Editing a secondary network
To update network settings or change network parameters for a secondary network in OpenShift Container Platform, you can modify the configuration for an existing secondary network. Edit the NetworkAttachmentDefinition custom resource to apply your changes.
Modify a NetworkAttachmentDefinition custom resource
To update network settings or change network parameters for a secondary network in OpenShift Container Platform, you can modify the NetworkAttachmentDefinition custom resource. Edit the Cluster Network Operator CR to apply your changes.
Prerequisites
- You have configured a secondary network for your cluster.
- Install the OpenShift CLI (
oc). - Log in as a user with
cluster-adminprivileges.
Procedure
-
Edit the Cluster Network Operator (CNO) CR in your default text editor by running the following command:
$ oc edit networks.operator.openshift.io cluster -
In the
additionalNetworkscollection, update the secondary network with your changes. -
Save your changes and quit the text editor to commit your changes.
-
Optional: Confirm that the CNO updated the
NetworkAttachmentDefinitionobject by running the following command. Replace<network_name>with the name of the secondary network to display. There might be a delay before the CNO updates theNetworkAttachmentDefinitionobject to reflect your changes.$ oc get network-attachment-definitions <network_name> -o yamlFor example, the following console output displays a
NetworkAttachmentDefinitionobject that is namednet1:$ oc get network-attachment-definitions net1 -o go-template='{{printf "%s\n" .spec.config}}'{ "cniVersion": "0.3.1", "type": "macvlan","master": "ens5","mode": "bridge","ipam": {"type":"static","routes":[{"dst":"0.0.0.0/0","gw":"10.128.2.1"}],"addresses":[{"address":"10.128.2.100/23","gateway":"10.128.2.1"}],"dns":{"nameservers":["172.30.0.10"],"domain":"us-west-2.compute.internal","search":["us-west-2.compute.internal"]}} }
Use an OVN-Kubernetes localnet topology to map VLANs to a secondary interface
You can use OVN-Kubernetes localnet topology in a NetworkAttachmentDefinition (NAD) to map a specific VLAN ID from the physical network to the secondary interface of a pod.
To provide multiple VLANs for cluster workloads in OpenShift Container Platform, define additional VLANs in the NetworkAttachmentDefinition custom resource (CR). Configuring trunk ports ensures that the physical network associates correctly with your virtual infrastructure for reliable traffic management.
The example in the procedure demonstrates the following configurations:
- Physical switch ports connect to OpenShift Container Platform nodes by using VLAN trunking. The trunk carries tagged traffic for the VLANs you define in NADs.
- The
br-exacts as the OVS bridge that connects virtual workloads to the physical workloads. - Multiple NADs with specific VLAN tags get created by using the
localnettopology. This configuration defines specific VLAN IDs for traffic isolation. - Pods or virtual machines (VMs) attach to the NAD CRs for the purposes of improved network connectivity.
Prerequisites
- You installed the OpenShift CLI (
oc). - You logged in as a user with
cluster-adminprivileges. - You installed the NMState Operator.
- You configured the
br-exbridge interface during cluster installation.
Procedure
-
Create an
NetworkAttachmentDefinitionCR for each VLAN, such asnad-cvlan100.yaml. OVN-Kubernetes uses the NAD files to tag and untag Ethernet frames for pods or VMs.Example configurationapiVersion: k8s.cni.cncf.io/v1kind: NetworkAttachmentDefinitionmetadata:name: vlan-100namespace: defaultspec:config: |-{"cniVersion": "0.4.0","name": "localnet-vlan-100","type": "ovn-k8s-cni-overlay","physicalNetworkName": "physnet","topology": "localnet","vlanID": 100,"mtu": 1500,"netAttachDefName": "default/vlan-100"}# ... -
Attach pods or VMs to the VLANs by referencing the NAD in the configuration for the pod or VM:
Example pod configurationapiVersion: v1kind: Podmetadata:annotations:k8s.v1.cni.cncf.io/networks: vlan-100# ...Example VM configurationapiVersion: kubevirt.io/v1kind: VirtualMachinespec:template:spec:networks:- multus:networkName: vlan-100name: secondary-vlan# ...