Skip to content

USER GUIDE

Configuration YAML

Purpose

Tune backend, monitored interfaces, policy routing, API/metrics bind, event filters, and audit logging — the control plane for every hook and CLI query.

When to use it

  • Initial install: copy from config/netevd.example.yaml
  • Multi-homed servers: list interfaces under routing.policy_rules
  • Noisy lab hosts: add filters to ignore docker*, veth*, br-*
  • Fleet scrape: enable metrics and optionally widen API bind on trusted networks

How to get there

  • Live file: /etc/netevd/netevd.yaml
  • Template: config/netevd.example.yaml in the repo or release tarball
  • Validate before apply: netevd validate

Operate from CLI

  1. Copy the example and edit:
sudo install -Dm644 config/netevd.example.yaml /etc/netevd/netevd.yaml
sudo ${EDITOR:-vi} /etc/netevd/netevd.yaml
  1. Set backend to match the host:
system:
  backend: "systemd-networkd"   # or NetworkManager | dhclient
  1. Limit monitoring scope (empty list = all interfaces):
monitoring:
  interfaces:
    - eth0
    - eth1
  1. Enable multi-homed policy routing:
routing:
  policy_rules:
    - eth1
  1. Open API/metrics for fleet hosts (trusted network only):
api:
  enabled: true
  bind_address: "127.0.0.1"   # use 0.0.0.0 only on isolated management nets
  port: 9090
metrics:
  enabled: true
  port: 9091
  1. Add a filter to ignore container interfaces. /metrics is served on api.port (default 9090); metrics.port is recorded in the config but is not a second listener.
filters:
  - match_rule:
      interface_pattern: "docker*"
    action: ignore
  1. Optional observe-only eBPF (requires cargo build --features ebpf and BPF object):
ebpf:
  enabled: true
  drops: true
  tcp_reset: true
  min_count: 8
  reasons_deny: ["NO_SOCKET"]

See eBPF guide.

  1. Validate, apply, verify:
netevd validate -c /etc/netevd/netevd.yaml
sudo systemctl restart netevd
netevd status -f json | jq .
journalctl -u netevd -n 20 --no-pager
  1. Empty / fail: Parse error → validator prints the offending key; hooks stop firing → check filter action: ignore; API unreachable → api.enabled: false or bind still 127.0.0.1 on remote scrape.

  2. Success: Summary from netevd validate matches intent; daemon logs show chosen backend; hooks and list rules behave per YAML.