Paul Fisher 4779f1d2bf ipvlan: support enslaving an interface returned by ipam
For IP allocation schemes that cannot be interface agnostic, master can be set
to "ipam". In this configuration, the IPAM plugin is required to return a single
interface name for the ipvlan plugin to enslave.
2017-11-01 10:14:04 -07:00

1.8 KiB

ipvlan plugin

Overview

ipvlan is a new addition to the Linux kernel. Like its cousin macvlan, it virtualizes the host interface. However unlike macvlan which generates a new MAC address for each interface, ipvlan devices all share the same MAC. The kernel driver inspects the IP address of each packet when making a decision about which virtual interface should process the packet.

Because all ipvlan interfaces share the MAC address with the host interface, DHCP can only be used in conjunction with ClientID (currently not supported by DHCP plugin).

Example configuration

{
	"name": "mynet",
	"type": "ipvlan",
	"master": "eth0",
	"ipam": {
		"type": "host-local",
		"subnet": "10.1.2.0/24"
	}
}

Network configuration reference

  • name (string, required): the name of the network.
  • type (string, required): "ipvlan".
  • master (string, required): name of the host interface to enslave or "ipam" to enslave an interface returned by ipam.
  • mode (string, optional): one of "l2", "l3". Defaults to "l2".
  • mtu (integer, optional): explicitly set MTU to the specified value. Defaults to the value chosen by the kernel.
  • ipam (dictionary, required): IPAM configuration to be used for this network.

Notes

  • ipvlan does not allow virtual interfaces to communicate with the master interface. Therefore the container will not be able to reach the host via ipvlan interface. Be sure to also have container join a network that provides connectivity to the host (e.g. ptp).
  • A single master interface can not be enslaved by both macvlan and ipvlan.
  • For IP allocation schemes that cannot be interface agnostic, master can be set to ipam. In this configuration, the ipam plugin is required to return a single interface name for the ipvlan plugin to enslave.