Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

sbr: Add rule for outbound interface when there is a single interface IP #1144

Open
wants to merge 6 commits into
base: main
Choose a base branch
from

Conversation

neilcook
Copy link

When using the sbr plugin with a CNI plugin such as multus, applications have to bind to the source IP address of the interface for the str plugin to work correctly. They cannot bind to the interface name, because the sbr plugin doesn't currently add a rule for the interface name.

This is problematic because it is straightforward to configure the name of a multus interface, however the IP address is usually assigned from a range, so the exact interface IP address to use is not known in advance unlike the interface name. It would thus be much easier for applications if the sbr plugin added a rule with the interface name in addition to the rule with the interface address.

This PR does exactly that - adds an additional rule with the outbound interface name, so that applications can configure the name of the interface to bind to, rather than having to know the interface IP address.

Obviously, this approach does not work if there are multiple IP addresses for the interface, so this change only adds the rule for the outbound interface name if there is a single IP address on that interface.

I have added tests for the new rule, which all pass.

Adding the outbound interface rule allows applications to bind to an interface name
rather than only the interface IP. This allows applications in a multus environment
to be configured with the interface name, which can be configured, rather than the
interface IP address, which is not known in advance.

The outbound interface rule is on;y added if the interface is configured with 1 IP
address, because when there are multiple, only one will be selected, depending on the
rule order, which is non-deterministic.

Signed-off-by: Neil Cook <[email protected]>
@neilcook neilcook changed the title Add rule for outbound interface when there is a single interface IP sbr: Add rule for outbound interface when there is a single interface IP Jan 26, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant