Skip to content

Sysctl

The sysctl statement allows configuring network-related sysctl settings which are not interface specific.

Schema description

# https://www.kernel.org/doc/Documentation/networking/ip-sysctl.txt
sysctl:
  all:
    # /proc/sys/net/ipv4/conf/all/
    ipv4:
      forwarding: 1
  default:
    # /proc/sys/net/ipv4/conf/default/
    ipv4:
      forwarding: 1

  # /proc/sys/net/mpls/
  # https://www.kernel.org/doc/Documentation/networking/mpls-sysctl.txt
  mpls:
    # set greater 0 to enable mpls forwarding
    platform_labels: 1024

The settings can be also configured inside of namespaces.

Tip

YAML has native support for anchors and aliases which can be used to apply the same sysctl settings to multiple namespaces:

sysctl: &my-sysctl
  all:
    ipv6:
      forwarding: 1
# …
namespaces:
  guests:
    sysctl: *my-sysctl
    # …

Examples:

Free-Form Configuration

The sysctl setting allows configuring settings explicitly supported in IfState, only. The sysctl_conf setting allows specifying any sysctl settings in the sysctl.conf configuration format.

It is possible to use YaML multiline strings or read the settings from a file using the !include tag. All settings need to be children of the net namespace. It is also possible to add empty and comment lines for convenience reasons:

sysctl_conf: |
  # double the max. number of conntrack entries
  net.nf_conntrack_max = 524288

  # change the default queuing discipline to CAKE
  net.core.default_qdisc = cake

  1. Multiprotocol Label Switching ↩

  2. Multipath TCP ↩