A Tanzu Kubernetes cluster provisioned by the Tanzu Kubernetes Grid Service supports two CNI options: Antrea (default) and Calico. Both are open-source software that provide networking for cluster pods, services, and ingress.
- Specify the CNI directly in the cluster YAML. See Examples for Provisioning Tanzu Kubernetes Clusters Using the Tanzu Kubernetes Grid Service v1alpha1 API.
- Change the default CNI. See Examples for Configuring the Tanzu Kubernetes Grid Service v1alpha1 API.
The table summarizes Tanzu Kubernetes cluster networking features and their implementation.
|Pod connectivity||Antrea or Calico||Container network interface for pods. Antrea uses Open vSwitch. Calico uses the Linux bridge with BGP.|
|Service type: ClusterIP||Antrea or Calico||Default Kubernetes service type that is only accessible from within the cluster.|
|Service type: NodePort||Antrea or Calico||Allows external access through a port opened on each worker node by the Kubernetes network proxy.|
|Service type: LoadBalancer||NSX-T load balancer, NSX Advanced Load Balancer, HAProxy||For NSX-T, one virtual server per service type definition. For NSX Advanced Load Balancer, refer to that section of this documentation.
Note: Some load balancing features may not be available with HAProxy, such as support for static IPs.
|Cluster ingress||Third-party ingress controller||Routing for inbound pod traffic; you can use any third-party ingress controller.|
|Network policy||Antrea or Calico||Controls what traffic is allowed to and from selected pods and network endpoints. Antrea uses Open vSwitch. Calico uses Linux IP tables.|