🐆
Container Platform

Calico

Kubernetes network policies and eBPF networking

🐧 Linux🍎 Mac🪟 Windows
Reviewed: Tested on: Kubernetes 1.29 · Terraform 1.8 · Ubuntu 22.04

What is this?

Calico provides network policies and pod networking for Kubernetes clusters.

📥

Step 01

Install Calico

(01)Install Calico

Linux
1kubectl create -f https://raw.githubusercontent.com/projectcalico/calico/v3.28.0/manifests/tigera-operator.yaml
2kubectl create -f https://raw.githubusercontent.com/projectcalico/calico/v3.28.0/manifests/custom-resources.yaml
⚙️

Step 02

Configure Calico

(01)Configure Calico

Linux
1cat > deny-all.yaml << 'EOF'
2apiVersion: networking.k8s.io/v1
3kind: NetworkPolicy
4metadata:
5 name: deny-all-ingress
6 namespace: default
7spec:
8 podSelector: {}
9 policyTypes: [Ingress]
10EOF
11kubectl apply -f deny-all.yaml

Step 03

Verify

(01)Verify installation

Linux
1kubectl get pods -n calico-system
2kubectl get ippools
🔧

Step 04

Common Problems

#1Calico pods not ready

Linux
1kubectl get pods -n calico-system
2kubectl logs -n calico-system -l k8s-app=calico-node --tail=30
3kubectl get installation default -o yaml

📋Config templates

2 YAML templates for Calico. Copy and deploy after setup.

2 ready-to-copy templates. Expand one, copy the YAML, then run the deploy commands.

deployment.yml

Deployment with resource requests/limits and local image

yaml
1apiVersion: apps/v1
2kind: Deployment
3metadata:
4 labels:
5 app: api-deploy
6 name: api-deploy
7spec:
8 replicas: 1
9 selector:
10 matchLabels:
11 app: api-deploy
12 template:
13 metadata:
14 labels:
15 app: api-deploy
16 spec:
17 containers:
18 - image: api:local
19 name: api
20 imagePullPolicy: IfNotPresent
21 ports:
22 - containerPort: 3000
23 resources:
24 limits:
25 memory: "512Mi"
26 cpu: "500m"
27 requests:
28 memory: "256Mi"
29 cpu: "250m"

services.yml

NodePort Service exposing the API on port 32000

yaml
1apiVersion: v1
2kind: Service
3metadata:
4 labels:
5 app: api-deploy
6 name: api-deploy-service
7spec:
8 type: NodePort
9 selector:
10 app: api-deploy
11 ports:
12 - port: 3000
13 protocol: TCP
14 targetPort: 3000
15 nodePort: 32000
📄

Step 01

Apply to Kubernetes

(01)Build image and load into cluster

Linux
1# Build local image
2docker build -t api:local .
3
4# For Minikube / Kind — load image into cluster
5minikube image load api:local
6# OR: kind load docker-image api:local

(02)Apply manifests

Linux
1kubectl apply -f deployment.yml
2kubectl apply -f services.yml
3kubectl get pods,svc
4curl http://localhost:32000 # or minikube service api-deploy-service