systemd_networkd User Guide¶
This role configures host networking with systemd-networkd. It writes
.netdev, .link and .network files into /etc/systemd/network
and, optionally, starts and enables the systemd-networkd service.
The role also configures systemd-resolved, but that part is not covered
here.
Overview¶
Networking is described with two lists:
systemd_netdevsVirtual devices to create: bonds, VLANs, bridges, dummies, veth pairs. Each item maps directly onto the sections of a
.netdevfile, so any option fromsystemd.netdevcan be used.systemd_networksConfiguration applied to an interface, physical or virtual. Each item produces a
.networkfile and a.linkfile.
A device that is created in systemd_netdevs normally also needs an entry in
systemd_networks, otherwise nothing tells networkd what to do with it.
Nothing is started unless systemd_run_networkd is set to true. Until
then the role only lays down configuration files.
Common network options¶
The most frequently used keys in a systemd_networks item:
interfaceRequired. Name of the interface to match.
filenameName of the generated file without its extension. When it is omitted the role generates one from the list index, which means file names shift around if the list ever changes. Being explicit with
filenameis highly recommended in production environments.addressIP address for the interface, or the string
dhcp. May also be a list to assign several addresses.netmask/gatewayNetmask and gateway used together with
address.mtuMTU for the interface.
bond/bridgeName of the bond or bridge this interface is enslaved to.
static_routes/routing_rulesLists of routes and routing policy rules.
config_overridesFree-form dictionary merged into the generated
.networkfile. Use this for anything the keys above do not cover.
The full list of options is documented in defaults/main.yml.
Creating a bond¶
A bond needs three things: a netdev for the bond device, a network entry
for each member interface pointing at it, and a network entry for the bond
itself.
systemd_netdevs:
- NetDev:
Name: bond0
Kind: bond
Bond:
Mode: 802.3ad
TransmitHashPolicy: layer3+4
MIIMonitorSec: 1s
LACPTransmitRate: fast
systemd_networks:
# Member interfaces
- interface: "eth0"
filename: "10-general-eth0"
bond: "bond0"
mtu: 9000
- interface: "eth1"
filename: "11-general-eth1"
bond: "bond0"
mtu: 9000
# The bond itself
- interface: "bond0"
filename: "12-general-bond0"
address: "10.0.0.10"
netmask: "255.255.255.0"
gateway: "10.0.0.1"
mtu: 9000
Member interfaces must not be given an address of their own.
Creating a VLAN¶
A VLAN also needs a netdev, and the parent interface has to be told which
VLAN devices belong to it. That link is made with config_overrides on the
parent, using a set of VLAN names:
systemd_netdevs:
- NetDev:
Name: bond0.110
Kind: vlan
VLAN:
Id: 110
systemd_networks:
# Parent interface, listing its VLANs
- interface: "bond0"
filename: "12-general-bond0"
mtu: 9000
vlan: "bond0.110"
# The VLAN interface
- interface: "bond0.110"
filename: "13-general-bond0-110"
address: "172.29.236.100"
netmask: "255.255.252.0"
mtu: 9000
Add more VLANs to the same parent with a list, e.g. vlan: ["bond0.110",
"bond0.120"].
Putting a VLAN in a bridge¶
A typical OpenStack-Ansible host puts each VLAN into a bridge and addresses the bridge rather than the VLAN device:
systemd_netdevs:
- NetDev:
Name: bond0.110
Kind: vlan
VLAN:
Id: 110
- NetDev:
Name: br-mgmt
Kind: bridge
systemd_networks:
- interface: "bond0"
filename: "12-general-bond0"
mtu: 9000
vlan: "bond0.110"
- interface: "bond0.110"
filename: "13-general-bond0-110"
bridge: "br-mgmt"
mtu: 9000
- interface: "br-mgmt"
filename: "14-general-br-mgmt"
address: "172.29.236.100"
netmask: "255.255.252.0"
mtu: 9000
Static routes¶
systemd_networks:
- interface: "br-mgmt"
filename: "14-general-br-mgmt"
address: "172.29.236.100"
netmask: "255.255.252.0"
static_routes:
- cidr: "10.100.0.0/16"
gateway: "172.29.236.1"
NetworkManager on RedHat distributions¶
NetworkManager and systemd-networkd compete for the same interfaces. On
RedHat based distributions the role stops, disables and masks the NetworkManager
units whenever systemd_run_networkd is enabled. Units that are not installed
on the host are skipped.
Set systemd_networkd_disable_network_manager to false to leave
NetworkManager alone, or override
systemd_networkd_network_manager_services to change which units are masked.
Cleaning up old files¶
Setting systemd_interface_cleanup to true removes any existing
.network and .netdev files matching systemd_networkd_prefix before
new ones are written. This is useful when interfaces have been removed from the
inventory, but it will delete files this role wrote on an earlier run, so
generated file names need to be stable.