround by excluding through annotation " ". else initcontainer fails and blocking the pod to be up.