---
title: Creating ip-masq-agent on DaemonSet | GSuite Solved
description: "GKE Network Policy Insights: Enhance GKE cluster creation by configuring ip-masq-agent seamlessly with Terraform. Say goodbye to post-creation adjustments!"
---

[Articles | C2C](https://www.c2cglobal.com/articles)

# [Creating ip-masq-agent on DaemonSet | GSuite Solved](https://www.c2cglobal.com/articles/how-is-ip-masq-agent-daemonset-created-3267)

 Written by [Gary Turner](https://www.c2cglobal.com/articles/author/gary-turner) | Oct 2, 2022 5:00:00 AM

Hi all,

I've recently created several GKE clusters through some custom Terraform code. However, by default it looks like NAT-ing from the pod network is not enabled which is not desirable. So I found this article on how to enable it:

[https://cloud.google.com/kubernetes-engine/docs/how-to/ip-masquerade-agent#how\_ipmasq\_works](https://cloud.google.com/kubernetes-engine/docs/how-to/ip-masquerade-agent#how_ipmasq_works)

 

Which did the trick just fine. However, I can't seem to find a way to enable this during the cluster creation. I'd prefer not to have to add in the daemonset and configmap after the cluster is created. Is there any way to configure this as part of the cluster creation through Terraform? Also, this is a private cluster and I do not have access to the cluster through kubectl from where I'm running Terraform.

 

Thanks!

 

**Best answer by garyturner3**

Found the issue. The ip-masq agent daemonset is created only if I initially create the cluster with a network policy on and using the calico provider. If I switch to using those after the initial cluster creation then the daemonset won’t be created.

[View full post](https://www.c2cglobal.com/articles/how-is-ip-masq-agent-daemonset-created-3267)

```json
{
  "@context" : "http://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Gary Turner"
  },
  "dateModified" : "2024-03-29T14:09:35.060Z",
  "datePublished" : "2022-10-02T05:00:00Z",
  "headline" : "How is ip-masq-agent DaemonSet created?",
  "image" : {
    "@type" : "ImageObject",
    "height" : 700,
    "url" : "https://www.c2cglobal.com/hubfs/Imported_Blog_Media/General%20Article%20Graphic-Mar-21-2024-09-11-30-9884-PM-Mar-26-2024-08-41-44-8399-PM.jpg",
    "width" : 2000
  },
  "mainEntityOfPage" : "https://www.c2cglobal.com/articles/how-is-ip-masq-agent-daemonset-created-3267",
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "height" : 60,
      "url" : "/hs/hsstatic/content_shared_assets/static-1.4092/img/default-amp-logo.png",
      "width" : 60
    },
    "name" : "C2C Articles"
  }
}
```