My application runs in Kubernetes and needs access to a few private resources through a VPN. I only want traffic destined for specific VPN subnets to use the tunnel; all other connections should continue using the pod or node's normal network path. I'm new to Kubernetes and currently host the VPN with OpenVPN through Pritunl. What setup would work for this kind of split routing?
4 Answers
If your cluster uses Cilium, a Local Redirect Policy is another possible design for directing selected traffic to a local proxy or networking component. That can be powerful, but for a single application and an OpenVPN connection, a sidecar with explicit routes is usually simpler to understand and maintain.
A VPN helper such as Gluetun can also run alongside the application and supports both OpenVPN and WireGuard. It may be useful for managing the tunnel and firewall rules, but you'll still need to configure split-routing rules for the target subnets. An init container alone generally isn't enough because the VPN process needs to remain running; use a sidecar unless you deliberately share and manage the network namespace another way.
You don't need Tailscale for this. Pritunl provides OpenVPN configuration files, so the same sidecar pattern applies directly. Store the .ovpn file in a Secret, mount it into the OpenVPN container, and explicitly add routes for the networks that should go through the VPN. Be careful with the required pod security settings, since creating the tunnel usually needs NET_ADMIN and /dev/net/tun.
A common approach is to run OpenVPN as a sidecar container in the same pod as the application. Export the client profile from Pritunl, mount it from a Kubernetes Secret, and give the VPN container NET_ADMIN plus access to /dev/net/tun. Configure the profile for split tunneling—for example, use route-nopull and then add route entries only for the private VPN subnets. That way, matching destinations use the tunnel while everything else keeps using the normal gateway.
So this works with Pritunl even though it isn't Tailscale? I can export the connection as an OpenVPN profile.

Yes, the same application needs to reach some resources through the VPN while using the regular network for everything else. Split routing is exactly what I'm looking for.