How can I send only selected pod traffic through an OpenVPN tunnel?

0
0
Asked By MellowPine47 On

My application runs in Kubernetes and needs access to a few private resources through a VPN. I only want traffic destined for specific VPN subnets to use the tunnel; all other connections should continue using the pod or node's normal network path. I'm new to Kubernetes and currently host the VPN with OpenVPN through Pritunl. What setup would work for this kind of split routing?

4 Answers

Answered By BlueOrbit24 On

If your cluster uses Cilium, a Local Redirect Policy is another possible design for directing selected traffic to a local proxy or networking component. That can be powerful, but for a single application and an OpenVPN connection, a sidecar with explicit routes is usually simpler to understand and maintain.

Answered By SilverMango31 On

A VPN helper such as Gluetun can also run alongside the application and supports both OpenVPN and WireGuard. It may be useful for managing the tunnel and firewall rules, but you'll still need to configure split-routing rules for the target subnets. An init container alone generally isn't enough because the VPN process needs to remain running; use a sidecar unless you deliberately share and manage the network namespace another way.

MellowPine47 -

Yes, the same application needs to reach some resources through the VPN while using the regular network for everything else. Split routing is exactly what I'm looking for.

Answered By QuietHarbor6 On

You don't need Tailscale for this. Pritunl provides OpenVPN configuration files, so the same sidecar pattern applies directly. Store the .ovpn file in a Secret, mount it into the OpenVPN container, and explicitly add routes for the networks that should go through the VPN. Be careful with the required pod security settings, since creating the tunnel usually needs NET_ADMIN and /dev/net/tun.

Answered By CopperLynx82 On

A common approach is to run OpenVPN as a sidecar container in the same pod as the application. Export the client profile from Pritunl, mount it from a Kubernetes Secret, and give the VPN container NET_ADMIN plus access to /dev/net/tun. Configure the profile for split tunneling—for example, use route-nopull and then add route entries only for the private VPN subnets. That way, matching destinations use the tunnel while everything else keeps using the normal gateway.

MellowPine47 -

So this works with Pritunl even though it isn't Tailscale? I can export the connection as an OpenVPN profile.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.