-
Notifications
You must be signed in to change notification settings - Fork 2
feature inventory
Pre-Alpha. This page describes behavior that may change.
The full inventory of what Ze does. Not the narrative ("why this exists") or the comparison ("how it stacks up"), just the list. Use this page when you need to check whether a specific feature is present and whether it is built into the engine or provided by a plugin.
The in-tree docs/features.md is the canonical source. When this page and that one disagree, the in-tree page wins.
See BGP peers for the configuration surface and the comparison page for the per-feature breakdown against other daemons.
| Area | Detail |
|---|---|
| Address families | 21, covering IPv4/IPv6 unicast, multicast, labelled unicast, VPN, FlowSpec, EVPN, VPLS, BGP-LS, MVPN, RTC, and MUP. IPv4/IPv6 unicast and multicast are built into the engine; everything else ships as an nlri plugin. |
| Capabilities | Multiprotocol, 4-byte ASN, Route Refresh, Enhanced Route Refresh, ADD-PATH, Extended Messages, Extended Next Hop, Graceful Restart, Long-Lived GR, BGP Role, Hostname, Software Version, Link-Local Next Hop. |
| Path attributes | ORIGIN, AS_PATH, NEXT_HOP, MED, LOCAL_PREF, ATOMIC_AGGREGATE, AGGREGATOR, COMMUNITY, ORIGINATOR_ID, CLUSTER_LIST, MP_REACH_NLRI, MP_UNREACH_NLRI, EXTENDED_COMMUNITY, LARGE_COMMUNITY, PREFIX_SID, AIGP (RFC 7311). |
| Route loop detection | AS loop (RFC 4271 section 9), ORIGINATOR_ID (RFC 4456), CLUSTER_LIST (RFC 4456). All three run before prefix-limit counting and silently treat the route as withdrawn. |
| UPDATE coalescing | Consecutive IPv4 unicast UPDATEs with identical attributes are merged into a single UPDATE message. |
| Feature | Detail |
|---|---|
| YANG-modelled | Every field, every CLI prompt, every web UI form comes from the same YANG schemas. |
| Atomic commit | Edit, diff, commit, rollback, commit confirmed with auto-rollback. Named archive blocks with triggers (commit, manual, daily, hourly), on-change detection, scheduler, RPC-triggered archival, and commit-revisions pruning. |
| Per-user drafts | Each user gets an independent editor session; drafts survive disconnection. |
| Hot reload | No daemon restart required for config changes. Session resets only when the underlying change demands it. Graceful listener migration on config reload for web, LG, REST, gRPC, MCP endpoints. Auto-reload config on web UI commit. |
| Prefix limits (RFC 4486) | Mandatory per-family per-peer maximum. Refuses to start without one. |
| Update groups | Automatic cross-peer UPDATE building deduplication, based on encoding context. |
| Keepalive timer | Configurable keepalive interval (RFC 4271 Section 10 MAY). Default 0 = hold-time/3 derivation. Non-zero overrides. Clamped to negotiated-hold/3 if peer negotiates a lower hold time. |
| Session resilience | TCP_NODELAY, DSCP CS6, graceful close, Send Hold Timer (RFC 9687), congestion extension for hold timer, bounded overflow pool with GR-aware teardown. |
| Deactivate/activate | Mark any node (container or leaf) inactive. Kept in the config file, skipped at apply time. |
interface plugin. Netlink on Linux, stdlib fallback elsewhere.
| Interface type | MAC required | Notes |
|---|---|---|
ethernet |
Yes | Physical ethernet interface. |
veth |
Yes | Virtual ethernet pair. |
bridge |
Yes | Bridge interface. |
dummy |
No | Virtual dummy interface. |
loopback |
No | Container, no key. |
pppoe |
No | PPPoE client interface. |
Static addressing (per-family ipv4 { address ... } / ipv6 { address ... } containers), DHCP client (with route/DNS/NTP discovery), interface monitoring, make-before-break migration with ze interface migrate, route-priority for configurable DHCP route metric, and IPv6 default route management from Router Advertisements. Named unit keys (string labels, not numeric IDs). Per-interface offload control (gso, gro, tso) and steering config. RPF check enum (strict, loose, disabled) replaces rp-filter integer. Per-interface rate tracking (1-second sampler with show interface rate, monitor interface rate, 12 ze_interface_* Prometheus gauges, web rate columns).
Additional interface types:
| Interface type | Notes |
|---|---|
tunnel (gre, gretap, ipip, sit, ip6gre, ip6gretap, ip6tnl) |
Full tunnel family support via netlink. |
wireguard |
WireGuard encrypted tunnels with peer reconciliation on reload. |
xfrm |
XFRM interface for route-based IPsec. Traffic routed through the interface is encrypted; traffic arriving on it is decrypted. |
VPP interface backend is also available (interface { backend vpp; }) for GoVPP-backed lifecycle, addressing, bridge, and monitoring.
| Surface | Transport | Auth |
|---|---|---|
| CLI | SSH, port 2222 by default. | User database with bcrypt passwords, SSH public keys (ed25519, RSA, ECDSA), ED25519 host key. |
| Web UI | HTTPS, port 3443 by default. Workbench V2 (experimental). | Same user database. Session cookies for browsers, Basic Auth for API clients. |
| Looking Glass | HTTP or HTTPS on its own configurable port (separate from the web UI). | None. Read-only by design. |
| MCP | HTTP on 127.0.0.1, port must be specified. |
Optional bearer token. Task-augmented tools/call, Apps resources. |
| REST API | Dedicated HTTP(S) server on port 8081 by default, /api/v1/execute, /api/v1/commands, typed config sessions, Swagger UI. |
Bearer per-user or single token. |
| gRPC API | Dedicated server on port 50051 by default, ze.api.v1.ZeService + ze.api.v1.ZeConfigService, server reflection, built-in TLS. |
Bearer metadata (same tokens as REST). |
| gNMI | gRPC Network Management Interface on port 9339 by default (env-gated ze.gnmi.enabled). Capabilities, Get, Set, Subscribe ONCE and STREAM. See gNMI. |
Bearer token (constant-time compare), optional TLS. |
The list of built-in plugins, grouped by category. Full reference in plugins.
| Category | Plugins |
|---|---|
| Storage |
bgp-rib (N-way multipath best-path, multi-source protocol IDs), bgp-adj-rib-in, bgp-persist. |
| Policy |
bgp-rs (with dynamic peers, RS-client, community filtering), bgp-rr (RFC 4456), bgp-watchdog, bgp-healthcheck, bgp-filter-community, bgp-filter-community-match, bgp-filter-prefix, bgp-filter-aspath, bgp-filter-aspath-length, bgp-filter-modify (set/inc/dec local-pref/MED/AIGP, community add/remove), bgp-filter-remove-private-as, bgp-redistribute, loop, bgp-role, policy-routes. |
| Resilience |
bgp-gr, bgp-route-refresh. |
| Validation |
bgp-rpki (ROA origin validation RFC 6811, ASPA path verification with policy enforcement reject/log-only/accept, RTR v2 RFC 9582), bgp-rpki-decorator. |
| Capabilities |
bgp-aigp (RFC 7311), bgp-hostname, bgp-llnh, bgp-softver. |
| Protocol |
bfd (RFC 5880, auth, echo mode), bgp-bmp (RFC 7854, Adj-RIB-Out, looking glass integration). |
| Address families |
bgp-nlri-vpn, bgp-nlri-evpn, bgp-nlri-flowspec, bgp-nlri-ls, bgp-nlri-labeled, bgp-nlri-vpls, bgp-nlri-mvpn, bgp-nlri-rtc, bgp-nlri-mup. |
| Subsystems |
l2tp (RFC 2661, PPP, BNG, RADIUS, shaping, CQM, web UI), pppoe (RFC 2516, AC + client), firewall (nftables + VPP, global-options, FlowSpec bridge), traffic (tc/VPP), ntp, sysctl, tacacs (RFC 8907), static, dhcpserver (multiple named ranges), kernel, flowspec-firewall (FlowSpec-to-nftables bridge). |
| Security |
ipsec (native IKEv2 in Go, XFRM dataplane), pki (X.509 certificate store, health monitoring, Prometheus metrics). |
| Provisioning |
tftpserver (RFC 1350), imageserver (HTTP image server with Range support). |
| Infrastructure |
interface, fib-kernel, fib-vpp (GoVPP, MPLS), fib-p4, iface-dhcp, iface-vpp, rib (system RIB, unified Loc-RIB), host (inventory, SMART, tuning), vpp. |
Native IKEv2 implementation in Go. No external IKE daemon.
| Feature | Detail |
|---|---|
| IKEv2 (RFC 7296) | Full IKE_SA_INIT, IKE_AUTH, CREATE_CHILD_SA, INFORMATIONAL exchange support. |
| Proposals | AES-CBC, AES-GCM (128/256), ChaCha20-Poly1305. DH: MODP 2048/3072/4096/8192, ECP 256/384/521. PRF: SHA-256/384/512. |
| Authentication | X.509 certificates, EAP-MSCHAPv2, EAP-TLS. |
| NAT-T (RFC 3948) | Automatic NAT detection, UDP encapsulation on port 4500, keepalive. |
| DPD | Dead Peer Detection via INFORMATIONAL exchange. |
| Rekeying | IKE SA and Child SA rekeying with collision handling. |
| MOBIKE (RFC 4555) | Address update on interface change. |
| Virtual IP pool | Remote-access server assigns addresses from a configured pool. |
| XFRM dataplane | Route-based IPsec via XFRM interfaces. |
| Interop testing | Docker-based interop tests against strongSwan. |
| CLI |
show ipsec tunnels, show ipsec sa, clear ipsec tunnel. |
| Health | IPsec component in health registry. Prometheus metrics. |
| Feature | Detail |
|---|---|
| Certificate management | X.509 certificates, private keys, CA certificates loaded from PEM files. |
| TLS integration | Serves TLS certificates for web UI and gRPC API. |
| Health monitoring | Certificate expiry warnings (30 days) and errors (expired). |
| Prometheus metrics |
ze_pki_certificate_expiry_seconds, ze_pki_certificate_valid. |
| CLI |
show pki certificates. |
Bidirectional Forwarding Detection (RFC 5880/5881/5882/5883). Sub-second failure detection.
| Feature | Detail |
|---|---|
| Single-hop (RFC 5881) | GTSM TTL=255, SO_BINDTODEVICE, per-session timers. |
| Multi-hop (RFC 5883) | UDP 4784, min-TTL gate, loopback peering. |
| Authentication (RFC 5880 S6.7) | Keyed MD5, meticulous keyed MD5, keyed SHA1, meticulous keyed SHA1. |
| Echo mode (RFC 5880 S6.4) | Single-hop only, async slow-down. |
| BGP peer opt-in |
bfd { } inside bgp peer connection. RFC 9384 Cease subcode 10 on BFD Down. |
| Named profiles | Bundles of timer and feature parameters, shared across sessions. |
| Standalone sessions | Pinned sessions for gateway or tunnel monitoring. |
| Prometheus metrics |
ze_bfd_sessions, ze_bfd_transitions_total, ze_bfd_detection_expired_total, ze_bfd_tx_packets_total, ze_bfd_rx_packets_total. |
BGP Monitoring Protocol (RFC 7854) in both directions.
| Feature | Detail |
|---|---|
| Receiver | Accepts BMP feeds from routers. Parses all 7 message types. Configurable listener endpoints. |
| Sender | Streams to collectors. Peer Up/Down, Route Monitoring (pre-policy and post-policy), Statistics, Initiation, Termination. |
| Adj-RIB-Out (RFC 8671) | Sender wraps sent UPDATEs as post-policy Route Monitoring with O+L flags. |
| Looking glass integration | BMP-monitored routes visible in dedicated LG endpoints under "bmp" protocol namespace. |
| CLI |
ze show bmp sessions, ze show bmp peers, ze show bmp collectors, ze show bmp rib. |
Native L2TPv2 (RFC 2661) BNG subsystem.
| Feature | Detail |
|---|---|
| Tunnel FSM | SCCRQ/SCCRP/SCCCN handshake, CHAP-MD5 tunnel auth, tie-breaker resolution. |
| Session FSM | ICRQ/ICRP/ICCN, OCRQ/OCRP, CDN/WEN/SLI. |
| PPP | LCP, PAP, CHAP-MD5, MS-CHAPv2, IPCP, IPv6CP. Periodic re-auth. |
| Kernel data plane |
l2tp_ppp via netlink. |
| RADIUS | Authentication and accounting. CoA/DM listener. Configurable source address. |
| Traffic shaping | TBF/HTB qdisc on pppN interfaces, per-session rates via RADIUS or config. |
| CQM | Firebrick-style per-session event ring and 24h sample buckets. |
| Session observer | Event namespace, CQM sampler. |
| Prometheus metrics | L2TP session, CQM, and RADIUS counters. |
| Web management UI | Sessions, CQM chart, event timeline, disconnect. |
| Redistribute | Subscriber /32 and /128 routes into BGP via bgp-redistribute. |
| CLI |
show l2tp tunnels/sessions/statistics, l2tp tunnel/session teardown. |
RFC 2516 PPPoE access concentrator (alternative to L2TP for direct-attach subscribers).
| Feature | Detail |
|---|---|
| Discovery | PADI/PADO/PADR/PADS/PADT with AC-Cookie, service-name filtering. |
| PPP driver | Shared with L2TP: LCP, auth, IPCP/IPv6CP, pool, shaper. |
| Security | HMAC-SHA256 AC-Cookie, PADI rate limiting, MAC binding. |
| Concurrent | Runs alongside L2TP on the same daemon. |
| Feature | Detail |
|---|---|
| ECMP | Multiple next-hops as multipath routes. |
| Weighted | Per-next-hop weight for traffic distribution. |
| BFD failover | BFD-tracked next-hops with automatic reprogramming. |
| Blackhole/reject | Discard or ICMP unreachable. |
| Routing table selection | Per-route table parameter for multi-table configurations. |
| Interface-only next-hops | Next-hop with interface name only (no IP address), for point-to-point links. |
| Redistribute | Importable as protocol "static" in BGP redistribute. Kernel routes also redistributable via import kernel. |
| Feature | Detail |
|---|---|
| Match criteria | Source/dest address, port, protocol, TCP flags, set references. |
| Actions | Accept, drop, table (user-populated), next-hop (auto-managed), tcp-mss. |
| Interface binding | Per-interface or wildcard (l2tp*) policy application. |
| Implementation | nftables fwmark + kernel ip rules. |
| Feature | Detail |
|---|---|
| Kernel MPLS FIB | BGP labeled-unicast routes programmed into the Linux MPLS FIB (label push via netlink lwtunnel). 20-bit label / 16-deep stack validation. net.mpls.platform_labels and per-interface mpls { enable } (net.mpls.conf.<iface>.input) sysctls. ze doctor kernel-module check, ze_fibkernel_mpls_* metrics, show mpls forwarding. See MPLS / LDP / RSVP-TE. |
| LDP (RFC 5036) | UDP multicast discovery, TCP session FSM, label information base. ldp component. |
| RSVP-TE (RFC 3209/2205) | Control plane over raw IP (protocol 46): PATH/RESV for ingress/transit/egress, ERO explicit routing, per-interface bandwidth admission with PathErr, soft-state refresh, PathTear, make-before-break (SE). rsvp-te plugin. See RSVP-TE. |
| Dataplane ownership | LDP and RSVP-TE emit push/swap/pop entries on the mpls-fib event bus; fib-kernel programs them and remains the single kernel-FIB owner. |
| SRv6 Prefix-SID (RFC 9252, RFC 8669) | PREFIX_SID attribute parse/transposition for VPN and EVPN families, EBGP opt-in filtering, Linux SEG6 and VPP SR-steering FIB programming (ingress PE). See SRv6. |
| Feature | Detail |
|---|---|
| Firewall (nft) | Stateful packet filtering with nftables backend. Expression lowering, conntrack. Named sets with timeout. Global-options sysctl convenience mappings. Masquerade port mapping and flags. FlowSpec-to-firewall bridge (flowspec-firewall plugin). |
| Firewall (VPP) | VPP ACL classify pipeline. NAT44-ED (SNAT, DNAT, masquerade). SetMark, Limit actions. |
| Traffic control | Per-interface queueing disciplines. HTB, TBF, FQ, netem (tc backend). Policers (VPP backend). Original-qdisc snapshot/restore. |
| Backend gate | Commit-time rejection of unsupported features via ze:backend YANG extension. |
| CLI |
show firewall, show traffic-control, clear verb. |
| Feature | Detail |
|---|---|
| Process lifecycle | Startup, crash recovery (exponential backoff), DPDK NIC binding, GoVPP connection. |
| FIB programming |
fib-vpp installs best routes via GoVPP binary API. Replays RIB on reconnect. MPLS label programming from labeled unicast. |
| Interface backend | GoVPP-backed lifecycle, addressing, bridge, monitor via interface { backend vpp; }. |
| Telemetry | Per-interface rx/tx counters, per-node clocks, system vector rates via stats segment. |
| External mode |
vpp.external true for systemd-managed or container VPP. |
| Feature | Detail |
|---|---|
| Local users | Multi-user YANG login, bcrypt passwords, ED25519 host key. ze passwd command. |
| SSH public keys | Per-user multi-key support. ssh-ed25519, ssh-rsa, ecdsa-sha2-nistp{256,384,521}. |
| TACACS+ (RFC 8907) | PAP authentication, priv-lvl mapping to local authz profiles, accounting. Local bcrypt fallback. |
| AAA chain | Pluggable backend registry (VFS-shaped). TACACS+ priority 100, local bcrypt priority 200. |
| Junos format |
$9$ encrypted passwords supported in config. |
| Feature | Detail |
|---|---|
| NTP client | System clock synchronization with clock readiness gate for interfaces. NTP diagnostics with show ntp and Adjtimex slew mode. |
| Sysctl profiles | Named profiles (dsr, router, hardened, multihomed, proxy) for interface units. Three-layer precedence. |
| Host inventory | Hardware inventory library, show host CLI surface. SMART health monitoring. Hardware tuning engine. |
| Static DNS | System nameserver config, resolver unification. |
| System reboot |
system reboot for gokrazy/Linux appliances. |
| Conntrack | Conntrack helper management. Per-helper enable/disable under system { conntrack { ... } }. Helpers: ftp, h323, sip, pptp, tftp, sane, irc, amanda, netbios-ns, snmp, nfs, sqlnet. |
| Serial console | Serial console configuration under system { serial-console { ... } }. Baud rate, data bits, stop bits, parity. |
| Self-update | Periodic version check with optional automated download, SHA-256 verification, atomic binary replacement via rename with .prev rollback. Fleet-scale: deterministic spread scheduling, maintenance windows, server-side pause. CLI: update system firmware {check,download,apply,restart,rollback}. Server: ze update-serve. |
| System readiness |
ze doctor offline pre-start checks: runtime platform detection (gokrazy, systemd, container, plain-linux, darwin) with capability probing, config syntax, TLS certs, VPP socket/configured-socket, BGP MD5, IPsec path, kernel modules, interfaces, SSH host key, listener conflicts, plugins, storage integrity, disk space, DNS resolver, clock skew, NTP/RPKI/BMP/writable checks, random-seed persistence, machine-id. --json output with stable diagnostic codes. ze explain <code> for remediation. |
| Tech-support bundle |
ze support offline archive generator with 20 pure-Go modules (no shell-outs, gokrazy-safe): version, doctor, host, platform, config (sanitized), crashes, disk, interfaces, routes, neighbors, env, sysctl, runtime, dmesg, sockets, kernel modules, conntrack, file descriptors, DNS, firewall. --module/--exclude/--since/--sensitive/--reason/--json. Archive: ze-support-<hostname>-<timestamp>.tar.gz. |
| Debug flags | Persistent per-subsystem debug flags in ZeFS. ze debug enable/disable/show, hierarchical prefixes (ze debug enable bgp covers bgp.*), three-tier resolution, survives restart. |
| Audit trail | Structured local audit log for config commit/discard, daemon reload, and failed authentication across SSH, web, REST, gRPC, MCP, CLI, system. show audit filters by action, actor, surface, time, count. Disk-backed JSON-lines (file configs) or memory-only (stdin configs). See Audit. |
| Health registry |
show health and /health HTTP endpoint. Per-component status (bgp, fib, firewall, iface, plugins, vpp, ipsec, pki, l2tp). HTTP 503 when any component is down. |
| Crash capture | Automatic stderr redirect captures panic stack traces. Forwarded to syslog and persisted to crash files with ring buffer context. CLI: show crashes, show crashes latest. |
| Config schema stamp | Schema version stamp in config files with downgrade recovery. |
| Config graph |
ze config graph for config dependency analysis. |
| Gokrazy appliance | TLS cert caching, management proxy, zefs bootstrap, kmsg logging, DHCP-auto discovery. Appliance builder with init, build, push, config-push, export/import. |
| Docker | Static binary on scratch base (~89 MB). make ze-docker. Compose support. |
| Local install |
ze install local: copies the binary to an FHS prefix, sets up a systemd unit (auto-detected), scaffolds the config directory. ze service install/uninstall manages the unit separately. ze uninstall reverses it (--purge removes config). |
| Zero-touch provisioning |
ze install remote: PXE-based bare-metal provisioning. Forks ze - to run DHCP+PXE (options 43/60/66/67/93, BIOS/UEFI bootfile), TFTP (RFC 1350), and HTTP image server (Range). Installer initrd (tools/installer-initrd/) PXE-boots, downloads the gokrazy image over HTTP, writes the first non-removable disk, injects zefs onto partition 4, reboots. Bootstrap mode: zefs-but-no-config boots DHCP client on every ethernet NIC plus SSH. |
| Config management interfaces | gNMI server (environment { gnmi {} }, default port 9339, env-gated) for YANG-modeled config via Capabilities/Get/Set/Subscribe. See gNMI. |
| ZeFS integrity | Per-record CRC32c checksums, in-place writes, ze data check/ze data repair CLI. |
| Remote credentials | Per-service SSH credential storage in ZeFS. ze remote CLI for remote operations. |
| Feature | Where |
|---|---|
| Prometheus metrics |
telemetry { prometheus { ... } }. Peer state, message counters, prefix counters, forward-pool utilisation, connection timing histograms, plugin health. Basic auth support. |
| Host metrics |
ze_host_* namespace: memory, CPU, ECC, NIC speed/carrier, thermal, storage. |
| OS metrics | Netdata-compatible collectors: CPU, memory, network, disk, conntrack, IPv6, softirqs, sockstat6. |
| Flow export | sFlow v5, NetFlow v9 (RFC 3954), IPFIX (RFC 7011) over UDP. tc/psample packet sampling, conntrack per-flow records, optional BGP next-hop enrichment. show flow-export [<collector>], ze_flowexport_* metrics. See Flow Export. |
| Structured logging | JSON output, hierarchical per-subsystem levels, runtime-configurable. Slog ring buffer query. |
| Live event stream |
ze cli monitor event, pipeable to ` |
| Live peer dashboard |
ze cli monitor bgp. Auto-refreshing two seconds, sortable. |
| Operational report bus |
ze show warnings, ze show errors. Cross-subsystem state and event surface, login banner reads the same source. |
| Core diagnostics | 11 built-in diagnostic commands replacing ss, dmesg, lsof, dig, nc, traceroute, mtr, ping, tcpdump, pprof on gokrazy appliances. show system sockets, show system kernel-log, show system goroutines, show tcp-check, show traceroute, show system file-descriptors, show system profile (cpu/heap pprof), show system memory-map, show capture interface (AF_PACKET live capture with BPF filters). |
| Live monitoring |
monitor ping (continuous ICMP with live stats), monitor traceroute (mtr-style continuous trace with | log | origin and | log | resolve enrichment), monitor system netlink (kernel route/link/address change stream), monitor interface rate (per-interface rate tracking). |
| DNS diagnostics |
show dns lookup (resolution), show dns cache list/stats/record (cache inspection), clear dns cache (selective delete and flush). |
| Runtime diagnostics | FSM history rings, capture rings (BGP, L2TP, BFD), VPP trace, pcap export. RPF lookup (LPM on Loc-RIB for multicast PIM-SM upstream next-hop resolution). |
| Component health |
/health endpoint, per-component status registry (bgp, fib, firewall, iface, plugins, vpp, ipsec, pki, l2tp). |
| MRT analysis | Standalone ze-analyse tool. Downloads from RIPE RIS and RouteViews, runs density, attribute, community, and AS_PATH suffix sharing analyses. |
| Benchmarking |
ze-perf cross-implementation latency benchmark. OpenBGPd added as 8th DUT. |
| Feature | Detail |
|---|---|
| In-daemon chaos |
--chaos-seed and --chaos-rate flags inject faults at runtime. Deterministic with a fixed seed. |
| Orchestrator |
ze-chaos runs mock peers, validates protocol properties, and records runs to NDJSON. |
| Dashboard | Live HTMX web dashboard with peer table, property badges, and interactive controls. |
| Event logs | Record, replay, and shrink failing runs. |
| Properties | Convergence deadline, route consistency, no duplicate routes, hold timer enforcement, message ordering. Per-family convergence. |
| Action types | 6 parameterized chaos action types (v2): configurable fault injection with per-action parameters. |
| MCP server | MCP integration for AI-driven chaos testing. Watchdog consumer. |
| Feature | Detail |
|---|---|
| Self-describing |
ze help --ai (grouped by sections), ze schema list, ze env list, ze --plugins. Unified show <noun> grammar for all read commands. Backend-aware completion filtering. ze help --json for structured output. |
| Plugin SDK | Go SDK for in-tree plugins, line-protocol SDK for external plugins in any language. |
| ExaBGP migration |
ze config migrate converts configs, ze exabgp plugin runs existing scripts unchanged. |
ze bgp decode / ze bgp encode
|
Offline BGP message codec. |
| Fuzz testing | Every external-input parser has a fuzz harness. |
| Interop testing | 30+ Docker-based scenarios against FRR, BIRD, GoBGP, OpenBGPD, FreeRtr, and Rust implementations. |
| Kind | Count or scope |
|---|---|
| Unit tests | Several thousand test functions. |
| Functional tests | Hundreds. Config parsing, wire encoding, plugin behaviour. |
| Fuzz harnesses | Every external-input parser. |
| Chaos scenarios | Configurable, deterministic, with event-log replay and shrinking. |
| Interop suite | Docker scenarios against FRR, BIRD, GoBGP. |
- Comparison for how these features line up against other BGP daemons.
- What is Ze for the narrative view.
- Status for what actually works today.
- In-tree features for the authoritative list.
Adapted from main/docs/features.md.
Unreviewed draft. This wiki was authored in bulk and has not been reviewed. File corrections on the issue tracker.
- Overview
- YANG Model
- Editor Workflow
- Archive and Rollback
- System
- Interfaces
- VRRP
- BFD
- FIB
- OSPF
- IS-IS
- MPLS / LDP / RSVP-TE
- RSVP-TE
- SRv6
- Static Routes
- Policy Routing
- Firewall
- Traffic Control
- Class of Service
- L2TP/PPP
- PPPoE
- VPP Data Plane
- RPKI
- IPsec VPN
- TACACS+ AAA
- RADIUS AAA
- AS112 DNS
- Authorization
- Fleet
- BGP
- Starting and Stopping
- Show Commands
- Monitoring
- Flow Export
- DDoS Mitigation
- Anomaly Detection
- Health Checks
- Audit Trail
- Production Diagnostics
- Logging
- Operational Reports
- Healthcheck
- Self-Update
- Zero-Touch Provisioning
- MRT Analysis
- Upgrade and Restart
- Storage
- Policy
- Core
- Resilience
- Validation
- Capabilities
- Address Families
- Protocol
- Subsystems
- Infrastructure
- Route Server at an IXP
- Transit Edge with RPKI
- Public Looking Glass
- ExaBGP Migration Walkthrough
- FlowSpec Injection
- Chaos-Tested Peering
- AS Path Topology