Skip to content

Support IPv6 addresses in the OPTE zone setup service - #11092

Draft
bnaecker wants to merge 1 commit into
mainfrom
ben/opte-setup-for-ipv6
Draft

Support IPv6 addresses in the OPTE zone setup service#11092
bnaecker wants to merge 1 commit into
mainfrom
ben/opte-setup-for-ipv6

Conversation

@bnaecker

Copy link
Copy Markdown
Collaborator
  • Add the new --create-v6 parameter to the zone-setup binary for setting up OPTE ports in a service zone. Also adds stronger types around IPv4 addresses for the gateway / private IP arguments. Includes a number of tests for those types, and all combinations of arguments we could provide.
  • Ensure we create both IPv4 and IPv6 DHCP address objects in the current zone, depending on how the SMF properties are set. These properties are now set in the sled-agent for both IPv4 and IPv6.
  • Move the code from the RunningZone which does the route(8) shenanigans to work around stlouis#326 (setting up a default route to the OPTE virtual gateway), and which also waits for the DHCPv6 address on the link. This was all duplicated, and moving it here means we can delete the workaround in one place in the future.

@bnaecker
bnaecker marked this pull request as draft August 14, 2026 21:56
- Add the new `--create-v6` parameter to the `zone-setup` binary for
  setting up OPTE ports in a service zone. Also adds stronger types
  around IPv4 addresses for the gateway / private IP arguments. Includes
  a number of tests for those types, and all combinations of arguments
  we could provide.
- Ensure we create both IPv4 and IPv6 DHCP address objects in the
  current zone, depending on how the SMF properties are set. These
  properties are now set in the sled-agent for both IPv4 and IPv6.
- Move the code from the `RunningZone` which does the `route(8)`
  shenanigans to work around stlouis#326 (setting up a default route to
  the OPTE virtual gateway), and which also waits for the DHCPv6
  address on the link. This was all duplicated, and moving it here means
  we can delete the workaround in one place in the future.
@bnaecker
bnaecker force-pushed the ben/opte-setup-for-ipv6 branch from 0f84ff4 to 2e55f4d Compare August 19, 2026 03:22
@sion42x

sion42x commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

The results look fairly good on Madrid with the Juniper backend providing NTP and BGP over IPv6. Obviously not a complete end-to-end, but promising.

[BRM42220081]root@oxz_switch0:~# swadm addr list
Link      IPv4  IPv6
int0/0          fdb1:a840:2504:3d2::1
                fdb2:a840:2504:3d2::1
                fe80::aa40:25ff:fe05:102
rear0/0         fe80::aa40:25ff:fe05:103
rear1/0         fe80::aa40:25ff:fe05:104
rear2/0         fe80::aa40:25ff:fe05:105
rear3/0         fe80::aa40:25ff:fe05:106
rear4/0         fe80::aa40:25ff:fe05:107
rear5/0         fe80::aa40:25ff:fe05:108
rear6/0         fe80::aa40:25ff:fe05:109
rear7/0         fe80::aa40:25ff:fe05:10a
rear8/0         fe80::aa40:25ff:fe05:10b
rear9/0         fe80::aa40:25ff:fe05:10c
rear10/0        fe80::aa40:25ff:fe05:10d
rear11/0        fe80::aa40:25ff:fe05:10e
rear12/0        fe80::aa40:25ff:fe05:10f
rear13/0        fe80::aa40:25ff:fe05:110
rear14/0        fe80::aa40:25ff:fe05:111
rear15/0        fe80::aa40:25ff:fe05:112
rear16/0        fe80::aa40:25ff:fe05:113
rear17/0        fe80::aa40:25ff:fe05:114
rear18/0        fe80::aa40:25ff:fe05:115
rear19/0        fe80::aa40:25ff:fe05:116
rear20/0        fe80::aa40:25ff:fe05:117
rear21/0        fe80::aa40:25ff:fe05:118
rear22/0        fe80::aa40:25ff:fe05:119
rear23/0        fe80::aa40:25ff:fe05:11a
rear24/0        fe80::aa40:25ff:fe05:11b
rear25/0        fe80::aa40:25ff:fe05:11c
rear26/0        fe80::aa40:25ff:fe05:11d
rear27/0        fe80::aa40:25ff:fe05:11e
rear28/0        fe80::aa40:25ff:fe05:11f
rear29/0        fe80::aa40:25ff:fe05:120
rear30/0        fe80::aa40:25ff:fe05:121
rear31/0        fe80::aa40:25ff:fe05:122
qsfp31/0        fe80::aa40:25ff:fe05:19f
loopback  fd71:1ffd:9277:72da::1
[BRM42220081]root@oxz_switch0:~# swadm route ls
Subnet                   Port    Link  Gateway                   Vlan
::/0                     qsfp31  0     fe80::46f4:77ff:feb1:737  
2001:db8:100::3/128      qsfp31  0     fe80::46f4:77ff:feb1:737  
fd04:35e4:ee08:1::/64    rear17  0     fe80::aa40:25ff:fe04:157  
fd04:35e4:ee08:2::/64    rear16  0     fe80::aa40:25ff:fe04:2d7  
fd04:35e4:ee08:3::/64    rear15  0     fe80::aa40:25ff:fe04:396  
fd04:35e4:ee08:101::/64  rear17  0     fe80::aa40:25ff:fe04:157  
fd04:35e4:ee08:102::/64  rear16  0     fe80::aa40:25ff:fe04:2d7  
fd04:35e4:ee08:103::/64  rear15  0     fe80::aa40:25ff:fe04:396  
fd04:35e4:ee08:104::/64  rear14  0     fe80::aa40:25ff:fe04:3d2  
fdb0:a840:2504:157::/64  rear17  0     fe80::aa40:25ff:fe04:157  
fdb0:a840:2504:2d7::/64  rear16  0     fe80::aa40:25ff:fe04:2d7  
fdb0:a840:2504:396::/64  rear15  0     fe80::aa40:25ff:fe04:396  
fdb0:a840:2504:3d2::/64  rear14  0     fe80::aa40:25ff:fe04:3d2  
root@asilomar-juniper> ...ch "Peer:|Local:|NLRI for this session"

Peer: fe80::1efd:8ff:fe78:c8df%xe-0/0/0.0 AS 0 Local: fe80::46f4:77ff:feb1:703%xe-0/0/0.0 AS 99
Peer: fe80::aa40:25ff:fe05:19f%et-0/0/49.0+53682 AS 47 Local: fe80::46f4:77ff:feb1:737%et-0/0/49.0+179 AS 99
  NLRI for restart configured on peer: inet6-unicast
  NLRI advertised by peer: inet-unicast inet6-unicast
  NLRI for this session: inet6-unicast
Peer: fe80::aa40:25ff:fe05:65f%et-0/0/48.0+53237 AS 47 Local: fe80::46f4:77ff:feb1:733%et-0/0/48.0+179 AS 99
  NLRI for restart configured on peer: inet6-unicast
  NLRI advertised by peer: inet-unicast inet6-unicast
  NLRI for this session: inet6-unicast

[BRM42220081]root@oxz_switch0:~# mgadm bgp status neighbors 47
Peer Address    Peer ASN  State        State Duration  Hold           Keepalive
tfportqsfp31_0  Some(99)  Established  2m 12s 183ms    6s 0ms/6s 0ms  2s 0ms/2s 0ms
[BRM42220081]root@oxz_switch0:~# omdb db network list-eips
note: database URL not specified.  Will search DNS.
note: (override with --db-url or OMDB_DB_URL)
note: using DNS from system config (typically /etc/resolv.conf)
note: (if this is not right, use --dns-server to specify an alternate DNS server)
note: using database URL postgresql://root@[fd04:35e4:ee08:104::3]:32221,[fd04:35e4:ee08:102::3]:32221,[fd04:35e4:ee08:104::4]:32221,[fd04:35e4:ee08:103::3]:32221,[fd04:35e4:ee08:101::3]:32221/omicron?sslmode=disable
note: database schema version matches expected (287.0.0)
 IP                PORTS        KIND      STATE     OWNER_KIND  OWNER_ID                              OWNER_NAME   OWNER_DISPOSITION 
 fd47:110::20/128  0/65535      floating  Attached  service     7fcfbff5-292d-4a0e-bd48-cf4c5d558e6a  ExternalDns  in service        
 fd47:110::21/128  0/65535      floating  Attached  service     d6536534-2a01-483c-b1cd-fd8b5f1c68b9  ExternalDns  in service        
 fd47:110::22/128  0/65535      floating  Attached  service     bf7b4c43-dc5c-40a7-91be-1e35b6f35a99  Nexus        in service        
 fd47:110::23/128  0/65535      floating  Attached  service     325a7a48-0d05-40d1-9459-f22b2cbbbb25  Nexus        in service        
 fd47:110::24/128  0/65535      floating  Attached  service     ee001704-23b4-4865-9baf-901c0e6241f1  Nexus        in service        
 fd47:110::25/128  16384/32767  SNAT      Attached  service     0419fd6e-890a-4343-adea-f6fb872819bd  Ntp          in service        
 fd47:110::25/128  0/16383      SNAT      Attached  service     b37460b4-7623-4beb-9f26-ac8444436af6  Ntp          in service   

@sion42x

sion42x commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

I started with v22rc1 in an IPv4 configuration and did an operator system update to this PR:

[madrid]root@oxz_switch0:~# swadm addr list
Link      IPv4          IPv6
int0/0                  fdb1:a840:2504:3d2::1
                        fdb2:a840:2504:3d2::1
                        fe80::aa40:25ff:fe05:102
rear0/0                 fe80::aa40:25ff:fe05:103
rear1/0                 fe80::aa40:25ff:fe05:104
rear2/0                 fe80::aa40:25ff:fe05:105
rear3/0                 fe80::aa40:25ff:fe05:106
rear4/0                 fe80::aa40:25ff:fe05:107
rear5/0                 fe80::aa40:25ff:fe05:108
rear6/0                 fe80::aa40:25ff:fe05:109
rear7/0                 fe80::aa40:25ff:fe05:10a
rear8/0                 fe80::aa40:25ff:fe05:10b
rear9/0                 fe80::aa40:25ff:fe05:10c
rear10/0                fe80::aa40:25ff:fe05:10d
rear11/0                fe80::aa40:25ff:fe05:10e
rear12/0                fe80::aa40:25ff:fe05:10f
rear13/0                fe80::aa40:25ff:fe05:110
rear14/0                fe80::aa40:25ff:fe05:111
rear15/0                fe80::aa40:25ff:fe05:112
rear16/0                fe80::aa40:25ff:fe05:113
rear17/0                fe80::aa40:25ff:fe05:114
rear18/0                fe80::aa40:25ff:fe05:115
rear19/0                fe80::aa40:25ff:fe05:116
rear20/0                fe80::aa40:25ff:fe05:117
rear21/0                fe80::aa40:25ff:fe05:118
rear22/0                fe80::aa40:25ff:fe05:119
rear23/0                fe80::aa40:25ff:fe05:11a
rear24/0                fe80::aa40:25ff:fe05:11b
rear25/0                fe80::aa40:25ff:fe05:11c
rear26/0                fe80::aa40:25ff:fe05:11d
rear27/0                fe80::aa40:25ff:fe05:11e
rear28/0                fe80::aa40:25ff:fe05:11f
rear29/0                fe80::aa40:25ff:fe05:120
rear30/0                fe80::aa40:25ff:fe05:121
rear31/0                fe80::aa40:25ff:fe05:122
qsfp0/0   172.20.15.37  
loopback  fdcc:fd9b:d746:346::1
[madrid]root@oxz_switch0:~# swadm route ls
Subnet                   Port    Link  Gateway                   Vlan
0.0.0.0/0                qsfp0   0     172.20.15.35              
fd07:8292:e2bd:1::/64    rear17  0     fe80::aa40:25ff:fe04:157  
fd07:8292:e2bd:2::/64    rear16  0     fe80::aa40:25ff:fe04:2d7  
fd07:8292:e2bd:3::/64    rear15  0     fe80::aa40:25ff:fe04:396  
fd07:8292:e2bd:101::/64  rear17  0     fe80::aa40:25ff:fe04:157  
fd07:8292:e2bd:102::/64  rear16  0     fe80::aa40:25ff:fe04:2d7  
fd07:8292:e2bd:103::/64  rear15  0     fe80::aa40:25ff:fe04:396  
fd07:8292:e2bd:104::/64  rear14  0     fe80::aa40:25ff:fe04:3d2  
fdb0:a840:2504:157::/64  rear17  0     fe80::aa40:25ff:fe04:157  
fdb0:a840:2504:2d7::/64  rear16  0     fe80::aa40:25ff:fe04:2d7  
fdb0:a840:2504:396::/64  rear15  0     fe80::aa40:25ff:fe04:396  
fdb0:a840:2504:3d2::/64  rear14  0     fe80::aa40:25ff:fe04:3d2 
[madrid]root@oxz_switch0:~# omdb db network list-eips
note: database URL not specified.  Will search DNS.
note: (override with --db-url or OMDB_DB_URL)
note: using DNS from system config (typically /etc/resolv.conf)
note: (if this is not right, use --dns-server to specify an alternate DNS server)
note: using database URL postgresql://root@[fd07:8292:e2bd:104::3]:32221,[fd07:8292:e2bd:102::3]:32221,[fd07:8292:e2bd:104::4]:32221,[fd07:8292:e2bd:101::3]:32221,[fd07:8292:e2bd:103::3]:32221/omicron?sslmode=disable
note: database schema version matches expected (287.0.0)
 IP               PORTS        KIND      STATE     OWNER_KIND  OWNER_ID                              OWNER_NAME   OWNER_DISPOSITION 
 172.20.35.1/32   0/65535      floating  Attached  service     c7f55ea8-dd5b-49e5-9ae8-470e0190b308  ExternalDns  in service        
 172.20.35.2/32   0/65535      floating  Attached  service     afe311e1-77be-49e7-a107-f686baac0e4c  ExternalDns  in service        
 172.20.35.3/32   0/65535      floating  Attached  service     8cc6ef56-575f-4786-843a-5d1516912df4  ExternalDns  in service        
 172.20.35.7/32   16384/32767  SNAT      Attached  service     527ea8e8-bbaf-440d-a46f-b1e8cd2a416a  Ntp          in service        
 172.20.35.7/32   0/16383      SNAT      Attached  service     8801ac0a-e3d5-43ca-afcd-486bd003ff4c  Ntp          in service        
 172.20.35.8/32   0/65535      floating  Attached  service     19c50002-c6ff-4976-852a-f4c6e36d7c3f  Nexus        in service        
 172.20.35.9/32   0/65535      floating  Attached  service     3ec7910e-5f9e-4a50-9775-d46636c2b7d7  Nexus        in service        
 172.20.35.10/32  0/65535      floating  Attached  service     ea190c46-2091-4336-9909-4edf437a9469  Nexus        in service      

On first glance, all looks good and proper and console comes up successfully.

image

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants