Node traffic
Traffic originating in a node’s own network namespace — anything on the host, hostNetwork pods included — is treated as coming from one network standing in for the node. Kubernetes assumes every node can reach every pod; Lace grants that to nothing implicitly, so the node is a source like any other and must be peered with what it should reach.
Kubelet’s probes of local pods are exempt and need none of this.
The node as a source network
Section titled “The node as a source network”The networks chart ships a host-local network for this. No pod is ever bound to it — it exists so a policy can name node-originated traffic as its source.
hostLocalNetwork.enableddeclares it.hostLocalRouting.enabledpeers it to a pod network (hostLocalRouting.dest, the default network when unset).
Enable it where something on the host dials pods itself.
Reaching pods and services
Section titled “Reaching pods and services”| From the node to | What it takes |
|---|---|
| a pod address | a NetworkRoutingPolicy from host-local to that pod’s network |
| a ClusterIP | that same peering, plus node.serviceCIDRs on the plugin chart |
| another node’s NodePort | a ServiceRoutingPolicy to the service — from the external network the source node’s address falls in, not from host-local, since the dialled node resolves it and sees an ordinary underlay source |
| a NodePort on its own address | nothing — it is never answered, see unsupported features |
node.serviceCIDRs must list the cluster’s service prefixes; without them the node has no route sending service traffic to Lace and it leaves by the uplink instead. The peering is needed alongside it because a service VIP resolves to an endpoint in the backing pods’ network, which is where the traffic actually goes.
Services backed by hostNetwork pods
Section titled “Services backed by hostNetwork pods”Such a service’s endpoints are node addresses, which no pod network covers, so it resolves to a destination in no network and its ClusterIP carries nothing. Bind it to a network whose prefixes do cover node addresses — the internet network does through its default prefixes — the same way pods are bound:
apiVersion: lace-cni.io/v1alpha1kind: NetworkBindingPolicymetadata: name: node-metricsspec: matchKind: [service] rules: - network: internet selector: name: lace-node-metricsLace’s own node metrics Service is one of these, since its backends are the node agent pods.
See also
Section titled “See also”- Networks — binding a service to a network.
- Topology — routing and service policies.
- External networks — how node addresses classify.