Skip to main content

Network policy tutorials (FluxVM Fabric)

One identity. One policy. At the VM edge.

Short, copy-paste guides for label identities, CNP documents, deny lists, audit mode, and observe โ€” aimed at operators of the VM-edge dataplane.

FluxVM pins programs under /sys/fs/bpf/fluxvm (schema v4). It does not write foreign CNI private maps. For node CNI coexistence (mode=cilium), see ebpf-cilium.md.

TutorialFocusTime
01 โ€” Getting startedEnable Fabric, identities, observe~10 min
02 โ€” IdentitiesReserved + group identity numbers~10 min
03 โ€” Security groupsLabel-based policy~15 min
04 โ€” Network policy (CNP)Apply a CNP JSON~20 min
05 โ€” Default deny + deny CIDRsFail-closed egress~15 min
06 โ€” Named portshttps / dns in toPorts~10 min
07 โ€” Entities and FQDNstoEntities / toFQDNs~15 min
08 โ€” Audit modeLog-and-forward~10 min
09 โ€” ObserveSnapshot identities/groups/CNPs/VMs~10 min
10 โ€” Multi-group mergeUnion / min-rate semantics~15 min

Reference: network-policy.md ยท network-groups.md ยท network-fabric.md ยท production-dataplane.md ยท PRODUCTION.md ยท production readiness tutorials ยท ebpf-cilium.md.

Shared prerequisitesโ€‹

  1. Linux host with KVM, fluxvm installed, and Network Fabric eBPF enabled:
# /etc/fluxvm.toml (excerpt)
[sandbox.dataplane]
mode = "ebpf"
bpf_object = "/usr/lib/fluxvm/bpf/fluxvm_tc.bpf.o"
pin_root = "/sys/fs/bpf/fluxvm"
required = true

Or: sudo ./scripts/enable-network-fabric-ga.sh --restart then install a fresh BPF object from ./scripts/build-ebpf.sh.

  1. Admin CLI access (default API 127.0.0.1:7788):
export FLUXVM_CONFIG=/etc/fluxvm.toml
# Prefer sudo when state_dir is /var/lib/fluxvm (root-owned).
alias fx='sudo fluxctl --config /etc/fluxvm.toml'
  1. Optional: a running FluxVm sandbox with TAP + netns when a live VM is required:
fx create --spec examples/fluxvm.json # adjust image/kernel paths
fx list

CLI cheat sheetโ€‹

TaskCommand
Livenesscurl -sf localhost:7788/healthz
Readinesscurl -sf localhost:7788/readyz
API / VM listcurl -s localhost:7788/v1/vms
Per-VM dataplane statusGET โ€ฆ/v1/vms/{id}/network/status
List identitiesfluxctl identity list
Apply / list CNPfluxvm cnp apply|list|get|delete
Security groupsfluxvm group โ€ฆ
Observe snapshotfluxctl observe
Dataplane healthfluxvm dataplane health
Guest IP โ†’ identityfluxvm dataplane ipcache
Refresh FQDN allowlistfluxvm dataplane refresh-dns
Per-VM flowsGET โ€ฆ/network/flows

Automated checksโ€‹

python3 scripts/test-security-groups.py
python3 scripts/test-network-policy.py
python3 scripts/test-production-dataplane.py
cargo test -p fluxvm-network --lib
sudo -E ./scripts/test-security-groups-e2e.sh
sudo -E ./scripts/test-production-dataplane-e2e.sh