Tested on kube-sigs/kubespray commit a923f4e7c0692229c442b07a531bfb5fc41a23f9.
- Add
enable-endpoint-routes: "true"
at EOFkubespray/roles/network_plugin/cilium/templates/cilium-config.yml.j2
- Modify kubespray inventory
group_vars/k8s-cluster/k8s-net-cilium.yml
cilium_auto_direct_node_routes: true
cilium_native_routing_cidr: 10.10.2.0/24
cilium_tunnel_mode: disabled
- presented above
10.10.2.0/24
- it's lan ips dedicated to k8s cluster only- if you use some resources in your lan network you must provide the same routes on non-k8s machines (via systemd-networkd, for example).