From 3966f8ed0ee3036cc81f42338f0473fdcbc8fc0c Mon Sep 17 00:00:00 2001 From: Joachim Wiberg Date: Thu, 29 Jan 2026 19:59:07 +0000 Subject: [PATCH] Document VETH pair limitation with containers Add documentation noting that at least one side of a VETH pair must remain in the host namespace. Both ends cannot be assigned to different containers. Updates: - container.md: Added IMPORTANT note in Container Host Interface section - infix-if-veth.yang: Added note in module description - infix-if-container.yang: Added note in host identity description Fixes: #947 Related: #941 Co-authored-by: troglobit <183517+troglobit@users.noreply.github.com> --- doc/container.md | 6 ++++++ src/confd/yang/confd/infix-if-container.yang | 6 +++++- src/confd/yang/confd/infix-if-veth.yang | 6 +++++- 3 files changed, 16 insertions(+), 2 deletions(-) diff --git a/doc/container.md b/doc/container.md index 59aca114..eb6de623 100644 --- a/doc/container.md +++ b/doc/container.md @@ -668,6 +668,12 @@ set: For an example of both, see the next section. +> [!IMPORTANT] +> **VETH Pair Limitation:** When using VETH pairs with containers, at least +> one side of the pair must remain in the host namespace. It is currently +> not possible to create VETH pairs where both ends are assigned to different +> containers. One end must always be accessible from the host. + [^3]: Something which the container bridge network type does behind the scenes with one end of an automatically created VETH pair. diff --git a/src/confd/yang/confd/infix-if-container.yang b/src/confd/yang/confd/infix-if-container.yang index f496aa4f..25cac63b 100644 --- a/src/confd/yang/confd/infix-if-container.yang +++ b/src/confd/yang/confd/infix-if-container.yang @@ -59,7 +59,11 @@ submodule infix-if-container { identity host { base container-network; - description "Host device, e.g., one end of a VETH pair or other host interface."; + description "Host device, e.g., one end of a VETH pair or other host interface. + + Note: When using VETH pairs, at least one side must remain in the + host namespace. Both ends of a VETH pair cannot be assigned to + different containers."; } /* diff --git a/src/confd/yang/confd/infix-if-veth.yang b/src/confd/yang/confd/infix-if-veth.yang index bd29d434..7feb9c00 100644 --- a/src/confd/yang/confd/infix-if-veth.yang +++ b/src/confd/yang/confd/infix-if-veth.yang @@ -13,7 +13,11 @@ submodule infix-if-veth { organization "KernelKit"; contact "kernelkit@googlegroups.com"; - description "Linux virtual Ethernet pair extension for ietf-interfaces."; + description "Linux virtual Ethernet pair extension for ietf-interfaces. + + Note: When using VETH pairs with containers, at least one side + of the pair must remain in the host namespace. Both ends of a + VETH pair cannot be assigned to different containers."; revision 2023-06-05 { description "Initial revision.";