- automatically generate filters based on the AS number of the BGP neighbor
- publish per-router VyOS configure scripts through Cloudflare Workers
- update all managed configurations periodically
This repository provides the logic and default templates used to configure a VyOS router for an ISP. The router runs BIRD inside a container; VyOS itself only handles the host plumbing.
The generated VyOS host script (configure.{router}.sh) manages:
system host-name
system task-scheduler task update-config
container name bird (the BIRD container)
system sflow
service snmp
The generated bird.conf (served separately, run inside the container) manages all routing policy:
RPKI ROA tables + RTR protocols
prefix / as-path / community filter sets (autogen defaults)
per-neighbor import/export filters
BGP protocol instances (upstream / downstream / peer / routeserver / ibgp)
kernel + direct + static protocols (redistribution)
BMP monitoring
AS{ASN}is the config repository. It storesnetwork/vyos/vyos.yamland the generated cache files undercache/.- This repository stores the generator code, default templates, helper tools, and the Cloudflare Worker.
configure/save-cache.pypreparescache/pdb/summary.json,cache/bgpq4/summary.json, andcache/as-set/summary.jsonfor the config repository.- The Cloudflare Worker reads
vyos.yamland the cache files directly from GitHub, then serves:/{user}/{config_repo}/router/configure.{router}.sh— VyOS host setup script/{user}/{config_repo}/router/bird.{router}.conf— generatedbird.conffor the router
- The
configure.{router}.shinstalls anupdate-configscheduler that re-downloads and re-applies the script from the Worker every 12 hours. The host script in turn fetchesbird.{router}.confinto the container and reloads BIRD.
- Fork this repository and name it
{Your Organization}/as{Your ASN}-vyos-scripts. - Create a new repository named
AS{Your ASN}. - Create
network/vyos/vyos.yamlin theAS{Your ASN}repository. You can refer to the example at https://github.com/KawaiiNetworks/AS27523/tree/main/network/vyos/vyos.yaml - Install local dependencies for cache generation:
- Python deps are managed by pixi: run
pixi installin the repo root. bgpq4is a separate system tool (not on conda-forge) — install it via your package manager, e.g.apt-get install bgpq4orbrew install bgpq4.
- Python deps are managed by pixi: run
- Build cache files into the config repository:
pixi run python configure/save-cache.py /path/to/AS{Your ASN}
- Deploy the Cloudflare Worker from this repository using the
Deploy Cloudflare WorkerGitHub Actions workflow. - Use the Worker URL to fetch
configure.{router}.sh, or let the installedupdate-configscheduler refresh it automatically on the router.
Kernel ECMP is enabled by default for the main routing table and each VRF. If
limit is omitted, the generator emits merge paths on;, leaving the maximum
number of nexthops at BIRD's native default (currently 16). It can be overridden
per routing context:
protocols:
kernel:
ecmp:
enabled: true # optional; defaults to true
limit: 16 # optional; omit to use BIRD's defaultSet enabled: false to disable path merging. A BGP neighbor may set a relative
ECMP nexthop weight from 1 through 256:
protocols:
bgp:
peer:
- asn: 6939
neighbor-address: 185.1.184.189
metric: "-10" # BGP MED adjustment / path eligibility
weight: 3 # ECMP share relative to other equivalent pathsweight does not make unequal BGP paths equivalent: attributes such as local
preference, AS path and MED must still satisfy BIRD's multipath selection rules.
For a route-map, we divide it into 3 parts: gather, filter, modifier.
gather: to gather routes and then goto filter filter: to filter routes and then goto modifier modifier: to modify attributes of routes
adding item to gather will increase the number of routes of filter (it can only add routes because it's whitelist) we call it pre-(import/export/none)-filter. EBGP import route-map do not have a gather now because we directly import all route to filter. For EBGP export route-map we will design a gather section in future. Now it's available for redistribution route-map.
in modifier, you can modify attributes of routes, or deny routes (it can only modify or deny routes because it's applied after filter) we call it pre-(import/export/none)-accept.