This page shows how to use Cilium for NetworkPolicy.
For background on Cilium, read the Introduction to Cilium.
You need to have a Kubernetes cluster, and the kubectl command-line tool must be configured to communicate with your cluster. If you do not already have a cluster, you can create one by using Minikube, or you can use one of these Kubernetes playgrounds:
To get familiar with Cilium easily you can follow the Cilium Kubernetes Getting Started Guide to perform a basic DaemonSet installation of Cilium in minikube.
Installation in a minikube setup uses a simple ‘‘all-in-one’’ YAML file that includes DaemonSet configurations for Cilium and a key-value store (consul) as well as appropriate RBAC settings:
$ kubectl create -f https://raw.githubusercontent.com/cilium/cilium/master/examples/minikube/cilium-ds.yaml clusterrole "cilium" created serviceaccount "cilium" created clusterrolebinding "cilium" created daemonset "cilium-consul" created daemonset "cilium" created
The remainder of the Getting Started Guide explains how to enforce both L3/L4 (i.e., IP address + port) security policies, as well as L7 (e.g., HTTP) security policies using an example application.
For detailed instructions around deploying Cilium for production, see: Cilium Administrator Guide This documentation includes detailed requirements, instructions and example production DaemonSet files.
Deploying a cluster with Cilium adds Pods to the
kube-system namespace. To see this list of Pods run:
kubectl get pods --namespace=kube-system
You’ll see a list of Pods similar to this:
NAME DESIRED CURRENT READY NODE-SELECTOR AGE cilium 1 1 1 <none> 2m ...
There are two main components to be aware of:
ciliumPod runs on each node in your cluster and enforces network policy on the traffic to/from Pods on that node using Linux BPF.
cilium-consulPod to provide a key-value store.
Once your cluster is running, you can follow the NetworkPolicy getting started guide to try out Kubernetes NetworkPolicy with Cilium. Have fun, and if you have questions, contact us using the Cilium Slack Channel.Create an Issue Edit this Page