Service Fabric tutorial (FluxVM)
A Maglev VIP on one FluxVM host.
Stand up a Maglev VIP on a single FluxVM host โ schema 4 ABI / program generation 6 (Service Fabric v6).
Level: Intermediate ยท Time: ~30 minutes
Prerequisites: Getting started, eBPF
dataplane enabled, bridged/tap VM or north-south uplink configured.
Operator reference: service-fabric.md ยท Fabric fan-out: ebpf-service-fabric.md.
What you will learnโ
- Confirm Service Fabric host status (
schema_version) - Upsert an east-west Maglev service
- Run health reconcile and inspect ads/flows
- (Optional) Apply an identity policy (v6)
Setupโ
export API=http://127.0.0.1:7788
export AUTH=(-H "Authorization: Bearer $TOKEN" -H "Content-Type: application/json")
# /etc/fluxvm.toml needs [sandbox.dataplane] mode = "ebpf"
# and [sandbox.dataplane.service] as required for your exposure mode
curl -sf "$API/readyz" | jq .
1. Host statusโ
curl -sf "${AUTH[@]}" "$API/v1/network/services/status" | jq '{
schema_version, program_generation, interfaces, xdp
}'
Expect BPF schema 4. Program generation 6 after a v6-capable build.
2. Upsert Maglev serviceโ
curl -sf "${AUTH[@]}" -d @docs/examples/service-fabric-v4-east-west.json \
"$API/v1/network/services" | jq .
curl -sf "${AUTH[@]}" "$API/v1/network/services" | jq .
Backend JSON uses "address" (not "ip"). States: ready / draining /
unhealthy.
3. Health and advertisementsโ
curl -sf -X POST "${AUTH[@]}" "$API/v1/network/services/health/reconcile" | jq .
curl -sf "${AUTH[@]}" "$API/v1/network/services/health" | jq .
curl -sf "${AUTH[@]}" "$API/v1/network/services/advertisements" | jq .
North-south ads need north_south_interfaces and matching exposure.
4. Identity policy (v6)โ
curl -sf "${AUTH[@]}" -d @examples/service-fabric-v6/identity-policy.json \
"$API/v1/network/services/policies" | jq .
curl -sf "${AUTH[@]}" "$API/v1/network/services/policies" | jq .
curl -sf -X POST "${AUTH[@]}" "$API/v1/network/services/policies/reconcile" | jq .
Policy fields: service, default_action, allow_identities,
deny_identities, audit_only, optional l7.
5. Cleanupโ
NAME=payments # or whatever the example used
curl -sf -X DELETE "${AUTH[@]}" "$API/v1/network/services/$NAME/policy"
curl -sf -X DELETE "${AUTH[@]}" "$API/v1/network/services/$NAME"
Nextโ
- service-fabric-phase6.md โ shipped vs remaining
- Network policy tutorials โ orthogonal per-VM edge
- Fabric: Edge Dataplane โ Services +
zyvorctl dataplane service โฆ