Kubermatic logo Docsumentation
  • Products
    Products
    Kubermatic Kubernetes Platform Automated hybrid & multicloud Kubernetes for enterprise demands
    Kubermatic AI New Product End idle GPUs. Securely share AI models across every team
    Kubermatic KubeLB Cloud Native Multi-Tenant Load Balancing
    Kubermatic Virtualization Seamlessly build your private cloud entirely with Kubernetes
    Kubermatic Developer Platform Empower Developers and Accelerate Innovation
    Kubermatic SecureGuard Protect and manage secrets with open-source transparency
    Kubermatic KubeOne Installation and support for your single Kubernetes cluster
    Kubermatic Kubernetes Subscription Upstream Kubernetes support
    Services
    Professional Services How we accelerate your growth
    Kubermatic Kubernetes Platform
    Edge VMware vSphere KubeVirt Static BareMetal Dynamic BareMetal ARM
    On-Prem VMware vSphere Nutanix OpenStack KubeVirt Static BareMetal Dynamic BareMetal
    Cloud AWS Azure Google Cloud Open Telekom Cloud Alibaba Cloud Hetzner Cloud DigitalOcean Equinix Metal KubeVirt
    Kubermatic AI

    A unified AI platform for enterprises, neoclouds, and sovereign AI providers. Turn fragmented GPU infrastructure into shared AI services and maximize GPU utilization across on-prem, cloud, and sovereign environments.

    Kubermatic KubeLB

    Welcome to Kubermatic KubeLB, the next-generation application delivery platform designed for cloud-native architectures. As cloud-native have evolved, Kubermatic KubeLB offers a multi-tenancy approach to load balancing, providing seamless scalability, security, and management for distributed applications and teams.

    Kubermatic Virtualization

    Simplify your operations and streamline your infrastructure with a platform that integrates Kubernetes and virtualized workloads. Enjoy enhanced networking and storage capabilities to fully support your organization’s cloud needs.

    Kubermatic Developer Platform

    Maximize developer productivity and accelerate innovation with Kubermatic Developer Platform (KDP). Powered by Kubernetes API and based on CNCF Sandbox project kcp, our cutting-edge internal developer platform enables the seamless creation and management of services backed by a centralized catalog.

    Kubermatic SecureGuard

    KubeSG is the open-source, unified secrets management solution that simplifies security across all environments. By combining the power of OpenBao with the integration of the External Secrets Operator, it enables automated, breakage-free secret rotation and provides a developer-friendly workflow.

    Kubermatic KubeOne
    Edge VMware vSphere Static BareMetal ARM
    On-Prem VMware vSphere OpenStack Static BareMetal
    Cloud AWS Azure Google Cloud Open Telekom Cloud Alibaba Cloud Hetzner Cloud DigitalOcean Equinix Metal
    Kubermatic Kubernetes Subscription
    Edge VMware vSphere Nutanix
    On-Prem VMware vSphere Nutanix OpenStack
    Cloud AWS Azure Google Cloud Open Telekom Cloud Alibaba Cloud
    Professional Services

    Our Kubernetes experts architect, migrate, and build inhouse competency to bring your cloud native stack into production. Kubermatic is a CNCF Certified Service Provider and Training Partner.

  • Solutions
    By Industry
    Defence
    Public Sector
    Manufacturing
    Telecom
    By Use Case
    Automate with AI
    Implement Platform Engineering
    Control Your Data Sovereignty
    Move Beyond VMware
    Explore All Solutions
  • Customers
  • Resources
    Knowledge base
    Blog
    Cloud Native FAQ
    Kubermatic Learn
    Community
    Kubermatic Community
    Events
    Explore All Resources
  • Company
    About Kubermatic
    Partners
    Press
    Careers
    Contact Us
  • Book a Demo
    • Products
      Kubermatic Kubernetes Platform
      • Features
      • Why Kubermatic
      • Technology Integrations
    • Kubermatic AI New Product
    • Kubermatic KubeLB
    • Kubermatic Virtualization
    • Kubermatic Developer Platform
    • Kubermatic SecureGuard
    • Kubermatic KubeOne
    • Kubermatic Kubernetes Subscription
    • Services
      Professional Services
    • By Industry
      Defence
    • Public Sector
    • Manufacturing
    • Telecom
    • By Use Case
      Automate with AI
    • Implement Platform Engineering
    • Control Your Data Sovereignty
    • Move Beyond VMware
    • Explore All Solutions
  • Customers
    • Knowledge base
      Blog
    • Cloud Native FAQ
    • Learn
    • Community
      Contribution
    • Events
    • Full resource library
    • About Kubermatic
    • Partners
    • Press
    • Careers
    • Contact Us
Book a Demo
  • Architecture
    • Role based access control
    • Requirements
      • Cluster Requirements
    • Support Policy
      • KKP Components Versioning
      • Operating Systems Support Matrix
      • Supported Versions
      • Cloud Provider
        • Nutanix
        • KubeVirt
        • Google Cloud Platform
        • Azure
        • AWS
        • VSphere
    • Concepts
      • KKP Concepts
        • Cluster Templates
        • Kubermatic Kubernetes Platform Security
          • Securing System Services
          • Pod Security Policy
        • Service Accounts
          • Using Service Accounts
          • Service Account Token Volume Projection
        • Addons
          • AWS Node Termination Handler
          • Multus-CNI Addon
          • Kubeflow Addon
        • User Interface
          • Preparing New Themes
            • With Source Access
            • Without Source Access
      • Comparing KubeOne with Kubermatic Kubernetes Platform (KKP)
    • Monitoring, Logging & Alerting
      • Master / Seed Cluster MLA
      • User Cluster MLA
    • Known Issues
  • Installation
    • Start with KKP
      • Concepts
        • Delivery Pipeline Description
      • Guides
        • Use the Wizard to Configure KKP
        • Explore the Generated Bundle
        • Setup your Git repository
      • Cheat Sheets
        • Get Access to Kubernetes Cluster
        • Validate Cluster and KKP Readiness
        • Troubleshoot GitHub Actions Pipeline
        • Customize the KKP Deployment
        • Work with Secrets using SOPS
    • Install Kubermatic Kubernetes Platform (KKP) CE on vSphere
      • Add Seed Cluster for CE on vSphere
    • Install Kubermatic Kubernetes Platform (KKP) EE on vSphere
      • Add Seed Cluster for EE on vSphere
    • Install Kubermatic Kubernetes Platform (KKP) EE on AWS
      • Add Seed Cluster for EE on AWS
    • Install Kubermatic Kubernetes Platform (KKP) CE on AWS
      • Add Seed Cluster for CE on AWS
    • Install KKP - Quick Guide
    • Install HA-Kubernetes
    • Install Kubermatic Kubernetes Platform (KKP) CE
      • Add Seed Cluster for CE
    • Install Kubermatic Kubernetes Platform (KKP) EE
      • Add Seed Cluster for EE
    • Install Kubermatic Kubernetes Platform (KKP) CE on Azure
      • Add Seed Cluster for CE on Azure
    • Install Kubermatic Kubernetes Platform (KKP) CE on GCP
      • Add Seed Cluster for CE on GCP
    • Install Kubermatic Kubernetes Platform (KKP) EE on Azure
      • Add Seed Cluster for EE on Azure
    • Install Kubermatic Kubernetes Platform (KKP) EE on GCP
      • Add Seed Cluster for EE on GCP
    • Offline Mode
  • Tutorials & How-tos
    • Project and Cluster Management
      • Seed Clusters
      • Cluster Defaulting
      • Using kubectl
    • Manage Worker Nodes
      • Manage Worker Nodes via UI
      • Manage Worker Nodes via CLI
      • SSH Access to Worker Nodes
    • Automatic Etcd Backups and Restore
    • Monitoring, Logging & Alerting
      • Master / Seed Cluster MLA
        • Installation
        • Customization
      • User Cluster MLA
        • Admin Guide
        • User Guide
        • Setting up Alertmanager with Slack Notifications
    • Cluster Templates
    • Kubermatic Kubernetes Platform Operating Systems Support
      • CoreOS End Of Support
    • Adding an External Kubernetes Cluster
      • Adding an External AKS Kubernetes Cluster
      • Adding an External EKS Kubernetes Cluster
      • Adding an External GKE Kubernetes Cluster
    • Configuration
      • Dynamic Kubelet configuration
      • Custom Certificates
    • Kubermatic Kubernetes Platform (KKP) Cluster Autoscaler
    • Networking
      • CNI & Cluster Network Configuration
      • Control Plane Expose Strategy
      • Proxy Whitelisting
      • API Server Network Policies
      • Manual CNI Migration
    • Operation
      • Control Plane
        • Example Usage
        • Upgrading the Control Plane and the kubelets
        • Scaling the Control Plane
    • Customizing the Dashboard
    • OPA Integration
      • [Experimental] OPA Mutation
      • Open Policy Agent (OPA) via UI
    • CCM Migration
      • CCM Migration via UI
    • Upgrading
      • Upgrading from 2.13 to 2.14
      • Upgrading from 2.14 to 2.15
        • Upgrading KKP Operator
        • Upgrading Helm Chart (EE)
        • Migrating to the Operator
        • Migrating to Helm 3
      • Upgrading from 2.15 to 2.16
      • Upgrading from 2.16 to 2.17
        • Upgrading KKP Operator
        • Migrating to the Operator
      • Upgrading from 2.17 to 2.18
      • Upgrading from 2.18 to 2.19
      • Upgrading from 2.19 to 2.20
      • Versions & Update Configuration
    • OIDC Provider Configuration
      • Share Clusters via Delegated OIDC Authentication
    • [Experimental] Operating System Manager
      • Enable Operating System Manager
    • Administration
      • Datacenters
      • User Settings
        • User SSH Key Agent
      • Kubermatic User
      • Presets
      • Admin Panel
        • Etcd Backup Settings
        • OPA Constraint Templates
        • OPA Default Constraint
        • Administrators
        • Cluster Settings
        • Custom Links
        • Dynamic Datacenters
        • Presets
    • Metering (EE)
    • Deploy Your Application
    • Telemetry
    • Deploy with AWS AssumeRole
    • Audit Logging
    • Admission Plugins Configuration
  • References
    • Kubermatic CRDs Reference
    • REST-API Reference
  • Cheat Sheets
    • Debugging
    • etcd
      • Replacing a member
      • Restoring from Backup
      • Etcd Launcher
      • Etcd Backup and Restore Controllers
    • Alerting Runbook
    • Changing cluster-id for existing vSphere user clusters
    • Changelog
  • Release Notes
  • Contribute to KKP
Imprint
Edit this page

Networking

This section provides guides on networking in KKP:

  • CNI & Cluster Network Configuration
  • Control Plane Expose Strategy
  • Proxy Whitelisting
  • API Server Network Policies
  • Manual CNI Migration