Stateless Kubernetes overlay networks with IPv6
john-millikin.com
john-millikin.com
You can explore this a bit further and set up some net namespaces, connect them to the host vm via a bridge device, assign them ipv6 addresses from the vm host /64 network, and then set up a default route inside each container to the /32 or /40 you're using via the vm host's address on the host local /64. It's cool to see one container on host 1 talk to another on host 2. You're basically subnetting the /40 for each host; each host is analogous to a household in 6rd, and the containers are like your devices on your lan with globally routable ipv6 addresses (except we're using a ULA prefix instead of a globally routable ipv6 prefix assigned to an ISP, so our containers are not globally addressable - whatever). I'd guess this is what the CNI thing you mention does under the hood. For others who are interested in this, it's basically combining OP's article with https://iximiuz.com/en/posts/container-networking-is-simple/ from a couple months ago.
The Teredo part was very interesting as well, I had not thought to worry about non-udp/tcp compatible intermediate systems.
Does this matter? Probably not. But when I have the option, I like to conform to the RFCs.
In the third paragraph of the first section you mention the "Toledo" protocol out of the blue. Is this a result of autocorrect?
Thanks for writing this up!
Not that there's any Teredo going on in the article...
> Not that there's any Teredo going on in the article...
I'm not sure exactly what you mean, but note that using 6to4 with FOU produces packets that are exactly the Teredo protocol. This is why some packet analysis tools (for example Wireshark) are able to recognize the UDP-encapsulated packet as IPv6-in-UDP.Since you're not using 2002::/16 it's not 6to4 either. It's 6rd, except tunnelling 6rd's 6in4 packets over UDP makes it incompatible with that. I was going to suggest "6rd-UDP" but https://tools.ietf.org/html/draft-lee-softwire-6rd-udp-02 exists/existed and it's different, so maybe something else.