all lists on lists.proxmox.com
 help / color / mirror / Atom feed
From: Gabriel Goller <g.goller@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [RFC manager/network/proxmox{-ve-rs,-perl-rs} 00/15] SDN VRF support
Date: Fri, 21 Aug 2026 16:03:44 +0200	[thread overview]
Message-ID: <20260821140404.322081-1-g.goller@proxmox.com> (raw)

This RFC adds VRF support to SDN zones and fabrics.

A simple zone can now use either the default VRF or a dedicated VRF. The
simple zone dialog has a checkbox for this and uses the default VRF by
default. If the checkbox is disabled, the zone creates a dedicated VRF named
`vrf_<zone-name>`. EVPN zones always create a dedicated VRF. BGP and OSPF
fabrics can select a zone and run inside its VRF.

This is the second iteration. The first iteration added VRFs as a separate
SDN object with a distinct GUI subdirectory. This was scrapped because VRFs
are an implementation detail and should not be exposed on their own in the
GUI. Zones already provide a logical L3 building block and should map to VRFs
instead.

Route leaking between VRFs partly depends on the following FRR change, so it
will come a bit later: https://github.com/FRRouting/frr/pull/22426

As always, thanks to Stefan Hanreich for his help.


proxmox-ve-rs:

Gabriel Goller (5):
  frr: add VRF-aware OSPF rendering
  sdn: add zone references to OSPF and BGP fabrics
  sdn: generate fabric routing configuration in zone VRFs
  sdn: fix VRF route-map scoping and zone ID validation
  tests: fabrics: add test for fabrics in VRFs

 proxmox-frr-templates/templates/fabricd.jinja |   2 +-
 .../templates/interface.jinja                 |   6 +-
 proxmox-frr-templates/templates/isisd.jinja   |   2 +-
 proxmox-frr-templates/templates/ospfd.jinja   |  12 +-
 .../templates/protocol_routemaps.jinja        |  13 ++
 proxmox-frr/debian/control                    |   8 +-
 proxmox-frr/src/ser/mod.rs                    |   8 +
 proxmox-ve-config/src/sdn/fabric/frr.rs       | 137 ++++++++----
 proxmox-ve-config/src/sdn/fabric/mod.rs       |  30 ++-
 .../src/sdn/fabric/section_config/fabric.rs   |  26 ++-
 .../sdn/fabric/section_config/protocol/bgp.rs |  11 +-
 .../fabric/section_config/protocol/ospf.rs    |  11 +-
 .../tests/fabric/cfg/vrf/fabrics.cfg          |  43 ++++
 .../tests/fabric/cfg/vrf/route-maps.cfg       |  15 ++
 proxmox-ve-config/tests/fabric/helper.rs      |  20 ++
 proxmox-ve-config/tests/fabric/main.rs        | 207 +++++++++++++++++-
 .../fabric/snapshots/fabric__vrf_pve.snap     | 134 ++++++++++++
 17 files changed, 627 insertions(+), 58 deletions(-)
 create mode 100644 proxmox-ve-config/tests/fabric/cfg/vrf/fabrics.cfg
 create mode 100644 proxmox-ve-config/tests/fabric/cfg/vrf/route-maps.cfg
 create mode 100644 proxmox-ve-config/tests/fabric/snapshots/fabric__vrf_pve.snap


proxmox-perl-rs:

Gabriel Goller (3):
  pve-rs: fabrics: assign network interfaces to configured VRFs
  pve-rs: fabrics: make per-fabric status queries VRF-aware
  pve-rs: fabrics: include VRF routes in aggregate status

 pve-rs/src/bindings/sdn/fabrics.rs | 301 +++++++++++++++++++----------
 pve-rs/src/sdn/status.rs           |  19 +-
 2 files changed, 207 insertions(+), 113 deletions(-)


pve-network:

Gabriel Goller (5):
  sdn: add optional VRFs for simple zones
  sdn: allow fabrics to use simple zone VRFs
  sdn: always generate EVPN zone VRFs
  api: sdn: allow EVPN zones as fabric VRFs
  api: sdn: disallow BGP fabrics in EVPN zone VRFs

 src/PVE/API2/Network/SDN/Fabrics/Fabric.pm    | 50 ++++++++++++++++---
 .../API2/Network/SDN/Fabrics/FabricNode.pm    | 18 +++++++
 src/PVE/API2/Network/SDN/Zones.pm             | 33 ++++++++++++
 src/PVE/Network/SDN/Controllers/BgpPlugin.pm  |  2 +-
 src/PVE/Network/SDN/Fabrics.pm                | 29 ++++++++++-
 src/PVE/Network/SDN/Zones.pm                  | 17 +++++--
 src/PVE/Network/SDN/Zones/EvpnPlugin.pm       | 35 +++++++------
 src/PVE/Network/SDN/Zones/Plugin.pm           |  6 +++
 src/PVE/Network/SDN/Zones/SimplePlugin.pm     | 20 +++++++-
 .../evpn/vrf-empty/expected_sdn_interfaces    |  6 +++
 src/test/zones/evpn/vrf-empty/interfaces      |  2 +
 src/test/zones/evpn/vrf-empty/sdn_config      | 13 +++++
 .../simple/vrf-empty/expected_sdn_interfaces  |  5 ++
 src/test/zones/simple/vrf-empty/interfaces    |  2 +
 src/test/zones/simple/vrf-empty/sdn_config    | 12 +++++
 .../zones/simple/vrf/expected_sdn_interfaces  | 12 +++++
 src/test/zones/simple/vrf/interfaces          |  2 +
 src/test/zones/simple/vrf/sdn_config          | 17 +++++++
 18 files changed, 253 insertions(+), 28 deletions(-)
 create mode 100644 src/test/zones/evpn/vrf-empty/expected_sdn_interfaces
 create mode 100644 src/test/zones/evpn/vrf-empty/interfaces
 create mode 100644 src/test/zones/evpn/vrf-empty/sdn_config
 create mode 100644 src/test/zones/simple/vrf-empty/expected_sdn_interfaces
 create mode 100644 src/test/zones/simple/vrf-empty/interfaces
 create mode 100644 src/test/zones/simple/vrf-empty/sdn_config
 create mode 100644 src/test/zones/simple/vrf/expected_sdn_interfaces
 create mode 100644 src/test/zones/simple/vrf/interfaces
 create mode 100644 src/test/zones/simple/vrf/sdn_config


pve-manager:

Gabriel Goller (2):
  ui: sdn: add VRF zone selection for fabrics
  ui: sdn: expose EVPN zones as fabric VRFs

 www/manager6/form/SDNZoneSelector.js   | 16 +++++++++++++++-
 www/manager6/sdn/fabrics/FabricEdit.js | 18 ++++++++++++++++++
 www/manager6/sdn/zones/SimpleEdit.js   | 12 +++++++++++-
 3 files changed, 44 insertions(+), 2 deletions(-)


Summary over all repositories:
  40 files changed, 1131 insertions(+), 201 deletions(-)

-- 
Generated by murpp 0.11.0




             reply	other threads:[~2026-08-21 14:04 UTC|newest]

Thread overview: 16+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-21 14:03 Gabriel Goller [this message]
2026-08-21 14:03 ` [PATCH proxmox-ve-rs 01/15] frr: add VRF-aware OSPF rendering Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-ve-rs 02/15] sdn: add zone references to OSPF and BGP fabrics Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-ve-rs 03/15] sdn: generate fabric routing configuration in zone VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-ve-rs 04/15] sdn: fix VRF route-map scoping and zone ID validation Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-ve-rs 05/15] tests: fabrics: add test for fabrics in VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-perl-rs 06/15] pve-rs: fabrics: assign network interfaces to configured VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-perl-rs 07/15] pve-rs: fabrics: make per-fabric status queries VRF-aware Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-perl-rs 08/15] pve-rs: fabrics: include VRF routes in aggregate status Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-network 09/15] sdn: add optional VRFs for simple zones Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-network 10/15] sdn: allow fabrics to use simple zone VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-network 11/15] sdn: always generate EVPN " Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-network 12/15] api: sdn: allow EVPN zones as fabric VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-network 13/15] api: sdn: disallow BGP fabrics in EVPN zone VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-manager 14/15] ui: sdn: add VRF zone selection for fabrics Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-manager 15/15] ui: sdn: expose EVPN zones as fabric VRFs Gabriel Goller

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260821140404.322081-1-g.goller@proxmox.com \
    --to=g.goller@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal