Cilium is a networking, security, and observability solution for Kubernetes, built on eBPF. It provides high-performance networking with support for Layer 3-7 policies, load balancing, and transparent encryption. With Cilium, you can enforce fine-grained security policies, observe network flows in real time, and integrate seamlessly with service meshes. It also offers eBPF-powered network policies and cluster mesh capabilities, enabling secure communication across multiple Kubernetes clusters.
Install with:
helm repo add cilium https://helm.cilium.io/
helm install cilium cilium/cilium -f values.yaml
See examples from other people.
Name | Repo | Stars | Version | Timestamp |
---|---|---|---|---|
cilium | kashalls/home-cluster | 113 | 1.17.1 | a day ago |
cilium | coolguy1771/home-ops | 69 | 1.17.1 | 2 days ago |
cilium | coolguy1771/home-ops | 69 | 1.17.1 | 2 days ago |
cilium | rafaribe/home-ops | 62 | 1.17.1 | 4 days ago |
cilium | JJGadgets/Biohazard | 49 | 1.17.0 | 5 days ago |
See the most popular values for this chart:
Key | Types |
---|---|
boolean | |
hubble.ui.ingress.hosts[] (114) - hubble.${SECRET_DOMAIN} | string |
string | |
hubble.ui.ingress.tls[].hosts[] (58) - hubble.${SECRET_DOMAIN} | string |
hubble.ui.ingress.tls[].secretName (18) hubble-tls | string |
hubble.ui.ingress.annotations."hajimari.io/icon" (16) simple-icons:cilium | string |
string | |
string | |
string | |
string | |
hubble.ui.ingress.annotations."cert-manager.io/cluster-issuer" (13) letsencrypt-production | string |
string | |
hubble.ui.ingress.annotations."gethomepage.dev/description" (10) Network Monitoring Dashboard | string |
string | |
string | |
string | |
string | |
string | |
hubble.ui.ingress.annotations."nginx.ingress.kubernetes.io/auth-response-headers" (5) Remote-User,Remote-Name,Remote-Groups,Remote-Email | string |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
boolean | |
boolean | |
number | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
string | |
boolean | |
boolean, string | |
boolean | |
boolean | |
boolean | |
string | |
string | |
string | |
number | |
string | |
boolean | |
hubble.metrics.enabled[] (102) - dns:query | string |
boolean, string | |
string | |
string | |
string | |
string | |
string | |
string | |
boolean, string | |
string | |
string | |
string | |
string | |
string | |
boolean | |
boolean | |
boolean | |
hubble.dashboards.namespace (10) monitoring | string |
string | |
hubble.dashboards.label (9) grafana_dashboard | string |
string | |
string | |
string | |
string | |
string | |
number | |
boolean | |
string | |
boolean | |
boolean | |
boolean | |
string | |
boolean | |
boolean | |
boolean | |
boolean | |
boolean | |
boolean | |
boolean | |
boolean | |
boolean | |
string | |
operator.prometheus.serviceMonitor.metricRelabelings[].regex (3) workqueue_(work|queue)_duration_seconds_bucket | string |
operator.prometheus.serviceMonitor.metricRelabelings[].sourceLabels[] (3) - __name__ | string |
boolean | |
string | |
boolean | |
boolean | |
string | |
string | |
string | |
string | |
string | |
boolean | |
number | |
boolean | |
string | |
string | |
boolean | |
string | |
string | |
string | |
string | |
ipam.mode (56) kubernetes | string |
number | |
string | |
number | |
string | |
boolean, string | |
k8sServiceHost (49) 127.0.0.1 | string |
number, string | |
boolean | |
ipv4NativeRoutingCIDR (45) ${CLUSTER_CIDR} | string |
boolean | |
boolean | |
cluster.name (44) home-cluster | string |
number, string | |
boolean | |
string | |
string | |
string | |
string | |
boolean | |
boolean | |
boolean | |
kubeProxyReplacementHealthzBindAddr (42) 0.0.0.0:10256 | string |
boolean | |
bpf.tproxy (9) true | boolean |
boolean | |
string | |
boolean | |
number | |
number | |
boolean | |
string | |
string | |
string | |
routingMode (37) native | string |
securityContext.capabilities.ciliumAgent[] (32) - CHOWN | string |
securityContext.capabilities.cleanCiliumState[] (32) - NET_ADMIN | string |
string | |
string | |
boolean | |
cgroup.hostRoot (30) /sys/fs/cgroup | string |
boolean | |
boolean | |
string | |
boolean | |
boolean | |
string | |
boolean | |
containerRuntime.integration (21) containerd | string |
containerRuntime.socketPath (17) /var/run/k3s/containerd/containerd.sock | string |
bgp.enabled (20) false | boolean |
boolean | |
boolean | |
cni.exclusive (18) false | boolean |
cni.binPath (5) /var/lib/rancher/k3s/data/cni | string |
cni.confPath (5) /var/lib/rancher/k3s/agent/etc/cni/net.d | string |
boolean | |
boolean | |
envoy.enabled (13) false | boolean |
boolean | |
boolean | |
tunnel (12) disabled | string |
boolean | |
boolean | |
boolean | |
boolean | |
string | |
l7Proxy (6) true | boolean |
boolean | |
boolean | |
string | |
boolean | |
string | |
string | |
string | |
boolean | |
boolean | |
boolean | |
string | |
string | |
boolean | |
boolean | |
boolean | |
string | |
number | |
number | |
boolean | |
string | |
string | |
string | |
string | |
boolean | |
boolean | |
boolean | |
boolean | |
boolean | |
string | |
boolean | |
boolean | |
string | |
boolean | |
boolean | |
boolean | |
boolean | |
boolean | |
boolean | |
string | |
string | |
number | |
string | |
string | |
boolean | |
boolean | |
string | |
boolean | |
boolean | |
boolean | |
string | |
number | |
string | |
string | |
boolean | |
boolean |