delonix network
Redes de utilizador: create, ls, route, inspect, rm, apply — bridge e overlay realizados fisicamente.
User networks: create, ls, inspect, rm, apply — bridge and overlay are physically realized.
Para os drivers bridge e overlay, o create
orquestra o registo declarativo (NetworkStore) E o plano físico rootless em conjunto —
bridge dentro do netns do holder; overlay sobe um uplink VXLAN cifrado com
WireGuard entre nós (device dlxvx<vni> a masterizar a bridge, FDB semeado com os
pares), tudo realizável sem privilégio de host. macvlan/ipvlan ficam só
registados no store — o create AVISA alto que a rede não foi realizada fisicamente
(precisam de CAP_NET_ADMIN na init-netns do host, fora do modelo rootless).
For the bridge and overlay drivers,
create orchestrates both the declarative record (NetworkStore) AND the
rootless physical plane together — bridge inside the holder's netns;
overlay brings up a WireGuard-encrypted VXLAN uplink between nodes (a
dlxvx<vni> device enslaved to the bridge, FDB seeded with the peers), all
achievable without host privilege. macvlan/ipvlan only get recorded in
the store — create WARNS loudly that the network wasn't physically realized (they
need CAP_NET_ADMIN in the host's init-netns, outside the rootless model).
📄 Implementação real em Rust: cmd/network.rs
Usage: delonix network [OPTIONS] <COMMAND>
Commands:
connect Connect a RUNNING container to an additional network, hot
create Create a network
disconnect Disconnect a container from an additional network, hot
rm Remove a network
route Open a DIRECTED path from one network to another (ADR-0013 tier B)
vlan 802.1Q VLAN on a physical NIC — **the one command here that needs root**
describe Readable detail of one or more networks, `kubectl describe` style
diagnose The LIVE state of this node's network, and what disagrees with it
inspect Detail of a network
ls List the networks
apply Apply the `kind: Network` documents of a manifest (idempotent by name)
ipam The IP lease registry — the `/16` anti-collision allocator
node WireGuard identity of THIS node, for the encrypted overlay between nodes
help Print this message or the help of the given subcommand(s)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
COMMAND MAP:
Lifecycle vlan · route · connect · disconnect · create · rm
Inspect diagnose · ls · inspect · describe
Declarative apply
Advanced node · ipam
EXAMPLES:
# a bridge network of its own, where containers reach each other by name
delonix network create app
# what exists, with driver, bridge and subnet
delonix network ls
# the detail of one, including whether it was physically realized
delonix network describe app
SEE ALSO:
delonix container run · delonix net ingress · delonix net httproute ·
delonix pod create
delonix › networknetwork describe
Readable detail of one or more networks, kubectl describe style.
For humans; use inspect for the usual compact view.
Usage: delonix network describe [OPTIONS] <NAMES>...
Arguments:
<NAMES>...
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# a readable block instead of the compact view
delonix network describe app
# several networks in one go
delonix network describe app backend
SEE ALSO:
delonix network inspect · delonix network ls · delonix container describe
delonix › network › describeExemplosExamples
delonix network describe minha-redenetwork node
WireGuard identity of THIS node, for the encrypted overlay between nodes.
The VXLAN overlay of network create --driver overlay. The private key stays 0600 in <root>/wg/node.key; the public one is what you hand out to the peers.
Usage: delonix network node [OPTIONS] <COMMAND>
Commands:
key Print only the public key (for composing in scripts)
init Generate the node key and print the public one. Idempotent
help Print this message or the help of the given subcommand(s)
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
COMMAND MAP:
Inspect key
Configure init
EXAMPLES:
# create this node's WireGuard identity and print the public key to hand out
delonix network node init
# the public key alone, for composing in a script
delonix network node key
SEE ALSO:
delonix network create · delonix network inspect · delonix net netns status
delonix › network › nodeExemplosExamples
delonix network node initdelonix network node keynetwork create
Create a network
Usage: delonix network create [OPTIONS] <NAME>
Arguments:
<NAME>
Options:
--driver <DRIVER>
`bridge` (default, filtered by the firewall) | `macvlan` | `ipvlan` (NOT filtered, see warning) | `overlay` (inter-node VXLAN)
[default: bridge]
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--parent <PARENT>
Host parent NIC (required for macvlan/ipvlan)
--subnet <SUBNET>
Subnet. For `bridge`, `10.<200-254>.0.0/16` (only /16); required for macvlan/ipvlan, e.g. `192.168.1.0/24`. Omit it and a free one is picked
--gateway <GATEWAY>
Gateway (macvlan/ipvlan)
[default: ""]
--vni <VNI>
VXLAN Network Identifier (required for overlay)
--peer <PEERS>
Peer node (`<ip>` or `<ip>=<wg_pubkey>=<wg_ip>`), repeatable (overlay)
--wg-ip <WG_IP>
WireGuard tunnel IP of this node (encrypted overlay)
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# a bridge network — the default driver, and the one rootless really
# realizes
delonix network create app
# pin the address space instead of letting the engine pick a free octet
delonix network create backend --subnet 10.220.0.0/16
# an encrypted VXLAN overlay across nodes, realized in the rootless holder
delonix network create mesh --driver overlay --vni 42 --peer 10.0.0.7 --wg-ip 10.42.0.1
# macvlan is registered but NOT realized without privilege — the warning
# says so instead of pretending
delonix network create lan --driver macvlan --parent eth0 --subnet 192.168.1.0/24
SEE ALSO:
delonix network ls · delonix network rm · delonix network node init ·
delonix container run
delonix › network › createExemplosExamples
delonix network create backenddelonix network create mesh --driver overlay --vni 42 --peer 10.0.0.2network connect
Connect a RUNNING container to an additional network, hot.
Multi-homing — the container keeps its primary network, this adds another. Moved here from container update --net-connect (Sprint 5 of the CLI restructuring): this is Docker's own verb and argument order (docker network connect NETWORK CONTAINER), for the one operation that is about a NETWORK's membership, not a container's ports/volumes/ limits — container update keeps those, which Docker cannot do hot at all.
Usage: delonix network connect [OPTIONS] <NETWORK> <CONTAINER>
Arguments:
<NETWORK>
<CONTAINER>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# hot multi-home a running container onto a second network
delonix network connect backend web
SEE ALSO:
delonix network disconnect · delonix container update · delonix network
create
delonix › network › connectExemplosExamples
delonix network connect backend webnetwork disconnect
Disconnect a container from an additional network, hot.
Refuses on the PRIMARY network — that one only goes away with the container itself.
Usage: delonix network disconnect [OPTIONS] <NETWORK> <CONTAINER>
Arguments:
<NETWORK>
<CONTAINER>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# drop the extra network — the primary one stays
delonix network disconnect backend web
SEE ALSO:
delonix network connect · delonix container update
delonix › network › disconnectExemplosExamples
delonix network disconnect backend webnetwork ls
List the networks
Usage: delonix network ls [OPTIONS]
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-o, --output <OUTPUT>
Output format: `table` (default) or `json` (ADR-0005)
[default: table]
[possible values: table, json]
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# name, driver, bridge and subnet of each network
delonix network ls
# as JSON, to feed automation
delonix network ls -o json
SEE ALSO:
delonix network inspect · delonix network describe · delonix dashboard
delonix › network › lsExemplosExamples
delonix network lsnetwork route
Open a DIRECTED path from one network to another (ADR-0013 tier B).
Networks are isolated from each other by default. A route says a packet MAY cross; it does not say it is allowed — the per-workload firewall still decides, and a namespace boundary still needs its own policy.
Usage: delonix network route [OPTIONS] [FROM] [TO]
Arguments:
[FROM]
Source network (the side that may initiate). Omit BOTH to list every route this node declares
[TO]
Destination network
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
--rm
Close the path instead of opening it
-o, --output <OUTPUT>
Output format: `table` (default) or `json` (ADR-0005). Applies to the listing and to the single route the command just acted on
[default: table]
[possible values: table, json]
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# open a DIRECTED path: web may reach db, db may not reach web
delonix network route web db
# close it again
delonix network route web db --rm
SEE ALSO:
delonix network create · delonix net ingress · delonix container run
delonix › network › routeExemplosExamples
delonix network routedelonix network route web dbdelonix network route web db --rmdelonix network route -o jsonnetwork inspect
Detail of a network
Usage: delonix network inspect [OPTIONS] <NAME>
Arguments:
<NAME>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-o, --output <OUTPUT>
Output format: `table` (default, the historical text) or `json` (ADR-0005)
[default: table]
[possible values: table, json]
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# driver, bridge, subnet and gateway of one network
delonix network inspect app
SEE ALSO:
delonix network describe · delonix network ls · delonix net ingress ls
delonix › network › inspectExemplosExamples
delonix network inspect backendnetwork rm
Remove a network
Usage: delonix network rm [OPTIONS] <NAME>
Arguments:
<NAME>
Options:
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# remove a network no container is attached to — both the record and the
# holder's bridge
delonix network rm app
SEE ALSO:
delonix network ls · delonix network create · delonix container update
delonix › network › rmExemplosExamples
delonix network rm backendnetwork apply
Apply the kind: Network documents of a manifest (idempotent by name)
Usage: delonix network apply [OPTIONS]
Options:
-f, --file <FILE>
--l18n <en|pt>
Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand
-h, --help
Print help (see a summary with '-h')
EXAMPLES:
# apply only the `kind: Network` documents of a manifest, idempotent by name
delonix network apply -f delonix-manifest.yaml
# the networks of a shipped example, leaving the other kinds alone
delonix network apply -f examples/network.yaml
SEE ALSO:
delonix stack apply · delonix stack plan · delonix network create · delonix
volume apply
delonix › network › applyExemplosExamples
delonix network apply -f delonix-manifest.yamlLaboratórioLab
Cria uma rede própria e confirma a descoberta por nome (DNS interno) entre dois containers na mesma rede.
delonix network create minha-rede
delonix container run -d --name db --net minha-rede postgres:16-alpine
delonix container run --rm --net minha-rede alpine ping -c1 dbCreate your own network and confirm name-based discovery (internal DNS) between two containers on the same network.
delonix network create my-net
delonix container run -d --name db --net my-net postgres:16-alpine
delonix container run --rm --net my-net alpine ping -c1 dbDesafioChallenge
Corre network describe minha-rede e identifica que
IP a rede atribuiu ao db; depois tenta network create --driver macvlan e
lê o aviso — porque é que esse driver não é realizado fisicamente em rootless?
Run network describe my-net and find the IP it assigned to
db; then try network create --driver macvlan and read the warning — why
isn't that driver physically realized in rootless?