]>
git.proxmox.com Git - pve-manager.git/blob - PVE/NodeConfig.pm
1 package PVE
::NodeConfig
;
7 use PVE
::JSONSchema
qw(get_standard_option);
8 use PVE
::Tools
qw(file_get_contents file_set_contents lock_file);
11 use PVE
::API2
::ACMEPlugin
;
13 # register up to 5 domain names per node for now
16 my $node_config_lock = '/var/lock/pvenode.lock';
18 PVE
::JSONSchema
::register_format
('pve-acme-domain', sub {
19 my ($domain, $noerr) = @_;
21 my $label = qr/[a-z0-9][a-z0-9_-]*/i;
23 return $domain if $domain =~ /^$label(?:\.$label)+$/;
24 return undef if $noerr;
25 die "value '$domain' does not look like a valid domain name!\n";
31 return "/etc/pve/nodes/${node}/config";
37 my $filename = config_file
($node);
38 my $raw = eval { PVE
::Tools
::file_get_contents
($filename); };
41 return parse_node_config
($raw);
45 my ($node, $conf) = @_;
47 my $filename = config_file
($node);
49 my $raw = write_node_config
($conf);
51 PVE
::Tools
::file_set_contents
($filename, $raw);
55 my ($node, $realcode, @param) = @_;
57 # make sure configuration file is up-to-date
59 PVE
::Cluster
::cfs_update
();
63 my $res = lock_file
($node_config_lock, 10, $code, @param);
73 description
=> 'Node description/comment.',
78 description
=> 'MAC address for wake on LAN',
82 'startall-onboot-delay' => {
83 description
=> 'Initial delay in seconds, before starting all the Virtual Guests with on-boot enabled.',
92 my $acme_domain_desc = {
95 format
=> 'pve-acme-domain',
96 format_description
=> 'domain',
97 description
=> 'domain for this node\'s ACME certificate',
102 format
=> 'pve-configid',
103 description
=> 'The ACME plugin ID',
104 format_description
=> 'name of the plugin configuration',
106 default => 'standalone',
110 format
=> 'pve-acme-domain',
111 format_description
=> 'domain',
112 description
=> 'Alias for the Domain to verify ACME Challenge over DNS',
118 account
=> get_standard_option
('pve-acme-account-name'),
121 format
=> 'pve-acme-domain-list',
122 format_description
=> 'domain[;domain;...]',
123 description
=> 'List of domains for this node\'s ACME certificate',
128 $confdesc->{acme
} = {
130 description
=> 'Node specific ACME settings.',
135 for my $i (0..$MAXDOMAINS) {
136 $confdesc->{"acmedomain$i"} = {
138 description
=> 'ACME domain and validation plugin',
139 format
=> $acme_domain_desc,
145 my ($key, $value) = @_;
147 die "unknown setting '$key'\n" if !$confdesc->{$key};
149 my $type = $confdesc->{$key}->{type
};
151 if (!defined($value)) {
152 die "got undefined value\n";
155 if ($value =~ m/[\n\r]/) {
156 die "property contains a line feed\n";
159 if ($type eq 'boolean') {
160 return 1 if ($value eq '1') || ($value =~ m/^(on|yes|true)$/i);
161 return 0 if ($value eq '0') || ($value =~ m/^(off|no|false)$/i);
162 die "type check ('boolean') failed - got '$value'\n";
163 } elsif ($type eq 'integer') {
164 return int($1) if $value =~ m/^(\d+)$/;
165 die "type check ('integer') failed - got '$value'\n";
166 } elsif ($type eq 'number') {
167 return $value if $value =~ m/^(\d+)(\.\d+)?$/;
168 die "type check ('number') failed - got '$value'\n";
169 } elsif ($type eq 'string') {
170 if (my $fmt = $confdesc->{$key}->{format
}) {
171 PVE
::JSONSchema
::check_format
($fmt, $value);
173 } elsif (my $pattern = $confdesc->{$key}->{pattern
}) {
174 if ($value !~ m/^$pattern$/) {
175 die "value does not match the regex pattern\n";
184 sub parse_node_config
{
187 return undef if !defined($content);
190 digest
=> Digest
::SHA
::sha1_hex
($content),
194 my @lines = split(/\n/, $content);
195 foreach my $line (@lines) {
196 if ($line =~ /^\#(.*)\s*$/ || $line =~ /^description:\s*(.*\S)\s*$/) {
197 $descr .= PVE
::Tools
::decode_text
($1) . "\n";
200 if ($line =~ /^([a-z][a-z-_]*\d*):\s*(\S.*)\s*$/) {
203 $value = eval { check_type
($key, $value) };
204 die "cannot parse value of '$key' in node config: $@" if $@;
205 $conf->{$key} = $value;
207 warn "cannot parse line '$line' in node config\n";
211 $conf->{description
} = $descr if $descr;
216 sub write_node_config
{
220 # add description as comment to top of file
221 my $descr = $conf->{description
} || '';
222 foreach my $cl (split(/\n/, $descr)) {
223 $raw .= '#' . PVE
::Tools
::encode_text
($cl) . "\n";
226 for my $key (sort keys %$conf) {
227 next if ($key eq 'description');
228 next if ($key eq 'digest');
230 my $value = $conf->{$key};
231 die "detected invalid newline inside property '$key'\n"
233 $raw .= "$key: $value\n";
239 # we always convert domain values to lower case, since DNS entries are not case
240 # sensitive and ACME implementations might convert the ordered identifiers
243 my ($node_conf, $noerr) = @_;
248 if (defined($node_conf->{acme
})) {
250 PVE
::JSONSchema
::parse_property_string
($acmedesc, $node_conf->{acme
})
253 return undef if $noerr;
256 my $standalone_domains = delete($res->{domains
}) // '';
257 $res->{domains
} = {};
258 for my $domain (split(";", $standalone_domains)) {
259 $domain = lc($domain);
260 die "duplicate domain '$domain' in ACME config properties\n"
261 if defined($res->{domains
}->{$domain});
263 $res->{domains
}->{$domain}->{plugin
} = 'standalone';
264 $res->{domains
}->{$domain}->{_configkey
} = 'acme';
268 $res->{account
} //= 'default';
270 for my $index (0..$MAXDOMAINS) {
271 my $domain_rec = $node_conf->{"acmedomain$index"};
272 next if !defined($domain_rec);
275 PVE
::JSONSchema
::parse_property_string
($acme_domain_desc, $domain_rec)
278 return undef if $noerr;
281 my $domain = lc(delete $parsed->{domain
});
282 if (my $exists = $res->{domains
}->{$domain}) {
283 return undef if $noerr;
284 die "duplicate domain '$domain' in ACME config properties"
285 ." 'acmedomain$index' and '$exists->{_configkey}'\n";
287 $parsed->{plugin
} //= 'standalone';
289 my $plugin_id = $parsed->{plugin
};
290 if ($plugin_id ne 'standalone') {
291 my $plugins = PVE
::API2
::ACMEPlugin
::load_config
();
292 die "plugin '$plugin_id' for domain '$domain' not found!\n"
293 if !$plugins->{ids
}->{$plugin_id};
296 $parsed->{_configkey
} = "acmedomain$index";
297 $res->{domains
}->{$domain} = $parsed;
303 # expects that basic format verification was already done, this is more higher
306 my ($node_conf) = @_;
308 # verify ACME domain uniqueness
309 my $tmp = get_acme_conf
($node_conf);
316 sub get_nodeconfig_schema
{