Network policy tutorials (FluxVM Fabric)
One identity. One policy. At the VM edge.
Short, copy-paste guides for label identities, CNP documents, deny lists, audit mode, and observe โ aimed at operators of the VM-edge dataplane.
FluxVM pins programs under /sys/fs/bpf/fluxvm (schema v4). It does not
write foreign CNI private maps. For node CNI coexistence (mode=cilium), see
ebpf-cilium.md.
| Tutorial | Focus | Time |
|---|---|---|
| 01 โ Getting started | Enable Fabric, identities, observe | ~10 min |
| 02 โ Identities | Reserved + group identity numbers | ~10 min |
| 03 โ Security groups | Label-based policy | ~15 min |
| 04 โ Network policy (CNP) | Apply a CNP JSON | ~20 min |
| 05 โ Default deny + deny CIDRs | Fail-closed egress | ~15 min |
| 06 โ Named ports | https / dns in toPorts | ~10 min |
| 07 โ Entities and FQDNs | toEntities / toFQDNs | ~15 min |
| 08 โ Audit mode | Log-and-forward | ~10 min |
| 09 โ Observe | Snapshot identities/groups/CNPs/VMs | ~10 min |
| 10 โ Multi-group merge | Union / min-rate semantics | ~15 min |
Reference: network-policy.md ยท network-groups.md ยท network-fabric.md ยท production-dataplane.md ยท PRODUCTION.md ยท production readiness tutorials ยท ebpf-cilium.md.
Shared prerequisitesโ
- Linux host with KVM,
fluxvminstalled, and Network Fabric eBPF enabled:
# /etc/fluxvm.toml (excerpt)
[sandbox.dataplane]
mode = "ebpf"
bpf_object = "/usr/lib/fluxvm/bpf/fluxvm_tc.bpf.o"
pin_root = "/sys/fs/bpf/fluxvm"
required = true
Or: sudo ./scripts/enable-network-fabric-ga.sh --restart then install a
fresh BPF object from ./scripts/build-ebpf.sh.
- Admin CLI access (default API
127.0.0.1:7788):
export FLUXVM_CONFIG=/etc/fluxvm.toml
# Prefer sudo when state_dir is /var/lib/fluxvm (root-owned).
alias fx='sudo fluxctl --config /etc/fluxvm.toml'
- Optional: a running FluxVm sandbox with TAP + netns when a live VM is required:
fx create --spec examples/fluxvm.json # adjust image/kernel paths
fx list
CLI cheat sheetโ
| Task | Command |
|---|---|
| Liveness | curl -sf localhost:7788/healthz |
| Readiness | curl -sf localhost:7788/readyz |
| API / VM list | curl -s localhost:7788/v1/vms |
| Per-VM dataplane status | GET โฆ/v1/vms/{id}/network/status |
| List identities | fluxctl identity list |
| Apply / list CNP | fluxvm cnp apply|list|get|delete |
| Security groups | fluxvm group โฆ |
| Observe snapshot | fluxctl observe |
| Dataplane health | fluxvm dataplane health |
| Guest IP โ identity | fluxvm dataplane ipcache |
| Refresh FQDN allowlist | fluxvm dataplane refresh-dns |
| Per-VM flows | GET โฆ/network/flows |
Automated checksโ
python3 scripts/test-security-groups.py
python3 scripts/test-network-policy.py
python3 scripts/test-production-dataplane.py
cargo test -p fluxvm-network --lib
sudo -E ./scripts/test-security-groups-e2e.sh
sudo -E ./scripts/test-production-dataplane-e2e.sh