Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 7 additions & 0 deletions kubernetes/infra/networking/cilium/README.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
# Cilium

Cilium provides the cluster datapath, kube-proxy replacement, Gateway API implementation, and Hubble observability.

The `devices` selector is restricted to the nodes' physical `enp+` interfaces. Talos-level overlays such as NetBird's `wt0` are not cluster-facing devices and must not participate in Cilium device or MTU detection. This keeps the pod datapath aligned with the physical LAN while NetBird remains available for node recovery access.

After changing device selection, verify that every Cilium agent lists only its physical NIC under `Devices`, reports the physical-network MTU, and that pod egress works over both UDP and TCP.
3 changes: 3 additions & 0 deletions kubernetes/infra/networking/cilium/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,9 @@ cgroup:
autoMount:
enabled: false
hostRoot: /sys/fs/cgroup
# NetBird's wt0 interface is an overlay, not a cluster-facing device. Restrict
# Cilium to the physical NICs so wt0 cannot lower the pod network MTU.
devices: "enp+"
hubble:
enabled: true
metrics:
Expand Down
Loading