containerd / containerd/nerdctl

Macvlan/ipvlan sharing subnet with host

Open
#5,026 1 comment 0 reactions 0 assignees View on GitHub
kind/unconfirmed-bug-claim
Dominant language
Go
Stars
10.4k
Forks
826
Avg merge
1d 23h
Merged PRs (30d)
44

Description

### Description

With docker you can create a macvlan (or ipvlan) that uses the same subnet as the parent interface. With nerdctl this results in:

```
FATA[0000] subnet 192.168.100.0/24 overlaps with other one on this address space
```

### Steps to reproduce the issue

1. Figure out what IP subnet your host network interface is on (e.g. with `ip addr` or `ifconfig`) and use interface and subnet that in the commands below:
2. `nerdctl network create mac0 --driver macvlan -opt=parent=enp0s31f6 --subnet=192.168.100.0/24 --gateway=192.168.100.1`
3. Compare with the same with docker, which is successful

### Describe the results you received and expected

I would expect to be able to have containers that are on the same subnet as the host is on, as is possible with docker.

### What version of nerdctl are you using?

2.3.4

### Are you using a variant of nerdctl? (e.g., Rancher Desktop)

None

### Host information

```
Client:
Namespace: default
Debug Mode: false

Server:
Server Version: v2.2.5
Storage Driver: overlayfs
Logging Driver: json-file
Cgroup Driver: systemd
Cgroup Version: 2
Plugins:
Log: fluentd journald json-file none syslog
Storage: native overlayfs
Security Options:
apparmor
seccomp
Profile: builtin
cgroupns
Kernel Version: 6.17.0-35-generic
Operating System: Ubuntu 24.04.4 LTS
OSType: linux
Architecture: x86_64
CPUs: 24
Total Memory: 61.65GiB
Name: hostname_elided_from_github
ID: 341d48a9-3718-4be9-9bb9-451cb451f849
```

Contributor guide

No contributing guide indexed for this repository

Research direction

Start by reproducing the issue with `nerdctl network create` using the macvlan or ipvlan driver, then compare the result with the equivalent Docker command. Trace the network-create path responsible for rejecting overlapping subnets. Done means a macvlan or ipvlan can share the host interface's subnet and the documented reproduction command succeeds.

Written by the indexing model from the issue text.

Assessment

Tech stack
docker, go
Domain
cli, networking
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.