|
This is unreleased documentation for Network Enforcer 0.3-dev. |
Compatibility
Overview
Kubewarden Network Enforcer observes cluster traffic, proposes workload network policies, and enforces them in Kubernetes. It supports Istio ambient, Calico, and Cilium as providers.
Quick Reference
| Component | Requirement | Notes |
|---|---|---|
Provider |
|
Chart enum in |
Architecture |
x86_64, aarch64 |
Fully supported. |
Kubernetes |
1.30+ |
The promote-label guard is a |
cert-manager |
Required for the default chart install |
Together with |
Linux distribution |
To be determined |
Provider Matrix
controller.provider.name is required and must be one of istio, cilium, calico. Defaults to istio.
| Provider | Minimum validated version | Transport and default endpoint | Policy backend |
|---|---|---|---|
Istio (ambient) |
1.30.3 |
OTLP gRPC mutual TLS to the controller. Default listen port |
|
Calico |
v3.32.1 |
gRPC mutual TLS to |
|
Cilium |
1.20.0 |
gRPC mutual TLS to |
|
Istio ambient install flags
Monitor and protect depend on ztunnel emitting JSON authorization logs that fluent-bit can parse:
-
istiod:
profile=ambientandpilot.env.AMBIENT_ENABLE_DRY_RUN_AUTHORIZATION_POLICY=true -
ztunnel:
env.AUTHZ_POLICY_INFO_LOGGING=trueandlogAsJson=true
Provider TLS
Mutual TLS means both peers present a certificate. A hop is one connection between Network Enforcer and the provider. TLS mode says where the certificates for that hop come from.
Set TLS under controller.provider.istio.tls, controller.provider.cilium.tls, or controller.provider.calico.tls.
Only the active provider is applied.
| Provider | Hop | Direction | Default mode | What you supply |
|---|---|---|---|---|
Istio |
fluent-bit to Service |
Controller is the server. fluent-bit is the client. Mutual TLS. |
|
Nothing, when cert-manager and |
Calico |
Controller to Goldmane at |
Controller is the client. Goldmane is the server. Mutual TLS. |
|
Nothing in the release namespace. |
Cilium |
Controller to Hubble Relay at |
Controller is the client. Relay is the server. Mutual TLS. |
|
Nothing, when Secret |
The chart renders --provider-tls-mode and the matching --provider-tls-* flags on the controller.
A cross-namespace Secret also renders a Role and a RoleBinding in that namespace.
The Role allows get on that Secret, and on the CA ConfigMap when one is set.