MicrosoftDocs / azure-docs

Open source documentation of Microsoft Azure
https://docs.microsoft.com/azure
Creative Commons Attribution 4.0 International
10.19k stars 21.33k forks source link

Expand limitations when using Calico and Cilium #122887

Closed 1kmilo closed 1 month ago

1kmilo commented 3 months ago

Please help to expand the limitation of Calico and Cilium in comparison with the third party options.

https://docs.cilium.io/en/latest/security/policy/ https://docs.tigera.io/calico/latest/network-policy/get-started/calico-policy/calico-network-policy

This can help to know what to expect from the versions that are available in AKS and decide if going with BYO CNI plugin.

For instance, after doing tests, it looks like AKS Calico/Cilium does not support policies that use FQDN:

apiVersion: "cilium.io/v2" kind: CiliumNetworkPolicy metadata: name: "fqdn" spec: endpointSelector: matchLabels: org: empire class: mediabot egress:


Document Details

Do not edit this section. It is required for learn.microsoft.com ➟ GitHub issue linking.

PesalaPavan commented 3 months ago

@1kmilo Thanks for your feedback! We will investigate and update as appropriate.

ManoharLakkoju-MSFT commented 3 months ago

@schaffererin Can you please check and add your comments on this doc update request as applicable.

ManoharLakkoju-MSFT commented 3 months ago

@1kmilo I'm going to assign this to the document author so they can take a look at it accordingly

rayoef commented 1 month ago

Thank you for your dedication to our documentation. Unfortunately, at this time we have been unable to review your issue in a timely manner, and we sincerely apologize for the delayed response. The requested updates have not been made since the creation of this issue, and the timeline for resolution may vary based on resourcing, so we've created an internal work item to incorporate your suggestions. We are closing this issue for now, but feel free to comment here as necessary.

please-close