# IP Reservation The DCE container network (Spiderpool) reserves some IP addresses for the entire Kubernetes cluster through the ReservedIP CR. These IP addresses will not be allocated by IPAM. ## Feature Introduction When it is clear that an IP address is already used outside the cluster, finding that IP address in existing IPPool instances and removing it can be time-consuming and laborious in order to avoid IP conflicts. In addition, network administrators want to ensure that the IP address is never allocated from any existing or future IPPool resource. Therefore, you can set the IP addresses that should not be used by the cluster in the ReservedIP CR. After that, even if the IPPool object contains those IP addresses, the IPAM plugin will not allocate them to Pods. The IP addresses in ReservedIP can be: - IP addresses that are clearly used by hosts outside the cluster - IP addresses that clearly cannot be used for network communication, such as the subnet IP and the broadcast IP ## Implementation Requirements 1. A Kubernetes cluster. 2. [Helm](https://helm.sh/docs/intro/install/) is installed. ## Install Spiderpool Follow the prompts to [install Spiderpool](../modules/spiderpool/install/install.md). ## Install the CNI Configuration To simplify writing Multus CNI configurations in JSON format, Spiderpool provides the SpiderMultusConfig CR to automatically manage Multus NetworkAttachmentDefinition CRs. The following is an example of creating a Macvlan SpiderMultusConfig configuration: - master: In this example, the interface `ens192` is used as the value of master. ```bash MACVLAN_MASTER_INTERFACE="ens192" MACVLAN_MULTUS_NAME="macvlan-$MACVLAN_MASTER_INTERFACE" cat < **Network Configuration** 2. Click **Static IP Pool** -> **IP Reservation** - **Reserve IP** 3. In the dialog box, enter one or more IPs to be reserved and click **OK** ![Create reserved IP](../images/reserved-ip01.png) ### Create Through the Command-Line YAML Use the following YAML, set `spec.ips` to `10.6.168.131-10.6.168.132`, and create the ReservedIP. ```bash cat < test-app-67dd9f645-lpjgs 0/1 ContainerCreating 0 17s node1 ``` If the IP address to be reserved has already been allocated to an application Pod, adding that IP address to the ReservedIP CR prevents the replica from running after it is restarted. Run the following command to add the IP address allocated to the Pod to the ReservedIP CR, and then restart the Pod. The Pod fails to start because "all IPs have been used up", which is as expected. ```bash ~# kubectl patch spiderreservedip test-reservedip --patch '{"spec":{"ips":["10.6.168.131-10.6.168.133"]}}' --type=merge ~# kubectl delete po test-app-67dd9f645-dv8xz pod "test-app-67dd9f645-dv8xz" deleted ~# kubectl get po -owide NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES test-app-67dd9f645-fvx4m 0/1 ContainerCreating 0 9s node2 test-app-67dd9f645-lpjgs 0/1 ContainerCreating 0 2m18s node1 ``` After the reserved IPs are removed, the Pods can obtain IP addresses and run. ```bash ~# kubectl delete sr test-reservedip spiderreservedip.spiderpool.spidernet.io "test-reservedip" deleted ~# kubectl get po -owide NAME READY STATUS RESTARTS AGE IP NODE NOMINATED NODE READINESS GATES test-app-67dd9f645-fvx4m 1/1 Running 0 4m23s 10.6.168.133 node2 test-app-67dd9f645-lpjgs 1/1 Running 0 6m14s 10.6.168.131 node1 ``` ## Summary The SpiderReservedIP feature helps infrastructure administrators plan networks more easily.