Kubernetes networking with Edera
Kubernetes networking with Edera
For Edera-managed pods, Edera should seamlessly use your existing cluster CNI configuration to set up networking for Edera pods, via the cri-shim to containerd.
The following CNIs have been tested with Edera:
Cilium
Both IPv4 and IPv6 mode supported.
When using Cilium’s kube-proxy-replacement with Edera, the in-pod socket-level loadbalancer must be disabled for pods by configuring Cilium with socketLB.hostNamespaceOnly=true.
See upstream Cilium docs for more details.
Flannel
Both IPv4 and IPv6 mode supported.
AWS VPC-CNI
Both IPv4 and IPv6 mode supported.
ipvlan
L2, L3, and L3s modes are supported, under both IPv4 and IPv6.
Currently, Edera does not support Multus or CNI configurations that configure multiple links for a single pod.
Debugging
The Edera component containerd-shim-edera-v2 reports any errors back through standard containerd flows. Containerd logs should be the first place to look for issues, which you can reach using journalctl -u containerd.
Legacy protect-cri
Before v1.12 these configurations were handled by the protect-cri component. Current versions of Edera utilize a CRI-shim and everything flows through containerd. You can choose to install the legacy protect-cri service by passing --env EDERA_PROTECT_INSTALLER_CONTAINERD_SHIM=false to the Edera Installer.
If you are running in this mode, errors and logs will be reported through systemd status and journald logs for the protect-cri service.
Related, if your CNI setups use a nonstandard CNI plugin binary or configuration paths, you will have updates in /var/lib/edera/protect/cri.toml with the nonstandard paths, and may need to restart the protect-cri service via sudo systemctl restart protect-cri the first time you use it.
If there is a CNI misconfiguration, the protect-cri systemd service should report the error and refuse to start. You can check the status of protect-cri with sudo systemctl status protect-cri on an Edera-enabled node. You can check the logs with sudo journalctl -u protect-cri.