Sitelet https://github.com/kubernetes/kops/pull/18432/files
Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 3 additions & 1 deletion docs/networking/cilium.md
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,7 @@ Enable this by setting `--networking=cilium-eni` (as of kOps 1.26) or by specify
ipam: eni
```

In kOps versions before 1.22, when using ENI IPAM you need to explicitly disable masquerading in Cilium as well.
When using ENI IPAM, kOps enables masquerading by default. If pods in your cluster can reach external destinations without it — for example, nodes in private subnets behind a NAT gateway, or via VPC endpoints — you can disable masquerading to match Cilium's upstream default for ENI IPAM:

```yaml
networking:
Expand All @@ -131,6 +131,8 @@ In kOps versions before 1.22, when using ENI IPAM you need to explicitly disable
ipam: eni
```

Do not disable masquerading if pods rely on the node's address to reach external destinations (for example, nodes in public subnets without a NAT gateway), as their traffic would otherwise be dropped.

Note that since Cilium Operator is the entity that interacts with the EC2 API to provision and attaching ENIs, we force it to run on the master nodes when this IPAM is used.

Also note that this feature has only been tested on the default kOps AMIs.
Expand Down
3 changes: 0 additions & 3 deletions pkg/apis/kops/validation/validation.go
Original file line number Diff line number Diff line change
Expand Up @@ -1411,9 +1411,6 @@ func validateNetworkingCilium(cluster *kops.Cluster, v *kops.CiliumNetworkingSpe
if cluster.GetCloudProvider() != kops.CloudProviderAWS {
allErrs = append(allErrs, field.Forbidden(fldPath.Child("ipam"), "Cilum ENI IPAM is supported only in AWS"))
}
if v.Masquerade != nil && !*v.Masquerade {
allErrs = append(allErrs, field.Forbidden(fldPath.Child("masquerade"), "Masquerade must be enabled when ENI IPAM is used"))
}
if c.IsIPv6Only() {
allErrs = append(allErrs, field.Forbidden(fldPath.Child("ipam"), "Cilium ENI IPAM does not support IPv6"))
}
Expand Down
1 change: 0 additions & 1 deletion pkg/apis/kops/validation/validation_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -1220,7 +1220,6 @@ func Test_Validate_Cilium(t *testing.T) {
AWS: &kops.AWSSpec{},
},
},
ExpectedErrors: []string{"Forbidden::cilium.masquerade"},
},
{
Cilium: kops.CiliumNetworkingSpec{
Expand Down
Loading