RWS Architecture article

Network addressing policy test matrix

Minimum addressing policy tests required before promotion.

  1. Typetopic
  2. Statusactive
  3. Domainnetwork
On this page
  1. Topic - Network addressing policy test matrix
  2. Overview
  3. Context
  4. Applicable Principles
  5. Decisions
  6. Current State
  7. Baseline tests and required evidence
  8. Future Work

Topic - Network addressing policy test matrix

Overview

Minimum addressing policy tests required before promotion.

Context

This matrix turns addressing policy into repeatable gates. It is the canonical test set referenced by network-addressing-guardrails and change evidence bundles.

Applicable Principles

Decisions

  • All in-scope addressing changes use this matrix as baseline gate set.
  • Failed critical tests block promotion until corrected or approved through exception governance.
  • Test results are stored with parser and command-profile metadata.
  • Tests anchored to adr-023-ipv6-numberplan-and-cluster-scale-strategy are interim working-direction gates while ADR-023 remains draft.

Current State

Baseline tests and required evidence

Test IDPolicy anchorPass criteriaEvidence artifactOwnerFrequencySeverity
ADDR-001network-addressing-guardrails overlap prohibitionNo duplicate prefix in unauthorized shared VRFRoute-policy parse report plus VRF route snapshotNetwork ArchitectureEvery changeBlocker
ADDR-002network-addressing-guardrails boundary-only overlap accessOverlap traffic exits only via approved boundary endpointFlow verification record and boundary policy proofNetwork + SecurityEvery exception changeBlocker
ADDR-003openshift-evpn-production-target-baseline NAT postureNo unintended node-level NAT on routed defaultsSource-identity check and conntrack impact recordPlatform + NetworkEvery changeBlocker
ADDR-004adr-023-ipv6-numberplan-and-cluster-scale-strategy (draft working direction) profile modelRequested profile fits approved pool with growth bufferCapacity calculation reportNetwork ArchitectureEvery profile-affecting changeBlocker
ADDR-005adr-023-ipv6-numberplan-and-cluster-scale-strategy (draft working direction) category usageNC1 and NC2 mappings are correct; NC3 and NC5 usage follows policyCategory assignment checkNetwork ArchitectureGovernment-facing changeMajor
ADDR-006topic-network-ip-addressing-scale-and-vrf-model support envelopeCapacity math includes product support reference and owner sign-offChange record reviewNetwork ArchitectureHigh-density requestMajor

Future Work

  • Add machine-readable policy IDs in NetBox so each change auto-selects expected tests.
  • Add failover-path variants for overlap exception flows.
  • Add stale-exception detection based on expiry metadata from network-addressing-guardrails.