The plugin matters most for one feature: NetworkPolicy (Pod Security and Policies). The API server accepts NetworkPolicy objects on any cluster, but only a plugin that implements them enforces anything; with a plugin that does not, the policies are silently ignored. kind 14,561 's kindnetd gained policy support in kind 0.24 (August 2024) by embedding the SIG Network project kube-network-policies, which works through an nftables 40,292 table on each node:
docker exec l3-booknest-worker nft list tables | grep kindnet
kubectl exec deploy/web -- wget -qO- http://web/healthztable inet kindnet-network-policies ok
The second command exercises the whole chain from this section: a front-end Pod resolved web through CoreDNS 366,312 , kube-proxy's rules rewrote the ClusterIP, and the packet crossed a veth pair into one of the two Pods, whose Nginx 75 answered its health check.
| Plugin | Data plane | NetworkPolicy | Typical home |
|---|---|---|---|
| kindnetd | Routes, nftables | Yes, since kind 0.24 | kind (default) |
| Flannel 9,549 | VXLAN overlay | No (k3s 51,195 adds kube-router) | k3s, small clusters |
| Calico 111,267 | Routes/BGP, VXLAN, eBPF | Yes, plus its own policy types | On-premises, EKS 24 , AKS 6 |
| Cilium 96,364 | eBPF, can replace kube-proxy | Yes, including layer 7 | GKE 1 Dataplane V2, large clusters |
For BookNest, kindnetd is enough: it routes Pods, enforces NetworkPolicy, and needs no installation. Calico (github.com/projectcalico/calico (https://github.com/projectcalico/calico 7,373 )) and Cilium (github.com/cilium/cilium (https://github.com/cilium/cilium 25,566 ), a CNCF graduated project) are worth learning next because managed clouds use them; both have commercial editions (Tigera's Calico Enterprise, Isovalent's Enterprise for Cilium) that add support, observability and compliance features. To try one on kind, set networking.disableDefaultCNI: true in the cluster configuration and install the plugin with Helm 29,435 .