Quick Start
This walkthrough takes an installed, activated node and gets a workload onto a managed network with an enforced identity, a firewall policy, and a load-balanced address — end to end.
If you have not installed the agent yet, start with Installation.
1. Define a network
A network is a managed private network: an IP CIDR whose usable host addresses are each materialized into an endpoint profile (an IP paired with a generated MAC). Create one with the CLI:
sudo cenvero-str-ctl network create \
--name app-net \
--cidr 10.20.0.0/24 \
--gateway 10.20.0.1
Stratum records the segment on the workload bridge, creates an address pool for it, reserves the gateway address, and prepares one endpoint for every usable address. It does not set up DHCP or DNS for the network, and it does not put the gateway address on the host — each of those is a separate step, covered in Networking Overview.
List what you have:
cenvero-str-ctl network list
{
"data": {
"networks": [
{
"id": "net-069088314b4e4712",
"name": "app-net",
"cidr": "10.20.0.0/24",
"gateway": "10.20.0.1",
"vlan": 0,
"tenant_id": "",
"created_at": "2026-07-24T20:53:31Z"
}
]
},
"status": "ok"
}
Note the generated id — the other network commands refer to a network by
that id, not by its name.
2. Attach a workload to an endpoint
Claim a free endpoint for your workload. Stratum returns the endpoint's IP and a MAC derived from it, and registers the IP↔MAC pairing in the packet path, so traffic from that endpoint is accepted only with exactly that pair:
sudo cenvero-str-ctl network attach net-069088314b4e4712 --ip 10.20.0.50
Put the workload on the workload bridge (cnv-user-br0) with the returned MAC,
and configure the endpoint's IP inside it as a static address — here
10.20.0.50/24 with gateway 10.20.0.1. Workloads on the same network reach
each other straight away. For the workload to reach anything beyond the network,
the gateway address must be on the host (see Host addressing in the
API Reference) and outbound traffic needs a masquerade rule (see
Gateway NAT).
Every usable address in the network has an endpoint; the one you claimed now
reads bound (the listing below is trimmed to it):
cenvero-str-ctl network endpoints net-069088314b4e4712
{
"data": {
"endpoints": [
{
"id": "ep-5d0c8e1a7b3f2946",
"network_id": "net-069088314b4e4712",
"ip": "10.20.0.50",
"mac": "02:ce:0a:14:00:32",
"state": "bound",
"bound_at": "2026-07-24T20:54:02Z"
}
]
},
"status": "ok"
}
3. Add a firewall policy
Each firewall rule is a single JSON object. Allow inbound HTTP and HTTPS to the endpoint, and let it reach out. Ports are matched one at a time, so HTTP and HTTPS are two rules:
sudo cenvero-str-ctl firewall allow '{"dest_ip":"10.20.0.50","protocol":"tcp","dest_port":443}'
sudo cenvero-str-ctl firewall allow '{"dest_ip":"10.20.0.50","protocol":"tcp","dest_port":80}'
sudo cenvero-str-ctl firewall allow '{"source_ip":"10.20.0.50"}'
Every rule is stateful: once a connection is allowed, its return traffic is
admitted automatically. These rules only matter once nothing else is allowed —
set the default action to deny with sudo cenvero-str-ctl firewall default set deny
after you have allowed what you need, including your own access to the node. See
Firewall for the full policy model and every rule
field.
4. Define a load-balanced VIP
Declare an L4 virtual IP, then attach a backend to it so you can scale horizontally later:
sudo cenvero-str-ctl lb create '{"id":"web-lb","frontend_ip":"10.20.0.10","frontend_port":80,"protocol":"tcp","algorithm":"least-conn"}'
sudo cenvero-str-ctl lb add-backend '{"vip_id":"web-lb","id":"web-1","ip":"10.20.0.50","port":80,"weight":1}'
Add and remove backends live with lb add-backend / lb remove-backend. See
Load Balancer.
5. Confirm
cenvero-str-ctl status
You now have a workload on a managed network with an enforced identity, a firewall policy, and a load-balancer VIP defined — all from one agent. Name resolution and DHCP are set up separately — see DHCP & DNS.
Where to go next
- Configuration — the node configuration model in depth.
- Networking Overview — addressing, DHCP scopes, and stretching a network across hosts.
- CLI Reference — every command in one place.