Static IP Address Usage

Last updated: 2023-09-26 15:56:45

Use Cases

Applicable for scenarios that rely on static container IPs, such as migrating traditional architectures to container platforms and implementing security policies based on IP restrictions. For services without IP restrictions, it is not recommended to use the fixed IP mode.

Features and Limitations

The static IP address is achieved by retaining the associated IP address when the Pod is terminated, or keeping the IP unchanged when the Pod is migrated.
Supports multiple subnets, but does not allow scheduling of Pods with static IPs across subnets. Therefore, Pods in static IP mode cannot be scheduled across availability zones.
The IP address of Pod can automatically associate with EIP, thus Pod can be accessed via internet.
For the static IP addresses with shared ENI, when the Pod with static IP address is terminated, its IP address is only retained in the cluster. If other clusters or services (such as CVM, CDB, CLB) use the same subnet, the retained static IP address may be occupied, and the Pod will be unable to obtain the IP address when it being restarted. Please ensure that the container subnet of this mode is exclusively used.

How to Use

You can enable the static IP address using either of the following methods:
Select VPC-CNI with static IP address when creating a cluster
Enable VPC-CNI with static IP address for GlobalRouter mode

Selecting static IP address of VPC-CNI mode when creating a cluster

Note
If you use this method to enable VPC-CNI, when you create a workload on the console or through YAML, all Pods will use ENIs by default.
1. Log in to the TKE console and select Cluster in the left sidebar.
2. On the Cluster Management page, click New at the top of the cluster list.
3. On the Create Cluster page, select the container network add-on as VPC-CNI and check the "Enable Support" for fixed Pod IP as shown in the image below:



Enabling VPC-CNI with static IP address for GlobalRouter mode

Enabling VPC-CNI for the existing clusters

Note
Enable VPC-CNI Mode with static IP address for GlobalRouter, that is, when creating a cluster, you select the Global Router network add-on, and then enable the VPC-CNI mode (both modes can be used at the same time by default) on the basic information page of the cluster.
If you use this method to enable VPC-CNI, the Pods cannot use ENIs by default.
1. Log in to the TKE console and select Cluster in the left sidebar.
2. On the Cluster Management page, select the cluster ID for which you want to enable VPC-CNI, and proceed to the cluster details page.
3. In the Cluster Details page, select Basic Information on the left. In the Cluster Information section, locate the VPC-CNI field and click Enable.
4. In the pop-up window, check "Enable Support" for fixed Pod IP, confirm the IP reclaim policy, and select a subnet, as shown in the figure below:


Note
For scenarios that use static IP addresses, when enabling VPC-CNI, you need to set the IP reclaiming policy to specify when to reclaim the IP addresses after Pods are terminated.
Pods with non-static IP addresses are not affected by these settings because their IP addresses are immediately released upon Pod termination. These IP addresses are not returned to the VPC, but returned to the IP address pool managed by the container.
5. Click Submit to enable VPC-CNI mode for the cluster.

Creating StatefulSets with static Pod IP addresses

In GlobalRouter mode with VPC-CNI enabled, if you have applications to deploy in TKE, which need to use the static Pod IP addresses, you can create a StatefulSets with static IP addresses. Pod created by this type of StatefulSet are assigned with an actual IP address in the VPC through an ENI. The IP addresses are assigned by TKE VPC-CNI add-on. So that when the Pod is restarted or migrated, the IP address can be unchanged.
By using StatefulSets with static IP addresses, you can:
Authorize based on source IP addresses.
Review processes based on IP addresses.
Query logs based on Pod IP addresses.
Note
When StatefulSets with static IP addresses are used, the static IP addresses survive only within the lifecycle of their StatefulSets.
You can create the static IP address using either of the following methods:
Via the console
Using YAML
1. Log in to the TKE console and select Cluster in the left sidebar.
2. Select a cluster ID that needs to use the static IP address and go to its management page.
3. Select Workload > StatefulSet to access the StatefulSet cluster management page.
4. Click Create. In the new StatefulSet, select Network Mode > Enable VPC-CNI mode and enable Fixed Pod IP, as shown in the image below:


IP address range: currently, only the Random value is supported.
Static pod IP: select Enable.
apiVersion: apps/v1
kind: StatefulSet
metadata:
labels:
k8s-app: busybox
name: busybox
namespace: default
spec:
replicas: 3
selector:
matchLabels:
k8s-app: busybox
qcloud-app: busybox
serviceName: ""
template:
metadata:
annotations:
tke.cloud.tencent.com/networks: "tke-route-eni"
tke.cloud.tencent.com/vpc-ip-claim-delete-policy: Never
creationTimestamp: null
labels:
k8s-app: busybox
qcloud-app: busybox
spec:
containers:
- args:
- "10000000000"
command:
- sleep
image: busybox
imagePullPolicy: Always
name: busybox
resources:
limits:
tke.cloud.tencent.com/eni-ip: "1"
requests:
tke.cloud.tencent.com/eni-ip: "1"
spec.template.annotations: tke.cloud.tencent.com/networks: "tke-route-eni" indicates that the Pod uses the shared ENI VPC-CNI mode. If using the independent ENI VPC-CNI mode, please change the value to "tke-direct-eni".
spec.template.annotations: to create Pods in VPC-CNI mode, you need to set the annotation tke.cloud.tencent.com/vpc-ip-claim-delete-policy. Its default value is “Immediate”, that is, when a Pod is terminated, the associated IP address is also terminated. To use a static IP address, set it to “Never”, that is, a Pod is terminated, but the associated IP address will be retained. When a Pod with the same name as the terminated Pod is pulled the next time, the original IP address is used.
spec.template.spec.containers.0.resources: To create a Pod in VPC-CNI mode with a shared ENI, add requests and limits restrictions, i.e., tke.cloud.tencent.com/eni-ip. For VPC-CNI mode with an independent ENI, add tke.cloud.tencent.com/direct-eni. This resource only needs to be added to the first container of the Pod, and other containers do not require it. Additionally, this resource will be added automatically by default, and you only need to declare the tke.cloud.tencent.com/networks annotation.