New and Updated Features

This section describes the new features in the Juniper Cloud-Native Router 26.2 release.

New Features in Juniper Cloud-Native Router Release 26.2

  • Support for multiple cSRX instances on a single Cloud-Native Router—Cloud-Native Router supports deploying multiple cSRX instances service-chained with a single Cloud-Native Router node. This enables large-scale 5G gateway deployments that require more IPSec tunnel capacity than a single cSRX instance can provide. Each cSRX instance is deployed in a separate Kubernetes namespace with dedicated VRFs, ensuring complete traffic isolation between instances. IPSec tunnel configuration for each instance can be applied at installation time via the Helm chart or post-deployment via configlets.

  • CoS telemetry for vRouter—Cloud-Native Router exposes aggregated CoS statistics for the scheduler, shaper, dropper, policer, BA classifier, MF classifier, and rewrite modules through Prometheus and gNMI. Prometheus metrics are available at port 8070 and gNMI subscriptions are available at port 50053. The qosdpdk utility provides per-forwarding-lcore statistics directly from the vRouter DPDK datapath for granular troubleshooting.

  • 2MB hugepage support for low memory deployments—Cloud-Native Router supports 2MB hugepages as an alternative to the default 1G hugepages, reducing the minimum memory footprint for the vRouter DPDK dataplane from 6 Gi to 3 Gi. Configure the hugepage size using the hugepage_sz parameter in values.yaml. When set to "2MB", Cloud-Native Router automatically sets the Kubernetes resource type to hugepages-2Mi, the resource limit to 3 Gi, and the socket memory to 512 MB per NUMA socket. Use the dpdkinfo -m debug command to verify the hugepage size in use after deployment.
  • Configurable ports for vRouter agent and DPDK health check—Cloud-Native Router supports overriding the default vRouter agent REST server port (9091) and vRouter DPDK health check port (9092) using the agentRestServerPort and dpdkHealthCheckPort parameters in values.yaml. This addresses deployments where these ports are already in use by other services on the host. The recommended range for both parameters is 9091 through 9100.
  • Pod annotation-based core dump handling on Wind River Cloud Platform (WRCP)—On WRCP deployments, Cloud-Native Router no longer modifies the host kernel.core_pattern when corePattern is set in values.yaml. Instead, Cloud-Native Router automatically applies the starlingx.io/core_pattern annotation to all Cloud-Native Router pods, constructed from the coreFilePath and corePattern values. The WRCP k8s-coredump handler reads this annotation and routes core dumps for each pod accordingly, preserving the platform's default core dump handler configuration. On all other platforms, the existing behavior is unchanged.
  • NAD-based SR-IOV interface support for Red Hat OpenShift Container Platform (RHOCP)—Cloud-Native Router supports Network Attachment Definition (NAD) based SR-IOV interface configuration on RHOCP, extending the NAD-based interface approach already available for WRCP deployments. Set interfaceBoundType to 1 and configure networkDetails and networkResources in values.yaml to bind SR-IOV VFs to Cloud-Native Router using NADs. The networkResources section uses the openshift.io/<resource-name> prefix for RHOCP deployments, which differs from the intel.com/<resource-name> prefix used for Wind River deployments.
  • Google Virtual NIC (gVNIC) support for Google Cloud Platform (GCP) deployments—Cloud-Native Router supports gVNIC as a high-performance NIC option on GCP. gVNIC uses the DPDK net_gve driver and has the VFIO driver built into the GCP kernel, eliminating the need to load vfio or vfio-pci modules manually. The recommended MTU for gVNIC deployments is 8400, with a maximum supported MTU of 8896. The recommended RX/TX descriptor size is 2048; if not set, Cloud-Native Router automatically adjusts to the gVNIC minimum of 512 descriptors.
  • Enhanced L2 Access Control Lists (ACL) with full action support—Cloud-Native Router extends bridge family firewall filter support to align with L3 and L4 ACL capabilities. In addition to the previously supported discard action, bridge family firewall filters now support accept and routing-instance as terminating actions, and count, log, and syslog as nonterminating actions. The routing-instance action is also reclassified from nonterminating to terminating for inet, inet6, and mpls families. The show firewall output format for bridge family is updated to display the filter name, named counter, and packet and byte counts, aligned with the L3 ACL output format. The acl vRouter utility now requires --family bridge to be explicitly specified for bridge family filters.
  • Azure MANA NIC support using the DPDK mana poll mode driver—Cloud-Native Router supports Microsoft Azure Network Adapter (MANA) NIC on Azure deployments using the DPDK mana poll mode driver. Azure defaults to MANA NIC for virtual machines with accelerated networking enabled.
  • Support for WRCP 26.03—Cloud-Native Router 26.2 supports WRCP version 26.03. Use the system show command on the WRCP controller to verify the installed platform version.

  • Ping support from cRPD pod—Cloud-Native Router supports the ping operational command from the cRPD CLI to debug and verify network connectivity. The ping command supports standard options including packet size, count, IPv4 and IPv6, interface, and routing instance. For more information, see the cRPD Deployment Guide.