RWS Architecture article

Network Addressing Guardrails

Operational addressing guardrails for network and OpenShift changes. This note is a review contract: default behavior, prohibited behavior, and exception evidence requirements.

  1. Typearchitecture
  2. Statusactive
  3. Domainnetwork
On this page
  1. Summary
  2. Applicable Principles
  3. Architecture
  4. Guardrail matrix (default/prohibited/exception plus evidence)
  5. Decisions
  6. Open Questions

Summary

Operational addressing guardrails for network and OpenShift changes. This note is a review contract: default behavior, prohibited behavior, and exception evidence requirements.

Applicable Principles

Architecture

Guardrail matrix (default/prohibited/exception plus evidence)

Control areaDefaultProhibitedException pathMinimum evidenceOwnerMax validityRevalidation trigger
Routed tenant addressingUnique prefixes per routed VRF scope (CUDN default)Overlapping prefixes leaked into shared routed domainsOverlap only in isolated VRFs with no direct cross-tenant routingDuplicate-prefix leak negative test and approved boundary designNetwork Architecture180 daysAny new shared dependency or route-policy change
Shared services with overlapShared dependency behind controlled endpointDirect route-leak between overlapping tenant domainsBoundary endpoint with explicit translation or proxy policyFlow test proving boundary-only access and source-identity impact noteNetwork + Security Architecture180 daysAny endpoint policy change or tenant scope change
IPv4 routed scaleTransitional use for bounded scopeNew large routed pod domains without approvalTime-bound exception with migration path to IPv6 profileCapacity sheet, product support reference, migration milestoneNetwork Architecture90 daysAny pod-density increase request
IPv6 cluster profileApproved profile set (/56, /54, /53)Ad-hoc profile sizing outside approved profilesNew profile by ADR review; while ADR-023 is draft this remains working directionNetBox profile update, CI pass, route-policy regression passNetwork ArchitectureUntil ADR updatePrefix model or allocator logic change
Government category mappingNC1 internet and NC2 Diginetwerk mappings are mandatory where applicableTreating NC3 or NC5 as equivalent mandatory classesNC3 only under additional agreement; NC5 for internal-use recommendationCategory assignment proof, RPKI or reverse-DNS ownership where internet-facingNetwork Architecture365 daysCategory policy or connectivity scope change

Decisions

Open Questions

  • Which exception classes require Platform Architecture co-sign in addition to Network Architecture?
  • Should high-risk overlap exceptions be capped at 90 days instead of 180 days?