# cilium

## clusterDnsEgress

Allow every pod in the cluster to reach cluster DNS, as one
CiliumClusterwideNetworkPolicy\. Only emitted when
` policyEnforcementMode ` is “always”, which is this package’s
default\.

In that mode every pod in the cluster is in default deny, including
the ones Kix never writes a policy for: a ` kubectl run ` debug pod,
an operator’s own Job, anything in a namespace Kix does not manage\.
Kix writes DNS egress for the workloads it renders and for nothing
else, so without this those pods cannot resolve a name, and the
failure reads as a DNS outage rather than as a policy decision\.

Set it false to write that policy yourself\. Turning it off while
leaving enforcement at “always” means anything outside a Kix
namespace has no DNS\.

*Type:*
boolean

*Default:*

```nix
true
```

## values

Helm values to deep-merge with the chart’s package-level values\.

*Type:*
attribute set of anything

*Default:*

```nix
{ }
```