1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["2820"],{25981:function(e,n,t){t.r(n),t.d(n,{frontMatter:()=>r,toc:()=>c,default:()=>h,metadata:()=>o,assets:()=>d,contentTitle:()=>s});var o=JSON.parse('{"id":"reference/calicoctl/node/run","title":"calicoctl node run","description":"Command and options for running a Calico node.","source":"@site/calico_versioned_docs/version-3.28/reference/calicoctl/node/run.mdx","sourceDirName":"reference/calicoctl/node","slug":"/reference/calicoctl/node/run","permalink":"/calico/3.28/reference/calicoctl/node/run","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico_versioned_docs/version-3.28/reference/calicoctl/node/run.mdx","tags":[],"version":"3.28","frontMatter":{"description":"Command and options for running a Calico node."},"sidebar":"calicoSidebar","previous":{"title":"calicoctl node","permalink":"/calico/3.28/reference/calicoctl/node/overview"},"next":{"title":"calicoctl node status","permalink":"/calico/3.28/reference/calicoctl/node/status"}}'),i=t(37937),a=t(17869);let r={description:"Command and options for running a Calico node."},s="calicoctl node run",d={},c=[{value:"Displaying the help text for 'calicoctl node run' command",id:"displaying-the-help-text-for-calicoctl-node-run-command",level:2},{value:"Kubernetes as the datastore",id:"kubernetes-as-the-datastore",level:3},{value:"Examples",id:"examples",level:3},{value:"IP Autodetection method examples",id:"ip-autodetection-method-examples",level:4},{value:"Options",id:"options",level:3},{value:"General options",id:"general-options",level:3},{value:"See also",id:"see-also",level:2}];function l(e){let n={a:"a",admonition:"admonition",code:"code",em:"em",h1:"h1",h2:"h2",h3:"h3",h4:"h4",header:"header",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,a.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(n.header,{children:(0,i.jsx)(n.h1,{id:"calicoctl-node-run",children:"calicoctl node run"})}),"\n",(0,i.jsxs)(n.p,{children:["This sections describes the ",(0,i.jsx)(n.code,{children:"calicoctl node run"})," command."]}),"\n",(0,i.jsxs)(n.p,{children:["Read the ",(0,i.jsx)(n.a,{href:"/calico/3.28/reference/calicoctl/overview",children:"calicoctl Overview"}),"\nfor a full list of calicoctl commands."]}),"\n",(0,i.jsx)(n.h2,{id:"displaying-the-help-text-for-calicoctl-node-run-command",children:"Displaying the help text for 'calicoctl node run' command"}),"\n",(0,i.jsxs)(n.p,{children:["Run ",(0,i.jsx)(n.code,{children:"calicoctl node run --help"})," to display the following help menu for the\ncommand."]}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{children:"Usage:\n calicoctl node run [--ip=<IP>] [--ip6=<IP6>] [--as=<AS_NUM>]\n [--name=<NAME>]\n [--ip-autodetection-method=<IP_AUTODETECTION_METHOD>]\n [--ip6-autodetection-method=<IP6_AUTODETECTION_METHOD>]\n [--log-dir=<LOG_DIR>]\n [--node-image=<DOCKER_IMAGE_NAME>]\n [--backend=(bird|none)]\n [--config=<CONFIG>]\n [--felix-config=<CONFIG>]\n [--no-default-ippools]\n [--dryrun]\n [--init-system]\n [--disable-docker-net
1working]\n [--docker-networking-ifprefix=<IFPREFIX>]\n [--use-docker-networking-container-labels]\n\nOptions:\n -h --help Show this screen.\n --name=<NAME> The name of the Calico node. If this is not\n supplied it defaults to the host name.\n --as=<AS_NUM> Set the AS number for this node. If omitted, it\n will use the value configured on the node resource.\n If there is no configured value and --as option is\n omitted, the node will inherit the global AS number\n (see 'calicoctl config' for details).\n --ip=<IP> Set the local IPv4 routing address for this node.\n If omitted, it will use the value configured on the\n node resource. If there is no configured value\n and the --ip option is omitted, the node will\n attempt to autodetect an IP address to use. Use a\n value of 'autodetect' to always force autodetection\n of the IP each time the node starts.\n --ip6=<IP6> Set the local IPv6 routing address for this node.\n If omitted, it will use the value configured on the\n node resource. If there is no configured value\n and the --ip6 option is omitted, the node will not\n route IPv6. Use a value of 'autodetect' to force\n autodetection of the IP each time the node starts.\n --ip-autodetection-method=<IP_AUTODETECTION_METHOD>\n Specify the autodetection method for detecting the\n local IPv4 routing address for this node. The valid\n options are:\n > first-found\n Use the first valid IP address on the first\n enumerated interface (common known exceptions are\n filtered out, e.g. the docker bridge). It is not\n recommended to use this if you have multiple\n external interfaces on your host.\n > can-reach=<IP OR DOMAINNAME>\n Use the interface determined by your host routing\n tables that will be used to reach the supplied\n destination IP or domain name.\n > interface=<IFACE NAME REGEX LIST>\n Use the first valid IP address found on interfaces\n named as per the first matching supplied interface\n name regex. Regexes are separated by commas\n (e.g. eth.*,enp0s.*).\n > skip-interface=<IFACE NAME REGEX LIST>\n Use the first valid IP address on the first\n enumerated interface (same logic as first-found\n above) that does NOT match with any of the\n specified interface name regexes. Regexes are\n separated by commas (e.g. eth.*,enp0s.*).\n [default: first-found]\n --ip6-autodetection-method=<IP6_AUTODETECTION_METHOD>\n Specify the autodetection method for detecting the\n local IPv6 routing address for this node. See\n ip-autodetection-method flag for valid options.\n [default: first-found]\n --log-dir=<LOG_DIR> The directory containing Calico logs.\n [default: /var/log/calico]\n --node-image=<DOCKER_IMAGE_NAME>\n Docker image to use for Calico's per-node container.\n [default: calico/node:latest]\n --backend=(bird|none)\n Specify which networking backend to use. When set\n to \"none\", C
1alico node runs in policy only mode.\n [default: bird]\n --dryrun Output the appropriate command, without starting the\n container.\n --init-system Run the appropriate command to use with an init\n system.\n --no-default-ippools Do not create default pools upon startup.\n Default IP pools will be created if this is not set\n and there are no pre-existing Calico IP pools.\n --disable-docker-networking\n Disable Docker networking.\n --docker-networking-ifprefix=<IFPREFIX>\n Interface prefix to use for the network interface\n within the Docker containers that have been networked\n by the Calico driver.\n [default: cali]\n --use-docker-networking-container-labels\n Extract the Calico-namespaced Docker container labels\n (org.projectcalico.label.*) and apply them to the\n container endpoints for use with Calico policy.\n This option is only valid when using Calico Docker\n networking, and when enabled traffic must be\n explicitly allowed by configuring Calico policies.\n -c --config=<CONFIG> Path to the file containing connection\n configuration in YAML or JSON format.\n [default: /etc/calico/calicoctl.cfg]\n --felix-config=<CONFIG>\n Path to the file containing Felix\n configuration in YAML or JSON format.\n\nDescription:\n This command is used to start a calico/node container instance which provides\n Calico networking and network policy on your compute host.\n"})}),"\n",(0,i.jsx)(n.h3,{id:"kubernetes-as-the-datastore",children:"Kubernetes as the datastore"}),"\n",(0,i.jsxs)(n.p,{children:["When Calico is configured to use the Kubernetes API as the datastore, BGP routing is ",(0,i.jsx)(n.em,{children:"currently"}),"\nnot supported. Many of the command line options related to BGP routing will\nhave no effect. These include:"]}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.code,{children:"--ip"}),", ",(0,i.jsx)(n.code,{children:"--ip6"}),", ",(0,i.jsx)(n.code,{children:"--ip-autodetection-method"}),", ",(0,i.jsx)(n.code,{children:"--ip6-autodetection-method"})]}),"\n",(0,i.jsx)(n.li,{children:(0,i.jsx)(n.code,{children:"--as"})}),"\n",(0,i.jsx)(n.li,{children:(0,i.jsx)(n.code,{children:"--backend"})}),"\n"]}),"\n",(0,i.jsx)(n.h3,{id:"examples",children:"Examples"}),"\n",(0,i.jsx)(n.p,{children:"Start the calico/node with a pre-configured IPv4 address for BGP."}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"sudo calicoctl node run\n"})}),"\n",(0,i.jsx)(n.p,{children:"An example response follows."}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{children:"Running command to load modules: modprobe -a xt_set ip6_tables\nEnabling IPv4 forwarding\nEnabling IPv6 forwarding\nIncreasing conntrack limit\nRunning the following command:\n\ndocker run --net=host --privileged --name=calico-node -d --restart=always -e ETCD_SCHEME=http -e HOSTNAME=calico -e ETCD_AUTHORITY=127.0.0.1:2379 -e AS= -e NO_DEFAULT_POOLS= -e ETCD_ENDPOINTS= -e IP= -e IP6= -e CALICO_NETWORKING_BACKEND=bird -v /var/run/docker.sock:/var/run/docker.sock -v /var/run/calico:/var/run/calico -v /lib/modules:/lib/modules -v /var/log/calico:/var/log/calico -v /run/docker/plugins:/run/docker/plugins calico/node:v3.28.5\n\nWaiting for etcd connection...\nUsing configured IPv4 address: 192.0.2.0\nNo IPv6 address configured\nUsing global AS number\nWARNING: Could not confirm that the provided IPv4 address is assigned to this host.\nCalico node name: calico\nCalico node started successfully\n"})}),"\n",(0,i.jsx)(n.h4,{id:"ip-autodetection-method-examples",children:"IP Autodetection method examples"}),"\n",(0,i.jsxs)(n.p,{children:["The node resource includes IPv4 and IPv6 routing IP addresses that should\nmatch those on one of the host interfaces. These IP addresses may be\nconfigured in advance by configuring the node resource prior to starting the\n",(0,i.jsx)(n.code,{children:"calico/node"})," service, alternatively, the addresses may either be explicitly\nspecified or autodetected through options on the ",(0,i.jsx)(n.code,{children:"calicoctl run"})," command."]}),"\n",(0,i.jsx)(n.p,{children:"There are different autodetection methods available and you should use the one\nbest suited to your deployment. If you are able to explicitly specify the IP\naddresses, that is always preferred over autodetection. This section describes\nthe available methods for autodetecting the hosts IP addresses."}),"\n",(0,i.jsx)(n.p,{children:"An IPv4 address is always required, and so if no address was previously\nconfigured in the node resource, and n
1o address was specified on the CLI, then\nwe will attempt to autodetect an IPv4 address. An IPv6 address, however, will\nonly be autodetected when explicitly requested."}),"\n",(0,i.jsxs)(n.p,{children:["To force autodetection of an IPv4 address, use the option ",(0,i.jsx)(n.code,{children:"--ip=autodetect"}),". To\nforce autodetection of an IPv6 address, use the option ",(0,i.jsx)(n.code,{children:"--ip6=autodetect"}),"."]}),"\n",(0,i.jsxs)(n.p,{children:["To set the autodetection method for IPv4, use the ",(0,i.jsx)(n.code,{children:"--ip-autodetection-method"})," option.\nTo set the autodetection method for IPv6, use the ",(0,i.jsx)(n.code,{children:"--ip6-autodetection-method"})," option."]}),"\n",(0,i.jsx)(n.admonition,{type:"note",children:(0,i.jsxs)(n.p,{children:["If you are starting the ",(0,i.jsx)(n.code,{children:"calico/node"})," container directly (and not using the\n",(0,i.jsx)(n.code,{children:"calicoctl run"})," helper command), the options are passed in environment\nvariables. These are described in\n",(0,i.jsxs)(n.a,{href:"/calico/3.28/reference/configure-calico-node",children:["Configuring ",(0,i.jsx)(n.code,{children:"calico/node"})]}),"."]})}),"\n",(0,i.jsx)(n.p,{children:(0,i.jsx)(n.strong,{children:"first-found"})}),"\n",(0,i.jsxs)(n.p,{children:["The ",(0,i.jsx)(n.code,{children:"first-found"}),' option enumerates all interface IP addresses and returns the\nfirst valid IP address (based on IP version and type of address) on\nthe first valid interface. Certain known "local" interfaces\nare omitted, such as the docker bridge. The order that both the interfaces\nand the IP addresses are listed is system dependent.']}),"\n",(0,i.jsx)(n.p,{children:"This is the default detection method. However, since this method only makes a\nvery simplified guess, it is recommended to either configure the node with a\nspecific IP address, or to use one of the other detection methods."}),"\n",(0,i.jsx)(n.p,{children:"An example with first-found auto detection method explicitly specified follows"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"sudo calicoctl node run --ip autodetect --ip-autodetection-method first-found\n"})}),"\n",(0,i.jsx)(n.p,{children:(0,i.jsx)(n.strong,{children:"can-reach=DESTINATION"})}),"\n",(0,i.jsxs)(n.p,{children:["The ",(0,i.jsx)(n.code,{children:"can-reach"})," method uses your local routing to determine which IP address\nwill be used to reach the supplied destination. Both IP addresses and domain\nnames may be used."]}),"\n",(0,i.jsx)(n.p,{children:"An example with IP detection using a can-reach IP address:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"sudo calicoctl node run --ip autodetect --ip-autodetection-method can-reach=8.8.8.8\n"})}),"\n",(0,i.jsx)(n.p,{children:"An example with IP detection using a can-reach domain name:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"sudo calicoctl node run --ip autodetect --ip-autodetection-method can-reach=www.google.com\n"})}),"\n",(0,i.jsx)(n.p,{children:(0,i.jsx)(n.strong,{children:"interface=INTERFACE-REGEX,INTERFACE-REGEX,..."})}),"\n",(0,i.jsxs)(n.p,{children:["The ",(0,i.jsx)(n.code,{children:"interface"})," method uses the supplied interface regular expressions (golang\nsyntax) to enumerate matching interfaces and to return the first IP address on\nthe first interface that matches any of the interface regexes provided. The\norder that both the interfaces and the IP addresses are listed is system\ndependent."]}),"\n",(0,i.jsx)(n.p,{children:"Example with IP detection on interface eth0:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"sudo calicoctl node run --ip autodetect --ip-autodetection-method interface=eth0\n"})}),"\n",(0,i.jsx)(n.p,{children:"Example with IP detection on interfaces eth0, eth1, eth2 etc.:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"sudo calicoctl node run --ip autodetect --ip-autodetection-method interface=eth.*\n"})}),"\n",(0,i.jsx)(n.p,{children:"An example with IP detection on interfaces eth0, eth1, eth2 etc. and wlp2s0:"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{className:"language-bash",children:"sudo calicoctl node run --ip-autodetect --ip-autodetection-method interface=eth.*,wlp2s0\n"})}),"\n",(0,i.jsx)(n.p,{children:(0,i.jsx)(n.strong,{children:"skip-interface=INTERFACE-REGEX,INT
1ERFACE-REGEX,..."})}),"\n",(0,i.jsxs)(n.p,{children:["The ",(0,i.jsx)(n.code,{children:"skip-interface"})," method uses the supplied interface regular expressions (golang\nsyntax) to enumerate all interface IP addresses and returns the first valid IP address\n(based on IP version and type of address) that does not match the listed regular\nexpressions. Like the ",(0,i.jsx)(n.code,{children:"first-found"}),' option, it also skips by default certain known\n"local" interfaces such as the docker bridge. The order that both the interfaces\nand the IP addresses are listed is system dependent.']}),"\n",(0,i.jsxs)(n.p,{children:["This method has the ability to take in multiple regular expressions separated by ",(0,i.jsx)(n.code,{children:","}),".\nSpecifying only one regular expression for interfaces to skip will also work and a\nterminating ",(0,i.jsx)(n.code,{children:","})," character does not need to be specified for those cases."]}),"\n",(0,i.jsx)(n.h3,{id:"options",children:"Options"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{children:" --name=<NAME> The name of the Calico node. If this is not\n supplied it defaults to the host name.\n --as=<AS_NUM> Set the AS number for this node. If omitted, it\n will use the value configured on the node resource.\n If there is no configured value and --as option is\n omitted, the node will inherit the global AS number\n (see 'calicoctl config' for details).\n --ip=<IP> Set the local IPv4 routing address for this node.\n If omitted, it will use the value configured on the\n node resource. If there is no configured value\n and the --ip option is omitted, the node will\n attempt to autodetect an IP address to use. Use a\n value of 'autodetect' to always force autodetection\n of the IP each time the node starts.\n --ip6=<IP6> Set the local IPv6 routing address for this node.\n If omitted, it will use the value configured on the\n node resource. If there is no configured value\n and the --ip6 option is omitted, the node will not\n route IPv6. Use a value of 'autodetect' to force\n autodetection of the IP each time the node starts.\n --ip-autodetection-method=<IP_AUTODETECTION_METHOD>\n Specify the autodetection method for detecting the\n local IPv4 routing address for this node. The valid\n options are:\n > first-found\n Use the first valid IP address on the first\n enumerated interface (common known exceptions are\n filtered out, e.g. the docker bridge). It is not\n recommended to use this if you have multiple\n external interfaces on your host.\n > can-reach=<IP OR DOMAINNAME>\n Use the interface determined by your host routing\n tables that will be used to reach the supplied\n destination IP or domain name.\n > interface=<IFACE NAME REGEX LIST>\n Use the first valid IP address found on interfaces\n named as per the first matching supplied interface\n name regex. Regexes are separated by commas\n (e.g. eth.*,enp0s.*).\n > skip-interface=<IFACE NAME REGEX LIST>\n Use the first valid IP address on the first\n enumerated interface (same logic as first-found\n above) that does NOT match with any of the\n specified interface name regexes. Regexes are\n separated by commas (e.g. eth.*,enp0s.*).\n [default: first-found]\n --ip6-autodetection-method=<IP6_AUTODETECTION_METHOD>\n Specify the autodetection method for detecting the\n local IPv6 routing address for this node. See\n ip-autodetection-method flag for valid options.\n [default: first-found]\n --log-dir=<LOG_DIR> The directory containing Calico logs.\n [default: /var/log/calico]\n --node-image=<DOCKER_IMAGE_NAME>\n Docker image to use for Calico's per-node container.\n [default: calico/node:latest]\n --backend=(bird|none)\n Specify which networking backend to use. When set\n to \"none\", C
1alico node runs in policy only mode.\n [default: bird]\n --dryrun Output the appropriate command, without starting the\n container.\n --init-system Run the appropriate command to use with an init\n system.\n --no-default-ippools Do not create default pools upon startup.\n Default IP pools will be created if this is not set\n and there are no pre-existing Calico IP pools.\n --disable-docker-networking\n Disable Docker networking.\n --docker-networking-ifprefix=<IFPREFIX>\n Interface prefix to use for the network interface\n within the Docker containers that have been networked\n by the Calico driver.\n [default: cali]\n --use-docker-networking-container-labels\n Extract the Calico-namespaced Docker container labels\n (org.projectcalico.label.*) and apply them to the\n container endpoints for use with Calico policy.\n This option is only valid when using Calico Docker\n networking, and when enabled traffic must be\n explicitly allowed by configuring Calico policies.\n"})}),"\n",(0,i.jsx)(n.h3,{id:"general-options",children:"General options"}),"\n",(0,i.jsx)(n.pre,{children:(0,i.jsx)(n.code,{children:"-c --config=<CONFIG> Path to the file containing connection\n configuration in YAML or JSON format.\n [default: /etc/calico/calicoctl.cfg]\n"})}),"\n",(0,i.jsx)(n.h2,{id:"see-also",children:"See also"}),"\n",(0,i.jsxs)(n.ul,{children:["\n",(0,i.jsx)(n.li,{children:(0,i.jsx)(n.a,{href:"/calico/3.28/operations/calicoctl/install",children:"Installing calicoctl"})}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.a,{href:"/calico/3.28/reference/resources/overview",children:"Resources"})," for details on all valid resources, including file format\nand schema"]}),"\n",(0,i.jsxs)(n.li,{children:[(0,i.jsx)(n.a,{href:"/calico/3.28/reference/resources/networkpolicy",children:"Policy"})," for details on the Calico selector-based policy model"]}),"\n"]})]})}function h(e={}){let{wrapper:n}={...(0,a.R)(),...e.components};return n?(0,i.jsx)(n,{...e,children:(0,i.jsx)(l,{...e})}):l(e)}},17869:function(e,n,t){t.d(n,{R:()=>r,x:()=>s});var o=t(82645);let i={},a=o.createContext(i);function r(e){let n=o.useContext(a);return o.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function s(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:r(e.components),o.createElement(a.Provider,{value:n},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.