tag: cilium
- Bare-metal k8s: keep Cilium L2 LoadBalancer & node maintenance reliable Make Cilium L2 LoadBalancer IPs stable on bare-metal Kubernetes, tune node networking, and keep upgrades and reboots from breaking reachability.
- Kubespray: a Dedicated Control Plane and Two Workers to Offload a Saturated Node Splitting an overloaded single Kubernetes node into a dedicated control plane plus two workers with Kubespray v2.31: inventory, Cilium, and workload isolation.
- Cilium L2 LoadBalancer on bare-metal k3s No cloud controller, no MetalLB — Cilium's built-in L2 announcements assign LoadBalancer IPs on bare-metal k3s using ARP.
- Cilium NetworkPolicy: default-deny and DNS-aware rules Default-deny ingress per namespace, allow from APISIX, CiliumNetworkPolicy toFQDNs for external APIs, L7 HTTP path rules, cluster-wide Prometheus scrape policy.
- Cilium network policy: default-deny and workload isolation Default-deny CiliumNetworkPolicy per namespace, selective allow rules for DNS, ingress controller, inter-service traffic, FQDN-based egress policies, and L7 HTTP policy for path-level control.
- Hubble: network observability built into Cilium Hubble UI and Relay setup in Cilium, flow inspection with hubble observe, DNS query visibility, policy verdict monitoring, and building Grafana dashboards from Hubble Prometheus metrics.
- Cilium as kube-proxy replacement with L2 LoadBalancer on k3s k3s installation without kube-proxy, Cilium Helm values for kube-proxy replacement mode, L2 announcement CiliumLoadBalancerIPPool and CiliumL2AnnouncementPolicy, and BGP alternative comparison.
No posts match the selected filters.