Skip to content

History / vpp

Revisions

  • docs(wiki): sync wiki with 505422597..10d198be3 (835 commits) New pages: none. Every change lands on a page that already existed. Updated 52 existing pages, from 181 user-facing commits in the range. Areas: the CLI and its pipe operators, BGP and the RIB, RPKI and IRR filtering, FlowSpec, plugins and the plugin SDK wire format, IPsec, interfaces and the VPP dataplane, the firewall, DDoS and anomaly detection, configuration and YANG, and the REST, gRPC, MCP and web surfaces. Two entries record a feature that had never run. The FlowSpec to firewall bridge read a flat event envelope no writer produces, so every FlowSpec route a peer sent was dropped in silence. BGP-LS attribute validation was registered for no attribute code, so a live session validated nothing. Both had passing tests. ddos.md and status.md now say what works and when it started working. Two spellings changed under operators: show bgp summary is now show bgp, with summary and peers as pipe aliases, and a one-scope OSPF router-information config advertises at the one scope written rather than at both. The wiki command catalog and the llms files are regenerated, not hand-edited. Links check clean over 179 pages. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

    @thomas-mangin thomas-mangin committed Aug 29, 2026
  • docs(wiki): sync wiki with acbef856e..505422597 (795 commits) New pages: dns.md, the shared authoritative DNS harness behind as112 and geodns, plus the caching resolver. Updated 94 existing pages. Feature areas covered: IKE/IPsec RFC 7296 conformance, EAP-TLS 1.3 and kernel dataplane read-back; BGP communities (RFC 1997 egress suppression, RFC 7999 blackhole agreement, RFC 7454 scrub); dynamic peer groups; RFC 9234 roles and OTC; RFC 4271 Section 5 egress attribute rules; RFC 7606 typed-family discard; RFC 7911 path-identifier regeneration; protocol event capture and replay; RPKI sync reporting and blackhole exemption; RIB-to-FIB forwarding actions; IS-IS LSDB operations; OSPF RFC 3101 NSSA defaults; BMP delivery bounds; MRT damage reporting; PPPoE subscriber authentication; L2TP accounting attributes; DNS answer policy; DDoS mitigation lifetime; IPv6 Router Advertisements; VPP and firewall reconcile deadlines; the templ and htmx 4 rendering cutover for the web UI and Looking Glass; MCP protocol revision 2026-07-28; startup config validation; the management listener exposure guard; PKI-backed TLS; the verb-first CLI migration; appliance kernel and build gates; and the RFC requirement ledger. Corrections to claims the code no longer supports: MOBIKE is not implemented, the BGP hold-timer grace period was deleted, the IPsec virtual IP pool is not wired, the Looking Glass defaults to TLS on, MCP tool names were wrong, and about twenty-five removed bare command spellings were replaced with their registered verb-first forms. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01FwRCPDR1JhZFg5aynjDQoo

    @thomas-mangin thomas-mangin committed Aug 16, 2026
  • docs(wiki): repoint every repo link at github.com/ze-software/ze Codeberg's 2026-07-23 LLM policy made hosting development there untenable, so the module path and origin moved to github.com/ze-software/ze (main 34cd33b87). Every clone URL, browse link, issue link and Go import path in the wiki still named a repository the project has left. Three forms needed three different targets, which is why this was scripted rather than sed'd: a browse link becomes /blob/main/ for a file and /tree/main/ for a directory, an import path just swaps its root, and the clone, issues and wiki links each have their own GitHub shape. The two prose labels that named Codeberg (the footer's "Source on Codeberg" and Home's "development on Codeberg") are corrected too, since the rewrite would otherwise leave them contradicting their own links. bin/gen-llms-txt.go carried the old base URL as its default, so every regeneration would have reintroduced 177 stale links into llms.txt. Fixed at the source rather than in the generated output. The Codeberg wiki remains a single-page redirect, so the remotes described in the untracked CLAUDE.md are unchanged and still accurate. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

    @thomas-mangin thomas-mangin committed Jul 25, 2026
  • docs(wiki): sync wiki with cc71d46e2..075d46b4b (440 commits) New pages: as112, radius, ddos, anomaly. Updated existing pages covering: IPsec IKEv2 responder and real make-before-break rekeying; OSPF extension family (Segment Routing, TE, TI-LFA, graceful restart, virtual links, NBMA, point-to- multipoint, multi-instance, OSPFv3 IPsec); VPP tunnels, SPAN, WireGuard, LCP pairs, DSCP policing, and static routes; L2TP LAC initiator and PPPoE-to-L2TP relay; appliance pure-Go initrd and startup resilience; build-time feature gates; web RBAC, AAA-chain login, config transfer, and i18n; verb-first CLI and new show, announce, anomaly, and ddos verbs; DDoS mitigation; behavioral anomaly detection; encrypted and validated DNS (DoT, DoH, DNSSEC); RADIUS operator auth; GTSM and CoPP control-plane protection. Refreshed feature-inventory, status, plugins, comparison, glossary, and _Sidebar; regenerated llms.txt and llms-full.txt. Corrected stale show ip ospf to show ospf and show ipsec to show vpn ipsec commands. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Ny5i2V6UuvNF8TQG4WN1zv

    @thomas-mangin thomas-mangin committed Jul 13, 2026
  • Deep update for l2tp, firewall, vpp, appliance, and monitoring l2tp: rewrite with RADIUS auth/acct/CoA, IP pools, traffic shaping, CQM metrics, session observer, Prometheus metrics, web UI, kernel integration detail, and environment variables. firewall: rewrite with full match/action tables, VPP backend (NAT44-ED, ACL classify), named sets with timeouts, NAT exclude pattern. vpp: MPLS label programming now implemented (was "not yet wired"), add firewall VPP backend cross-reference, update roadmap table. appliance: add ze appliance management CLI (init, build, push, config-push with auto-revert, export/import, batch parallel ops). monitoring: add OS metrics (Netdata-compatible collectors), host hardware metrics (ze_host_* namespace), diagnostics section (FSM history, capture rings, VPP trace, active probes, structured log query, component health endpoint). Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

    @thomas-mangin thomas-mangin committed May 14, 2026
  • wiki: sync with 538 commits of April development The wiki was pinned to 7fcc808 (2026-04-11) while the codebase added BFD, BMP, L2TP/PPP, firewall, traffic control, VPP integration, WireGuard, tunnel interfaces, TACACS+, NTP, sysctl, route reflector, route filters, gRPC API, and many more features across 538 commits. Updated 13 existing pages to fix factually wrong claims (BFD/BMP "not implemented", 32 plugin count, tunnels "not implemented") and reflect the current feature set. Created 9 new pages for the major new subsystems. Bumped .source-commit to current HEAD. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>

    @thomas-mangin thomas-mangin committed Apr 21, 2026