1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
|
{"name": "ovs_vswitchd_db",
"comment": "Configuration for one Open vSwitch daemon.",
"tables": {
"OpenVSwitch": {
"comment": "Configuration for an Open vSwitch daemon.",
"columns": {
"bridges": {
"comment": "Set of bridges managed by the daemon.",
"type": {"key": "uuid", "min": 0, "max": "unlimited"}},
"management_id": {
"comment": "Exactly 12 hex digits that identify the daemon.",
"type": "string"},
"controller": {
"comment": "Default Controller used by bridges.",
"type": {"key": "uuid", "min": 0, "max": 1}},
"ssl": {
"comment": "SSL used globally by the daemon.",
"type": {"key": "uuid", "min": 0, "max": 1}}}},
"Bridge": {
"comment": "Configuration for a bridge within an OpenVSwitch.",
"columns": {
"name": {
"comment": "Bridge identifier. Should be alphanumeric and no more than about 8 bytes long. Must be unique among the names of ports, interfaces, and bridges on a host.",
"type": "string"},
"datapath_id": {
"comment": "OpenFlow datapath ID. Exactly 12 hex digits.",
"type": {"key": "string", "min": 0, "max": 1}},
"hwaddr": {
"comment": "Ethernet address to use for bridge. Exactly 12 hex digits in the form XX:XX:XX:XX:XX:XX.",
"type": {"key": "string", "min": 0, "max": 1}},
"ports": {
"comment": "Ports included in the bridge.",
"type": {"key": "uuid", "min": 0, "max": "unlimited"}},
"mirrors": {
"comment": "Port mirroring configuration.",
"type": {"key": "uuid", "min": 0, "max": "unlimited"}},
"netflow": {
"comment": "NetFlow configuration.",
"type": {"key": "uuid", "min": 0, "max": "unlimited"}},
"controller": {
"comment": "OpenFlow controller. If unset, defaults to that specified by the parent OpenVSwitch.",
"type": {"key": "uuid", "min": 0, "max": 1}}}},
"Port": {
"comment": "A port within a Bridge. May contain a single Interface or multiple (bonded) Interfaces.",
"columns": {
"name": {
"comment": "Port name. Should be alphanumeric and no more than about 8 bytes long. May be the same as the interface name, for non-bonded ports. Must otherwise be unique among the names of ports, interfaces, and bridges on a host.",
"type": "string"},
"interfaces": {
"comment": "The Port's Interfaces. If there is more than one, this is a bonded Port.",
"type": {"key": "uuid", "min": 1, "max": "unlimited"}},
"trunks": {
"comment": "The 802.1Q VLAN(s) that this port trunks. Should be empty if this port trunks all VLAN(s) or if this is not a trunk port.",
"type": {"key": "integer", "min": 0, "max": 4096}},
"tag": {
"comment": "This port's implicitly tagged VLAN. Should be empty if this is a trunk port.",
"type": {"key": "integer", "min": 0, "max": 1}},
"updelay": {
"comment": "For a bonded port, the number of milliseconds for which carrier must stay up on an interface before the interface is considered to be up. Ignored for non-bonded ports.",
"type": "integer"},
"downdelay": {
"comment": "For a bonded port, the number of milliseconds for which carrier must stay down on an interface before the interface is considered to be down. Ignored for non-bonded ports.",
"type": "integer"}}},
"Interface": {
"comment": "An interface within a Port.",
"columns": {
"name": {
"comment": "Interface name. Should be alphanumeric and no more than about 8 bytes long. May be the same as the port name, for non-bonded ports. Must otherwise be unique among the names of ports, interfaces, and bridges on a host.",
"type": "string"},
"internal": {
"comment": "An \"internal\" port is one that is implemented in software as a logical device.",
"type": "boolean"},
"ingress_policing_rate": {
"comment": "Maximum rate for data received on this interface, in kbps. Set to 0 to disable policing.",
"type": "integer"},
"ingress_policing_burst": {
"comment": "Maximum burst size for data received on this interface, in kb. The default burst size if set to 0 is 10 kb.",
"type": "integer"}}},
"Mirror": {
"comment": "A port mirror within a Bridge.",
"columns": {
"name": {
"comment": "Arbitrary identifier for the Mirror.",
"type": "string"},
"select_src_port": {
"comment": "Ports on which arriving packets are selected for mirroring.",
"type": {"key": "uuid", "min": 0, "max": "unlimited"}},
"select_dst_port": {
"comment": "Ports on which departing packets are selected for mirroring.",
"type": {"key": "uuid", "min": 0, "max": "unlimited"}},
"select_vlan": {
"comment": "VLANs on which packets are selected for mirroring.",
"type": {"key": "integer", "min": 0, "max": 4096}},
"output_port": {
"comment": "Output port for selected packets. Mutually exclusive with output_vlan.",
"type": {"key": "uuid", "min": 0, "max": 1}},
"output_vlan": {
"comment": "Output VLAN for selected packets. Mutually exclusive with output_vlan.",
"type": {"key": "integer", "min": 0, "max": 1}}}},
"Netflow": {
"comment": "A Netflow target.",
"columns": {
"target": {
"comment": "Netflow target in the form \"IP:PORT\".",
"type": "string"},
"engine_type": {
"comment": "Engine type to use in NetFlow messages. Defaults to datapath ID if not specified.",
"type": "integer"},
"engine_id": {
"comment": "Engine ID to use in NetFlow messages. Defaults to datapath ID if not specified.",
"type": "integer"},
"add_id_to_interface": {
"comment": "Place least-significant 7 bits of engine ID into most significant bits of ingress and egress interface fields of NetFlow records?",
"type": "boolean"}}},
"Controller": {
"comment": "An OpenFlow controller.",
"columns": {
"target": {
"comment": "Connection method for controller, e.g. \"ssl:...\", \"tcp:...\". The special string \"discover\" enables controller discovery.",
"type": "string"},
"max_backoff": {
"comment": "Maximum number of milliseconds to wait between connection attempts. Default is implementation-specific.",
"type": {"key": "integer", "min": 0, "max": 1}},
"inactivity_probe": {
"comment": "Maximum number of milliseconds of idle time on connection to controller before sending an inactivity probe message. Default is implementation-specific.",
"type": {"key": "integer", "min": 0, "max": 1}},
"fail_mode": {
"comment": "Either \"standalone\" or \"secure\", or empty to use the implementation's default.",
"type": {"key": "string", "min": 0, "max": 1}},
"discovery_accept_regex": {
"comment": "If \"target\" is \"discovery\", a POSIX extended regular expression against which the discovered controller location is validated. If not specified, the default is implementation-specific.",
"type": {"key": "string", "min": 0, "max": 1}},
"discovery_update_resolv_conf": {
"comment": "If \"target\" is \"discovery\", whether to update /etc/resolv.conf when the controller is discovered. If not specified, the default is implementation-specific.",
"type": {"key": "boolean", "min": 0, "max": 1}},
"connection_mode": {
"comment": "Either \"in-band\" or \"out-of-band\". If not specified, the default is implementation-specific.",
"type": {"key": "string", "min": 0, "max": 1}},
"local_ip": {
"comment": "If \"target\" is not \"discovery\", the IP address to configure on the local port.",
"type": {"key": "string", "min": 0, "max": 1}},
"local_netmask": {
"comment": "If \"target\" is not \"discovery\", the IP netmask to configure on the local port.",
"type": {"key": "string", "min": 0, "max": 1}},
"local_gateway": {
"comment": "If \"target\" is not \"discovery\", the IP gateway to configure on the local port.",
"type": {"key": "string", "min": 0, "max": 1}},
"controller_rate_limit": {
"comment": "The maximum rate at which packets will be forwarded to the OpenFlow controller, in packets per second. If not specified, the default is implementation-specific.",
"type": {"key": "integer", "min": 0, "max": 1}},
"controller_burst_limit": {
"comment": "The maximum number of unused packet credits that the bridge will allow to accumulate, in packets. If not specified, the default is implementation-specific.",
"type": {"key": "integer", "min": 0, "max": 1}}}},
"SSL": {
"comment": "SSL configuration for an OpenVSwitch.",
"columns": {
"private_key": {
"comment": "Name of a PEM file containing the private key used as the switch's identity for SSL connections to the controller.",
"type": "string"},
"certificate": {
"comment": "Name of a PEM file containing a certificate, signed by the certificate authority (CA) used by the controller and manager, that certifies the switch's private key, identifying a trustworthy switch.",
"type": "string"},
"ca_cert": {
"comment": "Name of a PEM file containing the CA certificate used to verify that the switch is connected to a trustworthy controller.",
"type": "string"}}}}}
|