]> git.proxmox.com Git - qemu-server.git/blame - PVE/QemuServer/Cloudinit.pm
d/control: bump versioned dependency for libpve-guest-common-perl (>= 3.0-4)
[qemu-server.git] / PVE / QemuServer / Cloudinit.pm
CommitLineData
0c9a7596
AD
1package PVE::QemuServer::Cloudinit;
2
3use strict;
4use warnings;
5
6use File::Path;
7use Digest::SHA;
8use URI::Escape;
9
10use PVE::Tools qw(run_command file_set_contents);
11use PVE::Storage;
12use PVE::QemuServer;
13
7d761a01
ML
14use constant CLOUDINIT_DISK_SIZE => 4 * 1024 * 1024; # 4MiB in bytes
15
0c9a7596 16sub commit_cloudinit_disk {
4a853915 17 my ($conf, $vmid, $drive, $volname, $storeid, $files, $label) = @_;
f62c36cf
WB
18
19 my $path = "/run/pve/cloudinit/$vmid/";
20 mkpath $path;
21 foreach my $filepath (keys %$files) {
22 if ($filepath !~ m@^(.*)\/[^/]+$@) {
23 die "internal error: bad file name in cloud-init image: $filepath\n";
24 }
25 my $dirname = $1;
26 mkpath "$path/$dirname";
27
28 my $contents = $files->{$filepath};
29 file_set_contents("$path/$filepath", $contents);
30 }
41cd94a0
WB
31
32 my $storecfg = PVE::Storage::config();
33 my $iso_path = PVE::Storage::path($storecfg, $drive->{file});
34 my $scfg = PVE::Storage::storage_config($storecfg, $storeid);
7e8ab2a9 35 my $format = PVE::QemuServer::qemu_img_format($scfg, $volname);
b56d56cf 36
9a13f0fe
ML
37 my $size = eval { PVE::Storage::volume_size_info($storecfg, $drive->{file}) };
38 if (!defined($size) || $size <= 0) {
92fcaab7 39 $volname =~ m/(vm-$vmid-cloudinit(.\Q$format\E)?)/;
7e8ab2a9 40 my $name = $1;
84821d15
TL
41 $size = 4 * 1024;
42 PVE::Storage::vdisk_alloc($storecfg, $storeid, $vmid, $format, $name, $size);
43 $size *= 1024; # vdisk alloc takes KB, qemu-img dd's osize takes byte
7e8ab2a9 44 }
9a13f0fe
ML
45 my $plugin = PVE::Storage::Plugin->lookup($scfg->{type});
46 $plugin->activate_volume($storeid, $scfg, $volname);
7e8ab2a9 47
f62c36cf 48 eval {
8ebf1734 49 run_command([['genisoimage', '-iso-level', '3', '-R', '-V', $label, $path],
f0a762f7 50 ['qemu-img', 'dd', '-n', '-f', 'raw', '-O', $format,
f62c36cf
WB
51 'isize=0', "osize=$size", "of=$iso_path"]]);
52 };
53 my $err = $@;
54 rmtree($path);
55 die $err if $err;
0c9a7596
AD
56}
57
41cd94a0
WB
58sub get_cloudinit_format {
59 my ($conf) = @_;
60 if (defined(my $format = $conf->{citype})) {
61 return $format;
62 }
0c9a7596 63
41cd94a0
WB
64 # No format specified, default based on ostype because windows'
65 # cloudbased-init only supports configdrivev2, whereas on linux we need
66 # to use mac addresses because regular cloudinit doesn't map 'ethX' to
67 # the new predicatble network device naming scheme.
68 if (defined(my $ostype = $conf->{ostype})) {
69 return 'configdrive2'
70 if PVE::QemuServer::windows_version($ostype);
71 }
0c9a7596 72
41cd94a0 73 return 'nocloud';
0c9a7596
AD
74}
75
e8ac2138 76sub get_hostname_fqdn {
9a6ccb12
DC
77 my ($conf, $vmid) = @_;
78 my $hostname = $conf->{name} // "VM$vmid";
e8ac2138
WB
79 my $fqdn;
80 if ($hostname =~ /\./) {
81 $fqdn = $hostname;
82 $hostname =~ s/\..*$//;
83 } elsif (my $search = $conf->{searchdomain}) {
84 $fqdn = "$hostname.$search";
0c9a7596 85 }
e8ac2138 86 return ($hostname, $fqdn);
41cd94a0
WB
87}
88
67864d19
WB
89sub get_dns_conf {
90 my ($conf) = @_;
91
92 # Same logic as in pve-container, but without the testcase special case
93 my $host_resolv_conf = PVE::INotify::read_file('resolvconf');
94
95 my $searchdomains = [
96 split(/\s+/, $conf->{searchdomain} // $host_resolv_conf->{search})
97 ];
98
99 my $nameserver = $conf->{nameserver};
100 if (!defined($nameserver)) {
101 $nameserver = [grep { $_ } $host_resolv_conf->@{qw(dns1 dns2 dns3)}];
102 } else {
103 $nameserver = [split(/\s+/, $nameserver)];
104 }
105
106 return ($searchdomains, $nameserver);
107}
108
41cd94a0 109sub cloudinit_userdata {
9a6ccb12 110 my ($conf, $vmid) = @_;
41cd94a0 111
9a6ccb12 112 my ($hostname, $fqdn) = get_hostname_fqdn($conf, $vmid);
41cd94a0 113
7b42f951 114 my $content = "#cloud-config\n";
41cd94a0 115
e8ac2138 116 $content .= "hostname: $hostname\n";
8de34458 117 $content .= "manage_etc_hosts: true\n";
e8ac2138
WB
118 $content .= "fqdn: $fqdn\n" if defined($fqdn);
119
7b42f951
WB
120 my $username = $conf->{ciuser};
121 my $password = $conf->{cipassword};
41cd94a0
WB
122
123 $content .= "user: $username\n" if defined($username);
7b42f951
WB
124 $content .= "disable_root: False\n" if defined($username) && $username eq 'root';
125 $content .= "password: $password\n" if defined($password);
41cd94a0
WB
126
127 if (defined(my $keys = $conf->{sshkeys})) {
0c9a7596
AD
128 $keys = URI::Escape::uri_unescape($keys);
129 $keys = [map { chomp $_; $_ } split(/\n/, $keys)];
130 $keys = [grep { /\S/ } @$keys];
41cd94a0 131 $content .= "ssh_authorized_keys:\n";
0c9a7596 132 foreach my $k (@$keys) {
41cd94a0 133 $content .= " - $k\n";
0c9a7596
AD
134 }
135 }
41cd94a0
WB
136 $content .= "chpasswd:\n";
137 $content .= " expire: False\n";
138
7b42f951
WB
139 if (!defined($username) || $username ne 'root') {
140 $content .= "users:\n";
141 $content .= " - default\n";
142 }
0c9a7596
AD
143
144 $content .= "package_upgrade: true\n";
145
0c9a7596
AD
146 return $content;
147}
148
86280789
WB
149sub split_ip4 {
150 my ($ip) = @_;
151 my ($addr, $mask) = split('/', $ip);
152 die "not a CIDR: $ip\n" if !defined $mask;
153 return ($addr, $PVE::Network::ipv4_reverse_mask->[$mask]);
154}
155
41cd94a0
WB
156sub configdrive2_network {
157 my ($conf) = @_;
0c9a7596
AD
158
159 my $content = "auto lo\n";
67864d19
WB
160 $content .= "iface lo inet loopback\n\n";
161
162 my ($searchdomains, $nameservers) = get_dns_conf($conf);
163 if ($nameservers && @$nameservers) {
164 $nameservers = join(' ', @$nameservers);
165 $content .= " dns_nameservers $nameservers\n";
166 }
167 if ($searchdomains && @$searchdomains) {
168 $searchdomains = join(' ', @$searchdomains);
169 $content .= " dns_search $searchdomains\n";
170 }
0c9a7596
AD
171
172 my @ifaces = grep(/^net(\d+)$/, keys %$conf);
173 foreach my $iface (@ifaces) {
174 (my $id = $iface) =~ s/^net//;
175 next if !$conf->{"ipconfig$id"};
41cd94a0 176 my $net = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig$id"});
0c9a7596
AD
177 $id = "eth$id";
178
179 $content .="auto $id\n";
180 if ($net->{ip}) {
181 if ($net->{ip} eq 'dhcp') {
182 $content .= "iface $id inet dhcp\n";
183 } else {
86280789 184 my ($addr, $mask) = split_ip4($net->{ip});
0c9a7596 185 $content .= "iface $id inet static\n";
6f3999e0
ML
186 $content .= " address $addr\n";
187 $content .= " netmask $mask\n";
188 $content .= " gateway $net->{gw}\n" if $net->{gw};
0c9a7596
AD
189 }
190 }
191 if ($net->{ip6}) {
192 if ($net->{ip6} =~ /^(auto|dhcp)$/) {
193 $content .= "iface $id inet6 $1\n";
194 } else {
195 my ($addr, $mask) = split('/', $net->{ip6});
196 $content .= "iface $id inet6 static\n";
6f3999e0
ML
197 $content .= " address $addr\n";
198 $content .= " netmask $mask\n";
199 $content .= " gateway $net->{gw6}\n" if $net->{gw6};
0c9a7596
AD
200 }
201 }
202 }
203
0c9a7596
AD
204 return $content;
205}
206
e73ca4d0
ML
207sub configdrive2_gen_metadata {
208 my ($user, $network) = @_;
209
210 my $uuid_str = Digest::SHA::sha1_hex($user.$network);
211 return configdrive2_metadata($uuid_str);
212}
213
41cd94a0
WB
214sub configdrive2_metadata {
215 my ($uuid) = @_;
216 return <<"EOF";
217{
218 "uuid": "$uuid",
219 "network_config": { "content_path": "/content/0000" }
220}
221EOF
222}
223
224sub generate_configdrive2 {
225 my ($conf, $vmid, $drive, $volname, $storeid) = @_;
226
cb702ebe
DL
227 my ($user_data, $network_data, $meta_data) = get_custom_cloudinit_files($conf);
228 $user_data = cloudinit_userdata($conf, $vmid) if !defined($user_data);
229 $network_data = configdrive2_network($conf) if !defined($network_data);
41cd94a0 230
cb702ebe 231 if (!defined($meta_data)) {
e73ca4d0 232 $meta_data = configdrive2_gen_metadata($user_data, $network_data);
cb702ebe 233 }
f62c36cf
WB
234 my $files = {
235 '/openstack/latest/user_data' => $user_data,
236 '/openstack/content/0000' => $network_data,
237 '/openstack/latest/meta_data.json' => $meta_data
238 };
4a853915 239 commit_cloudinit_disk($conf, $vmid, $drive, $volname, $storeid, $files, 'config-2');
41cd94a0
WB
240}
241
242sub nocloud_network_v2 {
243 my ($conf) = @_;
244
245 my $content = '';
246
247 my $head = "version: 2\n"
248 . "ethernets:\n";
249
67864d19 250 my $dns_done;
41cd94a0
WB
251
252 my @ifaces = grep(/^net(\d+)$/, keys %$conf);
253 foreach my $iface (@ifaces) {
254 (my $id = $iface) =~ s/^net//;
255 next if !$conf->{"ipconfig$id"};
256
257 # indentation - network interfaces are inside an 'ethernets' hash
258 my $i = ' ';
259
260 my $net = PVE::QemuServer::parse_net($conf->{$iface});
261 my $ipconfig = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig$id"});
262
263 my $mac = $net->{macaddr}
264 or die "network interface '$iface' has no mac address\n";
265
67864d19 266 $content .= "${i}$iface:\n";
41cd94a0 267 $i .= ' ';
67864d19
WB
268 $content .= "${i}match:\n"
269 . "${i} macaddress: \"$mac\"\n"
270 . "${i}set-name: eth$id\n";
41cd94a0
WB
271 my @addresses;
272 if (defined(my $ip = $ipconfig->{ip})) {
273 if ($ip eq 'dhcp') {
67864d19 274 $content .= "${i}dhcp4: true\n";
41cd94a0
WB
275 } else {
276 push @addresses, $ip;
277 }
278 }
279 if (defined(my $ip = $ipconfig->{ip6})) {
280 if ($ip eq 'dhcp') {
67864d19 281 $content .= "${i}dhcp6: true\n";
41cd94a0
WB
282 } else {
283 push @addresses, $ip;
284 }
285 }
286 if (@addresses) {
67864d19 287 $content .= "${i}addresses:\n";
4efb58a9 288 $content .= "${i}- '$_'\n" foreach @addresses;
41cd94a0
WB
289 }
290 if (defined(my $gw = $ipconfig->{gw})) {
4efb58a9 291 $content .= "${i}gateway4: '$gw'\n";
41cd94a0
WB
292 }
293 if (defined(my $gw = $ipconfig->{gw6})) {
4efb58a9 294 $content .= "${i}gateway6: '$gw'\n";
41cd94a0
WB
295 }
296
67864d19
WB
297 next if $dns_done;
298 $dns_done = 1;
299
300 my ($searchdomains, $nameservers) = get_dns_conf($conf);
301 if ($searchdomains || $nameservers) {
302 $content .= "${i}nameservers:\n";
303 if (defined($nameservers) && @$nameservers) {
304 $content .= "${i} addresses:\n";
4efb58a9 305 $content .= "${i} - '$_'\n" foreach @$nameservers;
67864d19
WB
306 }
307 if (defined($searchdomains) && @$searchdomains) {
308 $content .= "${i} search:\n";
4efb58a9 309 $content .= "${i} - '$_'\n" foreach @$searchdomains;
41cd94a0
WB
310 }
311 }
41cd94a0
WB
312 }
313
314 return $head.$content;
315}
316
317sub nocloud_network {
318 my ($conf) = @_;
319
320 my $content = "version: 1\n"
321 . "config:\n";
322
323 my @ifaces = grep(/^net(\d+)$/, keys %$conf);
324 foreach my $iface (@ifaces) {
325 (my $id = $iface) =~ s/^net//;
326 next if !$conf->{"ipconfig$id"};
327
328 # indentation - network interfaces are inside an 'ethernets' hash
329 my $i = ' ';
330
331 my $net = PVE::QemuServer::parse_net($conf->{$iface});
332 my $ipconfig = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig$id"});
333
c3cedb3d 334 my $mac = lc($net->{macaddr})
41cd94a0
WB
335 or die "network interface '$iface' has no mac address\n";
336
67864d19
WB
337 $content .= "${i}- type: physical\n"
338 . "${i} name: eth$id\n"
4efb58a9 339 . "${i} mac_address: '$mac'\n"
67864d19 340 . "${i} subnets:\n";
41cd94a0
WB
341 $i .= ' ';
342 if (defined(my $ip = $ipconfig->{ip})) {
343 if ($ip eq 'dhcp') {
67864d19 344 $content .= "${i}- type: dhcp4\n";
41cd94a0 345 } else {
86280789 346 my ($addr, $mask) = split_ip4($ip);
67864d19 347 $content .= "${i}- type: static\n"
4efb58a9
DL
348 . "${i} address: '$addr'\n"
349 . "${i} netmask: '$mask'\n";
41cd94a0 350 if (defined(my $gw = $ipconfig->{gw})) {
4efb58a9 351 $content .= "${i} gateway: '$gw'\n";
41cd94a0
WB
352 }
353 }
354 }
355 if (defined(my $ip = $ipconfig->{ip6})) {
356 if ($ip eq 'dhcp') {
67864d19 357 $content .= "${i}- type: dhcp6\n";
c701be32
DL
358 } elsif ($ip eq 'auto') {
359 # SLAAC is not supported by cloud-init, this fallback should work with an up-to-date netplan at least
360 $content .= "${i}- type: dhcp6\n";
41cd94a0 361 } else {
8d54522b 362 $content .= "${i}- type: static\n"
4efb58a9 363 . "${i} address: '$ip'\n";
41cd94a0 364 if (defined(my $gw = $ipconfig->{gw6})) {
4efb58a9 365 $content .= "${i} gateway: '$gw'\n";
41cd94a0
WB
366 }
367 }
368 }
41cd94a0
WB
369 }
370
67864d19
WB
371 my $i = ' ';
372 my ($searchdomains, $nameservers) = get_dns_conf($conf);
373 if ($searchdomains || $nameservers) {
41cd94a0 374 $content .= "${i}- type: nameserver\n";
67864d19 375 if (defined($nameservers) && @$nameservers) {
41cd94a0 376 $content .= "${i} address:\n";
4efb58a9 377 $content .= "${i} - '$_'\n" foreach @$nameservers;
41cd94a0 378 }
67864d19 379 if (defined($searchdomains) && @$searchdomains) {
41cd94a0 380 $content .= "${i} search:\n";
4efb58a9 381 $content .= "${i} - '$_'\n" foreach @$searchdomains;
41cd94a0
WB
382 }
383 }
384
385 return $content;
386}
387
388sub nocloud_metadata {
e8ac2138
WB
389 my ($uuid) = @_;
390 return "instance-id: $uuid\n";
41cd94a0
WB
391}
392
e73ca4d0
ML
393sub nocloud_gen_metadata {
394 my ($user, $network) = @_;
395
396 my $uuid_str = Digest::SHA::sha1_hex($user.$network);
397 return nocloud_metadata($uuid_str);
398}
399
41cd94a0
WB
400sub generate_nocloud {
401 my ($conf, $vmid, $drive, $volname, $storeid) = @_;
402
cb702ebe
DL
403 my ($user_data, $network_data, $meta_data) = get_custom_cloudinit_files($conf);
404 $user_data = cloudinit_userdata($conf, $vmid) if !defined($user_data);
405 $network_data = nocloud_network($conf) if !defined($network_data);
41cd94a0 406
cb702ebe 407 if (!defined($meta_data)) {
e73ca4d0 408 $meta_data = nocloud_gen_metadata($user_data, $network_data);
cb702ebe 409 }
41cd94a0 410
f62c36cf
WB
411 my $files = {
412 '/user-data' => $user_data,
413 '/network-config' => $network_data,
414 '/meta-data' => $meta_data
415 };
4a853915 416 commit_cloudinit_disk($conf, $vmid, $drive, $volname, $storeid, $files, 'cidata');
41cd94a0
WB
417}
418
cb702ebe
DL
419sub get_custom_cloudinit_files {
420 my ($conf) = @_;
421
422 my $cicustom = $conf->{cicustom};
423 my $files = $cicustom ? PVE::JSONSchema::parse_property_string('pve-qm-cicustom', $cicustom) : {};
424
425 my $network_volid = $files->{network};
426 my $user_volid = $files->{user};
427 my $meta_volid = $files->{meta};
428
429 my $storage_conf = PVE::Storage::config();
430
431 my $network_data;
432 if ($network_volid) {
433 $network_data = read_cloudinit_snippets_file($storage_conf, $network_volid);
434 }
435
436 my $user_data;
437 if ($user_volid) {
438 $user_data = read_cloudinit_snippets_file($storage_conf, $user_volid);
439 }
440
441 my $meta_data;
442 if ($meta_volid) {
443 $meta_data = read_cloudinit_snippets_file($storage_conf, $meta_volid);
444 }
445
446 return ($user_data, $network_data, $meta_data);
447}
448
449sub read_cloudinit_snippets_file {
450 my ($storage_conf, $volid) = @_;
451
452 my ($full_path, undef, $type) = PVE::Storage::path($storage_conf, $volid);
453 die "$volid is not in the snippets directory\n" if $type ne 'snippets';
7e8ab2a9 454 return PVE::Tools::file_get_contents($full_path, 1 * 1024 * 1024);
cb702ebe
DL
455}
456
41cd94a0
WB
457my $cloudinit_methods = {
458 configdrive2 => \&generate_configdrive2,
459 nocloud => \&generate_nocloud,
460};
461
462sub generate_cloudinitconfig {
463 my ($conf, $vmid) = @_;
464
465 my $format = get_cloudinit_format($conf);
466
467 PVE::QemuServer::foreach_drive($conf, sub {
468 my ($ds, $drive) = @_;
469
470 my ($storeid, $volname) = PVE::Storage::parse_volume_id($drive->{file}, 1);
471
472 return if !$volname || $volname !~ m/vm-$vmid-cloudinit/;
473
474 my $generator = $cloudinit_methods->{$format}
475 or die "missing cloudinit methods for format '$format'\n";
476
477 $generator->($conf, $vmid, $drive, $volname, $storeid);
478 });
479}
0c9a7596 480
e73ca4d0
ML
481sub dump_cloudinit_config {
482 my ($conf, $vmid, $type) = @_;
483
484 my $format = get_cloudinit_format($conf);
485
486 if ($type eq 'user') {
487 return cloudinit_userdata($conf, $vmid);
488 } elsif ($type eq 'network') {
489 if ($format eq 'nocloud') {
490 return nocloud_network($conf);
491 } else {
492 return configdrive2_network($conf);
493 }
494 } else { # metadata config
495 my $user = cloudinit_userdata($conf, $vmid);
496 if ($format eq 'nocloud') {
497 my $network = nocloud_network($conf);
498 return nocloud_gen_metadata($user, $network);
499 } else {
500 my $network = configdrive2_network($conf);
501 return configdrive2_gen_metadata($user, $network);
502 }
503 }
504}
505
0c9a7596 5061;