03 — Security groups (label-based policy)
Goal: Define a Network Fabric security group, attach it via labels, and inspect the effective policy.
FluxVM analogue: identity selectors + security groups without writing a full CNP JSON document.
1. Create a group
sudo fluxctl --config /etc/fluxvm.toml group set web \
--label app=web --label env=prod \
--priority 10 \
--description "HTTPS + DNS egress" \
--default-allow false \
--allow-cidr 10.0.0.0/8 \
--allow-cidr 172.16.0.0/12 \
--deny-cidr 10.66.0.0/16 \
--allow-port tcp/443 --allow-port tcp/80 --allow-port udp/53 --allow-port icmp/0 \
--allow-icmp \
--max-egress-mbps 250
Or apply the example JSON via API:
curl -s -X POST http://127.0.0.1:7788/v1/network/groups \
-H 'Content-Type: application/json' \
--data @examples/security-group-web.json | python3 -m json.tool
sudo fluxctl --config /etc/fluxvm.toml group list
sudo fluxctl --config /etc/fluxvm.toml group get web
2. Select the group from a VM
Membership is label subset and/or explicit groups:
curl -s -X POST "http://127.0.0.1:7788/v1/vms/${ID}/network/policy" \
-H 'Content-Type: application/json' \
-d '{
"default_allow": true,
"labels": ["app=web", "env=prod", "tier=front"],
"groups": [],
"allow_cidrs": [],
"allow_ports": [],
"max_egress_mbps": 500
}'
3. Check effective merge
curl -s "http://127.0.0.1:7788/v1/vms/${ID}/network/effective" | python3 -m json.tool
Expect:
membership.matched→webeffective.default_allow→false(group fails closed)effective.allow_cidrsincludes10.0.0.0/8effective.deny_cidrsincludes10.66.0.0/16effective.max_egress_mbps→250(tightest of VM 500 and group 250)effective.allow_icmp→true
4. Named attachment (no labels on the group)
sudo fluxctl --config /etc/fluxvm.toml group set egress-only \
--default-allow false \
--allow-cidr 1.1.1.1/32 \
--deny-cidr 0.0.0.0/0 \
--allow-port udp/53 \
--allow-icmp
curl -s -X POST "http://127.0.0.1:7788/v1/vms/${ID}/network/policy" \
-H 'Content-Type: application/json' \
-d '{"default_allow":true,"groups":["egress-only"],"labels":[],"allow_cidrs":[],"allow_ports":[]}'
Cleanup
sudo fluxctl --config /etc/fluxvm.toml group delete web
sudo fluxctl --config /etc/fluxvm.toml group delete egress-only