My application runs in Kubernetes and needs VPN access to a few private resources. I want only traffic destined for specific VPN subnets to use the tunnel, while all other connections should continue through the cluster's normal network path. I'm using OpenVPN through Pritunl and am new to Kubernetes. What is a practical way to configure this split-tunnel setup?
4 Answers
A common approach is to run OpenVPN as a sidecar in the same pod as the application. Export the client profile from Pritunl, mount it from a Kubernetes Secret, and configure the profile for split tunneling with options such as `route-nopull` followed by routes for only the required VPN subnets. The VPN container will typically need the `NET_ADMIN` capability and access to `/dev/net/tun`. This keeps the tunnel limited to that pod instead of changing routing for the whole node.
Gluetun is another option for a VPN sidecar and supports both OpenVPN and WireGuard. It can simplify the container setup, although you may still need to adjust its firewall and routing rules so only the target networks use the tunnel. An init container alone generally isn't enough for a long-lived VPN connection; the VPN process needs to remain running alongside the application.
If you're already using Cilium, a Local Redirect Policy may also help direct selected traffic to a local proxy or networking component. For a first Kubernetes implementation, though, an OpenVPN sidecar with explicit routes is usually easier to understand and keeps the scope limited to the pod.
You don't need Tailscale for this. Pritunl provides regular OpenVPN profiles, so the same sidecar pattern works with OpenVPN directly. Make sure the VPN routes are specific enough, and verify that the application container can use the sidecar's network namespace and that DNS for the private resources is handled correctly.

The application needs to reach some services through the VPN and other services through the regular network, so I specifically need split tunneling rather than routing everything through OpenVPN.