一、Fix Fatal: can’t open lock file /run/xtables.lock: Read-only file system when use docker-desktop-for-mac:
kubectl get pods
docker ps | grep {YOUR_POD_NAME} | grep istio-proxy
docker inspect -f {{.State.Pid}} {CONTAINER_HASH}
docker run -it --rm --privileged --pid=host justincormack/nsenter1
nsenter -n -t {YOUR_CONTAINER_PID}
iptables -L