USER GUIDE
Configuration YAML
Purpose¶
Tune backend, monitored interfaces, policy routing, API/metrics bind, event filters, and audit logging — the control plane for every hook and CLI query.
When to use it¶
- Initial install: copy from
config/netevd.example.yaml - Multi-homed servers: list interfaces under
routing.policy_rules - Noisy lab hosts: add
filtersto ignoredocker*,veth*,br-* - Fleet scrape: enable metrics and optionally widen API bind on trusted networks
How to get there¶
- Live file:
/etc/netevd/netevd.yaml - Template:
config/netevd.example.yamlin the repo or release tarball - Validate before apply:
netevd validate
Operate from CLI¶
- Copy the example and edit:
sudo install -Dm644 config/netevd.example.yaml /etc/netevd/netevd.yaml
sudo ${EDITOR:-vi} /etc/netevd/netevd.yaml
- Set backend to match the host:
system:
backend: "systemd-networkd" # or NetworkManager | dhclient
- Limit monitoring scope (empty list = all interfaces):
monitoring:
interfaces:
- eth0
- eth1
- Enable multi-homed policy routing:
routing:
policy_rules:
- eth1
- Open API/metrics for fleet hosts (trusted network only):
api:
enabled: true
bind_address: "127.0.0.1" # use 0.0.0.0 only on isolated management nets
port: 9090
metrics:
enabled: true
port: 9091
- Add a filter to ignore container interfaces.
/metricsis served onapi.port(default 9090);metrics.portis recorded in the config but is not a second listener.
filters:
- match_rule:
interface_pattern: "docker*"
action: ignore
- Optional observe-only eBPF (requires
cargo build --features ebpfand BPF object):
ebpf:
enabled: true
drops: true
tcp_reset: true
min_count: 8
reasons_deny: ["NO_SOCKET"]
See eBPF guide.
- Validate, apply, verify:
netevd validate -c /etc/netevd/netevd.yaml
sudo systemctl restart netevd
netevd status -f json | jq .
journalctl -u netevd -n 20 --no-pager
-
Empty / fail: Parse error → validator prints the offending key; hooks stop firing → check filter
action: ignore; API unreachable →api.enabled: falseor bind still127.0.0.1on remote scrape. -
Success: Summary from
netevd validatematches intent; daemon logs show chosen backend; hooks andlist rulesbehave per YAML.