1 package PVE
::API2
::LXC
;
7 use PVE
::Tools
qw(extract_param run_command);
8 use PVE
::Exception
qw(raise raise_param_exc);
10 use PVE
::Cluster
qw(cfs_read_file);
11 use PVE
::AccessControl
;
15 use PVE
::RPCEnvironment
;
18 use PVE
::LXC
::Migrate
;
19 use PVE
::API2
::LXC
::Config
;
20 use PVE
::API2
::LXC
::Status
;
21 use PVE
::API2
::LXC
::Snapshot
;
23 use PVE
::JSONSchema
qw(get_standard_option);
24 use base
qw(PVE::RESTHandler);
26 use Data
::Dumper
; # fixme: remove
28 __PACKAGE__-
>register_method ({
29 subclass
=> "PVE::API2::LXC::Config",
30 path
=> '{vmid}/config',
33 __PACKAGE__-
>register_method ({
34 subclass
=> "PVE::API2::LXC::Status",
35 path
=> '{vmid}/status',
38 __PACKAGE__-
>register_method ({
39 subclass
=> "PVE::API2::LXC::Snapshot",
40 path
=> '{vmid}/snapshot',
43 __PACKAGE__-
>register_method ({
44 subclass
=> "PVE::API2::Firewall::CT",
45 path
=> '{vmid}/firewall',
48 __PACKAGE__-
>register_method({
52 description
=> "LXC container index (per node).",
54 description
=> "Only list CTs where you have VM.Audit permissons on /vms/<vmid>.",
58 protected
=> 1, # /proc files are only readable by root
60 additionalProperties
=> 0,
62 node
=> get_standard_option
('pve-node'),
71 links
=> [ { rel
=> 'child', href
=> "{vmid}" } ],
76 my $rpcenv = PVE
::RPCEnvironment
::get
();
77 my $authuser = $rpcenv->get_user();
79 my $vmstatus = PVE
::LXC
::vmstatus
();
82 foreach my $vmid (keys %$vmstatus) {
83 next if !$rpcenv->check($authuser, "/vms/$vmid", [ 'VM.Audit' ], 1);
85 my $data = $vmstatus->{$vmid};
86 $data->{vmid
} = $vmid;
94 __PACKAGE__-
>register_method({
98 description
=> "Create or restore a container.",
100 user
=> 'all', # check inside
101 description
=> "You need 'VM.Allocate' permissions on /vms/{vmid} or on the VM pool /pool/{pool}. " .
102 "For restore, it is enough if the user has 'VM.Backup' permission and the VM already exists. " .
103 "You also need 'Datastore.AllocateSpace' permissions on the storage.",
108 additionalProperties
=> 0,
109 properties
=> PVE
::LXC
::json_config_properties
({
110 node
=> get_standard_option
('pve-node'),
111 vmid
=> get_standard_option
('pve-vmid', { completion
=> \
&PVE
::Cluster
::complete_next_vmid
}),
113 description
=> "The OS template or backup file.",
116 completion
=> \
&PVE
::LXC
::complete_os_templates
,
121 description
=> "Sets root password inside container.",
124 storage
=> get_standard_option
('pve-storage-id', {
125 description
=> "Default Storage.",
132 description
=> "Allow to overwrite existing container.",
137 description
=> "Mark this as restore task.",
141 type
=> 'string', format
=> 'pve-poolid',
142 description
=> "Add the VM to the specified pool.",
152 my $rpcenv = PVE
::RPCEnvironment
::get
();
154 my $authuser = $rpcenv->get_user();
156 my $node = extract_param
($param, 'node');
158 my $vmid = extract_param
($param, 'vmid');
160 my $basecfg_fn = PVE
::LXC
::config_file
($vmid);
162 my $same_container_exists = -f
$basecfg_fn;
164 my $restore = extract_param
($param, 'restore');
167 # fixme: limit allowed parameters
171 my $force = extract_param
($param, 'force');
173 if (!($same_container_exists && $restore && $force)) {
174 PVE
::Cluster
::check_vmid_unused
($vmid);
177 my $password = extract_param
($param, 'password');
179 my $storage = extract_param
($param, 'storage') // 'local';
181 my $storage_cfg = cfs_read_file
("storage.cfg");
183 my $scfg = PVE
::Storage
::storage_check_node
($storage_cfg, $storage, $node);
185 raise_param_exc
({ storage
=> "storage '$storage' does not support container root directories"})
186 if !($scfg->{content
}->{images
} || $scfg->{content
}->{rootdir
});
188 my $pool = extract_param
($param, 'pool');
190 if (defined($pool)) {
191 $rpcenv->check_pool_exist($pool);
192 $rpcenv->check_perm_modify($authuser, "/pool/$pool");
195 $rpcenv->check($authuser, "/storage/$storage", ['Datastore.AllocateSpace']);
197 if ($rpcenv->check($authuser, "/vms/$vmid", ['VM.Allocate'], 1)) {
199 } elsif ($pool && $rpcenv->check($authuser, "/pool/$pool", ['VM.Allocate'], 1)) {
201 } elsif ($restore && $force && $same_container_exists &&
202 $rpcenv->check($authuser, "/vms/$vmid", ['VM.Backup'], 1)) {
203 # OK: user has VM.Backup permissions, and want to restore an existing VM
208 PVE
::LXC
::check_ct_modify_config_perm
($rpcenv, $authuser, $vmid, $pool, [ keys %$param]);
210 PVE
::Storage
::activate_storage
($storage_cfg, $storage);
212 my $ostemplate = extract_param
($param, 'ostemplate');
216 if ($ostemplate eq '-') {
217 die "pipe requires cli environment\n"
218 if $rpcenv->{type
} ne 'cli';
219 die "pipe can only be used with restore tasks\n"
222 die "restore from pipe requires rootfs parameter\n" if !defined($param->{rootfs
});
224 $rpcenv->check_volume_access($authuser, $storage_cfg, $vmid, $ostemplate);
225 $archive = PVE
::Storage
::abs_filesystem_path
($storage_cfg, $ostemplate);
230 my $no_disk_param = {};
231 foreach my $opt (keys %$param) {
232 my $value = $param->{$opt};
233 if ($opt eq 'rootfs' || $opt =~ m/^mp\d+$/) {
234 # allow to use simple numbers (add default storage in that case)
235 $param->{$opt} = "$storage:$value" if $value =~ m/^\d+(\.\d+)?$/;
237 $no_disk_param->{$opt} = $value;
240 PVE
::LXC
::update_pct_config
($vmid, $conf, 0, $no_disk_param);
242 my $check_vmid_usage = sub {
244 die "can't overwrite running container\n"
245 if PVE
::LXC
::check_running
($vmid);
247 PVE
::Cluster
::check_vmid_unused
($vmid);
252 &$check_vmid_usage(); # final check after locking
254 PVE
::Cluster
::check_cfs_quorum
();
258 if (!defined($param->{rootfs
})) {
260 my (undef, $disksize) = PVE
::LXC
::Create
::recover_config
($archive);
261 $disksize /= 1024 * 1024; # create_disks expects GB as unit size
262 die "unable to detect disk size - please specify rootfs (size)\n"
264 $param->{rootfs
} = "$storage:$disksize";
266 $param->{rootfs
} = "$storage:4"; # defaults to 4GB
270 $vollist = PVE
::LXC
::create_disks
($storage_cfg, $vmid, $param, $conf);
272 PVE
::LXC
::Create
::create_rootfs
($storage_cfg, $vmid, $conf, $archive, $password, $restore);
274 $conf->{hostname
} ||= "CT$vmid";
275 $conf->{memory
} ||= 512;
276 $conf->{swap
} //= 512;
277 PVE
::LXC
::create_config
($vmid, $conf);
280 PVE
::LXC
::destroy_disks
($storage_cfg, $vollist);
281 PVE
::LXC
::destroy_config
($vmid);
284 PVE
::AccessControl
::add_vm_to_pool
($vmid, $pool) if $pool;
287 my $realcmd = sub { PVE
::LXC
::lock_container
($vmid, 1, $code); };
289 &$check_vmid_usage(); # first check before locking
291 return $rpcenv->fork_worker($restore ?
'vzrestore' : 'vzcreate',
292 $vmid, $authuser, $realcmd);
296 __PACKAGE__-
>register_method({
301 description
=> "Directory index",
306 additionalProperties
=> 0,
308 node
=> get_standard_option
('pve-node'),
309 vmid
=> get_standard_option
('pve-vmid'),
317 subdir
=> { type
=> 'string' },
320 links
=> [ { rel
=> 'child', href
=> "{subdir}" } ],
326 my $conf = PVE
::LXC
::load_config
($param->{vmid
});
329 { subdir
=> 'config' },
330 { subdir
=> 'status' },
331 { subdir
=> 'vncproxy' },
332 { subdir
=> 'vncwebsocket' },
333 { subdir
=> 'spiceproxy' },
334 { subdir
=> 'migrate' },
335 # { subdir => 'initlog' },
337 { subdir
=> 'rrddata' },
338 { subdir
=> 'firewall' },
339 { subdir
=> 'snapshot' },
345 __PACKAGE__-
>register_method({
347 path
=> '{vmid}/rrd',
349 protected
=> 1, # fixme: can we avoid that?
351 check
=> ['perm', '/vms/{vmid}', [ 'VM.Audit' ]],
353 description
=> "Read VM RRD statistics (returns PNG)",
355 additionalProperties
=> 0,
357 node
=> get_standard_option
('pve-node'),
358 vmid
=> get_standard_option
('pve-vmid'),
360 description
=> "Specify the time frame you are interested in.",
362 enum
=> [ 'hour', 'day', 'week', 'month', 'year' ],
365 description
=> "The list of datasources you want to display.",
366 type
=> 'string', format
=> 'pve-configid-list',
369 description
=> "The RRD consolidation function",
371 enum
=> [ 'AVERAGE', 'MAX' ],
379 filename
=> { type
=> 'string' },
385 return PVE
::Cluster
::create_rrd_graph
(
386 "pve2-vm/$param->{vmid}", $param->{timeframe
},
387 $param->{ds
}, $param->{cf
});
391 __PACKAGE__-
>register_method({
393 path
=> '{vmid}/rrddata',
395 protected
=> 1, # fixme: can we avoid that?
397 check
=> ['perm', '/vms/{vmid}', [ 'VM.Audit' ]],
399 description
=> "Read VM RRD statistics",
401 additionalProperties
=> 0,
403 node
=> get_standard_option
('pve-node'),
404 vmid
=> get_standard_option
('pve-vmid'),
406 description
=> "Specify the time frame you are interested in.",
408 enum
=> [ 'hour', 'day', 'week', 'month', 'year' ],
411 description
=> "The RRD consolidation function",
413 enum
=> [ 'AVERAGE', 'MAX' ],
428 return PVE
::Cluster
::create_rrd_data
(
429 "pve2-vm/$param->{vmid}", $param->{timeframe
}, $param->{cf
});
432 __PACKAGE__-
>register_method({
433 name
=> 'destroy_vm',
438 description
=> "Destroy the container (also delete all uses files).",
440 check
=> [ 'perm', '/vms/{vmid}', ['VM.Allocate']],
443 additionalProperties
=> 0,
445 node
=> get_standard_option
('pve-node'),
446 vmid
=> get_standard_option
('pve-vmid', { completion
=> \
&PVE
::LXC
::complete_ctid_stopped
}),
455 my $rpcenv = PVE
::RPCEnvironment
::get
();
457 my $authuser = $rpcenv->get_user();
459 my $vmid = $param->{vmid
};
461 # test if container exists
462 my $conf = PVE
::LXC
::load_config
($vmid);
464 my $storage_cfg = cfs_read_file
("storage.cfg");
466 die "can't remove CT $vmid - protection mode enabled\n"
467 if ($conf->{protection
} == 1);
469 die "unable to remove CT $vmid - used in HA resources\n"
470 if PVE
::HA
::Config
::vm_is_ha_managed
($vmid);
473 # reload config after lock
474 $conf = PVE
::LXC
::load_config
($vmid);
475 PVE
::LXC
::check_lock
($conf);
477 PVE
::LXC
::destroy_lxc_container
($storage_cfg, $vmid, $conf);
478 PVE
::AccessControl
::remove_vm_access
($vmid);
479 PVE
::Firewall
::remove_vmfw_conf
($vmid);
482 my $realcmd = sub { PVE
::LXC
::lock_container
($vmid, 1, $code); };
484 return $rpcenv->fork_worker('vzdestroy', $vmid, $authuser, $realcmd);
489 __PACKAGE__-
>register_method ({
491 path
=> '{vmid}/vncproxy',
495 check
=> ['perm', '/vms/{vmid}', [ 'VM.Console' ]],
497 description
=> "Creates a TCP VNC proxy connections.",
499 additionalProperties
=> 0,
501 node
=> get_standard_option
('pve-node'),
502 vmid
=> get_standard_option
('pve-vmid'),
506 description
=> "use websocket instead of standard VNC.",
511 additionalProperties
=> 0,
513 user
=> { type
=> 'string' },
514 ticket
=> { type
=> 'string' },
515 cert
=> { type
=> 'string' },
516 port
=> { type
=> 'integer' },
517 upid
=> { type
=> 'string' },
523 my $rpcenv = PVE
::RPCEnvironment
::get
();
525 my $authuser = $rpcenv->get_user();
527 my $vmid = $param->{vmid
};
528 my $node = $param->{node
};
530 my $authpath = "/vms/$vmid";
532 my $ticket = PVE
::AccessControl
::assemble_vnc_ticket
($authuser, $authpath);
534 $sslcert = PVE
::Tools
::file_get_contents
("/etc/pve/pve-root-ca.pem", 8192)
537 my ($remip, $family);
539 if ($node ne PVE
::INotify
::nodename
()) {
540 ($remip, $family) = PVE
::Cluster
::remote_node_ip
($node);
542 $family = PVE
::Tools
::get_host_address_family
($node);
545 my $port = PVE
::Tools
::next_vnc_port
($family);
547 # NOTE: vncterm VNC traffic is already TLS encrypted,
548 # so we select the fastest chipher here (or 'none'?)
549 my $remcmd = $remip ?
550 ['/usr/bin/ssh', '-t', $remip] : [];
552 my $conf = PVE
::LXC
::load_config
($vmid, $node);
553 my $concmd = PVE
::LXC
::get_console_command
($vmid, $conf);
555 my $shcmd = [ '/usr/bin/dtach', '-A',
556 "/var/run/dtach/vzctlconsole$vmid",
557 '-r', 'winch', '-z', @$concmd];
562 syslog
('info', "starting lxc vnc proxy $upid\n");
566 my $cmd = ['/usr/bin/vncterm', '-rfbport', $port,
567 '-timeout', $timeout, '-authpath', $authpath,
568 '-perm', 'VM.Console'];
570 if ($param->{websocket
}) {
571 $ENV{PVE_VNC_TICKET
} = $ticket; # pass ticket to vncterm
572 push @$cmd, '-notls', '-listen', 'localhost';
575 push @$cmd, '-c', @$remcmd, @$shcmd;
582 my $upid = $rpcenv->fork_worker('vncproxy', $vmid, $authuser, $realcmd);
584 PVE
::Tools
::wait_for_vnc_port
($port);
595 __PACKAGE__-
>register_method({
596 name
=> 'vncwebsocket',
597 path
=> '{vmid}/vncwebsocket',
600 description
=> "You also need to pass a valid ticket (vncticket).",
601 check
=> ['perm', '/vms/{vmid}', [ 'VM.Console' ]],
603 description
=> "Opens a weksocket for VNC traffic.",
605 additionalProperties
=> 0,
607 node
=> get_standard_option
('pve-node'),
608 vmid
=> get_standard_option
('pve-vmid'),
610 description
=> "Ticket from previous call to vncproxy.",
615 description
=> "Port number returned by previous vncproxy call.",
625 port
=> { type
=> 'string' },
631 my $rpcenv = PVE
::RPCEnvironment
::get
();
633 my $authuser = $rpcenv->get_user();
635 my $authpath = "/vms/$param->{vmid}";
637 PVE
::AccessControl
::verify_vnc_ticket
($param->{vncticket
}, $authuser, $authpath);
639 my $port = $param->{port
};
641 return { port
=> $port };
644 __PACKAGE__-
>register_method ({
645 name
=> 'spiceproxy',
646 path
=> '{vmid}/spiceproxy',
651 check
=> ['perm', '/vms/{vmid}', [ 'VM.Console' ]],
653 description
=> "Returns a SPICE configuration to connect to the CT.",
655 additionalProperties
=> 0,
657 node
=> get_standard_option
('pve-node'),
658 vmid
=> get_standard_option
('pve-vmid'),
659 proxy
=> get_standard_option
('spice-proxy', { optional
=> 1 }),
662 returns
=> get_standard_option
('remote-viewer-config'),
666 my $vmid = $param->{vmid
};
667 my $node = $param->{node
};
668 my $proxy = $param->{proxy
};
670 my $authpath = "/vms/$vmid";
671 my $permissions = 'VM.Console';
673 my $conf = PVE
::LXC
::load_config
($vmid);
675 die "CT $vmid not running\n" if !PVE
::LXC
::check_running
($vmid);
677 my $concmd = PVE
::LXC
::get_console_command
($vmid, $conf);
679 my $shcmd = ['/usr/bin/dtach', '-A',
680 "/var/run/dtach/vzctlconsole$vmid",
681 '-r', 'winch', '-z', @$concmd];
683 my $title = "CT $vmid";
685 return PVE
::API2Tools
::run_spiceterm
($authpath, $permissions, $vmid, $node, $proxy, $title, $shcmd);
689 __PACKAGE__-
>register_method({
690 name
=> 'migrate_vm',
691 path
=> '{vmid}/migrate',
695 description
=> "Migrate the container to another node. Creates a new migration task.",
697 check
=> ['perm', '/vms/{vmid}', [ 'VM.Migrate' ]],
700 additionalProperties
=> 0,
702 node
=> get_standard_option
('pve-node'),
703 vmid
=> get_standard_option
('pve-vmid', { completion
=> \
&PVE
::LXC
::complete_ctid
}),
704 target
=> get_standard_option
('pve-node', {
705 description
=> "Target node.",
706 completion
=> \
&PVE
::Cluster
::complete_migration_target
,
710 description
=> "Use online/live migration.",
717 description
=> "the task ID.",
722 my $rpcenv = PVE
::RPCEnvironment
::get
();
724 my $authuser = $rpcenv->get_user();
726 my $target = extract_param
($param, 'target');
728 my $localnode = PVE
::INotify
::nodename
();
729 raise_param_exc
({ target
=> "target is local node."}) if $target eq $localnode;
731 PVE
::Cluster
::check_cfs_quorum
();
733 PVE
::Cluster
::check_node_exists
($target);
735 my $targetip = PVE
::Cluster
::remote_node_ip
($target);
737 my $vmid = extract_param
($param, 'vmid');
740 PVE
::LXC
::load_config
($vmid);
742 # try to detect errors early
743 if (PVE
::LXC
::check_running
($vmid)) {
744 die "can't migrate running container without --online\n"
745 if !$param->{online
};
748 if (PVE
::HA
::Config
::vm_is_ha_managed
($vmid) && $rpcenv->{type
} ne 'ha') {
753 my $service = "ct:$vmid";
755 my $cmd = ['ha-manager', 'migrate', $service, $target];
757 print "Executing HA migrate for CT $vmid to node $target\n";
759 PVE
::Tools
::run_command
($cmd);
764 return $rpcenv->fork_worker('hamigrate', $vmid, $authuser, $hacmd);
771 PVE
::LXC
::Migrate-
>migrate($target, $targetip, $vmid, $param);
776 return $rpcenv->fork_worker('vzmigrate', $vmid, $authuser, $realcmd);
780 __PACKAGE__-
>register_method({
781 name
=> 'vm_feature',
782 path
=> '{vmid}/feature',
786 description
=> "Check if feature for virtual machine is available.",
788 check
=> ['perm', '/vms/{vmid}', [ 'VM.Audit' ]],
791 additionalProperties
=> 0,
793 node
=> get_standard_option
('pve-node'),
794 vmid
=> get_standard_option
('pve-vmid'),
796 description
=> "Feature to check.",
798 enum
=> [ 'snapshot' ],
800 snapname
=> get_standard_option
('pve-lxc-snapshot-name', {
808 hasFeature
=> { type
=> 'boolean' },
811 #items => { type => 'string' },
818 my $node = extract_param
($param, 'node');
820 my $vmid = extract_param
($param, 'vmid');
822 my $snapname = extract_param
($param, 'snapname');
824 my $feature = extract_param
($param, 'feature');
826 my $conf = PVE
::LXC
::load_config
($vmid);
829 my $snap = $conf->{snapshots
}->{$snapname};
830 die "snapshot '$snapname' does not exist\n" if !defined($snap);
833 my $storage_cfg = PVE
::Storage
::config
();
835 #my $nodelist = PVE::LXC::shared_nodes($conf, $storage_cfg);
836 my $hasFeature = PVE
::LXC
::has_feature
($feature, $conf, $storage_cfg, $snapname);
839 hasFeature
=> $hasFeature,
840 #nodes => [ keys %$nodelist ],
844 __PACKAGE__-
>register_method({
846 path
=> '{vmid}/template',
850 description
=> "Create a Template.",
852 description
=> "You need 'VM.Allocate' permissions on /vms/{vmid}",
853 check
=> [ 'perm', '/vms/{vmid}', ['VM.Allocate']],
856 additionalProperties
=> 0,
858 node
=> get_standard_option
('pve-node'),
859 vmid
=> get_standard_option
('pve-vmid', { completion
=> \
&PVE
::LXC
::complete_ctid_stopped
}),
862 returns
=> { type
=> 'null'},
866 my $rpcenv = PVE
::RPCEnvironment
::get
();
868 my $authuser = $rpcenv->get_user();
870 my $node = extract_param
($param, 'node');
872 my $vmid = extract_param
($param, 'vmid');
876 my $conf = PVE
::LXC
::load_config
($vmid);
877 PVE
::LXC
::check_lock
($conf);
879 die "unable to create template, because CT contains snapshots\n"
880 if $conf->{snapshots
} && scalar(keys %{$conf->{snapshots
}});
882 die "you can't convert a template to a template\n"
883 if PVE
::LXC
::is_template
($conf);
885 die "you can't convert a CT to template if the CT is running\n"
886 if PVE
::LXC
::check_running
($vmid);
889 PVE
::LXC
::template_create
($vmid, $conf);
892 $conf->{template
} = 1;
894 PVE
::LXC
::write_config
($vmid, $conf);
895 # and remove lxc config
896 PVE
::LXC
::update_lxc_config
(undef, $vmid, $conf);
898 return $rpcenv->fork_worker('vztemplate', $vmid, $authuser, $realcmd);
901 PVE
::LXC
::lock_container
($vmid, undef, $updatefn);