API Reference

API Reference #

Packages #

network.openperouter.io/v1alpha1 #

Package v1alpha1 contains API Schema definitions for the openpe v1alpha1 API group.

Resource Types #

AddressFamilyProperty #

AddressFamilyProperty is an optional feature applied to a neighbor address family. The type field selects the property; typed sub-fields hold parameters for properties that require them.

Appears in:

FieldDescriptionDefaultValidation
type AddressFamilyPropertyTypetype selects the property.Enum: [routeReflectorClient] Required: {}

AddressFamilyPropertyType #

Underlying type: string

AddressFamilyPropertyType defines an optional feature on a neighbor address family.

Validation:

  • Enum: [routeReflectorClient]

Appears in:

FieldDescription
routeReflectorClientAddressFamilyPropertyRouteReflectorClient marks the neighbor as aroute reflector client of the local router in this address family (RFC 4456).

BFDSessionMode #

Underlying type: string

BFDSessionMode selects whether the local system initiates the BFD session.

Validation:

  • Enum: [Active Passive]

Appears in:

FieldDescription
ActiveBFDSessionModeActive initiates the BFD session. This is the defaultwhen sessionMode is omitted.
PassiveBFDSessionModePassive waits for the peer to initiate the BFD sessionbefore replying.

BFDSettings #

BFDSettings defines the BFD configuration for a BGP session.

Appears in:

FieldDescriptionDefaultValidation
receiveInterval integerreceiveInterval is the minimum interval that this system is capable ofreceiving control packets in milliseconds.Defaults to 300ms.Maximum: 60000 Minimum: 10 Optional: {}
transmitInterval integertransmitInterval is the minimum transmission interval (less jitter)that this system wants to use to send BFD control packets inmilliseconds. Defaults to 300msMaximum: 60000 Minimum: 10 Optional: {}
detectMultiplier integerdetectMultiplier configures the detection multiplier to determinepacket loss. The remote transmission interval will be multipliedby this value to determine the connection loss detection timer.Maximum: 255 Minimum: 2 Optional: {}
sessionMode BFDSessionModesessionMode marks the session active or passive. Active (the defaultwhen omitted) initiates the session. Passive waits for the peer toinitiate before replying (RFC 5880 Section 6.1).Enum: [Active Passive] Optional: {}
minimumTTL integerminimumTTL configures, for multi hop sessions only, the minimumexpected TTL for an incoming BFD control packet.Maximum: 254 Minimum: 1 Optional: {}

BridgeLifecycle #

Underlying type: string

BridgeLifecycle determines how the bridge is provisioned.

Validation:

  • Enum: [Managed External]

Appears in:

FieldDescription
ManagedBridgeLifecycleManaged means the controller creates and owns thebridge, named br-hs-, and deletes it when the L2VNI is removed.
ExternalBridgeLifecycleExternal means the user provides a pre-existing bridgevia the Name field. The controller does not create or delete it; onlyveth ports are attached/detached.

CNIConfigType #

Underlying type: string

CNIConfigType selects the source of the CNI configuration. It is the discriminator of the CNIDevice union and is designed to be extended with future config sources (e.g. a NetworkAttachmentDefinition reference or a filesystem path).

Validation:

  • Enum: [RawConfig]

Appears in:

FieldDescription
RawConfigCNIConfigTypeRawConfig embeds the CNI config JSON directly in the spec.

CNIDevice #

CNIDevice invokes a CNI plugin to provision an interface in the router netns. The config source is a discriminated union — additional source variants can be added later if a concrete user need emerges.

Appears in:

FieldDescriptionDefaultValidation
type CNIConfigTypetype selects the source of the CNI configuration.Enum: [RawConfig] Required: {}
rawConfig JSONrawConfig embeds a CNI conflist JSON blob directly in this spec.Only CNI spec >= 1.0.0 configurations are accepted. Immutable onceset: to change it, delete and recreate theUnderlay. Immutability is enforced by the validation webhook becauseCEL transition rules cannot be evaluated inside atomic lists.Type: object Optional: {}
interfaceName stringinterfaceName is the name of the interface the CNI plugin createsinside the router netns (passed as CNI_IFNAME). Defaults to “net1”.net1MaxLength: 15 MinLength: 1 Pattern: ^[a-zA-Z][a-zA-Z0-9._-]*$ Optional: {}
runtimeConfig JSONruntimeConfig is an opaque JSON object mapping CNI capability namesto the payloads passed as capability arguments to the CNIinvocation. Only keys that the plugin declares in its“capabilities” config block are forwarded; undeclared keys aresilently stripped. Well-known capabilities include ips, mac,bandwidth, portMappings, ipRanges and deviceID. Immutable onceset: to change it, delete and recreate the Underlay. Immutabilityis enforced by the validation webhook because CEL transition rulescannot be evaluated inside atomic lists.Type: object Optional: {}

EBGPMultiHopProperties #

EBGPMultiHopProperties holds parameters for the ebgpMultiHop property.

Appears in:

FieldDescriptionDefaultValidation
ttl integerttl is the maximum number of hops for the eBGP multihop session.When omitted, FRR defaults to 255.Maximum: 255 Minimum: 1 Optional: {}

FailedResource #

FailedResource describe failing router API resource

Appears in:

FieldDescriptionDefaultValidation
kind FailedResourceKindkind resource type name (e.g.: L3VNI, L2VNI).Enum: [Underlay L2VNI L3VNI FrrConfiguration L3Passthrough] Required: {}
name stringname failed API resource metadata.name.MaxLength: 253 MinLength: 1 Required: {}
reason FailedResourceReasonreason failure reason.Enum: [ValidationFailed DependencyFailed OverlayAttachmentFailed FrrConfigurationFailed] MaxLength: 100 MinLength: 1 Required: {}
message stringmessage human-readable failure description.MaxLength: 500 MinLength: 1 Required: {}

FailedResourceKind #

Underlying type: string

Validation:

  • Enum: [Underlay L2VNI L3VNI FrrConfiguration L3Passthrough]

Appears in:

FailedResourceReason #

Underlying type: string

FailedResourceReason machine-readable reason for a failure.

Validation:

  • Enum: [ValidationFailed DependencyFailed OverlayAttachmentFailed FrrConfigurationFailed]
  • MaxLength: 100
  • MinLength: 1

Appears in:

FieldDescription
ValidationFailedFailedResourceReasonValidationFailed indicates failed pre-emptive semantic validation(e.g., interface not found, VNI conflict).
DependencyFailedFailedResourceReasonDependencyFailed dependent-on resource is not ready(e.g., L2VNI specify an interface managed by failing Underlay resource).
OverlayAttachmentFailedFailedResourceReasonOverlayAttachmentFailed provisioning failure at the logical network layer of the router(e.g.: failed to create VRF, move interface to router namespace).
FrrConfigurationFailedFailedResourceReasonFrrConfigurationFailed applying FRR configuration failed.

GracefulRestartConfig #

GracefulRestartConfig holds BGP Graceful Restart parameters. Its presence on the Underlay enables graceful restart.

Appears in:

FieldDescriptionDefaultValidation
restartTimeSeconds integerrestartTimeSeconds is the time in seconds that the restarting routerrequests its peers to preserve routes. Peers will wait this longbefore removing stale routes.120Maximum: 4095 Minimum: 1 Optional: {}
stalePathTimeSeconds integerstalePathTimeSeconds is the time in seconds that stale paths from arestarting peer are retained locally.360Maximum: 4095 Minimum: 1 Optional: {}

HostMaster #

Appears in:

FieldDescriptionDefaultValidation
type stringtype of the host interface. Supported values: “LinuxBridge”, “OVSBridge”.Enum: [LinuxBridge OVSBridge] Required: {}
linuxBridge LinuxBridgeConfiglinuxBridge configuration. Must be set when Type is “LinuxBridge”.Optional: {}
ovsBridge OVSBridgeConfigovsBridge configuration. Must be set when Type is “OVSBridge”.Optional: {}

HostSession #

Host Session represents the leg between the router and the host. A BGP session is established over this leg.

Appears in:

FieldDescriptionDefaultValidation
asn integerasn is the local AS number to use to establish a BGP session withthe default namespace.Maximum: 4.294967295e+09 Minimum: 1 Required: {}
hostASN integerhostASN is the expected AS number for a BGP speaking component running inthe default network namespace. Either HostASN or HostType must be set.Maximum: 4.294967295e+09 Minimum: 1 Optional: {}
hostType stringhostType is the AS type of the BGP speaking component running in thedefault network namespace. Either HostASN or HostType must be set.Enum: [External Internal] Optional: {}
localCIDRs string arraylocalCIDRs is the list of CIDRs for the veth pair connecting to thedefault namespace. The router side uses the first usable IP of each CIDR.At most one IPv4 and one IPv6 CIDR may be set; list order is not significant.MaxItems: 2 MinItems: 1 Required: {}

IPFamily #

Underlying type: string

IPFamily specifies which address families are enabled.

Validation:

  • Enum: [IPv4 IPv6 DualStack]

Appears in:

FieldDescription
IPv4
IPv6
DualStack

ISISConfig #

ISISConfig contains ISIS configuration for the underlay.

Appears in:

FieldDescriptionDefaultValidation
baseNet ISISNetbaseNet holds the ISIS NET address.The configured Net address is a base address which is offset by the node index of each node.Only accepts the simplified NSAP format with a fixed AreaID length of 3 bytes and a 6 byte SystemID in compliancewith the U.S. GOSIP version 2.0 for a total of 10 bytes.MaxLength: 25 MinLength: 25 Required: {}
features ISISFeature arrayfeatures enables ISIS boolean features.Supported features are:advertisePassiveOnly: configures ISIS to advertise only prefixes that belong to passive interfaces.Enum: [advertisePassiveOnly] MaxItems: 32 MaxLength: 128 MinLength: 1 Optional: {}
interfaces ISISInterface arrayinterfaces holds additional ISIS interface level configuration and / or perinterface overrides. By default, OpenPERouter enables IPv6 on all requiredinterfaces with default settings.MaxItems: 128 Optional: {}
level integerlevel configures the ISIS type, system wide. It defaults to level-1-2 unless specified otherwise.Enum: [1 2] Optional: {}

ISISFeature #

Underlying type: string

ISISFeature represents a single ISIS feature.

Validation:

  • Enum: [advertisePassiveOnly]
  • MaxLength: 128
  • MinLength: 1

Appears in:

ISISInterface #

ISISInterface holds ISIS interface level configuration.

Appears in:

FieldDescriptionDefaultValidation
name stringname of the interface that these settings shall apply to.MaxLength: 15 MinLength: 1 Required: {}
ipFamily IPFamilyipFamily configures which address families ISIS is enabled for on this interface.Enum: [IPv4 IPv6 DualStack] Optional: {}
features ISISInterfaceFeature arrayfeatures enables ISIS interface boolean features.Supported features are:passive: configures ISIS passive mode on this interface.Enum: [passive] MaxItems: 32 MaxLength: 128 MinLength: 1 Optional: {}

ISISInterfaceFeature #

Underlying type: string

ISISInterfaceFeature represents a single ISIS feature of an ISIS interface.

Validation:

  • Enum: [passive]
  • MaxLength: 128
  • MinLength: 1

Appears in:

ISISNet #

Underlying type: string

ISISNet represents a single ISIS NET address. Only accepts the simplified NSAP format with a fixed AreaID length of 3 bytes and a 6 byte SystemID in compliance with the U.S. GOSIP version 2.0 for a total of 10 bytes.

Validation:

  • MaxLength: 25
  • MinLength: 25

Appears in:

L2VNI #

L2VNI represents a VXLan VNI to receive EVPN type 2 routes from.

FieldDescriptionDefaultValidation
apiVersion stringnetwork.openperouter.io/v1alpha1
kind stringL2VNI
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec L2VNISpecspec defines the desired state of L2VNI.Required: {}
status L2VNIStatusstatus defines the observed state of L2VNI.Optional: {}

L2VNISpec #

L2VNISpec defines the desired state of VNI.

Appears in:

FieldDescriptionDefaultValidation
nodeSelector LabelSelectornodeSelector specifies which nodes this L2VNI applies to.If empty or not specified, applies to all nodes.Multiple L2VNIs can match the same node.Optional: {}
routingDomain RoutingDomainroutingDomain optionally attaches this L2VNI to a routing domainprovided by a backing resource (L3VNI or L3VPN). When omitted, theL2VNI is a disconnected overlay (east-west L2 only, no VRF, nogateway).Optional: {}
vni integervni is the VXLan VNI to be usedMaximum: 1.6777215e+07 Minimum: 1 Required: {}
vxlanPort integervxlanPort is the port to be used for VXLan encapsulation.4789Optional: {}
underlayAddressFamily stringunderlayAddressFamily selects which VTEP address family to use for this VNI’sVXLAN interface. When omitted, defaults to the available family in the underlay(IPv4 preferred in dual-stack).Enum: [IPv4 IPv6] Optional: {}
hostMaster HostMasterhostMaster is the interface on the host the veth should be attached to.If not set, the host veth will not be attached to any interface and it must beattached manually (or by some other means). This is useful if another controlleris leveraging the host interface for the VNI.Optional: {}
gatewayIPs string arraygatewayIPs is a list of IP addresses in CIDR notation for thedistributed anycast gateway on this L2 segment’s bridge(Integrated Routing and Bridging interface). It is a property ofthe L2 segment itself, so it lives on the L2VNI rather thaninside the routing-domain reference.Maximum of 2 addresses are allowed. If 2 addresses are provided, one must be IPv4 and one must be IPv6.MaxItems: 2 Optional: {}

L2VNIStatus #

VNIStatus defines the observed state of VNI.

Appears in:

L3Passthrough #

L3Passthrough represents a session with the host which is not encapsulated and takes part to the bgp fabric.

FieldDescriptionDefaultValidation
apiVersion stringnetwork.openperouter.io/v1alpha1
kind stringL3Passthrough
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec L3PassthroughSpecspec defines the desired state of L3Passthrough.Required: {}
status L3PassthroughStatusstatus defines the observed state of L3Passthrough.Optional: {}

L3PassthroughSpec #

Appears in:

FieldDescriptionDefaultValidation
nodeSelector LabelSelectornodeSelector specifies which nodes this L3Passthrough applies to.If empty or not specified, applies to all nodes.Multiple L3Passthrough with overlapping node selectors will be rejected.Optional: {}
hostSession HostSessionhostSession is the configuration for the host session.Required: {}

L3PassthroughStatus #

L3PassthroughStatus defines the observed state of L3Passthrough.

Appears in:

L3VNI #

L3VNI represents a VXLan L3VNI to receive EVPN type 5 routes from.

FieldDescriptionDefaultValidation
apiVersion stringnetwork.openperouter.io/v1alpha1
kind stringL3VNI
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec L3VNISpecspec defines the desired state of L3VNI.Required: {}
status L3VNIStatusstatus defines the observed state of L3VNI.Optional: {}

L3VNIReference #

L3VNIReference references an L3VNI by name.

Appears in:

FieldDescriptionDefaultValidation
name stringname is the metadata.name of the L3VNI in the same namespace.MinLength: 1 Required: {}

L3VNISpec #

L3VNISpec defines the desired state of VNI.

Appears in:

FieldDescriptionDefaultValidation
nodeSelector LabelSelectornodeSelector specifies which nodes this L3VNI applies to.If empty or not specified, applies to all nodes.Multiple L3VNIs can match the same node.Optional: {}
vrf stringvrf is the name of the linux VRF to be used inside the PERouter namespace.MaxLength: 15 MinLength: 1 Pattern: ^[a-zA-Z][a-zA-Z0-9_-]*$ Required: {}
vni integervni is the VXLan VNI to be usedMaximum: 1.6777215e+07 Minimum: 1 Required: {}
vxlanPort integervxlanPort is the port to be used for VXLan encapsulation.4789Optional: {}
underlayAddressFamily stringunderlayAddressFamily selects which VTEP address family to use for this VNI’sVXLAN interface. When omitted, defaults to the available family in the underlay(IPv4 preferred in dual-stack).Enum: [IPv4 IPv6] Optional: {}
hostSession HostSessionhostSession is the configuration for the host session.Optional: {}
exportRTs RouteTarget arrayexportRTs are the Route Targets to be used for exporting routes.RouteTarget defines a BGP Extended Community for route filtering.MaxItems: 100 MaxLength: 21 Optional: {}
importRTs RouteTarget arrayimportRTs are the Route Targets to be used for importing routes.RouteTarget defines a BGP Extended Community for route filtering.MaxItems: 100 MaxLength: 21 Optional: {}

L3VNIStatus #

L3VNIStatus defines the observed state of L3VNI.

Appears in:

L3VPN #

L3VPN represents an SRv6 IP VPN.

FieldDescriptionDefaultValidation
apiVersion stringnetwork.openperouter.io/v1alpha1
kind stringL3VPN
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec L3VPNSpecspec defines the desired state of L3VPN.Required: {}
status L3VPNStatusstatus defines the observed state of L3VPN.Optional: {}

L3VPNReference #

L3VPNReference references an L3VPN by name.

Appears in:

FieldDescriptionDefaultValidation
name stringname is the metadata.name of the L3VPN in the same namespace.MinLength: 1 Required: {}

L3VPNSpec #

L3VPNSpec defines the desired state of L3VPN.

Appears in:

FieldDescriptionDefaultValidation
nodeSelector LabelSelectornodeSelector specifies which nodes this L3VPN applies to.If empty or not specified, applies to all nodes.Multiple L3VPNs can match the same node.Optional: {}
vrf stringvrf is the name of the linux VRF to be used inside the PERouter namespace.MaxLength: 15 MinLength: 1 Pattern: ^[a-zA-Z][a-zA-Z0-9_-]*$ Required: {}
exportRTs RouteTarget arrayexportRTs are the Route Targets to be used for exporting routes.If no exportRTs are provided, defaults to single export Route Target:.MaxItems: 100 MaxLength: 21 Optional: {}
importRTs RouteTarget arrayimportRTs are the Route Targets to be used for importing routes.importRTs must always be provided explicitly.MaxItems: 100 MaxLength: 21 Required: {}
rdAssignedNumber integerrdAssignedNumber sets the Route Distinguisher’s Assigned Number subfield.The Administrator subfield is automatically set to the value of the routerID. OpenPERouter uses Type 1 Route Distinguishers as defined in RFC4364,meaning :.Maximum: 65535 Minimum: 1 Required: {}
hostSession HostSessionhostSession is the configuration for the host session.Optional: {}

L3VPNStatus #

L3VPNStatus defines the observed state of L3VPN.

Appears in:

LinuxBridgeConfig #

LinuxBridgeConfig contains configuration for Linux bridge type.

Appears in:

FieldDescriptionDefaultValidation
lifecycle BridgeLifecyclelifecycle determines if the bridge is managed by the controller orprovided by the user.Enum: [Managed External] Required: {}
name stringname of the Linux bridge interface. Required when lifecycle isExternal, and must be omitted when it is Managed, in which case thebridge is named br-hs-.MaxLength: 15 Pattern: ^[a-zA-Z][a-zA-Z0-9_-]*$ Optional: {}

Neighbor #

Neighbor represents a BGP Neighbor we want FRR to connect to.

Appears in:

FieldDescriptionDefaultValidation
asn integerasn is the AS number of the neighbor. Either ASN or Type must be set.Maximum: 4.294967295e+09 Minimum: 1 Optional: {}
type stringtype is the AS type of the neighbor. Either ASN or Type must be set.Enum: [External Internal] Optional: {}
address stringaddress is the IP address to establish the session with. The IP addresscan be either IPv4 or IPv6.MaxLength: 39 MinLength: 1 Optional: {}
interface stringinterface is the interface name for BGP unnumbered sessions. The session will be established via IPv6 link locals.MaxLength: 15 MinLength: 1 Optional: {}
listenRange stringlistenRange accepts connections from any peers in the specified CIDR.When set, the hostcontroller generates a“bgp listen range peer-group ” stanza instead ofan explicit neighbor statement. Mutually exclusive with address andinterface.MaxLength: 43 MinLength: 1 Optional: {}
port integerport is the port to dial when establishing the session.Defaults to 179.Maximum: 16384 Minimum: 0 Optional: {}
passwordSecret SecretKeyRefpasswordSecret references a key in a Kubernetes Secret containing theBGP session password. The Secret must be created in the same namespaceas the Underlay.Optional: {}
holdTimeSeconds integerholdTimeSeconds is the requested BGP hold time in seconds, per RFC4271.Defaults to 180.Optional: {}
keepaliveTimeSeconds integerkeepaliveTimeSeconds is the requested BGP keepalive time in seconds, per RFC4271.Defaults to 60.Optional: {}
connectTimeSeconds integerconnectTimeSeconds controls how long BGP waits between connection attempts to a neighbor, in seconds.Maximum: 65535 Minimum: 1 Optional: {}
properties NeighborProperty arrayproperties is the set of optional session-level features for thisneighbor (e.g. ebgpMultiHop).MaxItems: 1 Optional: {}
bfd BFDSettingsbfd defines the BFD configuration for the BGP session.Optional: {}
addressFamilies NeighborAddressFamily arrayaddressFamilies specifies the BGP address families that shall be enabledfor this BGP neighbor. evpn and ipv4vpn/ipv6vpn are mutually exclusive.If ipv4vpn or ipv6vpn are set, the update source of this neighbor willbe set to the loopback’s IPv6 address.If addressFamilies is not provided or empty, the following defaults arechosen:For unnumbered neighbors:- ipv4unicast- ipv6unicast if passthrough is configured with IPv6 local CIDR- evpn if L2VNIs or L3VNIs are present.For IPv4 neighbors:- ipv4unicast- ipv6unicast if passthrough is configured with IPv6 local CIDR- evpn if L2VNIs or L3VNIs are present.For IPv6 neighbors:- ipv4unicast if L2VNIs or L3VNIs are present, or if passthrough is configured with IPv4 local CIDR- ipv6unicast- evpn if L2VNIs or L3VNIs are present- ipv4vpn if L3VPNs and SRv6 configuration are present.- ipv6vpn if L3VPNs and SRv6 configuration are present.MaxItems: 4 Optional: {}

NeighborAddressFamily #

NeighborAddressFamily represents a single BGP address family configuration for a neighbor.

Appears in:

FieldDescriptionDefaultValidation
type stringtype is the address family type.Enum: [ipv4unicast ipv6unicast evpn ipv4vpn ipv6vpn] MaxLength: 11 MinLength: 1 Required: {}
properties AddressFamilyProperty arrayproperties is the set of optional per-address-family features for thisneighbor (for example, marking the neighbor as a route reflector clientin this address family).MaxItems: 8 Optional: {}

NeighborProperty #

NeighborProperty is an optional feature applied to a neighbor session. The type field selects the property; typed sub-fields hold parameters for properties that require them.

Appears in:

FieldDescriptionDefaultValidation
type NeighborPropertyTypetype selects the property.Enum: [ebgpMultiHop] Required: {}
ebgpMultiHop EBGPMultiHopPropertiesebgpMultiHop holds parameters for the ebgpMultiHop property.May only be set when type is ebgpMultiHop.Optional: {}

NeighborPropertyType #

Underlying type: string

NeighborPropertyType defines an optional feature on a Neighbor. The values are protocol / FRR configuration tokens and are kept verbatim so they map directly to the rendered stanzas.

Validation:

  • Enum: [ebgpMultiHop]

Appears in:

FieldDescription
ebgpMultiHopNeighborPropertyEBGPMultiHop enables eBGP multihop on the neighborsession, rendered as “neighbor X ebgp-multihop [ttl]”.

NetworkDevice #

NetworkDevice moves an existing host network device into the router netns.

Appears in:

FieldDescriptionDefaultValidation
interfaceName stringinterfaceName is the name of the host network device to move intothe router netns.MaxLength: 15 MinLength: 1 Pattern: ^[a-zA-Z][a-zA-Z0-9._-]*$ Required: {}

OVSBridgeConfig #

OVSBridgeConfig contains configuration for OVS bridge type.

Appears in:

FieldDescriptionDefaultValidation
lifecycle BridgeLifecyclelifecycle determines if the OVS bridge is managed by the controller orprovided by the user.Enum: [Managed External] Required: {}
name stringname of the OVS bridge interface. Required when lifecycle isExternal, and must be omitted when it is Managed, in which case thebridge is named br-hs-.MaxLength: 15 Pattern: ^[a-zA-Z][a-zA-Z0-9_-]*$ Optional: {}

RawFRRConfig #

RawFRRConfig is the Schema for the rawfrrconfigs API.

FieldDescriptionDefaultValidation
apiVersion stringnetwork.openperouter.io/v1alpha1
kind stringRawFRRConfig
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec RawFRRConfigSpecspec defines the desired state of RawFRRConfig.Required: {}
status RawFRRConfigStatusstatus defines the observed state of RawFRRConfig.Optional: {}

RawFRRConfigSpec #

RawFRRConfigSpec defines the desired state of RawFRRConfig.

Appears in:

FieldDescriptionDefaultValidation
nodeSelector LabelSelectornodeSelector specifies which nodes this RawFRRConfig applies to.If empty or not specified, applies to all nodes.Optional: {}
priority integerpriority controls the ordering of raw config snippets in the rendered FRR configuration.Lower values are rendered first. Snippets with the same priority have undefined order.0Minimum: 0 Optional: {}
rawConfig stringrawConfig is the raw FRR configuration text to append to the rendered configuration.WARNING: This feature is intended for advanced use cases. No validation of FRR syntaxis performed at admission time; invalid configuration will cause FRR reload failures.MinLength: 1 Required: {}

RawFRRConfigStatus #

RawFRRConfigStatus defines the observed state of RawFRRConfig.

Appears in:

RouteReflectorConfig #

RouteReflectorConfig holds BGP Route Reflector parameters (RFC 4456). Its presence on the Underlay enables route reflection on matching nodes.

Appears in:

FieldDescriptionDefaultValidation
clusterID stringclusterID is the BGP cluster-id shared by all RR nodes in the samecluster (RFC 4456 §7). All RRs serving the same set of clients mustuse the same value so that CLUSTER_LIST loop detection preventsduplicate route reflection. The cluster-id is an opaque 32-bitidentifier, not a routable address, and must be outside therouterIDCIDR range to avoid colliding with allocated router-ids.The default (192.0.2.1) is an RFC 5737 documentation address,outside the default routerIDCIDR pool; with a custom routerIDCIDRthat contains it, the resource is rejected at admission.192.0.2.1MaxLength: 15 MinLength: 7 Optional: {}

RouteTarget #

Underlying type: string

RouteTarget defines a BGP Extended Community for route filtering.

Validation:

  • MaxLength: 21

Appears in:

RouterNodeConfigurationStatus #

RouterNodeConfigurationStatus describes a node router state.

FieldDescriptionDefaultValidation
apiVersion stringnetwork.openperouter.io/v1alpha1
kind stringRouterNodeConfigurationStatus
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.
status RouterNodeConfigurationStatusStatusstatus node router configuration status.Optional: {}

RouterNodeConfigurationStatusStatus #

Appears in:

FieldDescriptionDefaultValidation
failedResources FailedResource arrayfailedResources list of failed configuration resources on the node.Optional: {}
conditions Condition arrayconditions list of conditions.Optional: {}

RoutingDomain #

RoutingDomain is a discriminated union over the resource kinds that can provide a routing domain. Exactly one sub-struct must match the type discriminator.

Appears in:

FieldDescriptionDefaultValidation
type stringtype selects the kind of resource that provides this routing domain.Enum: [L3VNI L3VPN] Required: {}
l3vni L3VNIReferencel3vni references the L3VNI (metadata.name) in the same namespace thatprovides the routing domain for this L2VNI.Optional: {}
l3vpn L3VPNReferencel3vpn references the L3VPN (metadata.name) in the same namespace thatprovides the routing domain for this L2VNI.Optional: {}

SRV6Config #

SRV6Config contains SRV6 configuration for the underlay.

Appears in:

FieldDescriptionDefaultValidation
encapBehavior SRV6EncapBehaviorencapBehavior defines the behavior for SRv6 encapsulation as specifiedin RFC 8986 sections 5.1 and 5.2.If unset, defaults to H.Encaps.Enum: [H.Encaps H.Encaps.Red] MaxLength: 12 MinLength: 1 Optional: {}
locator SRV6Locatorlocator defines the locator for this SRv6 VPN.Required: {}

SRV6EncapBehavior #

Underlying type: string

SRV6EncapBehavior defines the behavior for SRv6 encapsulation as specified in RFC 8986 sections 5.1 and 5.2.

Validation:

  • Enum: [H.Encaps H.Encaps.Red]
  • MaxLength: 12
  • MinLength: 1

Appears in:

FieldDescription
H.EncapsHEncaps always adds an SRH to SRv6 encapsulated packets. For more details,see RFC 8986 section 5.1.
H.Encaps.RedHEncapsRed is an optimization of the H.Encaps behavior and reduces thelength of the SRH by excluding the first SID in the SRH of the pushedIPv6 header. The SRH is omitted when the SRv6 Policy only contains onesegment and there is no need to use any flag, tag or TLV. For moredetails, see RFC 8986 section 5.2.

SRV6Locator #

SRV6Locator holds the configuration of a locator for SRv6.

Appears in:

FieldDescriptionDefaultValidation
basePrefix stringbasePrefix is the CIDR to be used for the locator, offset by the router index.MaxLength: 43 MinLength: 1 Required: {}
format stringformat specifies the format of the locator. Defaults to usid-f3216Enum: [usid-f3216] MaxLength: 40 MinLength: 1 Required: {}

SecretKeyRef #

SecretKeyRef references a key within a Kubernetes Secret in the same namespace as the Underlay.

Appears in:

FieldDescriptionDefaultValidation
name stringname is the name of the Secret in the same namespace.MinLength: 1 Required: {}
key stringkey is the key within the Secret’s data to select.The controller defaults this to “password” when unset.MinLength: 1 Optional: {}

TunnelEndpointConfig #

TunnelEndpointConfig contains tunnel endpoint configuration for the underlay.

Appears in:

FieldDescriptionDefaultValidation
cidrs string arraycidrs is a list of CIDRs to be used to assign IPs to the local tunnel endpoint oneach node. IPs derived from these CIDRs will be assigned to the local loopback.At least one IPv4 or IPv6 CIDR is required. At most one of each family may be specified.MaxItems: 2 MinItems: 1 Required: {}

Underlay #

Underlay is the Schema for the underlays API.

FieldDescriptionDefaultValidation
apiVersion stringnetwork.openperouter.io/v1alpha1
kind stringUnderlay
metadata ObjectMetaRefer to Kubernetes API documentation for fields of metadata.Optional: {}
spec UnderlaySpecspec defines the desired state of Underlay.Required: {}
status UnderlayStatusstatus defines the observed state of Underlay.Optional: {}

UnderlayInterface #

UnderlayInterface defines how the router obtains a single underlay link. Exactly one of the sub-structs must match the type field. The union is designed to be extended with future modes for controller-provisioned interfaces.

Appears in:

FieldDescriptionDefaultValidation
type UnderlayInterfaceTypetype selects how the router obtains this underlay link.Enum: [NetworkDevice CNIDevice] Required: {}
networkDevice NetworkDevicenetworkDevice moves an existing host network device into the router netns.The device can be of any kind (physical NIC, bridge, macvlan, etc.).Must be set when type is “NetworkDevice”.Optional: {}
cniDevice CNIDevicecniDevice invokes a CNI plugin to provision an interface in the routernetns. IPAM is delegated to the CNI plugin. Must be set when type is“CNIDevice”.Optional: {}

UnderlayInterfaceType #

Underlying type: string

UnderlayInterfaceType selects how the router obtains an underlay link. It is the discriminator of the UnderlayInterface union and is designed to be extended with future modes.

Validation:

  • Enum: [NetworkDevice CNIDevice]

Appears in:

FieldDescription
NetworkDeviceUnderlayInterfaceTypeNetworkDevice moves an existing host network deviceinto the router netns.
CNIDeviceUnderlayInterfaceTypeCNIDevice invokes a CNI plugin to provision an interfacein the router netns.

UnderlaySpec #

UnderlaySpec defines the desired state of Underlay.

Appears in:

FieldDescriptionDefaultValidation
nodeSelector LabelSelectornodeSelector specifies which nodes this Underlay applies to.If empty or not specified, applies to all nodes (backward compatible).Multiple Underlays with overlapping node selectors will be rejected.Optional: {}
asn integerasn is the local AS number to use for the session with the TOR switch.Maximum: 4.294967295e+09 Minimum: 1 Required: {}
routerIDCIDR stringrouterIDCIDR is the ipv4 cidr to be used to assign a different routerID on each node.10.0.0.0/24Optional: {}
neighbors Neighbor arrayneighbors is the list of external BGP neighbors to peer with.Multiple neighbors are supported for connecting to multiple TOR switchesor establishing redundant BGP sessions. Each neighbor address must be unique.At least one neighbor is required.MaxItems: 128 MinItems: 1 Required: {}
interfaces UnderlayInterface arrayinterfaces is the list of interfaces the router uses for underlayconnectivity. Each entry is a discriminated union describing how theinterface is obtained. At least one interface is required. All theentries must be of the same type: mixing NetworkDevice and CNIDeviceinterfaces is not supported.MinItems: 1 Required: {}
tunnelEndpoint TunnelEndpointConfigtunnelEndpoint contains tunnel endpoint configuration for the underlay.Optional: {}
gracefulRestart GracefulRestartConfiggracefulRestart configures BGP Graceful Restart behaviour.When set, FRR advertises GR capability and preserves forwardingstate across restarts so that peers keep stale routes active.Omit to disable graceful restart.Optional: {}
isis ISISConfigisis holds the ISIS configuration for the underlay.Optional: {}
srv6 SRV6Configsrv6 holds the SRv6 configuration. Requires ISIS or Neighbors configuration.Optional: {}
routeReflector RouteReflectorConfigrouteReflector configures the local FRR process as a BGP route reflector.When set, the hostcontroller generates bgp cluster-id from clusterIDand derives bgp listen range and route-reflector-client stanzas fromneighbors with listenRange and the routeReflectorClient property.Omit to run as a standard router without route reflection.Optional: {}

UnderlayStatus #

UnderlayStatus defines the observed state of Underlay.

Appears in: