From: Stefan Hanreich <s.hanreich@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [PATCH pve-network v5 30/46] evpn controller: add route_map_{in,out} parameter
Date: Tue, 5 May 2026 17:36:58 +0200 [thread overview]
Message-ID: <20260505153720.412180-31-s.hanreich@proxmox.com> (raw)
In-Reply-To: <20260505153720.412180-1-s.hanreich@proxmox.com>
This parameter allows extending the default MAP_VTEP_{IN,OUT} route
maps by specifying a custom route map configured in route-maps.cfg.
This can be used for filtering incoming and outgoing routes, e.g. for
only advertising type-5 routes to external peers or only allow
importing routes with specific route targets.
The old default route maps are kept around in order to support the
exit nodes directive of the EVPN zone. They're still used for
filtering the default routes from other exit nodes and for setting the
metric of non-primary default routes. If a route map override is
configured, an additional call action gets inserted into the
auto-generated route map that jumps into the user-supplied route map,
after the entries handling the default routes are created.
Signed-off-by: Stefan Hanreich <s.hanreich@proxmox.com>
---
.../Network/SDN/RouteMaps/RouteMapEntry.pm | 6 ++++
src/PVE/Network/SDN/Controllers/EvpnPlugin.pm | 30 ++++++++++++++++---
src/PVE/Network/SDN/Controllers/Plugin.pm | 14 +++++++++
src/PVE/Network/SDN/RouteMaps.pm | 20 +++++++++++++
4 files changed, 66 insertions(+), 4 deletions(-)
diff --git a/src/PVE/API2/Network/SDN/RouteMaps/RouteMapEntry.pm b/src/PVE/API2/Network/SDN/RouteMaps/RouteMapEntry.pm
index 6cede04..f53cfad 100644
--- a/src/PVE/API2/Network/SDN/RouteMaps/RouteMapEntry.pm
+++ b/src/PVE/API2/Network/SDN/RouteMaps/RouteMapEntry.pm
@@ -5,6 +5,7 @@ use warnings;
use PVE::Exception qw(raise_param_exc);
use PVE::JSONSchema qw(get_standard_option);
+use PVE::Network::SDN::RouteMaps;
use PVE::Tools qw(extract_param);
use PVE::RESTHandler;
@@ -126,6 +127,11 @@ __PACKAGE__->register_method({
my $order = extract_param($param, 'order');
$config->delete($route_map_id, $order);
+
+ my $remaining_entries = $config->list_route_map($route_map_id);
+ PVE::Network::SDN::RouteMaps::check_references($route_map_id)
+ if !$remaining_entries->%*;
+
PVE::Network::SDN::RouteMaps::write_config($config);
},
"deleting route map entry failed",
diff --git a/src/PVE/Network/SDN/Controllers/EvpnPlugin.pm b/src/PVE/Network/SDN/Controllers/EvpnPlugin.pm
index 54a2227..f5c0bbb 100644
--- a/src/PVE/Network/SDN/Controllers/EvpnPlugin.pm
+++ b/src/PVE/Network/SDN/Controllers/EvpnPlugin.pm
@@ -45,6 +45,8 @@ sub options {
'asn' => { optional => 0 },
'peers' => { optional => 1 },
'fabric' => { optional => 1 },
+ 'route-map-in' => { optional => 1 },
+ 'route-map-out' => { optional => 1 },
};
}
@@ -165,11 +167,19 @@ sub generate_frr_config {
$bgp_router->{address_families}->{l2vpn_evpn}->{autort_as} = $autortas if $autortas;
- my $routemap_in = { seq => 1, action => "permit" };
- my $routemap_out = { seq => 1, action => "permit" };
+ if (!$config->{frr}->{routemaps}->{'MAP_VTEP_IN'}) {
+ my $entry = { seq => 1, action => "permit" };
+ $entry->{call} = $plugin_config->{'route-map-in'} if $plugin_config->{'route-map-in'};
- push($config->{frr}->{routemaps}->{'MAP_VTEP_IN'}->@*, $routemap_in);
- push($config->{frr}->{routemaps}->{'MAP_VTEP_OUT'}->@*, $routemap_out);
+ push($config->{frr}->{routemaps}->{'MAP_VTEP_IN'}->@*, $entry);
+ }
+
+ if (!$config->{frr}->{routemaps}->{'MAP_VTEP_OUT'}) {
+ my $entry = { seq => 1, action => "permit" };
+ $entry->{call} = $plugin_config->{'route-map-out'} if $plugin_config->{'route-map-out'};
+
+ push($config->{frr}->{routemaps}->{'MAP_VTEP_OUT'}->@*, $entry);
+ }
return $config;
}
@@ -488,6 +498,18 @@ sub on_update_hook {
}
my $controller = $controller_cfg->{ids}->{$controllerid};
+ my $route_map_config = PVE::Network::SDN::RouteMaps::config(0);
+
+ if ($controller->{'route-map-in'}) {
+ my $entries = $route_map_config->list_route_map($controller->{'route-map-in'});
+ die "route map $controller->{'route-map-in'} does not exist!" if !$entries->%*;
+ }
+
+ if ($controller->{'route-map-out'}) {
+ my $entries = $route_map_config->list_route_map($controller->{'route-map-out'});
+ die "route map $controller->{'route-map-out'} does not exist!" if !$entries->%*;
+ }
+
if ($controller->{type} eq 'evpn') {
die "must have exactly one of peers / fabric defined"
if ($controller->{peers} && $controller->{fabric})
diff --git a/src/PVE/Network/SDN/Controllers/Plugin.pm b/src/PVE/Network/SDN/Controllers/Plugin.pm
index 77d8f42..1068b5d 100644
--- a/src/PVE/Network/SDN/Controllers/Plugin.pm
+++ b/src/PVE/Network/SDN/Controllers/Plugin.pm
@@ -7,6 +7,8 @@ use PVE::Tools;
use PVE::JSONSchema;
use PVE::Cluster;
+use PVE::Network::SDN::RouteMaps;
+
use PVE::JSONSchema qw(get_standard_option);
use base qw(PVE::SectionConfig);
@@ -40,6 +42,18 @@ my $defaultData = {
'pve-sdn-controller-id',
{ completion => \&PVE::Network::SDN::complete_sdn_controller },
),
+ 'route-map-in' => {
+ description => "Route Map that should be applied for incoming routes",
+ type => 'string',
+ format => 'pve-sdn-route-map-id',
+ optional => 1,
+ },
+ 'route-map-out' => {
+ description => "Route Map that should be applied for outgoing routes",
+ type => 'string',
+ format => 'pve-sdn-route-map-id',
+ optional => 1,
+ },
},
};
diff --git a/src/PVE/Network/SDN/RouteMaps.pm b/src/PVE/Network/SDN/RouteMaps.pm
index 9e44546..5560f18 100644
--- a/src/PVE/Network/SDN/RouteMaps.pm
+++ b/src/PVE/Network/SDN/RouteMaps.pm
@@ -107,6 +107,26 @@ sub write_config {
cfs_write_file("sdn/route-maps.cfg", $config->to_raw(), 1);
}
+sub check_references {
+ my ($route_map_id) = @_;
+
+ my $controller_config = PVE::Network::SDN::Controllers::config();
+
+ for my $controller_id (keys $controller_config->{ids}->%*) {
+ my $controller = $controller_config->{ids}->{$controller_id};
+
+ if ($controller->{'route-map-in'}) {
+ die "route map $route_map_id still referenced by controller $controller_id"
+ if $controller->{'route-map-in'} eq $route_map_id;
+ }
+
+ if ($controller->{'route-map-out'}) {
+ die "route map $route_map_id still referenced by controller $controller_id"
+ if $controller->{'route-map-out'} eq $route_map_id;
+ }
+ }
+}
+
sub route_map_properties {
my ($update) = @_;
--
2.47.3
next prev parent reply other threads:[~2026-05-05 15:42 UTC|newest]
Thread overview: 47+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-05 15:36 [PATCH access-control/cluster/manager/network/proxmox{-ve-rs,-perl-rs} v5 00/46] Add support for route maps / prefix lists to SDN Stefan Hanreich
2026-05-05 15:36 ` [PATCH pve-cluster v5 01/46] cfs: add 'sdn/route-maps.cfg' to observed files Stefan Hanreich
2026-05-05 15:36 ` [PATCH pve-cluster v5 02/46] cfs: add 'sdn/prefix-lists.cfg' " Stefan Hanreich
2026-05-05 15:36 ` [PATCH pve-access-control v5 03/46] permissions: add ACL path for prefix-lists and route-maps Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 04/46] frr: add constructor to prefix list name Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 05/46] sdn-types: add common route-map helper types Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 06/46] frr: change order type to u16 Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 07/46] frr: implement routemap match/set statements via adjacent tagging Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 08/46] frr: implement support for call and exit action Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 09/46] frr-templates: change route maps template to adapt to new frr types Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 10/46] ve-config: fabrics: adapt frr config generation Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 11/46] ve-config: add prefix list section config Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 12/46] ve-config: frr: implement frr config generation for prefix lists Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 13/46] ve-config: add route map section config Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 14/46] ve-config: frr: implement frr config generation for route maps Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 15/46] ve-config: add prefix lists integration tests Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 16/46] ve-config: add route maps " Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 17/46] fabrics: ospf: fix deserializing OspfDeletableProperties Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 18/46] fabrics: ospf: openfabric: allow user-defined route filter Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-ve-rs v5 19/46] frr: fabrics: apply route_filter setting Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-perl-rs v5 20/46] pve-rs: sdn: add route maps module Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-perl-rs v5 21/46] pve-rs: sdn: add prefix lists module Stefan Hanreich
2026-05-05 15:36 ` [PATCH proxmox-perl-rs v5 22/46] sdn: add prefix list / route maps to frr config generation helper Stefan Hanreich
2026-05-05 15:36 ` [PATCH pve-network v5 23/46] controller: bgp: evpn: adapt to new match / set frr config syntax Stefan Hanreich
2026-05-05 15:36 ` [PATCH pve-network v5 24/46] sdn: add prefix lists module Stefan Hanreich
2026-05-05 15:36 ` [PATCH pve-network v5 25/46] sdn: add route map module Stefan Hanreich
2026-05-05 15:36 ` [PATCH pve-network v5 26/46] api2: add prefix list module Stefan Hanreich
2026-05-05 15:36 ` [PATCH pve-network v5 27/46] api2: add route maps module Stefan Hanreich
2026-05-05 15:36 ` [PATCH pve-network v5 28/46] api2: add route map module Stefan Hanreich
2026-05-05 15:36 ` [PATCH pve-network v5 29/46] api2: add route map entry module Stefan Hanreich
2026-05-05 15:36 ` Stefan Hanreich [this message]
2026-05-05 15:36 ` [PATCH pve-network v5 31/46] bgp controller: allow configuring custom route maps Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-network v5 32/46] sdn: commit route map / prefix list configuration on sdn apply Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-network v5 33/46] sdn: frr: consider route maps and prefix lists in dry-run Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-network v5 34/46] fabrics: ospf: openfabric: add route_filter property Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-network v5 35/46] tests: add simple route map test case Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-network v5 36/46] tests: add bgp evpn route map/prefix list testcase Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-network v5 37/46] tests: add route map with prefix " Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-network v5 38/46] tests: add exit node with custom route map testcase Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-manager v5 39/46] ui: sdn: add route map selector Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-manager v5 40/46] ui: sdn: add prefix list selector Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-manager v5 41/46] ui: sdn: add panel for managing prefix lists Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-manager v5 42/46] ui: sdn: add panel for managing route map entries Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-manager v5 43/46] ui: sdn: bgp controller: allow configuring route maps Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-manager v5 44/46] ui: sdn: evpn " Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-manager v5 45/46] ui: sdn: openfabric: add route filter Stefan Hanreich
2026-05-05 15:37 ` [PATCH pve-manager v5 46/46] ui: sdn: ospf: add route filter setting Stefan Hanreich
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260505153720.412180-31-s.hanreich@proxmox.com \
--to=s.hanreich@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox