Skip to content

cilium

Allow every pod in the cluster to reach cluster DNS, as one CiliumClusterwideNetworkPolicy. Only emitted when policyEnforcementMode is “always”, which is this package’s default.

In that mode every pod in the cluster is in default deny, including the ones Kix never writes a policy for: a kubectl run debug pod, an operator’s own Job, anything in a namespace Kix does not manage. Kix writes DNS egress for the workloads it renders and for nothing else, so without this those pods cannot resolve a name, and the failure reads as a DNS outage rather than as a policy decision.

Set it false to write that policy yourself. Turning it off while leaving enforcement at “always” means anything outside a Kix namespace has no DNS.

Type: boolean

Default:

true

Helm values to deep-merge with the chart’s package-level values.

Type: attribute set of anything

Default:

{ }