From: Gabriel Goller <g.goller@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [RFC manager/network/proxmox{-ve-rs,-perl-rs} 00/15] SDN VRF support
Date: Fri, 21 Aug 2026 16:03:44 +0200 [thread overview]
Message-ID: <20260821140404.322081-1-g.goller@proxmox.com> (raw)
This RFC adds VRF support to SDN zones and fabrics.
A simple zone can now use either the default VRF or a dedicated VRF. The
simple zone dialog has a checkbox for this and uses the default VRF by
default. If the checkbox is disabled, the zone creates a dedicated VRF named
`vrf_<zone-name>`. EVPN zones always create a dedicated VRF. BGP and OSPF
fabrics can select a zone and run inside its VRF.
This is the second iteration. The first iteration added VRFs as a separate
SDN object with a distinct GUI subdirectory. This was scrapped because VRFs
are an implementation detail and should not be exposed on their own in the
GUI. Zones already provide a logical L3 building block and should map to VRFs
instead.
Route leaking between VRFs partly depends on the following FRR change, so it
will come a bit later: https://github.com/FRRouting/frr/pull/22426
As always, thanks to Stefan Hanreich for his help.
proxmox-ve-rs:
Gabriel Goller (5):
frr: add VRF-aware OSPF rendering
sdn: add zone references to OSPF and BGP fabrics
sdn: generate fabric routing configuration in zone VRFs
sdn: fix VRF route-map scoping and zone ID validation
tests: fabrics: add test for fabrics in VRFs
proxmox-frr-templates/templates/fabricd.jinja | 2 +-
.../templates/interface.jinja | 6 +-
proxmox-frr-templates/templates/isisd.jinja | 2 +-
proxmox-frr-templates/templates/ospfd.jinja | 12 +-
.../templates/protocol_routemaps.jinja | 13 ++
proxmox-frr/debian/control | 8 +-
proxmox-frr/src/ser/mod.rs | 8 +
proxmox-ve-config/src/sdn/fabric/frr.rs | 137 ++++++++----
proxmox-ve-config/src/sdn/fabric/mod.rs | 30 ++-
.../src/sdn/fabric/section_config/fabric.rs | 26 ++-
.../sdn/fabric/section_config/protocol/bgp.rs | 11 +-
.../fabric/section_config/protocol/ospf.rs | 11 +-
.../tests/fabric/cfg/vrf/fabrics.cfg | 43 ++++
.../tests/fabric/cfg/vrf/route-maps.cfg | 15 ++
proxmox-ve-config/tests/fabric/helper.rs | 20 ++
proxmox-ve-config/tests/fabric/main.rs | 207 +++++++++++++++++-
.../fabric/snapshots/fabric__vrf_pve.snap | 134 ++++++++++++
17 files changed, 627 insertions(+), 58 deletions(-)
create mode 100644 proxmox-ve-config/tests/fabric/cfg/vrf/fabrics.cfg
create mode 100644 proxmox-ve-config/tests/fabric/cfg/vrf/route-maps.cfg
create mode 100644 proxmox-ve-config/tests/fabric/snapshots/fabric__vrf_pve.snap
proxmox-perl-rs:
Gabriel Goller (3):
pve-rs: fabrics: assign network interfaces to configured VRFs
pve-rs: fabrics: make per-fabric status queries VRF-aware
pve-rs: fabrics: include VRF routes in aggregate status
pve-rs/src/bindings/sdn/fabrics.rs | 301 +++++++++++++++++++----------
pve-rs/src/sdn/status.rs | 19 +-
2 files changed, 207 insertions(+), 113 deletions(-)
pve-network:
Gabriel Goller (5):
sdn: add optional VRFs for simple zones
sdn: allow fabrics to use simple zone VRFs
sdn: always generate EVPN zone VRFs
api: sdn: allow EVPN zones as fabric VRFs
api: sdn: disallow BGP fabrics in EVPN zone VRFs
src/PVE/API2/Network/SDN/Fabrics/Fabric.pm | 50 ++++++++++++++++---
.../API2/Network/SDN/Fabrics/FabricNode.pm | 18 +++++++
src/PVE/API2/Network/SDN/Zones.pm | 33 ++++++++++++
src/PVE/Network/SDN/Controllers/BgpPlugin.pm | 2 +-
src/PVE/Network/SDN/Fabrics.pm | 29 ++++++++++-
src/PVE/Network/SDN/Zones.pm | 17 +++++--
src/PVE/Network/SDN/Zones/EvpnPlugin.pm | 35 +++++++------
src/PVE/Network/SDN/Zones/Plugin.pm | 6 +++
src/PVE/Network/SDN/Zones/SimplePlugin.pm | 20 +++++++-
.../evpn/vrf-empty/expected_sdn_interfaces | 6 +++
src/test/zones/evpn/vrf-empty/interfaces | 2 +
src/test/zones/evpn/vrf-empty/sdn_config | 13 +++++
.../simple/vrf-empty/expected_sdn_interfaces | 5 ++
src/test/zones/simple/vrf-empty/interfaces | 2 +
src/test/zones/simple/vrf-empty/sdn_config | 12 +++++
.../zones/simple/vrf/expected_sdn_interfaces | 12 +++++
src/test/zones/simple/vrf/interfaces | 2 +
src/test/zones/simple/vrf/sdn_config | 17 +++++++
18 files changed, 253 insertions(+), 28 deletions(-)
create mode 100644 src/test/zones/evpn/vrf-empty/expected_sdn_interfaces
create mode 100644 src/test/zones/evpn/vrf-empty/interfaces
create mode 100644 src/test/zones/evpn/vrf-empty/sdn_config
create mode 100644 src/test/zones/simple/vrf-empty/expected_sdn_interfaces
create mode 100644 src/test/zones/simple/vrf-empty/interfaces
create mode 100644 src/test/zones/simple/vrf-empty/sdn_config
create mode 100644 src/test/zones/simple/vrf/expected_sdn_interfaces
create mode 100644 src/test/zones/simple/vrf/interfaces
create mode 100644 src/test/zones/simple/vrf/sdn_config
pve-manager:
Gabriel Goller (2):
ui: sdn: add VRF zone selection for fabrics
ui: sdn: expose EVPN zones as fabric VRFs
www/manager6/form/SDNZoneSelector.js | 16 +++++++++++++++-
www/manager6/sdn/fabrics/FabricEdit.js | 18 ++++++++++++++++++
www/manager6/sdn/zones/SimpleEdit.js | 12 +++++++++++-
3 files changed, 44 insertions(+), 2 deletions(-)
Summary over all repositories:
40 files changed, 1131 insertions(+), 201 deletions(-)
--
Generated by murpp 0.11.0
next reply other threads:[~2026-08-21 14:04 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-21 14:03 Gabriel Goller [this message]
2026-08-21 14:03 ` [PATCH proxmox-ve-rs 01/15] frr: add VRF-aware OSPF rendering Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-ve-rs 02/15] sdn: add zone references to OSPF and BGP fabrics Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-ve-rs 03/15] sdn: generate fabric routing configuration in zone VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-ve-rs 04/15] sdn: fix VRF route-map scoping and zone ID validation Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-ve-rs 05/15] tests: fabrics: add test for fabrics in VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-perl-rs 06/15] pve-rs: fabrics: assign network interfaces to configured VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-perl-rs 07/15] pve-rs: fabrics: make per-fabric status queries VRF-aware Gabriel Goller
2026-08-21 14:03 ` [PATCH proxmox-perl-rs 08/15] pve-rs: fabrics: include VRF routes in aggregate status Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-network 09/15] sdn: add optional VRFs for simple zones Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-network 10/15] sdn: allow fabrics to use simple zone VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-network 11/15] sdn: always generate EVPN " Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-network 12/15] api: sdn: allow EVPN zones as fabric VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-network 13/15] api: sdn: disallow BGP fabrics in EVPN zone VRFs Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-manager 14/15] ui: sdn: add VRF zone selection for fabrics Gabriel Goller
2026-08-21 14:03 ` [PATCH pve-manager 15/15] ui: sdn: expose EVPN zones as fabric VRFs Gabriel Goller
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260821140404.322081-1-g.goller@proxmox.com \
--to=g.goller@proxmox.com \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox