How can I route only selected pod traffic through an OpenVPN tunnel?

0
0
Asked By MellowPine47 On

My application runs in Kubernetes and needs VPN access to a few private resources. I want only traffic destined for specific VPN subnets to use the tunnel, while all other connections should continue through the cluster's normal network path. I'm using OpenVPN through Pritunl and am new to Kubernetes. What is a practical way to configure this split-tunnel setup?

4 Answers

Answered By CopperLynx8 On

A common approach is to run OpenVPN as a sidecar in the same pod as the application. Export the client profile from Pritunl, mount it from a Kubernetes Secret, and configure the profile for split tunneling with options such as `route-nopull` followed by routes for only the required VPN subnets. The VPN container will typically need the `NET_ADMIN` capability and access to `/dev/net/tun`. This keeps the tunnel limited to that pod instead of changing routing for the whole node.

Answered By NimbleQuartz5 On

Gluetun is another option for a VPN sidecar and supports both OpenVPN and WireGuard. It can simplify the container setup, although you may still need to adjust its firewall and routing rules so only the target networks use the tunnel. An init container alone generally isn't enough for a long-lived VPN connection; the VPN process needs to remain running alongside the application.

MellowPine47 -

The application needs to reach some services through the VPN and other services through the regular network, so I specifically need split tunneling rather than routing everything through OpenVPN.

Answered By BlueCedar19 On

If you're already using Cilium, a Local Redirect Policy may also help direct selected traffic to a local proxy or networking component. For a first Kubernetes implementation, though, an OpenVPN sidecar with explicit routes is usually easier to understand and keeps the scope limited to the pod.

Answered By QuietHarbor26 On

You don't need Tailscale for this. Pritunl provides regular OpenVPN profiles, so the same sidecar pattern works with OpenVPN directly. Make sure the VPN routes are specific enough, and verify that the application container can use the sidecar's network namespace and that DNS for the private resources is handled correctly.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.