MENU

Fun & Interesting

Learned it the hard way: don't use Cilium's default Pod CIDR, with Isala Piyarisi | KubeFM

KubeFM 416 2 months ago
Video Not Working? Fix It Now

This episode is sponsored by Learnk8s — get started on your Kubernetes journey through comprehensive online, in-person or remote training. https://learnk8s.io/training === This episode examines how a default configuration in *Cilium CNI* led to silent packet drops in production after 8 months of stable operations. *Isala Piyarisi*, Senior Software Engineer at *WSO2*, shares how his team discovered that *Cilium's default Pod CIDR* (10.0.0.0/8) was conflicting with their *Azure Firewall* subnet assignments, causing traffic disruptions in their staging environment. You will learn: - How *Cilium's default CIDR* allocation can create routing conflicts with existing infrastructure - A methodical process for debugging network issues using *packet tracing*, *routing table analysis*, and *firewall logs* - The procedure for safely changing *Pod CIDR* ranges in production clusters Find all the links and info for this episode here: https://ku.bz/kJjXQlmTw === Interested in sponsoring a KubeFM episode? https://kube.fm/sponsorships === CHAPTERS ========= 00:00 Introduction 01:04 Sponsor 01:09 Three emerging Kubernetes tools 02:21 Professional background and role 03:05 Journey into cloud native 04:45 Staying updated with Kubernetes 05:47 Career advice and blogging 06:37 Background with eBPF and Cilium migration 09:15 Reasons for choosing Cilium CNI 10:44 Post-migration incident in staging 12:30 Troubleshooting process 14:00 Root cause analysis: subnet assignments 18:20 Why the issue remained hidden 19:19 Resolution and implementation 22:33 Lessons learned 24:14 Prevention and detection strategies 26:13 Managing pressure and stress 28:35 Conference speaking and future plans 31:36 Outro LISTEN ON ========= - Apple Podcast https://kube.fm/apple - Spotify https://kube.fm/spotify - Amazon Music https://kube.fm/amazon - Overcast https://kube.fm/overcast - Pocket casts https://kube.fm/pocket-casts - Deezer https://kube.fm/deezer

Comment