summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2025-05-13Merge pull request #4502 from c-po/pam-nologinJohn Estabrook
T7443: Un-restricting non-root logins after scheduled reboot/shutdown via pam_nologin
2025-05-13validators: T7450: use PCRE2 instead of the outdated original PCREDaniil Baturin
2025-05-13Merge pull request #4503 from aapostoliuk/T7157-circinus-fix2Daniil Baturin
T7157: bgp: Added verification of the route-map existence in vrf import
2025-05-12Merge pull request #4483 from markh0338/remote-group-v6Christian Breunig
T7386: firewall: Allow IPv6 member in firewall remote-groups
2025-05-12T7157: bgp: Added verification of the route-map existence in vrf importaapostoliuk
Added verification of the route-map existence in the vrf route-leaking.
2025-05-12Merge pull request #4500 from dmbaturin/T7411-frr-restart-fixDaniil Baturin
frr: T7411: preserve FRR config on service restart if it exists
2025-05-12Merge pull request #4494 from c-po/haproxy-loggingDaniil Baturin
haproxy: T7429: remove unsupported logging facility and log level
2025-05-09T7443: Un-restricting non-root logins after scheduled reboot/shutdown via ↵Christian Breunig
pam_nologin When using reboot in, reboot at, or shutdown in, non-root users are prevented from logging in via SSH or console starting 5 minutes before the scheduled shutdown or reboot time. This behavior is intended by pam_nologin.so, which is included in the SSH and login PAM stack (default on Debian). While expected, it may be inconvenient and could be reconsidered.
2025-05-09Merge pull request #4491 from sever-sever/T7423Viacheslav Hletenko
T7423: Add kernel boot options isolcpus, hugepages, numa_balancing
2025-05-09policy: T5069: large-community-list regex validator should allow whitespaceAndrew Topp
* Re-introduce the whitespace/pattern matches ' ' and '_' as allowed * Perform a general Python regex validity check (not 100% 1003.2, but in combination with allowedChars, pretty close) * Introduce a warning against potentially malformed or over-complex patterns, but leave it up to the user to resolve - there are plenty of useful expressions we cannot validate easily
2025-05-08haproxy: T7429: remove unsupported logging facility and log levelChristian Breunig
VyOS 1.4.1 implemented support for logging facilities for HAProxy. The facilities got included from the syslog XML definition, which also added "virtual" or non existing facilities in HAProxy, namely: all, authpriv and mark. If any of the above facilities is set, HAProxy will not start. The XML definition for syslog also came with an arbitrary log-level "all" that is also unsupported in HAProxy. This commit adds a migration script removing the illegal CLI nodes.
2025-05-08frr: T7411: preserve FRR config on service restart if it existsDaniil Baturin
2025-05-08T7423: Add kernel boot options isolcpus, hugepages, numa_balancingViacheslav Hletenko
Add kernel options which apply during the boot: - isolcpus - nohz_full - rcu_nocbs - default_hugepagesz - hugepages - hugepagesz - numa_balancing - hpet - mce - nosoftlockup - nmi_watchdog CLI: ``` set system option kernel cpu disable-nmi-watchdog set system option kernel cpu isolate-cpus '1,2,4-5' set system option kernel cpu nohz-full '1,2,4-5' set system option kernel cpu rcu-no-cbs '1,2,4-5' set system option kernel disable-hpet set system option kernel disable-mce set system option kernel disable-softlockup set system option kernel memory default-hugepage-size '2M' set system option kernel memory disable-numa-balancing set system option kernel memory hugepage-size 1G hugepage-count '2' set system option kernel memory hugepage-size 2M hugepage-count '512' ```
2025-05-08Merge pull request #4484 from ryanzuwala/T7051Daniil Baturin
nat66: T7051: snat group as destination
2025-05-08Merge pull request #4323 from xeluior/T7095_vrf-fixDaniil Baturin
utils: T7095: make `vrf` and `netns` arguments aware of the shell
2025-05-07T7386: firewall: use signal SIGPIPE/SIG_DFL to suppress brokenpipe errors on ↵Mark Hayes
large output
2025-05-07T7386: firewall: allow mix of IPv4 and IPv6 addresses/prefixes/ranges in ↵Mark Hayes
remote groups
2025-05-07prometheus: T7435: Ensure only configured prometheus exporters are startedopswill
2025-05-06Merge pull request #4493 from jestabro/vrf-migration-err-1-to-2Daniil Baturin
T7417: check existence of paths before set_tag/return_value in migration scripts vrf/1-to-2; vrf/2-to-3
2025-05-06Merge pull request #4495 from c-po/frr-logDaniil Baturin
frr: T7431: missing logging options after rewrite to frrender class
2025-05-06Merge pull request #4447 from l0crian1/t7268-show-interfaces-kernelDaniil Baturin
interfaces: T7268: Add op-mode command for show all interfaces on system
2025-05-06Merge pull request #4387 from woodsb02/patch-1Daniil Baturin
installer: T7049: Fix GRUB boot with RAID1
2025-05-06Merge pull request #4480 from c-po/T7122-pkiDaniil Baturin
T7122: pki: unable to switch from custom cert to ACME when HAProxy service is running with 'redirect-http-to-https' option
2025-05-05frr: T7431: missing logging options after rewrite to frrender classChristian Breunig
In src/etc/systemd/system/frr.service.d/override.conf#L6-L11 the log entry is added on restart - but not during normal operation of frrender.py Logging should be added persistent when rendering the FRR configuration using FRRender class.
2025-05-05Bridge: T7430: Add BPDU Guard and Root Guard supportl0crian1
This will add support for BPDU Guard and Root Guard to the bridge interface. Verification will come from: show log spanning-tree
2025-05-05T7417: check existence of table setting before return_valueJohn Estabrook
Migration from 1.3.x may not contain table entries, later required. The migration script should not fail with error, leaving enforcement to config scripts.
2025-05-05T7417: check existence of path before set_tagJohn Estabrook
The migration script assumed the existence of path ['vrf', 'name', tag-val-name, 'protocols', 'static', 'route'] ignoring sole entries for [..., 'route6']. Check existence of each path before calling set_tag.
2025-05-05pki: T7122: when ACME listen-address is used - check if port is availableChristian Breunig
When instructing certbot to listen on a given address, check if the address is free to use. Also take this into account when spawning certbot behind HAProxy. If the address is not (yet) bound - the request must be done in standalone mode and not via the reverse-proxy.
2025-05-05haproxy: T7122: add ACME/certbot bootstrap supportChristian Breunig
When both the CLI PKI node for an ACME-issued certificate and HAProxy are configured during initial setup, the certbot challenge cannot be served via the reverse proxy because HAProxy has not yet been configured at all. This commit introduces a special case to handle this bootstrap scenario, ensuring that the certbot challenge can still be served correctly in standalone mode on port 80 despite initial config dependencies/priorities between PKI and HAProxy.
2025-05-05pki: T7122: extend ca/certificate removal check to listsChristian Breunig
Some VyOS CLI nodes support defining multiple certificates. The previous check when removing a certificate from the CLI only performed a string comparison, which failed in cases where the underlying data was a list (CLI <multi/> node). This update extends the check to handle both cases: - If the datum is a string, perform a string comparison. - If the datum is a list, check whether the target certificate is part of the list. This ensures proper removal behavior regardless of the data type used in the CLI node.
2025-05-05vyos.base: T7122: add new Message() helper wrapper for print()Christian Breunig
This will wrap the messages at 72 characters in the same way as Warning() and DeprecationWarning() would do. We now have simple wrappers for it! Example: vyos@vyos# commit [ pki ] Updating configuration: "load-balancing haproxy service frontend ssl certificate LE_cloud" Add/replace automatically imported CA certificate for "LE_cloud"
2025-05-05Merge pull request #4492 from c-po/ansi-revertDaniil Baturin
Revert "vyos-router: T7356: unset ANSI bold control character during boot"
2025-05-05Merge pull request #4488 from aapostoliuk/T7157-circinus-fixChristian Breunig
bgp: T7157: Fixed error with the unknown key in the verification
2025-05-04Revert "vyos-router: T7356: unset ANSI bold control character during boot"Christian Breunig
This reverts commit ddca20df57008bd85b1363e089152e0ebf014f73.
2025-05-04haproxy: T7122: always reverse-proxy ACL for certbotChristian Breunig
Always enable the ACL entry to reverse-proxy requests to the path "/.well-known/acme-challenge/" when "redirect-http-to-https" is configured for a given HAProxy frontend service. This is an intentional design decision to simplify the implementation and reduce overall code complexity. It poses no risk: a missing path returns a 404, and an unavailable backend yields an error 503. This approach avoids a chicken-and-egg problem where certbot might try to request a certificate via reverse-proxy before the proxy config is actually generated and active. By always routing through HAProxy, we also eliminate downtime as port 80 does not need to be freed for certbot's standalone mode.
2025-05-04Merge pull request #4478 from tjjh89017/T7408Christian Breunig
T7408: add mokutil in arm64
2025-05-04vyos.template: T7122: add Jinja2 clever function helper to read vyos.defaultsChristian Breunig
Add a new category if Jinja2 operands. We already have filters and tests, but sometimes we would like to call a Python function without and data "|" piped to it - that's what they call a clever-function. {{ get_default_port(NAME) }} can be used to retrieve the value from vyos.defaults.internal_ports[NAME] within Jinja2. We no longer need to extend the dictionary with arbitrary data retrieved from vyos.defaults, we can now simply register another clever-function to the Jinja2 backend.
2025-05-04xml: T7122: it is spelled HAProxyChristian Breunig
2025-05-04op-mode: T7122: add "show|monitor log haproxy" commandsChristian Breunig
2025-05-02Merge pull request #4481 from yzguy/T7412Daniil Baturin
T7412: Allow privileged containers
2025-05-01T7390: VPP CGNAT implementation (#30)Nataliia S.
CLI: ``` set vpp nat cgnat interface outside <interface> # multi set vpp nat cgnat interface inside <interface> # multi set vpp nat cgnat rule <rule> outside-prefix <prefix> set vpp nat cgnat rule <rule> inside-prefix <prefix> set vpp nat cgnat timeout udp <sec> # default 300 set vpp nat cgnat timeout tcp-established <sec> # default 7440 set vpp nat cgnat timeout tcp-transitory <sec> # default 240 set vpp nat cgnat timeout icmp <sec> # default 60 ``` OP mode: ``` show vpp nat cgnat interfaces show vpp nat cgnat mappings show vpp nat cgnat sessions clear vpp cgnat inside-address <address> port <port> external-address <address> port <port> ```
2025-05-01Merge pull request #4470 from ryanzuwala/currentDaniil Baturin
router-advert: T7389: Duplicate prefix safeguard
2025-05-01Merge pull request #4489 from dmbaturin/T7420-download-credentialsDaniil Baturin
installer: T7420: pass image download credentials in environment variables
2025-05-01Merge pull request #4472 from sever-sever/T7396Daniil Baturin
T7396: Return the old script to generate tech-support archive
2025-05-01Merge pull request #4452 from Hanarion/patch-1Daniil Baturin
T7364: Fixing Route reflector client check not working for peer-group
2025-05-01QoS: T7415: Fix tcp flags matchingl0crian1
Empty leaf nodes are cleaned, causing the tcp ack and syn flags to not match. These flags were moved to values of the tcp leafNode
2025-04-30installer: T7420: pass image download credentials in environment variablesDaniil Baturin
rather than in the command line
2025-04-30Merge pull request #4476 from ryanzuwala/T6696Daniil Baturin
session: T6696: 'clear session' to 'reset session'
2025-04-30Merge pull request #4485 from jestabro/nginx-bind-requires-restartDaniil Baturin
https: T7393: set listen-address bind fails silently without restart
2025-04-30Merge pull request #4486 from opswill/currentDaniil Baturin
node_exporter: T7416: Add missing backslash in node_exporter.service