Connecting a virtual machine to an OVN-Kubernetes layer 2 secondary network
You can connect a virtual machine (VM) to an OVN-Kubernetes custom secondary overlay network. You can use this overlay network to connect VMs on different nodes, without configuring any additional physical networking infrastructure.
An OVN-Kubernetes secondary network is compatible with the multi-network policy API which provides the MultiNetworkPolicy custom resource definition (CRD) to control traffic flow to and from VMs. You must use the ipBlock attribute to define network policy ingress and egress rules for specific CIDR blocks. You cannot use pod or namespace selectors for virtualization workloads.
A layer 2 topology connects workloads by a cluster-wide logical switch. The OVN-Kubernetes Container Network Interface (CNI) plugin uses the Geneve (Generic Network Virtualization Encapsulation) protocol to create an overlay network between nodes.
To configure an OVN-Kubernetes layer 2 secondary network and attach a VM to that network, perform the following steps:
- Define the secondary network
- Attach the VM to the secondary network
Configuring IP address management (IPAM) by specifying the spec.config.ipam.subnet attribute in a network attachment definition for virtual machines is not supported.
Creating a NAD for layer 2 topology by using the CLI
You can create a network attachment definition (NAD) which describes how to attach a pod to the layer 2 overlay network.
Prerequisites
- You have access to the cluster as a user with
cluster-adminprivileges. - You have installed the OpenShift CLI (
oc).
Procedure
-
Create a
NetworkAttachmentDefinitionobject:apiVersion: k8s.cni.cncf.io/v1kind: NetworkAttachmentDefinitionmetadata:name: l2-networknamespace: my-namespacespec:config: |-{"cniVersion": "0.3.1","name": "my-namespace-l2-network","type": "ovn-k8s-cni-overlay","topology":"layer2","mtu": 1400,"netAttachDefName": "my-namespace/l2-network"}-
spec.config.cniVersiondefines the Container Network Interface (CNI) specification version. The required value is0.3.1. -
spec.config.namedefines the name of the network. This attribute is not namespaced. For example, you can have a network namedl2-networkreferenced from two differentNetworkAttachmentDefinitionobjects that exist in two different namespaces. This feature is useful to connect VMs in different namespaces. -
spec.config.typedefines the name of the CNI plugin. The required value isovn-k8s-cni-overlay. -
spec.config.topologydefines the topological configuration for the network. The required value islayer2. -
spec.config.mtuis optional and defines the maximum transmission unit (MTU) value. If you do not set a value, the Cluster Network Operator (CNO) sets a default MTU value by calculating the difference among the underlay MTU of the primary network interface, the overlay MTU of the pod network, such as the Geneve (Generic Network Virtualization Encapsulation), and byte capacity of any enabled features, such as IPsec. -
spec.config.netAttachDefNamedefines the value of thenamespaceandnamefields in themetadatastanza of theNetworkAttachmentDefinitionobject.noteThe previous example configures a cluster-wide overlay without a subnet defined. This means that the logical switch implementing the network only provides layer 2 communication. You must configure an IP address when you create the virtual machine by either setting a static IP address or by deploying a DHCP server on the network for a dynamic IP address.
-
-
Apply the manifest by running the following command:
$ oc apply -f <filename>.yaml
Creating a NAD for layer 2 topology by using the web console
You can create a network attachment definition (NAD) that describes how to attach a pod to the layer 2 overlay network.
Prerequisites
- You have access to the cluster as a user with
cluster-adminprivileges.
Procedure
- Go to Networking → NetworkAttachmentDefinitions in the web console.
- Click Create Network Attachment Definition. The network attachment definition must be in the same namespace as the pod or virtual machine using it.
- Enter a unique Name and optional Description.
- Select OVN Kubernetes L2 overlay network from the Network Type list.
- Click Create.
Attaching a virtual machine to an OVN-Kubernetes secondary network using the CLI
You can connect a virtual machine (VM) to the OVN-Kubernetes secondary network by including the network details in the VM configuration.
Prerequisites
- You have access to the cluster as a user with
cluster-adminprivileges. - You have installed the OpenShift CLI (
oc).
Procedure
-
Edit the
VirtualMachinemanifest to add the OVN-Kubernetes secondary network interface details, as in the following example:apiVersion: kubevirt.io/v1kind: VirtualMachinemetadata:name: vm-serverspec:runStrategy: Alwaystemplate:spec:domain:devices:interfaces:- name: secondarybridge: {}resources:requests:memory: 1024Minetworks:- name: secondarymultus:networkName: <nad_name>nodeSelector:node-role.kubernetes.io/worker: ''# ...spec.template.spec.domain.devices.interfaces.namespecifies the name of the OVN-Kubernetes secondary interface.spec.template.spec.networks.namespecifies the name of the network. This must match the value of thespec.template.spec.domain.devices.interfaces.namefield.spec.template.spec.networks.multus.networkNamespecifies the name of theNetworkAttachmentDefinitionobject.spec.template.spec.nodeSelectorspecifies the nodes on which the VM can be scheduled. The recommended node selector value isnode-role.kubernetes.io/worker: ''.
-
Apply the
VirtualMachinemanifest:$ oc apply -f <filename>.yaml -
Optional: If you edited a running virtual machine, you must restart it for the changes to take effect.
Additional resources