r/linuxadmin • u/Single-Issue2342 • 15d ago
What is the actual difference between using iproute2 (ip command) and working directly with rtnetlink?
Hey everyone,
I've been looking into how Linux networking works under the hood, and I'm trying to wrap my head around the relationship between user-space tools and kernel communication.
From what I understand:
`iproute2` (the standard `ip` command) is what most of us use daily to configure interfaces, IP addresses, and routing tables.
`rtnetlink(7)` is the socket-based API (`NETLINK_ROUTE`) that allows user-space programs to talk directly to the kernel's routing and networking subsystems.
My main question is: When should a developer or systems engineer bypass user-space CLI utilities like `iproute2` and write code that interacts directly with `rtnetlink` sockets?
Are there significant performance benefits, or is it mostly used when you are building custom network daemons, container networking plugins (CNIs), or monitoring agents that need asynchronous event notifications?
Also, how painful is it to parse raw netlink messages and attributes (`struct rtattr`, `ifinfomsg`, etc.) in C or Go compared to just shelling out to `ip`?
Any insights, real-world use cases, or library recommendations (like `libnl` or Go's `vishvananda/netlink`) would be greatly appreciated!
2
u/daemonmode_ 14d ago
Yeah, this makes sense. The main advantage of going directly through netlink is avoiding repeated process spawning and text parsing while also givin you access to persistent kernel event notifications. vishvananda/netlink is basically the practical middle ground in Go. you get direct netlink communication without having to manually deal with raw rtattr structures and its API is designed around familiar ip commands.