07 — Entities and FQDNs
Goal: Allow egress to Network Fabric entities (world, host,
cluster, …) and record FQDN allow rules the same way a CNP would.
Entities
toEntities expands through identity::entity_cidrs
into concrete CIDRs folded into the group allowlist.
sudo fluxctl --config /etc/fluxvm.toml cnp apply \
--spec examples/cnp/cnp-entities-world.json
sudo fluxctl --config /etc/fluxvm.toml group get talk-to-world | python3 -m json.tool
Expect: allow_cidrs includes entity expansions (for example
0.0.0.0/0 / ::/0 for world, depending on the mapping), plus any
explicit toCIDR entries.
List the reserved identity table that backs entity names:
sudo fluxctl --config /etc/fluxvm.toml identity list \
| python3 -c 'import json,sys;print([i["name"] for i in json.load(sys.stdin)])'
FQDNs
CNP toFQDNs[].matchName is stored on the compiled group as allow_fqdns.
At apply/reconfigure, FluxVM resolves names to IPv4 /32 and IPv6 /128
CIDRs (wildcards with * are skipped). This is not an inline DNS proxy inside
the TC program. After DNS TTL or allowlist changes, refresh:
sudo fluxctl --config /etc/fluxvm.toml dataplane refresh-dns
# or POST /v1/network/refresh-dns
sudo fluxctl --config /etc/fluxvm.toml cnp apply \
--spec examples/cnp-web.json
sudo fluxctl --config /etc/fluxvm.toml group get web-egress \
| python3 -c 'import json,sys;d=json.load(sys.stdin);print(d["policy"].get("allow_fqdns"))'
Expect: ["example.com"] (from the sample CNP).
Pair with sandbox egress domains in config when you want L7 redirect:
[sandbox]
egress_allow_domains = ["example.com", ".github.com"]
Cleanup
sudo fluxctl --config /etc/fluxvm.toml cnp delete talk-to-world
sudo fluxctl --config /etc/fluxvm.toml cnp delete web-egress