Skip to content

Add EVPN monitoring with tenant-aware queries and ADD-PATH support - #12

Open
jbemmel wants to merge 11 commits into
FastNetMon:mainfrom
jbemmel:feature/evpn-symmetric-irb
Open

jbemmel wants to merge 11 commits into
FastNetMon:mainfrom
jbemmel:feature/evpn-symmetric-irb

Conversation

@jbemmel

@jbemmel jbemmel commented Oct 1, 2026

Copy link
Copy Markdown

This PR adds support for monitoring BGP L2VPN EVPN routes through BGP and BMP, including ADD-PATH sessions.

What’s included

  • Dedicated EVPN RIB — stores EVPN routes separately from global unicast, with identity based on route type, wire-format RD, route-specific keys, and ingress, including ADD-PATH identity.
  • EVPN route decoding — decodes Type 2 MAC/IP and Type 5 IP prefix advertisements, partially decodes Types 1, 3, and 4, and preserves unknown RD-bearing route types as opaque records. Raw NLRI is retained for inspection.
  • Route-target filtering — selects routes by advertised route target, allowing tenant-related state to be inspected across multiple RDs.
  • Symmetric IRB visibility — exposes fields useful for correlating MAC-VRF and IP-VRF advertisements, including MAC/IP addresses, Ethernet tags, ESIs, gateways, both Type 2 label fields, router MAC communities, and next hops.
  • Lifecycle handling — integrates EVPN into withdrawals, peer-down handling, and ingress cleanup, including address-family-scoped withdrawals. Route identity excludes applicable forwarding fields, so label changes do not prevent withdrawal matching.
  • REST API and CLI — adds GET /api/v1/ribs/l2vpnevpn/routes and netom-cli show evpn, with filters for RD, route target, route type, VNI, prefix, ingress, and retained withdrawn routes.
  • BMP output — includes EVPN in live rebuilt updates and initial RIB dumps, preserving next hops, communities, and ADD-PATH IDs.

Label fields are exposed as raw 24-bit values; the VNI filter matches these values for VXLAN monitoring. Withdrawn records are available when withdrawn-attribute retention is enabled.

Why this matters

EVPN monitoring provides visibility into advertised overlay state across tenants and forwarding domains. Route-target filtering supports inspection across multiple RDs, while separating route identity from forwarding attributes enables consistent tracking of route updates and withdrawals.

This provides a foundation for analyzing EVPN fabrics, correlating MAC-VRF and IP-VRF advertisements, and deriving resource inventories from observed control-plane data. It reports advertised state without inferring VRF membership, assigning L2/L3 VNI roles, or simulating import policy and forwarding resolution.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

EVPN withdrawal metrics are incorrect, and full-table snapshots and cleanup introduce significant scalability problems.

Review effort: Balanced
Findings: 3 Medium severity

Open (3)
What changed in this PR

Adds tenant-aware EVPN route monitoring across the RIB, REST API, CLI, MRT/BGP ingestion, and BMP output, including ADD-PATH support.

Changes:

  • Adds EVPN NLRI decoding, storage, filtering, and lifecycle handling.
  • Adds REST and CLI querying with RD, RT, type, VNI, prefix, and ingress filters.
  • Adds EVPN BMP replay, capabilities, documentation, and tests.
File Description
test-data/​cli/​evpn-routes.json Adds CLI rendering fixtures.
src/​units/​rib_unit/​rib.rs Adds EVPN storage and lifecycle integration.
src/​units/​rib_unit/​mod.rs Exposes the EVPN module.
src/​units/​rib_unit/​http_ng.rs Adds the EVPN query endpoint.
src/​units/​rib_unit/​evpn.rs Implements EVPN decoding and metadata extraction.
src/​units/​mrt_file_in/​unit.rs Enables EVPN for MRT update ingestion.
src/​units/​bmp_tcp_out/​client_handler.rs Includes EVPN in initial BMP dumps.
src/​units/​bmp_tcp_out/​bmp_builder.rs Builds EVPN BMP updates and EORs.
src/​roto_runtime/​types.rs Converts EVPN and ADD-PATH NLRIs.
src/​roto_runtime/​runtime.rs Exposes EVPN Roto helpers.
src/​payload.rs Adds EVPN to the route payload model.
src/​bin/​netom-cli/​tree.rs Adds EVPN command grammar and filters.
src/​bin/​netom-cli/​commands/​mod.rs Registers the EVPN CLI module.
src/​bin/​netom-cli/​commands/​evpn.rs Implements EVPN querying and rendering.
README.md Advertises EVPN monitoring.
docs/​rib-query-api.md Documents the EVPN endpoint.
docs/​index.md Adds EVPN documentation navigation.
docs/​evpn.md Documents EVPN behavior and limitations.
docs/​cli.md Documents EVPN CLI commands.
doc/​netom-cli.1 Adds the EVPN man-page entry.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/units/rib_unit/rib.rs Outdated
Comment thread src/units/rib_unit/rib.rs Outdated
Comment thread src/units/rib_unit/rib.rs Outdated
@nuclearcat nuclearcat self-assigned this Oct 2, 2026
@nuclearcat
nuclearcat self-requested a review October 2, 2026 08:15
Comment thread src/payload.rs Outdated
Comment thread src/units/rib_unit/rib.rs Outdated
Comment thread src/units/rib_unit/http_ng.rs Outdated
Comment thread src/units/rib_unit/rib.rs Outdated
Comment thread src/units/rib_unit/rib.rs Outdated
@jbemmel
jbemmel marked this pull request as draft October 2, 2026 12:11
@jbemmel

jbemmel commented Oct 2, 2026

Copy link
Copy Markdown
Author

I'm thinking given the potentially large impact and trade-offs involved, it's probably better to require an explicit opt-in for this feature. Added a global enable_evpn config flag, disabled by default

@jbemmel
jbemmel marked this pull request as ready for review October 2, 2026 13:11

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants