RWS Architecture article

OpenShift and EVPN Production Target Baseline

Production contract for OpenShift networking on the Location B EVPN/VXLAN lane. It defines defaults, exception boundaries, and minimum evidence gates for promotion.

  1. Typearchitecture
  2. Statusactive
  3. Domainnetwork
On this page
  1. Summary
  2. Applicable Principles
  3. Architecture
  4. Baseline Matrix
  5. Resilience and Evidence Controls
  6. Decisions
  7. Open Questions

Summary

Production contract for OpenShift networking on the Location B EVPN/VXLAN lane. It defines defaults, exception boundaries, and minimum evidence gates for promotion.

Applicable Principles

Architecture

Baseline Matrix

AreaDefault targetException policyRequired evidenceOwner
OpenShift routed attachmentInternal architecture policy default for in-scope production lanes is CUDN on validated releases.UDN is exception-only for strict isolation or overlap cases and requires release-pinned support profile validation.Pod IP allocation and VRF route visibility checks.Platform Architecture
Service identity and exposureService or LoadBalancer IP is stable north-south identity.Direct pod exposure requires explicit exception approval.Reachability and failover checks for service identity.Platform Architecture
External/provider reachabilityFRR plus BGP advertisements with filtered imports.Static-route model must be time-bound and retired.FRR state, BGP neighbor health, prefix-filter evidence.Platform + Network
NAT postureNo unintended node-level NAT on routed defaults.NAT only where overlap or edge policy requires it.Source-identity and conntrack impact checks.Platform + Network
Fabric multihomingEVPN ESI is default for multi-homed attachment in Location B.vPC profile only for scoped interoperability fallback.ESI state, DF behavior, failover transition evidence.Network Architecture
DC-to-backbone interconnectL3 VRF handoff default (EVPN VRF -> border -> L3VPN VRF).L2 cross-site extension requires ADR exception and rollback plan.Route-leak negative tests and border policy hit evidence.Network Architecture
MTU and encapsulationMTU budget validated for active encapsulation mix.Mixed-mode overlap windows must be time-bounded.Fragmentation checks on east-west and north-south paths.Platform + Network
  • CUDN and UDN statements in this note are internal architecture defaults for this vault, not generic OpenShift product defaults.
  • UDN limitations in this baseline: no implicit inter-UDN reachability, no automatic datacenter EVPN policy behavior, and explicit FRR or border policy required for external exposure.

Resilience and Evidence Controls

ControlRequirementMinimum evidence
ESI mode behaviorVIP next-hop with 2+ active peers; PIP with single active peer.show nve ethernet-segment, show l2route evpn ethernet-segment all detail.
ESI convergence profileL2FRR and recovery controls enabled for scoped ESI clusters.Peer-failure and recovery test with expected PIP/VIP transition.
Route distributionType-2 re-origination baseline; EAD-EVI disabled unless explicitly required.EVPN route-type checks and policy-delta review.
Interop boundaryA VTEP role uses either vPC-VTEP or ESI-VTEP, not both.Role-profile compliance check in rendered intent and runtime evidence.
OpenShift route visibilityFRR-scoped route imports are visible only in intended VRFs.FRR node state and tenant VRF route snapshots.

Decisions

Open Questions

  • Which release profile is promoted first for accepted ADR status after ESI evidence closes?
  • Which failover scenario set is mandatory for every production change window?