A host endpoint resource (
HostEndpoint) represents one or more real or virtual interfaces
attached to a host that is running Calico. It enforces Calico policy on
the traffic that is entering or leaving the host’s default network namespace through those
A host endpoint with
interfaceName: *represents all of a host’s real or virtual interfaces.
A host endpoint for one specific real interface is configured by
interfaceName: <name-of-that-interface>, for example
interfaceName: eth0, or by leaving
interfaceNameempty and including one of the interface’s IPs in
Each host endpoint may include a set of labels and list of profiles that Calico will use to apply policy to the interface.
Default behavior of external traffic to/from host
If a host endpoint is added and network policy is not in place, the Calico default is to deny traffic to/from that endpoint (except for traffic allowed by failsafe rules). For host endpoints, Calico blocks traffic only to/from interfaces that it’s been explicitly told about in network policy. Traffic to/from other interfaces is ignored.
Note: Currently, for host endpoints with
interfaceName: *, only pre-DNAT policy is implemented.
calicoctl commands that specify a resource type on the CLI, the following
aliases are supported (all case insensitive):
Important: When rendering security rules on other hosts, Calico uses the
expectedIPsfield to resolve label selectors to IP addresses. If the
expectedIPsfield is omitted then security rules that use labels will fail to match this endpoint.
apiVersion: projectcalico.org/v3 kind: HostEndpoint metadata: name: some.name labels: type: production spec: interfaceName: eth0 node: myhost expectedIPs: - 192.168.0.1 - 192.168.0.2 profiles: - profile1 - profile2 ports: - name: some-port port: 1234 protocol: TCP - name: another-port port: 5432 protocol: UDP
Host endpoint definition
|name||The name of this hostEndpoint. Required.||Alphanumeric string with optional
|labels||A set of labels to apply to this endpoint.||map|
|node||The name of the node where this HostEndpoint resides.||string|
|expectedIPs||The expected IP addresses associated with the interface.||Valid IPv4 or IPv6 address||list|
|profiles||The list of profiles to apply to the endpoint.||list|
|ports||List of named ports that this workload exposes.||List of EndpointPorts|
An EndpointPort associates a name with a particular TCP/UDP/SCTP port of the endpoint, allowing it to be referenced as a named port in policy rules.
|name||The name to attach to this port, allowing it to be referred to in policy rules. Names must be unique within an endpoint.||string|
|protocol||The protocol of this named port.||
|port||The workload port number.||
Note: On their own, EndpointPort entries don’t result in any change to the connectivity of the port. They only have an effect if they are referred to in policy.
|Kubernetes API server||Yes||Yes||Yes|