delonix network

Redes de utilizador: create, ls, route, inspect, rm, apply — bridge e overlay realizados fisicamente.

User networks: create, ls, inspect, rm, apply — bridge and overlay are physically realized.

Para os drivers bridge e overlay, o create orquestra o registo declarativo (NetworkStore) E o plano físico rootless em conjunto — bridge dentro do netns do holder; overlay sobe um uplink VXLAN cifrado com WireGuard entre nós (device dlxvx<vni> a masterizar a bridge, FDB semeado com os pares), tudo realizável sem privilégio de host. macvlan/ipvlan ficam só registados no store — o create AVISA alto que a rede não foi realizada fisicamente (precisam de CAP_NET_ADMIN na init-netns do host, fora do modelo rootless).

For the bridge and overlay drivers, create orchestrates both the declarative record (NetworkStore) AND the rootless physical plane together — bridge inside the holder's netns; overlay brings up a WireGuard-encrypted VXLAN uplink between nodes (a dlxvx<vni> device enslaved to the bridge, FDB seeded with the peers), all achievable without host privilege. macvlan/ipvlan only get recorded in the store — create WARNS loudly that the network wasn't physically realized (they need CAP_NET_ADMIN in the host's init-netns, outside the rootless model).

Usage: delonix network [OPTIONS] <COMMAND>

Commands:
  connect     Connect a RUNNING container to an additional network, hot
  create      Create a network
  disconnect  Disconnect a container from an additional network, hot
  rm          Remove a network
  route       Open a DIRECTED path from one network to another (ADR-0013 tier B)
  vlan        802.1Q VLAN on a physical NIC — **the one command here that needs root**
  describe    Readable detail of one or more networks, `kubectl describe` style
  diagnose    The LIVE state of this node's network, and what disagrees with it
  inspect     Detail of a network
  ls          List the networks
  apply       Apply the `kind: Network` documents of a manifest (idempotent by name)
  ipam        The IP lease registry — the `/16` anti-collision allocator
  node        WireGuard identity of THIS node, for the encrypted overlay between nodes
  help        Print this message or the help of the given subcommand(s)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

COMMAND MAP:
  Lifecycle    vlan · route · connect · disconnect · create · rm
  Inspect      diagnose · ls · inspect · describe
  Declarative  apply
  Advanced     node · ipam

EXAMPLES:
  # a bridge network of its own, where containers reach each other by name
  delonix network create app

  # what exists, with driver, bridge and subnet
  delonix network ls

  # the detail of one, including whether it was physically realized
  delonix network describe app

SEE ALSO:
  delonix container run · delonix net ingress · delonix net httproute ·
  delonix pod create

  delonix › network

network describe

Readable detail of one or more networks, kubectl describe style.

For humans; use inspect for the usual compact view.

Usage: delonix network describe [OPTIONS] <NAMES>...

Arguments:
  <NAMES>...
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # a readable block instead of the compact view
  delonix network describe app

  # several networks in one go
  delonix network describe app backend

SEE ALSO:
  delonix network inspect · delonix network ls · delonix container describe

  delonix › network › describe

ExemplosExamples

Detalhe de uma rede, estilo kubectl
Network detail, kubectl-style
delonix network describe minha-rede

network node

WireGuard identity of THIS node, for the encrypted overlay between nodes.

The VXLAN overlay of network create --driver overlay. The private key stays 0600 in <root>/wg/node.key; the public one is what you hand out to the peers.

Usage: delonix network node [OPTIONS] <COMMAND>

Commands:
  key   Print only the public key (for composing in scripts)
  init  Generate the node key and print the public one. Idempotent
  help  Print this message or the help of the given subcommand(s)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

COMMAND MAP:
  Inspect    key
  Configure  init

EXAMPLES:
  # create this node's WireGuard identity and print the public key to hand out
  delonix network node init

  # the public key alone, for composing in a script
  delonix network node key

SEE ALSO:
  delonix network create · delonix network inspect · delonix net netns status

  delonix › network › node

ExemplosExamples

A chave WireGuard DESTE nó, para dar aos pares do overlay
This node's WireGuard key, to hand out to the overlay's peers
delonix network node init
Só a chave pública, para compor num script
Just the public key, for composing in a script
delonix network node key

network create

Create a network

Usage: delonix network create [OPTIONS] <NAME>

Arguments:
  <NAME>
          

Options:
      --driver <DRIVER>
          `bridge` (default, filtered by the firewall) | `macvlan` | `ipvlan` (NOT filtered, see warning) | `overlay` (inter-node VXLAN)
          
          [default: bridge]

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --parent <PARENT>
          Host parent NIC (required for macvlan/ipvlan)

      --subnet <SUBNET>
          Subnet. For `bridge`, `10.<200-254>.0.0/16` (only /16); required for macvlan/ipvlan, e.g. `192.168.1.0/24`. Omit it and a free one is picked

      --gateway <GATEWAY>
          Gateway (macvlan/ipvlan)
          
          [default: ""]

      --vni <VNI>
          VXLAN Network Identifier (required for overlay)

      --peer <PEERS>
          Peer node (`<ip>` or `<ip>=<wg_pubkey>=<wg_ip>`), repeatable (overlay)

      --wg-ip <WG_IP>
          WireGuard tunnel IP of this node (encrypted overlay)

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # a bridge network — the default driver, and the one rootless really
  # realizes
  delonix network create app

  # pin the address space instead of letting the engine pick a free octet
  delonix network create backend --subnet 10.220.0.0/16

  # an encrypted VXLAN overlay across nodes, realized in the rootless holder
  delonix network create mesh --driver overlay --vni 42 --peer 10.0.0.7 --wg-ip 10.42.0.1

  # macvlan is registered but NOT realized without privilege — the warning
  # says so instead of pretending
  delonix network create lan --driver macvlan --parent eth0 --subnet 192.168.1.0/24

SEE ALSO:
  delonix network ls · delonix network rm · delonix network node init ·
  delonix container run

  delonix › network › create

ExemplosExamples

Rede bridge para um grupo de serviços
Bridge network for a group of services
delonix network create backend
Overlay cifrado entre nós (VXLAN + WireGuard)
Encrypted overlay between nodes (VXLAN + WireGuard)
delonix network create mesh --driver overlay --vni 42 --peer 10.0.0.2

network connect

Connect a RUNNING container to an additional network, hot.

Multi-homing — the container keeps its primary network, this adds another. Moved here from container update --net-connect (Sprint 5 of the CLI restructuring): this is Docker's own verb and argument order (docker network connect NETWORK CONTAINER), for the one operation that is about a NETWORK's membership, not a container's ports/volumes/ limits — container update keeps those, which Docker cannot do hot at all.

Usage: delonix network connect [OPTIONS] <NETWORK> <CONTAINER>

Arguments:
  <NETWORK>
          

  <CONTAINER>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # hot multi-home a running container onto a second network
  delonix network connect backend web

SEE ALSO:
  delonix network disconnect · delonix container update · delonix network
  create

  delonix › network › connect

ExemplosExamples

Multi-home a quente de um container a correr
Hot multi-home a running container
delonix network connect backend web

network disconnect

Disconnect a container from an additional network, hot.

Refuses on the PRIMARY network — that one only goes away with the container itself.

Usage: delonix network disconnect [OPTIONS] <NETWORK> <CONTAINER>

Arguments:
  <NETWORK>
          

  <CONTAINER>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # drop the extra network — the primary one stays
  delonix network disconnect backend web

SEE ALSO:
  delonix network connect · delonix container update

  delonix › network › disconnect

ExemplosExamples

Larga a rede adicional — a principal fica
Drop the extra network — the primary one stays
delonix network disconnect backend web

network ls

List the networks

Usage: delonix network ls [OPTIONS]

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -o, --output <OUTPUT>
          Output format: `table` (default) or `json` (ADR-0005)
          
          [default: table]
          [possible values: table, json]

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # name, driver, bridge and subnet of each network
  delonix network ls

  # as JSON, to feed automation
  delonix network ls -o json

SEE ALSO:
  delonix network inspect · delonix network describe · delonix dashboard

  delonix › network › ls

ExemplosExamples

delonix network ls

network route

Open a DIRECTED path from one network to another (ADR-0013 tier B).

Networks are isolated from each other by default. A route says a packet MAY cross; it does not say it is allowed — the per-workload firewall still decides, and a namespace boundary still needs its own policy.

Usage: delonix network route [OPTIONS] [FROM] [TO]

Arguments:
  [FROM]
          Source network (the side that may initiate). Omit BOTH to list every route this node declares

  [TO]
          Destination network

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

      --rm
          Close the path instead of opening it

  -o, --output <OUTPUT>
          Output format: `table` (default) or `json` (ADR-0005). Applies to the listing and to the single route the command just acted on
          
          [default: table]
          [possible values: table, json]

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # open a DIRECTED path: web may reach db, db may not reach web
  delonix network route web db

  # close it again
  delonix network route web db --rm

SEE ALSO:
  delonix network create · delonix net ingress · delonix container run

  delonix › network › route

ExemplosExamples

Todas as rotas declaradas neste nó — com o que o dataplane está a fazer a cada uma
delonix network route
Abre um caminho DIRIGIDO: web alcança db, db não alcança web
delonix network route web db
Fecha-o outra vez
delonix network route web db --rm
Para um script: contadores por rota, e null (nunca 0) quando não está viva
delonix network route -o json

network inspect

Detail of a network

Usage: delonix network inspect [OPTIONS] <NAME>

Arguments:
  <NAME>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -o, --output <OUTPUT>
          Output format: `table` (default, the historical text) or `json` (ADR-0005)
          
          [default: table]
          [possible values: table, json]

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # driver, bridge, subnet and gateway of one network
  delonix network inspect app

SEE ALSO:
  delonix network describe · delonix network ls · delonix net ingress ls

  delonix › network › inspect

ExemplosExamples

delonix network inspect backend

network rm

Remove a network

Usage: delonix network rm [OPTIONS] <NAME>

Arguments:
  <NAME>
          

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # remove a network no container is attached to — both the record and the
  # holder's bridge
  delonix network rm app

SEE ALSO:
  delonix network ls · delonix network create · delonix container update

  delonix › network › rm

ExemplosExamples

delonix network rm backend

network apply

Apply the kind: Network documents of a manifest (idempotent by name)

Usage: delonix network apply [OPTIONS]

Options:
  -f, --file <FILE>
          

      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

EXAMPLES:
  # apply only the `kind: Network` documents of a manifest, idempotent by name
  delonix network apply -f delonix-manifest.yaml

  # the networks of a shipped example, leaving the other kinds alone
  delonix network apply -f examples/network.yaml

SEE ALSO:
  delonix stack apply · delonix stack plan · delonix network create · delonix
  volume apply

  delonix › network › apply

ExemplosExamples

delonix network apply -f delonix-manifest.yaml

LaboratórioLab

Cria uma rede própria e confirma a descoberta por nome (DNS interno) entre dois containers na mesma rede.

delonix network create minha-rede
delonix container run -d --name db --net minha-rede postgres:16-alpine
delonix container run --rm --net minha-rede alpine ping -c1 db

Create your own network and confirm name-based discovery (internal DNS) between two containers on the same network.

delonix network create my-net
delonix container run -d --name db --net my-net postgres:16-alpine
delonix container run --rm --net my-net alpine ping -c1 db

DesafioChallenge

Corre network describe minha-rede e identifica que IP a rede atribuiu ao db; depois tenta network create --driver macvlan e lê o aviso — porque é que esse driver não é realizado fisicamente em rootless?

Run network describe my-net and find the IP it assigned to db; then try network create --driver macvlan and read the warning — why isn't that driver physically realized in rootless?