# Istio CNI

Istio CNI is the container network interface (CNI) add-on that lets Istio capture and secure service-mesh traffic for your workloads without reconfiguring each pod's network namespace. It is open source and self-hosted, installable on Docker Hub.

Canonical page: https://ourlocalhost.com/app/5726/istio-cni

## Description

Istio CNI plugin is the container network interface (CNI) add-on that lets Istio capture and secure service-mesh traffic for your workloads without reconfiguring each pod's network namespace. It's for Istio operators on Kubernetes who want CNI-based sidecar handling instead of the default iptables approach. Note: the original istio/cni repository is archived and the plugin has been merged into the main Istio project, so pull current install manifests there.

## Platform availability

Available on 0 of 6 install platforms.

## Health score

19/100 (Low), based on 3 of 4 factors.
- Maintained: 0 (GitHub repository is archived)
- Popular: 43 (139 GitHub stars)
- Easy to install: 25 (0 install platforms, install notes, Docker image)

## Links

- GitHub: https://github.com/istio/cni
- Docker Hub: https://hub.docker.com/r/ubuntu/istio-install-cni

## Common questions

### How do I enable the Istio CNI plugin during an Istio install?

Set the Helm variable istio_cni.enabled=true when applying the Istio manifests, or apply istio-cni_install.yaml as a separate install.

### Which kubelet CNI settings must the Istio CNI plugin match?

The cniBinDir and cniConfDir values must match the kubelet settings, with defaults of /opt/cni/bin and /etc/cni/net.d.

### Why might Istio CNI not activate on a hosted Kubernetes cluster?

Some hosted clusters do not configure the kubelet to use CNI plugins, so compatibility is not universal. It is expected to work with hosted Kubernetes that uses CNI plugins.

### How should the CNI plugin be configured for OpenShift?

Set the chained parameter to false because some Kubernetes flavors, such as OpenShift, do not support the CNI chain approach.

---
Source: Our Local Host (https://ourlocalhost.com/app/5726/istio-cni), the self-hosted and open-source app directory.
