This commit is contained in:
2025-08-02 15:18:37 +02:00
parent 92a020b05b
commit 89ca90e6b7
4 changed files with 67 additions and 51 deletions

View File

@@ -8,9 +8,9 @@ spec:
nodeToNodeMeshEnabled: false
asNumber: 65000
serviceClusterIPs:
- cidr: "2001:470:72f0:f:1::/108" #server service net
#- cidr: "2001:470:72f0:f:1::/108" #server service net
- cidr: "fd00:0:0:f:1::/108" #server service net
- cidr: "2001:470:72f0:f:2::/108" #dmz service net
#- cidr: "2001:470:72f0:f:2::/108" #dmz service net
- cidr: "fd00:0:0:f:2::/108" #dmz service net
- cidr: "10.0.91.0/24" #server service net
- cidr: "10.0.92.0/24" #dmz service net
@@ -18,31 +18,47 @@ spec:
apiVersion: projectcalico.org/v3
kind: BGPPeer
metadata:
name: "aux1-v6"
name: "firewall-v6"
spec:
peerIP: "fd00:0:0:2::6" #aux1 - bgp router...
peerIP: "fd00:0:0:2::1" #aux1 - bgp router...
asNumber: 65000
---
apiVersion: projectcalico.org/v3
kind: BGPPeer
metadata:
name: "aux2-v6"
name: "firewall-v6"
spec:
peerIP: "fd00:0:0:2::7" #aux2 - bgp router...
peerIP: "fd00:0:0:2::1" #aux2 - bgp router...
asNumber: 65000
---
apiVersion: projectcalico.org/v3
kind: BGPPeer
metadata:
name: "aux1-v4"
spec:
peerIP: "10.0.2.6" #aux1 - bgp router...
asNumber: 65000
---
apiVersion: projectcalico.org/v3
kind: BGPPeer
metadata:
name: "aux2-v4"
spec:
peerIP: "10.0.2.7" #aux2 - bgp router...
asNumber: 65000
#---
#apiVersion: projectcalico.org/v3
#kind: BGPPeer
#metadata:
# name: "aux1-v6"
#spec:
# peerIP: "fd00:0:0:2::6" #aux1 - bgp router...
# asNumber: 65000
#---
#apiVersion: projectcalico.org/v3
#kind: BGPPeer
#metadata:
# name: "aux2-v6"
#spec:
# peerIP: "fd00:0:0:2::7" #aux2 - bgp router...
# asNumber: 65000
#---
#apiVersion: projectcalico.org/v3
#kind: BGPPeer
#metadata:
# name: "aux1-v4"
#spec:
# peerIP: "10.0.2.6" #aux1 - bgp router...
# asNumber: 65000
#---
#apiVersion: projectcalico.org/v3
#kind: BGPPeer
#metadata:
# name: "aux2-v4"
#spec:
# peerIP: "10.0.2.7" #aux2 - bgp router...
# asNumber: 65000

View File

@@ -11,7 +11,7 @@ spec:
interface: en.*
ipPools:
- blockSize: 122
cidr: 2001:470:72f0:a::/64
cidr: fd00:0:0:a::/64
encapsulation: VXLAN
natOutgoing: Disabled
nodeSelector: all()

View File

@@ -1,15 +1,15 @@
apiVersion: projectcalico.org/v3
kind: IPPool
metadata:
name: ipv6-server-private # server net
spec:
blockSize: 122
cidr: fd00:0:0:a::/64
ipipMode: Never
#natOutgoing: false
#disabled: false
nodeSelector: all()
vxlanMode: Always
#apiVersion: projectcalico.org/v3
#kind: IPPool
#metadata:
# name: ipv6-server-private # server net
#spec:
# blockSize: 122
# cidr: fd00:0:0:a::/64
# ipipMode: Never
# #natOutgoing: false
# #disabled: false
# nodeSelector: all()
# vxlanMode: Always
---
apiVersion: projectcalico.org/v3
kind: IPPool
@@ -24,15 +24,15 @@ spec:
nodeSelector: all()
vxlanMode: Always
---
apiVersion: projectcalico.org/v3
kind: IPPool
metadata:
name: ipv6-dmz-public # dmz net
spec:
blockSize: 122
cidr: 2001:470:72f0:b::/64
ipipMode: Never
#natOutgoing: false
#disabled: false
nodeSelector: all()
vxlanMode: Always
#apiVersion: projectcalico.org/v3
#kind: IPPool
#metadata:
# name: ipv6-dmz-public # dmz net
#spec:
# blockSize: 122
# cidr: 2001:470:72f0:b::/64
# ipipMode: Never
# #natOutgoing: false
# #disabled: false
# nodeSelector: all()
# vxlanMode: Always