Chuyển đến nội dung chính

Lesson 15: Containers, Automation and Production Best Practices

Guide to running containers on VyOS, automation with Ansible and API, backup, upgrade, security hardening, real deployments, and an Ansible playbook lab.

Containers, Automation and Production Best Practices

Containers, Automation and Production Best Practices on VyOS

VyOS 1.4/1.5 supports containers (Podman), enabling auxiliary services such as exporters and monitoring components. In addition, VyOS provides API support, Ansible integration, backup, upgrades, and operational best practices for production environments.

Containers on VyOS

set container name prometheus-exporter image prom/node-exporter
set container name prometheus-exporter network bridge address 192.168.50.10/24
set container name prometheus-exporter health-check interval 30

Supports bridge, macvlan, health checks, and management via Podman CLI.

Automation with Ansible

# ansible.cfg
[defaults]
inventory = ./hosts
host_key_checking = False

playbook.yaml

  • hosts: vyos gather_facts: no tasks:
    • name: Push config vyos.vyos.vyos_config: lines: - set interfaces ethernet eth0 address 192.168.1.1/24

VyOS HTTP API and REST API

set service https api listen-address 0.0.0.0
set service https api port 8443

Send configuration commands through REST API:

curl -k -u vyos:password -X POST https://vyos:8443/configure -d '{"op": "set", "path": ["interfaces", "ethernet", "eth0", "address"], "value": "192.168.1.2/24"}'

Scripting and custom commands

set system login user vyos authentication plaintext-password 'password'
run show version

Backup, upgrade, and rollback

# Backup config
cp /config/config.boot /config/backup-$(date +%F).boot
# Upgrade image
add system image https://downloads.vyos.io/rolling/current/amd64/vyos-1.5-rolling.iso
# Rollback
set system image default-boot vyos-1.4-rolling

Security hardening checklist

  • Change SSH port, disable root login, and allow key-based auth only.
  • Disable unused services: delete service telnet, delete service ftp.
  • Set firewall policies to protect VyOS itself.

Production deployment scenarios

  • Home router: NAT, VPN, firewall, monitoring.
  • Small business: dual-WAN, HA, container exporter.
  • ISP edge: BGP, IPsec, automation, backup.

Hands-on lab: Ansible playbook deployment for VyOS config

  1. Prepare ansible.cfg and hosts files with VyOS IP addresses.
  2. Write a playbook using vyos_config module to push configuration.
  3. Run the playbook and verify state on VyOS.
ansible-playbook -i hosts playbook.yaml

Summary

This lesson helps you apply containers, Ansible automation, APIs, backup, upgrades, security hardening, and production deployment patterns for VyOS in real-world operations.