A network lab with containerlab

Docker and containerlab on one Linux machine, a network OS image, a spine and two leaves wired together, a first interface configuration, and the whole thing in a git repository.

beginner~30 min hands-on
#containerlab#docker#srlinux#ceos#lab#netdevops

Not validated end to end yet — be the first.Report a problem

Draft — not yet run end to end. This page was written but its author has not yet run it on a real machine. Commands may be wrong: read before you run, and tell us what breaks.

The gistOne machine, three switches
Lab machine
Lab ${LAB_NAME}
sshdeployslinklink
Your laptopssh · git
containerlabdeploy · inspect · destroy
spine1
leaf1
leaf2

containerlab reads topology.clab.yml, asks Docker for three containers running the network OS, wires them with virtual cables and puts their management interfaces on ${MGMT_SUBNET}.

A network lab used to be a rack, a week of cabling and a licence. With containerlab it is a YAML file and one command: the nodes are containers running a real network OS, the links are virtual wires between them. This page installs the tooling on one Linux machine, brings up a spine and two leaves, configures the first links, and puts the whole thing in git so the next pages can build on it.

Before you start

$sudo apt update && sudo apt install -y curl git
$mkdir -p
Check
$lsb_release -is && docker --version >/dev/null 2>&1 || echo no-docker-yet
Expected output
Ubuntu
no-docker-yet

Install Docker and containerlab

Sensitive command — runs a remote script. Review before running.
$curl -fsSL https://get.docker.com | sudo sh
$sudo usermod -aG docker $USER
$newgrp docker
$docker run --rm hello-world | head -2

Then containerlab, pinned to :

$sudo bash -c "$(curl -sL https://get.containerlab.dev)" -- -v
$containerlab version
Check
$containerlab version | grep -o 'version: '
Expected output
version: 

Get the image

$docker pull
Check
$docker image ls  -q | wc -l
Expected output
1

Write the topology

${LAB_DIR}/topology.clab.yml
name:
mgmt:
network: -mgmt
ipv4-subnet:
topology:
kinds:
nokia_srlinux:
image:
nodes:
spine1: { kind: nokia_srlinux, mgmt-ipv4: }
leaf1: { kind: nokia_srlinux, mgmt-ipv4: }
leaf2: { kind: nokia_srlinux, mgmt-ipv4: }
links:
- endpoints: ["spine1:e1-1", "leaf1:e1-1"]
- endpoints: ["spine1:e1-2", "leaf2:e1-1"]
Check
$cd  && python3 -c 'import yaml; t = yaml.safe_load(open("topology.clab.yml")); print(len(t["topology"]["nodes"]), len(t["topology"]["links"]))'
Expected output
3 2

Deploy and look around

$cd
$sudo containerlab deploy -t topology.clab.yml
$sudo containerlab inspect -t topology.clab.yml

Log in to a node. containerlab created /etc/hosts entries, and the default credentials are admin / NokiaSrl1!:

$ssh admin@
text
A:spine1# show version
A:spine1# show interface brief
Check
$docker ps --filter name=clab-- -q | wc -l
Expected output
3
Check
$sudo containerlab inspect -t /topology.clab.yml | grep -c running
Expected output
3
If a node stays in 'created' or restarts

docker logs clab-<V name="LAB_NAME" />-spine1 tells. The usual causes: not enough RAM (the kernel kills the biggest process, dmesg | grep -i kill), or a management subnet that overlaps a network the host already has (ip route; pick another ). Destroy, fix, redeploy.

A first configuration

text
enter candidate
set / interface ethernet-1/1 admin-state enable
set / interface ethernet-1/1 subinterface 0 admin-state enable
set / interface ethernet-1/1 subinterface 0 ipv4 admin-state enable
set / interface ethernet-1/1 subinterface 0 ipv4 address 10.1.0.0/31
set / interface ethernet-1/2 admin-state enable
set / interface ethernet-1/2 subinterface 0 admin-state enable
set / interface ethernet-1/2 subinterface 0 ipv4 admin-state enable
set / interface ethernet-1/2 subinterface 0 ipv4 address 10.1.0.2/31
set / network-instance default interface ethernet-1/1.0
set / network-instance default interface ethernet-1/2.0
commit now

From spine1, ping leaf1 across the link:

text
ping -c 3 10.1.0.1 network-instance default
Check
$docker exec clab--spine1 sr_cli 'ping -c 3 10.1.0.1 network-instance default' | grep -o '3 received'
Expected output
3 received

Save, destroy, redeploy

$cd
$sudo containerlab save -t topology.clab.yml
$ls clab-/
$sudo containerlab destroy -t topology.clab.yml
$sudo containerlab deploy -t topology.clab.yml
Check
$sudo containerlab inspect -t /topology.clab.yml | grep -c running
Expected output
3

The lab in git

${LAB_DIR}/.gitignore
clab-*/
*.tar.xz
.venv/
$cd
$git init
$git add topology.clab.yml .gitignore
$git commit -m "containerlab topology: spine1, leaf1, leaf2"
Check
$git -C  status --short | wc -l
Expected output
0

Done

Three SR Linux nodes run on , wired spine-to-leaf, reachable on , and , and the topology is in git. You can destroy and rebuild the whole thing in two commands:

$cd && sudo containerlab destroy -t topology.clab.yml --cleanup && sudo containerlab deploy -t topology.clab.yml

The addresses you typed by hand in this page are the last ones you will type: the next page models the lab in NetBox, devices, interfaces, cables and IPs, so that configuration can be generated from it.

Did everything work?

If you followed this page to the end on a real machine, say so. Your validation is dated and records your stack, so the next reader on the same path knows it still works.

This copy is read-only. To report that it works, or that it does not, open an issue

Only your stack choices are recorded, never your values. The pseudonym stays on this browser.