Direct networking - #1
Merged
Merged
Conversation
Adds RunDirect — a per-VM kernel netns mode that lives next to the existing
pasta-based Run. The motivating use case is supervisors that already run
inside a user namespace (e.g. Kubernetes pods) where pasta's user+netns
breaks KVM_CREATE_VM. RunDirect nsenter's firecracker into a fresh kernel
netns and manages two nft tables: knaller_box_nat (per-netns, in/out NAT to
the guest IP) and knaller_host (shared, host-side DNAT for inbound SSH +
masquerade outbound + a default-deny egress filter that lets guests reach
the internet but blocks the host's RFC1918 neighbours).
Other generally-useful primitives extracted from the same redesign:
* Config.RawDiskPath: hand a pre-attached block device to firecracker as
rootfs, skipping the per-VM cp+resize. Caller owns the disk lifecycle;
knaller does not touch it on Cleanup.
* Config.RootFSSize: grow the per-VM rootfs (truncate + e2fsck +
resize2fs) when bigger than the source image. Sparse.
* Config.Netns: pin the netns name (defaults derive from cfg.Name).
* Config.EscapeCgroupSlice: opt-in cgroupv2 slice for the firecracker
process so VM lifetimes can outlive a supervisor container restart.
* AdoptVM(name, socket, pid): re-attach to a VM the current process did
not start. VM.Wait/Kill switch to /proc-based liveness when cmd==nil.
* VM.Kill: SIGKILL fallback for a hung guest.
* CreateSnapshotRaw + SnapshotRawResult: pause/snapshot/resume without
rootfs copy, with a whilePaused hook for callers managing disk content
out of band, returning paused-window timing.
Config.validate now skips RootFS when RawDiskPath is set (previously RawDisk
users had to pass a stub RootFS). Tests cover deterministic name/IP
derivation, supernet bounds, exported aliases, AdoptVM happy/error paths,
no-op Wait/Kill on adopted VMs, RawDiskPath validation, prepareDisk
RootFSSize no-growth path, and the empty-slice error in EscapeContainerCgroup.
README and CLAUDE.md gain Direct Networking, Raw-disk, Adopt, and Raw
Snapshot sections.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
It needs CAP_NET_ADMIN + CAP_SYS_ADMIN + CAP_NET_RAW (and /sys/fs/cgroup write access if EscapeCgroupSlice is set), not just CAP_NET_ADMIN/RAW as the prior README/CLAUDE.md/vm_direct.go header suggested. CAP_SYS_ADMIN is needed for `ip netns add` and to setns into the netns via `nsenter --net`. The pasta path (Run) remains genuinely rootless. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.