User Tools

Site Tools


workshop:03a_networks

Networks (EVE-OS Control Plane Connectivity)

A Network in ZEDEDA Cloud defines how EVE-OS configures a physical port's IP connectivity – it is the control-plane configuration that tells EVE-OS how to get an IP address, where to find DNS and NTP, and how to reach the ZEDEDA Cloud controller.

This is fundamentally different from a Network Instance, which is about how application workloads connect to each other and to external networks. Do not confuse the two:

Network (this page) Network Instance (see 03b)
Purpose EVE-OS management plane connectivity App workload data plane connectivity
Controls How a physical port gets its IP How apps connect to each other and external networks
Assigned to A physical port on the edge node A running app interface
Terraform resource zedcloud_network zedcloud_network_instance
Analogy IPAM/addressing config for a server NIC A virtual switch or router for app traffic

What a Network Does

A network is a configuration for edge node connectivity (DHCP/static IP config, DNS, NTP config) that can be assigned to a network port to form a network adapter.

When EVE-OS boots and onboards, it needs to reach the ZEDEDA Cloud controller to receive its configuration. The Network object defines how each physical port on the node is configured to achieve that connectivity:

  1. EVE-OS reads the assigned Network config for each physical port
  2. Configures the port as DHCP client, static IP, or passthrough based on the dhcp setting
  3. Uses the specified DNS and gateway to reach the controller
  4. If a proxy is defined, routes all controller traffic through it
  5. Reports back to the controller once connected; continues to use this config for heartbeats

Network Kinds

kind value Description
NETWORK_KIND_V4 IPv4 network. Supports DHCP client, static, or passthrough.
NETWORK_KIND_V4_ONLY IPv4 only, strict. Used when you want to enforce IPv4 exclusively with no fallback. Typical for static IP configs.
NETWORK_KIND_V6 IPv6 network.
NETWORK_KIND_WIFI Wireless network. Requires SSID and credentials.
NETWORK_KIND_CELLULAR Cellular/LTE network. Requires APN configuration.

DHCP Types

dhcp value Description
NETWORK_DHCP_TYPE_CLIENT EVE-OS runs a DHCP client on this port and gets its IP from the network. Most common for management ports.
NETWORK_DHCP_TYPE_STATIC EVE-OS configures the port with a fixed IP, gateway, subnet, and DNS that you specify.
NETWORK_DHCP_TYPE_NONE No IP configuration. EVE-OS does not run a DHCP client. Used for ports dedicated to app use (switch NI).
NETWORK_DHCP_TYPE_PASSTHROUGH The port is passed directly to an app. EVE-OS does not manage its IP.

enterprise_default

When enterprise_default = true, this network is the fallback configuration applied to any edge node port that does not have an explicit network assignment. Useful for enterprises where most nodes are on the same DHCP network – set one network as default and only override for exceptions.

Only one network per enterprise can be the default. Setting a new default clears the previous one.

Terraform Examples

DHCP Client (Most Common)

The standard configuration for a management port on a network with DHCP. EVE-OS runs a DHCP client on this port and gets its IP, gateway, and DNS from the upstream DHCP server.

resource "zedcloud_network" "demo_eve_net_port" {
  name               = "DEMO-EVE-NET"
  title              = "DEMO-EVE-NET"
  description        = "EVE management port -- DHCP client"
  enterprise_default = false
  kind               = "NETWORK_KIND_V4"
  ip {
    dhcp = "NETWORK_DHCP_TYPE_CLIENT"
  }
  project_id = zedcloud_project.demo_zededa_project_1.id
}

This is the simplest and most common network config. Assign this network to the management port of any edge node that gets its IP from a local DHCP server.

Static IP

Fixed IP assignment for the management port. Use when the edge node must always have a predictable IP address – common in production deployments, remote sites without DHCP, or when the controller must whitelist the node's source IP.

resource "zedcloud_network" "demo_eve_net_port_static" {
  name               = "DEMO-EVE-STATIC-IP-192-168-2-0-24"
  title              = "DEMO-EVE-STATIC-IP-192-168-2-0-24"
  description        = "EVE management port -- static IP 192.168.2.x"
  enterprise_default = false
  kind               = "NETWORK_KIND_V4_ONLY"
  ip {
    dhcp    = "NETWORK_DHCP_TYPE_STATIC"
    gateway = "192.168.2.1"
    subnet  = "192.168.2.0/24"
    dns     = ["192.168.2.1"]
  }
  project_id = zedcloud_project.demo_zededa_project_1.id
}

Note: a static network defines the subnet and gateway but not the individual IP address of the port. The specific IP is configured at the edge node level (in the device/adapter assignment), not in the network object. This allows one network definition to serve multiple nodes on the same subnet with different IPs.

Static IP with Proxy

Static IP configuration where all EVE-OS controller traffic must pass through an HTTP/HTTPS proxy. Common in enterprise environments with strict egress controls, air-gapped sites with a jump proxy, or networks where direct internet access is blocked.

resource "zedcloud_network" "demo_eve_net_port_static_w_proxy" {
  name               = "DEMO-EVE-STATIC-IP-192-168-2-0-24-w-proxy"
  title              = "DEMO-EVE-STATIC-IP-192-168-2-0-24-w-proxy"
  description        = "EVE management port -- static IP with proxy egress"
  enterprise_default = false
  kind               = "NETWORK_KIND_V4_ONLY"
  ip {
    dhcp    = "NETWORK_DHCP_TYPE_STATIC"
    gateway = "192.168.2.1"
    subnet  = "192.168.2.0/24"
    dns     = ["192.168.2.1"]
  }
  proxy {
    proxies {
      proto  = "NETWORK_PROXY_PROTO_HTTP"
      server = "192.168.2.50"
      port   = 3128
    }
    proxies {
      proto  = "NETWORK_PROXY_PROTO_HTTPS"
      server = "192.168.2.50"
      port   = 3128
    }
    proxies {
      proto  = "NETWORK_PROXY_PROTO_SOCKS"
      server = ""
      port   = 0
    }
    proxies {
      proto  = "NETWORK_PROXY_PROTO_FTP"
      server = ""
      port   = 0
    }
  }
  project_id = zedcloud_project.demo_zededa_project_1.id
}

Notes:

  • The proxy configuration applies to EVE-OS controller traffic only – the HTTPS connection from EVE-OS to the ZEDEDA Cloud controller is routed through this proxy
  • Leave server = “” and port = 0 for proxy types you are not using – they must still be present in the block but are effectively disabled
  • NETWORK_PROXY_PROTO_HTTPS is the most important entry – this is what covers the controller heartbeat traffic
  • The proxy must be able to reach zedcloud.zededa.net (or your cluster URL) on port 443

Proxy Types

proto value Protocol Typical use
NETWORK_PROXY_PROTO_HTTP HTTP proxy Covers plain HTTP traffic from EVE-OS
NETWORK_PROXY_PROTO_HTTPS HTTPS proxy (CONNECT tunnel) Covers controller heartbeat and config traffic
NETWORK_PROXY_PROTO_SOCKS SOCKS proxy Less common; leave empty if not used
NETWORK_PROXY_PROTO_FTP FTP proxy Leave empty if not used

Proxy Configuration Options

Beyond the proxies block (manual proxy), ZEDEDA also supports:

Option Description
Manual (proxies block) Explicit proxy server, port, and protocol as shown above
Auto Proxy Discovery (WPAD) EVE-OS automatically discovers the proxy server via DHCP option 252 or DNS WPAD record
PAC File EVE-OS fetches and executes a Proxy Auto-Config file from a URL
Transparent SSL inspection proxy; provide the proxy's CA certificate so EVE-OS trusts the intercepted HTTPS
URL Single proxy URL for all protocols

For Terraform, the manual proxies block and network_proxy_url are the most commonly used options:

proxy {
  network_proxy_url = "http://proxy.example.com:3128"
}

Wireless Networks

For WiFi management connectivity (less common in industrial deployments but useful for IoT gateways):

resource "zedcloud_network" "demo_wifi_net" {
  name       = "DEMO-WIFI-NET"
  title      = "DEMO-WIFI-NET"
  kind       = "NETWORK_KIND_WIFI"
  project_id = zedcloud_project.demo_zededa_project_1.id
  ip {
    dhcp = "NETWORK_DHCP_TYPE_CLIENT"
  }
  wireless {
    type = "NETWORK_WIRELESS_TYPE_WIFI"
    wifi_cfg {
      ssid       = "MyCorpWifi"
      key_scheme = "NETWORK_WIFIKEY_SCHEME_WPAPSK"
      password   = var.wifi_password
      priority   = 1
    }
  }
}

Cellular Networks

For LTE/cellular management connectivity:

resource "zedcloud_network" "demo_lte_net" {
  name       = "NS-WWAN-NET-1"
  title      = "NS-WWAN-NET-1"
  kind       = "NETWORK_KIND_V4"
  project_id = zedcloud_project.demo_zededa_project_1.id
  ip {
    dhcp = "NETWORK_DHCP_TYPE_CLIENT"
  }
  wireless {
    type = "NETWORK_WIRELESS_TYPE_CELLULAR"
    cellular_cfg {
      apn              = "vzwinternet"
      location_tracking = true
    }
  }
}

ZCLI

# DHCP client network
zcli network create DEMO-EVE-NET \
  --project=demo-project \
  --kind=Portv4 \
  --dhcp=client \
  --title="DEMO-EVE-NET"
# Static IP network
zcli network create DEMO-EVE-STATIC \
  --project=demo-project \
  --kind=Portv4 \
  --dhcp=static \
  --subnet=192.168.2.0/24 \
  --gateway=192.168.2.1 \
  --nameserver=192.168.2.1 \
  --title="DEMO-EVE-STATIC"
# Static with proxy
zcli network create DEMO-EVE-STATIC-PROXY \
  --project=demo-project \
  --kind=Portv4 \
  --dhcp=static \
  --subnet=192.168.2.0/24 \
  --gateway=192.168.2.1 \
  --nameserver=192.168.2.1 \
  --proxy-static=./proxy-config.json \
  --title="DEMO-EVE-STATIC-PROXY"
# Show all networks
zcli network show
# Show networks in a project
zcli network show --project=demo-project

API

# DHCP client
POST /v1/networks
{
  "name": "DEMO-EVE-NET",
  "kind": "NETWORK_KIND_V4",
  "projectId": "<project_id>",
  "ip": {
    "dhcp": "NETWORK_DHCP_TYPE_CLIENT"
  }
}
# Static with proxy
POST /v1/networks
{
  "name": "DEMO-EVE-STATIC-IP-192-168-2-0-24-w-proxy",
  "kind": "NETWORK_KIND_V4_ONLY",
  "projectId": "<project_id>",
  "ip": {
    "dhcp": "NETWORK_DHCP_TYPE_STATIC",
    "gateway": "192.168.2.1",
    "subnet": "192.168.2.0/24",
    "dns": ["192.168.2.1"]
  },
  "proxy": {
    "proxies": [
      { "proto": "NETWORK_PROXY_PROTO_HTTP",  "server": "192.168.2.50", "port": 3128 },
      { "proto": "NETWORK_PROXY_PROTO_HTTPS", "server": "192.168.2.50", "port": 3128 }
    ]
  }
}

How This Flows to the Edge Node

  1. The Network object is created in ZEDEDA Cloud – it is a reusable config template
  2. It is assigned to a physical port on an edge node when the node is onboarded or when the port config is updated
  3. At the next heartbeat, EVE-OS receives the port's network assignment as part of its device config
  4. EVE-OS configures the physical NIC: runs DHCP client, sets static IP, or configures proxy routing as specified
  5. EVE-OS uses this configured port to reach the ZEDEDA Cloud controller for all subsequent heartbeats and config downloads
  6. If the proxy config changes in ZEDEDA Cloud, EVE-OS picks it up at next heartbeat and reconfigures its egress routing

Common Patterns

Scenario Network Config
Edge node on office LAN with DHCP NETWORK_DHCP_TYPE_CLIENT, no proxy
Remote site with fixed IP and no DHCP NETWORK_DHCP_TYPE_STATIC with gateway, subnet, DNS
Corporate network with HTTP proxy egress Static or DHCP + proxy block with HTTP/HTTPS entries
Air-gapped site with local proxy jump Static IP + proxy pointing to on-prem proxy server
WiFi-primary IoT gateway NETWORK_KIND_WIFI with SSID/password
LTE fallback or primary connectivity NETWORK_KIND_CELLULAR with APN
Node with two uplinks (wired primary, LTE backup) Two separate network assignments on two ports with different cost values
workshop/03a_networks.txt · Last modified: by mc