delonix net netns
Gestão de baixo nível da infra de ingress rootless.
Low-level management of the rootless ingress infrastructure.
A camada crua por baixo do ingress/egress: subir/descer o
holder do ingress, attach/detach de netns, publish/unpublish de portas e firewall por container. A
maioria dos utilizadores nunca precisa disto — usa os grupos de alto nível — mas está exposto para
depuração e integração.
The raw layer underneath ingress/egress: bringing
the ingress holder up/down, attaching/detaching netns, publishing/unpublishing ports and
per-container firewalling. Most users never need this — they use the higher-level groups — but
it's exposed for debugging and integration.
📄 Implementação real em Rust: cmd/netns.rs
Usage: delonix net netns [OPTIONS] <COMMAND>
Commands:
down Force tear-down of the ingress infra (kills slirp + holder, frees the netns)
gc Reclaim infra left behind by state roots that no longer exist
up Bring the ingress infra up (idempotent): holder netns + delonix0 + single slirp
status Show the ingress infra status (holder/slirp pids, bridge, refcount)
exec Run a command inside an attached netns (exercises the runtime join path)
attach Attach a netns to delonix0 via veth (the holder is the netns/veth factory)
detach Detach (and destroy) a previously attached netns
firewall Apply (or clear) a container's parameterizable firewall AT THE INGRESS
publish Publish a port through the ingress (add_hostfwd + DNAT) to a container
unpublish Unpublish a host port from the ingress
help Print this message or the help of the given subcommand(s)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
COMMAND MAP:
Lifecycle up · down · gc
Inspect status
Interact exec
Networking attach · detach · publish · unpublish · firewall
EXAMPLES:
# holder and slirp pids, the bridge, and how many containers still hold a
# reference
delonix net netns status
# bring the plumbing up by hand — idempotent, so it is safe before debugging
# a path
delonix net netns up
# look at the SDN from the inside of an attached netns
delonix net netns exec dbg1 ip addr show
SEE ALSO:
delonix net ingress ls · delonix net flow · delonix network create · delonix
system info
delonix › net › netnsnetns firewall
Apply (or clear) a container's parameterizable firewall AT THE INGRESS
Usage: delonix net netns firewall [OPTIONS] <NAME>
Arguments:
<NAME>
Netns/container name
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--spec <SPEC>
ContainerFw as JSON, e.g. `{"enabled":true,"policyIn":"deny","rules":[...]}`
--clear
Remove the container's firewall from the ingress
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# install a default-deny inbound firewall with a single open port, straight
# at the ingress
delonix net netns firewall web --spec '{"enabled":true,"policyIn":"deny","rules":[{"dir":"in","proto":"tcp","port":"80","action":"allow"}]}'
# take the container's firewall out of the ingress entirely
delonix net netns firewall web --clear
SEE ALSO:
delonix net ingress allow · delonix net ingress policy · delonix net ingress
ls
delonix › net › netns › firewallExemplosExamples
delonix net netns firewall <id> 10.200.0.5netns unpublish
Unpublish a host port from the ingress
Usage: delonix net netns unpublish [OPTIONS] <HOST_PORT>
Arguments:
<HOST_PORT>
The HOST port to stop forwarding, as it was given to `publish`
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# take the host port back — the slirp hostfwd and the DNAT rule both go
delonix net netns unpublish 8080
SEE ALSO:
delonix net netns publish · delonix net ingress unpublish
delonix › net › netns › unpublishExemplosExamples
delonix net netns unpublish 8080netns publish
Publish a port through the ingress (add_hostfwd + DNAT) to a container
Usage: delonix net netns publish [OPTIONS] <NAME> <SPEC>
Arguments:
<NAME>
Netns/container name (its IP is derived unless `--ip` is given)
<SPEC>
Port mapping `hostPort:containerPort[/tcp|udp]`
Options:
--ip <IP>
Override the container IP (defaults to the deterministic one from `name`)
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# host 8080 onto the container's 80 — the hostfwd and the DNAT in one step
delonix net netns publish web 8080:80
# a UDP service, with the container address spelled out instead of derived
# from the name
delonix net netns publish dns 5353:53/udp --ip 10.200.0.42
SEE ALSO:
delonix net netns unpublish · delonix net ingress publish · delonix
container run
delonix › net › netns › publishExemplosExamples
delonix net netns publish 8080:80 10.200.0.5netns exec
Run a command inside an attached netns (exercises the runtime join path)
Usage: delonix net netns exec [OPTIONS] <NAME> <COMMAND>...
Arguments:
<NAME>
Netns to enter — a container id, or `pod-<name>` for a pod's shared one
<COMMAND>...
Command and arguments to run in there. Everything after the name
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# the address the holder actually handed this netns
delonix net netns exec dbg1 ip addr show
# the way out through the holder's bridge, when traffic leaves but never
# comes back
delonix net netns exec dbg1 ip route show
SEE ALSO:
delonix net netns attach · delonix container exec · delonix net flow
delonix › net › netns › execExemplosExamples
delonix net netns exec minha-netns ip -br addrnetns detach
Detach (and destroy) a previously attached netns
Usage: delonix net netns detach [OPTIONS] <NAME>
Arguments:
<NAME>
Netns to destroy — a container id, or `pod-<name>` for a pod's shared one
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# destroy the netns and give its veth and address back to the pool
delonix net netns detach dbg1
SEE ALSO:
delonix net netns attach · delonix net netns status
delonix › net › netns › detachExemplosExamples
delonix net netns detach minha-netnsnetns attach
Attach a netns to delonix0 via veth (the holder is the netns/veth factory)
Usage: delonix net netns attach [OPTIONS] <NAME>
Arguments:
<NAME>
Netns name (typically a container id/short-id)
Options:
--ip <IP>
IP in the infra subnet. Defaults to a deterministic one derived from `name`
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# give a netns a veth on delonix0, with an address derived from its name
delonix net netns attach dbg1
# pin the address instead, when something on the network already expects it
delonix net netns attach dbg1 --ip 10.200.0.42
SEE ALSO:
delonix net netns detach · delonix net netns exec · delonix net netns
publish
delonix › net › netns › attachExemplosExamples
delonix net netns attach minha-netnsnetns down
Force tear-down of the ingress infra (kills slirp + holder, frees the netns)
Usage: delonix net netns down [OPTIONS]
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# force the plumbing down — every container on the SDN loses its network
# until it is rebuilt, so this is an operator decision, never automatic
delonix net netns down
# the recovery after an in-place upgrade left a holder from the previous
# binary behind
delonix net netns down && delonix net netns up
SEE ALSO:
delonix net netns up · delonix net netns status · delonix container start
delonix › net › netns › downExemplosExamples
delonix net netns downnetns status
Show the ingress infra status (holder/slirp pids, bridge, refcount)
Usage: delonix net netns status [OPTIONS]
Options:
--json
Emit JSON instead of a human summary
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# the first thing to read when a container has no network
delonix net netns status
# the same facts as JSON, for a monitoring script
delonix net netns status --json
SEE ALSO:
delonix net netns up · delonix net flow · delonix system info
delonix › net › netns › statusExemplosExamples
delonix net netns statusnetns up
Bring the ingress infra up (idempotent): holder netns + delonix0 + single slirp
Usage: delonix net netns up [OPTIONS]
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# holder netns, the delonix0 bridge and the single slirp — idempotent,
# repeat it as often as you like
delonix net netns up
# it also hardens containers that are already running (IPv6 off in their
# netns) without restarting them
delonix net netns up
SEE ALSO:
delonix net netns status · delonix net netns down · delonix container run
delonix › net › netns › upExemplosExamples
delonix net netns upLaboratórioLab
Olha para dentro da infra de rede rootless que a maioria dos utilizadores nunca precisa de tocar.
delonix net netns status
delonix net netns exec -- ip addr show delonix0Look inside the rootless network infrastructure most users never need to touch.
delonix net netns status
delonix net netns exec -- ip addr show delonix0DesafioChallenge
Desliga o holder com net netns down, depois corre
QUALQUER container run — confirma que ele reaparece sozinho (ensure_up) e
que net netns status volta a mostrar tudo saudável.
Bring the holder down with net netns down, then run ANY
container run — confirm it comes back up by itself (ensure_up) and that
net netns status reports everything healthy again.