Skip to content
This repository has been archived by the owner on Nov 28, 2023. It is now read-only.

How to add custom iptables rules to a Kubernetes cluster

License

Notifications You must be signed in to change notification settings

FlockFreight/k8s-custom-iptables

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

18 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

k8s-custom-iptables

An example of how to add custom IP tables rules to a Kubernetes cluster. This collection of scripts creates a NAT (MASQ) rule for outbound traffic to a TARGETS CIDR range(s) given to the script.

Installing rules into the cluster.

Install the daemonset that configures the cluster to NAT an IP range.

TARGETS="1.2.3.4/24 4.5.6.7/16" ./install.sh

Uninstall rules from the cluster.

Uninstall the IP tables rules from the cluster.

./uninstall.sh

Configuring

The configuration for which ranges are NAT'd are in the k8s-custom-iptables ConfigMap. Values can be changed via kubectl edit cm/k8s-custom-iptables:

apiVersion: v1
kind: ConfigMap
metadata:
  name: k8s-custom-iptables
data:
  nat.rules: "10.0.0.0/24 192.168.0.0/16"

Creating and pushing the image.

REGISTRY=gcr.io/my-registry make

About

How to add custom iptables rules to a Kubernetes cluster

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages

  • Shell 74.7%
  • Makefile 14.8%
  • Dockerfile 10.5%