A Network in ZEDEDA Cloud defines how EVE-OS configures a physical port's IP connectivity – it is the control-plane configuration that tells EVE-OS how to get an IP address, where to find DNS and NTP, and how to reach the ZEDEDA Cloud controller.
This is fundamentally different from a Network Instance, which is about how application workloads connect to each other and to external networks. Do not confuse the two:
| Network (this page) | Network Instance (see 03b) | |
|---|---|---|
| Purpose | EVE-OS management plane connectivity | App workload data plane connectivity |
| Controls | How a physical port gets its IP | How apps connect to each other and external networks |
| Assigned to | A physical port on the edge node | A running app interface |
| Terraform resource | zedcloud_network | zedcloud_network_instance |
| Analogy | IPAM/addressing config for a server NIC | A virtual switch or router for app traffic |
A network is a configuration for edge node connectivity (DHCP/static IP config, DNS, NTP config) that can be assigned to a network port to form a network adapter.
When EVE-OS boots and onboards, it needs to reach the ZEDEDA Cloud controller to receive its configuration. The Network object defines how each physical port on the node is configured to achieve that connectivity:
dhcp setting| kind value | Description |
|---|---|
NETWORK_KIND_V4 | IPv4 network. Supports DHCP client, static, or passthrough. |
NETWORK_KIND_V4_ONLY | IPv4 only, strict. Used when you want to enforce IPv4 exclusively with no fallback. Typical for static IP configs. |
NETWORK_KIND_V6 | IPv6 network. |
NETWORK_KIND_WIFI | Wireless network. Requires SSID and credentials. |
NETWORK_KIND_CELLULAR | Cellular/LTE network. Requires APN configuration. |
| dhcp value | Description |
|---|---|
NETWORK_DHCP_TYPE_CLIENT | EVE-OS runs a DHCP client on this port and gets its IP from the network. Most common for management ports. |
NETWORK_DHCP_TYPE_STATIC | EVE-OS configures the port with a fixed IP, gateway, subnet, and DNS that you specify. |
NETWORK_DHCP_TYPE_NONE | No IP configuration. EVE-OS does not run a DHCP client. Used for ports dedicated to app use (switch NI). |
NETWORK_DHCP_TYPE_PASSTHROUGH | The port is passed directly to an app. EVE-OS does not manage its IP. |
When enterprise_default = true, this network is the fallback configuration applied to any edge node port that does not have an explicit network assignment. Useful for enterprises where most nodes are on the same DHCP network – set one network as default and only override for exceptions.
Only one network per enterprise can be the default. Setting a new default clears the previous one.
The standard configuration for a management port on a network with DHCP. EVE-OS runs a DHCP client on this port and gets its IP, gateway, and DNS from the upstream DHCP server.
resource "zedcloud_network" "demo_eve_net_port" {
name = "DEMO-EVE-NET"
title = "DEMO-EVE-NET"
description = "EVE management port -- DHCP client"
enterprise_default = false
kind = "NETWORK_KIND_V4"
ip {
dhcp = "NETWORK_DHCP_TYPE_CLIENT"
}
project_id = zedcloud_project.demo_zededa_project_1.id
}
This is the simplest and most common network config. Assign this network to the management port of any edge node that gets its IP from a local DHCP server.
Fixed IP assignment for the management port. Use when the edge node must always have a predictable IP address – common in production deployments, remote sites without DHCP, or when the controller must whitelist the node's source IP.
resource "zedcloud_network" "demo_eve_net_port_static" {
name = "DEMO-EVE-STATIC-IP-192-168-2-0-24"
title = "DEMO-EVE-STATIC-IP-192-168-2-0-24"
description = "EVE management port -- static IP 192.168.2.x"
enterprise_default = false
kind = "NETWORK_KIND_V4_ONLY"
ip {
dhcp = "NETWORK_DHCP_TYPE_STATIC"
gateway = "192.168.2.1"
subnet = "192.168.2.0/24"
dns = ["192.168.2.1"]
}
project_id = zedcloud_project.demo_zededa_project_1.id
}
Note: a static network defines the subnet and gateway but not the individual IP address of the port. The specific IP is configured at the edge node level (in the device/adapter assignment), not in the network object. This allows one network definition to serve multiple nodes on the same subnet with different IPs.
Static IP configuration where all EVE-OS controller traffic must pass through an HTTP/HTTPS proxy. Common in enterprise environments with strict egress controls, air-gapped sites with a jump proxy, or networks where direct internet access is blocked.
resource "zedcloud_network" "demo_eve_net_port_static_w_proxy" {
name = "DEMO-EVE-STATIC-IP-192-168-2-0-24-w-proxy"
title = "DEMO-EVE-STATIC-IP-192-168-2-0-24-w-proxy"
description = "EVE management port -- static IP with proxy egress"
enterprise_default = false
kind = "NETWORK_KIND_V4_ONLY"
ip {
dhcp = "NETWORK_DHCP_TYPE_STATIC"
gateway = "192.168.2.1"
subnet = "192.168.2.0/24"
dns = ["192.168.2.1"]
}
proxy {
proxies {
proto = "NETWORK_PROXY_PROTO_HTTP"
server = "192.168.2.50"
port = 3128
}
proxies {
proto = "NETWORK_PROXY_PROTO_HTTPS"
server = "192.168.2.50"
port = 3128
}
proxies {
proto = "NETWORK_PROXY_PROTO_SOCKS"
server = ""
port = 0
}
proxies {
proto = "NETWORK_PROXY_PROTO_FTP"
server = ""
port = 0
}
}
project_id = zedcloud_project.demo_zededa_project_1.id
}
Notes:
server = “” and port = 0 for proxy types you are not using – they must still be present in the block but are effectively disabledNETWORK_PROXY_PROTO_HTTPS is the most important entry – this is what covers the controller heartbeat trafficzedcloud.zededa.net (or your cluster URL) on port 443| proto value | Protocol | Typical use |
|---|---|---|
NETWORK_PROXY_PROTO_HTTP | HTTP proxy | Covers plain HTTP traffic from EVE-OS |
NETWORK_PROXY_PROTO_HTTPS | HTTPS proxy (CONNECT tunnel) | Covers controller heartbeat and config traffic |
NETWORK_PROXY_PROTO_SOCKS | SOCKS proxy | Less common; leave empty if not used |
NETWORK_PROXY_PROTO_FTP | FTP proxy | Leave empty if not used |
Beyond the proxies block (manual proxy), ZEDEDA also supports:
| Option | Description |
|---|---|
| Manual (proxies block) | Explicit proxy server, port, and protocol as shown above |
| Auto Proxy Discovery (WPAD) | EVE-OS automatically discovers the proxy server via DHCP option 252 or DNS WPAD record |
| PAC File | EVE-OS fetches and executes a Proxy Auto-Config file from a URL |
| Transparent | SSL inspection proxy; provide the proxy's CA certificate so EVE-OS trusts the intercepted HTTPS |
| URL | Single proxy URL for all protocols |
For Terraform, the manual proxies block and network_proxy_url are the most commonly used options:
proxy {
network_proxy_url = "http://proxy.example.com:3128"
}
For WiFi management connectivity (less common in industrial deployments but useful for IoT gateways):
resource "zedcloud_network" "demo_wifi_net" {
name = "DEMO-WIFI-NET"
title = "DEMO-WIFI-NET"
kind = "NETWORK_KIND_WIFI"
project_id = zedcloud_project.demo_zededa_project_1.id
ip {
dhcp = "NETWORK_DHCP_TYPE_CLIENT"
}
wireless {
type = "NETWORK_WIRELESS_TYPE_WIFI"
wifi_cfg {
ssid = "MyCorpWifi"
key_scheme = "NETWORK_WIFIKEY_SCHEME_WPAPSK"
password = var.wifi_password
priority = 1
}
}
}
For LTE/cellular management connectivity:
resource "zedcloud_network" "demo_lte_net" {
name = "NS-WWAN-NET-1"
title = "NS-WWAN-NET-1"
kind = "NETWORK_KIND_V4"
project_id = zedcloud_project.demo_zededa_project_1.id
ip {
dhcp = "NETWORK_DHCP_TYPE_CLIENT"
}
wireless {
type = "NETWORK_WIRELESS_TYPE_CELLULAR"
cellular_cfg {
apn = "vzwinternet"
location_tracking = true
}
}
}
# DHCP client network zcli network create DEMO-EVE-NET \ --project=demo-project \ --kind=Portv4 \ --dhcp=client \ --title="DEMO-EVE-NET"
# Static IP network zcli network create DEMO-EVE-STATIC \ --project=demo-project \ --kind=Portv4 \ --dhcp=static \ --subnet=192.168.2.0/24 \ --gateway=192.168.2.1 \ --nameserver=192.168.2.1 \ --title="DEMO-EVE-STATIC"
# Static with proxy zcli network create DEMO-EVE-STATIC-PROXY \ --project=demo-project \ --kind=Portv4 \ --dhcp=static \ --subnet=192.168.2.0/24 \ --gateway=192.168.2.1 \ --nameserver=192.168.2.1 \ --proxy-static=./proxy-config.json \ --title="DEMO-EVE-STATIC-PROXY"
# Show all networks zcli network show
# Show networks in a project zcli network show --project=demo-project
# DHCP client
POST /v1/networks
{
"name": "DEMO-EVE-NET",
"kind": "NETWORK_KIND_V4",
"projectId": "<project_id>",
"ip": {
"dhcp": "NETWORK_DHCP_TYPE_CLIENT"
}
}
# Static with proxy
POST /v1/networks
{
"name": "DEMO-EVE-STATIC-IP-192-168-2-0-24-w-proxy",
"kind": "NETWORK_KIND_V4_ONLY",
"projectId": "<project_id>",
"ip": {
"dhcp": "NETWORK_DHCP_TYPE_STATIC",
"gateway": "192.168.2.1",
"subnet": "192.168.2.0/24",
"dns": ["192.168.2.1"]
},
"proxy": {
"proxies": [
{ "proto": "NETWORK_PROXY_PROTO_HTTP", "server": "192.168.2.50", "port": 3128 },
{ "proto": "NETWORK_PROXY_PROTO_HTTPS", "server": "192.168.2.50", "port": 3128 }
]
}
}
| Scenario | Network Config |
|---|---|
| Edge node on office LAN with DHCP | NETWORK_DHCP_TYPE_CLIENT, no proxy |
| Remote site with fixed IP and no DHCP | NETWORK_DHCP_TYPE_STATIC with gateway, subnet, DNS |
| Corporate network with HTTP proxy egress | Static or DHCP + proxy block with HTTP/HTTPS entries |
| Air-gapped site with local proxy jump | Static IP + proxy pointing to on-prem proxy server |
| WiFi-primary IoT gateway | NETWORK_KIND_WIFI with SSID/password |
| LTE fallback or primary connectivity | NETWORK_KIND_CELLULAR with APN |
| Node with two uplinks (wired primary, LTE backup) | Two separate network assignments on two ports with different cost values |