Files
poc-frr-anycast/docker-compose.yml
T

177 lines
5.0 KiB
YAML
Raw Normal View History

name: poc-frr-anycast
networks:
# Note: /29 rather than /30 — Docker's bridge driver always claims the first
# usable address of a subnet as the network gateway (even with internal:
# true), so the actual /30 peering addresses (.1/.2, matching hld.md) need
# room alongside it; the gateway is pushed to .6, which nothing else uses.
link-a1-b1:
driver: bridge
internal: true
ipam:
config: [{subnet: 10.0.1.0/29, gateway: 10.0.1.6}]
link-a1-b2:
driver: bridge
internal: true
ipam:
config: [{subnet: 10.0.2.0/29, gateway: 10.0.2.6}]
link-a2-b1:
driver: bridge
internal: true
ipam:
config: [{subnet: 10.0.3.0/29, gateway: 10.0.3.6}]
link-a2-b2:
driver: bridge
internal: true
ipam:
config: [{subnet: 10.0.4.0/29, gateway: 10.0.4.6}]
link-a3-b1:
driver: bridge
internal: true
ipam:
config: [{subnet: 10.0.5.0/29, gateway: 10.0.5.6}]
link-a3-b2:
driver: bridge
internal: true
ipam:
config: [{subnet: 10.0.6.0/29, gateway: 10.0.6.6}]
net-b1-clients:
driver: bridge
internal: true
ipam:
config: [{subnet: 10.100.1.0/24, gateway: 10.100.1.254}]
net-b2-clients:
driver: bridge
internal: true
ipam:
config: [{subnet: 10.100.2.0/24, gateway: 10.100.2.254}]
x-frr-a: &frr-a
image: frrouting/frr:latest
cap_add: [NET_ADMIN, NET_RAW, SYS_ADMIN]
sysctls:
net.ipv4.ip_forward: 1
entrypoint: ["/sbin/tini", "--", "/entrypoints/a-entrypoint.sh"]
x-frr-b: &frr-b
image: frrouting/frr:latest
cap_add: [NET_ADMIN, NET_RAW, SYS_ADMIN]
sysctls:
net.ipv4.ip_forward: 1
# default policy (0) hashes ECMP nexthop on src/dst IP only, ignoring L4
# ports - with a single client IP that pins every flow to the same A-node.
# Policy 1 adds L4 ports to the hash, matching the 5-tuple ECMP behavior
# described in hld.md.
net.ipv4.fib_multipath_hash_policy: 1
entrypoint: ["/sbin/tini", "--", "/entrypoints/b-entrypoint.sh"]
x-client: &client
image: nicolaka/netshoot
cap_add: [NET_ADMIN]
entrypoint: ["/entrypoints/client-entrypoint.sh"]
services:
# --- Site A: AS 65001, anycast 10.200.200.1/32 on dummy0 ---
a1:
<<: *frr-a
hostname: a1
volumes:
- ./frr/a1:/etc/frr
- ./entrypoints/a-entrypoint.sh:/entrypoints/a-entrypoint.sh:ro
networks:
link-a1-b1: {ipv4_address: 10.0.1.1}
link-a1-b2: {ipv4_address: 10.0.2.1}
a2:
<<: *frr-a
hostname: a2
volumes:
- ./frr/a2:/etc/frr
- ./entrypoints/a-entrypoint.sh:/entrypoints/a-entrypoint.sh:ro
networks:
link-a2-b1: {ipv4_address: 10.0.3.1}
link-a2-b2: {ipv4_address: 10.0.4.1}
a3:
<<: *frr-a
hostname: a3
volumes:
- ./frr/a3:/etc/frr
- ./entrypoints/a-entrypoint.sh:/entrypoints/a-entrypoint.sh:ro
networks:
link-a3-b1: {ipv4_address: 10.0.5.1}
link-a3-b2: {ipv4_address: 10.0.6.1}
# --- Site B: AS 65002 / 65003, client networks ---
b1:
<<: *frr-b
hostname: b1
volumes:
- ./frr/b1:/etc/frr
- ./entrypoints/b-entrypoint.sh:/entrypoints/b-entrypoint.sh:ro
networks:
link-a1-b1: {ipv4_address: 10.0.1.2}
link-a2-b1: {ipv4_address: 10.0.3.2}
link-a3-b1: {ipv4_address: 10.0.5.2}
net-b1-clients: {ipv4_address: 10.100.1.1}
b2:
<<: *frr-b
hostname: b2
volumes:
- ./frr/b2:/etc/frr
- ./entrypoints/b-entrypoint.sh:/entrypoints/b-entrypoint.sh:ro
networks:
link-a1-b2: {ipv4_address: 10.0.2.2}
link-a2-b2: {ipv4_address: 10.0.4.2}
link-a3-b2: {ipv4_address: 10.0.6.2}
net-b2-clients: {ipv4_address: 10.100.2.1}
# --- Клиенты площадки B (доверенная сеть) ---
c1:
<<: *client
hostname: c1
environment: {GATEWAY: 10.100.1.1}
volumes: ["./entrypoints/client-entrypoint.sh:/entrypoints/client-entrypoint.sh:ro"]
networks:
net-b1-clients: {ipv4_address: 10.100.1.11}
c2:
<<: *client
hostname: c2
environment: {GATEWAY: 10.100.1.1}
volumes: ["./entrypoints/client-entrypoint.sh:/entrypoints/client-entrypoint.sh:ro"]
networks:
net-b1-clients: {ipv4_address: 10.100.1.12}
c3:
<<: *client
hostname: c3
environment: {GATEWAY: 10.100.1.1}
volumes: ["./entrypoints/client-entrypoint.sh:/entrypoints/client-entrypoint.sh:ro"]
networks:
net-b1-clients: {ipv4_address: 10.100.1.13}
c4:
<<: *client
hostname: c4
environment: {GATEWAY: 10.100.2.1}
volumes: ["./entrypoints/client-entrypoint.sh:/entrypoints/client-entrypoint.sh:ro"]
networks:
net-b2-clients: {ipv4_address: 10.100.2.14}
c5:
<<: *client
hostname: c5
environment: {GATEWAY: 10.100.2.1}
volumes: ["./entrypoints/client-entrypoint.sh:/entrypoints/client-entrypoint.sh:ro"]
networks:
net-b2-clients: {ipv4_address: 10.100.2.15}
c6:
<<: *client
hostname: c6
environment: {GATEWAY: 10.100.2.1}
volumes: ["./entrypoints/client-entrypoint.sh:/entrypoints/client-entrypoint.sh:ro"]
networks:
net-b2-clients: {ipv4_address: 10.100.2.16}