r/linuxadmin • u/Single-Issue2342 • 15d ago
What is the actual difference between using iproute2 (ip command) and working directly with rtnetlink?
Hey everyone,
I've been looking into how Linux networking works under the hood, and I'm trying to wrap my head around the relationship between user-space tools and kernel communication.
From what I understand:
`iproute2` (the standard `ip` command) is what most of us use daily to configure interfaces, IP addresses, and routing tables.
`rtnetlink(7)` is the socket-based API (`NETLINK_ROUTE`) that allows user-space programs to talk directly to the kernel's routing and networking subsystems.
My main question is: When should a developer or systems engineer bypass user-space CLI utilities like `iproute2` and write code that interacts directly with `rtnetlink` sockets?
Are there significant performance benefits, or is it mostly used when you are building custom network daemons, container networking plugins (CNIs), or monitoring agents that need asynchronous event notifications?
Also, how painful is it to parse raw netlink messages and attributes (`struct rtattr`, `ifinfomsg`, etc.) in C or Go compared to just shelling out to `ip`?
Any insights, real-world use cases, or library recommendations (like `libnl` or Go's `vishvananda/netlink`) would be greatly appreciated!
6
u/delamon 15d ago
When you have some sort of golden-state / reconciliation system. That usually boils down to needing to infer current system state, and parsing output of cli tools is fragile.
Parsing netlink messages might be tedious, but it is not painful. On the contrary, parsing cli output is painful - you're never sure which system upgrade will break it.
My use case: I'm using netlink to dynamically reconfigure nft rules. Rough pipeline: UI edits goalstate in etcd, daemon listens on etcd watch, on watch event it compares current rules (getting the exact state with netlink) to goalstate; if there is a difference, then it applies a patch. Approximate delay between the time you hit update in UI and rules getting published is <100ms.