Schema reference
Every field a device and the network can hold, generated from the comments in src/schema/. A field marked ? may be left out; left out, it is off or at its default.
Device
Connection
How the framework reaches the device.
| Field | Type | Description |
|---|---|---|
host | IP | Management address. |
user | name | One of the device's users. Its password is the login. |
port? | number | SSH port. 22 when absent. |
Vrf
A separate routing table, with the interfaces that route in it.
| Field | Type | Description |
|---|---|---|
description? | string | What the VRF is for. |
Device
Everything one device runs. What is not written here is removed from the device or returned to its default. Type parameters are the names the device declares, so a reference to a name that does not exist fails to compile: N ports, V VLANs, I interfaces, P policies, S prefix sets, G BGP groups, A ACLs, AS address sets, U users, F VRFs, C certificates.
| Field | Type | Description |
|---|---|---|
name | string | Hostname. |
platform | platform | Operating system, which decides the adapter that renders and applies the device. |
model | model | Hardware model. Decides which port names exist. |
connection | Connection | How the framework logs in. |
system? | System | Device-wide settings. |
users? | Record<name, User> | Logins, keyed by user name. Users not listed are removed. |
management? | Management | Ways in, and who may use them. |
certificates? | Record<name, Certificate> | Certificates, keyed by name. |
vlans? | Record<name, Vlan> | VLANs, keyed by name. |
ports? | Partial<Record<name, Port>> | Physical ports, keyed by <speed>-<position>. |
interfaces? | Record<name, Interface> | Interfaces that are not physical ports, keyed by name. |
vrfs? | Record<name, Vrf> | Separate routing tables, keyed by name. |
routing? | Routing | Static routes, BGP, OSPF and route validation. |
policies? | Record<name, RoutePolicy> | Route policies, keyed by name. |
prefix_sets? | Record<name, PrefixSet> | Prefix sets that policies match on, keyed by name. |
firewall? | Firewall | Packet filtering and address translation. |
acls? | Record<name, readonly AclRule[]> | Hardware ACLs, keyed by name, applied to a port with acl. |
dhcp? | Record<string, DhcpServer> | DHCP servers, keyed by name. |
dhcp_relay? | Record<string, DhcpRelay> | DHCP relays, keyed by name. |
flow_export? | FlowExport | Flow records or packet samples sent to collectors. |
lldp? | true | { interfaces: readonly name[] } | Advertise and learn neighbors with LLDP on every port, or only on the interfaces listed. A port may override it. |
stp? | object | Spanning tree on every switched port. A port may override it. |
stp.mode? | "stp" | "rstp" | "mstp" | Which variant runs. RSTP when absent. |
stp.priority? | number | Bridge priority, 0 to 61440 in steps of 4096. Lower wins the root election. |
hardware_offload? | boolean | Forward in hardware where the platform can. An interface may override it. |
Ports and interfaces
Vlan
A VLAN. The key it is declared under is its name.
| Field | Type | Description |
|---|---|---|
id | number | The number carried on the wire, 1 to 4094. |
description? | string | What the VLAN is for. |
Threshold
A storm-control threshold: packets per second, or percent of the link's speed.
Vrrp
A virtual router address shared with other devices on the same segment, RFC 5798.
| Field | Type | Description |
|---|---|---|
id | number | Virtual router number, 1 to 255. The same on every device sharing the address. |
address | IP | The shared address, without a length. |
priority? | number | Higher wins the master election, 1 to 254. 100 when absent. |
preempt? | boolean | Take mastership back from a lower priority device when this one returns. Off when absent. |
interval? | number | Seconds between advertisements. 1 when absent. |
Routed
Layer 3 settings shared by every interface that can hold an address.
| Field | Type | Description |
|---|---|---|
addresses? | readonly (Address | { address: Address; peer: IP })[] | Addresses with their length. Use { address, peer } for a point-to-point address whose far end is outside its own prefix. |
ipv6_ra? | boolean | Send IPv6 router advertisements on this interface. Off when absent. |
hardware_offload? | boolean | Overrides the device's hardware_offload for traffic routed through this interface. Software forwarding is what makes the firewall apply. |
vrrp? | readonly Vrrp[] | Virtual router addresses held on this interface. |
vrf? | name | The VRF this interface routes in. The default table when absent. |
exchange? | Exchange | This interface is the network's presence at an internet exchange. Devices ignore it; circuit peeringdb publishes it. |
Exchange
Presence at an internet exchange, as a registry lists it. The addresses are the interface's own.
| Field | Type | Description |
|---|---|---|
name | string | The exchange's name, for output. |
speed | number | Capacity toward the exchange, in Mbit/s. |
peeringdb_ixlan? | number | The exchange LAN's id at PeeringDB, its ixlan_id. |
PortStp
Spanning tree settings for one port.
| Field | Type | Description |
|---|---|---|
edge? | boolean | The port faces a host, never a switch, so it forwards at once. |
cost? | number | Path cost. Lower is preferred. Derived from speed when absent. |
priority? | number | Port priority, 0 to 240 in steps of 16. Lower is preferred. |
Switched
Layer 2 membership. A port or LAG with none of these is routed.
| Field | Type | Description |
|---|---|---|
access_vlan? | name | Untagged member of one VLAN. |
trunk_vlans? | readonly name[] | Tagged member of these VLANs. |
native_vlan? | name | Untagged frames on a trunk belong to this VLAN. Only with trunk_vlans. |
stp? | boolean | PortStp | Overrides the device's stp for this port. false stops it sending or acting on BPDUs. |
storm_control? | object | Drop flooded traffic above these thresholds. |
storm_control.broadcast? | Threshold | |
storm_control.multicast? | Threshold | |
storm_control.unknown_unicast? | Threshold |
Link
The other end of a cable: another device and its port. Both ends must agree on how they are switched.
| Field | Type | Description |
|---|---|---|
device | string | Name of the device at the other end. |
port | string | The port on that device. |
Port
A physical port. Ports a device does not declare are shut down.
Also has every field of Routed and Switched.
| Field | Type | Description |
|---|---|---|
description? | string | What is plugged in. |
mtu? | number | Largest IP packet, in bytes. 1500 when absent. |
speed? | "100m" | "1g" | "10g" | "25g" | "40g" | "50g" | "100g" | Fixed speed, for an optic slower than the cage. Negotiated when absent. |
lldp? | boolean | Overrides the device's lldp for this port. |
acl? | name | Hardware ACL applied to traffic arriving on this port. |
lag? | name | Member of this LAG. The LAG holds every other setting. |
link? | Link | Another of our devices at the other end of the cable. |
Base
Settings every interface that is not a physical port shares.
Also has every field of Routed.
| Field | Type | Description |
|---|---|---|
description? | string | What the interface is for. |
mtu? | number | Largest IP packet, in bytes. |
VlanInterface
A layer 3 interface on a VLAN.
Also has every field of Base.
| Field | Type | Description |
|---|---|---|
type | "vlan" | |
vlan | name | The VLAN it sits on. |
Loopback
An interface that is always up and belongs to no link, for addresses that must not depend on one.
Also has every field of Base.
Lag
A link aggregation. Member ports name it with lag.
Also has every field of Base and Switched.
| Field | Type | Description |
|---|---|---|
type | "lag" | |
mode? | "lacp" | "static" | LACP negotiates membership with the far end; static bundles without asking. LACP when absent. |
id? | number | Number on platforms that name a LAG by number. Its position among the device's LAGs when absent. |
Gre
A GRE tunnel.
Also has every field of Base.
| Field | Type | Description |
|---|---|---|
type | "gre" | |
local | IP | Our tunnel endpoint. |
remote | IP | The far tunnel endpoint. |
Vxlan
A point-to-point VXLAN tunnel.
Also has every field of Base.
| Field | Type | Description |
|---|---|---|
type | "vxlan" | |
vni | number | Segment identifier, the same on both ends. |
local | IP | Our tunnel endpoint. |
remote | IP | The far tunnel endpoint. |
port? | number | UDP port. 4789 when absent. |
mac? | string | Fixed MAC address, so a rebuild keeps the one the far side learned. |
WireGuardPeer
One peer of a WireGuard interface.
| Field | Type | Description |
|---|---|---|
name | string | Who or what the peer is. |
public_key | string | The peer's public key. Public keys are not secrets. |
allowed_addresses | readonly Prefix[] | Addresses the peer may send from and that are routed to it. |
endpoint? | string | host:port, for a peer this side dials. The peer dials in when absent. |
keepalive? | number | Seconds between keepalives, for a peer behind NAT. None when absent. |
client_allowed_addresses? | readonly Prefix[] | What a generated client config routes into the tunnel. Affects no forwarding here. |
WireGuard
A WireGuard interface.
Also has every field of Base.
| Field | Type | Description |
|---|---|---|
type | "wireguard" | |
listen_port | number | UDP port peers connect to. |
endpoint? | IP | The address clients connect to, for generated client configs. |
private_key | Secret | This interface's private key. Its public key is derived from it. |
peers? | readonly WireGuardPeer[] | Who may connect. |
Interface
Any interface that is not a physical port.
VlanInterface | Loopback | Lag | Gre | Vxlan | WireGuardRouting
StaticRoute
A route the device carries without learning it.
| Field | Type | Description |
|---|---|---|
prefix | Prefix | Destination. |
via? | IP | Next-hop address. |
interface? | name | Next-hop interface, for a link without a next-hop address. |
blackhole? | true | Discard matching traffic. The usual way to originate an aggregate. |
distance? | number | Preference against other routes to the same prefix. Lower wins. 1 when absent. |
vrf? | name | The VRF the route belongs to. The default table when absent. |
description? | string | Why the route exists. |
BgpRole
Our side of the relationship, as RFC 9234 defines it.
"provider" | "customer" | "peer" | "rs" | "rs-client"NeighborSettings
Settings a BGP neighbor can state itself or take from its group.
| Field | Type | Description |
|---|---|---|
remote_as? | number | The neighbor's AS. Our own AS makes the session internal. |
description? | string | Who the neighbor is. |
local_address? | IP | Source address for the session. The outgoing interface's address when absent. |
import? | name | Policy for routes learned. Nothing is accepted when absent. |
export? | name | Policy for routes announced. Nothing is announced when absent. |
local_role? | BgpRole | Our role toward this neighbor, which lets both sides reject a leak. |
multihop? | boolean | The neighbor is more than one hop away. |
password? | Secret | TCP MD5 password shared with the neighbor. |
max_prefixes? | number | Close the session when the neighbor announces more prefixes than this. It stays closed until cleared by hand, on RouterOS with /routing bgp session clear <session> flag=limit-exceeded. |
hold_time? | number | Seconds without a message before the session is declared down. |
keepalive? | number | Seconds between keepalive messages. |
families? | readonly Family[] | Families exchanged. The family of the neighbor's address when absent. |
passive? | boolean | Wait for the neighbor to connect instead of connecting to it. |
bfd? | boolean | Detect a dead link in under a second with BFD. |
Neighbor
One BGP session. Settings it does not state come from its group.
Also has every field of NeighborSettings.
| Field | Type | Description |
|---|---|---|
address | IP | The neighbor's address. |
group? | name | Group whose settings this neighbor takes where it states none. |
Bgp
BGP on this device.
| Field | Type | Description |
|---|---|---|
asn | number | Our AS number. |
networks? | readonly Prefix[] | Prefixes this device originates. Each needs a route, for example a static blackhole. Export policy still decides who receives them. |
groups? | Record<name, NeighborSettings> | Settings shared by several neighbors, keyed by group name. |
neighbors? | Record<string, Neighbor> | Sessions keyed by name. |
RpkiServer
A route origin validation server, RFC 8210.
| Field | Type | Description |
|---|---|---|
address | IP | Where the validator listens. |
port | number | Its RTR port, often 323 or 8282. |
description? | string | Who runs it, or why it is here. |
OspfInterface
OSPF on one interface.
| Field | Type | Description |
|---|---|---|
cost? | number | Cost of sending through this interface. Lower is preferred. Derived from speed when absent. |
passive? | boolean | Advertise the interface's network but form no adjacency on it. |
network? | "broadcast" | "point-to-point" | How the link is treated. Broadcast when absent. |
bfd? | boolean | Detect a dead neighbor in under a second with BFD. |
Ospf
OSPF, version 2 for IPv4 and version 3 for IPv6.
| Field | Type | Description |
|---|---|---|
families? | readonly Family[] | Which versions run. IPv4 when absent. |
areas | Record<string, { interfaces: Partial<Record<name, OspfInterface>> }> | Areas keyed by area ID, for example 0.0.0.0, each with the interfaces in it. |
redistribute? | readonly ("connected" | "static")[] | Routes from other sources announced into OSPF. |
Routing
Routing on this device.
| Field | Type | Description |
|---|---|---|
router_id? | IP | Identifies this router to its neighbors. |
static? | readonly StaticRoute[] | Routes the device carries without learning them. |
bgp? | Bgp | BGP sessions and what they exchange. |
ospf? | Ospf | OSPF areas and interfaces. |
rpki? | readonly RpkiServer[] | Validators answering route origin validation. |
Route policies
Registry
Registries a prefix set can be fetched from.
"ripe-stat"PrefixSet
Prefixes listed here, or fetched from a registry by refresh and never typed by hand.
| Field | Type | Description |
|---|---|---|
prefixes | readonly Prefix[] | The prefixes, of one family. |
source | object | |
source.registry | Registry | Where the prefixes come from. |
source.query | string | What to ask for, for example AS7713. |
source.family | Family | Which family to keep. |
Match
Conditions on a route. All must hold. An empty match holds for every route.
| Field | Type | Description |
|---|---|---|
family? | Family | Only routes of this family. |
prefix? | Prefix | Exactly this prefix. |
prefix_set? | name | Any prefix in this set. |
prefix_length? | { min?: number; max?: number } | Prefix length within this range, inclusive. |
as_path_length? | { min?: number; max?: number } | AS path length within this range, inclusive. Every AS counts, prepends included. |
rpki? | "valid" | "invalid" | "not-found" | The route's origin validation state. |
community? | string | Carries this standard community, asn:value. |
large_community? | string | Carries this large community, asn:function:parameter. |
Sets
Changes to a route. In community lists to remove, * stands for any value of a field, as in 64500:*:*.
| Field | Type | Description |
|---|---|---|
local_pref? | number | Preference among routes to the same prefix within our AS. Higher wins. |
med? | number | Multi-exit discriminator offered to the neighbor. Lower wins. |
prepend? | number | Prepend our own AS this many times, to make the path look longer. |
communities? | readonly string[] | Replace the route's standard communities with these. |
add_communities? | readonly string[] | Add these standard communities. |
remove_communities? | readonly string[] | Remove standard communities matching these. |
large_communities? | readonly string[] | Replace the route's large communities with these. |
add_large_communities? | readonly string[] | Add these large communities. |
remove_large_communities? | readonly string[] | Remove large communities matching these. |
next_hop? | IP | Next hop for the route. |
preferred_source? | IP | Source address for traffic the device itself sends to the route. Applies to routes of the same family as the address. |
PolicyRule
One step of a route policy. Evaluated in this order: call, then match, then set, then action. A rule without action changes the route and moves on to the next rule.
| Field | Type | Description |
|---|---|---|
description? | string | Shown beside the rule on the device. |
call? | name | Evaluate another policy first. A route it accepts or rejects stops there. |
match? | Match | Which routes the rule applies to. Every route when absent. |
set? | Sets | What to change on a matching route. |
action? | "accept" | "reject" | Accept or reject a matching route, ending the policy for it. |
RoutePolicy
Rules evaluated in order, first decision wins. A route no rule accepts is rejected.
readonly PolicyRule[]Firewall and ACLs
Protocol
An IP protocol. icmp means ICMPv6 in an IPv6 rule.
"tcp" | "udp" | "icmp" | "gre" | "esp" | "ah" | "ospf" | "vrrp"ConnectionState
The state connection tracking assigns a packet.
"new" | "established" | "related" | "untracked" | "invalid"TcpFlag
A TCP header flag.
"fin" | "syn" | "rst" | "psh" | "ack" | "urg"FilterMatch
Conditions on a packet. All must hold. A rule with addresses of one family applies to that family only.
| Field | Type | Description |
|---|---|---|
family? | Family | Only packets of this family. |
protocol? | Protocol | IP protocol. |
src? | Prefix | Source address or prefix. |
dst? | Prefix | Destination address or prefix. |
src_set? | name | Source is in this address set. |
dst_set? | name | Destination is in this address set. |
src_port? | number | readonly number[] | Source port, or any of several. TCP and UDP only. |
dst_port? | number | readonly number[] | Destination port, or any of several. TCP and UDP only. |
in_interface? | name | Arrived on this interface. |
out_interface? | name | Leaves through this interface. |
state? | readonly ConnectionState[] | Connection tracking state, any of these. |
tcp_flags? | { set?: readonly TcpFlag[]; unset?: readonly TcpFlag[] } | TCP flags that must be set, and flags that must not be. |
FilterRule
One firewall rule.
| Field | Type | Description |
|---|---|---|
description? | string | Shown beside the rule on the device. |
match? | FilterMatch | Which packets the rule applies to. Every packet when absent. |
action | "accept" | "drop" | "reject" | What happens to a matching packet. reject answers the sender, drop does not. |
offload? | true | Hand the rest of an accepted flow to the fast path, past the remaining rules. |
Chain
Rules evaluated in order, first match wins, then default.
| Field | Type | Description |
|---|---|---|
default? | "accept" | "drop" | What happens to a packet no rule matched. Accept when absent. |
rules? | readonly FilterRule[] | Evaluated in order. |
NatRule
One address translation.
| Field | Type | Description |
|---|---|---|
description? | string | Shown beside the rule on the device. |
match? | FilterMatch | Which packets are translated. Every packet when absent. |
action | "masquerade" | Use the address of the outgoing interface. |
action | "snat" | "dnat" | snat rewrites the source, dnat the destination. |
to | IP | The address to rewrite to. |
to_port? | number | The port to rewrite to. Unchanged when absent. |
Helper
Connection-tracking helpers that rewrite application payloads. None run unless listed.
"ftp" | "tftp" | "sip" | "h323" | "pptp" | "rtsp" | "irc"Firewall
What the device filters and translates.
| Field | Type | Description |
|---|---|---|
address_sets? | Record<name, readonly (IP | Prefix)[]> | Named groups of addresses and prefixes, of either family, that rules match on. |
filter? | object | Traffic to the device, through it, and from it. |
filter.input? | Chain | |
filter.forward? | Chain | |
filter.output? | Chain | |
nat? | object | Source translation on the way out, destination translation on the way in. |
nat.source? | readonly NatRule[] | |
nat.destination? | readonly NatRule[] | |
helpers? | readonly Helper[] | Helpers that run. None when absent. |
AclRule
A stateless rule evaluated in hardware where traffic arrives, before routing.
| Field | Type | Description |
|---|---|---|
description? | string | Shown beside the rule on the device. |
match? | object | Which packets the rule applies to. Every packet when absent. |
match.family? | Family | Only packets of this family. |
match.protocol? | Protocol | IP protocol. |
match.src? | Prefix | Source prefix. |
match.dst? | Prefix | Destination prefix. |
match.src_port? | number | readonly number[] | Source port, or any of several. |
match.dst_port? | number | readonly number[] | Destination port, or any of several. |
match.vlan? | name | Carried in this VLAN. |
action | "accept" | "drop" | What happens to a matching packet. |
rate? | Rate | Accepted traffic above this rate is dropped. |
System and management
System
Device-wide settings.
| Field | Type | Description |
|---|---|---|
timezone? | string | IANA zone, for example Asia/Jakarta. UTC when absent. |
banner? | string | Shown at login. |
dns? | object | Resolvers the device uses. |
dns.servers | readonly IP[] | Resolvers, in order of preference. |
dns.serve? | boolean | Answer queries from others. Off when absent. |
ntp? | object | Time the device keeps. |
ntp.servers | readonly string[] | Time sources, by address or name. |
ntp.serve? | boolean | Answer time queries from others. Off when absent. |
logging? | object | Where log messages go. |
logging.local? | object | Kept on the device's own storage, from level up. |
logging.local.level | Severity | The least severe message kept. |
logging.local.files? | number | How many rotated files to keep. |
logging.local.lines_per_file? | number | Lines in each file before it rotates. |
logging.remote? | object | Sent to syslog collectors, each from its own level up. |
logging.remote.address | IP | |
logging.remote.port? | number | UDP port. 514 when absent. |
logging.remote.level | Severity | The least severe message sent. |
release_channel? | string | Software release track the device updates from. |
transceiver_monitoring? | boolean | Read optic temperature, power and voltage. |
ip? | object | Host behaviour of the IP stack. |
ip.icmp_redirects? | boolean | Send ICMP redirects. Off when absent. |
ip.syn_cookies? | boolean | Answer a TCP SYN flood with SYN cookies. Off when absent. |
User
A login on the device.
| Field | Type | Description |
|---|---|---|
role | "admin" | "operator" | "read-only" | What the user may do. |
password | Secret | The login password. |
description? | string | Who the account is for. |
ssh_keys? | readonly string[] | Public keys accepted instead of the password over SSH. |
Service
A way into the device. Absent means turned off.
| Field | Type | Description |
|---|---|---|
allow? | readonly Prefix[] | Sources allowed. management.allow when absent. |
port? | number | TCP or UDP port. The protocol's own when absent. |
SnmpUser
One SNMPv3 user.
| Field | Type | Description |
|---|---|---|
auth | "sha1" | "sha256" | How messages are authenticated. |
auth_password | Secret | The authentication passphrase. |
privacy | "aes128" | "des" | How messages are encrypted. |
privacy_password | Secret | The encryption passphrase. |
Management
How the device is reached and managed.
| Field | Type | Description |
|---|---|---|
allow? | readonly Prefix[] | Sources allowed to every service that does not state its own. |
ssh? | object | Secure shell. |
ssh.weak_crypto? | boolean | Also offer legacy ciphers, MACs and key exchanges. Off when absent. |
ssh.auth_timeout? | number | Seconds a login may take. |
ssh.auth_retries? | number | Failed attempts allowed per connection. |
telnet? | Service | Unencrypted remote login. |
http? | Service | Web interface, unencrypted. |
https? | object | Web interface over TLS. |
https.certificate? | name | One of the device's certificates. |
api? | Service | The platform's own API, unencrypted. |
api_tls? | object | The platform's own API over TLS. |
api_tls.certificate? | name | One of the device's certificates. |
ftp? | Service | File transfer, unencrypted. |
native? | Service & { interfaces?: readonly name[] } | The platform's own management protocol. interfaces also allows it at layer 2 on those interfaces. |
snmp? | object | Polling by SNMP. |
snmp.community? | Secret | Read-only community for version 2c. Version 2c is off when absent. |
snmp.users? | Record<string, SnmpUser> | Version 3 users, keyed by name. |
snmp.contact? | string | Who to contact about the device. |
snmp.location? | string | Where the device is. |
console? | { password: Secret } | Console login uses this password. The device's users when absent. |
privilege_password? | Secret | Password for privileged mode, on platforms that have one. |
DhcpServer
A DHCP server for one network.
| Field | Type | Description |
|---|---|---|
interface | name | Where it answers. |
network | Prefix | The network it serves. |
gateway | IP | Default gateway handed out. |
dns? | readonly IP[] | Resolvers handed out. |
pool | readonly [IP, IP] | First and last address handed out. |
lease_time? | number | Seconds a lease lasts. |
reservations? | object | Addresses fixed to a MAC. |
reservations.address | IP | |
reservations.mac | string | |
reservations.description? | string | Whose address it is. |
DhcpRelay
Forward DHCP requests heard on an interface to servers elsewhere.
| Field | Type | Description |
|---|---|---|
interface | name | Where requests are heard. |
servers | readonly IP[] | Where they are forwarded. |
Certificate
A certificate the device presents or trusts.
| Field | Type | Description |
|---|---|---|
certificate | string | The certificate, PEM. Public, so it lives in the repository. |
private_key? | Secret | Its private key: a PEM file through secretFile, or PEM base64-encoded as one line through secret. A certificate only trusted, such as a CA, has none. |
FlowExport
Export flow records or packet samples to collectors.
| Field | Type | Description |
|---|---|---|
protocol | "sflow" | "netflow-v9" | "ipfix" | The record format. |
collectors | object | Where records are sent. |
collectors.address | IP | |
collectors.port? | number | UDP port. 6343 for sFlow and 2055 otherwise when absent. |
sampling? | number | Sample one packet in this many. Every packet when absent, on a platform that can export every packet. |
interfaces? | readonly name[] | Where traffic is observed. Every interface when absent. |
Common values
Secret
A value kept out of the repository and resolved only when a device is applied. secret("NAME") reads a variable from the environment or .env.local. secretFile("path") reads a file, relative to the project root, for a value that spans lines such as a private key in PEM. Keep that file out of git.
| Field | Type | Description |
|---|---|---|
secret | string | Name of the value in the environment or in .env.local. |
secret_file | string | Path of a file holding the value, relative to the project root. |
IP
An address without a length, IPv4 or IPv6, for example 10.0.0.1.
stringPrefix
A network with its length, for example 10.0.0.0/24.
stringAddress
An interface address with its length, for example 10.0.0.1/24.
stringFamily
An address family.
"ipv4" | "ipv6"Rate
Bits per second, for example 2G, 500M or 64k.
Severity
A log severity, most severe first. A threshold includes everything above it.
"emergency" | "alert" | "critical" | "error" | "warning" | "notice" | "info" | "debug"