Red Hat OpenShift Networking is making it easier for you to seamlessly and directly integrate your Kubernetes platforms with the data center networks you already operate by adopting the same standards-based networking used throughout modern network fabrics. With Red Hat OpenShift 4.22, OpenShift Networking introduces support for ethernet VPN (EVPN), representing the next major milestone in enterprise network integration. By leveraging the industry-standard EVPN control plane, OpenShift can integrate more naturally with existing EVPN-VXLAN data center fabrics, enabling consistent Layer 2 and Layer 3 connectivity, scalable network virtualization, and operational alignment with enterprise networking infrastructure. This capability is particularly important for organizations modernizing large virtualization environments while preserving established network architectures and operational practices.

Extending OpenShift beyond the cluster

Traditional Kubernetes networking has typically treated the cluster boundary as the point where software-defined networking (SDN) ends and enterprise networking begins. Within the cluster, connectivity is abstracted and automated by the Kubernetes networking stack. Beyond the cluster, connectivity is governed by established routing architectures, data center fabrics, and operational practices that have evolved over many years.

OpenShift 4.18 introduced user-defined networks (UDN), providing isolated Layer 2 and Layer 3 network domains for advanced application connectivity within a cluster. OpenShift 4.19.12 extended those capabilities with the border gateway protocol (BGP), enabling OpenShift to participate directly in enterprise routing architectures (figure 1). 

Figure 1:  Seamless interconnect with an external Layer 2 or Layer 3 network using BGP+EVPN

Figure 1:  Seamless interconnect with an external Layer 2 or Layer 3 network using BGP+EVPN

Today, OpenShift Networking is designed to remove that architectural boundary. Rather than operating as an isolated networking domain, OpenShift continues to adopt the open protocols and standards used throughout modern enterprise networks, allowing cluster networking to integrate directly with the surrounding infrastructure.

Red Hat OpenShift 4.22 extends this approach by further integrating the OVN-Kubernetes cluster network with customer-managed external networks. Building on the BGP capabilities introduced in earlier releases, EVPN enables OpenShift to participate directly in standards-based EVPN-VXLAN fabrics, providing consistent connectivity between workloads running inside the cluster and the broader enterprise network.

The result is an OpenShift platform that operates as a first-class participant in the enterprise network fabric, enabling organizations to extend existing network architectures, operational models, and automation practices into Kubernetes without introducing a separate networking paradigm.

Connecting workloads across networks with EVPN

At its core, EVPN enables workloads connected to different physical networks to communicate as though they reside on the same Layer 2, or Layer 3 segment, even when traffic traverses multiple routed networks, leaf-spine fabrics, or geographically distributed data centers. It achieves this by using BGP as a standards-based control plane to distribute MAC and IP reachability information while decoupling the logical network from the underlying physical topology, and encapsulating that traffic inside VXLAN tunnels on the dataplane.

For network architects, this means that OpenShift becomes an active participant in your EVPN-VXLAN fabric, so rather than terminating EVPN-VXLAN at the Leaf or Top-of-rack (ToR) switch, EVPN-VXLAN instead terminates within OpenShift itself, extending the isolation further. Workloads retain consistent network connectivity while the underlying fabric provides scalable forwarding, resilient multipathing, and optimized traffic delivery. The EVPN border routers enforce which overlays should be able to reach the internet, WAN and other internal resources, and because they inject routes into EVPN, there is no change to the operational model.

This capability is particularly valuable for organizations modernizing large virtualization environments or operating across hybrid infrastructure. As virtual machine (VM) workloads are migrated from existing virtualization platforms to OpenShift Virtualization, EVPN enables those workloads to remain connected to the same logical network as their peers. Existing IP addressing schemes, network policies, and application dependencies can be preserved throughout the migration, eliminating the need for disruptive network redesigns or large-scale readdressing efforts.

Figure 2:  Logical flow diagram for traffic between an OpenShift VM/pod and an external network using EVPN

Figure 2:  Logical flow diagram for traffic between an OpenShift VM/pod and an external network using EVPN

The result is an OpenShift platform that integrates naturally into the enterprise network fabric, simplifying VM migrations to OpenShift while maintaining consistent network identity, easing migration planning, providing greater flexibility, and reducing operational risk.

Seamless integration with enterprise networks

OpenShift 4.22 enables administrators to extend selected user-defined networks beyond the cluster and into their enterprise EVPN fabric.

Description:  The logical set of steps for traffic flowing from an OpenShift UDN to an external network segment using EVPN

Figure 3: The logical set of steps for traffic flowing from an OpenShift UDN to an external network segment using EVPN

The result is standards-based connectivity that integrates naturally with existing enterprise networking infrastructure without requiring proprietary gateways or custom integrations.

Unlocking real-world customer scenarios

The introduction of EVPN enables several important customer use cases.

Accelerated virtualization modernization

Organizations migrating from traditional virtualization platforms can preserve existing Layer 2 connectivity during migration, allowing workloads to move into OpenShift Virtualization without disruptive IP address changes or network redesign.

Convenience and agility of overlay networking

EVPN decouples logical networks from the underlying physical infrastructure, enabling rapid network provisioning, simplified operations, and lower operational costs without requiring changes to the physical fabric.

Standards-based and industry standard networking

By leveraging the industry-standard EVPN control plane, organizations can extend existing network designs into Kubernetes while preserving operational consistency and avoiding proprietary SDN lock-in.

Hybrid infrastructure

Applications running across traditional infrastructure and OpenShift clusters can communicate using established enterprise networking architectures while maintaining consistent segmentation.

Enterprise data center integration

OpenShift user-defined networks can now extend directly into existing EVPN fabrics using industry-standard BGP/EVPN, allowing Kubernetes workloads to participate as native citizens within modern data center networks.

Advanced multi-tenant networking

Support for both MAC-VRFs and IP-VRFs enables customers to build highly segmented environments that maintain isolation while extending securely beyond cluster boundaries.

Built for enterprise scale and resilience

OpenShift's EVPN implementation is designed to integrate with the resiliency and scalability mechanisms already deployed throughout modern enterprise network fabrics. Rather than introducing a separate networking model, OpenShift leverages the same standards-based technologies used to deliver high availability and predictable forwarding across large-scale data center environments.

Combined with standards-based BGP integration, OpenShift can participate directly in dynamic routing, enabling fast convergence, Equal-Cost Multi-Path (ECMP) forwarding, and automated route distribution across the fabric.

Because both MAC-VRF and IP-VRF endpoint reachability is learned and advertised dynamically through BGP EVPN, network state remains synchronized as Layer 2 and Layer 3 workloads are created, migrated, or removed. This eliminates the need for static host configuration or custom automation to maintain connectivity, reducing operational overhead while allowing the network to adapt automatically to changes in infrastructure and workload placement.

Building a consistent networking architecture across hybrid cloud

EVPN support is more than a capability for on-premises deployments – it establishes the architectural foundation for a consistent networking model across hybrid and multi-cloud environments. By adopting open, standards-based networking protocols, OpenShift can integrate with enterprise network fabrics regardless of where clusters are deployed.

Longer-term, this architecture will be extended across Red Hat's managed OpenShift offerings, including Red Hat OpenShift Service on AWS, Microsoft Azure Red Hat OpenShift, and Red Hat OpenShift Dedicated. As these capabilities evolve, organizations will be able to apply the same networking architecture, operational practices, and integration model across self-managed and managed OpenShift environments.

For enterprises operating hybrid infrastructure, this provides a path toward consistent network connectivity, policy, and operations across data centers and cloud environments. Rather than managing separate networking models for each deployment target, organizations can build on a common standards-based architecture that scales with their hybrid cloud strategy.

The road ahead

OpenShift Networking continues to evolve with a clear architectural objective: Enable Kubernetes platforms to integrate directly with the enterprise networks organizations already operate. Rather than treating the cluster as a distinct networking domain, OpenShift adopts the same standards-based protocols, control planes, and operational models that underpin modern data center fabrics.

The introduction of EVPN in OpenShift 4.22 represents a significant milestone toward that objective. Together with user-defined networks and BGP, EVPN enables OpenShift to support both Layer 2 and Layer 3 cluster user-defined networks through standards-based MAC-VRF and IP-VRF route advertisement. This allows OpenShift workloads to integrate directly with existing EVPN-VXLAN fabrics while providing consistent Layer 2 and Layer 3 connectivity across enterprise and telecommunications network architectures.

This architecture provides a foundation for organizations modernizing virtualization platforms, extending workloads across hybrid infrastructure, and adopting cloud-native platforms without disrupting established network designs or operational practices. As OpenShift Networking continues to evolve, our focus remains on delivering open, standards-based networking capabilities that allow Kubernetes to integrate naturally into enterprise environments, wherever those environments are deployed.

Product trial

Red Hat OpenShift Container Platform | Product Trial

A consistent hybrid cloud foundation for building and scaling containerized applications.

About the authors

Marc Curry is a Distinguished Product Manager in Red Hat's Hybrid Platform Business Unit, specializing in the networking architecture, performance, and scalability of the OpenShift Container Platform.

With over 20 years at Red Hat, Marc has held various technical roles, including serving as a Solutions Architect focused on open-source solutions for the telecommunications industry. His expertise builds upon a strong foundation in scientific and high-performance computing.

Dave Tucker is a Senior Principal Software Engineer at Red Hat leading networking projects within the Emerging Technologies group in the Office of the CTO. Starting his career in network engineering, Dave shifted to software development with a focus on Software Defined Networking in 2014. His journey through the tech industry is marked by a unique blend of technical marketing and product management expertise, alongside significant engineering roles. A notable milestone in Dave's career was his co-founding of Socketplane, a networking startup that was acquired by Docker in 2015. Currently, Dave is the driving force behind the bpfman project at Red Hat, which focuses on enhancing the security and deployment of eBPF programs on Linux and Kubernetes. Dave is an active Rust programmer and a recognized speaker at industry conferences, where he shares his knowledge and insights into network software development.

UI_Icon-Red_Hat-Close-A-Black-RGB

Keep exploring

Browse by channel

automation icon

Automation

The latest on IT automation for tech, teams, and environments

AI icon

Artificial intelligence

Updates on the platforms that free customers to run AI workloads anywhere

open hybrid cloud icon

Open hybrid cloud

Explore how we build a more flexible future with hybrid cloud

security icon

Security

The latest on how we reduce risks across environments and technologies

edge icon

Edge computing

Updates on the platforms that simplify operations at the edge

Infrastructure icon

Infrastructure

The latest on the world’s leading enterprise Linux platform

application development icon

Applications

Inside our solutions to the toughest application challenges

Virtualization icon

Virtualization

The future of enterprise virtualization for your workloads on-premise or across clouds