mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-26 04:58:07 +00:00
30 lines
52 KiB
HTML
30 lines
52 KiB
HTML
<!doctype html>
|
||
<html lang="en" dir="ltr" class="docs-wrapper docs-doc-page docs-version-current plugin-docs plugin-id-default docs-doc-id-faq/container-network-interface-providers" data-has-hydrated="false">
|
||
<head>
|
||
<meta charset="UTF-8">
|
||
<meta name="generator" content="Docusaurus v2.4.3">
|
||
<title data-rh="true">Container Network Interface (CNI) Providers | Rancher</title><meta data-rh="true" name="viewport" content="width=device-width,initial-scale=1"><meta data-rh="true" name="twitter:card" content="summary_large_image"><meta data-rh="true" property="og:url" content="https://ranchermanager.docs.rancher.com/faq/container-network-interface-providers"><meta data-rh="true" name="docusaurus_locale" content="en"><meta data-rh="true" name="docsearch:language" content="en"><meta data-rh="true" name="docusaurus_version" content="current"><meta data-rh="true" name="docusaurus_tag" content="docs-default-current"><meta data-rh="true" name="docsearch:version" content="current"><meta data-rh="true" name="docsearch:docusaurus_tag" content="docs-default-current"><meta data-rh="true" property="og:title" content="Container Network Interface (CNI) Providers | Rancher"><meta data-rh="true" name="description" content="Learn about Container Network Interface (CNI), the CNI providers Rancher provides, the features they offer, and how to choose a provider for you"><meta data-rh="true" property="og:description" content="Learn about Container Network Interface (CNI), the CNI providers Rancher provides, the features they offer, and how to choose a provider for you"><link data-rh="true" rel="icon" href="/img/favicon.png"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/faq/container-network-interface-providers" hreflang="en"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/zh/faq/container-network-interface-providers" hreflang="zh"><link data-rh="true" rel="alternate" href="https://ranchermanager.docs.rancher.com/faq/container-network-interface-providers" hreflang="x-default"><link data-rh="true" rel="preconnect" href="https://30NEY6C9UY-dsn.algolia.net" crossorigin="anonymous"><link data-rh="true" rel="canonical" href="https://ranchermanager.docs.rancher.com/faq/container-network-interface-providers"><link rel="preconnect" href="https://www.googletagmanager.com">
|
||
<script>window.dataLayer=window.dataLayer||[]</script>
|
||
<script>!function(e,t,a,n,g){e[n]=e[n]||[],e[n].push({"gtm.start":(new Date).getTime(),event:"gtm.js"});var m=t.getElementsByTagName(a)[0],r=t.createElement(a);r.async=!0,r.src="https://www.googletagmanager.com/gtm.js?id=GTM-57KS2MW",m.parentNode.insertBefore(r,m)}(window,document,"script","dataLayer")</script>
|
||
|
||
|
||
|
||
<link rel="search" type="application/opensearchdescription+xml" title="Rancher" href="/opensearch.xml">
|
||
|
||
|
||
|
||
<script src="https://cdn.cookielaw.org/scripttemplates/otSDKStub.js" charset="UTF-8" data-domain-script="0f98beb0-fc4c-417d-a42e-564e2cae42d2" async></script>
|
||
<script src="/scripts/optanonwrapper.js" async></script><link rel="stylesheet" href="/assets/css/styles.dea80607.css">
|
||
<link rel="preload" href="/assets/js/runtime~main.d98f8a34.js" as="script">
|
||
<link rel="preload" href="/assets/js/main.e9ebdfba.js" as="script">
|
||
</head>
|
||
<body class="navigation-with-keyboard">
|
||
<noscript><iframe src="https://www.googletagmanager.com/ns.html?id=GTM-57KS2MW" height="0" width="0" style="display:none;visibility:hidden"></iframe></noscript>
|
||
|
||
|
||
<script>!function(){function t(t){document.documentElement.setAttribute("data-theme",t)}var e=function(){var t=null;try{t=new URLSearchParams(window.location.search).get("docusaurus-theme")}catch(t){}return t}()||function(){var t=null;try{t=localStorage.getItem("theme")}catch(t){}return t}();t(null!==e?e:"light")}()</script><div id="__docusaurus">
|
||
<div role="region" aria-label="Skip to main content"><a class="skipToContent_fXgn" href="#__docusaurus_skipToContent_fallback">Skip to main content</a></div><nav aria-label="Main" class="navbar navbar--fixed-top"><div class="navbar__inner"><div class="navbar__items"><button aria-label="Toggle navigation bar" aria-expanded="false" class="navbar__toggle clean-btn" type="button"><svg width="30" height="30" viewBox="0 0 30 30" aria-hidden="true"><path stroke="currentColor" stroke-linecap="round" stroke-miterlimit="10" stroke-width="2" d="M4 7h22M4 15h22M4 23h22"></path></svg></button><a class="navbar__brand" href="/"><div class="navbar__logo"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--light_HNdA"><img src="/img/rancher-logo-horiz-color.svg" alt="logo" class="themedImage_ToTc themedImage--dark_i4oU"></div><b class="navbar__title text--truncate"></b></a><div class="navbar__item dropdown dropdown--hoverable"><a aria-current="page" class="navbar__link active" aria-haspopup="true" aria-expanded="false" role="button" href="/">Latest</a><ul class="dropdown__menu"><li><a aria-current="page" class="dropdown__link dropdown__link--active" href="/faq/container-network-interface-providers">Latest</a></li><li><a class="dropdown__link" href="/v2.9/faq/container-network-interface-providers">v2.9 (Preview)</a></li><li><a class="dropdown__link" href="/v2.8/faq/container-network-interface-providers">v2.8</a></li><li><a class="dropdown__link" href="/v2.7/faq/container-network-interface-providers">v2.7</a></li><li><a class="dropdown__link" href="/v2.6/faq/container-network-interface-providers">v2.6</a></li><li><a class="dropdown__link" href="/v2.5/faq/container-network-interface-providers">v2.5</a></li><li><a class="dropdown__link" href="/v2.0-v2.4/faq/container-network-interface-providers">v2.0-v2.4</a></li><li><a class="dropdown__link" href="/versions">All versions</a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link"><svg viewBox="0 0 24 24" width="20" height="20" aria-hidden="true" class="iconLanguage_nlXk"><path fill="currentColor" d="M12.87 15.07l-2.54-2.51.03-.03c1.74-1.94 2.98-4.17 3.71-6.53H17V4h-7V2H8v2H1v1.99h11.17C11.5 7.92 10.44 9.75 9 11.35 8.07 10.32 7.3 9.19 6.69 8h-2c.73 1.63 1.73 3.17 2.98 4.56l-5.09 5.02L4 19l5-5 3.11 3.11.76-2.04zM18.5 10h-2L12 22h2l1.12-3h4.75L21 22h2l-4.5-12zm-2.62 7l1.62-4.33L19.12 17h-3.24z"></path></svg>English</a><ul class="dropdown__menu"><li><a href="/faq/container-network-interface-providers" target="_self" rel="noopener noreferrer" class="dropdown__link dropdown__link--active" lang="en">English</a></li><li><a href="/zh/faq/container-network-interface-providers" target="_self" rel="noopener noreferrer" class="dropdown__link" lang="zh">简体中文</a></li></ul></div><div class="searchBox_ZlJk"><button type="button" class="DocSearch DocSearch-Button" aria-label="Search"><span class="DocSearch-Button-Container"><svg width="20" height="20" class="DocSearch-Search-Icon" viewBox="0 0 20 20"><path d="M14.386 14.386l4.0877 4.0877-4.0877-4.0877c-2.9418 2.9419-7.7115 2.9419-10.6533 0-2.9419-2.9418-2.9419-7.7115 0-10.6533 2.9418-2.9419 7.7115-2.9419 10.6533 0 2.9419 2.9418 2.9419 7.7115 0 10.6533z" stroke="currentColor" fill="none" fill-rule="evenodd" stroke-linecap="round" stroke-linejoin="round"></path></svg><span class="DocSearch-Button-Placeholder">Search</span></span><span class="DocSearch-Button-Keys"></span></button></div></div><div class="navbar__items navbar__items--right"><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">Quick Links</a><ul class="dropdown__menu"><li><a href="https://github.com/rancher/rancher" target="_blank" rel="noopener noreferrer" class="dropdown__link">GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://github.com/rancher/rancher-docs" target="_blank" rel="noopener noreferrer" class="dropdown__link">Docs GitHub<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div><div class="navbar__item dropdown dropdown--hoverable dropdown--right"><a href="#" aria-haspopup="true" aria-expanded="false" role="button" class="navbar__link">More from SUSE</a><ul class="dropdown__menu"><li><a href="https://www.rancher.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher">Rancher<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://elemental.docs.rancher.com/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__elemental">Elemental<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://fleet.rancher.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__fleet">Fleet<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://harvesterhci.io" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__harvester">Harvester<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><a href="https://rancherdesktop.io/" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__rancher__desktop">Rancher Desktop<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li><li><hr style="margin: 0.3rem 0;"></li><li><a href="https://opensource.suse.com" target="_blank" rel="noopener noreferrer" class="dropdown__link navbar__icon navbar__suse">More Projects...<svg width="12" height="12" aria-hidden="true" viewBox="0 0 24 24" class="iconExternalLink_nPIU"><path fill="currentColor" d="M21 13v10h-21v-19h12v2h-10v15h17v-8h2zm3-12h-10.988l4.035 4-6.977 7.07 2.828 2.828 6.977-7.07 4.125 4.172v-11z"></path></svg></a></li></ul></div></div></div><div role="presentation" class="navbar-sidebar__backdrop"></div></nav><div id="__docusaurus_skipToContent_fallback" class="main-wrapper mainWrapper_z2l0 docsWrapper_BCFX"><button aria-label="Scroll back to top" class="clean-btn theme-back-to-top-button backToTopButton_sjWU" type="button"></button><div class="docPage__5DB"><aside class="theme-doc-sidebar-container docSidebarContainer_b6E3"><div class="sidebarViewport_Xe31"><div class="sidebar_njMd"><nav aria-label="Docs sidebar" class="menu thin-scrollbar menu_SIkG"><ul class="theme-doc-sidebar-menu menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/">What is Rancher?</a></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/getting-started/overview">Getting Started</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/how-to-guides/new-user-guides">How-to Guides</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/reference-guides/best-practices">Reference Guides</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist" aria-expanded="false" href="/integrations-in-rancher">Integrations in Rancher</a><button aria-label="Toggle the collapsible sidebar category 'Integrations in Rancher'" type="button" class="clean-btn menu__caret"></button></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret menu__link--active" aria-expanded="true" href="/faq/general-faq">FAQ</a></div><ul style="display:block;overflow:visible;height:auto" class="menu__list"><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/general-faq">General FAQ</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/deprecated-features">Deprecated Features in Rancher</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/install-and-configure-kubectl">Installing and Configuring kubectl</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/dockershim">Dockershim FAQ</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/technical-items">Technical FAQ</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/security">Security FAQ</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/telemetry">Telemetry FAQ</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link menu__link--active" aria-current="page" tabindex="0" href="/faq/container-network-interface-providers">Container Network Interface (CNI) Providers</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-2 menu__list-item"><a class="menu__link" tabindex="0" href="/faq/rancher-is-no-longer-needed">Rancher is No Longer Needed</a></li></ul></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/troubleshooting/general-troubleshooting">Troubleshooting</a></div></li><li class="theme-doc-sidebar-item-category theme-doc-sidebar-item-category-level-1 menu__list-item menu__list-item--collapsed"><div class="menu__list-item-collapsible"><a class="menu__link menu__link--sublist menu__link--sublist-caret" aria-expanded="false" href="/api/quickstart">Rancher Kubernetes API</a></div></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/contribute-to-rancher">Contributing to Rancher</a></li><li class="theme-doc-sidebar-item-link theme-doc-sidebar-item-link-level-1 menu__list-item"><a class="menu__link" href="/glossary">Glossary</a></li></ul></nav></div></div></aside><main class="docMainContainer_gTbr"><div class="container padding-top--md padding-bottom--lg"><div class="row"><div class="col docItemCol_VOVn"><div class="docItemContainer_Djhp"><article><nav class="theme-doc-breadcrumbs breadcrumbsContainer_Z_bl" aria-label="Breadcrumbs"><ul class="breadcrumbs" itemscope="" itemtype="https://schema.org/BreadcrumbList"><li class="breadcrumbs__item"><a aria-label="Home page" class="breadcrumbs__link" href="/"><svg viewBox="0 0 24 24" class="breadcrumbHomeIcon_YNFT"><path d="M10 19v-5h4v5c0 .55.45 1 1 1h3c.55 0 1-.45 1-1v-7h1.7c.46 0 .68-.57.33-.87L12.67 3.6c-.38-.34-.96-.34-1.34 0l-8.36 7.53c-.34.3-.13.87.33.87H5v7c0 .55.45 1 1 1h3c.55 0 1-.45 1-1z" fill="currentColor"></path></svg></a></li><li class="breadcrumbs__item"><span class="breadcrumbs__link">FAQ</span><meta itemprop="position" content="1"></li><li itemscope="" itemprop="itemListElement" itemtype="https://schema.org/ListItem" class="breadcrumbs__item breadcrumbs__item--active"><span class="breadcrumbs__link" itemprop="name">Container Network Interface (CNI) Providers</span><meta itemprop="position" content="2"></li></ul></nav><span class="theme-doc-version-badge badge badge--secondary">Version: Latest</span><div class="tocCollapsible_ETCw theme-doc-toc-mobile tocMobile_ITEo"><button type="button" class="clean-btn tocCollapsibleButton_TO0P">On this page</button></div><div class="theme-doc-markdown markdown"><header><h1>Container Network Interface (CNI) Providers</h1></header><h2 class="anchor anchorWithStickyNavbar_LWe7" id="what-is-cni">What is CNI?<a href="#what-is-cni" class="hash-link" aria-label="Direct link to What is CNI?" title="Direct link to What is CNI?"></a></h2><p>CNI (Container Network Interface), a <a href="https://cncf.io/" target="_blank" rel="noopener noreferrer">Cloud Native Computing Foundation project</a>, consists of a specification and libraries for writing plugins to configure network interfaces in Linux containers, along with a number of plugins. CNI concerns itself only with network connectivity of containers and removing allocated resources when the container is deleted.</p><p>Kubernetes uses CNI as an interface between network providers and Kubernetes pod networking.</p><p><img loading="lazy" alt="CNI Logo" src="/assets/images/cni-logo-4fc06f259de435a65ca64a52bd719a96.png" width="84" height="119" class="img_ev3q"></p><p>For more information visit <a href="https://github.com/containernetworking/cni" target="_blank" rel="noopener noreferrer">CNI GitHub project</a>.</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="what-network-models-are-used-in-cni">What Network Models are Used in CNI?<a href="#what-network-models-are-used-in-cni" class="hash-link" aria-label="Direct link to What Network Models are Used in CNI?" title="Direct link to What Network Models are Used in CNI?"></a></h2><p>CNI network providers implement their network fabric using either an encapsulated network model such as Virtual Extensible Lan (<a href="https://github.com/flannel-io/flannel/blob/master/Documentation/backends.md#vxlan" target="_blank" rel="noopener noreferrer">VXLAN</a>) or an unencapsulated network model such as Border Gateway Protocol (<a href="https://en.wikipedia.org/wiki/Border_Gateway_Protocol" target="_blank" rel="noopener noreferrer">BGP</a>).</p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="what-is-an-encapsulated-network">What is an Encapsulated Network?<a href="#what-is-an-encapsulated-network" class="hash-link" aria-label="Direct link to What is an Encapsulated Network?" title="Direct link to What is an Encapsulated Network?"></a></h3><p>This network model provides a logical Layer 2 (L2) network encapsulated over the existing Layer 3 (L3) network topology that spans the Kubernetes cluster nodes. With this model you have an isolated L2 network for containers without needing routing distribution, all at the cost of minimal overhead in terms of processing and increased IP package size, which comes from an IP header generated by overlay encapsulation. Encapsulation information is distributed by UDP ports between Kubernetes workers, interchanging network control plane information about how MAC addresses can be reached. Common encapsulation used in this kind of network model is VXLAN, Internet Protocol Security (IPSec), and IP-in-IP.</p><p>In simple terms, this network model generates a kind of network bridge extended between Kubernetes workers, where pods are connected.</p><p>This network model is used when an extended L2 bridge is preferred. This network model is sensitive to L3 network latencies of the Kubernetes workers. If datacenters are in distinct geolocations, be sure to have low latencies between them to avoid eventual network segmentation.</p><p>CNI network providers using this network model include Flannel, Canal, Weave, and Cilium. By default, Calico is not using this model, but it can be configured to do so.</p><p><img loading="lazy" alt="Encapsulated Network" src="/assets/images/encapsulated-network-0c75db46568d5b2636dad4a8c28d3cc4.png" width="767" height="446" class="img_ev3q"></p><h3 class="anchor anchorWithStickyNavbar_LWe7" id="what-is-an-unencapsulated-network">What is an Unencapsulated Network?<a href="#what-is-an-unencapsulated-network" class="hash-link" aria-label="Direct link to What is an Unencapsulated Network?" title="Direct link to What is an Unencapsulated Network?"></a></h3><p>This network model provides an L3 network to route packets between containers. This model doesn't generate an isolated l2 network, nor generates overhead. These benefits come at the cost of Kubernetes workers having to manage any route distribution that's needed. Instead of using IP headers for encapsulation, this network model uses a network protocol between Kubernetes workers to distribute routing information to reach pods, such as <a href="https://en.wikipedia.org/wiki/Border_Gateway_Protocol" target="_blank" rel="noopener noreferrer">BGP</a>.</p><p>In simple terms, this network model generates a kind of network router extended between Kubernetes workers, which provides information about how to reach pods.</p><p>This network model is used when a routed L3 network is preferred. This mode dynamically updates routes at the OS level for Kubernetes workers. It's less sensitive to latency.</p><p>CNI network providers using this network model include Calico and Cilium. Cilium may be configured with this model although it is not the default mode.</p><p><img loading="lazy" alt="Unencapsulated Network" src="/assets/images/unencapsulated-network-b87922f280aa17322e6485b81855dd4a.png" width="716" height="415" class="img_ev3q"></p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="what-cni-providers-are-provided-by-rancher">What CNI Providers are Provided by Rancher?<a href="#what-cni-providers-are-provided-by-rancher" class="hash-link" aria-label="Direct link to What CNI Providers are Provided by Rancher?" title="Direct link to What CNI Providers are Provided by Rancher?"></a></h2><h3 class="anchor anchorWithStickyNavbar_LWe7" id="rke-kubernetes-clusters">RKE Kubernetes clusters<a href="#rke-kubernetes-clusters" class="hash-link" aria-label="Direct link to RKE Kubernetes clusters" title="Direct link to RKE Kubernetes clusters"></a></h3><p>Out-of-the-box, Rancher provides the following CNI network providers for RKE Kubernetes clusters: Canal, Flannel, Calico, and Weave.</p><p>You can choose your CNI network provider when you create new Kubernetes clusters from Rancher.</p><h4 class="anchor anchorWithStickyNavbar_LWe7" id="canal">Canal<a href="#canal" class="hash-link" aria-label="Direct link to Canal" title="Direct link to Canal"></a></h4><p><img loading="lazy" alt="Canal Logo" src="/assets/images/canal-logo-59b1e2e7cb6ef69952216bc6c8778fea.png" width="328" height="184" class="img_ev3q"></p><p>Canal is a CNI network provider that gives you the best of Flannel and Calico. It allows users to easily deploy Calico and Flannel networking together as a unified networking solution, combining Calico’s network policy enforcement with the rich superset of Calico (unencapsulated) and/or Flannel (encapsulated) network connectivity options.</p><p>In Rancher, Canal is the default CNI network provider combined with Flannel and VXLAN encapsulation.</p><p>Kubernetes workers should open UDP port <code>8472</code> (VXLAN) and TCP port <code>9099</code> (health checks). If using Wireguard, you should open UDP ports <code>51820</code> and <code>51821</code>. For more details, refer to <a href="/how-to-guides/new-user-guides/kubernetes-clusters-in-rancher-setup/node-requirements-for-rancher-managed-clusters">the port requirements for user clusters</a>.</p><p><img loading="lazy" src="/assets/images/canal-diagram-098d93441385aab94e0a23e0a8cdd7b0.png" width="1782" height="898" class="img_ev3q"></p><p>For more information, see the <a href="https://github.com/projectcalico/canal" target="_blank" rel="noopener noreferrer">Canal GitHub Page.</a></p><h4 class="anchor anchorWithStickyNavbar_LWe7" id="flannel">Flannel<a href="#flannel" class="hash-link" aria-label="Direct link to Flannel" title="Direct link to Flannel"></a></h4><p><img loading="lazy" alt="Flannel Logo" src="/assets/images/flannel-logo-72cb4d5923f7a0be32a1148dc78d5c50.png" width="328" height="100" class="img_ev3q"></p><p>Flannel is a simple and easy way to configure L3 network fabric designed for Kubernetes. Flannel runs a single binary agent named flanneld on each host, which is responsible for allocating a subnet lease to each host out of a larger, preconfigured address space. Flannel uses either the Kubernetes API or etcd directly to store the network configuration, the allocated subnets, and any auxiliary data (such as the host's public IP). Packets are forwarded using one of several backend mechanisms, with the default encapsulation being <a href="https://github.com/flannel-io/flannel/blob/master/Documentation/backends.md#vxlan" target="_blank" rel="noopener noreferrer">VXLAN</a>.</p><p>Encapsulated traffic is unencrypted by default. Flannel provides two solutions for encryption:</p><ul><li><a href="https://github.com/flannel-io/flannel/blob/master/Documentation/backends.md#ipsec" target="_blank" rel="noopener noreferrer">IPSec</a>, which makes use of <a href="https://www.strongswan.org/" target="_blank" rel="noopener noreferrer">strongSwan</a> to establish encrypted IPSec tunnels between Kubernetes workers. It is an experimental backend for encryption.</li><li><a href="https://github.com/flannel-io/flannel/blob/master/Documentation/backends.md#wireguard" target="_blank" rel="noopener noreferrer">WireGuard</a>, which is a more faster-performing alternative to strongSwan.</li></ul><p>Kubernetes workers should open UDP port <code>8472</code> (VXLAN). See <a href="/how-to-guides/new-user-guides/kubernetes-clusters-in-rancher-setup/node-requirements-for-rancher-managed-clusters#networking-requirements">the port requirements for user clusters</a> for more details.</p><p><img loading="lazy" alt="Flannel Diagram" src="/assets/images/flannel-diagram-5d842974de10ad38569f46e70836f11f.png" width="1024" height="456" class="img_ev3q"></p><p>For more information, see the <a href="https://github.com/flannel-io/flannel" target="_blank" rel="noopener noreferrer">Flannel GitHub Page</a>.</p><h4 class="anchor anchorWithStickyNavbar_LWe7" id="weave">Weave<a href="#weave" class="hash-link" aria-label="Direct link to Weave" title="Direct link to Weave"></a></h4><div class="theme-admonition theme-admonition-warning alert alert--danger admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 12 16"><path fill-rule="evenodd" d="M5.05.31c.81 2.17.41 3.38-.52 4.31C3.55 5.67 1.98 6.45.9 7.98c-1.45 2.05-1.7 6.53 3.53 7.7-2.2-1.16-2.67-4.52-.3-6.61-.61 2.03.53 3.33 1.94 2.86 1.39-.47 2.3.53 2.27 1.67-.02.78-.31 1.44-1.13 1.81 3.42-.59 4.78-3.42 4.78-5.56 0-2.84-2.53-3.22-1.25-5.61-1.52.13-2.03 1.13-1.89 2.75.09 1.08-1.02 1.8-1.86 1.33-.67-.41-.66-1.19-.06-1.78C8.18 5.31 8.68 2.45 5.05.32L5.03.3l.02.01z"></path></svg></span>danger</div><div class="admonitionContent_S0QG"><p>The Weave CNI plugin for RKE with Kubernetes v1.27 and later is now deprecated. Weave will be removed in RKE with Kubernetes v1.30.</p></div></div><p><img loading="lazy" alt="Weave Logo" src="data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAOUAAADcCAMAAAC4YpZBAAABL1BMVEX///8yMkv/SxkA0v9VaZEA0P8cHDwrK0b/RQkvL0nIyM0YGDr/hmwWFjn/NQD19faR5/8RETfh+P/l5eciIkBLYYxsbHt4h6YsLEcA1v8mJkNGXYohIT+Bjqvc3N+cprziaVgqNU7dVjzd4OgYL0ylnadidJgLCzTt7e+dnaY+PlWPj5qzs7peXm+oqLB3d4S9vcOwuMnT09dOTmKDg49DQ1mQkJpZWWvg4+pnZ3dv4P/Bx9SNmbL/Vyv///7/08r/sKH/8Oys6///bk7/Xzn/pZT/kXv/ysAAACg0HDbt+/8AACkAADH/6OS/8f//nYoAABsyToE4XHU5c400g6A4lrUvqsz/aEb/fGAfvOI2TGM5KUD/vbAtc5Cj6v//IwCT8P9qfo8ln8OctcQAIUOQPSJCAAASdklEQVR4nO2d+WPaRhbHkXEkBMGEADYIBW/rrg0YA+bwETvO0aRpnMS926TJervd/v9/w+qYeXO9kRR3i4TL94fWQcfMRzPz3punkZTLrbTSSn9nXd6/urp6dn19/cz7/2XatflrdJ2/I+p+2jX6K3TvTl7QinJ5FUU5mo7Tq9if05ML4Z8RlAdu0+wPF12//4MunhT+Lf6ipazMHcMwbNc8qiy8mn9OTwobaxviTzrKrmEZoerOUrXn40cba2sJKTtm06Cy3X4xhereSBd3fcaElMWybXCyq5vL0W1fFgpriSkHVUOSVV0Gc/tV2JDJKHsKpKfyKJ2aJ9fbR4W15JSjEgJpGI6d7V77coNBxlHm75+6KKS9l+0++2RjbS0pZSv/q4NDupN0ap9Q3wiQ0ZQepIVCWlYtndon1AsRMpKy9d5oopDOPNtjMne3kJiy9f6DjULWj9Ope3Ilp2z9/AplNMzNdKr+CUpM2fpdA1mepVPzT1FSytaPGsjqMgTrCSlb/8Ih7epAPefTxVT9E5SIspX//gMOWULc5MeNt4upe3IlofTcJA7ZtDrqGV9sFB4tpu7JlYCydecz3E1a/a56Qj/wL3y1mMonVjylFwvgbtKZIrHAuyDK2Hi8mNonVSxl6/0rHNI8Vc928Qs5XeFC3Zii4ii1brKEuMmnMIXLWJ+NofztJ10s0FPP9bbAzVMzZWdjKP+jgdxD3ORjPvAv/LKY+idTNOWBZspcQrJ2H6Up3MsFESRRFGVlik+Zm3XETT6RpnCF5wtjiFcEZc3QTJl1blI6U4YaU0/ZcTRTZsxN3lUgM9WYWkopswxyMTf5ZUGBzFRooKNUM8uhTCTv+vQ5BrlWeLdQkihpKNHMsg95pJ7i7RoKuVZ4lJkACKec4Zll49Xv6r3oxwUN5C+ZgcQpNZll48PPLYXypWp3whNlp7+ilDo3aX9431LWFchuEs6TqUBWpez2cTfZ7L9vKasn5HQunOZFOjgaKZSdJu4mP/yabylrRBA3GZ7lY0o4GsmUa1/gbvLD9z6kSHnxpQ4yO54ylEL5GW5cf2jxd9wDXeBucq1QyNSsy1cyylc/tvIy5dNHGsi17GcqUcpXP7XyMuVbnZt8nj3IRJSvfqaQjPKxZkhmKKzjFE/pu8m8TPlRZ3fupoujUSxl0+AgKaXWTX6TMo5GcZTWPM9BEkp1ykwgM+YmQTGUxE2KlO90kGp24P7DxSMhiqZ0fxAYA0rILEsqILHA1Z1WCkyqIilLs9/yMqXeTaqxwPWdfPYpqz11vU9H5yYfqW4yODgFJlV6yuAGrEzZ+ocG8kt1yvwwODYFJlVayjCznJASmzKHkPlMPJyho2w6QWY5GSXiJi9b5MgsUHY/xylpZjkR5cYT5byXYK4yQFn74nO5ygElZJaTUCKxwH12RPqUExOndA/oHgkoUTeZIcpx1UYpSyyzHEuJTZmf8QelTTmsGgZCaZe5zHIcpdZNghYIhGm/bKCUwg3YGEoss/xQXGy6OCBMI9NAKf8Q1ixHU0a4yWxQHtQNlHJDXIwVSYllllvSAWnOScLnl1BKcccoSiSzfClNYfJ37i2ICBG7y/wnKKPdJKV8tiAkVRMTMss3p0SmzFfyBCbN5zXHJZY+vylloRAdCwDlgpgUDfe4eXIM5dNhC6XEMsvXCGRqJvaobCSmfFv4J0qJZZaV+XaglEzsgG/JGMrHGzilfsqsdNiUjE+nnJjy5cYaSolllmU3SSnTimJtOyGlf5cZo0SnzChjipHPzElGGTwZhVAiU2bVTVKl5keKpUSU4V1mlfJzJLOM91Zv5xRnXUKX1VDSxVgKZV5dZ4i5SV/pJpz3nVhKyCwrlGos80wHme69g041jpLdgI2nxN1k6pC53JRbBPIHQsndgI2lxN2kt991OmxMY5My2nvFr5T1PvxirDhKLWR6UxFQn9gf/zFfOetcEBZjRVNeamKBbLw5ZhA2ptWsIbl1Ma8TRXmJI+ZTdJOCmn5jho/5KpRrSSm1sUCabpKX35jkMd8bU2bTTQqa23TN8k0pM+omBU2+3Sd/3ZAys25SEDz1cjNKrQdJMWUXpRtRZtlNoroJpdZNXqVNo9OnU2qnzBlxk5iiKTf+K1NeZt5NYoqk3Hj5m/x+n2sNY4bcJKIISv8GrOIxlsKDKNJTBouxdH5xuSD1lIXnftI1GWVW3SRIR0kyy4koM+smQRpKmllOQpldNwnCKSGznIQyu26SCXtAlGWWE1Bm2E1yUp9i4m7AxlHeyXIsIEheas/fgI2hzHYsIEp47Z+4GCuaMutuUhT3YLO0GCuSMvNuUhZ9dkJejBVFmX5m+ZP1OEhRKouxIiiXwE2qunixUVAXY+kpM5FZvoGevlMXY+kpl8WDJJGOcmncZCLhlMvkJpMIpVwuN5lAGOXSuclYIZRL6CbjdM//JgnwBf9YRjcZp/tXz+49fPiw1fL+c+/Z1f1bZVtXWmmllf7mqjBpNyU+pFscHu3vHw2LyAv9hDN0J+PBcDgcFzvinhG1EbYq5Q6iy+18WyX6WlroePyGbpBOOqUbXgtvDC2OjKpZdzzVzfL0CHk9Y6hJb+pUS6Zbr7uuWSrPRwN2/jk99d6eijmCjY5wvplXrhuWW53v4+XSJVhGXXoZOLwbzBRfmlmBNesl7owDo2Rxi0ltp3qMfrlhaJTEtx3allsd0TYY6Ar1Beevc1d30C85QrnlKVYurFq2xJfXT2CdnSO+va5IN9hN+K3TN5WXMzWr6htwJ8h+fgn0McYuLC529pVjYVsZrm5tipWLvFIQKm2UhN97sADWngsbYGWsAxS9PfQFVHX5hZuDN/iLqrymI8/dHtN2ti25olCu3ac/Davo270cQ/k2RgUWuopvPT9mJzCFys5pTaFTzcpyOfSyWsKRY82rDoMrEjbAsE5/KMsDDN5+7dAOu687n20qmAdN+egAnqu5yT9MWYOOYxIDMTINnZp9/sgISI8qeCy1C4PekV6G3IFyq4T/SHdx/cEkGy+4fE3+0xlFruoOP8DG1EA0SScb8oXZluPwVsjhBvupJe7n1AV7FY5yWFzcnGqqSTvsmH9yRy7Xkj8DUoNa1rkLwK9Lt/kWGcHn1IbS4d5P5nTUOxr1y4yHfbyKe9LGKvVP93u93mxqsmLCHsO6bEkc1DCCiDHs8s1Qmo96vdG8zM5Wkl8Z3VcGWo4bfUFVuW7epBvIwDkAIrvaIxXrjICIXSFmztwDGHNd1t2tkXjRXKGeXfidlDti1rG6T+pXm8GgsB2pz4Iv4ax3VxhrXIHQIqSHFeG8Td6yDdjopcdCY9QFDwOl26Gvhy4rejbwpOSydaC/2hZnNdlAcyX3zxwgcxljgZIrEHoUGaww2GxLuHg9GL50fMnjioiZuXJFKMCo8rtt0nJIh4WBY7iCPR0AjC1SMl+yB0NBfMLJYCEVUIXdm3Uw+esbMA5Id4dSZOMJbRwORGaJhfAHrnrYYSvMy481pytLFQJf4sIRpI422cJiOTBkpnjlLflFzbCFWqlv90J9LVULWoUUAhaBN+2sv4U9AfqabIqZD5BCNqUXwgW1+6chJkSOEGYRPwIXyJQ/qgYDuHmQi9RMouxhXZvZDqnDurIthSDRlvihk8B5yVi3RoO6WFMwlKSFoMNWlTmEboDwNeqMeyPo2oSyJltTX33JsrODlMmWIfa2HHIOMpLJpaoPaMRRIkewQRSUxnygtSmLbkEqkqtMPLxp3Sy5nC+nw2KqhHKcZQ/bocs8xqm+XClGhP5A259MZrwLR7YQSwAmhPoRZootWbDFFMxAbTA7NqolVwh8hFpBf2F9rid1WDY/8WJlbbnS5A0qS1wGbUEHbCo5O+xIRvBQ84JqQS43ZAfzsus08ZkJpaypNn8uddixPnTmypU8JvMlblj5OjCTP4krhbiPXCfm3KJKAwMxtFzd1IujZAOIHgmBj22Qi5Xk6soui5nKsCTSgL6Foc0azr7m0sju4e/hFkWTEBVkyotSwlmpewIoGp0lo5Qn4pJzq3PF0oHpdzuI+6jNTURJrmnXxt7abTcV68PZNBKMQihCQ49EfciRcxU1wbmRsR1aGBJaBYfAcKDNw0prmlq9Ccf0XIL0Jktu2TSO55InySkTdQh0aIfl2tLWl7unZGRgKPhXr8eGJRuYvgkHW0wrxOamp5OiVsHOPa6T2R5feTo6GvuJSjkq8HQkJl3g4kIfhF/saVy5vGa8WSHTgrDB6MD0w1HqcMHRjyXjrFeFg3Tt2YCF2HKEl+PdoyPuQX3ShFHGlCuIuYgj6CDEahO/5tk7MPHQ4yFNIWXAVHG2vyRaeISSPUEf1AFCPoiiWLRm5D5BMP/xLg4lJhMRMjC9SS6MBvC3LDe7F1MAm+TI30SS7Hsg1mV7XMNxRhPsgRmTxteUtUeLoJ2QDkyLzfFYhMjyDEqut9b1BOn+A3xyzFeYo+xwF50hc5M7NktQstNdoVxRYEfc4nFYc2pHaYlmhw5LbpaBJGeJiq9N03XduuMGoedU9vQABMEaH3fy0Ti1uHzvZC5VTjF3aLl1ZJYAPb25SS4TzAjIwGxuSnktXyygdKWuAz7OGYmU0hQNzipQHrHIuqtYgxzvUuW87UwOKQTB1SOQbKhT8wBpaL46MM+xxGkke9FIOPPEs77+55MM7LQT+rO1OaC9TMhGgEuVptETCFbl+z7iNYDT0y1yOCVMGGHOS7PjpDB2TJjOAUsqpn0mXNgtzJRgxmIf0w4r3FOA/I7h8G3WYTOdPcwuFaUwn12KjvT5H2EIsgSM4fSpJejus1ePkb3ZpXLY1agc8R/CEihZPhhLkOS4TmQ4xhg5H+7BK1I+vox4r1CiWWM5ScMu9UfDwaB3ymV/qannktPOdOD9VqmNZ67QfwTKiXJ7QEqfjdkOtmkE5W6WuPNVlcgn0IF4/4i7EzoSI9CSaKMPuK22VffMG7+72VN3s13TsuslUwpsxbm9/OlTxf9v8tl/v1yHP5+r3BkMJcb5fIOLA1POVlUs/OM54bWC+xUT8YVkyBxMpJTthOKqKpovE4XV18Vi4i0p3kLpt4SbLW1x/Afo9zXze9STCEmPcKsSdnQ13ykMzqn98H2fv76CGxKuvJw08qfHmkmtecwXhn4Gs1nfh4hK5BCnkLaTU1Q51ly4+lwf9/F9REwv8gMTTTzuV5HLalWllMRI/bSg26+BcZeCNbHLKh02UK+KTOMt5FY/E+9LNLditMV1NvfqAoLt7G0qN4THjsuPYbvurycoylNzIrHLYt899VQbleviYgxn71S7PMVX5XUZ9FoosfY12yLfAKDq9qamWXcsy/KXpJjznsLoawg71c3SdOh36DE9+RvJw7lVVmrV1NW6G57SCcst9Y/QcnkYThXtFv3x3eJwfzYazfajljV5O3n7jGawT0V36i5fatQEq1IcHsWWu9JKK6200korrZQpVb5re0q7Fn+1Ko11T2nX4q/WivL2aEV5e7SizIy4J5N2DrfPz7cPd/Ada2fB1jM+G+Ef2w0pdY8/ZUNbjUYjaIntRrsRqL1+qO52uEu2NhpbcBlO/N/WQwWbFlftT9SWV8Ndrx3XaXX9Gu9KeZizBrd1vX1Ofj5pr4taeO2TKqTcaZMGofUVOt95e13Y3NgNNy8ZZderbqO9e769/SBs08YWt8t58FN7/YG/OQTbDTac+CFsSN5uZzqaDSi9/7S3SfOdBRxtZoO22wE2+WFn18dqPPD/rkx2dnbOAsydQAuvfVJtkU54Ar+cBBjb9J9BZ25zBimgbp/Rfy6FJ9mSIT172oA+6WlXgiTbgWt5KBui7wi6KN+Bt6RjPLAGbczloZTMRtB8Xba9LQ24E558aSgb5+JvDxpA2W1jDMFlII29PJRn4m8BZdh+vgVllojqkOuyS0Mp90iO8ryhXgTP7nLsy0Mp3ZvjKINhu6sIXOYyUUqTCY5yd10r4mtuA6UekpLdBsqwLRuYiPu5NZRemI4p3Pk2UD5AbSyv20C53VDiP0m3gTKICs6R40C3gRKP8HYOPZFpzG2gDENWecXgg3aj8d1tohQnm6EqfAPfCsqASIrXz3mTdCsoAyu73uYxw5QIPSagzG5eK1QsZS5MZ+1Sp3myFWAx7xJER1uTE0+LqPCNFE/ZDaPWhhcCHR6e7wapST6TSTJHmc9URlPmursNFs2Gf/GJoDOWe15MlW+gBJR+cp2/g9Boi8Zoq72UlFte5/tOyB+cnDfCOz/eVKRxLq9mPdxtZDy3jgm9S+ff99s6P8dv/FUq3ZNahq3PSiut9P/Q/wATIxQ4xmr5MAAAAABJRU5ErkJggg==" width="229" height="220" class="img_ev3q"></p><p>Weave enables networking and network policy in Kubernetes clusters across the cloud. Additionally, it support encrypting traffic between the peers.</p><p>Kubernetes workers should open TCP port <code>6783</code> (control port), UDP port <code>6783</code> and UDP port <code>6784</code> (data ports). See the <a href="/how-to-guides/new-user-guides/kubernetes-clusters-in-rancher-setup/node-requirements-for-rancher-managed-clusters#networking-requirements">port requirements for user clusters</a> for more details.</p><p>For more information, see the following pages:</p><ul><li><a href="https://www.weave.works/" target="_blank" rel="noopener noreferrer">Weave Net Official Site</a></li></ul><h3 class="anchor anchorWithStickyNavbar_LWe7" id="rke2-kubernetes-clusters">RKE2 Kubernetes clusters<a href="#rke2-kubernetes-clusters" class="hash-link" aria-label="Direct link to RKE2 Kubernetes clusters" title="Direct link to RKE2 Kubernetes clusters"></a></h3><p>Out-of-the-box, Rancher provides the following CNI network providers for RKE2 Kubernetes clusters: <a href="#canal">Canal</a> (see above section), Calico, and Cilium.</p><p>You can choose your CNI network provider when you create new Kubernetes clusters from Rancher.</p><h4 class="anchor anchorWithStickyNavbar_LWe7" id="calico">Calico<a href="#calico" class="hash-link" aria-label="Direct link to Calico" title="Direct link to Calico"></a></h4><p><img loading="lazy" alt="Calico Logo" src="/assets/images/calico-logo-876c7e5f55ffe5a9feb68c8eac7f6f09.png" width="256" height="256" class="img_ev3q"></p><p>Calico enables networking and network policy in Kubernetes clusters across the cloud. By default, Calico uses a pure, unencapsulated IP network fabric and policy engine to provide networking for your Kubernetes workloads. Workloads are able to communicate over both cloud infrastructure and on-prem using BGP.</p><p>Calico also provides a stateless IP-in-IP or VXLAN encapsulation mode that can be used, if necessary. Calico also offers policy isolation, allowing you to secure and govern your Kubernetes workloads using advanced ingress and egress policies.</p><p>Kubernetes workers should open TCP port <code>179</code> if using BGP or UDP port <code>4789</code> if using VXLAN encapsulation. In addition, TCP port <code>5473</code> is needed when using Typha. See <a href="/how-to-guides/new-user-guides/kubernetes-clusters-in-rancher-setup/node-requirements-for-rancher-managed-clusters#networking-requirements">the port requirements for user clusters</a> for more details.</p><div class="theme-admonition theme-admonition-note alert alert--secondary admonition_LlT9"><div class="admonitionHeading_tbUL"><span class="admonitionIcon_kALy"><svg viewBox="0 0 14 16"><path fill-rule="evenodd" d="M6.3 5.69a.942.942 0 0 1-.28-.7c0-.28.09-.52.28-.7.19-.18.42-.28.7-.28.28 0 .52.09.7.28.18.19.28.42.28.7 0 .28-.09.52-.28.7a1 1 0 0 1-.7.3c-.28 0-.52-.11-.7-.3zM8 7.99c-.02-.25-.11-.48-.31-.69-.2-.19-.42-.3-.69-.31H6c-.27.02-.48.13-.69.31-.2.2-.3.44-.31.69h1v3c.02.27.11.5.31.69.2.2.42.31.69.31h1c.27 0 .48-.11.69-.31.2-.19.3-.42.31-.69H8V7.98v.01zM7 2.3c-3.14 0-5.7 2.54-5.7 5.68 0 3.14 2.56 5.7 5.7 5.7s5.7-2.55 5.7-5.7c0-3.15-2.56-5.69-5.7-5.69v.01zM7 .98c3.86 0 7 3.14 7 7s-3.14 7-7 7-7-3.12-7-7 3.14-7 7-7z"></path></svg></span>Important:</div><div class="admonitionContent_S0QG"><p>In Rancher v2.6.3, Calico probes fail on Windows nodes upon RKE2 installation. <b>Note that this issue is resolved in v2.6.4.</b></p><ul><li><p>To work around this issue, first navigate to <code>https://<rancherserverurl>/v3/settings/windows-rke2-install-script</code>.</p></li><li><p>There, change the current setting: <code>https://raw.githubusercontent.com/rancher/wins/v0.1.3/install.ps1</code> to this new setting: <code>https://raw.githubusercontent.com/rancher/rke2/master/windows/rke2-install.ps1</code>.</p></li></ul></div></div><p><img loading="lazy" alt="Calico Diagram" src="/assets/images/calico-diagram-3e0d002feecad5d7ecde73da073b95be.svg" width="602" height="930" class="img_ev3q"></p><p>For more information, see the following pages:</p><ul><li><a href="https://www.projectcalico.org/" target="_blank" rel="noopener noreferrer">Project Calico Official Site</a></li><li><a href="https://github.com/projectcalico/calico" target="_blank" rel="noopener noreferrer">Project Calico GitHub Page</a></li></ul><h4 class="anchor anchorWithStickyNavbar_LWe7" id="cilium">Cilium<a href="#cilium" class="hash-link" aria-label="Direct link to Cilium" title="Direct link to Cilium"></a></h4><p><img loading="lazy" alt="Cilium Logo" src="/assets/images/cilium-logo-74a25c5fe67b4da4ce752dbf4ffbf11d.png" width="148" height="148" class="img_ev3q"></p><p>Cilium enables networking and network policies (L3, L4, and L7) in Kubernetes. By default, Cilium uses eBPF technologies to route packets inside the node and VXLAN to send packets to other nodes. Unencapsulated techniques can also be configured.</p><p>Cilium recommends kernel versions greater than 5.2 to be able to leverage the full potential of eBPF. Kubernetes workers should open TCP port <code>8472</code> for VXLAN and TCP port <code>4240</code> for health checks. In addition, ICMP 8/0 must be enabled for health checks. For more information, check <a href="https://docs.cilium.io/en/latest/operations/system_requirements/#firewall-requirements" target="_blank" rel="noopener noreferrer">Cilium System Requirements</a>.</p><h5 class="anchor anchorWithStickyNavbar_LWe7" id="ingress-routing-across-nodes-in-cilium">Ingress Routing Across Nodes in Cilium<a href="#ingress-routing-across-nodes-in-cilium" class="hash-link" aria-label="Direct link to Ingress Routing Across Nodes in Cilium" title="Direct link to Ingress Routing Across Nodes in Cilium"></a></h5><br>By default, Cilium does not allow pods to contact pods on other nodes. To work around this, enable the ingress controller to route requests across nodes with a `CiliumNetworkPolicy`.<p>After selecting the Cilium CNI and enabling Project Network Isolation for your new cluster, configure as follows:</p><div class="codeBlockContainer_Ckt0 theme-code-block" style="--prism-color:#bfc7d5;--prism-background-color:#292d3e"><div class="codeBlockContent_biex"><pre tabindex="0" class="prism-code language-text codeBlock_bY9V thin-scrollbar"><code class="codeBlockLines_e6Vv"><span class="token-line" style="color:#bfc7d5"><span class="token plain">apiVersion: cilium.io/v2</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">kind: CiliumNetworkPolicy</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">metadata:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> name: hn-nodes</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> namespace: default</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain">spec:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> endpointSelector: {}</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> ingress:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> - fromEntities:</span><br></span><span class="token-line" style="color:#bfc7d5"><span class="token plain"> - remote-node</span><br></span></code></pre><div class="buttonGroup__atx"><button type="button" aria-label="Copy code to clipboard" title="Copy" class="clean-btn"><span class="copyButtonIcons_eSgA" aria-hidden="true"><svg viewBox="0 0 24 24" class="copyButtonIcon_y97N"><path fill="currentColor" d="M19,21H8V7H19M19,5H8A2,2 0 0,0 6,7V21A2,2 0 0,0 8,23H19A2,2 0 0,0 21,21V7A2,2 0 0,0 19,5M16,1H4A2,2 0 0,0 2,3V17H4V3H16V1Z"></path></svg><svg viewBox="0 0 24 24" class="copyButtonSuccessIcon_LjdS"><path fill="currentColor" d="M21,7L9,19L3.5,13.5L4.91,12.09L9,16.17L19.59,5.59L21,7Z"></path></svg></span></button></div></div></div><h2 class="anchor anchorWithStickyNavbar_LWe7" id="cni-features-by-provider">CNI Features by Provider<a href="#cni-features-by-provider" class="hash-link" aria-label="Direct link to CNI Features by Provider" title="Direct link to CNI Features by Provider"></a></h2><p>The following table summarizes the different features available for each CNI network provider provided by Rancher.</p><table><thead><tr><th>Provider</th><th>Network Model</th><th>Route Distribution</th><th>Network Policies</th><th>Mesh</th><th>External Datastore</th><th>Encryption</th><th>Ingress/Egress Policies</th></tr></thead><tbody><tr><td>Canal</td><td>Encapsulated (VXLAN)</td><td>No</td><td>Yes</td><td>No</td><td>K8s API</td><td>Yes</td><td>Yes</td></tr><tr><td>Flannel</td><td>Encapsulated (VXLAN)</td><td>No</td><td>No</td><td>No</td><td>K8s API</td><td>Yes</td><td>No</td></tr><tr><td>Calico</td><td>Encapsulated (VXLAN,IPIP) OR Unencapsulated</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Etcd and K8s API</td><td>Yes</td><td>Yes</td></tr><tr><td>Weave</td><td>Encapsulated</td><td>Yes</td><td>Yes</td><td>Yes</td><td>No</td><td>Yes</td><td>Yes</td></tr><tr><td>Cilium</td><td>Encapsulated (VXLAN)</td><td>Yes</td><td>Yes</td><td>Yes</td><td>Etcd and K8s API</td><td>Yes</td><td>Yes</td></tr></tbody></table><ul><li><p>Network Model: Encapsulated or unencapsulated. For more information, see <a href="#what-network-models-are-used-in-cni">What Network Models are Used in CNI?</a></p></li><li><p>Route Distribution: An exterior gateway protocol designed to exchange routing and reachability information on the Internet. BGP can assist with pod-to-pod networking between clusters. This feature is a must on unencapsulated CNI network providers, and it is typically done by BGP. If you plan to build clusters split across network segments, route distribution is a feature that's nice-to-have.</p></li><li><p>Network Policies: Kubernetes offers functionality to enforce rules about which services can communicate with each other using network policies. This feature is stable as of Kubernetes v1.7 and is ready to use with certain networking plugins.</p></li><li><p>Mesh: This feature allows service-to-service networking communication between distinct Kubernetes clusters.</p></li><li><p>External Datastore: CNI network providers with this feature need an external datastore for its data.</p></li><li><p>Encryption: This feature allows cyphered and secure network control and data planes.</p></li><li><p>Ingress/Egress Policies: This feature allows you to manage routing control for both Kubernetes and non-Kubernetes communications.</p></li></ul><h2 class="anchor anchorWithStickyNavbar_LWe7" id="cni-community-popularity">CNI Community Popularity<a href="#cni-community-popularity" class="hash-link" aria-label="Direct link to CNI Community Popularity" title="Direct link to CNI Community Popularity"></a></h2><p>The following table summarizes different GitHub metrics to give you an idea of each project's popularity and activity levels. This data was collected in March 2024.</p><table><thead><tr><th>Provider</th><th>Project</th><th>Stars</th><th>Forks</th><th>Contributors</th></tr></thead><tbody><tr><td>Canal</td><td><a href="https://github.com/projectcalico/canal" target="_blank" rel="noopener noreferrer">https://github.com/projectcalico/canal</a></td><td>712</td><td>100</td><td>20</td></tr><tr><td>Flannel</td><td><a href="https://github.com/flannel-io/flannel" target="_blank" rel="noopener noreferrer">https://github.com/flannel-io/flannel</a></td><td>8.5k</td><td>2.9k</td><td>235</td></tr><tr><td>Calico</td><td><a href="https://github.com/projectcalico/calico" target="_blank" rel="noopener noreferrer">https://github.com/projectcalico/calico</a></td><td>5.5k</td><td>1.2k</td><td>344</td></tr><tr><td>Weave</td><td><a href="https://github.com/weaveworks/weave/" target="_blank" rel="noopener noreferrer">https://github.com/weaveworks/weave/</a></td><td>6.6k</td><td>662</td><td>87</td></tr><tr><td>Cilium</td><td><a href="https://github.com/cilium/cilium" target="_blank" rel="noopener noreferrer">https://github.com/cilium/cilium</a></td><td>18.6k</td><td>2.7k</td><td>740</td></tr></tbody></table><h2 class="anchor anchorWithStickyNavbar_LWe7" id="which-cni-provider-should-i-use">Which CNI Provider Should I Use?<a href="#which-cni-provider-should-i-use" class="hash-link" aria-label="Direct link to Which CNI Provider Should I Use?" title="Direct link to Which CNI Provider Should I Use?"></a></h2><p>It depends on your project needs. There are many different providers, which each have various features and options. There isn't one provider that meets everyone's needs.</p><p>Canal is the default CNI network provider. We recommend it for most use cases. It provides encapsulated networking for containers with Flannel, while adding Calico network policies that can provide project/namespace isolation in terms of networking.</p><h2 class="anchor anchorWithStickyNavbar_LWe7" id="how-can-i-configure-a-cni-network-provider">How can I configure a CNI network provider?<a href="#how-can-i-configure-a-cni-network-provider" class="hash-link" aria-label="Direct link to How can I configure a CNI network provider?" title="Direct link to How can I configure a CNI network provider?"></a></h2><p>Please see <a href="/reference-guides/cluster-configuration/rancher-server-configuration/rke1-cluster-configuration">Cluster Options</a> on how to configure a network provider for your cluster. For more advanced configuration options, please see how to configure your cluster using a <a href="/reference-guides/cluster-configuration/rancher-server-configuration/rke1-cluster-configuration#rke-cluster-config-file-reference">Config File</a> and the options for <a href="https://rancher.com/docs/rke/latest/en/config-options/add-ons/network-plugins/" target="_blank" rel="noopener noreferrer">Network Plug-ins</a>.</p></div><footer class="theme-doc-footer docusaurus-mt-lg"><div class="theme-doc-footer-edit-meta-row row"><div class="col"><a href="https://github.com/rancher/rancher-docs/edit/main/docs/faq/container-network-interface-providers.md" target="_blank" rel="noreferrer noopener" class="theme-edit-this-page"><svg fill="currentColor" height="20" width="20" viewBox="0 0 40 40" class="iconEdit_Z9Sw" aria-hidden="true"><g><path d="m34.5 11.7l-3 3.1-6.3-6.3 3.1-3q0.5-0.5 1.2-0.5t1.1 0.5l3.9 3.9q0.5 0.4 0.5 1.1t-0.5 1.2z m-29.5 17.1l18.4-18.5 6.3 6.3-18.4 18.4h-6.3v-6.2z"></path></g></svg>Edit this page</a></div><div class="col lastUpdated_vwxv"><span class="theme-last-updated">Last updated<!-- --> on <b><time datetime="2024-02-23T22:12:58.000Z">Feb 23, 2024</time></b></span></div></div></footer></article><nav class="pagination-nav docusaurus-mt-lg" aria-label="Docs pages"><a class="pagination-nav__link pagination-nav__link--prev" href="/faq/telemetry"><div class="pagination-nav__sublabel">Previous</div><div class="pagination-nav__label">Telemetry FAQ</div></a><a class="pagination-nav__link pagination-nav__link--next" href="/faq/rancher-is-no-longer-needed"><div class="pagination-nav__sublabel">Next</div><div class="pagination-nav__label">Rancher is No Longer Needed</div></a></nav></div></div><div class="col col--3"><div class="tableOfContents_bqdL thin-scrollbar theme-doc-toc-desktop"><ul class="table-of-contents table-of-contents__left-border"><li><a href="#what-is-cni" class="table-of-contents__link toc-highlight">What is CNI?</a></li><li><a href="#what-network-models-are-used-in-cni" class="table-of-contents__link toc-highlight">What Network Models are Used in CNI?</a><ul><li><a href="#what-is-an-encapsulated-network" class="table-of-contents__link toc-highlight">What is an Encapsulated Network?</a></li><li><a href="#what-is-an-unencapsulated-network" class="table-of-contents__link toc-highlight">What is an Unencapsulated Network?</a></li></ul></li><li><a href="#what-cni-providers-are-provided-by-rancher" class="table-of-contents__link toc-highlight">What CNI Providers are Provided by Rancher?</a><ul><li><a href="#rke-kubernetes-clusters" class="table-of-contents__link toc-highlight">RKE Kubernetes clusters</a></li><li><a href="#rke2-kubernetes-clusters" class="table-of-contents__link toc-highlight">RKE2 Kubernetes clusters</a></li></ul></li><li><a href="#cni-features-by-provider" class="table-of-contents__link toc-highlight">CNI Features by Provider</a></li><li><a href="#cni-community-popularity" class="table-of-contents__link toc-highlight">CNI Community Popularity</a></li><li><a href="#which-cni-provider-should-i-use" class="table-of-contents__link toc-highlight">Which CNI Provider Should I Use?</a></li><li><a href="#how-can-i-configure-a-cni-network-provider" class="table-of-contents__link toc-highlight">How can I configure a CNI network provider?</a></li></ul></div></div></div></div></main></div></div><footer class="footer footer--dark"><div class="container container-fluid"><div class="footer__bottom text--center"><div class="footer__copyright">Copyright © 2024 SUSE Rancher. All Rights Reserved.</div></div></div></footer></div>
|
||
<script src="/assets/js/runtime~main.d98f8a34.js"></script>
|
||
<script src="/assets/js/main.e9ebdfba.js"></script>
|
||
</body>
|
||
</html> |