Install Cilium / network policy support
This content is for the v0.1 version. Switch to the latest version for up-to-date documentation.
Use the cilium package to make Kix responsible for the Cilium CNI and the
CiliumNetworkPolicy API.
This guide uses a new Kind cluster. Cilium must be the cluster’s CNI from the start, so create Kind without its default CNI before deploying the example.
Create the Kind cluster
Section titled “Create the Kind cluster”Create this Kind configuration beside the kix-examples checkout:
kind: ClusterapiVersion: kind.x-k8s.io/v1alpha4networking: disableDefaultCNI: true podSubnet: "10.244.0.0/16"Create the cluster:
❱ kind create cluster --config kind-cilium.yaml The control-plane node remains NotReady until Cilium is deployed. That is
expected for a cluster with no CNI.
Make the CNI role available
Section titled “Make the CNI role available”Tell Kix that the Kind environment is not providing a CNI, then enable network policy generation:
# The Kind cluster for this example is created without kindnet, so the # CNI role is available for a managed package. cluster.roles.cni = { binding = "absent"; provider = null; };
networkPolicy.enable = true;The role setting must describe the cluster you actually created. Do not mark the role absent on a Kind cluster that is already running kindnet.
Add the Cilium instance
Section titled “Add the Cilium instance”Install Cilium in kube-system:
instances.kube-system.cilium = { package = packages.cilium; config.values = { # Keep Kind's kube-proxy and use the pod CIDR from kind-cilium.yaml. kubeProxyReplacement = false; ipam.operator.clusterPoolIPv4PodCIDRList = [ "10.244.0.0/16" ];
prometheus.enabled = false; }; };kubeProxyReplacement = false keeps Kind’s kube-proxy. The Cilium IPAM range
matches podSubnet in kind-cilium.yaml.
Check the generated resources
Section titled “Check the generated resources”Evaluate the cluster before deploying it:
❱ kix check how-to-package-cilium
TOOL RESULT DETAILS
eval pass 34 manifests evaluated
kubeconform pass skipped (this validation tool is not yet integrated with Kix)
pluto pass skipped (this validation tool is not yet integrated with Kix)
kyverno pass skipped (this validation tool is not yet integrated with Kix)
scorecard pass 0 errors, 36 warnings, 4 info Inspect the main Cilium components and a generated default-deny policy:
❱ kix build how-to-package-cilium --output json
[
{
"apiVersion": "apps/v1",
"kind": "DaemonSet",
"metadata": {
"name": "cilium",
"namespace": "kube-system"
},
"containers": [
{
"name": "cilium-agent",
"image": "quay.io/cilium/cilium:v1.19.6@sha256:0df5b2750b64c49843aba1d649e9eaf61467cb0645ad3171db6f6962c095ac92"
}
]
},
{
"apiVersion": "apps/v1",
"kind": "Deployment",
"metadata": {
"name": "cilium-operator",
"namespace": "kube-system"
},
"containers": [
{
"name": "cilium-operator",
"image": "quay.io/cilium/operator-generic:v1.19.6@sha256:0db4ca4e06969d8904ee036617795d0e9c3228cf7b8d902ba74fc2bb98d2d665"
}
]
},
{
"apiVersion": "cilium.io/v2",
"kind": "CiliumNetworkPolicy",
"metadata": {
"name": "kube-system-default-deny",
"namespace": "kube-system"
},
"spec": {
"egress": [
{}
],
"endpointSelector": {},
"ingress": [
{}
]
}
}
] Kix builds the Cilium DaemonSet and operator from the package, then connects generated policies to Cilium’s custom resource definitions in the deployment graph.
Deploy and verify Cilium
Section titled “Deploy and verify Cilium”Deploy the cluster and wait for the Cilium pods to become ready:
❱ kix deploy how-to-package-cilium❱ kubectl rollout status -n kube-system daemonset/cilium❱ kubectl get nodes The Kind node should report Ready after the Cilium DaemonSet is running.
Check the generated policies with:
❱ kubectl get ciliumnetworkpolicies --all-namespaces If the node remains NotReady, compare the pod CIDR in the Kind configuration
with clusterPoolIPv4PodCIDRList, then inspect the Cilium pod logs in
kube-system.