I have LXD containers connected to a linux bridge. I would like to enable port isolation on the bridge, eg:
ip link set dev tap0 master bridge0
bridge link set dev veth0 isolated on
bridge link set dev veth1 isolated on
bridge link set dev veth2 isolated on
The goal being that any of the containers can share the network segment and talk to the upstream bridge port, but not to each other.
It’s simple enough to configure the bridge with the upstream port, but I’m not sure how to handle dynamically setting the “isolated on” for the container links. It would be ideal if there were a bridge interface setting in lxd that supported this, but I don’t see reference to one in the docs.
Failing that, does anyone have any ideas for how to most efficiently configured LXD to run the CLI bridge command whenever a container starts? Some type of hook script? Something systemd?