From 8e6aa9f0064f94613b542f628b14a1176bccfeab Mon Sep 17 00:00:00 2001 From: Pragalva Sapkota Date: Sat, 15 Aug 2026 23:16:39 +0545 Subject: [PATCH] fix(cilium): select physical devices Signed-off-by: Pragalva Sapkota --- kubernetes/infra/networking/cilium/README.md | 7 +++++++ kubernetes/infra/networking/cilium/values.yaml | 3 +++ 2 files changed, 10 insertions(+) create mode 100644 kubernetes/infra/networking/cilium/README.md diff --git a/kubernetes/infra/networking/cilium/README.md b/kubernetes/infra/networking/cilium/README.md new file mode 100644 index 0000000..f881869 --- /dev/null +++ b/kubernetes/infra/networking/cilium/README.md @@ -0,0 +1,7 @@ +# Cilium + +Cilium provides the cluster datapath, kube-proxy replacement, Gateway API implementation, and Hubble observability. + +The `devices` selector is restricted to the nodes' physical `enp+` interfaces. Talos-level overlays such as NetBird's `wt0` are not cluster-facing devices and must not participate in Cilium device or MTU detection. This keeps the pod datapath aligned with the physical LAN while NetBird remains available for node recovery access. + +After changing device selection, verify that every Cilium agent lists only its physical NIC under `Devices`, reports the physical-network MTU, and that pod egress works over both UDP and TCP. diff --git a/kubernetes/infra/networking/cilium/values.yaml b/kubernetes/infra/networking/cilium/values.yaml index e0c7f55..c37b35d 100644 --- a/kubernetes/infra/networking/cilium/values.yaml +++ b/kubernetes/infra/networking/cilium/values.yaml @@ -2,6 +2,9 @@ cgroup: autoMount: enabled: false hostRoot: /sys/fs/cgroup +# NetBird's wt0 interface is an overlay, not a cluster-facing device. Restrict +# Cilium to the physical NICs so wt0 cannot lower the pod network MTU. +devices: "enp+" hubble: enabled: true metrics: