Skip to main content

Custom Pod and Service CIDRs

Every Managed Kubernetes cluster carries two internal address ranges: a pod CIDR for pod IPs and a service CIDR for ClusterIP services. NetActuate assigns sensible defaults, but you can set your own ranges when you create a cluster, which matters most for an in-VPC cluster that must not overlap the VPC it joins or other clusters in your account. Ranges are chosen once, at create time.

Defaults​

If you do not set custom ranges, a cluster uses:

  • Cluster (supernet): 10.0.0.0/8
  • Service CIDR: 10.0.0.0/16
  • Pod CIDR: 10.128.0.0/16

These defaults suit most edge clusters. Override them when the default space would collide with a VPC subnet, an on-premises network you route to, or another cluster.

Setting custom ranges​

Set both ranges in the cluster creation wizard under Advanced networking. This is a both-or-neither choice: if you supply one range you must supply the other, so that the pod and service ranges are always defined together and validated as a pair.

  1. Navigate to Infrastructure -> Kubernetes and click Add Cluster.
  2. Complete the standard configuration and, for an in-VPC cluster, select the target VPC.
  3. Open Advanced networking and enter both the pod CIDR and the service CIDR.
  4. Review and deploy.

API field placement​

The field names differ by cluster placement.

For an in-VPC cluster, send custom ranges inside the nested networking object on POST /nke/clusters. Use serviceCidr for the service range and podCidr for the pod range.

{
"networking": {
"vpcId": 321,
"serviceCidr": "10.240.0.0/16",
"podCidr": "10.241.0.0/16"
}
}

For an edge cluster with custom ranges and no VPC placement, send the top-level networks object. Use service for the service range and pod for the pod range.

{
"networks": {
"service": "10.240.0.0/16",
"pod": "10.241.0.0/16"
}
}

Do not use top-level networks to place a cluster in a VPC, and do not use top-level vpcId for cluster creation. The deployed in-VPC contract is the nested networking object.

Constraints​

The ranges you enter must satisfy all of the following, or creation is rejected:

  • Aligned /16. Each range is a /16 on its natural boundary.
  • Private or shared address space. Use RFC 1918 space (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or the shared-address space 100.64.0.0/10.
  • Service and pod ranges must differ. The two ranges cannot be the same and cannot overlap each other.
  • No account overlap. The ranges must not overlap the VPC subnet the cluster joins or the pod or service ranges of another cluster in your account.
  • Immutable after create. Both ranges are fixed once the cluster is built. To change them, create a new cluster.

Need Help?​

Contact support@netactuate.com or open a support ticket from the portal.