I have a raspberry host which has a couple of incus containers running. The network configuration uses a bridge type. For one specific container there significant network traffic, both incoming and outgoing. However the bridge device does not see the incoming traffic.
In the host this are the statistics for the physical device:
3: enx207bd297e6dc: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc fq_codel state UP mode DEFAULT group default qlen 1000
link/ether 20:7b:d2:97:e6:dc brd ff:ff:ff:ff:ff:ff
RX: bytes packets errors dropped missed mcast
35360303111 25100489 0 1 0 0
TX: bytes packets errors dropped carrier collsns
8537229375 9765756 0 0 0 0
That is roughly 35GB of received data and 8GB of transmitted data. All that traffic is comming from a single container, which has a simple http service.
One would expect the bridge device used by the container to have similar statistics:
9: veth155a6555@if8: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue master incusbr0 state UP mode DEFAULT group default qlen 1000
link/ether 9e:6c:9e:3c:77:08 brd ff:ff:ff:ff:ff:ff link-netnsid 1
RX: bytes packets errors dropped missed mcast
279924702 4170438 0 0 0 0
TX: bytes packets errors dropped carrier collsns
35577086390 23629517 0 0 0 0
In that case the transmitted bytes from the host bridge corresponds roughly to the received bytes of the physical device. However the received bytes of the bridge device (279MB) is far from the transmitted bytes of the physical device (8.2GB).
Inside the container the bridge device shows the same statistics as in the host, only inverted, obviously:
8: eth0@if9: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP mode DEFAULT group default qlen 1000
link/ether 10:66:6a:08:1e:4f brd ff:ff:ff:ff:ff:ff link-netnsid 0
RX: bytes packets errors dropped missed mcast
35577086390 23629517 0 0 0 0
TX: bytes packets errors dropped carrier collsns
279924702 4170438 0 0 0 0
How is then possible to do proper account of the container network resources?
This is using Debian 13 as the OS for the host and the container. incus is installed from the repo:
ii incus-base 6.0.4-2+deb13u11 arm64 Powerful system container and virtual machine manager - daemon (container-only)
ii incus-client 6.0.4-2+deb13u11 arm64 Powerful system container and virtual machine manager - client