Skip to content

Networking

VMs need to talk to each other and to the outside world. Here’s how SwarmCracker handles that.


Each VM gets a TAP device connected to a Linux bridge:

Host
├── swarm-br0 (192.168.127.1)
│ ├── tap0 ── VM1 (192.168.127.10)
│ └── tap1 ── VM2 (192.168.127.11)

VMs on the same bridge can talk directly. The host talks via the bridge IP. Internet access goes through NAT.


network:
bridge_name: "swarm-br0"
subnet: "192.168.127.0/24"
bridge_ip: "192.168.127.1/24"
ip_mode: "static" # static | dhcp
nat_enabled: true
Setting Default What It Does
bridge_name swarm-br0 The bridge name
subnet 192.168.127.0/24 IP range for VMs
bridge_ip 192.168.127.1/24 Host’s IP on the bridge
ip_mode static static (deterministic) or dhcp (dnsmasq)
nat_enabled true Let VMs reach internet

IPs come from hashing the VM ID. Same ID always gets the same IP. No DHCP needed, which makes startup faster.

If you want dynamic IPs, switch to dnsmasq-backed DHCP:

network:
ip_mode: "dhcp"

SwarmCracker starts a minimal dnsmasq instance bound to the bridge when ip_mode: "dhcp". If dnsmasq is not installed, the bridge is still created but DHCP allocation is unavailable.


If you have VMs on different workers, they need VXLAN to communicate.

Node 1 Node 2
swarm-br0 swarm-br0
┌───┐┌───┐ ┌───┐┌───┐
│VM1││VM2│ ← VXLAN UDP → │VM3││VM4│
└───┘└───┘ 4789 └───┘└───┘

When you start swarmd-firecracker with --vxlan-enabled, it creates a VXLAN interface named after the bridge (swarm-br0-vxlan for the default swarm-br0) and attaches it to the bridge:

Terminal window
swarmd-firecracker \
--vxlan-enabled \
--vxlan-peers 192.168.56.12,192.168.56.13 \
--bridge-name swarm-br0 \
--subnet 192.168.127.0/24

With a single static peer you can substitute --vxlan-peers <ip>; for dynamic discovery use --consul-enabled instead (see below).

Each node registers itself in Consul. When a new peer shows up, the VXLAN forwarding database gets updated automatically.

Terminal window
swarmd-firecracker \
--consul-enabled \
--consul-address 127.0.0.1:8500 \
--vxlan-enabled

VXLAN uses UDP port 4789:

Terminal window
sudo iptables -A INPUT -p udp --dport 4789 -j ACCEPT

SwarmCracker creates TAP devices automatically. Names follow the pattern tap-<8-char-task-hash>-<index>, where the hash is the first 8 hex characters of sha256(task-id):

tap-a1b2c3d4-0
tap-9f8e7d6c-0
Terminal window
# Create
sudo ip tuntap add dev tap0 mode tap
sudo ip link set tap0 up
sudo ip link set tap0 master swarm-br0
# Delete
sudo ip link del tap0

When nat_enabled: true, iptables masquerades outbound traffic:

Terminal window
iptables -t nat -A POSTROUTING -s 192.168.127.0/24 -j MASQUERADE
network:
nat_enabled: false

VMs can only talk to each other and the host.


Terminal window
ip link show swarm-br0 # Bridge exists?
ip link show | grep tap # TAP devices attached?

Inside the VM, check ip addr show eth0.

Terminal window
iptables -t nat -L POSTROUTING # NAT rule there?
sysctl net.ipv4.ip_forward # Should be 1

Enable forwarding if needed:

Terminal window
sudo sysctl -w net.ipv4.ip_forward=1
Terminal window
ip link show swarm-br0-vxlan # VXLAN interface up?
iptables -L INPUT | grep 4789 # Port open?
ping <other-node-ip> # Underlay reachable?

If FDB entries are missing, check Consul:

Terminal window
curl http://127.0.0.1:8500/v1/catalog/service/swarmcracker-vxlan