Control: 7.8 Ensure ENI multiple IP mode support for Kubernetes Cluster
Alibaba Cloud ENI (Elastic Network Interface) has supported assign ranges of internal IP addresses as aliases to a single virtual machine's ENI network interfaces. This is useful if you have lots of services running on a VM and you want to assign each service a different IP address without quota limitation.
Only the Terway network plugin support the Network Policy feature, so please make sure not choose Flannel as network plugin when creating cluster.
- Logon to ACK console.
- Click the
Create Kubernetes Clusterbutton and select
Run the control in your terminal:
steampipe check alicloud_compliance.control.cis_v100_7_8
Snapshot and share results via Steampipe Cloud:
steampipe loginsteampipe check --share alicloud_compliance.control.cis_v100_7_8
This control uses a named query:cs_kubernetes_cluster_ipvlan_enabled