From 4b5c1b67bfadc6578b7dc04a5ebb626b4f83cd95 Mon Sep 17 00:00:00 2001 From: Paul Holzinger Date: Fri, 3 Jul 2026 16:27:26 +0200 Subject: [PATCH] docs: update network create --route description The netavark mention is not needed as we only support it now. Then update it for the new route type syntax which was not documented in commit daaf8b62ba. Also add an example and a note that containers with CAP_NET_ADMIN can alter routes still. Signed-off-by: Paul Holzinger --- docs/source/markdown/podman-network-create.1.md.in | 13 ++++++++++++- 1 file changed, 12 insertions(+), 1 deletion(-) diff --git a/docs/source/markdown/podman-network-create.1.md.in b/docs/source/markdown/podman-network-create.1.md.in index 3a0da30733..8ccca4e26e 100644 --- a/docs/source/markdown/podman-network-create.1.md.in +++ b/docs/source/markdown/podman-network-create.1.md.in @@ -46,7 +46,13 @@ Ignore the create request if a network with the same name already exists instead #### **--route**=*route* -A static route in the format `,,`. This route will be added to every container in this network. Only available with the netavark backend. It can be specified multiple times if more than one static route is desired. +A static route in the format `,,`. +The gateway must be a valid ip address or alternatively a type can be set instead which must be either +of `blackhole`, `unreachable` or `prohibit` and means the subnet will not be routed anywhere. +This route will be added to every container in this network. It can be specified multiple times if more than one static route is desired. + +Note, routes are added into the container namespace, if a container is given the CAP_NET_ADMIN capability it is able to alter +the routes so this cannot be used for security relevant things in that case. @@option subnet @@ -99,6 +105,11 @@ route. $ podman network create --subnet 192.168.33.0/24 --route 10.1.0.0/24,192.168.33.10 --opt no_default_route=true newnet ``` +Create a network with a route type blackhole. This means the traffic to the destination subnet will be dropped silently. +``` +$ podman network create --route 10.1.0.0/24,blackhole --opt no_default_route=true newnet +``` + Create a Macvlan based network using the host interface eth0. Macvlan networks can only be used as root. ``` $ sudo podman network create -d macvlan -o parent=eth0 --subnet 192.5.0.0/16 newnet