]>
git.proxmox.com Git - pve-manager.git/blob - PVE/NodeConfig.pm
1 package PVE
::NodeConfig
;
7 use PVE
::JSONSchema
qw(get_standard_option);
8 use PVE
::Tools
qw(file_get_contents file_set_contents lock_file);
11 use PVE
::API2
::ACMEPlugin
;
13 # register up to 5 domain names per node for now
16 my $node_config_lock = '/var/lock/pvenode.lock';
18 PVE
::JSONSchema
::register_format
('pve-acme-domain', sub {
19 my ($domain, $noerr) = @_;
21 my $label = qr/[a-z0-9][a-z0-9_-]*/i;
23 return $domain if $domain =~ /^$label(?:\.$label)+$/;
24 return undef if $noerr;
25 die "value '$domain' does not look like a valid domain name!\n";
28 PVE
::JSONSchema
::register_format
('pve-acme-alias', sub {
29 my ($alias, $noerr) = @_;
31 my $label = qr/[a-z0-9_][a-z0-9_-]*/i;
33 return $alias if $alias =~ /^$label(?:\.$label)+$/;
34 return undef if $noerr;
35 die "value '$alias' does not look like a valid alias name!\n";
41 return "/etc/pve/nodes/${node}/config";
47 my $filename = config_file
($node);
48 my $raw = eval { PVE
::Tools
::file_get_contents
($filename); };
51 return parse_node_config
($raw);
55 my ($node, $conf) = @_;
57 my $filename = config_file
($node);
59 my $raw = write_node_config
($conf);
61 PVE
::Tools
::file_set_contents
($filename, $raw);
65 my ($node, $realcode, @param) = @_;
67 # make sure configuration file is up-to-date
69 PVE
::Cluster
::cfs_update
();
73 my $res = lock_file
($node_config_lock, 10, $code, @param);
83 description
=> "Description for the Node. Shown in the web-interface node notes panel."
84 ." This is saved as comment inside the configuration file.",
85 maxLength
=> 64 * 1024,
90 description
=> 'MAC address for wake on LAN',
94 'startall-onboot-delay' => {
95 description
=> 'Initial delay in seconds, before starting all the Virtual Guests with on-boot enabled.',
104 my $acme_domain_desc = {
107 format
=> 'pve-acme-domain',
108 format_description
=> 'domain',
109 description
=> 'domain for this node\'s ACME certificate',
114 format
=> 'pve-configid',
115 description
=> 'The ACME plugin ID',
116 format_description
=> 'name of the plugin configuration',
118 default => 'standalone',
122 format
=> 'pve-acme-alias',
123 format_description
=> 'domain',
124 description
=> 'Alias for the Domain to verify ACME Challenge over DNS',
130 account
=> get_standard_option
('pve-acme-account-name'),
133 format
=> 'pve-acme-domain-list',
134 format_description
=> 'domain[;domain;...]',
135 description
=> 'List of domains for this node\'s ACME certificate',
140 $confdesc->{acme
} = {
142 description
=> 'Node specific ACME settings.',
147 for my $i (0..$MAXDOMAINS) {
148 $confdesc->{"acmedomain$i"} = {
150 description
=> 'ACME domain and validation plugin',
151 format
=> $acme_domain_desc,
157 my ($key, $value) = @_;
159 die "unknown setting '$key'\n" if !$confdesc->{$key};
161 my $type = $confdesc->{$key}->{type
};
163 if (!defined($value)) {
164 die "got undefined value\n";
167 if ($value =~ m/[\n\r]/) {
168 die "property contains a line feed\n";
171 if ($type eq 'boolean') {
172 return 1 if ($value eq '1') || ($value =~ m/^(on|yes|true)$/i);
173 return 0 if ($value eq '0') || ($value =~ m/^(off|no|false)$/i);
174 die "type check ('boolean') failed - got '$value'\n";
175 } elsif ($type eq 'integer') {
176 return int($1) if $value =~ m/^(\d+)$/;
177 die "type check ('integer') failed - got '$value'\n";
178 } elsif ($type eq 'number') {
179 return $value if $value =~ m/^(\d+)(\.\d+)?$/;
180 die "type check ('number') failed - got '$value'\n";
181 } elsif ($type eq 'string') {
182 if (my $fmt = $confdesc->{$key}->{format
}) {
183 PVE
::JSONSchema
::check_format
($fmt, $value);
185 } elsif (my $pattern = $confdesc->{$key}->{pattern
}) {
186 if ($value !~ m/^$pattern$/) {
187 die "value does not match the regex pattern\n";
196 sub parse_node_config
{
199 return undef if !defined($content);
202 digest
=> Digest
::SHA
::sha1_hex
($content),
206 my @lines = split(/\n/, $content);
207 foreach my $line (@lines) {
208 if ($line =~ /^\#(.*)\s*$/ || $line =~ /^description:\s*(.*\S)\s*$/) {
209 $descr .= PVE
::Tools
::decode_text
($1) . "\n";
212 if ($line =~ /^([a-z][a-z-_]*\d*):\s*(\S.*)\s*$/) {
215 $value = eval { check_type
($key, $value) };
216 die "cannot parse value of '$key' in node config: $@" if $@;
217 $conf->{$key} = $value;
219 warn "cannot parse line '$line' in node config\n";
223 $conf->{description
} = $descr if $descr;
228 sub write_node_config
{
232 # add description as comment to top of file
233 my $descr = $conf->{description
} || '';
234 foreach my $cl (split(/\n/, $descr)) {
235 $raw .= '#' . PVE
::Tools
::encode_text
($cl) . "\n";
238 for my $key (sort keys %$conf) {
239 next if ($key eq 'description');
240 next if ($key eq 'digest');
242 my $value = $conf->{$key};
243 die "detected invalid newline inside property '$key'\n"
245 $raw .= "$key: $value\n";
251 # we always convert domain values to lower case, since DNS entries are not case
252 # sensitive and ACME implementations might convert the ordered identifiers
255 my ($node_conf, $noerr) = @_;
260 if (defined($node_conf->{acme
})) {
262 PVE
::JSONSchema
::parse_property_string
($acmedesc, $node_conf->{acme
})
265 return undef if $noerr;
268 my $standalone_domains = delete($res->{domains
}) // '';
269 $res->{domains
} = {};
270 for my $domain (split(";", $standalone_domains)) {
271 $domain = lc($domain);
272 die "duplicate domain '$domain' in ACME config properties\n"
273 if defined($res->{domains
}->{$domain});
275 $res->{domains
}->{$domain}->{plugin
} = 'standalone';
276 $res->{domains
}->{$domain}->{_configkey
} = 'acme';
280 $res->{account
} //= 'default';
282 for my $index (0..$MAXDOMAINS) {
283 my $domain_rec = $node_conf->{"acmedomain$index"};
284 next if !defined($domain_rec);
287 PVE
::JSONSchema
::parse_property_string
($acme_domain_desc, $domain_rec)
290 return undef if $noerr;
293 my $domain = lc(delete $parsed->{domain
});
294 if (my $exists = $res->{domains
}->{$domain}) {
295 return undef if $noerr;
296 die "duplicate domain '$domain' in ACME config properties"
297 ." 'acmedomain$index' and '$exists->{_configkey}'\n";
299 $parsed->{plugin
} //= 'standalone';
301 my $plugin_id = $parsed->{plugin
};
302 if ($plugin_id ne 'standalone') {
303 my $plugins = PVE
::API2
::ACMEPlugin
::load_config
();
304 die "plugin '$plugin_id' for domain '$domain' not found!\n"
305 if !$plugins->{ids
}->{$plugin_id};
308 $parsed->{_configkey
} = "acmedomain$index";
309 $res->{domains
}->{$domain} = $parsed;
315 # expects that basic format verification was already done, this is more higher
318 my ($node_conf) = @_;
320 # verify ACME domain uniqueness
321 my $tmp = get_acme_conf
($node_conf);
328 sub get_nodeconfig_schema
{