-
Notifications
You must be signed in to change notification settings - Fork 2
blueprints
Thomas Mangin edited this page Apr 8, 2026
·
1 revision
Pre-Alpha. This page describes behavior that may change.
Blueprints are end-to-end worked examples. Each one covers a real deployment scenario with a topology, the full Ze configuration, the verification steps, and a list of the things to expect to go wrong the first time. They are not reference documentation; they are the page you read when you have decided what you want to build and you want a starting point that already works.
- Route server at an IXP. Run Ze as an IXP route server. Topology, peer config, route server policy, Looking Glass exposure, RPKI integration.
- Transit edge with RPKI. A transit-customer edge router with RPKI validation, BGP Role enforcement, and prefix limits.
- Public Looking Glass. Stand up a public Looking Glass for your AS, with TLS, a reverse proxy, and Alice-LG integration.
- ExaBGP Migration Walkthrough. A complete worked migration of a non-trivial ExaBGP setup, end to end.
- FlowSpec Injection. Inject BGP FlowSpec rules from a script for DDoS mitigation.
- Chaos-Tested Peering. Set up a peering session and verify it survives a battery of chaos scenarios.
- AS Path Topology. Use the Looking Glass topology graph to visualise a real network's AS paths.
- First Steps for the shortest path from a fresh install to a working first peer.
- Configuration overview for the underlying model every blueprint builds on.
- Operation for the day-2 surface.
Unreviewed draft. This wiki was authored in bulk and has not been reviewed. File corrections on the issue tracker.
- Overview
- YANG Model
- Editor Workflow
- Archive and Rollback
- System
- Interfaces
- VRRP
- BFD
- FIB
- OSPF
- IS-IS
- MPLS / LDP / RSVP-TE
- RSVP-TE
- SRv6
- Static Routes
- Policy Routing
- Firewall
- Traffic Control
- Class of Service
- L2TP/PPP
- PPPoE
- VPP Data Plane
- RPKI
- IPsec VPN
- TACACS+ AAA
- RADIUS AAA
- AS112 DNS
- Authorization
- Fleet
- BGP
- Starting and Stopping
- Show Commands
- Monitoring
- Flow Export
- DDoS Mitigation
- Anomaly Detection
- Health Checks
- Audit Trail
- Production Diagnostics
- Logging
- Operational Reports
- Healthcheck
- Self-Update
- Zero-Touch Provisioning
- MRT Analysis
- Upgrade and Restart
- Storage
- Policy
- Core
- Resilience
- Validation
- Capabilities
- Address Families
- Protocol
- Subsystems
- Infrastructure
- Route Server at an IXP
- Transit Edge with RPKI
- Public Looking Glass
- ExaBGP Migration Walkthrough
- FlowSpec Injection
- Chaos-Tested Peering
- AS Path Topology