[Witarea] Re: [v6ops] Re: How to make an elegant IPv4 outage
Franck Martin <[email protected]> Tue, 9 Jun 2026 19:07:12 -0500 (CDT)
| Newsgroups | gmane.ietf.tsv-area,gmane.ietf.general,gmane.ietf.v6ops |
|---|---|
| Message-ID | <[email protected]> |
--===============3557887754708136985== Content-Type: multipart/alternative; boundary="=_0eab963c-d712-4bc0-80ec-15ec02bb36b7" --=_0eab963c-d712-4bc0-80ec-15ec02bb36b7 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable while https://github.com/franckhlmartin/ietf-draft-deploying-ipv6-data-cent= er mentions K8S it would be awesome if some of you could provide some more = information on K8S/Containers via a PR or an issue.=20 Would be super cool.=20 I think your experience is more up to date than mine.=20 Franck=20 From: "Nick Buraglio" <[email protected]>=20 To: "Franck Martin" <[email protected]>=20 Cc: "Xipengxiao" <[email protected]>, "Brian E Carpe= nter" <[email protected]>, "S Moonesamy" <[email protected]>, = "witarea" <[email protected]>, "ietf" <[email protected]>, "v6ops" <[email protected]= rg>=20 Sent: Tuesday, June 9, 2026 3:33:16 AM=20 Subject: Re: [v6ops] Re: How to make an elegant IPv4 outage=20 This is basically the same experience we had. We=E2=80=99re more of less us= ing cilium for all networking.=20 nb=20 On Sun, Jun 7, 2026 at 20:38 Franck Martin < [ mailto:[email protected]= g | [email protected] ] > wrote:=20 I spent some time diving into various K8S deployments. K8S is great, but yo= u really really need to standardize your deployments. And because K8S uses = eBPF, and sometimes some network namespaces and sometimes not, you can no l= onger trust /proc/net to tell you the reality. you need to dive into the na= mespaces too...=20 so K8S NAT is often not stored in the routing or iptable, but in eBPF, and = it is very hard to get that information when you are on the host itself... = At least that was my experience.=20 having K8S with IPv6-only makes life much easier.=20 From: "Nick Buraglio" < [ mailto:[email protected] | buraglio@fo= rwardingplane.net ] >=20 To: "Xipengxiao" <xipengxiao=3D [ mailto:[email protected] | 40hu= [email protected] ] >=20 Cc: "Franck Martin" < [ mailto:[email protected] | franck@peachymango.= org ] >, "Brian E Carpenter" < [ mailto:[email protected] | brian= [email protected] ] >, "S Moonesamy" < [ mailto:sm%[email protected]= | [email protected] ] >, "witarea" < [ mailto:[email protected] | witare= [email protected] ] >, "ietf" < [ mailto:[email protected] | [email protected] ] >, "v6ops= " < [ mailto:[email protected] | [email protected] ] >=20 Sent: Sunday, June 7, 2026 8:32:24 AM=20 Subject: Re: [v6ops] Re: How to make an elegant IPv4 outage=20 +1=20 We have done k8s with IPv6-only in our data centers and once the initial hu= rdles are past, it is significantly easier to work with.=20 Where the complications lie are in the random libraries inside of random co= ntainers, and in some cases in the container repositories.=20 I=E2=80=99m curious to see what your experience is/was, and how it differed= from ours, if at all.=20 nb=20 On Fri, Jun 5, 2026 at 10:21 Xipengxiao <xipengxiao=3D [ mailto:40huawei.co= [email protected] | [email protected] ] > wrote:=20 BQ_BEGIN Hi Franck,=20 You are very welcome to take the lead on "Deploying IPv6 in the Data Center= /Enterprises". We look forward to your drafts.=20 XiPeng=20 -----Original Message-----=20 From: Franck Martin < [ mailto:[email protected] | franck@peachymango.= org ] >=20 Sent: Thursday, June 4, 2026 1:51 AM=20 To: Brian E Carpenter < [ mailto:[email protected] | brian.e.carp= [email protected] ] >=20 Cc: S Moonesamy < [ mailto:sm%[email protected] | [email protected] ] = >; witarea < [ mailto:[email protected] | [email protected] ] >; ietf < [ mai= lto:[email protected] | [email protected] ] >; [ mailto:[email protected] | v6ops@ietf= .org ]=20 Subject: [v6ops] Re: How to make an elegant IPv4 outage=20 Adding v6ops to the list of Cc=20 Brian,=20 Getting myself up to date with the v6ops.=20 I see there is a milestone to adopt by dec 2026 Deploying IPv6 in the Data = Center and Deploying IPv6 in the Enterprise. I have some experience with th= is having done that at LinkedIn and been very close to an IPv6-only deploym= ent. I also was aware of what was happening at the mothership at Microsoft.= =20 I don=E2=80=99t see any lead for this besides the WG chair. I would be happ= y to contribute and may be to reach out to folks. I quickly looked through = the archives but did not see anything obvious on those topics.=20 Franck=20 > On Jun 3, 2026, at 15:34, Brian E Carpenter < [ mailto:brian.e.carpenter@= gmail.com | [email protected] ] > wrote:=20 >=20 > Franck,=20 >=20 > You definitely need to keep [ mailto:[email protected] | [email protected] ] aw= are of this.=20 >=20 > I assume you are aware of [ https://datatracker.ietf.org/doc/draft-palet-= v6ops-ipv6-only/ | https://datatracker.ietf.org/doc/draft-palet-v6ops-ipv6-= only/ ] and other work in v6ops related to IPv6-only and IPv6-mostly.=20 >=20 > Regards/Ng=C4=81 mihi=20 > Brian Carpenter=20 >=20 > On 04-Jun-26 09:29, Franck Martin wrote:=20 >> Moving to Witarea, but keeping ietf in the loop for the moment.=20 >> Hi Surya,=20 >> Many thanks for those great points.=20 >>> On Jun 3, 2026, at 13:00, S Moonesamy < [ mailto:sm%[email protected]= | [email protected] ] > wrote:=20 >>>=20 >>> Hi Franck,=20 >>>=20 >>> [Cc to witarea@]=20 >>>=20 >>> At 11:32 AM 03-06-2026, Franck Martin wrote:=20 >>>> Today I submitted this Internet Draft (I-D) to the IETF=20 >>>> [ https://datatracker.ietf.org/doc/draft-martin-retry-over-ipv6/ | htt= ps://datatracker.ietf.org/doc/draft-martin-retry-over-ipv6/ ]=20 >>>>=20 >>>> I have been building this site: [ http://pacific.ipv6forum.com/ | paci= fic.ipv6forum.com ] and I have been wondering, how could I do an IPv4 outag= e on this site on 6/6?=20 >>>>=20 >>>> I have also seen that Czechoslovakia has mandated the end of IPv4 on g= overnment sites on 6/6/2032, 6 years from now.=20 >>>>=20 >>>> I also recall (from recent experience) that it is relatively easy to r= each >90% of IPv6 connections to an internal network (think datacenter), bu= t the remaining last % are difficult to identify (or discard) because servi= ces may misbehave and prefer IPv4 from time to time: You don't know if they= can't really do IPv4 or if they did not bother to do IPv6.=20 >>>>=20 >>>> In an enterprise environment, micro-services are made redundant, there= are multiple IPs and have fallback mechanisms when they encounter a 5xx er= ror on one endpoint.=20 >>>>=20 >>>> So, I started to work on this Internet Draft. It is ready for the firs= t round of public comments. I suspect, if successful, it will take 1 or 2 y= ears to make it a standard. Then an extra 1 or 2 years, before it is implem= ented on enough clients (and browsers), we will be just in time for doing e= nough IPv4 outages on 6/6 to meet the 6/6/2032 deadline.=20 >>>=20 >>> There is a recent thread about IPv6 at [ https://mailarchive.ietf.org/a= rch/msg/ipv6/BxSOgbF34xbBcijtxf85Pfnb5tc/ | https://mailarchive.ietf.org/ar= ch/msg/ipv6/BxSOgbF34xbBcijtxf85Pfnb5tc/ ] I don't remember seeing anything= resulting from that discussion. Having a draft is, relatively, better than= the usual email discussion. The draft falls under the WIT Area and v6ops (= which is in another IETF Area).=20 >> I quickly read the thread, and also asked for a summary. I agree with ma= ny points like : some mobiles are IPv6-only (T-Mobile, Reliance,=E2=80=A6),= some networks are IPv6-only on the management side (Comcast),.. StarLink i= s moving the needle A LOT in small countries, see countries on [ https://pa= cific.ipv6forum.com/ | https://pacific.ipv6forum.com ] < [ https://pacific.= ipv6forum.com/ | https://pacific.ipv6forum.com ] >.. but yes the frontier i= s Entreprise adoption. I have some experience here that I=E2=80=99m trying = to share.=20 >>>=20 >>> Section 1.1 of the draft states that "Governments are also publishing f= ixed IPv4 end dates" and lists one example [1]. Are there any other governm= ents which have a fixed end date?=20 >> I am not aware of other governments that have published an equally=20 >> specific =E2=80=9CIPv4 service ends on <date>=E2=80=9D policy for their = public=20 >> services. Several others publish IPv6 transition *milestones* rather=20 >> than a fixed IPv4 shutdown date =E2=80=94 for example, US OMB M-21-07 (8= 0% of=20 >> federal IP-enabled assets in IPv6-only environments by FY 2025, with=20 >> strategic intent to phase out IPv4):=20 >> [ https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf | ht= tps://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf ]=20 >> The Netherlands and others have long-standing IPv6 =E2=80=9Cuse-or-expla= in=E2=80=9D or adoption targets, but not, to my knowledge, a single publish= ed IPv4 end date comparable to the Czech case.=20 >> There was also a memo from the State of Washington going in the same=20 >> direction=E2=80=A6 I used to track all those=E2=80=A6 looks like I need = to do that again.=20 >> And I agree that those memos come and go=E2=80=A6 Why? Because it is not= trivial, we (IETF?) ought to make it easier.=20 >>>=20 >>> Section 3 of the draft states that "Many operators plan to remove or di= sable IPv4 while retaining IPv6 service." Are those plans available on the = operators' websites?=20 >> I tend to abuse the word =E2=80=9CMany=E2=80=9D, you caught me! I make a= note to change it to =E2=80=9CSome"=20 >> That being said:=20 >> * Meta is IPv6-only in their data centers:=20 >> [ https://engineering.fb.com/2017/01/17/production-engineering/legacy-s = | https://engineering.fb.com/2017/01/17/production-engineering/legacy-s ]= =20 >> upport-on-ipv6-only-infra/=20 >> < [ https://engineering.fb.com/2017/01/17/production-engineering/legacy-= | https://engineering.fb.com/2017/01/17/production-engineering/legacy- ]= =20 >> support-on-ipv6-only-infra/>=20 >> * Google Cloud has guidance for IPv6-only:=20 >> [ https://cloud.google.com/blog/products/networking/connect-ipv6-only-w = | https://cloud.google.com/blog/products/networking/connect-ipv6-only-w ]= =20 >> orkloads-to-ipv4-with-dns64-and-nat64=20 >> < [ https://cloud.google.com/blog/products/networking/connect-ipv6-only-= | https://cloud.google.com/blog/products/networking/connect-ipv6-only- ]= =20 >> workloads-to-ipv4-with-dns64-and-nat64>=20 >> * All the could providers are moving to support IPv6 (because for=20 >> instance K8S bring undue complexity when you use NAT, also with the=20 >> explosion of AI agents, this will not be sustainable, I=E2=80=99m not wo= rry,=20 >> they can afford to buy large chunks of IPv4 - side note: I spoke=20 >> recently with a banker on why IPv4 is not on the balance sheet of=20 >> companies?)=20 >> * Cisco has an IPv6-only building:=20 >> [ https://blogs.cisco.com/networking/an-ipv6-campus-of-the-future | http= s://blogs.cisco.com/networking/an-ipv6-campus-of-the-future ]=20 >> < [ https://blogs.cisco.com/networking/an-ipv6-campus-of-the-future | ht= tps://blogs.cisco.com/networking/an-ipv6-campus-of-the-future ] >=20 >> * Orange is considering IPv6-only:=20 >> [ https://www.youtube.com/watch?v=3DahlY1vwM8qE | https://www.youtube.co= m/watch?v=3DahlY1vwM8qE ]=20 >> < [ https://www.youtube.com/watch?v=3DahlY1vwM8qE | https://www.youtube.= com/watch?v=3DahlY1vwM8qE ] >=20 >> * Microsoft has IPv6-only deployments (I know that in Azure this is=20 >> way more complicated):=20 >> [ https://labs.ripe.net/author/mirjam/ipv6-only-at-microsoft/ | https://= labs.ripe.net/author/mirjam/ipv6-only-at-microsoft/ ]=20 >> < [ https://labs.ripe.net/author/mirjam/ipv6-only-at-microsoft/ | https:= //labs.ripe.net/author/mirjam/ipv6-only-at-microsoft/ ] >=20 >> * LinkedIn is moving to Dual Stack and IPv6-only in their Datacenters. I= may point you to the links in this post: [ https://www.patreon.com/posts/i= pv6-in-lessons-159595711 | https://www.patreon.com/posts/ipv6-in-lessons-15= 9595711 ] where I share my experience with IPv6.=20 >> On this last point, I want to say my motivation is more on how to make l= ife easier for internal deployments than external deployments. As such I fo= und out that making a software outage is easier than an infrastructure outa= ge, and easier and faster to rollback. =E2=80=9CYou can=E2=80=99t fix what = you don=E2=80=99t measure=E2=80=9D, if you can differentiate an IPv4 outage= from any other outage, then you don=E2=80=99t know what to fix.=20 >> I=E2=80=99m not expecting the web browsers to implement anything fast, b= ut I think we can have =E2=80=9Cfaster=E2=80=9D implementation in open sour= ce software like gRPC and Rest.Li to make life easier in enterprises, there= fore impacting other software in those enterprises, which will lead to make= it easier on the public Internet...=20 >> So thanks for all those valid points, I=E2=80=99ll figure out how to bet= ter answer them in version -01.=20 >> I tried to address the same with email, a while back. See those expired = ID: [ https://datatracker.ietf.org/doc/draft-martin-smtp-ipv6-to-ipv4-fallb= ack/ | https://datatracker.ietf.org/doc/draft-martin-smtp-ipv6-to-ipv4-fall= back/ ] < [ https://datatracker.ietf.org/doc/draft-martin-smtp-ipv6-to-ipv4= -fallback/ | https://datatracker.ietf.org/doc/draft-martin-smtp-ipv6-to-ipv= 4-fallback/ ] >, [ https://datatracker.ietf.org/doc/draft-martin-smtp-targe= t-host-selection-ipv4-ipv6/ | https://datatracker.ietf.org/doc/draft-martin= -smtp-target-host-selection-ipv4-ipv6/ ] < [ https://datatracker.ietf.org/d= oc/draft-martin-smtp-target-host-selection-ipv4-ipv6/ | https://datatracker= .ietf.org/doc/draft-martin-smtp-target-host-selection-ipv4-ipv6/ ] >. I hop= e this ID has a bit more chances.=20 >> Franck=20 >> PS: if any has more references of mandate or wannabe mandates, please le= t me know.=20 >>>=20 >>> Regards,=20 >>> S. Moonesamy=20 >>>=20 >>> 1. The IPv6 adoption rate for a social network in that country is 35.2%= .=20 _______________________________________________=20 v6ops mailing list -- [ mailto:[email protected] | [email protected] ]=20 To unsubscribe send an email to [ mailto:[email protected] | v6ops-leave= @ietf.org ]=20 _______________________________________________=20 v6ops mailing list -- [ mailto:[email protected] | [email protected] ]=20 To unsubscribe send an email to [ mailto:[email protected] | v6ops-leave= @ietf.org ]=20 BQ_END --=_0eab963c-d712-4bc0-80ec-15ec02bb36b7 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><body><div style=3D"font-family: arial,helvetica,sans-serif; font-siz= e: 12pt; color: #000000">while https://github.com/franckhlmartin/ietf-draft= -deploying-ipv6-data-center mentions K8S it would be awesome if some of you= could provide some more information on K8S/Containers via a PR or an issue= .<br><br>Would be super cool.<br><br>I think your experience is more up to = date than mine.<br><br>Franck<br><br><hr id=3D"zwchr" data-marker=3D""><div= data-marker=3D""><b>From: </b>"Nick Buraglio" <buraglio@forwardingplane= .net><br><b>To: </b>"Franck Martin" <[email protected]><br><b= >Cc: </b>"Xipengxiao" <[email protected]>, "Br= ian E Carpenter" <[email protected]>, "S Moonesamy" <sm+= [email protected]>, "witarea" <[email protected]>, "ietf" <ietf@= ietf.org>, "v6ops" <[email protected]><br><b>Sent: </b>Tuesday, June = 9, 2026 3:33:16 AM<br><b>Subject: </b>Re: [v6ops] Re: How to make an elegan= t IPv4 outage<br></div><br><div data-marker=3D""><div dir=3D"auto">This is = basically the same experience we had. We=E2=80=99re more of less using cili= um for all networking. </div><div dir=3D"auto"><br></div><div dir=3D"a= uto">nb</div><div><br><div class=3D"gmail_quote gmail_quote_container"><div= dir=3D"ltr" class=3D"gmail_attr">On Sun, Jun 7, 2026 at 20:38 Franck Marti= n <<a href=3D"mailto:[email protected]" target=3D"_blank" rel=3D"no= follow noopener noreferrer">[email protected]</a>> wrote:<br></div>= <blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-= left:1px solid rgb( 204 , 204 , 204 );padding-left:1ex"><div><div style=3D"= font-family:'arial' , 'helvetica' , sans-serif;font-size:12pt;color:rgb( 0 = , 0 , 0 )"><div style=3D"font-family:'arial' , 'helvetica' , sans-serif">I = spent some time diving into various K8S deployments. K8S is great, but you = really really need to standardize your deployments. And because K8S uses eB= PF, and sometimes some network namespaces and sometimes not, you can no lon= ger trust /proc/net to tell you the reality. you need to dive into the name= spaces too...</div><div style=3D"font-family:'arial' , 'helvetica' , sans-s= erif"><br></div><div style=3D"font-family:'arial' , 'helvetica' , sans-seri= f">so K8S NAT is often not stored in the routing or iptable, but in eBPF, a= nd it is very hard to get that information when you are on the host itself.= .. At least that was my experience.</div><div style=3D"font-family:'arial' = , 'helvetica' , sans-serif"><br></div><div style=3D"font-family:'arial' , '= helvetica' , sans-serif">having K8S with IPv6-only makes life much easier.<= /div><div style=3D"font-family:'arial' , 'helvetica' , sans-serif"><br></di= v><hr id=3D"m_-8132224587898458546zwchr" style=3D"font-family:'arial' , 'he= lvetica' , sans-serif"><div style=3D"font-family:'arial' , 'helvetica' , sa= ns-serif"><b style=3D"font-family:'arial' , 'helvetica' , sans-serif">From:= </b>"Nick Buraglio" <<a href=3D"mailto:[email protected]" st= yle=3D"font-family:'arial' , 'helvetica' , sans-serif" target=3D"_blank" re= l=3D"nofollow noopener noreferrer">[email protected]</a>><br>= <b style=3D"font-family:'arial' , 'helvetica' , sans-serif">To: </b>"Xipeng= xiao" <xipengxiao=3D<a href=3D"mailto:[email protected]" style= =3D"font-family:'arial' , 'helvetica' , sans-serif" target=3D"_blank" rel= =3D"nofollow noopener noreferrer">[email protected]</a>><br><b= style=3D"font-family:'arial' , 'helvetica' , sans-serif">Cc: </b>"Franck M= artin" <<a href=3D"mailto:[email protected]" style=3D"font-family:'= arial' , 'helvetica' , sans-serif" target=3D"_blank" rel=3D"nofollow noopen= er noreferrer">[email protected]</a>>, "Brian E Carpenter" <<a h= ref=3D"mailto:[email protected]" style=3D"font-family:'arial' , '= helvetica' , sans-serif" target=3D"_blank" rel=3D"nofollow noopener norefer= rer">[email protected]</a>>, "S Moonesamy" <<a href=3D"mail= to:sm%[email protected]" style=3D"font-family:'arial' , 'helvetica' , san= s-serif" target=3D"_blank" rel=3D"nofollow noopener noreferrer">sm+ietf@ela= ndsys.com</a>>, "witarea" <<a href=3D"mailto:[email protected]" style= =3D"font-family:'arial' , 'helvetica' , sans-serif" target=3D"_blank" rel= =3D"nofollow noopener noreferrer">[email protected]</a>>, "ietf" <<a h= ref=3D"mailto:[email protected]" style=3D"font-family:'arial' , 'helvetica' , s= ans-serif" target=3D"_blank" rel=3D"nofollow noopener noreferrer">ietf@ietf= .org</a>>, "v6ops" <<a href=3D"mailto:[email protected]" style=3D"font-f= amily:'arial' , 'helvetica' , sans-serif" target=3D"_blank" rel=3D"nofollow= noopener noreferrer">[email protected]</a>><br><b style=3D"font-family:'ar= ial' , 'helvetica' , sans-serif">Sent: </b>Sunday, June 7, 2026 8:32:24 AM<= br><b style=3D"font-family:'arial' , 'helvetica' , sans-serif">Subject: </b= >Re: [v6ops] Re: How to make an elegant IPv4 outage<br></div></div></div><d= iv><div style=3D"font-family:'arial' , 'helvetica' , sans-serif;font-size:1= 2pt;color:rgb( 0 , 0 , 0 )"><div style=3D"font-family:'arial' , 'helvetica'= , sans-serif"><br></div><div style=3D"font-family:'arial' , 'helvetica' , = sans-serif"><div dir=3D"auto" style=3D"font-family:'arial' , 'helvetica' , = sans-serif">+1</div><div dir=3D"auto" style=3D"font-family:'arial' , 'helve= tica' , sans-serif"><br></div><div dir=3D"auto" style=3D"font-family:'arial= ' , 'helvetica' , sans-serif">We have done k8s with IPv6-only in our data c= enters and once the initial hurdles are past, it is significantly easier to= work with. </div><div dir=3D"auto" style=3D"font-family:'arial' , 'he= lvetica' , sans-serif">Where the complications lie are in the random librar= ies inside of random containers, and in some cases in the container reposit= ories. </div><div dir=3D"auto" style=3D"font-family:'arial' , 'helveti= ca' , sans-serif">I=E2=80=99m curious to see what your experience is/was, a= nd how it differed from ours, if at all. </div><div dir=3D"auto" style= =3D"font-family:'arial' , 'helvetica' , sans-serif"><br></div><div dir=3D"a= uto" style=3D"font-family:'arial' , 'helvetica' , sans-serif">nb</div><div = style=3D"font-family:'arial' , 'helvetica' , sans-serif"><br><div class=3D"= gmail_quote" style=3D"font-family:'arial' , 'helvetica' , sans-serif"><div = dir=3D"ltr" class=3D"gmail_attr" style=3D"font-family:'arial' , 'helvetica'= , sans-serif">On Fri, Jun 5, 2026 at 10:21 Xipengxiao <xipengxiao=3D<a = href=3D"mailto:[email protected]" rel=3D"nofollow noopener norefe= rrer nofollow noopener noreferrer" style=3D"font-family:'arial' , 'helvetic= a' , sans-serif" target=3D"_blank">[email protected]</a>> wrot= e:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0= .8ex;border-left:1px solid rgb( 204 , 204 , 204 );padding-left:1ex;font-fam= ily:'arial' , 'helvetica' , sans-serif">Hi Franck,<br> <br> You are very welcome to take the lead on "Deploying IPv6 in the Data Center= /Enterprises". We look forward to your drafts.<br> <br> XiPeng <br> <br> -----Original Message-----<br> From: Franck Martin <<a href=3D"mailto:[email protected]" rel=3D"no= follow noopener noreferrer nofollow noopener noreferrer" style=3D"font-fami= ly:'arial' , 'helvetica' , sans-serif" target=3D"_blank">franck@peachymango= .org</a>> <br> Sent: Thursday, June 4, 2026 1:51 AM<br> To: Brian E Carpenter <<a href=3D"mailto:[email protected]" re= l=3D"nofollow noopener noreferrer nofollow noopener noreferrer" style=3D"fo= nt-family:'arial' , 'helvetica' , sans-serif" target=3D"_blank">brian.e.car= [email protected]</a>><br> Cc: S Moonesamy <<a href=3D"mailto:sm%[email protected]" rel=3D"nofoll= ow noopener noreferrer nofollow noopener noreferrer" style=3D"font-family:'= arial' , 'helvetica' , sans-serif" target=3D"_blank">[email protected]</= a>>; witarea <<a href=3D"mailto:[email protected]" rel=3D"nofollow noo= pener noreferrer nofollow noopener noreferrer" style=3D"font-family:'arial'= , 'helvetica' , sans-serif" target=3D"_blank">[email protected]</a>>; ie= tf <<a href=3D"mailto:[email protected]" rel=3D"nofollow noopener noreferrer= nofollow noopener noreferrer" style=3D"font-family:'arial' , 'helvetica' ,= sans-serif" target=3D"_blank">[email protected]</a>>; <a href=3D"mailto:v6o= [email protected]" rel=3D"nofollow noopener noreferrer nofollow noopener noreferr= er" style=3D"font-family:'arial' , 'helvetica' , sans-serif" target=3D"_bla= nk">[email protected]</a><br> Subject: [v6ops] Re: How to make an elegant IPv4 outage<br> <br> Adding v6ops to the list of Cc<br> <br> Brian,<br> <br> Getting myself up to date with the v6ops.<br> <br> I see there is a milestone to adopt by dec 2026 Deploying IPv6 in the Data = Center and Deploying IPv6 in the Enterprise. I have some experience with th= is having done that at LinkedIn and been very close to an IPv6-only deploym= ent. I also was aware of what was happening at the mothership at Microsoft.= <br> <br> I don=E2=80=99t see any lead for this besides the WG chair. I would be happ= y to contribute and may be to reach out to folks. I quickly looked through = the archives but did not see anything obvious on those topics.<br> <br> Franck<br> <br> > On Jun 3, 2026, at 15:34, Brian E Carpenter <<a href=3D"mailto:bria= [email protected]" rel=3D"nofollow noopener noreferrer nofollow noope= ner noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-serif" ta= rget=3D"_blank">[email protected]</a>> wrote:<br> > <br> > Franck,<br> > <br> > You definitely need to keep <a href=3D"mailto:[email protected]" rel=3D"n= ofollow noopener noreferrer nofollow noopener noreferrer" style=3D"font-fam= ily:'arial' , 'helvetica' , sans-serif" target=3D"_blank">[email protected]</a= > aware of this.<br> > <br> > I assume you are aware of <a href=3D"https://datatracker.ietf.org/doc/= draft-palet-v6ops-ipv6-only/" rel=3D"noreferrer nofollow noopener noreferre= r nofollow noopener noreferrer" style=3D"font-family:'arial' , 'helvetica' = , sans-serif" target=3D"_blank">https://datatracker.ietf.org/doc/draft-pale= t-v6ops-ipv6-only/</a> and other work in v6ops related to IPv6-only and IPv= 6-mostly.<br> > <br> > Regards/Ng=C4=81 mihi<br> > Brian Carpenter<br> > <br> > On 04-Jun-26 09:29, Franck Martin wrote:<br> >> Moving to Witarea, but keeping ietf in the loop for the moment.<br= > >> Hi Surya,<br> >> Many thanks for those great points.<br> >>> On Jun 3, 2026, at 13:00, S Moonesamy <<a href=3D"mailto:sm= %[email protected]" rel=3D"nofollow noopener noreferrer nofollow noopener= noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-serif" targe= t=3D"_blank">[email protected]</a>> wrote:<br> >>> <br> >>> Hi Franck,<br> >>> <br> >>> [Cc to witarea@]<br> >>> <br> >>> At 11:32 AM 03-06-2026, Franck Martin wrote:<br> >>>> Today I submitted this Internet Draft (I-D) to the IETF <b= r> >>>> <a href=3D"https://datatracker.ietf.org/doc/draft-martin-r= etry-over-ipv6/" rel=3D"noreferrer nofollow noopener noreferrer nofollow no= opener noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-serif"= target=3D"_blank">https://datatracker.ietf.org/doc/draft-martin-retry-over= -ipv6/</a><br> >>>> <br> >>>> I have been building this site: <a href=3D"http://pacific.= ipv6forum.com" rel=3D"noreferrer nofollow noopener noreferrer nofollow noop= ener noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-serif" t= arget=3D"_blank">pacific.ipv6forum.com</a> and I have been wondering, how c= ould I do an IPv4 outage on this site on 6/6?<br> >>>> <br> >>>> I have also seen that Czechoslovakia has mandated the end = of IPv4 on government sites on 6/6/2032, 6 years from now.<br> >>>> <br> >>>> I also recall (from recent experience) that it is relative= ly easy to reach >90% of IPv6 connections to an internal network (think = datacenter), but the remaining last % are difficult to identify (or discard= ) because services may misbehave and prefer IPv4 from time to time: You don= 't know if they can't really do IPv4 or if they did not bother to do IPv6.<= br> >>>> <br> >>>> In an enterprise environment, micro-services are made redu= ndant, there are multiple IPs and have fallback mechanisms when they encoun= ter a 5xx error on one endpoint.<br> >>>> <br> >>>> So, I started to work on this Internet Draft. It is ready = for the first round of public comments. I suspect, if successful, it will t= ake 1 or 2 years to make it a standard. Then an extra 1 or 2 years, before = it is implemented on enough clients (and browsers), we will be just in time= for doing enough IPv4 outages on 6/6 to meet the 6/6/2032 deadline.<br> >>> <br> >>> There is a recent thread about IPv6 at <a href=3D"https://mail= archive.ietf.org/arch/msg/ipv6/BxSOgbF34xbBcijtxf85Pfnb5tc/" rel=3D"norefer= rer nofollow noopener noreferrer nofollow noopener noreferrer" style=3D"fon= t-family:'arial' , 'helvetica' , sans-serif" target=3D"_blank">https://mail= archive.ietf.org/arch/msg/ipv6/BxSOgbF34xbBcijtxf85Pfnb5tc/</a> I don't rem= ember seeing anything resulting from that discussion. Having a draft = is, relatively, better than the usual email discussion. The draft fal= ls under the WIT Area and v6ops (which is in another IETF Area).<br> >> I quickly read the thread, and also asked for a summary. I agree w= ith many points like : some mobiles are IPv6-only (T-Mobile, Reliance,=E2= =80=A6), some networks are IPv6-only on the management side (Comcast),.. St= arLink is moving the needle A LOT in small countries, see countries on <a h= ref=3D"https://pacific.ipv6forum.com" rel=3D"noreferrer nofollow noopener n= oreferrer nofollow noopener noreferrer" style=3D"font-family:'arial' , 'hel= vetica' , sans-serif" target=3D"_blank">https://pacific.ipv6forum.com</a> &= lt;<a href=3D"https://pacific.ipv6forum.com" rel=3D"noreferrer nofollow noo= pener noreferrer nofollow noopener noreferrer" style=3D"font-family:'arial'= , 'helvetica' , sans-serif" target=3D"_blank">https://pacific.ipv6forum.co= m</a>>.. but yes the frontier is Entreprise adoption. I have some experi= ence here that I=E2=80=99m trying to share.<br> >>> <br> >>> Section 1.1 of the draft states that "Governments are also pub= lishing fixed IPv4 end dates" and lists one example [1]. Are there an= y other governments which have a fixed end date?<br> >> I am not aware of other governments that have published an equally= <br> >> specific =E2=80=9CIPv4 service ends on <date>=E2=80=9D polic= y for their public <br> >> services. Several others publish IPv6 transition *milestones* rath= er <br> >> than a fixed IPv4 shutdown date =E2=80=94 for example, US OMB M-21= -07 (80% of <br> >> federal IP-enabled assets in IPv6-only environments by FY 2025, wi= th <br> >> strategic intent to phase out IPv4): <br> >> <a href=3D"https://www.whitehouse.gov/wp-content/uploads/2020/11/M= -21-07.pdf" rel=3D"noreferrer nofollow noopener noreferrer nofollow noopene= r noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-serif" targ= et=3D"_blank">https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07= .pdf</a><br> >> The Netherlands and others have long-standing IPv6 =E2=80=9Cuse-or= -explain=E2=80=9D or adoption targets, but not, to my knowledge, a single p= ublished IPv4 end date comparable to the Czech case.<br> >> There was also a memo from the State of Washington going in the sa= me <br> >> direction=E2=80=A6 I used to track all those=E2=80=A6 looks like I= need to do that again.<br> >> And I agree that those memos come and go=E2=80=A6 Why? Because it = is not trivial, we (IETF?) ought to make it easier.<br> >>> <br> >>> Section 3 of the draft states that "Many operators plan to rem= ove or disable IPv4 while retaining IPv6 service." Are those plans av= ailable on the operators' websites?<br> >> I tend to abuse the word =E2=80=9CMany=E2=80=9D, you caught me! I = make a note to change it to =E2=80=9CSome"<br> >> That being said:<br> >> * Meta is IPv6-only in their data centers: <br> >> <a href=3D"https://engineering.fb.com/2017/01/17/production-engine= ering/legacy-s" rel=3D"noreferrer nofollow noopener noreferrer nofollow noo= pener noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-serif" = target=3D"_blank">https://engineering.fb.com/2017/01/17/production-engineer= ing/legacy-s</a><br> >> upport-on-ipv6-only-infra/ <br> >> <<a href=3D"https://engineering.fb.com/2017/01/17/production-en= gineering/legacy-" rel=3D"noreferrer nofollow noopener noreferrer nofollow = noopener noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-seri= f" target=3D"_blank">https://engineering.fb.com/2017/01/17/production-engin= eering/legacy-</a><br> >> support-on-ipv6-only-infra/><br> >> * Google Cloud has guidance for IPv6-only: <br> >> <a href=3D"https://cloud.google.com/blog/products/networking/conne= ct-ipv6-only-w" rel=3D"noreferrer nofollow noopener noreferrer nofollow noo= pener noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-serif" = target=3D"_blank">https://cloud.google.com/blog/products/networking/connect= -ipv6-only-w</a><br> >> orkloads-to-ipv4-with-dns64-and-nat64 <br> >> <<a href=3D"https://cloud.google.com/blog/products/networking/c= onnect-ipv6-only-" rel=3D"noreferrer nofollow noopener noreferrer nofollow = noopener noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-seri= f" target=3D"_blank">https://cloud.google.com/blog/products/networking/conn= ect-ipv6-only-</a><br> >> workloads-to-ipv4-with-dns64-and-nat64><br> >> * All the could providers are moving to support IPv6 (becaus= e for <br> >> instance K8S bring undue complexity when you use NAT, also with th= e <br> >> explosion of AI agents, this will not be sustainable, I=E2=80=99m = not worry, <br> >> they can afford to buy large chunks of IPv4 - side note: I spoke <= br> >> recently with a banker on why IPv4 is not on the balance sheet of = <br> >> companies?)<br> >> * Cisco has an IPv6-only building: <br> >> <a href=3D"https://blogs.cisco.com/networking/an-ipv6-campus-of-th= e-future" rel=3D"noreferrer nofollow noopener noreferrer nofollow noopener = noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-serif" target= =3D"_blank">https://blogs.cisco.com/networking/an-ipv6-campus-of-the-future= </a> <br> >> <<a href=3D"https://blogs.cisco.com/networking/an-ipv6-campus-o= f-the-future" rel=3D"noreferrer nofollow noopener noreferrer nofollow noope= ner noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-serif" ta= rget=3D"_blank">https://blogs.cisco.com/networking/an-ipv6-campus-of-the-fu= ture</a>><br> >> * Orange is considering IPv6-only: <br> >> <a href=3D"https://www.youtube.com/watch?v=3DahlY1vwM8qE" rel=3D"n= oreferrer nofollow noopener noreferrer nofollow noopener noreferrer" style= =3D"font-family:'arial' , 'helvetica' , sans-serif" target=3D"_blank">https= ://www.youtube.com/watch?v=3DahlY1vwM8qE</a> <br> >> <<a href=3D"https://www.youtube.com/watch?v=3DahlY1vwM8qE" rel= =3D"noreferrer nofollow noopener noreferrer nofollow noopener noreferrer" s= tyle=3D"font-family:'arial' , 'helvetica' , sans-serif" target=3D"_blank">h= ttps://www.youtube.com/watch?v=3DahlY1vwM8qE</a>><br> >> * Microsoft has IPv6-only deployments (I know that in Azure = this is <br> >> way more complicated): <br> >> <a href=3D"https://labs.ripe.net/author/mirjam/ipv6-only-at-micros= oft/" rel=3D"noreferrer nofollow noopener noreferrer nofollow noopener nore= ferrer" style=3D"font-family:'arial' , 'helvetica' , sans-serif" target=3D"= _blank">https://labs.ripe.net/author/mirjam/ipv6-only-at-microsoft/</a> <br= > >> <<a href=3D"https://labs.ripe.net/author/mirjam/ipv6-only-at-mi= crosoft/" rel=3D"noreferrer nofollow noopener noreferrer nofollow noopener = noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-serif" target= =3D"_blank">https://labs.ripe.net/author/mirjam/ipv6-only-at-microsoft/</a>= ><br> >> * LinkedIn is moving to Dual Stack and IPv6-only in their Da= tacenters. I may point you to the links in this post: <a href=3D"https://ww= w.patreon.com/posts/ipv6-in-lessons-159595711" rel=3D"noreferrer nofollow n= oopener noreferrer nofollow noopener noreferrer" style=3D"font-family:'aria= l' , 'helvetica' , sans-serif" target=3D"_blank">https://www.patreon.com/po= sts/ipv6-in-lessons-159595711</a> where I share my experience with IPv6.<br= > >> On this last point, I want to say my motivation is more on how to = make life easier for internal deployments than external deployments. As suc= h I found out that making a software outage is easier than an infrastructur= e outage, and easier and faster to rollback. =E2=80=9CYou can=E2=80=99t fix= what you don=E2=80=99t measure=E2=80=9D, if you can differentiate an IPv4 = outage from any other outage, then you don=E2=80=99t know what to fix.<br> >> I=E2=80=99m not expecting the web browsers to implement anything f= ast, but I think we can have =E2=80=9Cfaster=E2=80=9D implementation in ope= n source software like gRPC and Rest.Li to make life easier in enterprises,= therefore impacting other software in those enterprises, which will lead t= o make it easier on the public Internet...<br> >> So thanks for all those valid points, I=E2=80=99ll figure out how = to better answer them in version -01.<br> >> I tried to address the same with email, a while back. See those ex= pired ID: <a href=3D"https://datatracker.ietf.org/doc/draft-martin-smtp-ipv= 6-to-ipv4-fallback/" rel=3D"noreferrer nofollow noopener noreferrer nofollo= w noopener noreferrer" style=3D"font-family:'arial' , 'helvetica' , sans-se= rif" target=3D"_blank">https://datatracker.ietf.org/doc/draft-martin-smtp-i= pv6-to-ipv4-fallback/</a> <<a href=3D"https://datatracker.ietf.org/doc/d= raft-martin-smtp-ipv6-to-ipv4-fallback/" rel=3D"noreferrer nofollow noopene= r noreferrer nofollow noopener noreferrer" style=3D"font-family:'arial' , '= helvetica' , sans-serif" target=3D"_blank">https://datatracker.ietf.org/doc= /draft-martin-smtp-ipv6-to-ipv4-fallback/</a>>, <a href=3D"https://datat= racker.ietf.org/doc/draft-martin-smtp-target-host-selection-ipv4-ipv6/" rel= =3D"noreferrer nofollow noopener noreferrer nofollow noopener noreferrer" s= tyle=3D"font-family:'arial' , 'helvetica' , sans-serif" target=3D"_blank">h= ttps://datatracker.ietf.org/doc/draft-martin-smtp-target-host-selection-ipv= 4-ipv6/</a> <<a href=3D"https://datatracker.ietf.org/doc/draft-martin-sm= tp-target-host-selection-ipv4-ipv6/" rel=3D"noreferrer nofollow noopener no= referrer nofollow noopener noreferrer" style=3D"font-family:'arial' , 'helv= etica' , sans-serif" target=3D"_blank">https://datatracker.ietf.org/doc/dra= ft-martin-smtp-target-host-selection-ipv4-ipv6/</a>>. I hope this ID has= a bit more chances.<br> >> Franck<br> >> PS: if any has more references of mandate or wannabe mandates, ple= ase let me know.<br> >>> <br> >>> Regards,<br> >>> S. Moonesamy<br> >>> <br> >>> 1. The IPv6 adoption rate for a social network in that country= is 35.2%.<br> <br> _______________________________________________<br> v6ops mailing list -- <a href=3D"mailto:[email protected]" rel=3D"nofollow noo= pener noreferrer nofollow noopener noreferrer" style=3D"font-family:'arial'= , 'helvetica' , sans-serif" target=3D"_blank">[email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" rel= =3D"nofollow noopener noreferrer nofollow noopener noreferrer" style=3D"fon= t-family:'arial' , 'helvetica' , sans-serif" target=3D"_blank">v6ops-leave@= ietf.org</a><br> _______________________________________________<br> v6ops mailing list -- <a href=3D"mailto:[email protected]" rel=3D"nofollow noo= pener noreferrer nofollow noopener noreferrer" style=3D"font-family:'arial'= , 'helvetica' , sans-serif" target=3D"_blank">[email protected]</a><br> To unsubscribe send an email to <a href=3D"mailto:[email protected]" rel= =3D"nofollow noopener noreferrer nofollow noopener noreferrer" style=3D"fon= t-family:'arial' , 'helvetica' , sans-serif" target=3D"_blank">v6ops-leave@= ietf.org</a><br> </blockquote></div></div></div></div></div></blockquote></div></div><br></d= iv></div></body></html> --=_0eab963c-d712-4bc0-80ec-15ec02bb36b7-- --===============3557887754708136985== Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Content-Disposition: inline LS0gCldpdGFyZWEgbWFpbGluZyBsaXN0IC0tIHdpdGFyZWFAaWV0Zi5vcmcKVG8gdW5zdWJzY3Jp YmUgc2VuZCBhbiBlbWFpbCB0byB3aXRhcmVhLWxlYXZlQGlldGYub3JnCg== --===============3557887754708136985==--