I recently figured out how to expose a public IPv6 address for an Incus container running in my home network. I created a bridge on the Incus host and attached its Ethernet card to it. I then use this bridge as the container’s network when launching the container. This allows my router to assign a public IPv6 address to it.
I would like to do the same thing with an Incus managed bridge. This will help me isolate the exposed container. Any idea how get get my router and the new Incus network to work together in such a way to provide public IPv6 address to containers running in the new Incus managed bridge?
Assuming you have a block larger than /64 from your ISP (I have a /56), then you simply need to create an incus bridge with its own unique /64, and static route it on the upstream router.
For example:
your ISP routes 2001:db8:beef:ca00::/56 to you
you use subnet 2001:db8:beef:caff::/64 between the router and your incus server
router is 2001:db8:beef:caff::1
incus host is 2001:db8:beef:caff::2
assign address 2001:db8:beef:cafe::1/64 to the incus managed bridge (e.g. incusbr0), and set ipv6.nat: "false"
on the router, add a static route to 2001:db8:beef:cafe::/64 via 2001:db8:beef:caff::2
You can get incus’ dnsmasq to assign addresses to containers using either SLAAC or DHCPv6. The latter has the advantage that you can set static assignments per container.
I have a /64 block provided from my ISP. I guess the process would be the same. I would just cut up what I have and setup the static routes and managed bridge the ways you suggested.
In priciple, yes. But that won’t play nice with e.g. SLAAC in the instances, which assumes that you have a /64 on the managed bridge (in general, pretty much anything in IPv6 assumes that the smallest routed segment is a /64). You might get away with using DHCPv6 (ipv6.dhcp.stateful=true in the nework config), but I wouldn’t rely on it.
It might work to make a more specific subnet from the /64, but you’d have to be careful that SLAAC on the main /64 doesn’t assign any addresses from that chunk. And/or you’d need some sort of proxy NDP.
Trying to split into two /65’s is unlikely to work. In principle DHCPv6 could do it, but some devices can’t use DHCPv6 - the main example being any Android phone.
Sensible ISPs are supposed to assign a /56 or a /48 to end customers, as a matter of best practice. It’s possible that they are doing so, but your router is only picking up the first available /64. You might just need to configure your router to ask for a larger block, via DHCP prefix delegation. But really the ins-and-outs of how IPv6 works are off-topic for an incus discussion group.
At worst, you can run all the containers behind a single IPv6 address (with ipv6.nat: "true"), and then use incus proxy devices to redirect individual ports to your containers. In that case, the host listens on port X and then forwards traffic to container Y port Z.
Thanks for all the great advice. Networking has always been the hardest part of using Incus. I have learned most of what I know from experimenting and this forum. The rest I learned from cloud computing.
True. Any idea of where to go for a good discussion? Sadly, the best alternative I have found is chatting with Claude.