API Reference #
Packages #
network.openperouter.io/v1alpha1 #
Package v1alpha1 contains API Schema definitions for the openpe v1alpha1 API group.
Resource Types #
AddressFamilyProperty #
AddressFamilyProperty is an optional feature applied to a neighbor address family. The type field selects the property; typed sub-fields hold parameters for properties that require them.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
type AddressFamilyPropertyType | type selects the property. | Enum: [routeReflectorClient] Required: {} |
AddressFamilyPropertyType #
Underlying type: string
AddressFamilyPropertyType defines an optional feature on a neighbor address family.
Validation:
- Enum: [routeReflectorClient]
Appears in:
| Field | Description |
|---|---|
routeReflectorClient | AddressFamilyPropertyRouteReflectorClient marks the neighbor as aroute reflector client of the local router in this address family (RFC 4456). |
BFDSessionMode #
Underlying type: string
BFDSessionMode selects whether the local system initiates the BFD session.
Validation:
- Enum: [Active Passive]
Appears in:
| Field | Description |
|---|---|
Active | BFDSessionModeActive initiates the BFD session. This is the defaultwhen sessionMode is omitted. |
Passive | BFDSessionModePassive waits for the peer to initiate the BFD sessionbefore replying. |
BFDSettings #
BFDSettings defines the BFD configuration for a BGP session.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
receiveInterval integer | receiveInterval is the minimum interval that this system is capable ofreceiving control packets in milliseconds.Defaults to 300ms. | Maximum: 60000 Minimum: 10 Optional: {} | |
transmitInterval integer | transmitInterval is the minimum transmission interval (less jitter)that this system wants to use to send BFD control packets inmilliseconds. Defaults to 300ms | Maximum: 60000 Minimum: 10 Optional: {} | |
detectMultiplier integer | detectMultiplier configures the detection multiplier to determinepacket loss. The remote transmission interval will be multipliedby this value to determine the connection loss detection timer. | Maximum: 255 Minimum: 2 Optional: {} | |
sessionMode BFDSessionMode | sessionMode marks the session active or passive. Active (the defaultwhen omitted) initiates the session. Passive waits for the peer toinitiate before replying (RFC 5880 Section 6.1). | Enum: [Active Passive] Optional: {} | |
minimumTTL integer | minimumTTL configures, for multi hop sessions only, the minimumexpected TTL for an incoming BFD control packet. | Maximum: 254 Minimum: 1 Optional: {} |
BridgeLifecycle #
Underlying type: string
BridgeLifecycle determines how the bridge is provisioned.
Validation:
- Enum: [Managed External]
Appears in:
| Field | Description |
|---|---|
Managed | BridgeLifecycleManaged means the controller creates and owns thebridge, named br-hs-, and deletes it when the L2VNI is removed. |
External | BridgeLifecycleExternal means the user provides a pre-existing bridgevia the Name field. The controller does not create or delete it; onlyveth ports are attached/detached. |
CNIConfigType #
Underlying type: string
CNIConfigType selects the source of the CNI configuration. It is the discriminator of the CNIDevice union and is designed to be extended with future config sources (e.g. a NetworkAttachmentDefinition reference or a filesystem path).
Validation:
- Enum: [RawConfig]
Appears in:
| Field | Description |
|---|---|
RawConfig | CNIConfigTypeRawConfig embeds the CNI config JSON directly in the spec. |
CNIDevice #
CNIDevice invokes a CNI plugin to provision an interface in the router netns. The config source is a discriminated union — additional source variants can be added later if a concrete user need emerges.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
type CNIConfigType | type selects the source of the CNI configuration. | Enum: [RawConfig] Required: {} | |
rawConfig JSON | rawConfig embeds a CNI conflist JSON blob directly in this spec.Only CNI spec >= 1.0.0 configurations are accepted. Immutable onceset: to change it, delete and recreate theUnderlay. Immutability is enforced by the validation webhook becauseCEL transition rules cannot be evaluated inside atomic lists. | Type: object Optional: {} | |
interfaceName string | interfaceName is the name of the interface the CNI plugin createsinside the router netns (passed as CNI_IFNAME). Defaults to “net1”. | net1 | MaxLength: 15 MinLength: 1 Pattern: ^[a-zA-Z][a-zA-Z0-9._-]*$ Optional: {} |
runtimeConfig JSON | runtimeConfig is an opaque JSON object mapping CNI capability namesto the payloads passed as capability arguments to the CNIinvocation. Only keys that the plugin declares in its“capabilities” config block are forwarded; undeclared keys aresilently stripped. Well-known capabilities include ips, mac,bandwidth, portMappings, ipRanges and deviceID. Immutable onceset: to change it, delete and recreate the Underlay. Immutabilityis enforced by the validation webhook because CEL transition rulescannot be evaluated inside atomic lists. | Type: object Optional: {} |
EBGPMultiHopProperties #
EBGPMultiHopProperties holds parameters for the ebgpMultiHop property.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
ttl integer | ttl is the maximum number of hops for the eBGP multihop session.When omitted, FRR defaults to 255. | Maximum: 255 Minimum: 1 Optional: {} |
FailedResource #
FailedResource describe failing router API resource
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
kind FailedResourceKind | kind resource type name (e.g.: L3VNI, L2VNI). | Enum: [Underlay L2VNI L3VNI FrrConfiguration L3Passthrough] Required: {} | |
name string | name failed API resource metadata.name. | MaxLength: 253 MinLength: 1 Required: {} | |
reason FailedResourceReason | reason failure reason. | Enum: [ValidationFailed DependencyFailed OverlayAttachmentFailed FrrConfigurationFailed] MaxLength: 100 MinLength: 1 Required: {} | |
message string | message human-readable failure description. | MaxLength: 500 MinLength: 1 Required: {} |
FailedResourceKind #
Underlying type: string
Validation:
- Enum: [Underlay L2VNI L3VNI FrrConfiguration L3Passthrough]
Appears in:
FailedResourceReason #
Underlying type: string
FailedResourceReason machine-readable reason for a failure.
Validation:
- Enum: [ValidationFailed DependencyFailed OverlayAttachmentFailed FrrConfigurationFailed]
- MaxLength: 100
- MinLength: 1
Appears in:
| Field | Description |
|---|---|
ValidationFailed | FailedResourceReasonValidationFailed indicates failed pre-emptive semantic validation(e.g., interface not found, VNI conflict). |
DependencyFailed | FailedResourceReasonDependencyFailed dependent-on resource is not ready(e.g., L2VNI specify an interface managed by failing Underlay resource). |
OverlayAttachmentFailed | FailedResourceReasonOverlayAttachmentFailed provisioning failure at the logical network layer of the router(e.g.: failed to create VRF, move interface to router namespace). |
FrrConfigurationFailed | FailedResourceReasonFrrConfigurationFailed applying FRR configuration failed. |
GracefulRestartConfig #
GracefulRestartConfig holds BGP Graceful Restart parameters. Its presence on the Underlay enables graceful restart.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
restartTimeSeconds integer | restartTimeSeconds is the time in seconds that the restarting routerrequests its peers to preserve routes. Peers will wait this longbefore removing stale routes. | 120 | Maximum: 4095 Minimum: 1 Optional: {} |
stalePathTimeSeconds integer | stalePathTimeSeconds is the time in seconds that stale paths from arestarting peer are retained locally. | 360 | Maximum: 4095 Minimum: 1 Optional: {} |
HostMaster #
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
type string | type of the host interface. Supported values: “LinuxBridge”, “OVSBridge”. | Enum: [LinuxBridge OVSBridge] Required: {} | |
linuxBridge LinuxBridgeConfig | linuxBridge configuration. Must be set when Type is “LinuxBridge”. | Optional: {} | |
ovsBridge OVSBridgeConfig | ovsBridge configuration. Must be set when Type is “OVSBridge”. | Optional: {} |
HostSession #
Host Session represents the leg between the router and the host. A BGP session is established over this leg.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
asn integer | asn is the local AS number to use to establish a BGP session withthe default namespace. | Maximum: 4.294967295e+09 Minimum: 1 Required: {} | |
hostASN integer | hostASN is the expected AS number for a BGP speaking component running inthe default network namespace. Either HostASN or HostType must be set. | Maximum: 4.294967295e+09 Minimum: 1 Optional: {} | |
hostType string | hostType is the AS type of the BGP speaking component running in thedefault network namespace. Either HostASN or HostType must be set. | Enum: [External Internal] Optional: {} | |
localCIDRs string array | localCIDRs is the list of CIDRs for the veth pair connecting to thedefault namespace. The router side uses the first usable IP of each CIDR.At most one IPv4 and one IPv6 CIDR may be set; list order is not significant. | MaxItems: 2 MinItems: 1 Required: {} |
IPFamily #
Underlying type: string
IPFamily specifies which address families are enabled.
Validation:
- Enum: [IPv4 IPv6 DualStack]
Appears in:
| Field | Description |
|---|---|
IPv4 | |
IPv6 | |
DualStack |
ISISConfig #
ISISConfig contains ISIS configuration for the underlay.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
baseNet ISISNet | baseNet holds the ISIS NET address.The configured Net address is a base address which is offset by the node index of each node.Only accepts the simplified NSAP format with a fixed AreaID length of 3 bytes and a 6 byte SystemID in compliancewith the U.S. GOSIP version 2.0 for a total of 10 bytes. | MaxLength: 25 MinLength: 25 Required: {} | |
features ISISFeature array | features enables ISIS boolean features.Supported features are:advertisePassiveOnly: configures ISIS to advertise only prefixes that belong to passive interfaces. | Enum: [advertisePassiveOnly] MaxItems: 32 MaxLength: 128 MinLength: 1 Optional: {} | |
interfaces ISISInterface array | interfaces holds additional ISIS interface level configuration and / or perinterface overrides. By default, OpenPERouter enables IPv6 on all requiredinterfaces with default settings. | MaxItems: 128 Optional: {} | |
level integer | level configures the ISIS type, system wide. It defaults to level-1-2 unless specified otherwise. | Enum: [1 2] Optional: {} |
ISISFeature #
Underlying type: string
ISISFeature represents a single ISIS feature.
Validation:
- Enum: [advertisePassiveOnly]
- MaxLength: 128
- MinLength: 1
Appears in:
ISISInterface #
ISISInterface holds ISIS interface level configuration.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
name string | name of the interface that these settings shall apply to. | MaxLength: 15 MinLength: 1 Required: {} | |
ipFamily IPFamily | ipFamily configures which address families ISIS is enabled for on this interface. | Enum: [IPv4 IPv6 DualStack] Optional: {} | |
features ISISInterfaceFeature array | features enables ISIS interface boolean features.Supported features are:passive: configures ISIS passive mode on this interface. | Enum: [passive] MaxItems: 32 MaxLength: 128 MinLength: 1 Optional: {} |
ISISInterfaceFeature #
Underlying type: string
ISISInterfaceFeature represents a single ISIS feature of an ISIS interface.
Validation:
- Enum: [passive]
- MaxLength: 128
- MinLength: 1
Appears in:
ISISNet #
Underlying type: string
ISISNet represents a single ISIS NET address. Only accepts the simplified NSAP format with a fixed AreaID length of 3 bytes and a 6 byte SystemID in compliance with the U.S. GOSIP version 2.0 for a total of 10 bytes.
Validation:
- MaxLength: 25
- MinLength: 25
Appears in:
L2VNI #
L2VNI represents a VXLan VNI to receive EVPN type 2 routes from.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | network.openperouter.io/v1alpha1 | ||
kind string | L2VNI | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | Optional: {} | |
spec L2VNISpec | spec defines the desired state of L2VNI. | Required: {} | |
status L2VNIStatus | status defines the observed state of L2VNI. | Optional: {} |
L2VNISpec #
L2VNISpec defines the desired state of VNI.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
nodeSelector LabelSelector | nodeSelector specifies which nodes this L2VNI applies to.If empty or not specified, applies to all nodes.Multiple L2VNIs can match the same node. | Optional: {} | |
routingDomain RoutingDomain | routingDomain optionally attaches this L2VNI to a routing domainprovided by a backing resource (L3VNI or L3VPN). When omitted, theL2VNI is a disconnected overlay (east-west L2 only, no VRF, nogateway). | Optional: {} | |
vni integer | vni is the VXLan VNI to be used | Maximum: 1.6777215e+07 Minimum: 1 Required: {} | |
vxlanPort integer | vxlanPort is the port to be used for VXLan encapsulation. | 4789 | Optional: {} |
underlayAddressFamily string | underlayAddressFamily selects which VTEP address family to use for this VNI’sVXLAN interface. When omitted, defaults to the available family in the underlay(IPv4 preferred in dual-stack). | Enum: [IPv4 IPv6] Optional: {} | |
hostMaster HostMaster | hostMaster is the interface on the host the veth should be attached to.If not set, the host veth will not be attached to any interface and it must beattached manually (or by some other means). This is useful if another controlleris leveraging the host interface for the VNI. | Optional: {} | |
gatewayIPs string array | gatewayIPs is a list of IP addresses in CIDR notation for thedistributed anycast gateway on this L2 segment’s bridge(Integrated Routing and Bridging interface). It is a property ofthe L2 segment itself, so it lives on the L2VNI rather thaninside the routing-domain reference.Maximum of 2 addresses are allowed. If 2 addresses are provided, one must be IPv4 and one must be IPv6. | MaxItems: 2 Optional: {} |
L2VNIStatus #
VNIStatus defines the observed state of VNI.
Appears in:
L3Passthrough #
L3Passthrough represents a session with the host which is not encapsulated and takes part to the bgp fabric.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | network.openperouter.io/v1alpha1 | ||
kind string | L3Passthrough | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | Optional: {} | |
spec L3PassthroughSpec | spec defines the desired state of L3Passthrough. | Required: {} | |
status L3PassthroughStatus | status defines the observed state of L3Passthrough. | Optional: {} |
L3PassthroughSpec #
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
nodeSelector LabelSelector | nodeSelector specifies which nodes this L3Passthrough applies to.If empty or not specified, applies to all nodes.Multiple L3Passthrough with overlapping node selectors will be rejected. | Optional: {} | |
hostSession HostSession | hostSession is the configuration for the host session. | Required: {} |
L3PassthroughStatus #
L3PassthroughStatus defines the observed state of L3Passthrough.
Appears in:
L3VNI #
L3VNI represents a VXLan L3VNI to receive EVPN type 5 routes from.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | network.openperouter.io/v1alpha1 | ||
kind string | L3VNI | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | Optional: {} | |
spec L3VNISpec | spec defines the desired state of L3VNI. | Required: {} | |
status L3VNIStatus | status defines the observed state of L3VNI. | Optional: {} |
L3VNIReference #
L3VNIReference references an L3VNI by name.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
name string | name is the metadata.name of the L3VNI in the same namespace. | MinLength: 1 Required: {} |
L3VNISpec #
L3VNISpec defines the desired state of VNI.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
nodeSelector LabelSelector | nodeSelector specifies which nodes this L3VNI applies to.If empty or not specified, applies to all nodes.Multiple L3VNIs can match the same node. | Optional: {} | |
vrf string | vrf is the name of the linux VRF to be used inside the PERouter namespace. | MaxLength: 15 MinLength: 1 Pattern: ^[a-zA-Z][a-zA-Z0-9_-]*$ Required: {} | |
vni integer | vni is the VXLan VNI to be used | Maximum: 1.6777215e+07 Minimum: 1 Required: {} | |
vxlanPort integer | vxlanPort is the port to be used for VXLan encapsulation. | 4789 | Optional: {} |
underlayAddressFamily string | underlayAddressFamily selects which VTEP address family to use for this VNI’sVXLAN interface. When omitted, defaults to the available family in the underlay(IPv4 preferred in dual-stack). | Enum: [IPv4 IPv6] Optional: {} | |
hostSession HostSession | hostSession is the configuration for the host session. | Optional: {} | |
exportRTs RouteTarget array | exportRTs are the Route Targets to be used for exporting routes.RouteTarget defines a BGP Extended Community for route filtering. | MaxItems: 100 MaxLength: 21 Optional: {} | |
importRTs RouteTarget array | importRTs are the Route Targets to be used for importing routes.RouteTarget defines a BGP Extended Community for route filtering. | MaxItems: 100 MaxLength: 21 Optional: {} |
L3VNIStatus #
L3VNIStatus defines the observed state of L3VNI.
Appears in:
L3VPN #
L3VPN represents an SRv6 IP VPN.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | network.openperouter.io/v1alpha1 | ||
kind string | L3VPN | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | Optional: {} | |
spec L3VPNSpec | spec defines the desired state of L3VPN. | Required: {} | |
status L3VPNStatus | status defines the observed state of L3VPN. | Optional: {} |
L3VPNReference #
L3VPNReference references an L3VPN by name.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
name string | name is the metadata.name of the L3VPN in the same namespace. | MinLength: 1 Required: {} |
L3VPNSpec #
L3VPNSpec defines the desired state of L3VPN.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
nodeSelector LabelSelector | nodeSelector specifies which nodes this L3VPN applies to.If empty or not specified, applies to all nodes.Multiple L3VPNs can match the same node. | Optional: {} | |
vrf string | vrf is the name of the linux VRF to be used inside the PERouter namespace. | MaxLength: 15 MinLength: 1 Pattern: ^[a-zA-Z][a-zA-Z0-9_-]*$ Required: {} | |
exportRTs RouteTarget array | exportRTs are the Route Targets to be used for exporting routes.If no exportRTs are provided, defaults to single export Route Target:. | MaxItems: 100 MaxLength: 21 Optional: {} | |
importRTs RouteTarget array | importRTs are the Route Targets to be used for importing routes.importRTs must always be provided explicitly. | MaxItems: 100 MaxLength: 21 Required: {} | |
rdAssignedNumber integer | rdAssignedNumber sets the Route Distinguisher’s Assigned Number subfield.The Administrator subfield is automatically set to the value of the routerID. OpenPERouter uses Type 1 Route Distinguishers as defined in RFC4364,meaning :. | Maximum: 65535 Minimum: 1 Required: {} | |
hostSession HostSession | hostSession is the configuration for the host session. | Optional: {} |
L3VPNStatus #
L3VPNStatus defines the observed state of L3VPN.
Appears in:
LinuxBridgeConfig #
LinuxBridgeConfig contains configuration for Linux bridge type.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
lifecycle BridgeLifecycle | lifecycle determines if the bridge is managed by the controller orprovided by the user. | Enum: [Managed External] Required: {} | |
name string | name of the Linux bridge interface. Required when lifecycle isExternal, and must be omitted when it is Managed, in which case thebridge is named br-hs-. | MaxLength: 15 Pattern: ^[a-zA-Z][a-zA-Z0-9_-]*$ Optional: {} |
Neighbor #
Neighbor represents a BGP Neighbor we want FRR to connect to.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
asn integer | asn is the AS number of the neighbor. Either ASN or Type must be set. | Maximum: 4.294967295e+09 Minimum: 1 Optional: {} | |
type string | type is the AS type of the neighbor. Either ASN or Type must be set. | Enum: [External Internal] Optional: {} | |
address string | address is the IP address to establish the session with. The IP addresscan be either IPv4 or IPv6. | MaxLength: 39 MinLength: 1 Optional: {} | |
interface string | interface is the interface name for BGP unnumbered sessions. The session will be established via IPv6 link locals. | MaxLength: 15 MinLength: 1 Optional: {} | |
listenRange string | listenRange accepts connections from any peers in the specified CIDR.When set, the hostcontroller generates a“bgp listen range peer-group ” stanza instead ofan explicit neighbor statement. Mutually exclusive with address andinterface. | MaxLength: 43 MinLength: 1 Optional: {} | |
port integer | port is the port to dial when establishing the session.Defaults to 179. | Maximum: 16384 Minimum: 0 Optional: {} | |
passwordSecret SecretKeyRef | passwordSecret references a key in a Kubernetes Secret containing theBGP session password. The Secret must be created in the same namespaceas the Underlay. | Optional: {} | |
holdTimeSeconds integer | holdTimeSeconds is the requested BGP hold time in seconds, per RFC4271.Defaults to 180. | Optional: {} | |
keepaliveTimeSeconds integer | keepaliveTimeSeconds is the requested BGP keepalive time in seconds, per RFC4271.Defaults to 60. | Optional: {} | |
connectTimeSeconds integer | connectTimeSeconds controls how long BGP waits between connection attempts to a neighbor, in seconds. | Maximum: 65535 Minimum: 1 Optional: {} | |
properties NeighborProperty array | properties is the set of optional session-level features for thisneighbor (e.g. ebgpMultiHop). | MaxItems: 1 Optional: {} | |
bfd BFDSettings | bfd defines the BFD configuration for the BGP session. | Optional: {} | |
addressFamilies NeighborAddressFamily array | addressFamilies specifies the BGP address families that shall be enabledfor this BGP neighbor. evpn and ipv4vpn/ipv6vpn are mutually exclusive.If ipv4vpn or ipv6vpn are set, the update source of this neighbor willbe set to the loopback’s IPv6 address.If addressFamilies is not provided or empty, the following defaults arechosen:For unnumbered neighbors:- ipv4unicast- ipv6unicast if passthrough is configured with IPv6 local CIDR- evpn if L2VNIs or L3VNIs are present.For IPv4 neighbors:- ipv4unicast- ipv6unicast if passthrough is configured with IPv6 local CIDR- evpn if L2VNIs or L3VNIs are present.For IPv6 neighbors:- ipv4unicast if L2VNIs or L3VNIs are present, or if passthrough is configured with IPv4 local CIDR- ipv6unicast- evpn if L2VNIs or L3VNIs are present- ipv4vpn if L3VPNs and SRv6 configuration are present.- ipv6vpn if L3VPNs and SRv6 configuration are present. | MaxItems: 4 Optional: {} |
NeighborAddressFamily #
NeighborAddressFamily represents a single BGP address family configuration for a neighbor.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
type string | type is the address family type. | Enum: [ipv4unicast ipv6unicast evpn ipv4vpn ipv6vpn] MaxLength: 11 MinLength: 1 Required: {} | |
properties AddressFamilyProperty array | properties is the set of optional per-address-family features for thisneighbor (for example, marking the neighbor as a route reflector clientin this address family). | MaxItems: 8 Optional: {} |
NeighborProperty #
NeighborProperty is an optional feature applied to a neighbor session. The type field selects the property; typed sub-fields hold parameters for properties that require them.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
type NeighborPropertyType | type selects the property. | Enum: [ebgpMultiHop] Required: {} | |
ebgpMultiHop EBGPMultiHopProperties | ebgpMultiHop holds parameters for the ebgpMultiHop property.May only be set when type is ebgpMultiHop. | Optional: {} |
NeighborPropertyType #
Underlying type: string
NeighborPropertyType defines an optional feature on a Neighbor. The values are protocol / FRR configuration tokens and are kept verbatim so they map directly to the rendered stanzas.
Validation:
- Enum: [ebgpMultiHop]
Appears in:
| Field | Description |
|---|---|
ebgpMultiHop | NeighborPropertyEBGPMultiHop enables eBGP multihop on the neighborsession, rendered as “neighbor X ebgp-multihop [ttl]”. |
NetworkDevice #
NetworkDevice moves an existing host network device into the router netns.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
interfaceName string | interfaceName is the name of the host network device to move intothe router netns. | MaxLength: 15 MinLength: 1 Pattern: ^[a-zA-Z][a-zA-Z0-9._-]*$ Required: {} |
OVSBridgeConfig #
OVSBridgeConfig contains configuration for OVS bridge type.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
lifecycle BridgeLifecycle | lifecycle determines if the OVS bridge is managed by the controller orprovided by the user. | Enum: [Managed External] Required: {} | |
name string | name of the OVS bridge interface. Required when lifecycle isExternal, and must be omitted when it is Managed, in which case thebridge is named br-hs-. | MaxLength: 15 Pattern: ^[a-zA-Z][a-zA-Z0-9_-]*$ Optional: {} |
RawFRRConfig #
RawFRRConfig is the Schema for the rawfrrconfigs API.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | network.openperouter.io/v1alpha1 | ||
kind string | RawFRRConfig | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | Optional: {} | |
spec RawFRRConfigSpec | spec defines the desired state of RawFRRConfig. | Required: {} | |
status RawFRRConfigStatus | status defines the observed state of RawFRRConfig. | Optional: {} |
RawFRRConfigSpec #
RawFRRConfigSpec defines the desired state of RawFRRConfig.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
nodeSelector LabelSelector | nodeSelector specifies which nodes this RawFRRConfig applies to.If empty or not specified, applies to all nodes. | Optional: {} | |
priority integer | priority controls the ordering of raw config snippets in the rendered FRR configuration.Lower values are rendered first. Snippets with the same priority have undefined order. | 0 | Minimum: 0 Optional: {} |
rawConfig string | rawConfig is the raw FRR configuration text to append to the rendered configuration.WARNING: This feature is intended for advanced use cases. No validation of FRR syntaxis performed at admission time; invalid configuration will cause FRR reload failures. | MinLength: 1 Required: {} |
RawFRRConfigStatus #
RawFRRConfigStatus defines the observed state of RawFRRConfig.
Appears in:
RouteReflectorConfig #
RouteReflectorConfig holds BGP Route Reflector parameters (RFC 4456). Its presence on the Underlay enables route reflection on matching nodes.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
clusterID string | clusterID is the BGP cluster-id shared by all RR nodes in the samecluster (RFC 4456 §7). All RRs serving the same set of clients mustuse the same value so that CLUSTER_LIST loop detection preventsduplicate route reflection. The cluster-id is an opaque 32-bitidentifier, not a routable address, and must be outside therouterIDCIDR range to avoid colliding with allocated router-ids.The default (192.0.2.1) is an RFC 5737 documentation address,outside the default routerIDCIDR pool; with a custom routerIDCIDRthat contains it, the resource is rejected at admission. | 192.0.2.1 | MaxLength: 15 MinLength: 7 Optional: {} |
RouteTarget #
Underlying type: string
RouteTarget defines a BGP Extended Community for route filtering.
Validation:
- MaxLength: 21
Appears in:
RouterNodeConfigurationStatus #
RouterNodeConfigurationStatus describes a node router state.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | network.openperouter.io/v1alpha1 | ||
kind string | RouterNodeConfigurationStatus | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | ||
status RouterNodeConfigurationStatusStatus | status node router configuration status. | Optional: {} |
RouterNodeConfigurationStatusStatus #
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
failedResources FailedResource array | failedResources list of failed configuration resources on the node. | Optional: {} | |
conditions Condition array | conditions list of conditions. | Optional: {} |
RoutingDomain #
RoutingDomain is a discriminated union over the resource kinds that can provide a routing domain. Exactly one sub-struct must match the type discriminator.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
type string | type selects the kind of resource that provides this routing domain. | Enum: [L3VNI L3VPN] Required: {} | |
l3vni L3VNIReference | l3vni references the L3VNI (metadata.name) in the same namespace thatprovides the routing domain for this L2VNI. | Optional: {} | |
l3vpn L3VPNReference | l3vpn references the L3VPN (metadata.name) in the same namespace thatprovides the routing domain for this L2VNI. | Optional: {} |
SRV6Config #
SRV6Config contains SRV6 configuration for the underlay.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
encapBehavior SRV6EncapBehavior | encapBehavior defines the behavior for SRv6 encapsulation as specifiedin RFC 8986 sections 5.1 and 5.2.If unset, defaults to H.Encaps. | Enum: [H.Encaps H.Encaps.Red] MaxLength: 12 MinLength: 1 Optional: {} | |
locator SRV6Locator | locator defines the locator for this SRv6 VPN. | Required: {} |
SRV6EncapBehavior #
Underlying type: string
SRV6EncapBehavior defines the behavior for SRv6 encapsulation as specified in RFC 8986 sections 5.1 and 5.2.
Validation:
- Enum: [H.Encaps H.Encaps.Red]
- MaxLength: 12
- MinLength: 1
Appears in:
| Field | Description |
|---|---|
H.Encaps | HEncaps always adds an SRH to SRv6 encapsulated packets. For more details,see RFC 8986 section 5.1. |
H.Encaps.Red | HEncapsRed is an optimization of the H.Encaps behavior and reduces thelength of the SRH by excluding the first SID in the SRH of the pushedIPv6 header. The SRH is omitted when the SRv6 Policy only contains onesegment and there is no need to use any flag, tag or TLV. For moredetails, see RFC 8986 section 5.2. |
SRV6Locator #
SRV6Locator holds the configuration of a locator for SRv6.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
basePrefix string | basePrefix is the CIDR to be used for the locator, offset by the router index. | MaxLength: 43 MinLength: 1 Required: {} | |
format string | format specifies the format of the locator. Defaults to usid-f3216 | Enum: [usid-f3216] MaxLength: 40 MinLength: 1 Required: {} |
SecretKeyRef #
SecretKeyRef references a key within a Kubernetes Secret in the same namespace as the Underlay.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
name string | name is the name of the Secret in the same namespace. | MinLength: 1 Required: {} | |
key string | key is the key within the Secret’s data to select.The controller defaults this to “password” when unset. | MinLength: 1 Optional: {} |
TunnelEndpointConfig #
TunnelEndpointConfig contains tunnel endpoint configuration for the underlay.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
cidrs string array | cidrs is a list of CIDRs to be used to assign IPs to the local tunnel endpoint oneach node. IPs derived from these CIDRs will be assigned to the local loopback.At least one IPv4 or IPv6 CIDR is required. At most one of each family may be specified. | MaxItems: 2 MinItems: 1 Required: {} |
Underlay #
Underlay is the Schema for the underlays API.
| Field | Description | Default | Validation |
|---|---|---|---|
apiVersion string | network.openperouter.io/v1alpha1 | ||
kind string | Underlay | ||
metadata ObjectMeta | Refer to Kubernetes API documentation for fields of metadata. | Optional: {} | |
spec UnderlaySpec | spec defines the desired state of Underlay. | Required: {} | |
status UnderlayStatus | status defines the observed state of Underlay. | Optional: {} |
UnderlayInterface #
UnderlayInterface defines how the router obtains a single underlay link. Exactly one of the sub-structs must match the type field. The union is designed to be extended with future modes for controller-provisioned interfaces.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
type UnderlayInterfaceType | type selects how the router obtains this underlay link. | Enum: [NetworkDevice CNIDevice] Required: {} | |
networkDevice NetworkDevice | networkDevice moves an existing host network device into the router netns.The device can be of any kind (physical NIC, bridge, macvlan, etc.).Must be set when type is “NetworkDevice”. | Optional: {} | |
cniDevice CNIDevice | cniDevice invokes a CNI plugin to provision an interface in the routernetns. IPAM is delegated to the CNI plugin. Must be set when type is“CNIDevice”. | Optional: {} |
UnderlayInterfaceType #
Underlying type: string
UnderlayInterfaceType selects how the router obtains an underlay link. It is the discriminator of the UnderlayInterface union and is designed to be extended with future modes.
Validation:
- Enum: [NetworkDevice CNIDevice]
Appears in:
| Field | Description |
|---|---|
NetworkDevice | UnderlayInterfaceTypeNetworkDevice moves an existing host network deviceinto the router netns. |
CNIDevice | UnderlayInterfaceTypeCNIDevice invokes a CNI plugin to provision an interfacein the router netns. |
UnderlaySpec #
UnderlaySpec defines the desired state of Underlay.
Appears in:
| Field | Description | Default | Validation |
|---|---|---|---|
nodeSelector LabelSelector | nodeSelector specifies which nodes this Underlay applies to.If empty or not specified, applies to all nodes (backward compatible).Multiple Underlays with overlapping node selectors will be rejected. | Optional: {} | |
asn integer | asn is the local AS number to use for the session with the TOR switch. | Maximum: 4.294967295e+09 Minimum: 1 Required: {} | |
routerIDCIDR string | routerIDCIDR is the ipv4 cidr to be used to assign a different routerID on each node. | 10.0.0.0/24 | Optional: {} |
neighbors Neighbor array | neighbors is the list of external BGP neighbors to peer with.Multiple neighbors are supported for connecting to multiple TOR switchesor establishing redundant BGP sessions. Each neighbor address must be unique.At least one neighbor is required. | MaxItems: 128 MinItems: 1 Required: {} | |
interfaces UnderlayInterface array | interfaces is the list of interfaces the router uses for underlayconnectivity. Each entry is a discriminated union describing how theinterface is obtained. At least one interface is required. All theentries must be of the same type: mixing NetworkDevice and CNIDeviceinterfaces is not supported. | MinItems: 1 Required: {} | |
tunnelEndpoint TunnelEndpointConfig | tunnelEndpoint contains tunnel endpoint configuration for the underlay. | Optional: {} | |
gracefulRestart GracefulRestartConfig | gracefulRestart configures BGP Graceful Restart behaviour.When set, FRR advertises GR capability and preserves forwardingstate across restarts so that peers keep stale routes active.Omit to disable graceful restart. | Optional: {} | |
isis ISISConfig | isis holds the ISIS configuration for the underlay. | Optional: {} | |
srv6 SRV6Config | srv6 holds the SRv6 configuration. Requires ISIS or Neighbors configuration. | Optional: {} | |
routeReflector RouteReflectorConfig | routeReflector configures the local FRR process as a BGP route reflector.When set, the hostcontroller generates bgp cluster-id from clusterIDand derives bgp listen range and route-reflector-client stanzas fromneighbors with listenRange and the routeReflectorClient property.Omit to run as a standard router without route reflection. | Optional: {} |
UnderlayStatus #
UnderlayStatus defines the observed state of Underlay.
Appears in: