aclplugin

package
v1.0.8 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Nov 21, 2017 License: Apache-2.0 Imports: 11 Imported by: 0

README

ACL plugin

The aclplugin is a Core Agent Plugin designed to configure ACL in the VPP. Configuration managed by this plugin is modelled by acl proto file.

The configuration must be stored in ETCD using following keys:

/vnf-agent/<agent-label>/vpp/config/v1/acl/<acl-name>

JSON configuration example with vpp-agent-ctl

An example of basic ACL configuration in JSON format can be found with rules for MACIP, TCP, UDP

Built-in configuration example with vpp-agent-ctl

The vpp-agent-ctl binary also ships with some simple predefined acl configurations. It is meant to be used solely for testing purposes.

To configure a new acl acl1, use:

vpp-agent-ctl /opt/vpp-agent/dev/etcd.conf -acl

To delete the acl, use:

vpp-agent-ctl /opt/vpp-agent/dev/etcd.conf -dacl

Documentation

Overview

Package aclplugin implements the ACL Plugin that handles management of VPP Access lists.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type ACLConfigurator

type ACLConfigurator struct {
	Log            logging.Logger
	GoVppmux       govppmux.API
	ACLL3L4Indexes idxvpp.NameToIdxRW
	ACLL2Indexes   idxvpp.NameToIdxRW // mapping for L2 ACLs
	SwIfIndexes    ifaceidx.SwIfIndex
	Stopwatch      *measure.Stopwatch // timer used to measure and store time
	// contains filtered or unexported fields
}

ACLConfigurator runs in the background in its own goroutine where it watches for any changes in the configuration of ACLs as modelled by the proto file "../model/acl/acl.proto" and stored in ETCD under the key "/vnf-agent/{agent-label}/vpp/config/v1/acl/". Updates received from the northbound API are compared with the VPP run-time configuration and differences are applied through the VPP binary API.

func (*ACLConfigurator) Close

func (plugin *ACLConfigurator) Close()

Close GOVPP channel.

func (*ACLConfigurator) ConfigureACL

func (plugin *ACLConfigurator) ConfigureACL(acl *acl.AccessLists_Acl, callback func(error)) error

ConfigureACL creates access list with provided rules and sets this list to every relevant interface.

func (*ACLConfigurator) DeleteACL

func (plugin *ACLConfigurator) DeleteACL(acl *acl.AccessLists_Acl, callback func(error)) error

DeleteACL removes existing ACL. To detach ACL from interfaces, list of interfaces has to be provided.

func (*ACLConfigurator) DumpACL added in v1.0.8

func (plugin *ACLConfigurator) DumpACL() []*acl.AccessLists_Acl

DumpACL returns all configured ACLs in proto format todo ACLDump/ACLDetails error invalid message ID 924, expected 922

func (*ACLConfigurator) Init

func (plugin *ACLConfigurator) Init() (err error)

Init goroutines, channels and mappings.

func (*ACLConfigurator) ModifyACL

func (plugin *ACLConfigurator) ModifyACL(oldACL *acl.AccessLists_Acl, newACL *acl.AccessLists_Acl, callback func(error)) error

ModifyACL modifies previously created access list. L2 access list is removed and recreated, L3/L4 access list is modified directly. List of interfaces is refreshed as well.

func (*ACLConfigurator) Resync

func (plugin *ACLConfigurator) Resync(acls []*acl.AccessLists_Acl, log logging.Logger) error

Resync writes ACLs to the empty VPP.

Directories

Path Synopsis
Package binapi defines the aclplugin's southbound API.
Package binapi defines the aclplugin's southbound API.
acl
Code generated by govpp binapi-generator DO NOT EDIT.
Code generated by govpp binapi-generator DO NOT EDIT.
Package model defines the acplugin's northbound API.
Package model defines the acplugin's northbound API.
acl
Package acl is a generated protocol buffer package.
Package acl is a generated protocol buffer package.
Package vppcalls contains wrappers over VPP ACL binary APIs.
Package vppcalls contains wrappers over VPP ACL binary APIs.
Package vppdump provides helpers to dump ACLs configured in VPP - per interface and total.
Package vppdump provides helpers to dump ACLs configured in VPP - per interface and total.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL