delonix net
A infra-estrutura de baixo nível da rede — netns, flow, ingress, egress, httproute, tunnel, l4guard, capture.
The low-level network plumbing — netns, flow, ingress, egress, httproute, tunnel, l4guard, capture.
Plumbing de rede/infra de baixo nível, agrupado desde a reestruturação da CLI
(v0.30.0): netns/flow/ingress/egress/
httproute/tunnel/l4guard/capture/boot
viviam soltos na raiz, fáceis de invocar como se fossem um comando principal por engano. Cada
subgrupo aqui tem a sua própria página (ver a barra lateral) — esta é só a porta de entrada.
Não confundir com network (sem o "net"): esse é o Kind que o cliente cria (bridge,
overlay, subnet); este é o que corre por baixo — a firewall por-container, o holder netns, o
proxy L7, o rate-limit de borda.
Low-level network/infra plumbing, grouped since the CLI restructuring
(v0.30.0): netns/flow/ingress/egress/
httproute/tunnel/l4guard/capture/boot
used to sit loose at the root, easy to invoke by mistake as if they were a top-level command. Each
subgroup here has its own page (see the sidebar) — this is just the front door.
Not to be confused with network (no "net"): that is the Kind the client creates
(bridge, overlay, subnet); this is what runs underneath — the per-container firewall, the netns
holder, the L7 proxy, the edge rate limiter.
Usage: delonix net [OPTIONS] <COMMAND>
Commands:
capture Raw packet capture on a container's SDN interface, via the host's own `tcpdump`
flow Live per-container traffic (eBPF datapath; degrades to veth counters)
egress OUTBOUND firewall (L4 rules + per-network egress policy) for a container
ingress INBOUND firewall (L4 rules + DNAT publishes) for a container on the SDN
l4guard Ingress-wide L4 DDoS guard (per-source connection rate + concurrent cap)
httproute Embedded L7/HTTP reverse-proxy (`kind: HTTPRoute`): apply/rm
tunnel Expose a local port to the public internet (`kind: Gateway`)
netns Low-level management of the rootless ingress infra (up/status/attach/publish/firewall)
help Print this message or the help of the given subcommand(s)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
COMMAND MAP:
Inspect flow · capture
Configure ingress · egress · l4guard
Networking httproute · tunnel
Advanced netns
EXAMPLES:
# who can reach what: the inbound policy, rules and published ports of every
# container on the SDN
delonix net ingress ls
# the state of the rootless plumbing every `--net <network>` container
# depends on
delonix net netns status
# live per-container traffic, redrawn every 2s
delonix net flow -w
# one public URL for a local port, with no account and no public IP on this
# host
delonix net tunnel expose 8080
SEE ALSO:
delonix network ls · delonix container run · delonix container update ·
delonix network create
delonix › net