Created
December 13, 2025 14:22
-
-
Save orange723/6e6e1a9d3646c7996355ad3de1396b70 to your computer and use it in GitHub Desktop.
flannel
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| apiVersion: v1 | |
| kind: Namespace | |
| metadata: | |
| labels: | |
| k8s-app: flannel | |
| pod-security.kubernetes.io/enforce: privileged | |
| name: kube-flannel | |
| --- | |
| apiVersion: v1 | |
| kind: ServiceAccount | |
| metadata: | |
| labels: | |
| k8s-app: flannel | |
| name: flannel | |
| namespace: kube-flannel | |
| --- | |
| apiVersion: rbac.authorization.k8s.io/v1 | |
| kind: ClusterRole | |
| metadata: | |
| labels: | |
| k8s-app: flannel | |
| name: flannel | |
| rules: | |
| - apiGroups: | |
| - "" | |
| resources: | |
| - pods | |
| verbs: | |
| - get | |
| - apiGroups: | |
| - "" | |
| resources: | |
| - nodes | |
| verbs: | |
| - get | |
| - list | |
| - watch | |
| - apiGroups: | |
| - "" | |
| resources: | |
| - nodes/status | |
| verbs: | |
| - patch | |
| --- | |
| apiVersion: rbac.authorization.k8s.io/v1 | |
| kind: ClusterRoleBinding | |
| metadata: | |
| labels: | |
| k8s-app: flannel | |
| name: flannel | |
| roleRef: | |
| apiGroup: rbac.authorization.k8s.io | |
| kind: ClusterRole | |
| name: flannel | |
| subjects: | |
| - kind: ServiceAccount | |
| name: flannel | |
| namespace: kube-flannel | |
| --- | |
| apiVersion: v1 | |
| data: | |
| cni-conf.json: | | |
| { | |
| "name": "cbr0", | |
| "cniVersion": "0.3.1", | |
| "plugins": [ | |
| { | |
| "type": "flannel", | |
| "delegate": { | |
| "hairpinMode": true, | |
| "isDefaultGateway": true | |
| } | |
| }, | |
| { | |
| "type": "portmap", | |
| "capabilities": { | |
| "portMappings": true | |
| } | |
| } | |
| ] | |
| } | |
| net-conf.json: | | |
| { | |
| "Network": "10.244.0.0/16", | |
| "EnableNFTables": false, | |
| "Backend": { | |
| "Type": "vxlan" | |
| } | |
| } | |
| kind: ConfigMap | |
| metadata: | |
| labels: | |
| app: flannel | |
| k8s-app: flannel | |
| tier: node | |
| name: kube-flannel-cfg | |
| namespace: kube-flannel | |
| --- | |
| apiVersion: apps/v1 | |
| kind: DaemonSet | |
| metadata: | |
| labels: | |
| app: flannel | |
| k8s-app: flannel | |
| tier: node | |
| name: kube-flannel-ds | |
| namespace: kube-flannel | |
| spec: | |
| selector: | |
| matchLabels: | |
| app: flannel | |
| k8s-app: flannel | |
| template: | |
| metadata: | |
| labels: | |
| app: flannel | |
| k8s-app: flannel | |
| tier: node | |
| spec: | |
| affinity: | |
| nodeAffinity: | |
| requiredDuringSchedulingIgnoredDuringExecution: | |
| nodeSelectorTerms: | |
| - matchExpressions: | |
| - key: kubernetes.io/os | |
| operator: In | |
| values: | |
| - linux | |
| containers: | |
| - args: | |
| - --ip-masq | |
| - --kube-subnet-mgr | |
| command: | |
| - /opt/bin/flanneld | |
| env: | |
| - name: POD_NAME | |
| valueFrom: | |
| fieldRef: | |
| fieldPath: metadata.name | |
| - name: POD_NAMESPACE | |
| valueFrom: | |
| fieldRef: | |
| fieldPath: metadata.namespace | |
| - name: EVENT_QUEUE_DEPTH | |
| value: "5000" | |
| - name: CONT_WHEN_CACHE_NOT_READY | |
| value: "false" | |
| image: ghcr.io/flannel-io/flannel:v0.27.4 | |
| name: kube-flannel | |
| resources: | |
| requests: | |
| cpu: 100m | |
| memory: 50Mi | |
| securityContext: | |
| capabilities: | |
| add: | |
| - NET_ADMIN | |
| - NET_RAW | |
| privileged: false | |
| volumeMounts: | |
| - mountPath: /run/flannel | |
| name: run | |
| - mountPath: /etc/kube-flannel/ | |
| name: flannel-cfg | |
| - mountPath: /run/xtables.lock | |
| name: xtables-lock | |
| hostNetwork: true | |
| initContainers: | |
| - args: | |
| - -f | |
| - /flannel | |
| - /opt/cni/bin/flannel | |
| command: | |
| - cp | |
| image: ghcr.io/flannel-io/flannel-cni-plugin:v1.8.0-flannel1 | |
| name: install-cni-plugin | |
| volumeMounts: | |
| - mountPath: /opt/cni/bin | |
| name: cni-plugin | |
| - args: | |
| - -f | |
| - /etc/kube-flannel/cni-conf.json | |
| - /etc/cni/net.d/10-flannel.conflist | |
| command: | |
| - cp | |
| image: ghcr.io/flannel-io/flannel:v0.27.4 | |
| name: install-cni | |
| volumeMounts: | |
| - mountPath: /etc/cni/net.d | |
| name: cni | |
| - mountPath: /etc/kube-flannel/ | |
| name: flannel-cfg | |
| priorityClassName: system-node-critical | |
| serviceAccountName: flannel | |
| tolerations: | |
| - effect: NoSchedule | |
| operator: Exists | |
| volumes: | |
| - hostPath: | |
| path: /run/flannel | |
| name: run | |
| - hostPath: | |
| path: /opt/cni/bin | |
| name: cni-plugin | |
| - hostPath: | |
| path: /etc/cni/net.d | |
| name: cni | |
| - configMap: | |
| name: kube-flannel-cfg | |
| name: flannel-cfg | |
| - hostPath: | |
| path: /run/xtables.lock | |
| type: FileOrCreate | |
| name: xtables-lock |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment