!VhzbGHamdfMiGxpXyg:robins.wtf

NixOS LXC

37 Members
lxc, lxd, incus discussions related to NixOS15 Servers

Load older messages


SenderMessageTime
31 Jan 2025
@adam:robins.wtfadamcstephensWhat network setup did you end up with?15:46:56
@hexa:lossy.networkhexamultichassis link aggregation, where the two L3 switches use EVPN-VXLAN between each other and provide Active/Active Gateways 15:48:26
@hexa:lossy.networkhexathen 2x25G lacp to each host15:48:50
@hexa:lossy.networkhexa * then redundant\ 2x25G lacp to each host 15:49:00
@hexa:lossy.networkhexa* then redundant 2x25G lacp to each host, with one leg to each switch15:49:10
@hexa:lossy.networkhexaand then another non-redundant network segment with 10G uplink on each host15:50:21
@hexa:lossy.networkhexaon the hosts we just use vlans and dumb bridges15:50:46
@hexa:lossy.networkhexastorage is 4x4 TB zfs on each machine15:51:09
@hexa:lossy.networkhexa* storage is 4x4 TB zfs raidz on each machine15:51:23
@adam:robins.wtfadamcstephens Vlan aware bridges? And attaching VMs the bridge with vlan in the guest config? 15:52:06
@adam:robins.wtfadamcstephens Or not vlan aware 15:52:17
@hexa:lossy.networkhexadumb bridges15:52:25
@hexa:lossy.networkhexaI'm unclear on the benefits of vlan-aware bridging tbh15:52:47
@adam:robins.wtfadamcstephens I’m not convinced vlan aware is worth the extra config. Yeah :) 15:52:52
@hexa:lossy.networkhexaI could provide a guest with a more complex network setup15:52:57
@hexa:lossy.networkhexabut that is nothing we generally do15:53:02
@adam:robins.wtfadamcstephens Unless you want to filter on an interface  15:53:06
@hexa:lossy.networkhexaI just pass two interfaces into the guest, if it should be a member of two network segments15:53:31
@hexa:lossy.networkhexawe also use none of the addressing and dns features that incus provides15:53:57
@adam:robins.wtfadamcstephens Is there a bridge per vlan? 15:54:05
@hexa:lossy.networkhexayes15:54:07
@adam:robins.wtfadamcstephens Ahh 15:54:15
@hexa:lossy.networkhexaL3 is usually provided by actual networking gear15:54:28
@adam:robins.wtfadamcstephens Right  15:54:38
@hexa:lossy.networkhexaand JunOS beats dnsmasq every day of the week15:54:44
@hexa:lossy.networkhexaoh and we have a funny gigabit link connected, that leads into a managment vrf15:55:21
@hexa:lossy.networkhexakinda like a second default route, that is unlikely to be fucked up15:55:35
@hexa:lossy.networkhexathat way you can ssh in over two addresses15:55:48
@hexa:lossy.networkhexaanyway, five to seven years in the future I hope we can find a proper FOSS solution that natively supports EVPN-VXLAN15:57:14
@adam:robins.wtfadamcstephens Do you have any Go developers? I bet you could get it added to Incus if you wrote it :) 15:59:50

Show newer messages


Back to Room ListRoom Version: 10