Skip to content

Schema reference ​

Every field a device and the network can hold, generated from the comments in src/schema/. A field marked ? may be left out; left out, it is off or at its default.

Device ​

Connection ​

How the framework reaches the device.

FieldTypeDescription
hostIPManagement address.
usernameOne of the device's users. Its password is the login.
port?numberSSH port. 22 when absent.

Vrf ​

A separate routing table, with the interfaces that route in it.

FieldTypeDescription
description?stringWhat the VRF is for.

Device ​

Everything one device runs. What is not written here is removed from the device or returned to its default. Type parameters are the names the device declares, so a reference to a name that does not exist fails to compile: N ports, V VLANs, I interfaces, P policies, S prefix sets, G BGP groups, A ACLs, AS address sets, U users, F VRFs, C certificates.

FieldTypeDescription
namestringHostname.
platformplatformOperating system, which decides the adapter that renders and applies the device.
modelmodelHardware model. Decides which port names exist.
connectionConnectionHow the framework logs in.
system?SystemDevice-wide settings.
users?Record<name, User>Logins, keyed by user name. Users not listed are removed.
management?ManagementWays in, and who may use them.
certificates?Record<name, Certificate>Certificates, keyed by name.
vlans?Record<name, Vlan>VLANs, keyed by name.
ports?Partial<Record<name, Port>>Physical ports, keyed by <speed>-<position>.
interfaces?Record<name, Interface>Interfaces that are not physical ports, keyed by name.
vrfs?Record<name, Vrf>Separate routing tables, keyed by name.
routing?RoutingStatic routes, BGP, OSPF and route validation.
policies?Record<name, RoutePolicy>Route policies, keyed by name.
prefix_sets?Record<name, PrefixSet>Prefix sets that policies match on, keyed by name.
firewall?FirewallPacket filtering and address translation.
acls?Record<name, readonly AclRule[]>Hardware ACLs, keyed by name, applied to a port with acl.
dhcp?Record<string, DhcpServer>DHCP servers, keyed by name.
dhcp_relay?Record<string, DhcpRelay>DHCP relays, keyed by name.
flow_export?FlowExportFlow records or packet samples sent to collectors.
lldp?true | { interfaces: readonly name[] }Advertise and learn neighbors with LLDP on every port, or only on the interfaces listed. A port may override it.
stp?objectSpanning tree on every switched port. A port may override it.
stp.mode?"stp" | "rstp" | "mstp"Which variant runs. RSTP when absent.
stp.priority?numberBridge priority, 0 to 61440 in steps of 4096. Lower wins the root election.
hardware_offload?booleanForward in hardware where the platform can. An interface may override it.

Ports and interfaces ​

Vlan ​

A VLAN. The key it is declared under is its name.

FieldTypeDescription
idnumberThe number carried on the wire, 1 to 4094.
description?stringWhat the VLAN is for.

Threshold ​

A storm-control threshold: packets per second, or percent of the link's speed.

Vrrp ​

A virtual router address shared with other devices on the same segment, RFC 5798.

FieldTypeDescription
idnumberVirtual router number, 1 to 255. The same on every device sharing the address.
addressIPThe shared address, without a length.
priority?numberHigher wins the master election, 1 to 254. 100 when absent.
preempt?booleanTake mastership back from a lower priority device when this one returns. Off when absent.
interval?numberSeconds between advertisements. 1 when absent.

Routed ​

Layer 3 settings shared by every interface that can hold an address.

FieldTypeDescription
addresses?readonly (Address | { address: Address; peer: IP })[]Addresses with their length. Use { address, peer } for a point-to-point address whose far end is outside its own prefix.
ipv6_ra?booleanSend IPv6 router advertisements on this interface. Off when absent.
hardware_offload?booleanOverrides the device's hardware_offload for traffic routed through this interface. Software forwarding is what makes the firewall apply.
vrrp?readonly Vrrp[]Virtual router addresses held on this interface.
vrf?nameThe VRF this interface routes in. The default table when absent.
exchange?ExchangeThis interface is the network's presence at an internet exchange. Devices ignore it; circuit peeringdb publishes it.

Exchange ​

Presence at an internet exchange, as a registry lists it. The addresses are the interface's own.

FieldTypeDescription
namestringThe exchange's name, for output.
speednumberCapacity toward the exchange, in Mbit/s.
peeringdb_ixlan?numberThe exchange LAN's id at PeeringDB, its ixlan_id.

PortStp ​

Spanning tree settings for one port.

FieldTypeDescription
edge?booleanThe port faces a host, never a switch, so it forwards at once.
cost?numberPath cost. Lower is preferred. Derived from speed when absent.
priority?numberPort priority, 0 to 240 in steps of 16. Lower is preferred.

Switched ​

Layer 2 membership. A port or LAG with none of these is routed.

FieldTypeDescription
access_vlan?nameUntagged member of one VLAN.
trunk_vlans?readonly name[]Tagged member of these VLANs.
native_vlan?nameUntagged frames on a trunk belong to this VLAN. Only with trunk_vlans.
stp?boolean | PortStpOverrides the device's stp for this port. false stops it sending or acting on BPDUs.
storm_control?objectDrop flooded traffic above these thresholds.
storm_control.broadcast?Threshold
storm_control.multicast?Threshold
storm_control.unknown_unicast?Threshold

The other end of a cable: another device and its port. Both ends must agree on how they are switched.

FieldTypeDescription
devicestringName of the device at the other end.
portstringThe port on that device.

Port ​

A physical port. Ports a device does not declare are shut down.

Also has every field of Routed and Switched.

FieldTypeDescription
description?stringWhat is plugged in.
mtu?numberLargest IP packet, in bytes. 1500 when absent.
speed?"100m" | "1g" | "10g" | "25g" | "40g" | "50g" | "100g"Fixed speed, for an optic slower than the cage. Negotiated when absent.
lldp?booleanOverrides the device's lldp for this port.
acl?nameHardware ACL applied to traffic arriving on this port.
lag?nameMember of this LAG. The LAG holds every other setting.
link?LinkAnother of our devices at the other end of the cable.

Base ​

Settings every interface that is not a physical port shares.

Also has every field of Routed.

FieldTypeDescription
description?stringWhat the interface is for.
mtu?numberLargest IP packet, in bytes.

VlanInterface ​

A layer 3 interface on a VLAN.

Also has every field of Base.

FieldTypeDescription
type"vlan"
vlannameThe VLAN it sits on.

Loopback ​

An interface that is always up and belongs to no link, for addresses that must not depend on one.

Also has every field of Base.

Lag ​

A link aggregation. Member ports name it with lag.

Also has every field of Base and Switched.

FieldTypeDescription
type"lag"
mode?"lacp" | "static"LACP negotiates membership with the far end; static bundles without asking. LACP when absent.
id?numberNumber on platforms that name a LAG by number. Its position among the device's LAGs when absent.

Gre ​

A GRE tunnel.

Also has every field of Base.

FieldTypeDescription
type"gre"
localIPOur tunnel endpoint.
remoteIPThe far tunnel endpoint.

Vxlan ​

A point-to-point VXLAN tunnel.

Also has every field of Base.

FieldTypeDescription
type"vxlan"
vninumberSegment identifier, the same on both ends.
localIPOur tunnel endpoint.
remoteIPThe far tunnel endpoint.
port?numberUDP port. 4789 when absent.
mac?stringFixed MAC address, so a rebuild keeps the one the far side learned.

WireGuardPeer ​

One peer of a WireGuard interface.

FieldTypeDescription
namestringWho or what the peer is.
public_keystringThe peer's public key. Public keys are not secrets.
allowed_addressesreadonly Prefix[]Addresses the peer may send from and that are routed to it.
endpoint?stringhost:port, for a peer this side dials. The peer dials in when absent.
keepalive?numberSeconds between keepalives, for a peer behind NAT. None when absent.
client_allowed_addresses?readonly Prefix[]What a generated client config routes into the tunnel. Affects no forwarding here.

WireGuard ​

A WireGuard interface.

Also has every field of Base.

FieldTypeDescription
type"wireguard"
listen_portnumberUDP port peers connect to.
endpoint?IPThe address clients connect to, for generated client configs.
private_keySecretThis interface's private key. Its public key is derived from it.
peers?readonly WireGuardPeer[]Who may connect.

Interface ​

Any interface that is not a physical port.

ts
VlanInterface | Loopback | Lag | Gre | Vxlan | WireGuard

Routing ​

StaticRoute ​

A route the device carries without learning it.

FieldTypeDescription
prefixPrefixDestination.
via?IPNext-hop address.
interface?nameNext-hop interface, for a link without a next-hop address.
blackhole?trueDiscard matching traffic. The usual way to originate an aggregate.
distance?numberPreference against other routes to the same prefix. Lower wins. 1 when absent.
vrf?nameThe VRF the route belongs to. The default table when absent.
description?stringWhy the route exists.

BgpRole ​

Our side of the relationship, as RFC 9234 defines it.

ts
"provider" | "customer" | "peer" | "rs" | "rs-client"

NeighborSettings ​

Settings a BGP neighbor can state itself or take from its group.

FieldTypeDescription
remote_as?numberThe neighbor's AS. Our own AS makes the session internal.
description?stringWho the neighbor is.
local_address?IPSource address for the session. The outgoing interface's address when absent.
import?namePolicy for routes learned. Nothing is accepted when absent.
export?namePolicy for routes announced. Nothing is announced when absent.
local_role?BgpRoleOur role toward this neighbor, which lets both sides reject a leak.
multihop?booleanThe neighbor is more than one hop away.
password?SecretTCP MD5 password shared with the neighbor.
max_prefixes?numberClose the session when the neighbor announces more prefixes than this. It stays closed until cleared by hand, on RouterOS with /routing bgp session clear <session> flag=limit-exceeded.
hold_time?numberSeconds without a message before the session is declared down.
keepalive?numberSeconds between keepalive messages.
families?readonly Family[]Families exchanged. The family of the neighbor's address when absent.
passive?booleanWait for the neighbor to connect instead of connecting to it.
bfd?booleanDetect a dead link in under a second with BFD.

Neighbor ​

One BGP session. Settings it does not state come from its group.

Also has every field of NeighborSettings.

FieldTypeDescription
addressIPThe neighbor's address.
group?nameGroup whose settings this neighbor takes where it states none.

Bgp ​

BGP on this device.

FieldTypeDescription
asnnumberOur AS number.
networks?readonly Prefix[]Prefixes this device originates. Each needs a route, for example a static blackhole. Export policy still decides who receives them.
groups?Record<name, NeighborSettings>Settings shared by several neighbors, keyed by group name.
neighbors?Record<string, Neighbor>Sessions keyed by name.

RpkiServer ​

A route origin validation server, RFC 8210.

FieldTypeDescription
addressIPWhere the validator listens.
portnumberIts RTR port, often 323 or 8282.
description?stringWho runs it, or why it is here.

OspfInterface ​

OSPF on one interface.

FieldTypeDescription
cost?numberCost of sending through this interface. Lower is preferred. Derived from speed when absent.
passive?booleanAdvertise the interface's network but form no adjacency on it.
network?"broadcast" | "point-to-point"How the link is treated. Broadcast when absent.
bfd?booleanDetect a dead neighbor in under a second with BFD.

Ospf ​

OSPF, version 2 for IPv4 and version 3 for IPv6.

FieldTypeDescription
families?readonly Family[]Which versions run. IPv4 when absent.
areasRecord<string, { interfaces: Partial<Record<name, OspfInterface>> }>Areas keyed by area ID, for example 0.0.0.0, each with the interfaces in it.
redistribute?readonly ("connected" | "static")[]Routes from other sources announced into OSPF.

Routing ​

Routing on this device.

FieldTypeDescription
router_id?IPIdentifies this router to its neighbors.
static?readonly StaticRoute[]Routes the device carries without learning them.
bgp?BgpBGP sessions and what they exchange.
ospf?OspfOSPF areas and interfaces.
rpki?readonly RpkiServer[]Validators answering route origin validation.

Route policies ​

Registry ​

Registries a prefix set can be fetched from.

ts
"ripe-stat"

PrefixSet ​

Prefixes listed here, or fetched from a registry by refresh and never typed by hand.

FieldTypeDescription
prefixesreadonly Prefix[]The prefixes, of one family.
sourceobject
source.registryRegistryWhere the prefixes come from.
source.querystringWhat to ask for, for example AS7713.
source.familyFamilyWhich family to keep.

Match ​

Conditions on a route. All must hold. An empty match holds for every route.

FieldTypeDescription
family?FamilyOnly routes of this family.
prefix?PrefixExactly this prefix.
prefix_set?nameAny prefix in this set.
prefix_length?{ min?: number; max?: number }Prefix length within this range, inclusive.
as_path_length?{ min?: number; max?: number }AS path length within this range, inclusive. Every AS counts, prepends included.
rpki?"valid" | "invalid" | "not-found"The route's origin validation state.
community?stringCarries this standard community, asn:value.
large_community?stringCarries this large community, asn:function:parameter.

Sets ​

Changes to a route. In community lists to remove, * stands for any value of a field, as in 64500:*:*.

FieldTypeDescription
local_pref?numberPreference among routes to the same prefix within our AS. Higher wins.
med?numberMulti-exit discriminator offered to the neighbor. Lower wins.
prepend?numberPrepend our own AS this many times, to make the path look longer.
communities?readonly string[]Replace the route's standard communities with these.
add_communities?readonly string[]Add these standard communities.
remove_communities?readonly string[]Remove standard communities matching these.
large_communities?readonly string[]Replace the route's large communities with these.
add_large_communities?readonly string[]Add these large communities.
remove_large_communities?readonly string[]Remove large communities matching these.
next_hop?IPNext hop for the route.
preferred_source?IPSource address for traffic the device itself sends to the route. Applies to routes of the same family as the address.

PolicyRule ​

One step of a route policy. Evaluated in this order: call, then match, then set, then action. A rule without action changes the route and moves on to the next rule.

FieldTypeDescription
description?stringShown beside the rule on the device.
call?nameEvaluate another policy first. A route it accepts or rejects stops there.
match?MatchWhich routes the rule applies to. Every route when absent.
set?SetsWhat to change on a matching route.
action?"accept" | "reject"Accept or reject a matching route, ending the policy for it.

RoutePolicy ​

Rules evaluated in order, first decision wins. A route no rule accepts is rejected.

ts
readonly PolicyRule[]

Firewall and ACLs ​

Protocol ​

An IP protocol. icmp means ICMPv6 in an IPv6 rule.

ts
"tcp" | "udp" | "icmp" | "gre" | "esp" | "ah" | "ospf" | "vrrp"

ConnectionState ​

The state connection tracking assigns a packet.

ts
"new" | "established" | "related" | "untracked" | "invalid"

TcpFlag ​

A TCP header flag.

ts
"fin" | "syn" | "rst" | "psh" | "ack" | "urg"

FilterMatch ​

Conditions on a packet. All must hold. A rule with addresses of one family applies to that family only.

FieldTypeDescription
family?FamilyOnly packets of this family.
protocol?ProtocolIP protocol.
src?PrefixSource address or prefix.
dst?PrefixDestination address or prefix.
src_set?nameSource is in this address set.
dst_set?nameDestination is in this address set.
src_port?number | readonly number[]Source port, or any of several. TCP and UDP only.
dst_port?number | readonly number[]Destination port, or any of several. TCP and UDP only.
in_interface?nameArrived on this interface.
out_interface?nameLeaves through this interface.
state?readonly ConnectionState[]Connection tracking state, any of these.
tcp_flags?{ set?: readonly TcpFlag[]; unset?: readonly TcpFlag[] }TCP flags that must be set, and flags that must not be.

FilterRule ​

One firewall rule.

FieldTypeDescription
description?stringShown beside the rule on the device.
match?FilterMatchWhich packets the rule applies to. Every packet when absent.
action"accept" | "drop" | "reject"What happens to a matching packet. reject answers the sender, drop does not.
offload?trueHand the rest of an accepted flow to the fast path, past the remaining rules.

Chain ​

Rules evaluated in order, first match wins, then default.

FieldTypeDescription
default?"accept" | "drop"What happens to a packet no rule matched. Accept when absent.
rules?readonly FilterRule[]Evaluated in order.

NatRule ​

One address translation.

FieldTypeDescription
description?stringShown beside the rule on the device.
match?FilterMatchWhich packets are translated. Every packet when absent.
action"masquerade"Use the address of the outgoing interface.
action"snat" | "dnat"snat rewrites the source, dnat the destination.
toIPThe address to rewrite to.
to_port?numberThe port to rewrite to. Unchanged when absent.

Helper ​

Connection-tracking helpers that rewrite application payloads. None run unless listed.

ts
"ftp" | "tftp" | "sip" | "h323" | "pptp" | "rtsp" | "irc"

Firewall ​

What the device filters and translates.

FieldTypeDescription
address_sets?Record<name, readonly (IP | Prefix)[]>Named groups of addresses and prefixes, of either family, that rules match on.
filter?objectTraffic to the device, through it, and from it.
filter.input?Chain
filter.forward?Chain
filter.output?Chain
nat?objectSource translation on the way out, destination translation on the way in.
nat.source?readonly NatRule[]
nat.destination?readonly NatRule[]
helpers?readonly Helper[]Helpers that run. None when absent.

AclRule ​

A stateless rule evaluated in hardware where traffic arrives, before routing.

FieldTypeDescription
description?stringShown beside the rule on the device.
match?objectWhich packets the rule applies to. Every packet when absent.
match.family?FamilyOnly packets of this family.
match.protocol?ProtocolIP protocol.
match.src?PrefixSource prefix.
match.dst?PrefixDestination prefix.
match.src_port?number | readonly number[]Source port, or any of several.
match.dst_port?number | readonly number[]Destination port, or any of several.
match.vlan?nameCarried in this VLAN.
action"accept" | "drop"What happens to a matching packet.
rate?RateAccepted traffic above this rate is dropped.

System and management ​

System ​

Device-wide settings.

FieldTypeDescription
timezone?stringIANA zone, for example Asia/Jakarta. UTC when absent.
banner?stringShown at login.
dns?objectResolvers the device uses.
dns.serversreadonly IP[]Resolvers, in order of preference.
dns.serve?booleanAnswer queries from others. Off when absent.
ntp?objectTime the device keeps.
ntp.serversreadonly string[]Time sources, by address or name.
ntp.serve?booleanAnswer time queries from others. Off when absent.
logging?objectWhere log messages go.
logging.local?objectKept on the device's own storage, from level up.
logging.local.levelSeverityThe least severe message kept.
logging.local.files?numberHow many rotated files to keep.
logging.local.lines_per_file?numberLines in each file before it rotates.
logging.remote?objectSent to syslog collectors, each from its own level up.
logging.remote.addressIP
logging.remote.port?numberUDP port. 514 when absent.
logging.remote.levelSeverityThe least severe message sent.
release_channel?stringSoftware release track the device updates from.
transceiver_monitoring?booleanRead optic temperature, power and voltage.
ip?objectHost behaviour of the IP stack.
ip.icmp_redirects?booleanSend ICMP redirects. Off when absent.
ip.syn_cookies?booleanAnswer a TCP SYN flood with SYN cookies. Off when absent.

User ​

A login on the device.

FieldTypeDescription
role"admin" | "operator" | "read-only"What the user may do.
passwordSecretThe login password.
description?stringWho the account is for.
ssh_keys?readonly string[]Public keys accepted instead of the password over SSH.

Service ​

A way into the device. Absent means turned off.

FieldTypeDescription
allow?readonly Prefix[]Sources allowed. management.allow when absent.
port?numberTCP or UDP port. The protocol's own when absent.

SnmpUser ​

One SNMPv3 user.

FieldTypeDescription
auth"sha1" | "sha256"How messages are authenticated.
auth_passwordSecretThe authentication passphrase.
privacy"aes128" | "des"How messages are encrypted.
privacy_passwordSecretThe encryption passphrase.

Management ​

How the device is reached and managed.

FieldTypeDescription
allow?readonly Prefix[]Sources allowed to every service that does not state its own.
ssh?objectSecure shell.
ssh.weak_crypto?booleanAlso offer legacy ciphers, MACs and key exchanges. Off when absent.
ssh.auth_timeout?numberSeconds a login may take.
ssh.auth_retries?numberFailed attempts allowed per connection.
telnet?ServiceUnencrypted remote login.
http?ServiceWeb interface, unencrypted.
https?objectWeb interface over TLS.
https.certificate?nameOne of the device's certificates.
api?ServiceThe platform's own API, unencrypted.
api_tls?objectThe platform's own API over TLS.
api_tls.certificate?nameOne of the device's certificates.
ftp?ServiceFile transfer, unencrypted.
native?Service & { interfaces?: readonly name[] }The platform's own management protocol. interfaces also allows it at layer 2 on those interfaces.
snmp?objectPolling by SNMP.
snmp.community?SecretRead-only community for version 2c. Version 2c is off when absent.
snmp.users?Record<string, SnmpUser>Version 3 users, keyed by name.
snmp.contact?stringWho to contact about the device.
snmp.location?stringWhere the device is.
console?{ password: Secret }Console login uses this password. The device's users when absent.
privilege_password?SecretPassword for privileged mode, on platforms that have one.

DhcpServer ​

A DHCP server for one network.

FieldTypeDescription
interfacenameWhere it answers.
networkPrefixThe network it serves.
gatewayIPDefault gateway handed out.
dns?readonly IP[]Resolvers handed out.
poolreadonly [IP, IP]First and last address handed out.
lease_time?numberSeconds a lease lasts.
reservations?objectAddresses fixed to a MAC.
reservations.addressIP
reservations.macstring
reservations.description?stringWhose address it is.

DhcpRelay ​

Forward DHCP requests heard on an interface to servers elsewhere.

FieldTypeDescription
interfacenameWhere requests are heard.
serversreadonly IP[]Where they are forwarded.

Certificate ​

A certificate the device presents or trusts.

FieldTypeDescription
certificatestringThe certificate, PEM. Public, so it lives in the repository.
private_key?SecretIts private key: a PEM file through secretFile, or PEM base64-encoded as one line through secret. A certificate only trusted, such as a CA, has none.

FlowExport ​

Export flow records or packet samples to collectors.

FieldTypeDescription
protocol"sflow" | "netflow-v9" | "ipfix"The record format.
collectorsobjectWhere records are sent.
collectors.addressIP
collectors.port?numberUDP port. 6343 for sFlow and 2055 otherwise when absent.
sampling?numberSample one packet in this many. Every packet when absent, on a platform that can export every packet.
interfaces?readonly name[]Where traffic is observed. Every interface when absent.

Common values ​

Secret ​

A value kept out of the repository and resolved only when a device is applied. secret("NAME") reads a variable from the environment or .env.local. secretFile("path") reads a file, relative to the project root, for a value that spans lines such as a private key in PEM. Keep that file out of git.

FieldTypeDescription
secretstringName of the value in the environment or in .env.local.
secret_filestringPath of a file holding the value, relative to the project root.

IP ​

An address without a length, IPv4 or IPv6, for example 10.0.0.1.

ts
string

Prefix ​

A network with its length, for example 10.0.0.0/24.

ts
string

Address ​

An interface address with its length, for example 10.0.0.1/24.

ts
string

Family ​

An address family.

ts
"ipv4" | "ipv6"

Rate ​

Bits per second, for example 2G, 500M or 64k.

Severity ​

A log severity, most severe first. A threshold includes everything above it.

ts
"emergency" | "alert" | "critical" | "error" | "warning" | "notice" | "info" | "debug"

Released under the Business Source License 1.1.