-
Notifications
You must be signed in to change notification settings - Fork 1.6k
Add confd integration tests for BGPFilter #12142
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
song-jiang
merged 2 commits into
projectcalico:master
from
song-jiang:song-bgpfilter-confd-ut
Mar 20, 2026
Merged
Changes from 1 commit
Commits
Show all changes
2 commits
Select commit
Hold shift + click to select a range
File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
120 changes: 120 additions & 0 deletions
120
confd/tests/compiled_templates/bgpfilter/as_path_and_priority/bird.cfg
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,120 @@ | ||
| function apply_communities () | ||
| { | ||
| } | ||
|
|
||
| # Generated by confd | ||
| include "bird_aggr.cfg"; | ||
| include "bird_ipam.cfg"; | ||
|
|
||
| router id 10.192.0.2; | ||
|
|
||
| # Configure synchronization between routing tables and kernel. | ||
| protocol kernel { | ||
| learn; # Learn all alien routes from the kernel | ||
| persist; # Don't remove routes on bird shutdown | ||
| scan time 2; # Scan kernel routing table every 2 seconds | ||
| import all; | ||
| export filter calico_kernel_programming; # Default is export none | ||
| graceful restart; # Turn on graceful restart to reduce potential flaps in | ||
| # routes when reloading BIRD configuration. With a full | ||
| # automatic mesh, there is no way to prevent BGP from | ||
| # flapping since multiple nodes update their BGP | ||
| # configuration at the same time, GR is not guaranteed to | ||
| # work correctly in this scenario. | ||
| merge paths on; # Allow export multipath routes (ECMP) | ||
| } | ||
|
|
||
| # Watch interface up/down events. | ||
| protocol device { | ||
| debug { states }; | ||
| scan time 2; # Scan interfaces every 2 seconds | ||
| } | ||
|
|
||
| protocol direct { | ||
| debug { states }; | ||
| interface -"cali*", -"kube-ipvs*", "*"; # Exclude cali* and kube-ipvs* but | ||
| # include everything else. In | ||
| # IPVS-mode, kube-proxy creates a | ||
| # kube-ipvs0 interface. We exclude | ||
| # kube-ipvs0 because this interface | ||
| # gets an address for every in use | ||
| # cluster IP. We use static routes | ||
| # for when we legitimately want to | ||
| # export cluster IPs. | ||
| } | ||
|
|
||
|
|
||
| # Template for all BGP clients | ||
| template bgp bgp_template { | ||
| debug { states }; | ||
| description "Connection to BGP peer"; | ||
| local as 64512; | ||
| gateway recursive; # This should be the default, but just in case. | ||
| add paths on; | ||
| graceful restart; # See comment in kernel section about graceful restart. | ||
| connect delay time 2; | ||
| connect retry time 5; | ||
| error wait time 5,30; | ||
| } | ||
|
|
||
| # -------------- BGP Filters ------------------ | ||
| # v4 BGPFilter test-filter-aspath-prio | ||
| function 'bgp_test-filter-aspath-prio_importFilterV4'() { | ||
| if ((bgp_path ~ [= 65000 * =])) then { krt_metric = 100; accept; } | ||
| if ((bgp_path ~ [= 65000 65001 * =])) then { krt_metric = 200; accept; } | ||
| accept; | ||
| } | ||
| function 'bgp_test-filter-aspath-prio_exportFilterV4'() { | ||
| if ((krt_metric = 100)) then { bgp_community.add((65000, 100)); accept; } | ||
| if ((krt_metric = 200)) then { bgp_path.prepend(65001); bgp_path.prepend(65000); accept; } | ||
| reject; | ||
| } | ||
| # BGP Protocol Configurations | ||
| protocol bgp Global_10_192_0_3 from bgp_template { | ||
| ttl security off; | ||
| multihop; | ||
| neighbor 10.192.0.3 as 64512; | ||
| source address 10.192.0.2; # The local address we use for the TCP connection | ||
| import filter { | ||
| krt_metric = 1024; | ||
| if (defined(bgp_local_pref)) then { | ||
| krt_metric = 2147483647 - bgp_local_pref; | ||
| } | ||
| 'bgp_test-filter-aspath-prio_importFilterV4'(); | ||
| if (krt_metric < 1024) then | ||
| preference = 200; | ||
| accept; | ||
| }; | ||
| export filter { | ||
| if (!defined(krt_metric)) then { krt_metric = 1024; } | ||
| bgp_local_pref = 2147483647 - krt_metric; | ||
| 'bgp_test-filter-aspath-prio_exportFilterV4'(); | ||
| calico_export_to_bgp_peers(true); | ||
| reject; | ||
| }; # Only want to export routes for workloads. | ||
| } | ||
| protocol bgp Global_10_192_0_4 from bgp_template { | ||
| ttl security off; | ||
| multihop; | ||
| neighbor 10.192.0.4 as 64512; | ||
| source address 10.192.0.2; # The local address we use for the TCP connection | ||
| import filter { | ||
| krt_metric = 1024; | ||
| if (defined(bgp_local_pref)) then { | ||
| krt_metric = 2147483647 - bgp_local_pref; | ||
| } | ||
| 'bgp_test-filter-aspath-prio_importFilterV4'(); | ||
| if (krt_metric < 1024) then | ||
| preference = 200; | ||
| accept; | ||
| }; | ||
| export filter { | ||
| if (!defined(krt_metric)) then { krt_metric = 1024; } | ||
| bgp_local_pref = 2147483647 - krt_metric; | ||
| 'bgp_test-filter-aspath-prio_exportFilterV4'(); | ||
| calico_export_to_bgp_peers(true); | ||
| reject; | ||
| }; # Only want to export routes for workloads. | ||
| } | ||
|
|
||
|
|
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.