summaryrefslogtreecommitdiff
path: root/src/conf_mode
AgeCommit message (Collapse)Author
2025-12-04vpp: T7972: Make `nat44 no-forwarding` feature automatically configurableNataliia Solomko
If any dynamic rule is configured forwarding should be disabled because each packet must be processed through the NAT session table to apply proper translations
2025-12-04salt: T8056: add a deprecation warningDaniil Baturin
2025-12-01T8030: VPP: Check support for changed driver tooNataliia Solomko
2025-11-28Merge pull request #4824 from alexandr-san4ez/T4251-currentViacheslav Hletenko
syslog: T4251: Rename "permitted-peers" to "permitted-peer" and improve TLS checks
2025-11-27Merge pull request #4868 from natali-rs1985/T8036Daniil Baturin
vpp: T8036: Commit fails removing nat44 static rule
2025-11-26Merge pull request #4869 from c-po/T8034Christian Breunig
frr: T8034: use dict_search() for routing protocols to check if VRF is used
2025-11-25frr: T8034: use dict_search() for routing protocols to check if VRF is usedChristian Breunig
dict_search() is save when passing in keys that do not exist in the dict we are working on.
2025-11-25Merge pull request #4860 from sarthurdev/ping-checkJohn Estabrook
kea: T7913: Fixes for ping-check handling
2025-11-25vpp: T8036: Commit fails removing nat44 static ruleNataliia Solomko
2025-11-24Merge pull request #4672 from apschultz/zone_default_firewall_rulesetSimon
firewall: T7739: Default ruleset for firewall zones
2025-11-24Merge pull request #4861 from c-po/bond-member-mtuChristian Breunig
bond: T8023: validate member interface min/max MTU
2025-11-21bond: T8023: validate member interface min/max MTUChristian Breunig
It is impossible to set the bond interface MTU to be larger or lower then the limits of the underlaying interface MTU. Add proper commit validation and smoketest.
2025-11-20kea: T7913: Fixes for ping-check handlingsarthurdev
- Kea docs state multi-threaded mode is required for ping checking. - Parent scope needs enabling if shared-network/subnet has ping-check enabled.
2025-11-19login: T8024: show user warning for unconfigured TACACS source-addressChristian Breunig
Add a commit-time check and warning to the user if the TACACS source-address is not configured on the system or the given VRF.
2025-11-19login: T8024: show user warning for unconfigured RADIUS source-addressChristian Breunig
Add a commit-time check and warning to the user if the RADIUS source-address (IPv4 or IPv6) is not configured on the system or the given VRF.
2025-11-19login: T8024: fix typo in TACACS error message if all servers are disabledChristian Breunig
2025-11-19Merge pull request #4854 from c-po/veth-fixViacheslav Hletenko
veth: T8017: bugfix KeyError: 'peer_name'
2025-11-19Merge pull request #4850 from sever-sever/T8012Christian Breunig
T8012: Add user vpp to user groups
2025-11-19T8012: Add user vpp to user groupsViacheslav Hletenko
To allow call VPP api without sudo - Get op-mode commands without sudo - Use API call in smoke-tests
2025-11-18Merge pull request #4845 from vyos/T7556Daniil Baturin
T7556: VPP add IPFIX collector configuration
2025-11-18veth: T8017: bugfix KeyError: 'peer_name'Christian Breunig
Use safe dict_search() function to locate veth peer interface name. If no peer is defined an error will be displayed.
2025-11-14T7556: VPP add IPFIX collector configurationViacheslav Hletenko
Add VPP IPFIX configuration commands: ``` set vpp ipfix active-timeout '8' set vpp ipfix collector 192.0.2.2 port '2055' set vpp ipfix collector 192.0.2.2 source-address '192.0.2.1' set vpp ipfix flowprobe-record 'l2' set vpp ipfix flowprobe-record 'l3' set vpp ipfix flowprobe-record 'l4' set vpp ipfix inactive-timeout '32' set vpp ipfix interface eth0 set vpp ipfix interface eth1 direction 'both' set vpp ipfix interface eth1 flow-variant 'ipv4' ```
2025-11-13T7950: VPP: Unexpected None interface in CGNAT when ethernet subinterface is ↵Nataliia Solomko
removed from vif Do not allow to delete subinterface if it is in use in VPP features
2025-11-13Merge pull request #4835 from natali-rs1985/T7731Nataliia S.
T7731: Static ARP entries are missing after an interface status change
2025-11-12T7731: Static ARP entries are missing after an interface status changeNataliia Solomko
2025-11-10T8003: Add early kernel panic reboot supportGrant Slater
2025-11-10T7982: container: generate run arguments onceNicolas Vollmar
2025-11-05firewall: T7112: Default action drop failsOleksandr Kuchmystyi
Prevent `KeyError` by safely handling missing 'member' dict in zone config. Add smoketest to verify commit fails gracefully when zone has no interfaces.
2025-11-04Merge pull request #4828 from c-po/restart-container-vrfViacheslav Hletenko
container: T7305: fix VRF loss when restarting pods
2025-11-04Merge pull request #4829 from c-po/pki-t7976Christian Breunig
pki: T7976: calls to node_changed_presence() must use unmangled config paths
2025-11-04Merge pull request #4747 from natali-rs1985/T7789Nataliia S.
T7789: T7661: VPP prevent failing to load XDP in clouds (ena/gve drivers)
2025-11-03container: T7305: fix VRF loss when restarting podsChristian Breunig
Container networks are only started when there is at least one active consumer. If a network is created without any attached containers, it does not need to be assigned to a VRF yet. When the last container in a pod is stopped, its associated container network is removed. Upon container restart, the kernel recreates the network, but the VRF assignment may be lost in the process. This change ensures that all container networks are correctly reattached to their designated VRFs when a pod restarts.
2025-11-03Merge pull request #4808 from natali-rs1985/T7949Daniil Baturin
T7949: VPP add the ability to configure bond subinterfaces for NAT
2025-11-02pki: T7976: calls to node_changed_presence() must use unmangled config pathsChristian Breunig
We do use mangled config paths where pki = conf.get_config_dict(base, key_mangling=('-', '_'), ... returns a config dict where "-" is replaced by "_" when assembling the config dict keys. This does not work when we throw the retrieved path into ConfigDiff().node_changed_presence() https://github.com/vyos/vyos-1x/blob/07936657062c/src/conf_mode/pki.py#L259-L265 Add orig_path key which is preferred over path.
2025-11-01Merge pull request #4820 from c-po/certbot-fixesChristian Breunig
pki: T7953: implement certbot_renew() function to have everything at one place
2025-10-31T7789: T7661: VPP prevent failing to set XDP driver on cloudsNataliia Solomko
Some cloud NICs (ena, gve) fail to load XDP if all RX queues are configured. To avoid this, we limit the number of queues to half of the maximum supported by the driver.
2025-10-31syslog: T4251: Rename "permitted-peers" to "permitted-peer" and improve TLS ↵Oleksandr Kuchmystyi
checks - Renamed `permitted-peers` to `permitted-peer` across templates, schema, and tests. - Added support for multiple `permitted-peer` entries and trimmed empty values. - Replaced TLS/UDP warning with ConfigError for strict validation. - Updated tests to use TCP for TLS and verified new validation logic.
2025-10-30Merge pull request #4813 from natali-rs1985/T7797Daniil Baturin
T7797: VPP: switching from XDP to DPDK driver fails in cloud vm (hv_netvsc)
2025-10-30Merge pull request #4702 from nvollmar/T6686Daniil Baturin
T6686: adds container health checks
2025-10-29pki: T7953: implement certbot_renew() function to have everything at one placeChristian Breunig
2025-10-29Merge pull request #4812 from c-po/pki-certbot-fixesChristian Breunig
pki: T7953: refactor internal dependency generation
2025-10-29Merge pull request #4810 from bl0way/T7896-frr-profileChristian Breunig
T7896: Add frr profile selection
2025-10-29frr: T7896: Configure frr profile with 'system frr profile' commandbl0way
Co-authored-by: Christian Breunig <christian@breunig.cc>
2025-10-28dhcp-server: T3936: fix indent typoJohn Estabrook
2025-10-28dhcp-server: T3936: Added support for DHCP Option 82 (#4665)cblackburn-igl
* dhcp-server: T3936: Added support for DHCP Option 82 This commit adds support in both the CLI and the underlying code for DHCP Option 82 to be used to filter/route DHCP address assignments. The primary use case for this is to support enterprise switches which can "tag" DHCP requests with physical real world informaiton such as which switch first saw the request and which port it originated from (known in this context as remote-id and circuit-id). Once client-classes have been defined they can be assigned to subnets or ranges so that only certain addresses get assigned to specific requests. There is also a corresponding documentation update which pairs with this code change. (cherry picked from commit 326b5e713cb363a2b9f69e2204c4ee2ccd9939bb) * Update src/conf_mode/service_dhcp-server.py Co-authored-by: Nataliia S. <81954790+natali-rs1985@users.noreply.github.com> * Update src/conf_mode/service_dhcp-server.py Co-authored-by: Nataliia S. <81954790+natali-rs1985@users.noreply.github.com> * Update interface-definitions/include/dhcp/dhcp-server-common-config.xml.i Co-authored-by: Nataliia S. <81954790+natali-rs1985@users.noreply.github.com> --------- Co-authored-by: Daniil Baturin <daniil@baturin.org> Co-authored-by: Nataliia S. <81954790+natali-rs1985@users.noreply.github.com>
2025-10-28Merge pull request #4796 from natali-rs1985/T7938Daniil Baturin
T7938: VPP: Rewrite sFlow implementation
2025-10-27T7797: VPP: switching from XDP to DPDK driver fails in cloud vm (hv_netvsc)Nataliia Solomko
2025-10-26pki: T7953: reword inline commentsChristian Breunig
2025-10-26pki: T7953: certbot_request() should return NoneChristian Breunig
2025-10-26pki: T7953: use dict_set_nested() over manually assembly of dict dataChristian Breunig