2018-02-17 11:37:47 +08:00
|
|
|
---
|
|
|
|
# Log-level
|
|
|
|
cilium_debug: false
|
2019-08-06 16:37:55 +08:00
|
|
|
|
2020-07-02 22:12:47 +08:00
|
|
|
cilium_mtu: ""
|
2019-08-06 16:37:55 +08:00
|
|
|
cilium_enable_ipv4: true
|
|
|
|
cilium_enable_ipv6: false
|
2018-02-17 11:37:47 +08:00
|
|
|
|
|
|
|
# Etcd SSL dirs
|
|
|
|
cilium_cert_dir: /etc/cilium/certs
|
2019-04-19 21:01:54 +08:00
|
|
|
kube_etcd_cacert_file: ca.pem
|
|
|
|
kube_etcd_cert_file: node-{{ inventory_hostname }}.pem
|
|
|
|
kube_etcd_key_file: node-{{ inventory_hostname }}-key.pem
|
2018-02-17 11:37:47 +08:00
|
|
|
|
|
|
|
# Limits for apps
|
|
|
|
cilium_memory_limit: 500M
|
2018-07-27 04:17:27 +08:00
|
|
|
cilium_cpu_limit: 500m
|
2018-02-17 11:37:47 +08:00
|
|
|
cilium_memory_requests: 64M
|
2018-07-27 04:17:27 +08:00
|
|
|
cilium_cpu_requests: 100m
|
2018-02-17 11:37:47 +08:00
|
|
|
|
2019-11-11 19:19:42 +08:00
|
|
|
# Overlay Network Mode
|
|
|
|
cilium_tunnel_mode: vxlan
|
2018-02-17 11:37:47 +08:00
|
|
|
# Optional features
|
|
|
|
cilium_enable_prometheus: false
|
2020-08-18 15:35:29 +08:00
|
|
|
cilium_enable_hubble_metrics: false
|
2020-08-27 14:19:02 +08:00
|
|
|
cilium_enable_hubble: false
|
|
|
|
cilium_hubble_metrics: ""
|
2019-08-06 16:37:55 +08:00
|
|
|
# Enable if you want to make use of hostPort mappings
|
|
|
|
cilium_enable_portmap: false
|
2020-03-11 23:15:36 +08:00
|
|
|
# Monitor aggregation level (none/low/medium/maximum)
|
|
|
|
cilium_monitor_aggregation: medium
|
2020-07-30 17:46:31 +08:00
|
|
|
# Kube Proxy Replacement mode (strict/probe/partial)
|
|
|
|
cilium_kube_proxy_replacement: probe
|
2019-08-06 16:37:55 +08:00
|
|
|
|
|
|
|
# If upgrading from Cilium < 1.5, you may want to override some of these options
|
|
|
|
# to prevent service disruptions. See also:
|
|
|
|
# http://docs.cilium.io/en/stable/install/upgrade/#changes-that-may-require-action
|
|
|
|
cilium_preallocate_bpf_maps: false
|
|
|
|
cilium_tofqdns_enable_poller: false
|
|
|
|
cilium_enable_legacy_services: false
|
2020-07-17 20:57:01 +08:00
|
|
|
|
|
|
|
# Deploy cilium even if kube_network_plugin is not cilium.
|
|
|
|
# This enables to deploy cilium alongside another CNI to replace kube-proxy.
|
|
|
|
cilium_deploy_additionally: false
|
2020-08-18 15:39:42 +08:00
|
|
|
|
|
|
|
# Auto direct nodes routes can be used to advertise pods routes in your cluster
|
|
|
|
# without any tunelling (with `cilium_tunnel_mode` sets to `disabled`).
|
|
|
|
# This works only if you have a L2 connectivity between all your nodes.
|
|
|
|
# You wil also have to specify the variable `cilium_native_routing_cidr` to
|
|
|
|
# make this work. Please refer to the cilium documentation for more
|
|
|
|
# information about this kind of setups.
|
|
|
|
cilium_auto_direct_node_routes: false
|
|
|
|
cilium_native_routing_cidr: ""
|
2021-03-24 04:46:06 +08:00
|
|
|
|
|
|
|
# IPsec based transparent encryption between nodes
|
2021-04-01 22:33:22 +08:00
|
|
|
cilium_ipsec_enabled: false
|
|
|
|
|
|
|
|
# IP address management mode for v1.9+.
|
|
|
|
# https://docs.cilium.io/en/v1.9/concepts/networking/ipam/
|
|
|
|
cilium_ipam_mode: kubernetes
|