1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["3150"],{35834:function(e,t,n){n.r(t),n.d(t,{frontMatter:()=>c,toc:()=>a,default:()=>j,metadata:()=>r,assets:()=>h,contentTitle:()=>l});var r=JSON.parse('{"id":"reference/resources/workloadendpoint","title":"Workload endpoint","description":"API for this Calico resource.","source":"@site/calico_versioned_docs/version-3.28/reference/resources/workloadendpoint.mdx","sourceDirName":"reference/resources","slug":"/reference/resources/workloadendpoint","permalink":"/calico/3.28/reference/resources/workloadendpoint","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico_versioned_docs/version-3.28/reference/resources/workloadendpoint.mdx","tags":[],"version":"3.28","frontMatter":{"description":"API for this Calico resource."},"sidebar":"calicoSidebar","previous":{"title":"Profile","permalink":"/calico/3.28/reference/resources/profile"},"next":{"title":"Configuring etcd RBAC","permalink":"/calico/3.28/reference/etcd-rbac/"}}'),d=n(37937),s=n(17869);function i(e){let t={p:"p",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,s.R)(),...e.components};return(0,d.jsxs)(d.Fragment,{children:[(0,d.jsx)(t.p,{children:"IPNAT contains a single NAT mapping for a WorkloadEndpoint resource."}),"\n",(0,d.jsxs)(t.table,{children:[(0,d.jsx)(t.thead,{children:(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.th,{children:"Field"}),(0,d.jsx)(t.th,{children:"Description"}),(0,d.jsx)(t.th,{children:"Accepted Values"}),(0,d.jsx)(t.th,{children:"Schema"}),(0,d.jsx)(t.th,{children:"Default"})]})}),(0,d.jsxs)(t.tbody,{children:[(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"internalIP"}),(0,d.jsx)(t.td,{children:"The internal IP address of the NAT mapping."}),(0,d.jsx)(t.td,{children:"A valid IP address"}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"externalIP"}),(0,d.jsx)(t.td,{children:"The external IP address."}),(0,d.jsx)(t.td,{children:"A valid IP address"}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]})]})]})]})}function o(e={}){let{wrapper:t}={...(0,s.R)(),...e.components};return t?(0,d.jsx)(t,{...e,children:(0,d.jsx)(i,{...e})}):i(e)}let c={description:"API for this Calico resource."},l="Workload endpoint",h={},a=[{value:"Sample YAML",id:"sample-yaml",level:2},{value:"Definitions",id:"definitions",level:2},{value:"Metadata",id:"metadata",level:3},{value:"Spec",id:"spec",level:3},{value:"IPNAT",id:"ipnat",level:3},{value:"EndpointPort",id:"endpointport",level:3}];function x(e){let t={a:"a",admonition:"admonition",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",p:"p",pre:"pre",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,s.R)(),...e.components};return(0,d.jsxs)(d.Fragment,{children:[(0,d.jsx)(t.header,{children:(0,d.jsx)(t.h1,{id:"workload-endpoint",children:"Workload endpoint"})}),"\n","\n",(0,d.jsxs)(t.p,{children:["A workload endpoint resource (",(0,d.jsx)(t.code,{children:"WorkloadEndpoint"}),") represents an interface\nconnecting a Calico networked container or VM to its host."]}),"\n",(0,d.jsx)(t.p,{children:"Each endpoint may specify a set of labels and list of profiles that Calico will use\nto apply policy to the interface."}),"\n",(0,d.jsxs)(t.p,{children:["A workload endpoint is a namespaced resource, that means a\n",(0,d.jsx)(t.a,{href:"/calico/3.28/reference/resources/networkpolicy",children:"NetworkPolicy"}),"\nin a specific namespace only applies to the WorkloadEndpoint in that namespace.\nTwo resources are in the same namespace if the namespace value is set the same\non both."]}),"\n",(0,d.jsx)(t.admonition,{type:"note",children:(0,d.jsxs)(t.p,{children:["While ",(0,d.jsx)(t.code,{children:"calicoctl"})," allows the user to fully manage Workload Endpoint resources,\nthe lifecycle of these resources is generally handled by an orchestrator-specific\nplugin such as the Calico CNI plugin, the Calico Docker network plugin,\nor the Calico OpenStack Neutron Driver. In general, we recommend that you only\nuse ",(0,d.jsx)(t.code,{children:"calicoctl"})," to view this resource type."]})}),"\n",(0,d.jsx)(t.h2,{id:"sample-yaml",children:"Sample YAML"}),"\n",(0,d.jsx)(t.pre,{children:(0,d.jsx)(t.code,{className:"language-yaml",children:"apiVersion: projectcalico.org/v3\nkind: WorkloadEndpoint\nmetadata:\n name: node1-k8s-my--nginx--b1337a-eth0\n namespace: default\n labels:\n app: frontend\n projectcalico.org/namespace: default\n projectcalico.org/orchestrator: k8s\nspec:\n node: node1\n orchestrator: k8s\n endpoint: eth0\n containerID: 1337495556942031415926535\n pod: my-nginx-b1337a\n endpoint: eth0\n interfaceName: cali0ef24ba\n mac: ca:fe:1d:52:bb:e9\n ipNetworks:\n - 192.168.0.0/32\n profiles:\n - profile1\n ports:\n - name: some-port\n port: 1234\n protocol: TCP\n - name: another-port\n port: 5432\n protocol: UDP\n"})}),"\n",(0,d.jsx)(t.h2,{id:"definitions",children:"Definitions"}),"\n",(0,d.jsx)(t.h3,{id:"metadata",children:"Metadata"}),"\n",(0,d.jsxs)(t.table,{children:[(0,d.jsx)(t.thead,{children:(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.th,{children:"Field"}),(0,d.jsx)(t.th,{children:"Description"}),(0,d.jsx)(t.th,{children:"Accepted Values"}),(0,d.jsx)(t.th,{children:"Schema"}),(0,d.jsx)(t.th,{children:"Default"})]})}),(0,d.jsxs)(t.tbody,{children:[(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"name"}),(0,d.jsx)(t.td,{children:"The name of this workload endpoint resource. Required."}),(0,d.jsxs)(t.td,{children:["Alphanumeric string with optional ",(0,d.jsx)(t.code,{children:"."}),", ",(0,d.jsx)(t.code,{children:"_"}),", or ",(0,d.jsx)(t.code,{children:"-"})]}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"namespace"}),(0,d.jsx)(t.td,{children:"Namespace provides an additional qual
1ification to a resource name."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{children:'"default"'})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"labels"}),(0,d.jsx)(t.td,{children:"A set of labels to apply to this endpoint."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"map"}),(0,d.jsx)(t.td,{})]})]})]}),"\n",(0,d.jsx)(t.h3,{id:"spec",children:"Spec"}),"\n",(0,d.jsxs)(t.table,{children:[(0,d.jsx)(t.thead,{children:(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.th,{children:"Field"}),(0,d.jsx)(t.th,{children:"Description"}),(0,d.jsx)(t.th,{children:"Accepted Values"}),(0,d.jsx)(t.th,{children:"Schema"}),(0,d.jsx)(t.th,{children:"Default"})]})}),(0,d.jsxs)(t.tbody,{children:[(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"workload"}),(0,d.jsx)(t.td,{children:"The name of the workload to which this endpoint belongs."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"orchestrator"}),(0,d.jsx)(t.td,{children:"The orchestrator that created this endpoint."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"node"}),(0,d.jsx)(t.td,{children:"The node where this endpoint resides."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"containerID"}),(0,d.jsx)(t.td,{children:"The CNI CONTAINER_ID of the workload endpoint."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"pod"}),(0,d.jsx)(t.td,{children:"Kubernetes pod name for this workload endpoint."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"endpoint"}),(0,d.jsx)(t.td,{children:"Container network interface name."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"ipNetworks"}),(0,d.jsx)(t.td,{children:"The CIDRs assigned to the interface."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"List of strings"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"ipNATs"}),(0,d.jsx)(t.td,{children:"List of 1:1 NAT mappings to apply to the endpoint."}),(0,d.jsx)(t.td,{}),(0,d.jsxs)(t.td,{children:["List of ",(0,d.jsx)(t.a,{href:"#ipnat",children:"IPNATs"})]}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"ipv4Gateway"}),(0,d.jsx)(t.td,{children:"The gateway IPv4 address for traffic from the workload."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"ipv6Gateway"}),(0,d.jsx)(t.td,{children:"The gateway IPv6 address for traffic from the workload."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"profiles"}),(0,d.jsx)(t.td,{children:"List of profiles assigned to this endpoint."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"List of strings"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"interfaceName"}),(0,d.jsx)(t.td,{children:"The name of the host-side interface attached to the workload."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"mac"}),(0,d.jsx)(t.td,{children:"The source MAC address of traffic generated by the workload."}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"IEEE 802 MAC-48, EUI-48, or EUI-64"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"ports"}),(0,d.jsx)(t.td,{children:"List on named ports that this workload exposes."}),(0,d.jsx)(t.td,{}),(0,d.jsxs)(t.td,{children:["List of ",(0,d.jsx)(t.a,{href:"#endpointport",children:"WorkloadEndpointPorts"})]}),(0,d.jsx)(t.td,{})]})]})]}),"\n",(0,d.jsx)(t.h3,{id:"ipnat",children:"IPNAT"}),"\n",(0,d.jsx)(o,{}),"\n",(0,d.jsx)(t.h3,{id:"endpointport",children:"EndpointPort"}),"\n",(0,d.jsxs)(t.p,{children:["A WorkloadEndpointPort associates a name with a particular TCP/UDP/SCTP port of the endpoint, allowing it to\nbe referenced as a named port in ",(0,d.jsx)(t.a,{href:"/calico/3.28/reference/resources/networkpolicy#entityrule",children:"policy rules"}),"."]}),"\n",(0,d.jsxs)(t.table,{children:[(0,d.jsx)(t.thead,{children:(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.th,{children:"Field"}),(0,d.jsx)(t.th,{children:"Description"}),(0,d.jsx)(t.th,{children:"Accepted Values"}),(0,d.jsx)(t.th,{children:"Schema"}),(0,d.jsx)(t.th,{children:"Default"})]})}),(0,d.jsxs)(t.tbody,{children:[(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"name"}),(0,d.jsxs)(t.td,{children:["The name to attach to this port, allowing it to be referred to in ",(0,d.jsx)(t.a,{href:"/calico/3.28/reference/resources/networkpolicy#entityrule",children:"policy rules"}),". Names must be unique within an endpoint."]}),(0,d.jsx)(t.td,{}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"protocol"}),(0,d.jsx)(t.td,{children:"The protocol of this named port."}),(0,d.jsxs)(t.td,{children:[(0,d.jsx)(t.code,{children:"TCP"}),", ",(0,d.jsx)(t.code,{children:"UDP"}),", ",(0,d.jsx)(t.code,{children:"SCTP"})]}),(0,d.jsx)(t.td,{children:"string"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"port"}),(0,d.jsx)(t.td,{children:"The workload port number."}),(0,d.jsxs)(t.td,{children:[(0,d.jsx)(t.code,{children:"1"}),"-",(0,d.jsx)(t.code,{children:"65535"})]}),(0,d.jsx)(t.td,{children:"int"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"hostPort"}),(0,d.jsx)(t.td,{children:"Port on the host that is forwarded to this port."}),(0,d.jsxs)(t.td,{children:[(0,d.jsx)(t.code,{children:"1"}),"-",(0,d.jsx)(t.code,{children:"65535"})]}),(0,d.jsx)(t.td,{children:"int"}),(0,d.jsx)(t.td,{})]}),(0,d.jsxs)(t.tr,{children:[(0,d.jsx)(t.td,{children:"hostIP"}),(0,d.jsx)(t.td,{children:"IP address on the host on which the hostPort is accessible."}),(0,d.jsxs)(t.td,{children:[(0,d.jsx)(t.code,{children:"1"}),"-",(0,d.jsx)(t.code,{children:"65535"})]}),(0,d.jsx)(t.td,{children:"int"}),(0,d.jsx)(t.td,{})]})]})]}),"\n",(0,d.jsx)(t.admonition,{type:"note",children:(0,d.jsx)(t.p,{children:"On their own, WorkloadEndpointPort entries don't result in any change to the connectivity of the port.\nThey only have an effect if they are referred to in policy."})}),"\n",(0,d.jsx)(t.admonition,{type:"note",children:(0,d.jsx)(t.p,{children:"The hostPort and hostIP fields are read-only and determined from Kubernetes hostPort configuration.\nThese fields are used only when host ports are enabled in Calico."})})]})}function j(e={}){let{wrapper:t}={...(0,s.R)(),...e.components};return t?(0,d.jsx)(t,{...e,children:(0,d.jsx)(x,{...e})}):x(e)}},17869:function(e,t,n){n.d(t,{R:()=>i,x:()=>o});var r=n(82645);let d={},s=r.createContext(d);function i(e){let t=r.useContext(s);return r.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function o(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(d):e.components||d:i(e.components),r.createElement(s.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.