Kube-OVN integrates the OVN-based Network Virtualization with Kubernetes. It offers an advanced Container Network Fabric that is feature rich and enterprise friendly.

Namespaced Subnets

Each Namespace can have a unique Subnet (backed by a Logical Switch).

Static IP Addresses

Allocates random or static IP addresses to workloads.

Subnet Isolation

Denies traffic from IP addresses not within the same Subnet. Allow-lists specific IP addresses or IP ranges.

Network Policy

Implements the Kubernetes NetworkPolicy API using OVN ACLs.

Dual Stack

Supports IPv4-only, IPv6-only or dual stack mode for Pods.

Pod NAT and EIP

Manages the Pod external traffic and IP addresses like traditional VMs.

Multi-Cluster Networking

Connects different clusters into one L3 network.

Dynamic QoS

Supports Pod/Gateway Ingress/Egress rate limits configuration on the fly.

Traffic Mirror

Duplicates container network traffic for monitoring, diagnosis and replays.

Underlay Support

Supports underlay and Vlan mode for better performance and direct connectivity with the physical network.

VPC Support

Supports multi-tenant networking with overlapped IP address spaces.

Cilium Integration

Integrates Cilium for advanced security and observability.
# Dual-stack Subnet with centralized gateway
kind: Subnet
  name: dualstack
  default: false
  - fd00:10:16::1
  gatewayNode: "gw1,gw2"
  gatewayType: centralized
  natOutgoing: true
  protocol: Dual

