{"id":18684561,"url":"https://github.com/kubevirt/macvtap-cni","last_synced_at":"2026-01-12T09:04:24.916Z","repository":{"id":37805507,"uuid":"234783713","full_name":"kubevirt/macvtap-cni","owner":"kubevirt","description":"A CNI + device plugin combo for virtualization workloads on Kubernetes.","archived":false,"fork":false,"pushed_at":"2025-10-29T17:19:42.000Z","size":14072,"stargazers_count":52,"open_issues_count":1,"forks_count":32,"subscribers_count":5,"default_branch":"main","last_synced_at":"2025-10-29T19:28:54.853Z","etag":null,"topics":["cni","device","kubernetes","network"],"latest_commit_sha":null,"homepage":"","language":"Go","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/kubevirt.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2020-01-18T19:10:47.000Z","updated_at":"2025-10-29T17:19:47.000Z","dependencies_parsed_at":"2022-08-18T15:21:14.037Z","dependency_job_id":"db6fcad6-c819-437e-baf2-a49212d3db53","html_url":"https://github.com/kubevirt/macvtap-cni","commit_stats":null,"previous_names":[],"tags_count":23,"template":false,"template_full_name":null,"purl":"pkg:github/kubevirt/macvtap-cni","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kubevirt%2Fmacvtap-cni","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kubevirt%2Fmacvtap-cni/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kubevirt%2Fmacvtap-cni/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kubevirt%2Fmacvtap-cni/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/kubevirt","download_url":"https://codeload.github.com/kubevirt/macvtap-cni/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/kubevirt%2Fmacvtap-cni/sbom","scorecard":{"id":572793,"data":{"date":"2025-08-11","repo":{"name":"github.com/kubevirt/macvtap-cni","commit":"03052df2eea1ca111ad679b5a547c7f81b8aa704"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":5.3,"checks":[{"name":"Code-Review","score":10,"reason":"all changesets reviewed","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Maintained","score":1,"reason":"2 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 1","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Packaging","score":-1,"reason":"packaging workflow not detected","details":["Warn: no GitHub/GitLab publishing workflow detected."],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Dangerous-Workflow","score":-1,"reason":"no workflows found","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Token-Permissions","score":-1,"reason":"No tokens found","details":null,"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"Branch-Protection","score":-1,"reason":"internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration","details":null,"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Security-Policy","score":10,"reason":"security policy file detected","details":["Info: security policy file detected: github.com/kubevirt/.github/SECURITY.md:1","Info: Found linked content: github.com/kubevirt/.github/SECURITY.md:1","Info: Found disclosure, vulnerability, and/or timelines in security policy: github.com/kubevirt/.github/SECURITY.md:1","Info: Found text in security policy: github.com/kubevirt/.github/SECURITY.md:1"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"SAST","score":0,"reason":"SAST tool is not run on all commits -- score normalized to 0","details":["Warn: 0 commits out of 30 are checked with a SAST tool"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"Pinned-Dependencies","score":1,"reason":"dependency not pinned by hash detected -- score normalized to 1","details":["Warn: containerImage not pinned by hash: cmd/Dockerfile:3","Warn: containerImage not pinned by hash: cmd/Dockerfile:18: pin your Docker image by updating registry.access.redhat.com/ubi8/ubi-minimal to registry.access.redhat.com/ubi8/ubi-minimal@sha256:395dec18e7ba913157b1ecf2fd696d701ef834fd77054fffdb7eb678f864eb9e","Warn: downloadThenRun not pinned by hash: automation/check-patch.setup.sh:19","Warn: goCommand not pinned by hash: vendor/github.com/json-iterator/go/build.sh:10","Warn: goCommand not pinned by hash: vendor/google.golang.org/grpc/regenerate.sh:35","Warn: goCommand not pinned by hash: vendor/google.golang.org/grpc/vet.sh:37","Info:   0 out of   2 containerImage dependencies pinned","Info:   0 out of   1 downloadThenRun dependencies pinned","Info:   1 out of   4 goCommand dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"Vulnerabilities","score":7,"reason":"3 existing vulnerabilities detected","details":["Warn: Project is vulnerable to: GO-2025-3503 / GHSA-qxp5-gwg8-xv66","Warn: Project is vulnerable to: GO-2025-3595 / GHSA-vvgc-356p-c3xw","Warn: Project is vulnerable to: GO-2025-3488 / GHSA-6v2p-p543-phr9"],"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-20T16:47:33.160Z","repository_id":37805507,"created_at":"2025-08-20T16:47:33.160Z","updated_at":"2025-08-20T16:47:33.160Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":28337617,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-01-12T06:09:07.588Z","status":"ssl_error","status_checked_at":"2026-01-12T06:05:18.301Z","response_time":98,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cni","device","kubernetes","network"],"created_at":"2024-11-07T10:18:09.357Z","updated_at":"2026-01-12T09:04:24.892Z","avatar_url":"https://github.com/kubevirt.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"# macvtap CNI\n\nThis plugin allows users to define Kubernetes networks on top of existing\nhost interfaces. By using the macvtap plugin, the user is able to directly\nconnect the pod to a host interface and consume it through a tap device.\n\nThe main use cases are virtualization workloads inside the pod driven by\nKubevirt but it can also be used directly with QEMU/libvirt and it might be\nsuitable combined with other virtualization backends.\n\nmacvtap CNI includes a device plugin to properly expose the macvtap interfaces\nto the pods. A metaplugin such as [Multus](https://github.com/intel/multus-cni)\ngets the name of the interface allocated by the device plugin and is responsible\nto invoke the cni plugin with that name as deviceID.\n\n## Deployment\n\nThe device plugin is configured through environment variable `DP_MACVTAP_CONF`.\nThe value is a json array and each element of the array is a separate resource\nto be made available:\n\n* `name` (string, required) the name of the resource\n* `lowerDevice` (string, required) the name of the macvtap lower link\n* `mode` (string, optional, default=bridge) the macvtap operating mode\n* `capacity` (uint, optional, default=100) the capacity of the resource\n\nIn the default deployment, this configuration shall be provided through a\nconfig map, for [example](examples/macvtap-deviceplugin-config-explicit.yaml):\n\n```yaml\nkind: ConfigMap\napiVersion: v1\nmetadata:\n  name: macvtap-deviceplugin-config\ndata:\n  DP_MACVTAP_CONF: |\n    [ {\n        \"name\" : \"dataplane\",\n        \"lowerDevice\" : \"eth0\",\n        \"mode\": \"bridge\",\n        \"capacity\" : 50\n    } ]\n```\n\n```bash\n$ kubectl apply -f https://raw.githubusercontent.com/kubevirt/macvtap-cni/main/examples/macvtap-deviceplugin-config.yaml\nconfigmap \"macvtap-deviceplugin-config\" created\n```\n\nThis configuration will result in up to 50 macvtap interfaces being offered for\nconsumption, using eth0 as the lower device, in bridge mode, and under\nresource name `macvtap.network.kubevirt.io/dataplane`.\n\nA configuration consisting of an empty json array, as proposed in the default\n[example](examples/macvtap-deviceplugin-config-default.yaml), causes the device\nplugin to expose one resource for every physical link or bond on each node. For\nexample, if a node has a physical link called eth0, a resourced named\n`macvtap.network.kubevirt.io/eth0` would be made available to use macvtap\ninterfaces with eth0 as the lower device\n\nThe macvtap CNI can be deployed using the proposed\n[daemon set](manifests/macvtap.yaml):\n\n```\n$ kubectl apply -f https://raw.githubusercontent.com/kubevirt/macvtap-cni/main/manifests/macvtap.yaml\ndaemonset \"macvtap-cni\" created\n\n$ kubectl get pods\nNAME                                 READY     STATUS    RESTARTS   AGE\nmacvtap-cni-745x4                      1/1    Running           0    5m\n```\n\nThis will result in the CNI being installed and device plugin running on all\nnodes.\n\nThere is also a [template](templates/macvtap.yaml.in) available to parameterize\nthe deployment with different configuration options.\n\n## Usage\n\nmacvtap CNI is best used with Multus by defining a NetworkAttachmentDefinition:\n\n```yaml\nkind: NetworkAttachmentDefinition\napiVersion: k8s.cni.cncf.io/v1\nmetadata:\n  name: dataplane\n  annotations:\n    k8s.v1.cni.cncf.io/resourceName: macvtap.network.kubevirt.io/dataplane\nspec:\n  config: '{\n      \"cniVersion\": \"0.3.1\",\n      \"name\": \"dataplane\",\n      \"type\": \"macvtap\",\n      \"mtu\": 1500\n    }'\n```\n\nThe CNI config json allows the following parameters:\n* `name`     (string, required): the name of the network. Optional when used within a\n   NetworkAttachmentDefinition, as Multus provides the name in that case.\n* `type`     (string, required): \"macvtap\".\n* `mac`      (string, optional): mac address to assign to the macvtap interface.\n* `mtu`      (integer, optional): mtu to set in the macvtap interface.\n* `deviceID` (string, required): name of an existing macvtap host interface, which\n  will be moved to the correct net namespace and configured. Optional when used within a\n  NetworkAttachmentDefinition, as Multus provides the deviceID in that case.\n* `promiscMode` (bool, optional): enable promiscous mode on the pod side of the\n  veth. Defaults to false.\n\nA pod can be attached to that network which would result in the pod having the corresponding\nmacvtap interface:\n\n```yaml\napiVersion: v1\nkind: Pod\nmetadata:\n  name: pod\n  annotations:\n    k8s.v1.cni.cncf.io/networks: dataplane\nspec:\n  containers:\n  - name: busybox\n    image: busybox\n    command: [\"/bin/sleep\", \"1800\"]\n    resources:\n      limits:\n        macvtap.network.kubevirt.io/dataplane: 1 \n``` \n\nA mac can also be assigned to the interface through the network annotation:\n\n```yaml\napiVersion: v1\nkind: Pod\nmetadata:\n  name: pod-with-mac\n  annotations:\n    k8s.v1.cni.cncf.io/networks: |\n      [\n        {\n          \"name\":\"dataplane\",\n          \"mac\": \"02:23:45:67:89:01\"\n        }\n      ]\nspec:\n  containers:\n  - name: busybox\n    image: busybox\n    command: [\"/bin/sleep\", \"1800\"]\n    resources:\n      limits:\n        macvtap.network.kubevirt.io/dataplane: 1 \n```\n\n**Note:** The resource limit can be ommited from the pod definition if \n[network-resources-injector](https://github.com/intel/network-resources-injector)\nis deployed in the cluster.\n\nThe device plugin can potentially be used by itself in case you only need the\ntap device in the pod and not the interface:\n\n```yaml\napiVersion: v1\nkind: Pod\nmetadata:\n  name: macvtap-consumer\nspec:\n  containers:\n  - name: busybox\n    image: busybox\n    command: [\"/bin/sleep\", \"123\"]\n    resources:\n      limits:\n        macvtap.network.kubevirt.io/dataplane: 1 \n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkubevirt%2Fmacvtap-cni","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fkubevirt%2Fmacvtap-cni","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fkubevirt%2Fmacvtap-cni/lists"}