--- # Enables Internet connectivity from containers nat_outgoing: true # Use IP-over-IP encapsulation across hosts ipip: false # Set to true if you want your calico cni binaries to overwrite the # ones from hyperkube while leaving other cni plugins intact. overwrite_hyperkube_cni: true calico_cert_dir: /etc/calico/certs etcd_cert_dir: /etc/ssl/etcd/ssl # Global as_num (/calico/bgp/v1/global/as_num) global_as_num: "64512" # You can set MTU value here. If left undefined or empty, it will # not be specified in calico CNI config, so Calico will use built-in # defaults. The value should be a number, not a string. # calico_mtu: 1500 # Linux capabilities to be dropped for container engines calico_drop_cap: - chown - dac_override - fowner - fsetid - kill - setgid - setuid - setpcap - net_bind_service - net_raw - sys_chroot - mknod - audit_write - setfcap # Limits for apps calico_node_memory_limit: 500M calico_node_cpu_limit: 300m calico_node_memory_requests: 256M calico_node_cpu_requests: 150m calicoctl_memory_limit: 170M calicoctl_cpu_limit: 100m calicoctl_memory_requests: 70M calicoctl_cpu_requests: 50m