mirror of
https://gitlab.kube.huskypup.net/Scooby/Homelabv4.git
synced 2026-08-21 05:26:49 +00:00
Initial commit
This commit is contained in:
@@ -0,0 +1,120 @@
|
||||
# Cilium CNI - eBPF-based networking with kube-proxy replacement
|
||||
# Replaces: Calico CNI + kube-proxy + MetalLB
|
||||
|
||||
# Full kube-proxy replacement via eBPF
|
||||
kubeProxyReplacement: true
|
||||
k8sServiceHost: 172.28.101.40
|
||||
k8sServicePort: 6443
|
||||
|
||||
# IPAM - use existing pod CIDR
|
||||
ipam:
|
||||
mode: kubernetes
|
||||
operator:
|
||||
clusterPoolIPv4PodCIDRList:
|
||||
- "10.244.0.0/16"
|
||||
|
||||
# Explicitly set devices to avoid using leftover Calico tunl0 interface
|
||||
devices: "ens+"
|
||||
|
||||
# Native routing (no encapsulation overhead)
|
||||
routingMode: native
|
||||
autoDirectNodeRoutes: true
|
||||
ipv4NativeRoutingCIDR: "10.244.0.0/16"
|
||||
|
||||
# eBPF features
|
||||
bpf:
|
||||
masquerade: false # Must be false for Istio ambient (breaks link-local SNAT for health probes)
|
||||
tproxy: true
|
||||
lbExternalClusterIP: true
|
||||
hostLegacyRouting: true # Use iptables host routing (eBPF host routing drops 169.254.7.127 packets)
|
||||
|
||||
# Socket LB - restrict to host namespace for Istio ambient compatibility
|
||||
socketLB:
|
||||
hostNamespaceOnly: true
|
||||
|
||||
# L2 announcements (replaces MetalLB)
|
||||
l2announcements:
|
||||
enabled: true
|
||||
|
||||
# Allow istio-cni to coexist
|
||||
cni:
|
||||
exclusive: false
|
||||
|
||||
# Hubble observability
|
||||
hubble:
|
||||
enabled: true
|
||||
relay:
|
||||
enabled: true
|
||||
resources:
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
memory: 256Mi
|
||||
ui:
|
||||
enabled: true
|
||||
resources:
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
memory: 128Mi
|
||||
metrics:
|
||||
enabled:
|
||||
- dns
|
||||
- drop
|
||||
- tcp
|
||||
- flow
|
||||
- port-distribution
|
||||
- icmp
|
||||
- httpV2:exemplars=true;labelsContext=source_ip,source_namespace,source_workload,destination_ip,destination_namespace,destination_workload,traffic_direction
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
labels:
|
||||
release: kube-prometheus-stack
|
||||
|
||||
# Operator settings
|
||||
operator:
|
||||
replicas: 1
|
||||
resources:
|
||||
requests:
|
||||
cpu: 10m
|
||||
memory: 64Mi
|
||||
limits:
|
||||
memory: 256Mi
|
||||
|
||||
# Agent resources
|
||||
resources:
|
||||
requests:
|
||||
cpu: 50m
|
||||
memory: 128Mi
|
||||
limits:
|
||||
memory: 512Mi
|
||||
|
||||
# Prometheus metrics
|
||||
prometheus:
|
||||
enabled: true
|
||||
serviceMonitor:
|
||||
enabled: true
|
||||
labels:
|
||||
release: kube-prometheus-stack
|
||||
|
||||
# Security
|
||||
securityContext:
|
||||
capabilities:
|
||||
ciliumAgent:
|
||||
- CHOWN
|
||||
- KILL
|
||||
- NET_ADMIN
|
||||
- NET_RAW
|
||||
- IPC_LOCK
|
||||
- SYS_ADMIN
|
||||
- SYS_RESOURCE
|
||||
- DAC_OVERRIDE
|
||||
- FOWNER
|
||||
- SETGID
|
||||
- SETUID
|
||||
cleanCiliumState:
|
||||
- NET_ADMIN
|
||||
- SYS_ADMIN
|
||||
- SYS_RESOURCE
|
||||
Reference in New Issue
Block a user