]> git.proxmox.com Git - pve-network.git/blob - PVE/Network/SDN/Zones/VlanPlugin.pm
ca6bd8f2472d6714281e052bd6a506f20ee570fe
[pve-network.git] / PVE / Network / SDN / Zones / VlanPlugin.pm
1 package PVE::Network::SDN::Zones::VlanPlugin;
2
3 use strict;
4 use warnings;
5 use PVE::Network::SDN::Zones::Plugin;
6 use PVE::Exception qw(raise raise_param_exc);
7
8 use base('PVE::Network::SDN::Zones::Plugin');
9
10 sub type {
11 return 'vlan';
12 }
13
14 PVE::JSONSchema::register_format('pve-sdn-vlanrange', \&pve_verify_sdn_vlanrange);
15 sub pve_verify_sdn_vlanrange {
16 my ($vlanstr) = @_;
17
18 PVE::Network::SDN::Zones::Plugin::parse_tag_number_or_range($vlanstr, '4096');
19
20 return $vlanstr;
21 }
22
23 sub properties {
24 return {
25 'bridge' => {
26 type => 'string',
27 },
28 };
29 }
30
31 sub options {
32
33 return {
34 nodes => { optional => 1},
35 'bridge' => { optional => 0 },
36 mtu => { optional => 1 },
37 dns => { optional => 1 },
38 reversedns => { optional => 1 },
39 dnszone => { optional => 1 },
40 ipam => { optional => 0 },
41 };
42 }
43
44 # Plugin implementation
45 sub generate_sdn_config {
46 my ($class, $plugin_config, $zoneid, $vnetid, $vnet, $controller, $controller_cfg, $subnet_cfg, $interfaces_config, $config) = @_;
47
48 my $bridge = $plugin_config->{bridge};
49 die "can't find bridge $bridge" if !-d "/sys/class/net/$bridge";
50
51 my $vlan_aware = PVE::Tools::file_read_firstline("/sys/class/net/$bridge/bridge/vlan_filtering");
52 my $is_ovs = !-d "/sys/class/net/$bridge/brif";
53
54 my $tag = $vnet->{tag};
55 my $alias = $vnet->{alias};
56 my $mtu = $plugin_config->{mtu};
57
58 my $vnet_uplink = "ln_".$vnetid;
59 my $vnet_uplinkpeer = "pr_".$vnetid;
60
61 my @iface_config = ();
62
63 if($is_ovs) {
64
65 # keep vmbrXvY for compatibility with existing network
66 # eth0----ovs vmbr0--(ovsintport tag)---->vnet---->vm
67
68 @iface_config = ();
69 push @iface_config, "ovs_type OVSIntPort";
70 push @iface_config, "ovs_bridge $bridge";
71 push @iface_config, "ovs_mtu $mtu" if $mtu;
72 if($vnet->{vlanaware}) {
73 push @iface_config, "ovs_options vlan_mode=dot1q-tunnel other_config:qinq-ethtype=802.1q tag=$tag";
74 } else {
75 push @iface_config, "ovs_options tag=$tag";
76 }
77 push(@{$config->{$vnet_uplink}}, @iface_config) if !$config->{$vnet_uplink};
78
79 #redefine main ovs bridge, ifupdown2 will merge ovs_ports
80 @iface_config = ();
81 push @iface_config, "ovs_ports $vnet_uplink";
82 push(@{$config->{$bridge}}, @iface_config);
83
84 } elsif ($vlan_aware) {
85 # eth0----vlanaware bridge vmbr0--(vmbr0.X tag)---->vnet---->vm
86 $vnet_uplink = "$bridge.$tag";
87 } else {
88
89 # keep vmbrXvY for compatibility with existing network
90 # eth0<---->eth0.X----vmbr0v10------vnet---->vm
91
92 my $bridgevlan = $bridge."v".$tag;
93
94 my @bridge_ifaces = ();
95 my $dir = "/sys/class/net/$bridge/brif";
96 PVE::Tools::dir_glob_foreach($dir, '(((eth|bond)\d+|en[^.]+)(\.\d+)?)', sub {
97 push @bridge_ifaces, $_[0];
98 });
99
100 my $bridge_ports = "";
101 foreach my $bridge_iface (@bridge_ifaces) {
102 $bridge_ports .= " $bridge_iface.$tag";
103 }
104
105 @iface_config = ();
106 push @iface_config, "link-type veth";
107 push @iface_config, "veth-peer-name $vnet_uplinkpeer";
108 push(@{$config->{$vnet_uplink}}, @iface_config) if !$config->{$vnet_uplink};
109
110 @iface_config = ();
111 push @iface_config, "link-type veth";
112 push @iface_config, "veth-peer-name $vnet_uplink";
113 push(@{$config->{$vnet_uplinkpeer}}, @iface_config) if !$config->{$vnet_uplinkpeer};
114
115 @iface_config = ();
116 push @iface_config, "bridge_ports $bridge_ports $vnet_uplinkpeer";
117 push @iface_config, "bridge_stp off";
118 push @iface_config, "bridge_fd 0";
119 push(@{$config->{$bridgevlan}}, @iface_config) if !$config->{$bridgevlan};
120 }
121
122 #vnet bridge
123 @iface_config = ();
124 push @iface_config, "bridge_ports $vnet_uplink";
125 push @iface_config, "bridge_stp off";
126 push @iface_config, "bridge_fd 0";
127 if($vnet->{vlanaware}) {
128 push @iface_config, "bridge-vlan-aware yes";
129 push @iface_config, "bridge-vids 2-4094";
130 }
131 push @iface_config, "mtu $mtu" if $mtu;
132 push @iface_config, "alias $alias" if $alias;
133 push(@{$config->{$vnetid}}, @iface_config) if !$config->{$vnetid};
134
135 return $config;
136 }
137
138 sub status {
139 my ($class, $plugin_config, $zone, $vnetid, $vnet, $status) = @_;
140
141 my $bridge = $plugin_config->{bridge};
142
143 my $err_msg = [];
144 if (!-d "/sys/class/net/$bridge") {
145 push @$err_msg, "missing $bridge";
146 return $err_msg;
147 }
148
149 my $vlan_aware = PVE::Tools::file_read_firstline("/sys/class/net/$bridge/bridge/vlan_filtering");
150 my $is_ovs = !-d "/sys/class/net/$bridge/brif";
151
152 my $tag = $vnet->{tag};
153 my $vnet_uplink = "ln_".$vnetid;
154 my $vnet_uplinkpeer = "pr_".$vnetid;
155
156 # ifaces to check
157 my $ifaces = [ $vnetid, $bridge ];
158 if($is_ovs) {
159 push @$ifaces, $vnet_uplink;
160 } elsif (!$vlan_aware) {
161 my $bridgevlan = $bridge."v".$tag;
162 push @$ifaces, $bridgevlan;
163 push @$ifaces, $vnet_uplink;
164 push @$ifaces, $vnet_uplinkpeer;
165 }
166
167 foreach my $iface (@{$ifaces}) {
168 if (!$status->{$iface}->{status}) {
169 push @$err_msg, "missing $iface";
170 } elsif ($status->{$iface}->{status} ne 'pass') {
171 push @$err_msg, "error iface $iface";
172 }
173 }
174 return $err_msg;
175 }
176
177 sub vnet_update_hook {
178 my ($class, $vnet_cfg, $vnetid, $zone_cfg) = @_;
179
180 my $vnet = $vnet_cfg->{ids}->{$vnetid};
181 my $tag = $vnet->{tag};
182
183 raise_param_exc({ tag => "missing vlan tag"}) if !defined($vnet->{tag});
184 raise_param_exc({ tag => "vlan tag max value is 4096"}) if $vnet->{tag} > 4096;
185
186 # verify that tag is not already defined in another vnet on same zone
187 foreach my $id (keys %{$vnet_cfg->{ids}}) {
188 next if $id eq $vnetid;
189 my $othervnet = $vnet_cfg->{ids}->{$id};
190 my $other_tag = $othervnet->{tag};
191 next if $vnet->{zone} ne $othervnet->{zone};
192 raise_param_exc({ tag => "tag $tag already exist in vnet $id"}) if $other_tag && $tag eq $other_tag;
193 }
194 }
195
196 1;
197
198