Hardware-lab tooling, HW line-rate CI and published performance results for FastACL, the FlowSpec DDoS filter plugin for VPP.
| Strategy | docs/test-strategy.md: layers, topologies, methodology, thresholds, reporting |
| Lab | docs/lab.md: machines, cabling, access |
| Reports | reports/: one folder per full-suite hardware run, named by date and time |
labs/hw/ hardware bench: bring-up, generator, DUT, suites, report
labs/hw/dpu/ BlueField-3 Arm bench
labs/hw/profiles per-DUT thresholds
docker/ TRex generator image, DUT image (built from a FastACL release bundle)
docs/ strategy, lab
- FastACL CI (in the FastACL repository) runs the functional suite, sanitizers and performance sanity on every push, against builds made with throwaway licence keys.
- Hardware runs are GitHub Actions workflows in this repository:
hw-line-rate, started manually (gate or full suite, on server1, epyc-sp5, epyc-cx8, the bluefield3 DPU, alice and bob); the BNG and generator-pair suites run fromrun.sh. They install the licensed FastACL release bundle on the DUT, the same one customers receive. Nothing here builds or unlocks FastACL. - One command per rig:
labs/hw/run.sh <server1|epyc-sp5|epyc-cx8|bluefield3|alice|bob> <gate|full|bng|pair>downloads the release bundle, syncs the lab hosts, switches the BlueField-3 between NIC and DPU mode when needed, brings up the DUT and generator, runs the suite, writes the report (published toreports/for the full, bng and pair suites; never for the gate), and tears down. The workflow calls exactly this; it runs the same from any machine withlabs/hw/lab.env, the lab SSH key andghaccess to the FastACL releases.
The bench never compiles anything. Every run installs a release bundle built and published
by the CI of the FastACL source repository, FastNetMon/fastacl
(private; the workflow reads it with the FASTACL_RELEASE_TOKEN secret):
- VPP: the
base-imageworkflow builds upstream FD.io VPP from its release tag (v25.10,v26.06) withmake pkg-deb, inside Ubuntu 24.04, on native GitHub runners:ubuntu-24.04for amd64 andubuntu-24.04-armfor arm64. - Plugin: the
ci.ymlrelease job builds the FastACL plugin out of tree against that VPP, with the production licence key, on the same runner architecture. - Bundle: the same job repacks the VPP packages (
vpp,libvppinfra,vpp-plugin-core,vpp-plugin-dpdk,vpp-crypto-engines) withdpkg-repack, addsfastacl-plugin, the install scripts and a 30-day evaluation licence, and publishes one tarball per VPP version and architecture:- every push to
mainreplaces the assets of the rollinglatest-mainrelease (fastacl-main-vpp2510.tar.gz,fastacl-main-vpp2510-arm64.tar.gz, ...); - every tag
vX.Y.Zcreates a versioned release (fastacl-vX.Y.Z-vpp2510.tar.gz, ...).
- every push to
The workflow inputs release_tag (default latest-main) and vpp (2510, 2606 or 2610) pick
the bundle; the rig profile adds the -arm64 suffix for bluefield3.
| Step | Code | What happens |
|---|---|---|
| Download | labs/hw/run.sh fetch_bundle |
gh release download of the bundle into bundle/, extracted to bundle/debs/*.deb |
| Copy | labs/hw/sync-hosts.sh |
rsync of the whole testbench, bundle/ included, to ~/fastacl-testbench on the DUT and the generator; for bluefield3 this runs after the switch to DPU mode |
| Image | labs/hw/dut-image.sh + docker/Dockerfile.dut |
on the DUT itself: Ubuntu 24.04 + apt-get install /tmp/debs/*.deb + the bundle licence, tagged fastacl-dut:current |
| Start | labs/hw/bringup-guarded.sh (x86) / labs/hw/dpu/run-dpu-bench.sh (Arm) |
x86: docker compose run dut with labs/hw/dut/start.sh; BlueField-3: docker run … fastacl-dut:current vpp -c labs/hw/dpu/startup-arm.conf |
The report records the installed vpp and fastacl-plugin versions and the release tag, so
every published number traces back to one bundle. Teardown removes the image, the bundle and
the checkout from the lab hosts.
Apache-2.0. FastACL itself is licensed separately.