Skip to content

Install Cilium / network policy support

Use the cilium package to make Kix responsible for the Cilium CNI and the CiliumNetworkPolicy API.

This guide uses a new Kind cluster. Cilium must be the cluster’s CNI from the start, so create Kind without its default CNI before deploying the example.

Create this Kind configuration beside the kix-examples checkout:

kind-cilium.yaml
kind: Cluster
apiVersion: kind.x-k8s.io/v1alpha4
networking:
disableDefaultCNI: true
podSubnet: "10.244.0.0/16"

Create the cluster:

❱ kind create cluster --config kind-cilium.yaml

The control-plane node remains NotReady until Cilium is deployed. That is expected for a cluster with no CNI.

Tell Kix that the Kind environment is not providing a CNI, then enable network policy generation:

how-to/package-stacks/cilium-cluster.nix (L17–L24)
# The Kind cluster for this example is created without kindnet, so the
# CNI role is available for a managed package.
cluster.roles.cni = {
binding = "absent";
provider = null;
};
networkPolicy.enable = true;

View source on GitHub ↗

The role setting must describe the cluster you actually created. Do not mark the role absent on a Kind cluster that is already running kindnet.

Install Cilium in kube-system:

how-to/package-stacks/cilium-cluster.nix (L28–L37)
instances.kube-system.cilium = {
package = packages.cilium;
config.values = {
# Keep Kind's kube-proxy and use the pod CIDR from kind-cilium.yaml.
kubeProxyReplacement = false;
ipam.operator.clusterPoolIPv4PodCIDRList = [ "10.244.0.0/16" ];
prometheus.enabled = false;
};
};

View source on GitHub ↗

kubeProxyReplacement = false keeps Kind’s kube-proxy. The Cilium IPAM range matches podSubnet in kind-cilium.yaml.

Evaluate the cluster before deploying it:

Run in kix-examples/
❱ kix check how-to-package-cilium
 TOOL         RESULT  DETAILS                                                       
 eval         pass    34 manifests evaluated                                        
 kubeconform  pass    skipped (this validation tool is not yet integrated with Kix) 
 pluto        pass    skipped (this validation tool is not yet integrated with Kix) 
 kyverno      pass    skipped (this validation tool is not yet integrated with Kix) 
 scorecard    pass    0 errors, 36 warnings, 4 info

Inspect the main Cilium components and a generated default-deny policy:

Run in kix-examples/ Output excerpt
❱ kix build how-to-package-cilium --output json
[
  {
    "apiVersion": "apps/v1",
    "kind": "DaemonSet",
    "metadata": {
      "name": "cilium",
      "namespace": "kube-system"
    },
    "containers": [
      {
        "name": "cilium-agent",
        "image": "quay.io/cilium/cilium:v1.19.6@sha256:0df5b2750b64c49843aba1d649e9eaf61467cb0645ad3171db6f6962c095ac92"
      }
    ]
  },
  {
    "apiVersion": "apps/v1",
    "kind": "Deployment",
    "metadata": {
      "name": "cilium-operator",
      "namespace": "kube-system"
    },
    "containers": [
      {
        "name": "cilium-operator",
        "image": "quay.io/cilium/operator-generic:v1.19.6@sha256:0db4ca4e06969d8904ee036617795d0e9c3228cf7b8d902ba74fc2bb98d2d665"
      }
    ]
  },
  {
    "apiVersion": "cilium.io/v2",
    "kind": "CiliumNetworkPolicy",
    "metadata": {
      "name": "kube-system-default-deny",
      "namespace": "kube-system"
    },
    "spec": {
      "egress": [
        {}
      ],
      "endpointSelector": {},
      "ingress": [
        {}
      ]
    }
  }
]

Kix builds the Cilium DaemonSet and operator from the package, then connects generated policies to Cilium’s custom resource definitions in the deployment graph.

Deploy the cluster and wait for the Cilium pods to become ready:

Run in kix-examples/
❱ kix deploy how-to-package-cilium
❱ kubectl rollout status -n kube-system daemonset/cilium
❱ kubectl get nodes

The Kind node should report Ready after the Cilium DaemonSet is running. Check the generated policies with:

❱ kubectl get ciliumnetworkpolicies --all-namespaces

If the node remains NotReady, compare the pod CIDR in the Kind configuration with clusterPoolIPv4PodCIDRList, then inspect the Cilium pod logs in kube-system.