Skip to content

Node traffic

Traffic originating in a node’s own network namespace — anything on the host, hostNetwork pods included — is treated as coming from one network standing in for the node. Kubernetes assumes every node can reach every pod; Lace grants that to nothing implicitly, so the node is a source like any other and must be peered with what it should reach.

Kubelet’s probes of local pods are exempt and need none of this.

The networks chart ships a host-local network for this. No pod is ever bound to it — it exists so a policy can name node-originated traffic as its source.

  • hostLocalNetwork.enabled declares it.
  • hostLocalRouting.enabled peers it to a pod network (hostLocalRouting.dest, the default network when unset).

Enable it where something on the host dials pods itself.

From the node to What it takes
a pod address a NetworkRoutingPolicy from host-local to that pod’s network
a ClusterIP that same peering, plus node.serviceCIDRs on the plugin chart
another node’s NodePort a ServiceRoutingPolicy to the service — from the external network the source node’s address falls in, not from host-local, since the dialled node resolves it and sees an ordinary underlay source
a NodePort on its own address nothing — it is never answered, see unsupported features

node.serviceCIDRs must list the cluster’s service prefixes; without them the node has no route sending service traffic to Lace and it leaves by the uplink instead. The peering is needed alongside it because a service VIP resolves to an endpoint in the backing pods’ network, which is where the traffic actually goes.

Such a service’s endpoints are node addresses, which no pod network covers, so it resolves to a destination in no network and its ClusterIP carries nothing. Bind it to a network whose prefixes do cover node addresses — the internet network does through its default prefixes — the same way pods are bound:

apiVersion: lace-cni.io/v1alpha1
kind: NetworkBindingPolicy
metadata:
name: node-metrics
spec:
matchKind: [service]
rules:
- network: internet
selector:
name: lace-node-metrics

Lace’s own node metrics Service is one of these, since its backends are the node agent pods.