Building a Network Lab with Containerlab and SR Linux - 夜莺博客

Building a Network Lab with Containerlab and SR Linux

Containerlab turns a folder of YAML into a running multi-vendor network topology in seconds, and Nokia SR Linux is the reference containerized NOS for it. That combination is the cheapest way to practise BGP, EVPN or ZTP without touching production hardware. This guide builds a three-node lab, gives each node a startup configuration written in SR Linux CLI syntax, and shows how to reach it both through ssh and through gNMI from the host.

Prerequisites

# Docker must be present; containerlab installs as a single binary
bash -c "$(curl -sL https://get.containerlab.dev)"
containerlab version

SR Linux images are pulled from the Nokia registry (ghcr.io/nokia/srlinux). Check the available tags with docker pull ghcr.io/nokia/srlinux before pinning a version in the topology file.

The Topology File

name: srl-lab
topology:
  nodes:
    srl1:
      kind: nokia_srlinux
      image: ghcr.io/nokia/srlinux
      startup-config: configs/srl1.cli
    srl2:
      kind: nokia_srlinux
      image: ghcr.io/nokia/srlinux
      startup-config: configs/srl2.cli
  links:
    - endpoints: ["srl1:e1-1", "srl2:e1-1"]
      ipv4: ["10.1.1.1/30", "10.1.1.2/30"]
    - endpoints: ["srl1:e1-2", "srl2:e1-2"]

Link addressing can live in the topology file (handy for pure-IP labs) or in the per-node startup configuration, but not both for the same interface - mixing them is the most common reason a lab comes up with duplicate or missing addresses.

Startup Configuration in SR Linux CLI Syntax

# configs/srl1.cli
set / system name host-name srl1
set / interface ethernet-1/1 admin-state enable
set / interface ethernet-1/1 subinterface 0 ipv4 admin-state enable
set / interface ethernet-1/1 subinterface 0 ipv4 address 10.1.1.1/30
set / network-instance default interface ethernet-1/1.0
set / network-instance default protocols bgp admin-state enable
set / network-instance default protocols bgp autonomous-system 65001
set / network-instance default protocols bgp router-id 10.0.0.1
set / network-instance default protocols bgp neighbor 10.1.1.2 peer-as 65002

Capture the exact lines from a working device with info flat and paste them here, so the lab configuration and the production configuration never diverge.

Deploy, Inspect, Connect

containerlab deploy -t srl-lab.clab.yml
containerlab inspect -t srl-lab.clab.yml
ssh admin@clab-srl-lab-srl1        # password: NokiaSrl1!
docker exec -it clab-srl-lab-srl1 sr_cli

Containerlab prepends clab-<topology>-<node> to container names, and also gives every node a management IP reachable from the host, so both SSH and gNMI work without port forwarding:

gnmic -a clab-srl-lab-srl1 --skip-verify -u admin -p NokiaSrl1! \
  -e json_ietf get --path /system/name/host-name
ssh admin@clab-srl-lab-srl1 "show network-instance default protocols bgp neighbor"

Debugging and Teardown

  • containerlab inspect shows node state; docker ps confirms the containers are up.
  • A node that boots with an empty config usually has a path typo in startup-config - run docker logs clab-...-srl1 to see the parse error.
  • Links that stay down in the lab are usually a mismatch between the endpoint names in YAML and the real interface names (e1-1 maps to ethernet-1/1).
  • Destroy with containerlab destroy -t srl-lab.clab.yml, or add --cleanup to remove the lab directory as well.

Once the lab is up, the workflow on the nodes themselves is the same as on hardware - start with SR Linux CLI and gNMI basics, then add telemetry with gNMI dial-in vs dial-out. For a full virtual data center alternative see EVE-NG lab installation, and for vendor-specific workflows CloudVision AVD labs in containerlab.

Extending the Lab into a Usable Test Bed

  • Add a Linux container with FRR or simply install iproute2 so you can generate traffic and test reachability from a host rather than from a router.
  • Capture on a link with containerlab tools veth capture -l clab-srl-lab-srl1-e1-1, or use tcpdump inside the node container.
  • Save a known-good snapshot by committing and exporting info flat from each node; restore by redeploying with the exported files as startup configs.
  • Pin image versions in the topology file once a lab works, so a registry update cannot silently change behaviour.

原文链接:https://containerlab.dev/manual/kinds/srl/