User Tools

Site Tools


eve-k:how-vm-is-created:nad-l2

This is an old revision of the document!


What is a NAD (NetworkAttachmentDefinition)?

A NetworkAttachmentDefinition (NAD) is a Kubernetes Custom Resource from the Multus CNI project. Multus is a “meta-CNI” plugin that allows a pod or VM to have multiple network interfaces – something standard Kubernetes cannot do on its own (normally every pod gets exactly one network interface).

A NAD defines an additional network that can be attached to a pod or VMI. You reference it by name in the pod/VMI spec and Multus calls the appropriate CNI plugin to wire up that extra interface.

The EVE-K NAD (confirmed live)

EVE-K registers a single bootstrap NAD at cluster initialisation:

kind: NetworkAttachmentDefinition
name: network-instance-attachment
namespace: eve-kube-app
spec:
  config: '{ "cniVersion": "0.3.1", "type": "eve-bridge" }'

This tells Multus: when a pod or VMI requests this network, call the eve-bridge CNI plugin. The eve-bridge plugin is EVE's own CNI implementation that connects the pod/VMI VIF into the correct EVE Network Instance bridge on the host.

EVE does not create a separate NAD per Network Instance. One bootstrap NAD handles all NIs. The eve-bridge CNI plugin resolves which NI to attach to at runtime using context passed by EVE.

Full chain: VMI → NAD → Multus → eve-bridge → Network Instance

VMI spec references NAD by name
    |
    v
Multus reads the NAD config
    |
    v
Multus calls eve-bridge CNI plugin
    |
    v
eve-bridge wires pod6c270ef2f25 into the eth0 Switch NI bridge on the host
    |
    v
VM has a bridged L2 interface on eth0 (Switch NI)

VMI network spec (confirmed live)

networks:
- multus:
    networkName: network-instance-attachment   # references the bootstrap NAD
  name: net1

interfaces:
- bridge: {}                                   # bridge mode = Switch NI (L2)
  macAddress: "02:11:22:33:44:55"              # EVE-assigned MAC
  name: net1
  podInterfaceName: pod6c270ef2f25             # Multus VIF name on the pod
  linkState: up                                # confirmed UP
  infoSource: domain, multus-status            # confirmed by both KubeVirt AND Multus

How to inspect

# See the NAD
kubectl get network-attachment-definitions -n eve-kube-app -o yaml
 
# See network attachment on a running VMI
kubectl get vmi <name> -n eve-kube-app -o yaml | grep -A10 "networks:\|interfaces:"
 
# Confirm Multus wired the interface
kubectl get vmi <name> -n eve-kube-app -o yaml | grep -E "linkState|infoSource|podInterfaceName"
eve-k/how-vm-is-created/nad-l2.1781884432.txt.gz · Last modified: (external edit)