KOP Recipes - Install Calico - Rafay Product Documentation

Install

What Will You Do

In this exercise,

Important
This tutorial describes the steps to create and use a custom cluster blueprint using the Web Console. The entire workflow can also be fully automated and embedded into an automation pipeline.

Assumptions

Step 1: Create NetworkPolicy Yaml

---
kind: Namespace
apiVersion: v1
metadata:
  name: namespace-a
  labels:
    ns-policy: namespace-a
---
kind: NetworkPolicy
apiVersion: networking.k8s.io/v1
metadata:
  name: np-allow-ns-a-b
spec:
  podSelector:
    matchLabels: {}
  ingress:
  - from:
    - namespaceSelector:
        matchLabels:
          ns-policy: namespace-b
    - namespaceSelector:
        matchLabels:
          ns-policy: namespace-a
  egress:
  - to:
    - namespaceSelector:
        matchLabels:
          ns-policy: namespace-b
    - namespaceSelector:
        matchLabels:
          ns-policy: namespace-a

Step 2: Create Namespace Yaml

kind: Namespace
apiVersion: v1
metadata:
  name: namespace-b
  labels:
    ns-policy: namespace-b

Step 3: Create NetworkPolicy Addons

Step 4: Create Blueprint

Now, we are ready to assemble a custom cluster blueprint using the addons.

Once the blueprint is created, ensure you publish it and optionally provide a version so that it can be tracked.

Step 5: Apply Blueprint

Now, we are ready to apply this custom blueprint to a cluster.

Click on "Save and Publish". This will start the deployment of the addons configured in the np-ns-a-allow-ns-b blueprint to the targeted cluster. The blueprint sync process can take a few minutes. Once complete, the cluster will display the current cluster blueprint details and whether the sync was successful or not.

Step 6: Verify Deployment

Users can optionally verify whether the correct resources have been created on the cluster.

kubectl get networkpolicies -n namespace-a

NAME            POD-SELECTOR   AGE
np-allow-ns-b   <none>         54s

kubectl get namespaces -l ns-policy=namespace-b
NAME          STATUS   AGE
namespace-b   Active   6d

Recap

Congratulations! You have successfully created a custom cluster blueprint defining a network policy and applied it to a cluster. You can now use this blueprint on as many clusters as you require.