Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Welp. Time to switch CNI on that k8s cluster...

This is why whenever there is a choice between a grassroots open source project, and a corporate source project, I choose grassroots. When the corporation gets bored of the project (or just dies), the project dies too. Grassroots doesn't die as long as one person is still willing to merge PRs and make releases, and grassroots is much more likely to be forked and maintained in perpetuity. Community makes or breaks open source.



Kinda surprised anyone would still using WeaveNet as a CNI.. it was a bit of a dumpster fire: https://blog.quentin-machu.fr/2020/08/07/our-breakup-with-we...


It has been 100% fine for me, was easiest to deploy, very easy to encrypt all network communication. Has been anything but a dumpster fire, will likely wait it out a see what happens with the plugin, rather than switch to something else.


I still use it, shamefully, ex-Weaveworks employee - there is a fork I can recommend which has a live maintainer, actively interested in keeping it up:

https://github.com/rajch/weave/tree/reweave

If you use Weave net still, definitely follow his work and consider learning to build the image, so you can keep it ahead of CVE scanners. (You are using a CVE scanner in your clusters, right?)


what is the idiomatic approach these days?


Cillium is probably the most rock solid option these days. They are still pumping out releases even though they had been recently sold to cisco


Cilium wasn't sold to Cisco, Isovalent was. Cilium is F/OSS and a graduated CNCF project: https://landscape.cncf.io/?item=runtime--cloud-native-networ... Cheers.


EKS + AWS CNI work great and will get you pretty darn far. Scaling ceiling is really just your cidr range space. If you're bumping up against that you may be outgrowing EKS, then cillium i guess


Lots of Cillium deployments lately but... Cisco just happened so, let's see how that goes.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: