Skip to main content

09 — Observe snapshot

Goal: Take a single observe snapshot of identities, groups, CNPs, and labeled VM endpoints — a quick fabric dashboard glance over policy state.

CLI​

sudo fluxctl --config /etc/fluxvm.toml observe | python3 -m json.tool

REST​

curl -s http://127.0.0.1:7788/v1/network/observe | python3 -m json.tool

Shape​

{
"identities": [ { "id": 2, "name": "reserved:world", "reserved": true, "...": "..." } ],
"groups": [ { "name": "web-egress", "identity": 1688068488, "...": "..." } ],
"policies": [ { "metadata": { "name": "web-egress" }, "...": "..." } ],
"endpoints": [
{
"vm_id": "...",
"name": "fluxvm-cnp-e2e",
"status": "Running",
"labels": ["app=web"],
"groups": [],
"identity": 12345
}
]
}

endpoints only lists VMs that already have a persisted network-policy file under $state_dir/network-policy/.

Per-VM flows (deeper than observe)​

curl -s "http://127.0.0.1:7788/v1/vms/${ID}/network/flows?limit=50" | python3 -m json.tool
curl -s "http://127.0.0.1:7788/v1/vms/${ID}/network/stats" | python3 -m json.tool

NDJSON exporter for shipping elsewhere:

python3 scripts/export_network_flows.py --help

Next​