salt.modules.nm_ip#

The networking module for RedHat-family distributions managed by NetworkManager (RHEL/CentOS/Alma/Rocky 8+, Fedora).

This is the ip execution-module provider behind network.managed on NetworkManager systems. The legacy rh_ip provider writes /etc/sysconfig/network-scripts/ifcfg-* and brings interfaces up with ifup/ifdown from the network-scripts package. On EL8+ that package is not installed by default (and is removed entirely on EL10), so rh_ip fails with No such file or directory: 'ifdown' and no interface is configured -- see issues #54791, #68252 and #62844.

This provider instead writes NetworkManager keyfiles under /etc/NetworkManager/system-connections/ and applies them with nmcli, which is the supported way to manage networking on modern RedHat systems.

New in version 3006.28.

Note

NetworkManager is the source of truth here, so only the subset of the network.managed schema that maps cleanly onto NM connection keyfiles is supported: addresses, gateway, nameservers, dns search domains, mtu (on ethernet, bond, bridge and vlan), dhcp, hwaddr/macaddr, the autoneg/speed/duplex link parameters, wake-on-lan, the full bond option set, bridge/vlan attributes and static routes.

ifcfg/ifupdown-only options such as ethtool offload/channel settings and up/down hook scripts have no keyfile equivalent and raise an informative error rather than being silently dropped.

salt.modules.nm_ip.apply_network_settings(**settings)#

Reload NetworkManager so it picks up the keyfiles written by build_interface (nmcli connection reload).

CLI Example:

salt '*' ip.apply_network_settings
salt.modules.nm_ip.build_interface(iface, iface_type, enabled, **settings)#

Build (and, unless test=True, write) the NetworkManager keyfile for a network interface. Returns the rendered keyfile as a list of lines.

For bond and bridge interfaces the enslaved members (slaves / ports) are written out as their own port keyfiles as a side effect.

CLI Example:

salt '*' ip.build_interface eth0 eth True ipaddr=10.0.0.5 netmask=255.255.255.0 gateway=10.0.0.1
salt.modules.nm_ip.build_network_settings(**settings)#

No-op on NetworkManager: there is no global /etc/sysconfig/network equivalent that this provider manages; settings are expressed per connection. Returns an empty list.

CLI Example:

salt '*' ip.build_network_settings
salt.modules.nm_ip.build_routes(iface, **settings)#

Fold static routes into iface's salt-managed keyfile as NM routeN=<dest>,<nexthop> entries in the matching ipv4/ipv6 section. Returns the rendered route lines.

CLI Example:

salt '*' ip.build_routes eth0 routes='[{"ipaddr": "10.1.0.0", "netmask": "255.255.0.0", "gateway": "10.0.0.1"}]'
salt.modules.nm_ip.down(iface, iface_type=None)#

Deactivate iface's NetworkManager connection.

CLI Example:

salt '*' ip.down eth0
salt.modules.nm_ip.get_interface(iface)#

Return the salt-managed NetworkManager keyfile for iface as a list of lines, or an empty list if salt does not manage it yet.

CLI Example:

salt '*' ip.get_interface eth0
salt.modules.nm_ip.get_network_settings()#

NetworkManager has no separate global network-settings file (each connection keyfile is self-contained). Returns an empty list.

CLI Example:

salt '*' ip.get_network_settings
salt.modules.nm_ip.get_routes(iface)#

Return the static routes currently declared for iface in the salt-managed keyfile, as a list of lines.

CLI Example:

salt '*' ip.get_routes eth0
salt.modules.nm_ip.nm_managed()#

Return True if this system is managed by NetworkManager without the legacy network-scripts tooling: nmcli is available, NetworkManager is running (/run/NetworkManager exists) and neither ifup nor ifdown is on PATH.

This is the deterministic, load-time-safe condition that decides whether nm_ip or rh_ip owns the ip provider. The check itself lives in salt.utils.network.nm_managed() so both providers share a single definition, exactly one claims ip and no runtime service call is needed during __virtual__ resolution.

CLI Example:

salt '*' ip.nm_managed
salt.modules.nm_ip.up(iface, iface_type=None)#

Reload keyfiles and (re)activate iface's NetworkManager connection.

CLI Example:

salt '*' ip.up eth0