USER GUIDE
Common workflows
A. First routable notify¶
- Install and start
netevd. - Drop an executable script in
/etc/netevd/routable.d/. - Bounce the interface or renew DHCP.
- Confirm
journalctl -u netevd,netevd events --tail 10, and script side effects.
sudo systemctl enable --now netevd
sudo chmod +x /etc/netevd/routable.d/01-notify.sh
sudo ip link set eth0 down && sudo ip link set eth0 up
journalctl -u netevd -n 20 --no-pager
B. Multi-homed policy routing¶
- List secondary interfaces under
routing.policy_rulesin YAML. - Acquire addresses on each uplink.
- Verify:
netevd validate
sudo systemctl restart netevd
netevd list rules
ip rule list
ip route show table $((200 + $(cat /sys/class/net/eth1/ifindex)))
Traffic sourced from an address on eth1 should leave via eth1's gateway.
C. Watch events live¶
netevd events -f
# or filter:
netevd events -f -i eth0 -t routable
D. Fleet observability¶
- Set
api.bind_address: "0.0.0.0"only on trusted management networks (or scrape via SSH tunnel). - Point Prometheus at
http://<host>:9090/metricsand RESThttp://<host>:9090/api/v1/status. - Alert when
netevd_script_executions_totalgoes quiet (daemon likely down).
E. Safe change window¶
netevd validate -c /etc/netevd/netevd.yaml
sudo systemctl restart netevd
# or when hot reload is available:
netevd reload --endpoint http://127.0.0.1:9090
journalctl -u netevd -n 50 --no-pager
netevd status
F. Ignore noisy interfaces¶
Add a YAML filter with action: ignore for docker*, veth*, etc. (see config/netevd.example.yaml), then:
netevd validate && sudo systemctl restart netevd
netevd events -f # confirm docker events no longer dispatch hooks
G. Veth hook check¶
From a checkout, on a host that should not hook every existing veth:
./scripts/deploy-remote.sh <host> [user]
The script installs netevd with a config that matches only veth-netevd*, creates that pair (peer in a network namespace), and checks link-added and address-added hooks. Same-host ping between two veth ends is not a valid check on hosts that filter local ICMP; the script pings across the namespace boundary.
Operate from CLI¶
Every workflow above is CLI-first: hooks in /etc/netevd/, validation via netevd validate, observation via netevd events and journalctl, fleet checks via curl to <host>:9090. See Page-by-page guides for command-level detail per surface.