Skip to main content

Network policy on the FluxVM VM-edge

FluxVM is not a CNI. This document is the supported CNP-shaped policy subset that compiles onto Network Fabric (GA; dataplane schema v4) pins under /sys/fs/bpf/fluxvm.

Not the same plane as Kubernetes NetworkPolicy. Sentinel Secure Containers Sets 13–15 compile networking.k8s.io/v1 NetworkPolicy into Pod-scoped VM-edge policy (schema v2 / fluxvm_prules) via fluxvm-networkpolicy-controller — see secure-containers-set14.md and secure-containers-set15.md. This file covers Fabric CNP/group policy for disposable VMs, not that controller.

Coexistence with a node CNI (mode=cilium) is separate — see ebpf-cilium.md. That mode only checks the agent socket; FluxVM never writes foreign private BPF maps.

Production runbook: production-dataplane.md. Security groups: network-groups.md.

Mapped features​

ConceptFluxVM
Numeric identities (reserved:world=2, local ≥256)identity.rs + group FNV ≥ 0x10000
endpointSelector.matchLabelsGroup labels app=web
CNP document (kind NetworkPolicy / CNP JSON)POST /v1/network/cnp, fluxvm cnp apply
toCIDR / toCIDRSet / exceptallow_cidrs / deny_cidrs
toEntities world/host/cluster/remote-nodeEntity → CIDR expansion
toFQDNsResolve to IPv4/32 + IPv6/128 at apply; wildcards skipped
toPorts + ranges + named portstcp/443, tcp/8000-8003, https→443
egressDeny / ingressDenyfluxvm_deny4/6 before allow
enableDefaultDenydefault_allow=false
auditModesample_rate bit 31; log drop, forward packet
Conntrackfluxvm_ct LRU learn/hit
Identity listGET /v1/network/identities, fluxctl identity list
Group / identity policyfluxvm_gid written at configure_maps
Observe snapshotGET /v1/network/observe, fluxctl observe
toFQDNs live refreshPOST /v1/network/refresh-dns, fluxvm dataplane refresh-dns (best-effort fleet-wide; skipped VMs logged, call returns refreshed count)
ipcacheGuest IP → identity (GET /v1/network/ipcache)
Production healthfluxvm dataplane health, production-dataplane.md

Not in scope for this policy plane: kube-proxy replacement, WireGuard/IPsec datapath, L7 Envoy/Kafka parsers, ClusterMesh, or a full flow UI.

Maglev / DSR / SNAT service LB lives in Service Fabric v6 (BPF schema 4 / program generation 6) — service-fabric.md. Per-VM Network Fabric policy (this doc) is orthogonal. (service-fabric.md), not in CNP/group compilers.

Apply a CNP​

fluxvm cnp apply --spec examples/cnp-web.json
fluxvm cnp list
fluxctl identity list
fluxctl observe

Label the VM policy so the compiled group matches:

{ "labels": ["app=web"], "default_allow": false }

Tutorials​

Hands-on Network Fabric policy guides:

docs/tutorials/network-policy/ — getting started, identities, security groups, CNP, default deny, named ports, entities/FQDNs, audit mode, observe, multi-group merge.

Tests​

python3 scripts/test-network-policy.py
cargo test -p fluxvm-network --lib
python3 scripts/test-production-dataplane.py
sudo -E ./scripts/test-security-groups-e2e.sh
sudo -E ./scripts/test-production-dataplane-e2e.sh