Reference Package catalog
cilium
Auto-generated from cilium package options. Do not edit by hand.
clusterDnsEgress
Section titled “clusterDnsEgress”Allow every pod in the cluster to reach cluster DNS, as the
CiliumClusterwideNetworkPolicy cilium-cluster-dns-egress. Emitted
only when the instance configures Cilium (chart or helmChartConfig
delivery) and the effective policyEnforcementMode is “always”,
which it is by default when networkPolicy.enable is true.
In that mode every pod in the cluster is in default deny, including
the ones Kix never writes a policy for: a kubectl run debug pod,
an operator’s own Job, anything in a namespace Kix does not manage.
Kix writes DNS egress for the workloads it renders and for nothing
else, so without this those pods cannot resolve a name, and the
failure reads as a DNS outage rather than as a policy decision.
Set it false to write that policy yourself.
Type: boolean
Default:
truevalues
Section titled “values”Helm values, merged with lib.recursiveUpdate over the package’s
defaults for the delivery; a list replaces the default list.
Chart delivery: values for the cilium chart. helmChartConfig delivery: the values written to the environment’s HelmChartConfig, which its helm-controller merges over its own chart defaults. Must be empty when the platform-cilium dependency’s out.helmChartConfig is null, because the instance then writes no Cilium configuration.
Type: attribute set of anything
Default:
{ }