diff --git a/pkg/routing/bird/config.go b/pkg/routing/bird/config.go index c23d144..2eb9a4d 100644 --- a/pkg/routing/bird/config.go +++ b/pkg/routing/bird/config.go @@ -53,30 +53,36 @@ protocol kernel kernel6 { learn; ipv6 { import all; - export all; + # Do NOT push BIRD static routes back to the kernel; the agent owns + # the kernel host routes for anycast. BIRD static is for advertise only. + export filter { + if source = RTS_STATIC then reject; + accept; + }; }; } protocol kernel kernel4 { learn; ipv4 { import all; - export all; + export filter { + if source = RTS_STATIC then reject; + accept; + }; }; } -# gateway recursive is set per BGP protocol below — it controls how -# BIRD resolves a route's next-hop when the gateway isn't on a directly -# connected interface (our case: anycast routes use the pod's /128 eth0 -# IP as via, which is itself a host route, not a network). protocol static static6 { ipv6; {{range $cidr := .CIDR6}}route {{$cidr}} blackhole; + {{end}}{{range $a := .Anycast6}}route {{$a}}/128 blackhole; {{end}} } protocol static static4 { ipv4; {{range $cidr := .CIDR4}}route {{$cidr}} blackhole; + {{end}}{{range $a := .Anycast4}}route {{$a}}/32 blackhole; {{end}} } {{range $i, $p := .Peers}}{{if eq $p.Family "v6"}} @@ -84,7 +90,6 @@ protocol bgp upstream6_{{$i}} { local{{if $.LocalV6}} {{$.LocalV6}}{{end}} as {{$.LocalASN}}; neighbor {{$p.Address}} as {{$p.ASN}}; graceful restart; - gateway recursive; ipv6 { import all; next hop self; @@ -100,7 +105,6 @@ protocol bgp upstream4_{{$i}} { local{{if $.LocalV4}} {{$.LocalV4}}{{end}} as {{$.LocalASN}}; neighbor {{$p.Address}} as {{$p.ASN}}; graceful restart; - gateway recursive; ipv4 { import all; next hop self;