diff --git a/cluster/README.md b/cluster/README.md index bee2ef8..aae5411 100644 --- a/cluster/README.md +++ b/cluster/README.md @@ -186,8 +186,13 @@ EOF ### casa - control Plane - k3s setup ``` bash -curl -sfL https://get.k3s.io | INSTALL_K3S_VERSION=v1.36.1+k3s1 sh - -``` +curl -sfL https://get.k3s.io | INSTALL_K3S_VERSION=v1.36.1+k3s1 \ +INSTALL_K3S_EXEC="\ +--flannel-backend=none \ +--disable-network-policy \ +--disable=servicelb" \ + sh - + ``` **Taint NoSchedule on master node:** diff --git a/services/cilium/deploy/README.md b/services/cilium/deploy/README.md new file mode 100644 index 0000000..8cdc1f1 --- /dev/null +++ b/services/cilium/deploy/README.md @@ -0,0 +1,27 @@ +# Cilium + + + + +## setup and deploy + +Using flux for reconciliation. + +**Restart:** + +Occasionally, Cilium's eBPF maps for L2 announcements can get "stale" after a configuration change (like switching from Local to Cluster). Perform a rolling restart of the Cilium pods to clear the state: + +```bash +``` + +``` bash +POD_NAME=$(kubectl get pod -l 'app.kubernetes.io/name'=cilium-agent -n cilium -o jsonpath='{.items[0].metadata.name}') +kubectl exec -n cilium ${POD_NAME} -c cilium-agent -- cilium-dbg status +``` + +**list load balancers ip pools:** +*Required after changes* + +```bash +kubectl get CiliumLoadBalancerIPPool -A +``` diff --git a/services/cilium/deploy/app/helm-release.yaml b/services/cilium/deploy/app/helm-release.yaml index 1850ad3..a6245c6 100644 --- a/services/cilium/deploy/app/helm-release.yaml +++ b/services/cilium/deploy/app/helm-release.yaml @@ -8,8 +8,17 @@ spec: chart: spec: chart: cilium - version: 1.18.2 + version: 1.19.5 sourceRef: kind: HelmRepository name: cilium interval: 40h + values: + kubeProxyReplacement: true + installCRDs: true + routingMode: native + enableIPv4Masquerade: false # using bpf.masquerade: true + autoDirectNodeRoutes: true + bpf: + masquerade: true + hostLegacyRouting: false # force use of bfp diff --git a/services/cilium/deploy/flux/app-sync.yaml b/services/cilium/deploy/flux/app-sync.yaml index 58b4c23..f174e28 100644 --- a/services/cilium/deploy/flux/app-sync.yaml +++ b/services/cilium/deploy/flux/app-sync.yaml @@ -7,6 +7,6 @@ spec: sourceRef: kind: GitRepository name: casa - namespace: flux-system + namespace: casa-limbosolutions-com path: ./services/cilium/deploy/app prune: true