DirectorySecurity AdvisoriesPricing
Sign in
Directory
istio-cni logoHELM

istio-cni

Helm chart
Last changed
Request a free trial

Contact our team to test out this Helm chart and related images for free. Please also indicate any other images you would like to evaluate.

Overview
Chart tags
Default values
Chart metadata
Images

Tag:
Compare:

1
# "_internal_defaults_do_not_set" is a workaround for Helm limitations. Users should NOT set "._internal_defaults_do_not_set" explicitly, but rather directly set the fields internally.
2
# For instance, instead of `--set _internal_defaults_do_not_set.foo=bar``, just set `--set foo=bar`.
3
image: istio-install-cni
4
global:
5
hub: chainreg.biz/chainguard-private
6
tag: 1.31.1-r2@sha256:aab0a1b8b275c079ffd5e1765f8c55673d00b13f6c51a837f9243f4240150412
7
variant: ""
8
_internal_defaults_do_not_set:
9
hub: ""
10
tag: ""
11
variant: ""
12
image: install-cni
13
pullPolicy: ""
14
# Same as `global.logging.level`, but will override it if set
15
logging:
16
level: ""
17
# Configuration file to insert istio-cni plugin configuration
18
# by default this will be the first file found in the cni-conf-dir
19
# Example
20
# cniConfFileName: 10-calico.conflist
21
22
# CNI-and-platform specific path defaults.
23
# These may need to be set to platform-specific values, consult
24
# overrides for your platform in `manifests/helm-profiles/platform-*.yaml`
25
cniBinDir: /opt/cni/bin
26
cniConfDir: /etc/cni/net.d
27
cniConfFileName: ""
28
cniNetnsDir: "/var/run/netns"
29
# If Istio owned CNI config is enabled, defaults to 02-istio-cni.conflist
30
istioOwnedCNIConfigFileName: ""
31
istioOwnedCNIConfig: false
32
excludeNamespaces:
33
- kube-system
34
# Allows user to set custom affinity for the DaemonSet
35
affinity: {}
36
# Additional labels to apply on the daemonset level
37
daemonSetLabels: {}
38
# Custom annotations on pod level, if you need them
39
podAnnotations: {}
40
# Additional labels to apply on the pod level
41
podLabels: {}
42
# Deploy the config files as plugin chain (value "true") or as standalone files in the conf dir (value "false")?
43
# Some k8s flavors (e.g. OpenShift) do not support the chain approach, set to false if this is the case
44
chained: true
45
# Custom configuration happens based on the CNI provider.
46
# Possible values: "default", "multus"
47
provider: "default"
48
# Configure ambient settings
49
ambient:
50
# If enabled, ambient redirection will be enabled
51
enabled: false
52
# If ambient is enabled, this selector will be used to identify the ambient-enabled pods
53
enablementSelectors:
54
- podSelector:
55
matchLabels: {istio.io/dataplane-mode: ambient}
56
- podSelector:
57
matchExpressions:
58
- {key: istio.io/dataplane-mode, operator: NotIn, values: [none]}
59
namespaceSelector:
60
matchLabels: {istio.io/dataplane-mode: ambient}
61
# Set ambient config dir path: defaults to /etc/ambient-config
62
configDir: ""
63
# If enabled, and ambient is enabled, DNS redirection will be enabled
64
dnsCapture: true
65
# If enabled, and ambient is enabled, enables ipv6 support
66
ipv6: true
67
# If enabled, and ambient is enabled, the CNI agent will reconcile incompatible iptables rules and chains at startup.
68
# This is enabled by default
69
reconcileIptablesOnStartup: true
70
# If enabled, and ambient is enabled, the CNI agent will always share the network namespace of the host node it is running on
71
shareHostNetworkNamespace: false
72
# If enabled, the CNI agent will retry checking if a pod is ambient enabled when there are errors
73
enableAmbientDetectionRetry: false
74
repair:
75
enabled: true
76
hub: ""
77
tag: ""
78
# Repair controller has 3 modes. Pick which one meets your use cases. Note only one may be used.
79
# This defines the action the controller will take when a pod is detected as broken.
80
81
# labelPods will label all pods with <brokenPodLabelKey>=<brokenPodLabelValue>.
82
# This is only capable of identifying broken pods; the user is responsible for fixing them (generally, by deleting them).
83
# Note this gives the DaemonSet a relatively high privilege, as modifying pod metadata/status can have wider impacts.
84
labelPods: false
85
# deletePods will delete any broken pod. These will then be rescheduled, hopefully onto a node that is fully ready.
86
# Note this gives the DaemonSet a relatively high privilege, as it can delete any Pod.
87
deletePods: false
88
# repairPods will dynamically repair any broken pod by setting up the pod networking configuration even after it has started.
89
# Note the pod will be crashlooping, so this may take a few minutes to become fully functional based on when the retry occurs.
90
# This requires no RBAC privilege, but does require `securityContext.privileged/CAP_SYS_ADMIN`.
91
repairPods: true
92
initContainerName: "istio-validation"
93
brokenPodLabelKey: "cni.istio.io/uninitialized"
94
brokenPodLabelValue: "true"
95
# Set to `type: RuntimeDefault` to use the default profile if available.
96
seccompProfile: {}
97
# SELinux options to set in the istio-cni-node pods. You may need to set this to `type: spc_t` for some platforms.
98
seLinuxOptions: {}
99
# Use `useAppArmorAnnotation: true` to set up appArmor profile via `container.apparmor.security.beta.kubernetes.io` annotation.
100
# This is required for Kubernetes 1.29 (and earlier) which does not support setting appArmorProfile in the
101
# securityContext. Otherwise, appArmor profile will be set via appArmorProfile setting in securityContext.
102
useAppArmorAnnotation: true
103
resources:
104
requests:
105
cpu: 100m
106
memory: 100Mi
107
resourceQuotas:
108
enabled: false
109
pods: 5000
110
tolerations:
111
# Make sure istio-cni-node gets scheduled on all nodes.
112
- effect: NoSchedule
113
operator: Exists
114
# Mark the pod as a critical add-on for rescheduling.
115
- key: CriticalAddonsOnly
116
operator: Exists
117
- effect: NoExecute
118
operator: Exists
119
# K8s DaemonSet update strategy.
120
# https://kubernetes.io/docs/reference/kubernetes-api/workload-resources/daemon-set-v1/#DaemonSetSpec).
121
updateStrategy:
122
type: RollingUpdate
123
rollingUpdate:
124
maxUnavailable: 1
125
# Sets the per-pod terminationGracePeriodSeconds setting.
126
# A higher value gives more time for CNI cleanup during rolling updates,
127
# preventing "failed to find plugin istio-cni" errors.
128
# Default K8s value is 30 seconds.
129
terminationGracePeriodSeconds: 30
130
# Revision is set as 'version' label and part of the resource names when installing multiple control planes.
131
revision: ""
132
# For Helm compatibility.
133
ownerName: ""
134
global:
135
# Default hub for Istio images.
136
# Releases are published to docker hub under 'istio' project.
137
# Dev builds from prow are on registry.istio.io/testing
138
hub: registry.istio.io/testing
139
# Default tag for Istio images.
140
tag: latest
141
# Variant of the image to use.
142
# Currently supported are: [debug, distroless]
143
variant: ""
144
# Specify image pull policy if default behavior isn't desired.
145
# Default behavior: latest images will be Always else IfNotPresent.
146
imagePullPolicy: ""
147
# change cni scope level to control logging out of istio-cni-node DaemonSet
148
logging:
149
level: info
150
logAsJson: false
151
# When enabled, default NetworkPolicy resources will be created
152
networkPolicy:
153
enabled: false
154
# ImagePullSecrets for all ServiceAccount, list of secrets in the same namespace
155
# to use for pulling any images in pods that reference this ServiceAccount.
156
# For components that don't use ServiceAccounts (i.e. grafana, servicegraph, tracing)
157
# ImagePullSecrets will be added to the corresponding Deployment(StatefulSet) objects.
158
# Must be set for any cluster configured with private docker registry.
159
imagePullSecrets: []
160
# - private-registry-key
161
162
# Default resources allocated
163
defaultResources:
164
requests:
165
cpu: 100m
166
memory: 100Mi
167
# In order to use native nftable rules instead of iptable rules, set this flag to true.
168
nativeNftables: false
169
# resourceScope controls what resources will be processed by helm.
170
# This is useful when installing Istio on a cluster where some resources need to be owned by a cluster administrator and some can be owned by the mesh administrator.
171
# It can be one of:
172
# - all: all resources are processed
173
# - cluster: only cluster-scoped resources are processed
174
# - namespace: only namespace-scoped resources are processed
175
resourceScope: all
176
# A `key: value` mapping of environment variables to add to the pod
177
env: {}
178

The trusted source for open source

Talk to an expert
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsChainguard OS PackagesChainguard ActionsChainguard Agent SkillsIntegrationsPricing
© 2026 Chainguard, Inc. All Rights Reserved.
Chainguard® and the Chainguard logo are registered trademarks of Chainguard, Inc. in the United States and/or other countries.
The other respective trademarks mentioned on this page are owned by the respective companies and use of them does not imply any affiliation or endorsement.