]> git.proxmox.com Git - qemu-server.git/blob - PVE/QemuServer/Cloudinit.pm
bump version to 8.2.1
[qemu-server.git] / PVE / QemuServer / Cloudinit.pm
1 package PVE::QemuServer::Cloudinit;
2
3 use strict;
4 use warnings;
5
6 use File::Path;
7 use Digest::SHA;
8 use URI::Escape;
9 use MIME::Base64 qw(encode_base64);
10 use Storable qw(dclone);
11
12 use PVE::Tools qw(run_command file_set_contents);
13 use PVE::Storage;
14 use PVE::QemuServer;
15 use PVE::QemuServer::Helpers;
16
17 use constant CLOUDINIT_DISK_SIZE => 4 * 1024 * 1024; # 4MiB in bytes
18
19 sub commit_cloudinit_disk {
20 my ($conf, $vmid, $drive, $volname, $storeid, $files, $label) = @_;
21
22 my $path = "/run/pve/cloudinit/$vmid/";
23 mkpath $path;
24 foreach my $filepath (keys %$files) {
25 if ($filepath !~ m@^(.*)\/[^/]+$@) {
26 die "internal error: bad file name in cloud-init image: $filepath\n";
27 }
28 my $dirname = $1;
29 mkpath "$path/$dirname";
30
31 my $contents = $files->{$filepath};
32 file_set_contents("$path/$filepath", $contents);
33 }
34
35 my $storecfg = PVE::Storage::config();
36 my $iso_path = PVE::Storage::path($storecfg, $drive->{file});
37 my $scfg = PVE::Storage::storage_config($storecfg, $storeid);
38 my $format = PVE::QemuServer::qemu_img_format($scfg, $volname);
39
40 my $size = eval { PVE::Storage::volume_size_info($storecfg, $drive->{file}) };
41 if (!defined($size) || $size <= 0) {
42 $volname =~ m/(vm-$vmid-cloudinit(.\Q$format\E)?)/;
43 my $name = $1;
44 $size = 4 * 1024;
45 PVE::Storage::vdisk_alloc($storecfg, $storeid, $vmid, $format, $name, $size);
46 $size *= 1024; # vdisk alloc takes KB, qemu-img dd's osize takes byte
47 }
48 my $plugin = PVE::Storage::Plugin->lookup($scfg->{type});
49 $plugin->activate_volume($storeid, $scfg, $volname);
50
51 print "generating cloud-init ISO\n";
52 eval {
53 run_command([
54 ['genisoimage', '-quiet', '-iso-level', '3', '-R', '-V', $label, $path],
55 ['qemu-img', 'dd', '-n', '-f', 'raw', '-O', $format, 'isize=0', "osize=$size", "of=$iso_path"]
56 ]);
57 };
58 my $err = $@;
59 rmtree($path);
60 die $err if $err;
61 }
62
63 sub get_cloudinit_format {
64 my ($conf) = @_;
65 if (defined(my $format = $conf->{citype})) {
66 return $format;
67 }
68
69 # No format specified, default based on ostype because windows'
70 # cloudbased-init only supports configdrivev2, whereas on linux we need
71 # to use mac addresses because regular cloudinit doesn't map 'ethX' to
72 # the new predicatble network device naming scheme.
73 if (defined(my $ostype = $conf->{ostype})) {
74 return 'configdrive2'
75 if PVE::QemuServer::Helpers::windows_version($ostype);
76 }
77
78 return 'nocloud';
79 }
80
81 sub get_hostname_fqdn {
82 my ($conf, $vmid) = @_;
83 my $hostname = $conf->{name} // "VM$vmid";
84 my $fqdn;
85 if ($hostname =~ /\./) {
86 $fqdn = $hostname;
87 $hostname =~ s/\..*$//;
88 } elsif (my $search = $conf->{searchdomain}) {
89 $fqdn = "$hostname.$search";
90 } else {
91 $fqdn = $hostname;
92 }
93 return ($hostname, $fqdn);
94 }
95
96 sub get_dns_conf {
97 my ($conf) = @_;
98
99 # Same logic as in pve-container, but without the testcase special case
100 my $host_resolv_conf = PVE::INotify::read_file('resolvconf');
101
102 my $searchdomains = [
103 split(/\s+/, $conf->{searchdomain} // $host_resolv_conf->{search})
104 ];
105
106 my $nameserver = $conf->{nameserver};
107 if (!defined($nameserver)) {
108 $nameserver = [grep { $_ } $host_resolv_conf->@{qw(dns1 dns2 dns3)}];
109 } else {
110 $nameserver = [split(/\s+/, $nameserver)];
111 }
112
113 return ($searchdomains, $nameserver);
114 }
115
116 sub cloudinit_userdata {
117 my ($conf, $vmid) = @_;
118
119 my ($hostname, $fqdn) = get_hostname_fqdn($conf, $vmid);
120
121 my $content = "#cloud-config\n";
122
123 $content .= "hostname: $hostname\n";
124 $content .= "manage_etc_hosts: true\n";
125 $content .= "fqdn: $fqdn\n";
126
127 my $username = $conf->{ciuser};
128 my $password = $conf->{cipassword};
129
130 $content .= "user: $username\n" if defined($username);
131 $content .= "disable_root: False\n" if defined($username) && $username eq 'root';
132 $content .= "password: $password\n" if defined($password);
133
134 if (defined(my $keys = $conf->{sshkeys})) {
135 $keys = URI::Escape::uri_unescape($keys);
136 $keys = [map { my $key = $_; chomp $key; $key } split(/\n/, $keys)];
137 $keys = [grep { /\S/ } @$keys];
138 $content .= "ssh_authorized_keys:\n";
139 foreach my $k (@$keys) {
140 $content .= " - $k\n";
141 }
142 }
143 $content .= "chpasswd:\n";
144 $content .= " expire: False\n";
145
146 if (!defined($username) || $username ne 'root') {
147 $content .= "users:\n";
148 $content .= " - default\n";
149 }
150
151 $content .= "package_upgrade: true\n" if !defined($conf->{ciupgrade}) || $conf->{ciupgrade};
152
153 return $content;
154 }
155
156 sub split_ip4 {
157 my ($ip) = @_;
158 my ($addr, $mask) = split('/', $ip);
159 die "not a CIDR: $ip\n" if !defined $mask;
160 return ($addr, $PVE::Network::ipv4_reverse_mask->[$mask]);
161 }
162
163 sub configdrive2_network {
164 my ($conf) = @_;
165
166 my $content = "auto lo\n";
167 $content .= "iface lo inet loopback\n\n";
168
169 my ($searchdomains, $nameservers) = get_dns_conf($conf);
170 if ($nameservers && @$nameservers) {
171 $nameservers = join(' ', @$nameservers);
172 $content .= " dns_nameservers $nameservers\n";
173 }
174 if ($searchdomains && @$searchdomains) {
175 $searchdomains = join(' ', @$searchdomains);
176 $content .= " dns_search $searchdomains\n";
177 }
178
179 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
180 foreach my $iface (sort @ifaces) {
181 (my $id = $iface) =~ s/^net//;
182 next if !$conf->{"ipconfig$id"};
183 my $net = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig$id"});
184 $id = "eth$id";
185
186 $content .="auto $id\n";
187 if ($net->{ip}) {
188 if ($net->{ip} eq 'dhcp') {
189 $content .= "iface $id inet dhcp\n";
190 } else {
191 my ($addr, $mask) = split_ip4($net->{ip});
192 $content .= "iface $id inet static\n";
193 $content .= " address $addr\n";
194 $content .= " netmask $mask\n";
195 $content .= " gateway $net->{gw}\n" if $net->{gw};
196 }
197 }
198 if ($net->{ip6}) {
199 if ($net->{ip6} =~ /^(auto|dhcp)$/) {
200 $content .= "iface $id inet6 $1\n";
201 } else {
202 my ($addr, $mask) = split('/', $net->{ip6});
203 $content .= "iface $id inet6 static\n";
204 $content .= " address $addr\n";
205 $content .= " netmask $mask\n";
206 $content .= " gateway $net->{gw6}\n" if $net->{gw6};
207 }
208 }
209 }
210
211 return $content;
212 }
213
214 sub configdrive2_gen_metadata {
215 my ($user, $network) = @_;
216
217 my $uuid_str = Digest::SHA::sha1_hex($user.$network);
218 return configdrive2_metadata($uuid_str);
219 }
220
221 sub configdrive2_metadata {
222 my ($uuid) = @_;
223 return <<"EOF";
224 {
225 "uuid": "$uuid",
226 "network_config": { "content_path": "/content/0000" }
227 }
228 EOF
229 }
230
231 sub generate_configdrive2 {
232 my ($conf, $vmid, $drive, $volname, $storeid) = @_;
233
234 my ($user_data, $network_data, $meta_data, $vendor_data) = get_custom_cloudinit_files($conf);
235 $user_data = cloudinit_userdata($conf, $vmid) if !defined($user_data);
236 $network_data = configdrive2_network($conf) if !defined($network_data);
237 $vendor_data = '' if !defined($vendor_data);
238
239 if (!defined($meta_data)) {
240 $meta_data = configdrive2_gen_metadata($user_data, $network_data);
241 }
242
243 # we always allocate a 4MiB disk for cloudinit and with the overhead of the ISO
244 # make sure we always stay below it by keeping the sum of all files below 3 MiB
245 my $sum = length($user_data) + length($network_data) + length($meta_data) + length($vendor_data);
246 die "Cloud-Init sum of snippets too big (> 3 MiB)\n" if $sum > (3 * 1024 * 1024);
247
248 my $files = {
249 '/openstack/latest/user_data' => $user_data,
250 '/openstack/content/0000' => $network_data,
251 '/openstack/latest/meta_data.json' => $meta_data,
252 '/openstack/latest/vendor_data.json' => $vendor_data
253 };
254 commit_cloudinit_disk($conf, $vmid, $drive, $volname, $storeid, $files, 'config-2');
255 }
256
257 sub generate_opennebula {
258 my ($conf, $vmid, $drive, $volname, $storeid) = @_;
259
260 my $content = "";
261
262 my $username = $conf->{ciuser} || "root";
263 $content .= "USERNAME=$username\n" if defined($username);
264
265 if (defined(my $password = $conf->{cipassword})) {
266 $content .= "CRYPTED_PASSWORD_BASE64=". encode_base64($password) ."\n";
267 }
268
269 if (defined($conf->{sshkeys})) {
270 my $keys = [ split(/\s*\n\s*/, URI::Escape::uri_unescape($conf->{sshkeys})) ];
271 $content .= "SSH_PUBLIC_KEY=\"". join("\n", $keys->@*) ."\"\n";
272 }
273
274 my ($hostname, $fqdn) = get_hostname_fqdn($conf, $vmid);
275 $content .= "SET_HOSTNAME=$hostname\n";
276
277 my ($searchdomains, $nameservers) = get_dns_conf($conf);
278 $content .= 'DNS="' . join(' ', @$nameservers) ."\"\n" if $nameservers && @$nameservers;
279 $content .= 'SEARCH_DOMAIN="'. join(' ', @$searchdomains) ."\"\n" if $searchdomains && @$searchdomains;
280
281 my $networkenabled = undef;
282 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
283 foreach my $iface (sort @ifaces) {
284 (my $id = $iface) =~ s/^net//;
285 my $net = PVE::QemuServer::parse_net($conf->{$iface});
286 next if !$conf->{"ipconfig$id"};
287 my $ipconfig = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig$id"});
288 my $ethid = "ETH$id";
289
290 my $mac = lc $net->{hwaddr};
291
292 if ($ipconfig->{ip}) {
293 $networkenabled = 1;
294
295 if ($ipconfig->{ip} eq 'dhcp') {
296 $content .= "${ethid}_DHCP=YES\n";
297 } else {
298 my ($addr, $mask) = split_ip4($ipconfig->{ip});
299 $content .= "${ethid}_IP=$addr\n";
300 $content .= "${ethid}_MASK=$mask\n";
301 $content .= "${ethid}_MAC=$mac\n";
302 $content .= "${ethid}_GATEWAY=$ipconfig->{gw}\n" if $ipconfig->{gw};
303 }
304 $content .= "${ethid}_MTU=$net->{mtu}\n" if $net->{mtu};
305 }
306
307 if ($ipconfig->{ip6}) {
308 $networkenabled = 1;
309 if ($ipconfig->{ip6} eq 'dhcp') {
310 $content .= "${ethid}_DHCP6=YES\n";
311 } elsif ($ipconfig->{ip6} eq 'auto') {
312 $content .= "${ethid}_AUTO6=YES\n";
313 } else {
314 my ($addr, $mask) = split('/', $ipconfig->{ip6});
315 $content .= "${ethid}_IP6=$addr\n";
316 $content .= "${ethid}_MASK6=$mask\n";
317 $content .= "${ethid}_MAC6=$mac\n";
318 $content .= "${ethid}_GATEWAY6=$ipconfig->{gw6}\n" if $ipconfig->{gw6};
319 }
320 $content .= "${ethid}_MTU=$net->{mtu}\n" if $net->{mtu};
321 }
322 }
323
324 $content .= "NETWORK=YES\n" if $networkenabled;
325
326 my $files = { '/context.sh' => $content };
327 commit_cloudinit_disk($conf, $vmid, $drive, $volname, $storeid, $files, 'CONTEXT');
328 }
329
330 sub nocloud_network_v2 {
331 my ($conf) = @_;
332
333 my $content = '';
334
335 my $head = "version: 2\n"
336 . "ethernets:\n";
337
338 my $dns_done;
339
340 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
341 foreach my $iface (sort @ifaces) {
342 (my $id = $iface) =~ s/^net//;
343 next if !$conf->{"ipconfig$id"};
344
345 # indentation - network interfaces are inside an 'ethernets' hash
346 my $i = ' ';
347
348 my $net = PVE::QemuServer::parse_net($conf->{$iface});
349 my $ipconfig = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig$id"});
350
351 my $mac = $net->{macaddr}
352 or die "network interface '$iface' has no mac address\n";
353
354 $content .= "${i}$iface:\n";
355 $i .= ' ';
356 $content .= "${i}match:\n"
357 . "${i} macaddress: \"$mac\"\n"
358 . "${i}set-name: eth$id\n";
359 my @addresses;
360 if (defined(my $ip = $ipconfig->{ip})) {
361 if ($ip eq 'dhcp') {
362 $content .= "${i}dhcp4: true\n";
363 } else {
364 push @addresses, $ip;
365 }
366 }
367 if (defined(my $ip = $ipconfig->{ip6})) {
368 if ($ip eq 'dhcp') {
369 $content .= "${i}dhcp6: true\n";
370 } else {
371 push @addresses, $ip;
372 }
373 }
374 if (@addresses) {
375 $content .= "${i}addresses:\n";
376 $content .= "${i}- '$_'\n" foreach @addresses;
377 }
378 if (defined(my $gw = $ipconfig->{gw})) {
379 $content .= "${i}gateway4: '$gw'\n";
380 }
381 if (defined(my $gw = $ipconfig->{gw6})) {
382 $content .= "${i}gateway6: '$gw'\n";
383 }
384
385 next if $dns_done;
386 $dns_done = 1;
387
388 my ($searchdomains, $nameservers) = get_dns_conf($conf);
389 if ($searchdomains || $nameservers) {
390 $content .= "${i}nameservers:\n";
391 if (defined($nameservers) && @$nameservers) {
392 $content .= "${i} addresses:\n";
393 $content .= "${i} - '$_'\n" foreach @$nameservers;
394 }
395 if (defined($searchdomains) && @$searchdomains) {
396 $content .= "${i} search:\n";
397 $content .= "${i} - '$_'\n" foreach @$searchdomains;
398 }
399 }
400 }
401
402 return $head.$content;
403 }
404
405 sub nocloud_network {
406 my ($conf) = @_;
407
408 my $content = "version: 1\n"
409 . "config:\n";
410
411 my @ifaces = grep { /^net(\d+)$/ } keys %$conf;
412 foreach my $iface (sort @ifaces) {
413 (my $id = $iface) =~ s/^net//;
414 next if !$conf->{"ipconfig$id"};
415
416 # indentation - network interfaces are inside an 'ethernets' hash
417 my $i = ' ';
418
419 my $net = PVE::QemuServer::parse_net($conf->{$iface});
420 my $ipconfig = PVE::QemuServer::parse_ipconfig($conf->{"ipconfig$id"});
421
422 my $mac = lc($net->{macaddr})
423 or die "network interface '$iface' has no mac address\n";
424
425 $content .= "${i}- type: physical\n"
426 . "${i} name: eth$id\n"
427 . "${i} mac_address: '$mac'\n"
428 . "${i} subnets:\n";
429 $i .= ' ';
430 if (defined(my $ip = $ipconfig->{ip})) {
431 if ($ip eq 'dhcp') {
432 $content .= "${i}- type: dhcp4\n";
433 } else {
434 my ($addr, $mask) = split_ip4($ip);
435 $content .= "${i}- type: static\n"
436 . "${i} address: '$addr'\n"
437 . "${i} netmask: '$mask'\n";
438 if (defined(my $gw = $ipconfig->{gw})) {
439 $content .= "${i} gateway: '$gw'\n";
440 }
441 }
442 }
443 if (defined(my $ip = $ipconfig->{ip6})) {
444 if ($ip eq 'dhcp') {
445 $content .= "${i}- type: dhcp6\n";
446 } elsif ($ip eq 'auto') {
447 # SLAAC is only supported by cloud-init since 19.4
448 $content .= "${i}- type: ipv6_slaac\n";
449 } else {
450 $content .= "${i}- type: static6\n"
451 . "${i} address: '$ip'\n";
452 if (defined(my $gw = $ipconfig->{gw6})) {
453 $content .= "${i} gateway: '$gw'\n";
454 }
455 }
456 }
457 }
458
459 my $i = ' ';
460 my ($searchdomains, $nameservers) = get_dns_conf($conf);
461 if ($searchdomains || $nameservers) {
462 $content .= "${i}- type: nameserver\n";
463 if (defined($nameservers) && @$nameservers) {
464 $content .= "${i} address:\n";
465 $content .= "${i} - '$_'\n" foreach @$nameservers;
466 }
467 if (defined($searchdomains) && @$searchdomains) {
468 $content .= "${i} search:\n";
469 $content .= "${i} - '$_'\n" foreach @$searchdomains;
470 }
471 }
472
473 return $content;
474 }
475
476 sub nocloud_metadata {
477 my ($uuid) = @_;
478 return "instance-id: $uuid\n";
479 }
480
481 sub nocloud_gen_metadata {
482 my ($user, $network) = @_;
483
484 my $uuid_str = Digest::SHA::sha1_hex($user.$network);
485 return nocloud_metadata($uuid_str);
486 }
487
488 sub generate_nocloud {
489 my ($conf, $vmid, $drive, $volname, $storeid) = @_;
490
491 my ($user_data, $network_data, $meta_data, $vendor_data) = get_custom_cloudinit_files($conf);
492 $user_data = cloudinit_userdata($conf, $vmid) if !defined($user_data);
493 $network_data = nocloud_network($conf) if !defined($network_data);
494 $vendor_data = '' if !defined($vendor_data);
495
496 if (!defined($meta_data)) {
497 $meta_data = nocloud_gen_metadata($user_data, $network_data);
498 }
499
500 # we always allocate a 4MiB disk for cloudinit and with the overhead of the ISO
501 # make sure we always stay below it by keeping the sum of all files below 3 MiB
502 my $sum = length($user_data) + length($network_data) + length($meta_data) + length($vendor_data);
503 die "Cloud-Init sum of snippets too big (> 3 MiB)\n" if $sum > (3 * 1024 * 1024);
504
505 my $files = {
506 '/user-data' => $user_data,
507 '/network-config' => $network_data,
508 '/meta-data' => $meta_data,
509 '/vendor-data' => $vendor_data
510 };
511 commit_cloudinit_disk($conf, $vmid, $drive, $volname, $storeid, $files, 'cidata');
512 }
513
514 sub get_custom_cloudinit_files {
515 my ($conf) = @_;
516
517 my $cicustom = $conf->{cicustom};
518 my $files = $cicustom ? PVE::JSONSchema::parse_property_string('pve-qm-cicustom', $cicustom) : {};
519
520 my $network_volid = $files->{network};
521 my $user_volid = $files->{user};
522 my $meta_volid = $files->{meta};
523 my $vendor_volid = $files->{vendor};
524
525 my $storage_conf = PVE::Storage::config();
526
527 my $network_data;
528 if ($network_volid) {
529 $network_data = read_cloudinit_snippets_file($storage_conf, $network_volid);
530 }
531
532 my $user_data;
533 if ($user_volid) {
534 $user_data = read_cloudinit_snippets_file($storage_conf, $user_volid);
535 }
536
537 my $meta_data;
538 if ($meta_volid) {
539 $meta_data = read_cloudinit_snippets_file($storage_conf, $meta_volid);
540 }
541
542 my $vendor_data;
543 if ($vendor_volid) {
544 $vendor_data = read_cloudinit_snippets_file($storage_conf, $vendor_volid);
545 }
546
547 return ($user_data, $network_data, $meta_data, $vendor_data);
548 }
549
550 sub read_cloudinit_snippets_file {
551 my ($storage_conf, $volid) = @_;
552
553 my ($vtype, undef) = PVE::Storage::parse_volname($storage_conf, $volid);
554
555 die "$volid is not in the snippets directory\n" if $vtype ne 'snippets';
556
557 my $full_path = PVE::Storage::abs_filesystem_path($storage_conf, $volid, 1);
558 return PVE::Tools::file_get_contents($full_path, 1 * 1024 * 1024);
559 }
560
561 my $cloudinit_methods = {
562 configdrive2 => \&generate_configdrive2,
563 nocloud => \&generate_nocloud,
564 opennebula => \&generate_opennebula,
565 };
566
567 sub has_changes {
568 my ($conf) = @_;
569
570 return !!$conf->{cloudinit}->%*;
571 }
572
573 sub generate_cloudinit_config {
574 my ($conf, $vmid) = @_;
575
576 my $format = get_cloudinit_format($conf);
577
578 my $has_changes = has_changes($conf);
579
580 PVE::QemuConfig->foreach_volume($conf, sub {
581 my ($ds, $drive) = @_;
582
583 my ($storeid, $volname) = PVE::Storage::parse_volume_id($drive->{file}, 1);
584
585 return if !$volname || $volname !~ m/vm-$vmid-cloudinit/;
586
587 my $generator = $cloudinit_methods->{$format}
588 or die "missing cloudinit methods for format '$format'\n";
589
590 $generator->($conf, $vmid, $drive, $volname, $storeid);
591 });
592
593 return $has_changes;
594 }
595
596 sub apply_cloudinit_config {
597 my ($conf, $vmid) = @_;
598
599 my $has_changes = generate_cloudinit_config($conf, $vmid);
600
601 if ($has_changes) {
602 delete $conf->{cloudinit};
603 PVE::QemuConfig->write_config($vmid, $conf);
604 return 1;
605 }
606
607 return $has_changes;
608 }
609
610 sub dump_cloudinit_config {
611 my ($conf, $vmid, $type) = @_;
612
613 my $format = get_cloudinit_format($conf);
614
615 if ($type eq 'user') {
616 return cloudinit_userdata($conf, $vmid);
617 } elsif ($type eq 'network') {
618 if ($format eq 'nocloud') {
619 return nocloud_network($conf);
620 } else {
621 return configdrive2_network($conf);
622 }
623 } else { # metadata config
624 my $user = cloudinit_userdata($conf, $vmid);
625 if ($format eq 'nocloud') {
626 my $network = nocloud_network($conf);
627 return nocloud_gen_metadata($user, $network);
628 } else {
629 my $network = configdrive2_network($conf);
630 return configdrive2_gen_metadata($user, $network);
631 }
632 }
633 }
634
635 1;