1 package PVE
::QemuServer
::Cloudinit
;
9 use MIME
::Base64
qw(encode_base64);
10 use Storable
qw(dclone);
12 use PVE
::Tools
qw(run_command file_set_contents);
15 use PVE
::QemuServer
::Helpers
;
17 use constant CLOUDINIT_DISK_SIZE
=> 4 * 1024 * 1024; # 4MiB in bytes
19 sub commit_cloudinit_disk
{
20 my ($conf, $vmid, $drive, $volname, $storeid, $files, $label) = @_;
22 my $path = "/run/pve/cloudinit/$vmid/";
24 foreach my $filepath (keys %$files) {
25 if ($filepath !~ m
@^(.*)\
/[^/]+$@) {
26 die "internal error: bad file name in cloud-init image: $filepath\n";
29 mkpath
"$path/$dirname";
31 my $contents = $files->{$filepath};
32 file_set_contents
("$path/$filepath", $contents);
35 my $storecfg = PVE
::Storage
::config
();
36 my $iso_path = PVE
::Storage
::path
($storecfg, $drive->{file
});
37 my $scfg = PVE
::Storage
::storage_config
($storecfg, $storeid);
38 my $format = PVE
::QemuServer
::qemu_img_format
($scfg, $volname);
40 my $size = eval { PVE
::Storage
::volume_size_info
($storecfg, $drive->{file
}) };
41 if (!defined($size) || $size <= 0) {
42 $volname =~ m/(vm-$vmid-cloudinit(.\Q$format\E)?)/;
45 PVE
::Storage
::vdisk_alloc
($storecfg, $storeid, $vmid, $format, $name, $size);
46 $size *= 1024; # vdisk alloc takes KB, qemu-img dd's osize takes byte
48 my $plugin = PVE
::Storage
::Plugin-
>lookup($scfg->{type
});
49 $plugin->activate_volume($storeid, $scfg, $volname);
51 print "generating cloud-init ISO\n";
54 ['genisoimage', '-quiet', '-iso-level', '3', '-R', '-V', $label, $path],
55 ['qemu-img', 'dd', '-n', '-f', 'raw', '-O', $format, 'isize=0', "osize=$size", "of=$iso_path"]
63 sub get_cloudinit_format
{
65 if (defined(my $format = $conf->{citype
})) {
69 # No format specified, default based on ostype because windows'
70 # cloudbased-init only supports configdrivev2, whereas on linux we need
71 # to use mac addresses because regular cloudinit doesn't map 'ethX' to
72 # the new predicatble network device naming scheme.
73 if (defined(my $ostype = $conf->{ostype
})) {
75 if PVE
::QemuServer
::Helpers
::windows_version
($ostype);
81 sub get_hostname_fqdn
{
82 my ($conf, $vmid) = @_;
83 my $hostname = $conf->{name
} // "VM$vmid";
85 if ($hostname =~ /\./) {
87 $hostname =~ s/\..*$//;
88 } elsif (my $search = $conf->{searchdomain
}) {
89 $fqdn = "$hostname.$search";
91 return ($hostname, $fqdn);
97 # Same logic as in pve-container, but without the testcase special case
98 my $host_resolv_conf = PVE
::INotify
::read_file
('resolvconf');
100 my $searchdomains = [
101 split(/\s+/, $conf->{searchdomain
} // $host_resolv_conf->{search
})
104 my $nameserver = $conf->{nameserver
};
105 if (!defined($nameserver)) {
106 $nameserver = [grep { $_ } $host_resolv_conf->@{qw(dns1 dns2 dns3)}];
108 $nameserver = [split(/\s+/, $nameserver)];
111 return ($searchdomains, $nameserver);
114 sub cloudinit_userdata
{
115 my ($conf, $vmid) = @_;
117 my ($hostname, $fqdn) = get_hostname_fqdn
($conf, $vmid);
119 my $content = "#cloud-config\n";
121 $content .= "hostname: $hostname\n";
122 $content .= "manage_etc_hosts: true\n";
123 $content .= "fqdn: $fqdn\n" if defined($fqdn);
125 my $username = $conf->{ciuser
};
126 my $password = $conf->{cipassword
};
128 $content .= "user: $username\n" if defined($username);
129 $content .= "disable_root: False\n" if defined($username) && $username eq 'root';
130 $content .= "password: $password\n" if defined($password);
132 if (defined(my $keys = $conf->{sshkeys
})) {
133 $keys = URI
::Escape
::uri_unescape
($keys);
134 $keys = [map { my $key = $_; chomp $key; $key } split(/\n/, $keys)];
135 $keys = [grep { /\S/ } @$keys];
136 $content .= "ssh_authorized_keys:\n";
137 foreach my $k (@$keys) {
138 $content .= " - $k\n";
141 $content .= "chpasswd:\n";
142 $content .= " expire: False\n";
144 if (!defined($username) || $username ne 'root') {
145 $content .= "users:\n";
146 $content .= " - default\n";
149 $content .= "package_upgrade: true\n";
156 my ($addr, $mask) = split('/', $ip);
157 die "not a CIDR: $ip\n" if !defined $mask;
158 return ($addr, $PVE::Network
::ipv4_reverse_mask-
>[$mask]);
161 sub configdrive2_network
{
164 my $content = "auto lo\n";
165 $content .= "iface lo inet loopback\n\n";
167 my ($searchdomains, $nameservers) = get_dns_conf
($conf);
168 if ($nameservers && @$nameservers) {
169 $nameservers = join(' ', @$nameservers);
170 $content .= " dns_nameservers $nameservers\n";
172 if ($searchdomains && @$searchdomains) {
173 $searchdomains = join(' ', @$searchdomains);
174 $content .= " dns_search $searchdomains\n";
177 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
178 foreach my $iface (sort @ifaces) {
179 (my $id = $iface) =~ s/^net//;
180 next if !$conf->{"ipconfig$id"};
181 my $net = PVE
::QemuServer
::parse_ipconfig
($conf->{"ipconfig$id"});
184 $content .="auto $id\n";
186 if ($net->{ip
} eq 'dhcp') {
187 $content .= "iface $id inet dhcp\n";
189 my ($addr, $mask) = split_ip4
($net->{ip
});
190 $content .= "iface $id inet static\n";
191 $content .= " address $addr\n";
192 $content .= " netmask $mask\n";
193 $content .= " gateway $net->{gw}\n" if $net->{gw
};
197 if ($net->{ip6
} =~ /^(auto|dhcp)$/) {
198 $content .= "iface $id inet6 $1\n";
200 my ($addr, $mask) = split('/', $net->{ip6
});
201 $content .= "iface $id inet6 static\n";
202 $content .= " address $addr\n";
203 $content .= " netmask $mask\n";
204 $content .= " gateway $net->{gw6}\n" if $net->{gw6
};
212 sub configdrive2_gen_metadata
{
213 my ($user, $network) = @_;
215 my $uuid_str = Digest
::SHA
::sha1_hex
($user.$network);
216 return configdrive2_metadata
($uuid_str);
219 sub configdrive2_metadata
{
224 "network_config": { "content_path": "/content/0000" }
229 sub generate_configdrive2
{
230 my ($conf, $vmid, $drive, $volname, $storeid) = @_;
232 my ($user_data, $network_data, $meta_data, $vendor_data) = get_custom_cloudinit_files
($conf);
233 $user_data = cloudinit_userdata
($conf, $vmid) if !defined($user_data);
234 $network_data = configdrive2_network
($conf) if !defined($network_data);
235 $vendor_data = '' if !defined($vendor_data);
237 if (!defined($meta_data)) {
238 $meta_data = configdrive2_gen_metadata
($user_data, $network_data);
241 # we always allocate a 4MiB disk for cloudinit and with the overhead of the ISO
242 # make sure we always stay below it by keeping the sum of all files below 3 MiB
243 my $sum = length($user_data) + length($network_data) + length($meta_data) + length($vendor_data);
244 die "Cloud-Init sum of snippets too big (> 3 MiB)\n" if $sum > (3 * 1024 * 1024);
247 '/openstack/latest/user_data' => $user_data,
248 '/openstack/content/0000' => $network_data,
249 '/openstack/latest/meta_data.json' => $meta_data,
250 '/openstack/latest/vendor_data.json' => $vendor_data
252 commit_cloudinit_disk
($conf, $vmid, $drive, $volname, $storeid, $files, 'config-2');
255 sub generate_opennebula
{
256 my ($conf, $vmid, $drive, $volname, $storeid) = @_;
260 my $username = $conf->{ciuser
} || "root";
261 $content .= "USERNAME=$username\n" if defined($username);
263 if (defined(my $password = $conf->{cipassword
})) {
264 $content .= "CRYPTED_PASSWORD_BASE64=". encode_base64
($password) ."\n";
267 if (defined($conf->{sshkeys
})) {
268 my $keys = [ split(/\s*\n\s*/, URI
::Escape
::uri_unescape
($conf->{sshkeys
})) ];
269 $content .= "SSH_PUBLIC_KEY=\"". join("\n", $keys->@*) ."\"\n";
272 my ($hostname, $fqdn) = get_hostname_fqdn
($conf, $vmid);
273 $content .= "SET_HOSTNAME=$hostname\n";
275 my ($searchdomains, $nameservers) = get_dns_conf
($conf);
276 $content .= 'DNS="' . join(' ', @$nameservers) ."\"\n" if $nameservers && @$nameservers;
277 $content .= 'SEARCH_DOMAIN="'. join(' ', @$searchdomains) ."\"\n" if $searchdomains && @$searchdomains;
279 my $networkenabled = undef;
280 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
281 foreach my $iface (sort @ifaces) {
282 (my $id = $iface) =~ s/^net//;
283 my $net = PVE
::QemuServer
::parse_net
($conf->{$iface});
284 next if !$conf->{"ipconfig$id"};
285 my $ipconfig = PVE
::QemuServer
::parse_ipconfig
($conf->{"ipconfig$id"});
286 my $ethid = "ETH$id";
288 my $mac = lc $net->{hwaddr
};
290 if ($ipconfig->{ip
}) {
293 if ($ipconfig->{ip
} eq 'dhcp') {
294 $content .= "${ethid}_DHCP=YES\n";
296 my ($addr, $mask) = split_ip4
($ipconfig->{ip
});
297 $content .= "${ethid}_IP=$addr\n";
298 $content .= "${ethid}_MASK=$mask\n";
299 $content .= "${ethid}_MAC=$mac\n";
300 $content .= "${ethid}_GATEWAY=$ipconfig->{gw}\n" if $ipconfig->{gw
};
302 $content .= "${ethid}_MTU=$net->{mtu}\n" if $net->{mtu
};
305 if ($ipconfig->{ip6
}) {
307 if ($ipconfig->{ip6
} eq 'dhcp') {
308 $content .= "${ethid}_DHCP6=YES\n";
309 } elsif ($ipconfig->{ip6
} eq 'auto') {
310 $content .= "${ethid}_AUTO6=YES\n";
312 my ($addr, $mask) = split('/', $ipconfig->{ip6
});
313 $content .= "${ethid}_IP6=$addr\n";
314 $content .= "${ethid}_MASK6=$mask\n";
315 $content .= "${ethid}_MAC6=$mac\n";
316 $content .= "${ethid}_GATEWAY6=$ipconfig->{gw6}\n" if $ipconfig->{gw6
};
318 $content .= "${ethid}_MTU=$net->{mtu}\n" if $net->{mtu
};
322 $content .= "NETWORK=YES\n" if $networkenabled;
324 my $files = { '/context.sh' => $content };
325 commit_cloudinit_disk
($conf, $vmid, $drive, $volname, $storeid, $files, 'CONTEXT');
328 sub nocloud_network_v2
{
333 my $head = "version: 2\n"
338 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
339 foreach my $iface (sort @ifaces) {
340 (my $id = $iface) =~ s/^net//;
341 next if !$conf->{"ipconfig$id"};
343 # indentation - network interfaces are inside an 'ethernets' hash
346 my $net = PVE
::QemuServer
::parse_net
($conf->{$iface});
347 my $ipconfig = PVE
::QemuServer
::parse_ipconfig
($conf->{"ipconfig$id"});
349 my $mac = $net->{macaddr
}
350 or die "network interface '$iface' has no mac address\n";
352 $content .= "${i}$iface:\n";
354 $content .= "${i}match:\n"
355 . "${i} macaddress: \"$mac\"\n"
356 . "${i
}set-name
: eth
$id\n";
358 if (defined(my $ip = $ipconfig->{ip})) {
360 $content .= "${i
}dhcp4
: true
\n";
362 push @addresses, $ip;
365 if (defined(my $ip = $ipconfig->{ip6})) {
367 $content .= "${i
}dhcp6
: true
\n";
369 push @addresses, $ip;
373 $content .= "${i
}addresses
:\n";
374 $content .= "${i
}- '$_'\n" foreach @addresses;
376 if (defined(my $gw = $ipconfig->{gw})) {
377 $content .= "${i
}gateway4
: '$gw'\n";
379 if (defined(my $gw = $ipconfig->{gw6})) {
380 $content .= "${i
}gateway6
: '$gw'\n";
386 my ($searchdomains, $nameservers) = get_dns_conf($conf);
387 if ($searchdomains || $nameservers) {
388 $content .= "${i
}nameservers
:\n";
389 if (defined($nameservers) && @$nameservers) {
390 $content .= "${i
} addresses
:\n";
391 $content .= "${i
} - '$_'\n" foreach @$nameservers;
393 if (defined($searchdomains) && @$searchdomains) {
394 $content .= "${i
} search
:\n";
395 $content .= "${i
} - '$_'\n" foreach @$searchdomains;
400 return $head.$content;
403 sub nocloud_network {
406 my $content = "version
: 1\n"
409 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
410 foreach my $iface (sort @ifaces) {
411 (my $id = $iface) =~ s/^net//;
412 next if !$conf->{"ipconfig
$id"};
414 # indentation - network interfaces are inside an 'ethernets' hash
417 my $net = PVE::QemuServer::parse_net($conf->{$iface});
418 my $ipconfig = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig
$id"});
420 my $mac = lc($net->{macaddr})
421 or die "network interface
'$iface' has no mac address
\n";
423 $content .= "${i
}- type
: physical
\n"
424 . "${i
} name
: eth
$id\n"
425 . "${i
} mac_address
: '$mac'\n"
428 if (defined(my $ip = $ipconfig->{ip})) {
430 $content .= "${i
}- type
: dhcp4
\n";
432 my ($addr, $mask) = split_ip4($ip);
433 $content .= "${i
}- type
: static
\n"
434 . "${i
} address
: '$addr'\n"
435 . "${i
} netmask
: '$mask'\n";
436 if (defined(my $gw = $ipconfig->{gw})) {
437 $content .= "${i
} gateway
: '$gw'\n";
441 if (defined(my $ip = $ipconfig->{ip6})) {
443 $content .= "${i
}- type
: dhcp6
\n";
444 } elsif ($ip eq 'auto') {
445 # SLAAC is only supported by cloud-init since 19.4
446 $content .= "${i
}- type
: ipv6_slaac
\n";
448 $content .= "${i
}- type
: static6
\n"
449 . "${i
} address
: '$ip'\n";
450 if (defined(my $gw = $ipconfig->{gw6})) {
451 $content .= "${i
} gateway
: '$gw'\n";
458 my ($searchdomains, $nameservers) = get_dns_conf($conf);
459 if ($searchdomains || $nameservers) {
460 $content .= "${i
}- type
: nameserver
\n";
461 if (defined($nameservers) && @$nameservers) {
462 $content .= "${i
} address
:\n";
463 $content .= "${i
} - '$_'\n" foreach @$nameservers;
465 if (defined($searchdomains) && @$searchdomains) {
466 $content .= "${i
} search
:\n";
467 $content .= "${i
} - '$_'\n" foreach @$searchdomains;
474 sub nocloud_metadata {
476 return "instance-id
: $uuid\n";
479 sub nocloud_gen_metadata {
480 my ($user, $network) = @_;
482 my $uuid_str = Digest::SHA::sha1_hex($user.$network);
483 return nocloud_metadata($uuid_str);
486 sub generate_nocloud {
487 my ($conf, $vmid, $drive, $volname, $storeid) = @_;
489 my ($user_data, $network_data, $meta_data, $vendor_data) = get_custom_cloudinit_files($conf);
490 $user_data = cloudinit_userdata($conf, $vmid) if !defined($user_data);
491 $network_data = nocloud_network($conf) if !defined($network_data);
492 $vendor_data = '' if !defined($vendor_data);
494 if (!defined($meta_data)) {
495 $meta_data = nocloud_gen_metadata($user_data, $network_data);
498 # we always allocate a 4MiB disk for cloudinit and with the overhead of the ISO
499 # make sure we always stay below it by keeping the sum of all files below 3 MiB
500 my $sum = length($user_data) + length($network_data) + length($meta_data) + length($vendor_data);
501 die "Cloud-Init sum of snippets too big
(> 3 MiB
)\n" if $sum > (3 * 1024 * 1024);
504 '/user-data' => $user_data,
505 '/network-config' => $network_data,
506 '/meta-data' => $meta_data,
507 '/vendor-data' => $vendor_data
509 commit_cloudinit_disk($conf, $vmid, $drive, $volname, $storeid, $files, 'cidata');
512 sub get_custom_cloudinit_files {
515 my $cicustom = $conf->{cicustom};
516 my $files = $cicustom ? PVE::JSONSchema::parse_property_string('pve-qm-cicustom', $cicustom) : {};
518 my $network_volid = $files->{network};
519 my $user_volid = $files->{user};
520 my $meta_volid = $files->{meta};
521 my $vendor_volid = $files->{vendor};
523 my $storage_conf = PVE::Storage::config();
526 if ($network_volid) {
527 $network_data = read_cloudinit_snippets_file($storage_conf, $network_volid);
532 $user_data = read_cloudinit_snippets_file($storage_conf, $user_volid);
537 $meta_data = read_cloudinit_snippets_file($storage_conf, $meta_volid);
542 $vendor_data = read_cloudinit_snippets_file($storage_conf, $vendor_volid);
545 return ($user_data, $network_data, $meta_data, $vendor_data);
548 sub read_cloudinit_snippets_file {
549 my ($storage_conf, $volid) = @_;
551 my ($full_path, undef, $type) = PVE::Storage::path($storage_conf, $volid);
552 die "$volid is not in the snippets directory
\n" if $type ne 'snippets';
553 return PVE::Tools::file_get_contents($full_path, 1 * 1024 * 1024);
556 my $cloudinit_methods = {
557 configdrive2 => \&generate_configdrive2,
558 nocloud => \&generate_nocloud,
559 opennebula => \&generate_opennebula,
562 sub generate_cloudinitconfig {
563 my ($conf, $vmid) = @_;
565 my $format = get_cloudinit_format($conf);
567 PVE::QemuConfig->foreach_volume($conf, sub {
568 my ($ds, $drive) = @_;
570 my ($storeid, $volname) = PVE::Storage::parse_volume_id($drive->{file}, 1);
572 return if !$volname || $volname !~ m/vm-$vmid-cloudinit/;
574 my $generator = $cloudinit_methods->{$format}
575 or die "missing cloudinit methods
for format
'$format'\n";
577 $generator->($conf, $vmid, $drive, $volname, $storeid);
580 my $cloudinitconf = delete $conf->{cloudinit};
583 my @cloudinit_opts = keys %{PVE::QemuServer::cloudinit_config_properties()};
584 push @cloudinit_opts, 'name';
586 for my $opt (@cloudinit_opts) {
588 if ($opt =~ m/^ipconfig(\d+)/) {
590 next if !defined($conf->{$netid});
591 $conf->{cloudinit}->{$netid} = $conf->{$netid};
594 $conf->{cloudinit}->{$opt} = $conf->{$opt} if $conf->{$opt};
597 $conf->{cloudinit}->{name} = "VM
$vmid" if !$conf->{cloudinit}->{name};
599 for my $opt (keys %{$conf}) {
600 if (PVE::QemuServer::is_valid_drivename($opt)) {
601 my $drive = PVE::QemuServer::parse_drive($opt, $conf->{$opt});
602 if (PVE::QemuServer::drive_is_cloudinit($drive)) {
603 $conf->{cloudinit}->{$opt} = $conf->{$opt};
608 PVE::QemuConfig->write_config($vmid, $conf);
612 sub dump_cloudinit_config {
613 my ($conf, $vmid, $type) = @_;
615 my $format = get_cloudinit_format($conf);
617 if ($type eq 'user') {
618 return cloudinit_userdata($conf, $vmid);
619 } elsif ($type eq 'network') {
620 if ($format eq 'nocloud') {
621 return nocloud_network($conf);
623 return configdrive2_network($conf);
625 } else { # metadata config
626 my $user = cloudinit_userdata($conf, $vmid);
627 if ($format eq 'nocloud') {
628 my $network = nocloud_network($conf);
629 return nocloud_gen_metadata($user, $network);
631 my $network = configdrive2_network($conf);
632 return configdrive2_gen_metadata($user, $network);
637 sub get_pending_config {
638 my ($conf, $vmid) = @_;
640 my $newconf = dclone($conf);
642 my $cloudinit_current = $newconf->{cloudinit};
643 my @cloudinit_opts = keys %{PVE::QemuServer::cloudinit_config_properties()};
644 push @cloudinit_opts, 'name';
646 #add cloud-init drive
648 PVE::QemuConfig->foreach_volume($newconf, sub {
649 my ($ds, $drive) = @_;
650 $drives->{$ds} = 1 if PVE::QemuServer::drive_is_cloudinit($drive);
653 PVE::QemuConfig->foreach_volume($cloudinit_current, sub {
654 my ($ds, $drive) = @_;
655 $drives->{$ds} = 1 if PVE::QemuServer::drive_is_cloudinit($drive);
657 for my $ds (keys %{$drives}) {
658 push @cloudinit_opts, $ds;
661 $newconf->{name} = "VM
$vmid" if !$newconf->{name};
662 $cloudinit_current->{name} = "VM
$vmid" if !$cloudinit_current->{name};
664 #only mac-address is used in cloud-init config.
665 #We don't want to display other pending net changes.
666 my $print_cloudinit_net = sub {
667 my ($conf, $opt) = @_;
669 if (defined($conf->{$opt})) {
670 my $net = PVE::QemuServer::parse_net($conf->{$opt});
671 $conf->{$opt} = "macaddr
=".$net->{macaddr} if $net->{macaddr};
675 my $cloudinit_options = {};
676 for my $opt (@cloudinit_opts) {
677 if ($opt =~ m/^ipconfig(\d+)/) {
680 next if !defined($newconf->{$netid}) && !defined($cloudinit_current->{$netid}) &&
681 !defined($newconf->{$opt}) && !defined($cloudinit_current->{$opt});
683 &$print_cloudinit_net($newconf, $netid);
684 &$print_cloudinit_net($cloudinit_current, $netid);
685 $cloudinit_options->{$netid} = 1;
687 $cloudinit_options->{$opt} = 1;
692 for my $opt (keys %{$cloudinit_options}) {
697 if ($cloudinit_current->{$opt}) {
698 $item->{value} = $cloudinit_current->{$opt};
699 if (defined($newconf->{$opt})) {
700 $item->{pending} = $newconf->{$opt}
701 if $newconf->{$opt} ne $cloudinit_current->{$opt};
706 $item->{pending} = $newconf->{$opt} if $newconf->{$opt}