<feed xmlns='http://www.w3.org/2005/Atom'>
<title>vyos-documentation.git, branch T9456-container-kernel-overlayfs</title>
<subtitle>VyOS readthedocs (mirror of https://github.com/vyos/vyos-documentation.git)
</subtitle>
<id>https://git.amelek.net/vyos/vyos-documentation.git/atom?h=T9456-container-kernel-overlayfs</id>
<link rel='self' href='https://git.amelek.net/vyos/vyos-documentation.git/atom?h=T9456-container-kernel-overlayfs'/>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-documentation.git/'/>
<updated>2026-10-11T07:34:37+00:00</updated>
<entry>
<title>container: T9453: explain migration to kernel overlayfs from fuse-overlayfs</title>
<updated>2026-10-11T07:34:37+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-10-11T07:34:37+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-documentation.git/commit/?id=6fb26907c617758fe2f27546b7a50d0f0da5aada'/>
<id>urn:sha1:6fb26907c617758fe2f27546b7a50d0f0da5aada</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Merge pull request #2337 from mandelbitdev/T9386-openvpn-shared-secret-aead</title>
<updated>2026-10-10T15:49:56+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-10-10T15:49:56+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-documentation.git/commit/?id=f03c3e5f737bdcdd8d2a4e2d21147de9032bdbdb'/>
<id>urn:sha1:f03c3e5f737bdcdd8d2a4e2d21147de9032bdbdb</id>
<content type='text'>
T9386: openvpn: AEAD fallback ciphers can't be used with shared-secret-key</content>
</entry>
<entry>
<title>openvpn: T9386: AEAD fallback ciphers can't be used with shared-secret-key</title>
<updated>2026-10-09T13:41:29+00:00</updated>
<author>
<name>Antonio Quartulli</name>
<email>antonio@mandelbit.com</email>
</author>
<published>2026-10-01T13:45:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-documentation.git/commit/?id=f7a1fdf0266cf3149764b3608384f5a5092ab526'/>
<id>urn:sha1:f7a1fdf0266cf3149764b3608384f5a5092ab526</id>
<content type='text'>
Note that "encryption data-ciphers-fallback" only takes CBC ciphers
together with "shared-secret-key".
</content>
</entry>
<entry>
<title>Merge pull request #2336 from rnavarro/feat/T9413-router-advert-on-exit</title>
<updated>2026-10-08T05:41:38+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-10-08T05:41:38+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-documentation.git/commit/?id=60144987946cc5ffaa9e29b5ca0dd5dbbf35e8ca'/>
<id>urn:sha1:60144987946cc5ffaa9e29b5ca0dd5dbbf35e8ca</id>
<content type='text'>
router-advert: T9413: document no-remove-on-exit and no-flush-* options</content>
</entry>
<entry>
<title>router-advert: T9413: suppress linter on NAT64 well-known prefix examples</title>
<updated>2026-10-07T22:28:10+00:00</updated>
<author>
<name>Robert Navarro</name>
<email>crshman@gmail.com</email>
</author>
<published>2026-10-07T22:28:10+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-documentation.git/commit/?id=d569c5e017520d43b2fd29f139e0d7a15c3a73d9'/>
<id>urn:sha1:d569c5e017520d43b2fd29f139e0d7a15c3a73d9</id>
<content type='text'>
The two nat64prefix examples use the well-known prefix 64:ff9b::/96,
which the doc linter reports as outside the documentation ranges. Wrap
them in stop/start_vyoslinter markers, as AGENTS.md describes for this
prefix, so the page passes the linter.
</content>
</entry>
<entry>
<title>router-advert: T9413: document no-remove-on-exit and no-flush-* options</title>
<updated>2026-10-07T22:28:03+00:00</updated>
<author>
<name>Robert Navarro</name>
<email>crshman@gmail.com</email>
</author>
<published>2026-10-07T22:28:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-documentation.git/commit/?id=82d8ad823310a9250e7a2dc644984d5d23811072'/>
<id>urn:sha1:82d8ad823310a9250e7a2dc644984d5d23811072</id>
<content type='text'>
Document the three per-interface options added in vyos-1x for T9413,
which keep radvd from sending zero-lifetime router, RDNSS and DNSSL
advertisements on shutdown, and add an example of two routers sharing
fe80::1 as the RA source address through VRRP.
</content>
</entry>
<entry>
<title>Merge pull request #2324 from mandelbitdev/T9370-openvpn-chacha20poly1305</title>
<updated>2026-10-07T18:05:14+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-10-07T18:05:14+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-documentation.git/commit/?id=d7180eee731b58b664b1691173a4d2e8bbc206c3'/>
<id>urn:sha1:d7180eee731b58b664b1691173a4d2e8bbc206c3</id>
<content type='text'>
openvpn: T9370: document the chacha20poly1305 data cipher</content>
</entry>
<entry>
<title>container: document remaining per-container options and network types (#2244)</title>
<updated>2026-10-06T18:40:31+00:00</updated>
<author>
<name>Ruben Herold</name>
<email>ruben@puettmann.net</email>
</author>
<published>2026-10-06T18:40:31+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-documentation.git/commit/?id=de45e02be519513c45229db2f9d1db6cc759970d'/>
<id>urn:sha1:de45e02be519513c45229db2f9d1db6cc759970d</id>
<content type='text'>
* container: document remaining per-container options and network types

The container page covered 44 of the 53 nodes in container.xml.in. Add
the eight that were missing, grouped where they belong on the page:

- allow-host-cgroups, next to allow-host-pid
- network &lt;net&gt; mac, next to the network address option
- volume &lt;vol&gt; propagation, with all six modes
- stop-timeout, next to restart
- shared-memory, next to memory
- network &lt;net&gt; type bridge / type macvlan mode / type macvlan parent

The network type is the notable gap: MACVLAN was entirely undocumented,
although it is the way to put containers directly on a parent network
instead of behind the host bridge and NAT. The page now states that
parent and mode are both required, that the parent must exist, and that
MACVLAN networks cannot be assigned to a VRF - all three are enforced
by verify() in src/conf_mode/container.py.

Defaults and ranges are taken from container.xml.in; the "--cgroupns
host" note matches what the quadlet generator emits.

* container: describe volume propagation in terms of mount events

The six propagation modes were described in terms of sub-mount
visibility, taken from the &lt;description&gt; text in container.xml.in. That
is not what the modes do - mount(2)/umount(2) event propagation is.
Per mount_namespaces(7):

- MS_SHARED propagates events *both ways* between members of the peer
  group, not only from the original mount to the replica
- MS_PRIVATE propagates no events out of or into the mount; it does not
  hide sub-mounts within it

Also note the constraint the host side imposes, which is easy to trip
over: per docker-run(1)/podman, shared propagation requires the source
mount to be shared and slave requires it to be shared or slave, or the
requested mode silently does not take effect. Added the findmnt
invocation to check it.

Raised by CodeRabbit on #2244.

* container: document stop-timeout range and MACVLAN private mode precisely</content>
</entry>
<entry>
<title>docs: T9200: note no-ipv6-auto-ra doesn't stop already-active RA (#2195)</title>
<updated>2026-10-06T17:38:04+00:00</updated>
<author>
<name>Ruben Herold</name>
<email>ruben@puettmann.net</email>
</author>
<published>2026-10-06T17:38:04+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-documentation.git/commit/?id=1ea306dedf016c4132611db1efdb6b9e3feba136'/>
<id>urn:sha1:1ea306dedf016c4132611db1efdb6b9e3feba136</id>
<content type='text'>
* docs: T9200: note no-ipv6-auto-ra doesn't stop already-active RA

no-ipv6-auto-ra only prevents future RA initiation; it doesn't
retroactively silence router advertisements already sent on an
established session. Confirmed on VyOS 1.5.1: neither a soft nor a
hard clear/reset bgp on the neighbor stopped it. Per FRR's
bgp_zebra_terminate_radv()/upstream PR FRRouting/frr#19487, that only
runs when the neighbor's remote-as is removed and re-added.

* docs: T9200: distinguish blast radius of the two RA workarounds

remote-as re-add only affects the one neighbor; a bgpd/frr restart
clears every BGP session on the router. The note listed them as
equivalent options - reframe the restart as a maintenance-window
fallback instead.

Flagged by CodeRabbit review on PR #2195.

* Make the note less wordy

---------

Co-authored-by: Daniil Baturin &lt;daniil@baturin.org&gt;</content>
</entry>
<entry>
<title>Merge pull request #2260 from ordex/T9364-openvpn-dco-mtu</title>
<updated>2026-10-01T18:37:52+00:00</updated>
<author>
<name>Christian Breunig</name>
<email>christian@breunig.cc</email>
</author>
<published>2026-10-01T18:37:52+00:00</published>
<link rel='alternate' type='text/html' href='https://git.amelek.net/vyos/vyos-documentation.git/commit/?id=70ffde48e951caea564b558dceeb049f94a37903'/>
<id>urn:sha1:70ffde48e951caea564b558dceeb049f94a37903</id>
<content type='text'>
openvpn: T9364: document the mtu option</content>
</entry>
</feed>
