Network policy on the FluxVM VM-edge
FluxVM is not a CNI. This document is the supported CNP-shaped policy
subset that compiles onto Network Fabric (GA; dataplane schema v4) pins
under /sys/fs/bpf/fluxvm.
Not the same plane as Kubernetes NetworkPolicy. Sentinel Secure Containers Sets 13–15 compile
networking.k8s.io/v1 NetworkPolicyinto Pod-scoped VM-edge policy (schema v2 /fluxvm_prules) viafluxvm-networkpolicy-controller— see secure-containers-set14.md and secure-containers-set15.md. This file covers Fabric CNP/group policy for disposable VMs, not that controller.
Coexistence with a node CNI (mode=cilium) is separate — see
ebpf-cilium.md. That mode only checks the agent socket;
FluxVM never writes foreign private BPF maps.
Production runbook: production-dataplane.md. Security groups: network-groups.md.
Mapped features
| Concept | FluxVM |
|---|---|
Numeric identities (reserved:world=2, local ≥256) | identity.rs + group FNV ≥ 0x10000 |
endpointSelector.matchLabels | Group labels app=web |
CNP document (kind NetworkPolicy / CNP JSON) | POST /v1/network/cnp, fluxvm cnp apply |
toCIDR / toCIDRSet / except | allow_cidrs / deny_cidrs |
toEntities world/host/cluster/remote-node | Entity → CIDR expansion |
toFQDNs | Resolve to IPv4/32 + IPv6/128 at apply; wildcards skipped |
toPorts + ranges + named ports | tcp/443, tcp/8000-8003, https→443 |
egressDeny / ingressDeny | fluxvm_deny4/6 before allow |
enableDefaultDeny | default_allow=false |
auditMode | sample_rate bit 31; log drop, forward packet |
| Conntrack | fluxvm_ct LRU learn/hit |
| Identity list | GET /v1/network/identities, fluxctl identity list |
| Group / identity policy | fluxvm_gid written at configure_maps |
| Observe snapshot | GET /v1/network/observe, fluxctl observe |
| toFQDNs live refresh | POST /v1/network/refresh-dns, fluxvm dataplane refresh-dns (best-effort fleet-wide; skipped VMs logged, call returns refreshed count) |
| ipcache | Guest IP → identity (GET /v1/network/ipcache) |
| Production health | fluxvm dataplane health, production-dataplane.md |
Not in scope for this policy plane: kube-proxy replacement, WireGuard/IPsec datapath, L7 Envoy/Kafka parsers, ClusterMesh, or a full flow UI.
Maglev / DSR / SNAT service LB lives in Service Fabric v6 (BPF schema 4 / program generation 6) — service-fabric.md. Per-VM Network Fabric policy (this doc) is orthogonal. (service-fabric.md), not in CNP/group compilers.
Apply a CNP
fluxvm cnp apply --spec examples/cnp-web.json
fluxvm cnp list
fluxctl identity list
fluxctl observe
Label the VM policy so the compiled group matches:
{ "labels": ["app=web"], "default_allow": false }
Tutorials
Hands-on Network Fabric policy guides:
docs/tutorials/network-policy/ — getting started, identities, security groups, CNP, default deny, named ports, entities/FQDNs, audit mode, observe, multi-group merge.
Tests
python3 scripts/test-network-policy.py
cargo test -p fluxvm-network --lib
python3 scripts/test-production-dataplane.py
sudo -E ./scripts/test-security-groups-e2e.sh
sudo -E ./scripts/test-production-dataplane-e2e.sh