Table of Contents
Networks (EVE-OS Control Plane Connectivity)
A Network in ZEDEDA Cloud defines how EVE-OS configures a physical port's IP connectivity – it is the control-plane configuration that tells EVE-OS how to get an IP address, where to find DNS and NTP, and how to reach the ZEDEDA Cloud controller.
This is fundamentally different from a Network Instance, which is about how application workloads connect to each other and to external networks. Do not confuse the two:
| Network (this page) | Network Instance (see 03b) | |
|---|---|---|
| Purpose | EVE-OS management plane connectivity | App workload data plane connectivity |
| Controls | How a physical port gets its IP | How apps connect to each other and external networks |
| Assigned to | A physical port on the edge node | A running app interface |
| Terraform resource | zedcloud_network | zedcloud_network_instance |
| Analogy | IPAM/addressing config for a server NIC | A virtual switch or router for app traffic |
What a Network Does
A network is a configuration for edge node connectivity (DHCP/static IP config, DNS, NTP config) that can be assigned to a network port to form a network adapter.
When EVE-OS boots and onboards, it needs to reach the ZEDEDA Cloud controller to receive its configuration. The Network object defines how each physical port on the node is configured to achieve that connectivity:
- EVE-OS reads the assigned Network config for each physical port
- Configures the port as DHCP client, static IP, or passthrough based on the
dhcpsetting - Uses the specified DNS and gateway to reach the controller
- If a proxy is defined, routes all controller traffic through it
- Reports back to the controller once connected; continues to use this config for heartbeats
Network Kinds
| kind value | Description |
|---|---|
NETWORK_KIND_V4 | IPv4 network. Supports DHCP client, static, or passthrough. |
NETWORK_KIND_V4_ONLY | IPv4 only, strict. Used when you want to enforce IPv4 exclusively with no fallback. Typical for static IP configs. |
NETWORK_KIND_V6 | IPv6 network. |
NETWORK_KIND_WIFI | Wireless network. Requires SSID and credentials. |
NETWORK_KIND_CELLULAR | Cellular/LTE network. Requires APN configuration. |
DHCP Types
| dhcp value | Description |
|---|---|
NETWORK_DHCP_TYPE_CLIENT | EVE-OS runs a DHCP client on this port and gets its IP from the network. Most common for management ports. |
NETWORK_DHCP_TYPE_STATIC | EVE-OS configures the port with a fixed IP, gateway, subnet, and DNS that you specify. |
NETWORK_DHCP_TYPE_NONE | No IP configuration. EVE-OS does not run a DHCP client. Used for ports dedicated to app use (switch NI). |
NETWORK_DHCP_TYPE_PASSTHROUGH | The port is passed directly to an app. EVE-OS does not manage its IP. |
enterprise_default
When enterprise_default = true, this network is the fallback configuration applied to any edge node port that does not have an explicit network assignment. Useful for enterprises where most nodes are on the same DHCP network – set one network as default and only override for exceptions.
Only one network per enterprise can be the default. Setting a new default clears the previous one.
Terraform Examples
DHCP Client (Most Common)
The standard configuration for a management port on a network with DHCP. EVE-OS runs a DHCP client on this port and gets its IP, gateway, and DNS from the upstream DHCP server.
resource "zedcloud_network" "demo_eve_net_port" {
name = "DEMO-EVE-NET"
title = "DEMO-EVE-NET"
description = "EVE management port -- DHCP client"
enterprise_default = false
kind = "NETWORK_KIND_V4"
ip {
dhcp = "NETWORK_DHCP_TYPE_CLIENT"
}
project_id = zedcloud_project.demo_zededa_project_1.id
}
This is the simplest and most common network config. Assign this network to the management port of any edge node that gets its IP from a local DHCP server.
Static IP
Fixed IP assignment for the management port. Use when the edge node must always have a predictable IP address – common in production deployments, remote sites without DHCP, or when the controller must whitelist the node's source IP.
resource "zedcloud_network" "demo_eve_net_port_static" {
name = "DEMO-EVE-STATIC-IP-192-168-2-0-24"
title = "DEMO-EVE-STATIC-IP-192-168-2-0-24"
description = "EVE management port -- static IP 192.168.2.x"
enterprise_default = false
kind = "NETWORK_KIND_V4_ONLY"
ip {
dhcp = "NETWORK_DHCP_TYPE_STATIC"
gateway = "192.168.2.1"
subnet = "192.168.2.0/24"
dns = ["192.168.2.1"]
}
project_id = zedcloud_project.demo_zededa_project_1.id
}
Note: a static network defines the subnet and gateway but not the individual IP address of the port. The specific IP is configured at the edge node level (in the device/adapter assignment), not in the network object. This allows one network definition to serve multiple nodes on the same subnet with different IPs.
Static IP with Proxy
Static IP configuration where all EVE-OS controller traffic must pass through an HTTP/HTTPS proxy. Common in enterprise environments with strict egress controls, air-gapped sites with a jump proxy, or networks where direct internet access is blocked.
resource "zedcloud_network" "demo_eve_net_port_static_w_proxy" {
name = "DEMO-EVE-STATIC-IP-192-168-2-0-24-w-proxy"
title = "DEMO-EVE-STATIC-IP-192-168-2-0-24-w-proxy"
description = "EVE management port -- static IP with proxy egress"
enterprise_default = false
kind = "NETWORK_KIND_V4_ONLY"
ip {
dhcp = "NETWORK_DHCP_TYPE_STATIC"
gateway = "192.168.2.1"
subnet = "192.168.2.0/24"
dns = ["192.168.2.1"]
}
proxy {
proxies {
proto = "NETWORK_PROXY_PROTO_HTTP"
server = "192.168.2.50"
port = 3128
}
proxies {
proto = "NETWORK_PROXY_PROTO_HTTPS"
server = "192.168.2.50"
port = 3128
}
proxies {
proto = "NETWORK_PROXY_PROTO_SOCKS"
server = ""
port = 0
}
proxies {
proto = "NETWORK_PROXY_PROTO_FTP"
server = ""
port = 0
}
}
project_id = zedcloud_project.demo_zededa_project_1.id
}
Notes:
- The proxy configuration applies to EVE-OS controller traffic only – the HTTPS connection from EVE-OS to the ZEDEDA Cloud controller is routed through this proxy
- Leave
server = “”andport = 0for proxy types you are not using – they must still be present in the block but are effectively disabled NETWORK_PROXY_PROTO_HTTPSis the most important entry – this is what covers the controller heartbeat traffic- The proxy must be able to reach
zedcloud.zededa.net(or your cluster URL) on port 443
Proxy Types
| proto value | Protocol | Typical use |
|---|---|---|
NETWORK_PROXY_PROTO_HTTP | HTTP proxy | Covers plain HTTP traffic from EVE-OS |
NETWORK_PROXY_PROTO_HTTPS | HTTPS proxy (CONNECT tunnel) | Covers controller heartbeat and config traffic |
NETWORK_PROXY_PROTO_SOCKS | SOCKS proxy | Less common; leave empty if not used |
NETWORK_PROXY_PROTO_FTP | FTP proxy | Leave empty if not used |
Proxy Configuration Options
Beyond the proxies block (manual proxy), ZEDEDA also supports:
| Option | Description |
|---|---|
| Manual (proxies block) | Explicit proxy server, port, and protocol as shown above |
| Auto Proxy Discovery (WPAD) | EVE-OS automatically discovers the proxy server via DHCP option 252 or DNS WPAD record |
| PAC File | EVE-OS fetches and executes a Proxy Auto-Config file from a URL |
| Transparent | SSL inspection proxy; provide the proxy's CA certificate so EVE-OS trusts the intercepted HTTPS |
| URL | Single proxy URL for all protocols |
For Terraform, the manual proxies block and network_proxy_url are the most commonly used options:
proxy {
network_proxy_url = "http://proxy.example.com:3128"
}
Wireless Networks
For WiFi management connectivity (less common in industrial deployments but useful for IoT gateways):
resource "zedcloud_network" "demo_wifi_net" {
name = "DEMO-WIFI-NET"
title = "DEMO-WIFI-NET"
kind = "NETWORK_KIND_WIFI"
project_id = zedcloud_project.demo_zededa_project_1.id
ip {
dhcp = "NETWORK_DHCP_TYPE_CLIENT"
}
wireless {
type = "NETWORK_WIRELESS_TYPE_WIFI"
wifi_cfg {
ssid = "MyCorpWifi"
key_scheme = "NETWORK_WIFIKEY_SCHEME_WPAPSK"
password = var.wifi_password
priority = 1
}
}
}
Cellular Networks
For LTE/cellular management connectivity:
resource "zedcloud_network" "demo_lte_net" {
name = "NS-WWAN-NET-1"
title = "NS-WWAN-NET-1"
kind = "NETWORK_KIND_V4"
project_id = zedcloud_project.demo_zededa_project_1.id
ip {
dhcp = "NETWORK_DHCP_TYPE_CLIENT"
}
wireless {
type = "NETWORK_WIRELESS_TYPE_CELLULAR"
cellular_cfg {
apn = "vzwinternet"
location_tracking = true
}
}
}
ZCLI
# DHCP client network zcli network create DEMO-EVE-NET \ --project=demo-project \ --kind=Portv4 \ --dhcp=client \ --title="DEMO-EVE-NET"
# Static IP network zcli network create DEMO-EVE-STATIC \ --project=demo-project \ --kind=Portv4 \ --dhcp=static \ --subnet=192.168.2.0/24 \ --gateway=192.168.2.1 \ --nameserver=192.168.2.1 \ --title="DEMO-EVE-STATIC"
# Static with proxy zcli network create DEMO-EVE-STATIC-PROXY \ --project=demo-project \ --kind=Portv4 \ --dhcp=static \ --subnet=192.168.2.0/24 \ --gateway=192.168.2.1 \ --nameserver=192.168.2.1 \ --proxy-static=./proxy-config.json \ --title="DEMO-EVE-STATIC-PROXY"
# Show all networks zcli network show
# Show networks in a project zcli network show --project=demo-project
API
# DHCP client
POST /v1/networks
{
"name": "DEMO-EVE-NET",
"kind": "NETWORK_KIND_V4",
"projectId": "<project_id>",
"ip": {
"dhcp": "NETWORK_DHCP_TYPE_CLIENT"
}
}
# Static with proxy
POST /v1/networks
{
"name": "DEMO-EVE-STATIC-IP-192-168-2-0-24-w-proxy",
"kind": "NETWORK_KIND_V4_ONLY",
"projectId": "<project_id>",
"ip": {
"dhcp": "NETWORK_DHCP_TYPE_STATIC",
"gateway": "192.168.2.1",
"subnet": "192.168.2.0/24",
"dns": ["192.168.2.1"]
},
"proxy": {
"proxies": [
{ "proto": "NETWORK_PROXY_PROTO_HTTP", "server": "192.168.2.50", "port": 3128 },
{ "proto": "NETWORK_PROXY_PROTO_HTTPS", "server": "192.168.2.50", "port": 3128 }
]
}
}
How This Flows to the Edge Node
- The Network object is created in ZEDEDA Cloud – it is a reusable config template
- It is assigned to a physical port on an edge node when the node is onboarded or when the port config is updated
- At the next heartbeat, EVE-OS receives the port's network assignment as part of its device config
- EVE-OS configures the physical NIC: runs DHCP client, sets static IP, or configures proxy routing as specified
- EVE-OS uses this configured port to reach the ZEDEDA Cloud controller for all subsequent heartbeats and config downloads
- If the proxy config changes in ZEDEDA Cloud, EVE-OS picks it up at next heartbeat and reconfigures its egress routing
Common Patterns
| Scenario | Network Config |
|---|---|
| Edge node on office LAN with DHCP | NETWORK_DHCP_TYPE_CLIENT, no proxy |
| Remote site with fixed IP and no DHCP | NETWORK_DHCP_TYPE_STATIC with gateway, subnet, DNS |
| Corporate network with HTTP proxy egress | Static or DHCP + proxy block with HTTP/HTTPS entries |
| Air-gapped site with local proxy jump | Static IP + proxy pointing to on-prem proxy server |
| WiFi-primary IoT gateway | NETWORK_KIND_WIFI with SSID/password |
| LTE fallback or primary connectivity | NETWORK_KIND_CELLULAR with APN |
| Node with two uplinks (wired primary, LTE backup) | Two separate network assignments on two ports with different cost values |
