Skip to content
kix /docs
Install the CLI

Reference Package catalog

cilium

Auto-generated from cilium package options. Do not edit by hand.

Allow every pod in the cluster to reach cluster DNS, as the CiliumClusterwideNetworkPolicy cilium-cluster-dns-egress. Emitted only when the instance configures Cilium (chart or helmChartConfig delivery) and the effective policyEnforcementMode is “always”, which it is by default when networkPolicy.enable is true.

In that mode every pod in the cluster is in default deny, including the ones Kix never writes a policy for: a kubectl run debug pod, an operator’s own Job, anything in a namespace Kix does not manage. Kix writes DNS egress for the workloads it renders and for nothing else, so without this those pods cannot resolve a name, and the failure reads as a DNS outage rather than as a policy decision.

Set it false to write that policy yourself.

Type: boolean

Default:

true

Helm values, merged with lib.recursiveUpdate over the package’s defaults for the delivery; a list replaces the default list.

Chart delivery: values for the cilium chart. helmChartConfig delivery: the values written to the environment’s HelmChartConfig, which its helm-controller merges over its own chart defaults. Must be empty when the platform-cilium dependency’s out.helmChartConfig is null, because the instance then writes no Cilium configuration.

Type: attribute set of anything

Default:

{ }