On this page
WP-01 DC3.0 Network and Supporting Services
Summary
Deliver lane-scoped Phase 1 networking: Location A single-ACI-pod AI lane and Location B VXLAN BGP EVPN spine-leaf target lane, plus supporting services for DNS, load balancing, firewalling, and identity-aware access.
Scope
Deliver lane-scoped Phase 1 networking: Location A single-ACI-pod AI lane (strictly AI use case only) and Location B VXLAN BGP EVPN spine-leaf target lane (L3VNI-per-VRF, L2VNI-per-VLAN segmentation, Anycast GW), plus supporting services for DNS, load balancing, firewalling, and identity-aware access.
- Enforce explicit service-versus-transport boundaries in design and validation artifacts (
L3VPN service,SR-MPLS transport,EVPN control-plane,VXLAN dataplane). - Implement default L3 interconnect between datacenter EVPN VRFs and backbone L3VPN VRFs.
- Treat any cross-site L2 stretch request as exception-only with ADR-level approval.
Architecture Context
- Domain architecture index: Network Architecture
- OpenShift runtime context where relevant: Platform Architecture
Decision Context
- adr-013-implementation-phasing
- adr-019-hybrid-network-rollout-aci-a-ai-only-evpn-b-target
- adr-021-dc-evpn-to-backbone-l3vpn-interconnect
Dependencies
Acceptance Criteria
- Location A single ACI pod lane is operational for the AI cluster use case only, with documented controls preventing non-AI tenant onboarding.
- Location A and Location B lane boundaries are documented, approved, and auditable.
- MTU validation shows no fragmentation for in-scope east-west and north-south paths, including encapsulation budgets for EVPN/VXLAN and OpenShift overlays.
- Network-path benchmarks for storage traffic (replication and client data paths) meet target transport SLOs.
- BFD failure detection meets the defined p95 target for in-scope adjacency tests in the approved failover test profile.
- BGP reconvergence for the approved failover test profile (for example single-link loss and single-node failure scenarios) meets p95 < 2s, with scenario definitions and measurement method captured in evidence artifacts.
- EVPN control-plane health (
show bgp l2vpn evpn) and dataplane health (show nve peersandshow nve vni) pass change gates before close. - Production-target multihoming evidence confirms ESI state stability and expected PIP/VIP transition behavior in scoped failover and recovery tests.
- Scoped routed workload tests confirm no unintended node-level NAT on CUDN-first paths and preserve workload source identity for policy and observability controls.
- No unauthorized route leaks are observed in scoped validation evidence; negative tests for defined tenant pairs confirm RT isolation remains intact.
- Network control evidence for cutover is published in the release evidence bundle and approved by network and platform owners.