# cilium

## clusterDnsEgress

Allow every pod in the cluster to reach cluster DNS, as one
CiliumClusterwideNetworkPolicy. Only emitted when
`policyEnforcementMode` is “always”, which is this package’s
default.

In that mode every pod in the cluster is in default deny, including
the ones Kix never writes a policy for: a `kubectl run` debug pod,
an operator’s own Job, anything in a namespace Kix does not manage.
Kix writes DNS egress for the workloads it renders and for nothing
else, so without this those pods cannot resolve a name, and the
failure reads as a DNS outage rather than as a policy decision.

Set it false to write that policy yourself. Turning it off while
leaving enforcement at “always” means anything outside a Kix
namespace has no DNS.

*Type:*
boolean

*Default:*

```nix
true
```

## values

Helm values to deep-merge with the chart’s package-level values.

*Type:*
attribute set of anything

*Default:*

```nix
{ }
```