09 — Observe snapshot
Goal: Take a single observe snapshot of identities, groups, CNPs, and labeled VM endpoints — a quick fabric dashboard glance over policy state.
CLI
sudo fluxctl --config /etc/fluxvm.toml observe | python3 -m json.tool
REST
curl -s http://127.0.0.1:7788/v1/network/observe | python3 -m json.tool
Shape
{
"identities": [ { "id": 2, "name": "reserved:world", "reserved": true, "...": "..." } ],
"groups": [ { "name": "web-egress", "identity": 1688068488, "...": "..." } ],
"policies": [ { "metadata": { "name": "web-egress" }, "...": "..." } ],
"endpoints": [
{
"vm_id": "...",
"name": "fluxvm-cnp-e2e",
"status": "Running",
"labels": ["app=web"],
"groups": [],
"identity": 12345
}
]
}
endpoints only lists VMs that already have a persisted network-policy
file under $state_dir/network-policy/.
Per-VM flows (deeper than observe)
curl -s "http://127.0.0.1:7788/v1/vms/${ID}/network/flows?limit=50" | python3 -m json.tool
curl -s "http://127.0.0.1:7788/v1/vms/${ID}/network/stats" | python3 -m json.tool
NDJSON exporter for shipping elsewhere:
python3 scripts/export_network_flows.py --help