Merge pull request #1376 from kernelkit/copilot/review-issue-947

Document VETH pair limitation with containers
This commit is contained in:
Joachim Wiberg
2026-02-06 15:58:20 +01:00
committed by GitHub
3 changed files with 16 additions and 2 deletions
+6
View File
@@ -668,6 +668,12 @@ set:
For an example of both, see the next section.
> [!IMPORTANT]
> **VETH Pair Limitation:** When using VETH pairs with containers, at least
> one side of the pair must remain in the host namespace. It is currently
> not possible to create VETH pairs where both ends are assigned to different
> containers. One end must always be accessible from the host.
[^3]: Something which the container bridge network type does behind the
scenes with one end of an automatically created VETH pair.
+5 -1
View File
@@ -59,7 +59,11 @@ submodule infix-if-container {
identity host {
base container-network;
description "Host device, e.g., one end of a VETH pair or other host interface.";
description "Host device, e.g., one end of a VETH pair or other host interface.
Note: When using VETH pairs, at least one side must remain in the
host namespace. Both ends of a VETH pair cannot be assigned to
different containers.";
}
/*
+5 -1
View File
@@ -13,7 +13,11 @@ submodule infix-if-veth {
organization "KernelKit";
contact "kernelkit@googlegroups.com";
description "Linux virtual Ethernet pair extension for ietf-interfaces.";
description "Linux virtual Ethernet pair extension for ietf-interfaces.
Note: When using VETH pairs with containers, at least one side
of the pair must remain in the host namespace. Both ends of a
VETH pair cannot be assigned to different containers.";
revision 2023-06-05 {
description "Initial revision.";