{"id":32739434,"url":"https://github.com/istio/cni","last_synced_at":"2025-11-03T09:02:16.458Z","repository":{"id":55878960,"uuid":"150199467","full_name":"istio/cni","owner":"istio","description":"Istio CNI to setup kubernetes pod namespaces to redirect traffic to sidecar proxy.","archived":true,"fork":false,"pushed_at":"2020-12-09T23:40:14.000Z","size":54232,"stargazers_count":140,"open_issues_count":2,"forks_count":86,"subscribers_count":105,"default_branch":"master","last_synced_at":"2024-04-16T23:49:23.987Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Go","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/istio.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":"CODEOWNERS","security":null,"support":null}},"created_at":"2018-09-25T02:58:43.000Z","updated_at":"2024-04-16T23:49:23.987Z","dependencies_parsed_at":"2022-08-15T08:30:41.653Z","dependency_job_id":null,"html_url":"https://github.com/istio/cni","commit_stats":null,"previous_names":[],"tags_count":110,"template":false,"template_full_name":null,"purl":"pkg:github/istio/cni","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/istio%2Fcni","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/istio%2Fcni/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/istio%2Fcni/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/istio%2Fcni/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/istio","download_url":"https://codeload.github.com/istio/cni/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/istio%2Fcni/sbom","scorecard":{"id":496336,"data":{"date":"2025-08-11","repo":{"name":"github.com/istio/cni","commit":"c2c2a7e0c929528f76504e3c799df2c8a7118025"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":2.8,"checks":[{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Maintained","score":0,"reason":"project is archived","details":["Warn: Repository is archived."],"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Code-Review","score":2,"reason":"Found 7/30 approved changesets -- score normalized to 2","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: containerImage not pinned by hash: deployments/kubernetes/Dockerfile.install-cni:1: pin your Docker image by updating ubuntu:xenial to ubuntu:xenial@sha256:1f1a2d56de1d604801a9671f301190704c25d604a416f59e03c04f5c6ffee0d6","Info:   0 out of   1 containerImage dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Vulnerabilities","score":5,"reason":"5 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2022-0230 / GHSA-xjqr-g762-pxwp","Warn: Project is vulnerable to: GO-2023-1915 / GHSA-fx6x-h9g4-56f8","Warn: Project is vulnerable to: GO-2024-2748 / GHSA-33c5-9fx5-fvjm","Warn: Project is vulnerable to: GO-2021-0065 / GHSA-jmrx-5g74-6v2f","Warn: Project is vulnerable to: GO-2021-0064 / GHSA-8cfg-vx93-jvxw"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}}]},"last_synced_at":"2025-08-19T20:30:05.329Z","repository_id":55878960,"created_at":"2025-08-19T20:30:05.329Z","updated_at":"2025-08-19T20:30:05.329Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":282430364,"owners_count":26667755,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-11-03T02:00:05.676Z","response_time":108,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2025-11-03T09:01:10.504Z","updated_at":"2025-11-03T09:02:16.430Z","avatar_url":"https://github.com/istio.png","language":"Go","funding_links":[],"categories":["Networking \u0026 Connectivity"],"sub_categories":[],"readme":"[![Go Report Card](https://goreportcard.com/badge/github.com/istio/cni)](https://goreportcard.com/report/github.com/istio/cni)\n[![GolangCI](https://golangci.com/badges/github.com/istio/cni.svg)](https://golangci.com/r/github.com/istio/cni)\n\n# Deprecation Notice\n\nThis repo has been merged into [istio.io/istio/cni](https://github.com/istio/istio/blob/master/cni/). Please go to that repo\nto make any changes to CNI. The only exception is bug backports to branches \u003c= 1.6, which should be submitted here. The text\nbelow is preserved for reference but is no longer maintained at this location.\n\n# Istio CNI plugin\n\nFor application pods in the Istio service mesh, all traffic to/from the pods needs to go through the\nsidecar proxies (istio-proxy containers).  This `istio-cni` Container Network Interface (CNI) plugin will\nset up the pods' networking to fulfill this requirement in place of the current Istio injected pod `initContainers`\n`istio-init` approach.\n\nThis is currently accomplished (for IPv4) via configuring the iptables rules in the netns for the pods.\n\nThe CNI handling the netns setup replaces the current Istio approach using a `NET_ADMIN` privileged\n`initContainers` container, `istio-init`, injected in the pods along with `istio-proxy` sidecars.  This\nremoves the need for a privileged, `NET_ADMIN` container in the Istio users' application pods.\n\n## Usage\n\nA complete set of instructions on how to use and install the Istio CNI is available on the Istio documentation site under [Install Istio with the Istio CNI plugin](https://preliminary.istio.io/docs/setup/kubernetes/install/cni/).  Only a summary is provided here.  The steps are:\n\n1. Install Kubernetes and `kubelet` in a manner that can support the CNI\n\n1. Install Kubernetes with the [ServiceAccount admission controller](https://kubernetes.io/docs/reference/access-authn-authz/admission-controllers/#serviceaccount) enabled\n\n1. Install the Istio CNI components. A specific example assuming locally built CNI images would be:\n\n    ```console\n    $ CNI_HUB=docker.io/my_userid\n    $ CNI_TAG=mytag\n    # run from the ${GOPATH}/src/istio.io/cni dir (repo where istio/cni was cloned)\n    $ helm template --name=istio-cni --namespace=kube-system --set \"excludeNamespaces={}\" --set hub=${CNI_HUB} --set tag=${CNI_TAG} --set pullPolicy=IfNotPresent --set logLevel=debug  deployments/kubernetes/install/helm/istio-cni \u003e istio-cni_install.yaml\n    $ kubectl apply -f istio-cni_install.yaml\n    ```\n\n1. Create and apply Istio manifests with the Istio CNI plugin enabled using the `--set istio_cni.enabled=true` Helm variable\n\nFor most Kubernetes environments the `istio-cni` [helm parameters' defaults](deployments/kubernetes/install/helm/istio-cni/values.yaml) will configure the Istio CNI plugin in a manner compatible with the Kubernetes installation.  Refer to\nthe [Hosted Kubernetes Usage](#hosted-kubernetes-usage) section for Kubernetes environment specific procedures.\n\nHelm chart parameters:\n\n| Option | Values | Default | Description |\n|--------|--------|---------|-------------|\n| hub | | | The container registry to pull the `install-cni` image. |\n| tag | | | The container tag to use to pull the `install-cni` image. |\n| logLevel | `panic`, `fatal`, `error`, `warn`, `info`, `debug` | `warn` | Logging level for CNI binary |\n| excludeNamespaces | `[]string` | `[ istio-system ]` | List of namespaces to exclude from Istio pod check |\n| cniBinDir | | `/opt/cni/bin` | Must be the same as the environment's `--cni-bin-dir` setting (`kubelet` param) |\n| cniConfDir | | `/etc/cni/net.d` | Must be the same as the environment's `--cni-conf-dir` setting (`kubelet` param) |\n| cniConfFileName | | None | Leave unset to auto-find the first file in the `cni-conf-dir` (as `kubelet` does).  Primarily used for testing `install-cni` plugin config.  If set, `install-cni` will inject the plugin config into this file in the `cni-conf-dir` |\n| psp_cluster_role | | | A `ClusterRole` that sets the according use of [PodSecurityPolicy](https://kubernetes.io/docs/concepts/policy/pod-security-policy) for the `ServiceAccount`|\n| chained | `true` or `false` | `true` | Whether to deploy the config file as a plugin chain or as a standalone file in the conf dir. Some k8s flavors (e.g. OpenShift) do not support the chain approach, set to false if this is the case. |\n\n### Hosted Kubernetes Usage\n\nNot all hosted Kubernetes clusters are created with the `kubelet` configured to use the CNI plugin so\ncompatibility with this `istio-cni` solution is not ubiquitous.  The `istio-cni` plugin is expected\nto work with any hosted kubernetes leveraging CNI plugins.  The below table indicates the known CNI status\nof hosted Kubernetes environments and whether `istio-cni` has been trialed in the cluster type.\n\n| Hosted Cluster Type | Uses CNI | istio-cni tested? |\n|---------------------|----------|-------------------|\n| GKE 1.9.7-gke.6 default | N | N |\n| GKE 1.9.7-gke.6 w/ [network-policy](https://cloud.google.com/kubernetes-engine/docs/how-to/network-policy) | Y | Y |\n| IKS (IBM cloud) | Y | Y (on k8s 1.10) |\n| EKS (AWS) | Y | N |\n| AKS (Azure) | Y | N |\n| Red Hat OpenShift 3.10| Y | Y |\n\n#### GKE Setup\n\n1. Enable [network-policy](https://cloud.google.com/kubernetes-engine/docs/how-to/network-policy) in your cluster.  NOTE: for existing clusters this redeploys the nodes.\n\n1. Make sure your kubectl user (service-account) has a ClusterRoleBinding to the `cluster-admin` role.  This is also a typical pre-requisite for installing Istio on GKE.\n    1. `kubectl create clusterrolebinding cni-cluster-admin-binding --clusterrole=cluster-admin --user=istio-user@gmail.com`\n        1. User `istio-user@gmail.com` is an admin user associated with the gcloud GKE cluster\n\n1. Create the Istio CNI manifests with this Helm chart option `--set cniBinDir=/home/kubernetes/bin`\n\n#### IKS Setup\n\nNo special set up is required for IKS, as it currently uses the default `cni-conf-dir` and `cni-bin-dir`.\n\n#### Red Hat OpenShift Setup\n\nAdd the following section into [istio-cni.yaml](deployments/kubernetes/install/helm/istio-cni/templates/istio-cni.yaml#L109)\nto run the `install-cni` DaemonSet container as privileged so that it has proper write permission in the host filesystem:\n\n```yaml\nsecurityContext:\n  privileged: true\n```\n\n1. Grant privileged permission to `istio-cni` service account:\n\n```console\n$ oc adm policy add-scc-to-user privileged -z istio-cni -n kube-system\n```\n\n## Build\n\nFirst, clone this repository under `$GOPATH/src/istio.io/`.\n\nFor linux targets:\n\n```console\n$ GOOS=linux make build\n```\n\nYou can also build the project from a non-standard location like so:\n\n```console\n$ ISTIO_CNI_RELPATH=github.com/some/cni GOOS=linux make build\n```\n\nTo push the Docker image:\n\n```console\n$ export HUB=docker.io/myuser\n$ export TAG=dev\n$ GOOS=linux make docker.push\n```\n\n**NOTE:** Set HUB and TAG per your docker registry.\n\n### Helm\n\nThe Helm package tarfile can be created via\n\n```console\n$ helm package $GOPATH/src/istio.io/cni/deployments/kubernetes/install/helm/istio-cni\n```\n\n#### Serve Helm Repo\n\nAn example for hosting a test repo for the Helm istio-cni package:\n\n1. Create package tarfile with `helm package $GOPATH/src/istio.io/cni/deployments/kubernetes/install/helm/istio-cni`\n1. Copy tarfile to dir to serve the repo from\n1. Run `helm serve --repo-path \u003cdir where helm tarfile is\u003e \u0026`\n\n    1. The repo URL will be output (`http://127.0.0.1:8879`)\n    1. (optional) Use the `--address \u003cIP\u003e:\u003cport\u003e` option to bind the server to a specific address/port\n\nTo use this repo via `helm install`:\n\n```console\n$ helm repo add local_istio http://127.0.0.1:8879\n$ helm repo update\n```\n\nAt this point the `istio-cni` chart is ready for use by `helm install`.\n\nTo make use of the `istio-cni` chart from another chart:\n\n1. Add the following to the other chart's `requirements.yaml`:\n\n   ```yaml\n   - name: istio-cni\n     version: \"\u003e=0.0.1\"\n     repository: http://127.0.0.1:8879\n     condition: istio-cni.enabled\n   ```\n\n1. Run `helm dependency update \u003cchart\u003e` on the chart that needs to depend on istio-cni.\n\n    1. NOTE: for [istio/istio](https://github.com/istio/istio/tree/master/install/kubernetes/helm/istio) the charts\n       need to be reorganized to make `helm dependency update` work.  The child charts (pilot, galley, etc) need to\n       be made independent charts in the directorkefiy at the same level as the main `istio` chart\n       (\u003chttps://github.com/istio/istio/pull/9306\u003e).\n\n## Testing\n\nThe Istio CNI testing strategy and execution details are explained [here](test/README.md).\n\n## Troubleshooting\n\n### Validate the iptables are modified\n\n1. Collect your pod's container id using kubectl.\n\n    ```console\n    $ ns=test-istio\n    $ podnm=reviews-v1-6b7f6db5c5-59jhf\n    $ container_id=$(kubectl get pod -n ${ns} ${podnm} -o jsonpath=\"{.status.containerStatuses[?(@.name=='istio-proxy')].containerID}\" | sed -n 's/docker:\\/\\/\\(.*\\)/\\1/p')\n    ```\n\n1. SSH into the Kubernetes worker node that runs your pod.\n\n1. Use `nsenter` to view the iptables.\n\n    ```console\n    $ cpid=$(docker inspect --format '{{ .State.Pid }}' $container_id)\n    $ nsenter -t $cpid -n iptables -L -t nat -n -v --line-numbers -x\n    ```\n\n### Collecting Logs\n\nThe CNI plugins are executed by threads in the `kubelet` process.  The CNI plugins logs end up the syslog\nunder the `kubelet` process.  On systems with `journalctl` the following is an example command line\nto view the last 1000 `kubelet` logs via the `less` utility to allow for `vi`-style searching:\n\n```console\n$ journalctl -t kubelet -n 1000 | less\n```\n\n#### GKE via Stackdriver Log Viewer\n\nEach GKE cluster's will have many categories of logs collected by Stackdriver.  Logs can be monitored via\nthe project's [log viewer](https://cloud.google.com/logging/docs/view/overview) and/or the `gcloud logging read`\ncapability.\n\nThe following example grabs the last 10 `kubelet` logs containing the string \"cmdAdd\" in the log message.\n\n```console\n$ gcloud logging read \"resource.type=gce_instance AND jsonPayload.SYSLOG_IDENTIFIER=kubelet AND jsonPayload.MESSAGE:cmdAdd\" --limit 10 --format json\n```\n\n## Implementation Details\n\n### Overview\n\n- [istio-cni.yaml](deployments/kubernetes/install/helm/istio-cni/templates/istio-cni.yaml)\n    - Helm chart manifest for deploying `install-cni` container as daemonset\n    - `istio-cni-config` configmap with CNI plugin config to add to CNI plugin chained config\n    - creates service-account `istio-cni` with `ClusterRoleBinding` to allow gets on pods' info\n\n- `install-cni` container\n    - copies `istio-cni` binary and `istio-iptables.sh` to `/opt/cni/bin`\n    - creates kubeconfig for the service account the pod is run under\n    - injects the CNI plugin config to the config file pointed to by CNI_CONF_NAME env var\n        - example: `CNI_CONF_NAME: 10-calico.conflist`\n        - `jq` is used to insert `CNI_NETWORK_CONFIG` into the `plugins` list in `/etc/cni/net.d/${CNI_CONF_NAME}`\n\n- `istio-cni`\n    - CNI plugin executable copied to `/opt/cni/bin`\n    - currently implemented for k8s only\n    - on pod add, determines whether pod should have netns setup to redirect to Istio proxy\n        - if so, calls `istio-iptables.sh` with params to setup pod netns\n\n- [istio-iptables.sh](tools/istio-cni-docker.mk)\n    - sets up iptables to redirect a list of ports to the port envoy will listen\n\n### Background\n\nThe framework for this implementation of the CNI plugin is based on the\n[containernetworking sample plugin](https://github.com/containernetworking/plugins/blob/master/plugins/sample).\n\n#### Build Toolchains\n\nThe Istio makefiles and container build logic was leveraged heavily/lifted for this repo.\n\nSpecifically:\n- golang build logic\n- multi-arch target logic\n- k8s lib versions (Gopkg.toml)\n- docker container build logic\n    - setup staging dir for docker build\n    - grab built executables from target dir and cp to staging dir for docker build\n    - tagging and push logic\n\n#### Deployment\n\nThe details for the deployment \u0026 installation of this plugin were pretty much lifted directly from the\n[Calico CNI plugin](https://github.com/projectcalico/cni-plugin).\n\nSpecifically:\n\n- [CNI installation script](https://github.com/projectcalico/cni-plugin/blob/master/k8s-install/scripts/install-cni.sh)\n    - This does the following\n        - sets up CNI conf in /host/etc/cni/net.d/*\n        - copies calico CNI binaries to /host/opt/cni/bin\n        - builds kubeconfig for CNI plugin from service-account info mounted in the pod:\n          \u003chttps://github.com/projectcalico/cni-plugin/blob/master/k8s-install/scripts/install-cni.sh#L142\u003e\n        - reference: \u003chttps://kubernetes.io/docs/reference/access-authn-authz/service-accounts-admin/\u003e\n- The CNI installation script is containerized and deployed as a daemonset in k8s.  The relevant\n  calico k8s manifests were used as the model for the istio-cni plugin's manifest:\n    - [daemonset and configmap](https://docs.projectcalico.org/v3.2/getting-started/kubernetes/installation/hosted/calico.yaml)\n        - search for the `calico-node` Daemonset and its `install-cni` container deployment\n    - [RBAC](https://docs.projectcalico.org/v3.2/getting-started/kubernetes/installation/rbac.yaml)\n        - this creates the service account the CNI plugin is configured to use to access the kube-api-server\n\nThe installation script `install-cni.sh` injects the `istio-cni` plugin config at the end of the CNI plugin chain\nconfig.  It creates or modifies the file from the configmap created by the Kubernetes manifest.\n\n#### Plugin Logic\n\n##### cmdAdd\n\nWorkflow:\n1. Check k8s pod namespace against exclusion list (plugin config)\n    1. Config must exclude namespace that Istio control-plane is installed in\n    1. If excluded, ignore the pod and return prevResult\n1. Setup redirect rules for the pods:\n    1. Get the port list from pods definition\n    1. Setup iptables with required port list: `nsenter --net=\u003ck8s pod netns\u003e /opt/cni/bin/istio-iptables.sh ...`\n\n    Following conditions will prevent the redirect rules to be setup in the pods:\n\n        1. Pods only have 1 container(no sidecar proxy injected)\n        2. Pods have annotation `sidecar.istio.io/inject` set to `false` or has no key `sidecar.istio.io/status` in annotations\n        3. Pod has `istio-init` initContainer\n        4. Pods are in one of the namespaces specified in the `exclude_namespaces` parameter of the `istio-cni` plugin config\n1.  Return prevResult\n\n**TBD** istioctl / auto-sidecar-inject logic for handling things like specific include/exclude IPs and any\nother features.\n-  Watch configmaps or CRDs and update the `istio-cni` plugin's config\n   with these options.\n\n##### cmdDel\n\nAnything needed?  The netns is destroyed by `kubelet` so ideally this is a NOOP.\n\n##### Logging\n\nThe plugin leverages `logrus` \u0026 directly utilizes some Calico logging lib util functions.\n\n## Comparison with Pod Network Controller Approach\n\nThe proposed [Istio pod network controller](https://github.com/sabre1041/istio-pod-network-controller) has\nthe problem of synchronizing the netns setup with the rest of the pod init.  This approach requires implementing\ncustom synchronization between the controller and pod initialization.\n\nKubernetes has already solved this problem by not starting any containers in new pods until the full CNI plugin\nchain has completed successfully.  Also, architecturally, the CNI plugins are the components responsible for network\nsetup for container runtimes.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fistio%2Fcni","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fistio%2Fcni","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fistio%2Fcni/lists"}