summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorzsdc <taras@vyos.io>2021-01-29 18:19:30 +0200
committerzsdc <taras@vyos.io>2021-01-29 23:37:03 +0200
commit8129a37a936de781467c4d053f5ad6b1bcf585ba (patch)
treec7cca39f3f59cc1c3f4066c4e02bd4dbdd4981ff
parentdecb5d2d3a3adf27db301f69dc7909fbb8bad561 (diff)
downloadvyos-cloud-init-8129a37a936de781467c4d053f5ad6b1bcf585ba.tar.gz
vyos-cloud-init-8129a37a936de781467c4d053f5ad6b1bcf585ba.zip
T3270: Backported all changes from the equuleus branch
The behavior of VyOS modules was almost totally changed. Therefore instead of changes, here is a list of what is supported by new versions: `cc_vyos.py`: - extended logging for debugging purposes - work with any environment or datasource - all available in VyOS SSH keys (ssh-dss, ssh-rsa, ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ssh-ed25519, ecdsa-sha2-nistp521) with options - both encrypted and plain-text passwords - multiple user accounts - the fallback user creating (default "vyos/vyos") in credentials are missed in a Meta-Data - interfaces configuration using Network-Config v1 or v2 - fallback interface config (DHCP on eth0) if Network-config is not available - both IPv4 and IPv6 addresses in Network-Config - MTU, multiple addresses, DHCP or static addresses, gateway, routes, DNS nameserver, DNS search domain in Network-Config - filtration of a hostname value from metadata - VyOS-specific options from the OVF template - automatically enabling SSH server `cc_vyos_userdata.py`: set and delete configuration commands inside the User-Data (#cloud-config). See details: https://github.com/vyos/vyos-cloud-init/commit/1607eec32641ad93ea211e447336b3366c28de06 Configuration template: - enabled `write_files` module - disabled the `runcmd` module (functionality replaced by `cc_vyos_userdata.py` and `write_files`)
-rw-r--r--cloudinit/config/cc_vyos.py696
-rw-r--r--cloudinit/config/cc_vyos_userdata.py213
-rw-r--r--config/cloud.cfg.tmpl46
3 files changed, 715 insertions, 240 deletions
diff --git a/cloudinit/config/cc_vyos.py b/cloudinit/config/cc_vyos.py
index 6007b1b3..e472a1cd 100644
--- a/cloudinit/config/cc_vyos.py
+++ b/cloudinit/config/cc_vyos.py
@@ -20,300 +20,554 @@
# You should have received a copy of the GNU General Public License
# along with this program. If not, see <http://www.gnu.org/licenses/>.
-import os
import re
-import sys
-import ast
-import subprocess
-
-from ipaddress import IPv4Network
-from cloudinit import stages
-from cloudinit import util
-
+import ipaddress
+from os import path
+from uuid import uuid4
+from cloudinit import log as logging
+from cloudinit.ssh_util import AuthKeyLineParser
from cloudinit.distros import ug_util
from cloudinit.settings import PER_INSTANCE
-
+from cloudinit.sources import INSTANCE_JSON_FILE
+from cloudinit.stages import Init
+from cloudinit.util import load_file, load_json, get_hostname_fqdn
+from cloudinit.sources.DataSourceOVF import get_properties as ovf_get_properties
from vyos.configtree import ConfigTree
+# configure logging
+logger = logging.getLogger(__name__)
+logger.setLevel(logging.DEBUG)
+
frequency = PER_INSTANCE
+
class VyosError(Exception):
"""Raised when the distro runs into an exception when setting vyos config.
This may happen when the ssh pub key format is wrong.
"""
pass
-def set_pass_login(config, user, password, encrypted_pass):
+
+# configure user account with password
+def set_pass_login(config, user, password):
+ # check if a password string is a hash or a plaintext password
+ # the regex from Cloud-init documentation, so we should trust it for this purpose
+ encrypted_pass = re.match(r'\$(1|2a|2y|5|6)(\$.+){2}', password)
if encrypted_pass:
+ logger.debug("Configuring encrypted password for: {}".format(user))
config.set(['system', 'login', 'user', user, 'authentication', 'encrypted-password'], value=password, replace=True)
else:
+ logger.debug("Configuring plaintext password password for: {}".format(user))
config.set(['system', 'login', 'user', user, 'authentication', 'plaintext-password'], value=password, replace=True)
config.set_tag(['system', 'login', 'user'])
- config.set(['system', 'login', 'user', user, 'level'], value='admin', replace=True)
+ # Return True if credentials added
+ return True
-def set_ssh_login(config, log, user, key_string, key_x):
- key_type = None
- key_data = None
- key_name = None
- if key_string == '':
- log.debug("No keys found.")
- return
+# configure user account with ssh key
+def set_ssh_login(config, user, key_string):
+ ssh_parser = AuthKeyLineParser()
+ key_parsed = ssh_parser.parse(key_string)
+ logger.debug("Parsed SSH public key: type: {}, base64: \"{}\", comment: {}, options: {}".format(key_parsed.keytype, key_parsed.base64, key_parsed.comment, key_parsed.options))
- key_parts = key_string.split(None)
+ if key_parsed.keytype not in ['ssh-dss', 'ssh-rsa', 'ecdsa-sha2-nistp256', 'ecdsa-sha2-nistp384', 'ssh-ed25519', 'ecdsa-sha2-nistp521']:
+ logger.error("Key type {} not supported.".format(key_parsed.keytype))
+ return False
- for key in key_parts:
- if 'ssh-dss' in key or 'ssh-rsa' in key:
- key_type = key
+ if not key_parsed.base64:
+ logger.error("Key base64 not defined, wrong ssh key format.")
+ return False
- if key.startswith('AAAAB3NzaC1yc2E') or key.startswith('AAAAB3NzaC1kc3M'):
- key_data = key
+ if not key_parsed.comment:
+ key_parsed.comment = "cloud-init-{}".format(uuid4())
- if not key_type:
- util.logexc(log, 'Key type not defined, wrong ssh key format.')
- return
-
- if not key_data:
- util.logexc(log, 'Key base64 not defined, wrong ssh key format.')
- return
-
- if len(key_parts) > 2:
- if key_parts[2] != key_type or key_parts[2] != key_data:
- key_name = key_parts[2]
- else:
- key_name = "cloud-init-%s" % key_x
- else:
- key_name = "cloud-init-%s" % key_x
-
- config.set(['system', 'login', 'user', user, 'authentication', 'public-keys', key_name , 'key'], value=key_data, replace=True)
- config.set(['system', 'login', 'user', user, 'authentication', 'public-keys', key_name , 'type'], value=key_type, replace=True)
+ config.set(['system', 'login', 'user', user, 'authentication', 'public-keys', key_parsed.comment, 'key'], value=key_parsed.base64, replace=True)
+ config.set(['system', 'login', 'user', user, 'authentication', 'public-keys', key_parsed.comment, 'type'], value=key_parsed.keytype, replace=True)
+ if key_parsed.options:
+ config.set(['system', 'login', 'user', user, 'authentication', 'public-keys', key_parsed.comment, 'options'], value=key_parsed.options, replace=True)
config.set_tag(['system', 'login', 'user'])
config.set_tag(['system', 'login', 'user', user, 'authentication', 'public-keys'])
- config.set(['system', 'login', 'user', user, 'level'], value='admin', replace=True)
-
-
-def set_config_ovf(config, hostname, metadata):
- ip_0 = metadata['ip0']
- mask_0 = metadata['netmask0']
- gateway = metadata['gateway']
- DNS = list(metadata['DNS'].replace(' ', '').split(','))
- NTP = list(metadata['NTP'].replace(' ', '').split(','))
- APIKEY = metadata['APIKEY']
- APIPORT = metadata['APIPORT']
- APIDEBUG = metadata['APIDEBUG']
-
- if ip_0 and ip_0 != 'null' and mask_0 and mask_0 != 'null' and gateway and gateway != 'null':
- cidr = str(IPv4Network('0.0.0.0/' + mask_0).prefixlen)
- ipcidr = ip_0 + '/' + cidr
-
- config.set(['interfaces', 'ethernet', 'eth0', 'address'], value=ipcidr, replace=True)
- config.set_tag(['interfaces', 'ethernet'])
+ logger.debug("Configured SSH public key for user: {}".format(user))
+
+ # Return True if credentials added
+ return True
+
+
+# filter hostname to be sure that it can be applied
+# NOTE: here we cannot attempt to deny anything prohibited, as it is too late.
+# Therefore, we need only pass what is allowed, cutting everything else
+def hostname_filter(hostname):
+ # define regex for alloweed characters and resulted hostname
+ regex_characters = re.compile(r'[a-z0-9.-]', re.IGNORECASE)
+ regex_hostname = re.compile(r'[a-z0-9](([a-z0-9-]\.|[a-z0-9-])*[a-z0-9])?', re.IGNORECASE)
+ # filter characters
+ filtered_characters = ''.join(regex_characters.findall(hostname))
+ # check that hostname start and end by allowed characters and cut unsupported ones, limit to 64 characters total
+ filtered_hostname = regex_hostname.search(filtered_characters).group()[:64]
+
+ if hostname != filtered_hostname:
+ logger.warning("Hostname/domain was filtered: {} -> {}".format(hostname, filtered_hostname))
+ # return safe to apply host-name value
+ return filtered_hostname
+
+
+# configure system parameters from OVF template
+def set_config_ovf(config, ovf_environment):
+ logger.debug("Applying configuration from an OVF template")
+
+ # Check for 'null' values and replace them by the 'None'
+ # this make the rest of the code easier
+ for (ovf_property_key, ovf_property_value) in ovf_environment.items():
+ if ovf_property_value == 'null':
+ ovf_environment[ovf_property_key] = None
+
+ # get all variables required for configuration
+ ip_address = ovf_environment['ip0']
+ ip_mask = ovf_environment['netmask0']
+ gateway = ovf_environment['gateway']
+ dns_string = ovf_environment['DNS']
+ ntp_string = ovf_environment['NTP']
+ api_key = ovf_environment['APIKEY']
+ api_port = ovf_environment['APIPORT']
+ api_debug = ovf_environment['APIDEBUG']
+
+ # Configure an interface and default route
+ if ip_address and ip_mask and gateway:
+ ip_address_cidr = ipaddress.ip_interface("{}/{}".format(ip_address, ip_mask)).with_prefixlen
+ logger.debug("Configuring the IP address on the eth0 interface: {}".format(ip_address_cidr))
+ set_ipaddress(config, 'eth0', ip_address_cidr)
+
+ logger.debug("Configuring default route via: {}".format(gateway))
config.set(['protocols', 'static', 'route', '0.0.0.0/0', 'next-hop'], value=gateway, replace=True)
config.set_tag(['protocols', 'static', 'route'])
config.set_tag(['protocols', 'static', 'route', '0.0.0.0/0', 'next-hop'])
else:
- config.set(['interfaces', 'ethernet', 'eth0', 'address'], value='dhcp', replace=True)
- config.set_tag(['interfaces', 'ethernet'])
-
- DNS = [server for server in DNS if server and server != 'null']
- if DNS:
- for server in DNS:
+ logger.debug("Configuring a DHCP client on the eth0 interface (fallback from OVF)")
+ set_ipaddress(config, 'eth0', 'dhcp')
+
+ # Configure DNS servers
+ if dns_string:
+ dns_list = list(dns_string.replace(' ', '').split(','))
+ for server in dns_list:
+ logger.debug("Configuring DNS server: {}".format(server))
config.set(['system', 'name-server'], value=server, replace=False)
- NTP = [server for server in NTP if server and server != 'null']
- if NTP:
- for server in NTP:
+ # Configure NTP servers
+ if ntp_string:
+ ntp_list = list(ntp_string.replace(' ', '').split(','))
+ for server in ntp_list:
+ logger.debug("Configuring NTP server: {}".format(server))
config.set(['system', 'ntp', 'server'], value=server, replace=False)
- config.set_tag(['system', 'ntp', 'server'])
+ config.set_tag(['system', 'ntp', 'server'])
- if APIKEY and APIKEY != 'null':
- config.set(['service', 'https', 'api', 'keys', 'id', 'cloud-init', 'key'], value=APIKEY, replace=True)
+ # Configure API
+ if api_key:
+ logger.debug("Configuring HTTP API key: {}".format(api_key))
+ config.set(['service', 'https', 'api', 'keys', 'id', 'cloud-init', 'key'], value=api_key, replace=True)
config.set_tag(['service', 'https', 'api', 'keys', 'id'])
-
- if APIDEBUG != 'False' and APIKEY and APIKEY != 'null':
+ if api_key and api_port:
+ logger.debug("Configuring HTTP API port: {}".format(api_port))
+ config.set(['service', 'https', 'listen-address', '0.0.0.0', 'listen-port'], value=api_port, replace=True)
+ config.set_tag(['service', 'https', 'listen-address'])
+ if api_key and api_debug != 'False':
+ logger.debug("Enabling HTTP API debug")
config.set(['service', 'https', 'api', 'debug'], replace=True)
- if APIPORT and APIPORT != 'null' and APIKEY and APIKEY != 'null':
- config.set(['service', 'https', 'listen-address', '0.0.0.0', 'listen-port'], value=APIPORT, replace=True)
- config.set_tag(['service', 'https', 'listen-address'])
- config.set(['service', 'ssh'], replace=True)
- config.set(['service', 'ssh', 'port'], value='22', replace=True)
-
- if hostname and hostname != 'null':
- config.set(['system', 'host-name'], value=hostname, replace=True)
+# get an IP address type
+def get_ip_type(address):
+ addr_type = None
+ if address in ['dhcp', 'dhcpv6']:
+ addr_type = address
else:
- config.set(['system', 'host-name'], value='vyos', replace=True)
-
-
-def set_config_interfaces(config, interface):
- for item in interface['subnets']:
- if item['type'] == 'static':
- if 'address' in item and runcommand("/usr/bin/ipaddrcheck --is-ipv4 " + item['address']) == 0:
- cidr = str(IPv4Network('0.0.0.0/' + item['netmask']).prefixlen)
- ipcidr = item['address'] + '/' + cidr
- config.set(['interfaces', 'ethernet', interface['name'], 'address'], value=ipcidr, replace=True)
- config.set_tag(['interfaces', 'ethernet'])
- if item['gateway']:
- config.set(['protocols', 'static', 'route', '0.0.0.0/0', 'next-hop'], value=item['gateway'], replace=True)
- config.set_tag(['protocols', 'static', 'route'])
- config.set_tag(['protocols', 'static', 'route', '0.0.0.0/0', 'next-hop'])
+ try:
+ ip_version = ipaddress.ip_interface(address).version
+ if ip_version == 4:
+ addr_type = 'ipv4'
+ if ip_version == 6:
+ addr_type = 'ipv6'
+ except Exception as err:
+ logger.error("Unable to detect IP address type: {}".format(err))
+ logger.debug("IP address {} have type: {}".format(address, addr_type))
+ return addr_type
+
+
+# configure IP address for interface
+def set_ipaddress(config, iface, address):
+ # detect an IP address type
+ addr_type = get_ip_type(address)
+ if not addr_type:
+ logger.error("Unable to configure the IP address: {}".format(address))
+ return
- if 'address' in item and runcommand("/usr/bin/ipaddrcheck --is-ipv6 " + item['address']) == 0:
- config.set(['interfaces', 'ethernet', interface['name'], 'address'], value=item['address'], replace=False)
- config.set_tag(['interfaces', 'ethernet'])
- if item['gateway']:
- config.set(['protocols', 'static', 'route6', '::/0', 'next-hop'], value=item['gateway'], replace=True)
- config.set_tag(['protocols', 'static', 'route6'])
- config.set_tag(['protocols', 'static', 'route6', '::/0', 'next-hop'])
- else:
- config.set(['interfaces', 'ethernet', interface['name'], 'address'], value='dhcp', replace=True)
- config.set_tag(['interfaces', 'ethernet'])
+ # check a current configuration of an interface
+ if config.exists(['interfaces', 'ethernet', iface, 'address']):
+ current_addresses = config.return_values(['interfaces', 'ethernet', iface, 'address'])
+ logger.debug("IP address for interface {} already configured: {}".format(iface, current_addresses))
+ # check if currently configured addresses can be used with new one
+ incompatible_addresses = []
+ for current_address in current_addresses:
+ # dhcp cannot be used with static IP address at the same time
+ if ((addr_type == 'dhcp' and get_ip_type(current_address) == 'ipv4') or
+ (addr_type == 'ipv4' and get_ip_type(current_address) == 'dhcp') or
+ (addr_type == 'dhcpv6' and get_ip_type(current_address) == 'ipv6') or
+ (addr_type == 'ipv6' and get_ip_type(current_address) == 'dhcpv6')):
+ incompatible_addresses.append(current_address)
+ # inform about error and skip configuration
+ if incompatible_addresses:
+ logger.error("IP address {} cannot be configured, because it conflicts with already exists: {}".format(address, incompatible_addresses))
+ return
+
+ # configure address
+ logger.debug("Configuring IP address {} on interface {}".format(address, iface))
+ config.set(['interfaces', 'ethernet', iface, 'address'], value=address, replace=False)
+ config.set_tag(['interfaces', 'ethernet'])
-def set_config_nameserver(config, log, interface):
- if 'address' in interface:
- for server in interface['address']:
- config.set(['system', 'name-server'], value=server, replace=False)
- else:
- log.debug("No name-servers found.")
- if 'search' in interface:
- for server in interface['search']:
- config.set(['system', 'domain-search'], value=server, replace=False)
- else:
- log.debug("No search-domains found.")
+# configure interface from networking config version 1
+def set_config_interfaces_v1(config, iface_config):
+ logger.debug("Configuring network using Cloud-init networking config version 1")
+ # configure physical interfaces
+ if iface_config['type'] == 'physical':
+ iface_name = iface_config['name']
+ # configre MTU
+ if 'mtu' in iface_config:
+ logger.debug("Setting MTU for {}: {}".format(iface_name, iface_config['mtu']))
+ config.set(['interfaces', 'ethernet', iface_name, 'mtu'], value=iface_config['mtu'], replace=True)
+ config.set_tag(['interfaces', 'ethernet'])
+ # configure subnets
+ if 'subnets' in iface_config:
+ for subnet in iface_config['subnets']:
+ # configure DHCP client
+ if subnet['type'] in ['dhcp', 'dhcp4', 'dhcp6']:
+ if subnet['type'] == 'dhcp6':
+ set_ipaddress(config, iface_name, 'dhcpv6')
+ else:
+ set_ipaddress(config, iface_name, 'dhcp')
+
+ continue
+
+ # configure static options
+ if subnet['type'] in ['static', 'static6']:
+ # configure IP address
+ try:
+ ip_interface = ipaddress.ip_interface(subnet['address'])
+ ip_version = ip_interface.version
+ ip_address = ip_interface.ip.compressed
+ ip_static_addr = ''
+ # format IPv4
+ if ip_version == 4 and ip_address != '0.0.0.0':
+ if '/' in subnet['address']:
+ ip_static_addr = ip_interface.compressed
+ else:
+ ip_static_addr = ipaddress.IPv4Interface('{}/{}'.format(ip_address, subnet['netmask'])).compressed
+ # format IPv6
+ if ip_version == 6:
+ ip_static_addr = ip_interface.compressed
+ # apply to the configuration
+ if ip_static_addr:
+ set_ipaddress(config, iface_name, ip_static_addr)
+ except Exception as err:
+ logger.error("Impossible to configure static IP address: {}".format(err))
+
+ # configure gateway
+ if 'gateway' in subnet and subnet['gateway'] != '0.0.0.0':
+ logger.debug("Configuring gateway for {}: {}".format(iface_name, subnet['gateway']))
+ config.set(['protocols', 'static', 'route', '0.0.0.0/0', 'next-hop'], value=subnet['gateway'], replace=True)
+ config.set_tag(['protocols', 'static', 'route'])
+ config.set_tag(['protocols', 'static', 'route', '0.0.0.0/0', 'next-hop'])
+
+ # configure routes
+ if 'routes' in subnet:
+ for item in subnet['routes']:
+ try:
+ ip_network = ipaddress.ip_network('{}/{}'.format(item['network'], item['netmask']))
+ if ip_network.version == 4:
+ logger.debug("Configuring IPv4 route on {}: {} via {}".format(iface_name, ip_network.compressed, item['gateway']))
+ config.set(['protocols', 'static', 'route', ip_network.compressed, 'next-hop'], value=item['gateway'], replace=True)
+ config.set_tag(['protocols', 'static', 'route'])
+ config.set_tag(['protocols', 'static', 'route', ip_network.compressed, 'next-hop'])
+ if ip_network.version == 6:
+ logger.debug("Configuring IPv6 route on {}: {} via {}".format(iface_name, ip_network.compressed, item['gateway']))
+ config.set(['protocols', 'static', 'route6', ip_network.compressed, 'next-hop'], value=item['gateway'], replace=True)
+ config.set_tag(['protocols', 'static', 'route6'])
+ config.set_tag(['protocols', 'static', 'route6', ip_network.compressed, 'next-hop'])
+ except Exception as err:
+ logger.error("Impossible to detect IP protocol version: {}".format(err))
+
+ # configure nameservers
+ if 'dns_nameservers' in subnet:
+ for item in subnet['dns_nameservers']:
+ logger.debug("Configuring DNS nameserver for {}: {}".format(iface_name, item))
+ config.set(['system', 'name-server'], value=item, replace=False)
+
+ if 'dns_search' in subnet:
+ for item in subnet['dns_search']:
+ logger.debug("Configuring DNS search domain for {}: {}".format(iface_name, item))
+ config.set(['system', 'domain-search'], value=item, replace=False)
+
+ # configure nameservers
+ if iface_config['type'] == 'nameserver':
+ for item in iface_config['address']:
+ logger.debug("Configuring DNS nameserver: {}".format(item))
+ config.set(['system', 'name-server'], value=item, replace=False)
+
+ if 'search' in iface_config:
+ for item in iface_config['search']:
+ logger.debug("Configuring DNS search domain: {}".format(item))
+ config.set(['system', 'domain-search'], value=item, replace=False)
+
+ # configure routes
+ if iface_config['type'] == 'route':
+ try:
+ ip_network = ipaddress.ip_network(iface_config['destination'])
+ if ip_network.version == 4:
+ logger.debug("Configuring IPv4 route: {} via {}".format(ip_network.compressed, iface_config['gateway']))
+ config.set(['protocols', 'static', 'route', ip_network.compressed, 'next-hop'], value=iface_config['gateway'], replace=True)
+ config.set_tag(['protocols', 'static', 'route'])
+ config.set_tag(['protocols', 'static', 'route', ip_network.compressed, 'next-hop'])
+ if 'metric' in iface_config:
+ config.set(['protocols', 'static', 'route', ip_network.compressed, 'next-hop', iface_config['gateway'], 'distance'], value=iface_config['metric'], replace=True)
+ if ip_network.version == 6:
+ logger.debug("Configuring IPv6 route: {} via {}".format(ip_network.compressed, iface_config['gateway']))
+ config.set(['protocols', 'static', 'route6', ip_network.compressed, 'next-hop'], value=iface_config['gateway'], replace=True)
+ config.set_tag(['protocols', 'static', 'route6'])
+ config.set_tag(['protocols', 'static', 'route6', ip_network.compressed, 'next-hop'])
+ if 'metric' in iface_config:
+ config.set(['protocols', 'static', 'route6', ip_network.compressed, 'next-hop', iface_config['gateway'], 'distance'], value=iface_config['metric'], replace=True)
+ except Exception as err:
+ logger.error("Impossible to detect IP protocol version: {}".format(err))
+
+
+# configure interface from networking config version 2
+def set_config_interfaces_v2(config, iface_name, iface_config):
+ logger.debug("Configuring network using Cloud-init networking config version 2")
+ # configure DHCP client
+ if 'dhcp4' in iface_config:
+ if iface_config['dhcp4'] is True:
+ set_ipaddress(config, iface_name, 'dhcp')
+ if 'dhcp6' in iface_config:
+ if iface_config['dhcp6'] is True:
+ set_ipaddress(config, iface_name, 'dhcpv6')
+
+ # configure static addresses
+ if 'addresses' in iface_config:
+ for item in iface_config['addresses']:
+ set_ipaddress(config, iface_name, item)
+
+ # configure gateways
+ if 'gateway4' in iface_config:
+ logger.debug("Configuring IPv4 gateway for {}: {}".format(iface_name, iface_config['gateway4']))
+ config.set(['protocols', 'static', 'route', '0.0.0.0/0', 'next-hop'], value=iface_config['gateway4'], replace=True)
+ config.set_tag(['protocols', 'static', 'route'])
+ config.set_tag(['protocols', 'static', 'route', '0.0.0.0/0', 'next-hop'])
+ if 'gateway6' in iface_config:
+ logger.debug("Configuring IPv6 gateway for {}: {}".format(iface_name, iface_config['gateway6']))
+ config.set(['protocols', 'static', 'route6', '::/0', 'next-hop'], value=iface_config['gateway6'], replace=True)
+ config.set_tag(['protocols', 'static', 'route6'])
+ config.set_tag(['protocols', 'static', 'route6', '::/0', 'next-hop'])
+
+ # configre MTU
+ if 'mtu' in iface_config:
+ logger.debug("Setting MTU for {}: {}".format(iface_name, iface_config['mtu']))
+ config.set(['interfaces', 'ethernet', iface_name, 'mtu'], value=iface_config['mtu'], replace=True)
+ config.set_tag(['interfaces', 'ethernet'])
+ # configure routes
+ if 'routes' in iface_config:
+ for item in iface_config['routes']:
+ try:
+ if ipaddress.ip_network(item['to']).version == 4:
+ logger.debug("Configuring IPv4 route on {}: {} via {}".format(iface_name, item['to'], item['via']))
+ config.set(['protocols', 'static', 'route', item['to'], 'next-hop'], value=item['via'], replace=True)
+ config.set_tag(['protocols', 'static', 'route'])
+ config.set_tag(['protocols', 'static', 'route', item['to'], 'next-hop'])
+ if ipaddress.ip_network(item['to']).version == 6:
+ logger.debug("Configuring IPv6 route on {}: {} via {}".format(iface_name, item['to'], item['via']))
+ config.set(['protocols', 'static', 'route6', item['to'], 'next-hop'], value=item['via'], replace=True)
+ config.set_tag(['protocols', 'static', 'route6'])
+ config.set_tag(['protocols', 'static', 'route6', item['to'], 'next-hop'])
+ except Exception as err:
+ logger.error("Impossible to detect IP protocol version: {}".format(err))
+
+ # configure nameservers
+ if 'nameservers' in iface_config:
+ if 'search' in iface_config['nameservers']:
+ for item in iface_config['nameservers']['search']:
+ logger.debug("Configuring DNS search domain for {}: {}".format(iface_name, item))
+ config.set(['system', 'domain-search'], value=item, replace=False)
+ if 'addresses' in iface_config['nameservers']:
+ for item in iface_config['nameservers']['addresses']:
+ logger.debug("Configuring DNS nameserver for {}: {}".format(iface_name, item))
+ config.set(['system', 'name-server'], value=item, replace=False)
+
+
+# configure DHCP client for eth0 interface (fallback)
def set_config_dhcp(config):
- config.set(['interfaces', 'ethernet', 'eth0', 'address'], value='dhcp', replace=True)
- config.set_tag(['interfaces', 'ethernet'])
+ logger.debug("Configuring DHCPv4 on eth0 interface (fallback)")
+ set_ipaddress(config, 'eth0', 'dhcp')
+# configure SSH server service
def set_config_ssh(config):
+ logger.debug("Configuring SSH service")
config.set(['service', 'ssh'], replace=True)
config.set(['service', 'ssh', 'port'], value='22', replace=True)
config.set(['service', 'ssh', 'client-keepalive-interval'], value='180', replace=True)
-def set_config_hostname(config, hostname):
- config.set(['system', 'host-name'], value=hostname, replace=True)
-
-
-def set_config_cloud(config, hostname):
- config.set(['service', 'ssh'], replace=True)
- config.set(['service', 'ssh', 'port'], value='22', replace=True)
- config.set(['service', 'ssh', 'client-keepalive-interval'], value='180', replace=True)
- config.set(['interfaces', 'ethernet', 'eth0', 'address'], value='dhcp', replace=True)
- config.set_tag(['interfaces', 'ethernet'])
- config.set(['system', 'host-name'], value=hostname, replace=True)
-
-
-def runcommand(cmd):
- proc = subprocess.Popen(cmd,
- stdout=subprocess.PIPE,
- stderr=subprocess.PIPE,
- shell=True,
- universal_newlines=True)
- std_out, std_err = proc.communicate()
- return proc.returncode
+# configure hostname
+def set_config_hostname(config, hostname, fqdn):
+ if hostname:
+ logger.debug("Configuring hostname to: {}".format(hostname_filter(hostname)))
+ config.set(['system', 'host-name'], value=hostname_filter(hostname), replace=True)
+ if fqdn:
+ try:
+ domain_name = fqdn.partition("{}.".format(hostname))[2]
+ logger.debug("Configuring domain-name to: {}".format(hostname_filter(domain_name)))
+ config.set(['system', 'domain-name'], value=hostname_filter(domain_name), replace=True)
+ except Exception as err:
+ logger.error("Failed to configure domain-name: {}".format(err))
+# main config handler
def handle(name, cfg, cloud, log, _args):
- init = stages.Init()
- dc = init.fetch()
+ logger.debug("Cloud-init config: {}".format(cfg))
+ # fetch all required data from Cloud-init
+ # Datasource name
+ dsname = cloud.datasource.dsname
+ logger.debug("Datasource: {}".format(dsname))
+ # Metadata (datasource specific)
+ metadata_ds = cloud.datasource.metadata
+ logger.debug("Meta-Data ds: {}".format(metadata_ds))
+ # Metadata in stable v1 format (the same structure for all datasources)
+ instance_data_json = load_json(load_file("{}/{}".format(cloud.datasource.paths.run_dir, INSTANCE_JSON_FILE)))
+ metadata_v1 = instance_data_json.get('v1')
+ logger.debug("Meta-Data v1: {}".format(metadata_v1))
+ # User-Data
+ userdata = cloud.datasource.userdata
+ logger.debug("User-Data: {}".format(userdata))
+ # Vendor-Data
+ vendordata = cloud.datasource.vendordata
+ logger.debug("Vendor-Data: {}".format(vendordata))
+ # Network-config
+ init_stage = Init()
+ (netcfg, netcfg_src) = init_stage._find_networking_config()
+ logger.debug("Network-config: {}".format(netcfg))
+ logger.debug("Network-config source: {}".format(netcfg_src))
+ # Hostname with FQDN (if exist)
+ (hostname, fqdn) = get_hostname_fqdn(cfg, cloud, metadata_only=True)
+ logger.debug("Hostname: {}, FQDN: {}".format(hostname, fqdn))
+ # Get users list
+ (users, _) = ug_util.normalize_users_groups(cfg, cloud.distro)
+ logger.debug("Users: {}".format(users))
+ (default_user, default_user_config) = ug_util.extract_default(users)
+ logger.debug("Default user: {}".format(default_user))
+ # Get OVF properties
+ if 'OVF' in dsname:
+ ovf_environment = ovf_get_properties(cloud.datasource.environment)
+ logger.debug("OVF environment: {}".format(ovf_environment))
+
+ # VyOS configuration file selection
cfg_file_name = '/opt/vyatta/etc/config/config.boot'
bak_file_name = '/opt/vyatta/etc/config.boot.default'
- metadata = cloud.datasource.metadata
- (netcfg, _) = init._find_networking_config()
- (users, _) = ug_util.normalize_users_groups(cfg, cloud.distro)
- (hostname, _) = util.get_hostname_fqdn(cfg, cloud)
- key_x = 1
- key_y = 0
- # look at data that can be used for configuration
- #print(dir(dc))
-
- if not os.path.exists(cfg_file_name):
+ # open configuration file
+ if not path.exists(cfg_file_name):
file_name = bak_file_name
else:
file_name = cfg_file_name
+ logger.debug("Using configuration file: {}".format(file_name))
with open(file_name, 'r') as f:
config_file = f.read()
config = ConfigTree(config_file)
- if 'Azure' in dc.dsname:
- encrypted_pass = True
- for key, val in users.items():
- user = key
-
- if 'passwd' in val:
- password = val.get('passwd')
- set_pass_login(config, user, password, encrypted_pass)
-
- vyos_keys = metadata['public-keys']
+ # Initialization of variables
+ DEFAULT_VYOS_USER = 'vyos'
+ DEFAULT_VYOS_PASSWORD = 'vyos'
+ logins_configured = False
+ network_configured = False
+
+ # configure system logins
+ # Prepare SSH public keys for default user, to be sure that global keys applied to the default account (if it exist)
+ ssh_keys = metadata_v1['public_ssh_keys']
+ # append SSH keys from cloud-config
+ ssh_keys.extend(cfg.get('ssh_authorized_keys', []))
+ # Configure authentication for default user account
+ if default_user:
+ # key-based
+ for ssh_key in ssh_keys:
+ if set_ssh_login(config, default_user, ssh_key):
+ logins_configured = True
+ # password-based
+ password = cfg.get('password')
+ if password:
+ if set_pass_login(config, default_user, password):
+ logins_configured = True
+
+ # Configure all users accounts
+ for user, user_cfg in users.items():
+ # Configure password-based authentication
+ password = user_cfg.get('passwd')
+ if password and password != '':
+ if set_pass_login(config, user, password):
+ logins_configured = True
+
+ # Configure key-based authentication
+ for ssh_key in user_cfg.get('ssh_authorized_keys', []):
+ if set_ssh_login(config, user, ssh_key):
+ logins_configured = True
+
+ # Create a fallback user if there was no others
+ if not logins_configured:
+ logger.debug("Adding fallback user: {}".format(DEFAULT_VYOS_USER))
+ set_pass_login(config, DEFAULT_VYOS_USER, DEFAULT_VYOS_PASSWORD)
+
+ # apply settings from OVF template
+ if 'OVF' in dsname:
+ set_config_ovf(config, ovf_environment)
+ # Empty hostname option may be interpreted as 'null' string by some hypervisors
+ # we need to replace it to the empty value to process it later properly
+ if hostname and hostname == 'null':
+ hostname = None
+ network_configured = True
+
+ # process networking configuration data
+ if netcfg and network_configured is False:
+ # check which one version of config we have
+ # version 1
+ if netcfg['version'] == 1:
+ for interface_config in netcfg['config']:
+ set_config_interfaces_v1(config, interface_config)
+ network_configured = True
+
+ # version 2
+ if netcfg['version'] == 2:
+ if 'ethernets' in netcfg:
+ for interface_name, interface_config in netcfg['ethernets'].items():
+ set_config_interfaces_v2(config, interface_name, interface_config)
+ network_configured = True
+
+ # enable DHCPv4 on eth0 if network still not configured
+ if network_configured is False:
+ set_config_dhcp(config)
- for ssh_key in vyos_keys:
- set_ssh_login(config, log, user, ssh_key, key_x)
- key_x = key_x + 1
+ # enable SSH service
+ set_config_ssh(config)
+ # configure hostname and domain
+ if hostname:
+ set_config_hostname(config, hostname, fqdn)
else:
- encrypted_pass = False
- for (user, user_cfg) in users.items():
- password = None
-
- if "passwd" in user_cfg:
- password = user_cfg["passwd"]
-
- if "password" in user_cfg:
- password = user_cfg["password"]
-
- if password and password != '':
- hash = re.match("(^\$.\$)", password)
- hash_count = password.count('$')
- if hash and hash_count >= 3:
- base64 = password.split('$')[3]
- base_64_len = len(base64)
- if ((hash.group(1) == '$1$' and base_64_len == 22) or
- (hash.group(1) == '$5$' and base_64_len == 43) or
- (hash.group(1) == '$6$' and base_64_len == 86)):
- encrypted_pass = True
- set_pass_login(config, user, password, encrypted_pass)
-
- vyos_keys = cloud.get_public_ssh_keys() or []
- if 'ssh_authorized_keys' in user_cfg:
- cfgkeys = user_cfg['ssh_authorized_keys']
- vyos_keys.extend(cfgkeys)
-
- for ssh_key in vyos_keys:
- set_ssh_login(config, log, user, ssh_key, key_x)
- key_x = key_x + 1
-
- if 'OVF' in dc.dsname:
- set_config_ovf(config, hostname, metadata)
- key_y = 1
- elif netcfg:
- for interface in netcfg['config']:
- if interface['type'] == 'physical':
- key_y = 1
- set_config_interfaces(config, interface)
-
- if interface['type'] == 'nameserver':
- set_config_nameserver(config, log, interface)
-
- set_config_ssh(config)
- set_config_hostname(config, hostname)
- else:
- set_config_dhcp(config)
- set_config_ssh(config)
- set_config_hostname(config, hostname)
-
- if key_y == 0:
- set_config_dhcp(config)
+ set_config_hostname(config, 'vyos', None)
+ # save a new configuration file
try:
with open(cfg_file_name, 'w') as f:
f.write(config.to_string())
+ logger.debug("Configuration file saved: {}".format(cfg_file_name))
except Exception as e:
- util.logexc(log, "Failed to write configs into file %s error %s", file_name, e)
+ logger.error("Failed to write configs into file {}: {}".format(cfg_file_name, e))
diff --git a/cloudinit/config/cc_vyos_userdata.py b/cloudinit/config/cc_vyos_userdata.py
new file mode 100644
index 00000000..c10e417a
--- /dev/null
+++ b/cloudinit/config/cc_vyos_userdata.py
@@ -0,0 +1,213 @@
+# vi: ts=4 expandtab
+#
+# Copyright (C) 2020 Sentrium S.L.
+#
+# This program is free software: you can redistribute it and/or modify
+# it under the terms of the GNU General Public License version 3, as
+# published by the Free Software Foundation.
+#
+# This program is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with this program. If not, see <http://www.gnu.org/licenses/>.
+
+import re
+from pathlib import Path
+from cloudinit import log as logging
+from cloudinit.settings import PER_INSTANCE
+from vyos.configtree import ConfigTree
+
+# configure logging
+logger = logging.getLogger(__name__)
+logger.setLevel(logging.DEBUG)
+
+frequency = PER_INSTANCE
+# path to templates directory, required for analyzing nodes
+TEMPLATES_DIR = '/opt/vyatta/share/vyatta-cfg/templates/'
+# VyOS configuration files
+CFG_FILE_MAIN = '/opt/vyatta/etc/config/config.boot'
+CFG_FILE_DEFAULT = '/opt/vyatta/etc/config.boot.default'
+
+
+# get list of all tag nodes
+def get_tag_nodes():
+ try:
+ logger.debug("Searching for tag nodes in configuration templates")
+ tag_nodes = []
+ # search for node.tag directories
+ node_tag_dirs = Path(TEMPLATES_DIR).rglob('node.tag')
+ # add each found directory to tag nodes list
+ for node_tag in node_tag_dirs:
+ current_node_path = node_tag.relative_to(TEMPLATES_DIR).parent.parts
+ tag_nodes.append(current_node_path)
+ logger.debug("Tag nodes: {}".format(tag_nodes))
+ return tag_nodes
+ except Exception as err:
+ logger.error("Failed to find tag nodes: {}".format(err))
+
+
+# get list of all multi nodes
+def get_multi_nodes():
+ try:
+ logger.debug("Searching for multi nodes in configuration templates")
+ multi_nodes = []
+ # search for node.def files
+ node_def_files = Path(TEMPLATES_DIR).rglob('node.def')
+ # prepare filter to match multi node files
+ regex_filter = re.compile(r'^multi:$', re.MULTILINE)
+ # add each node.def with multi mark to list
+ for node_def_file in node_def_files:
+ file_content = node_def_file.open().read()
+ if regex_filter.search(file_content):
+ current_multi_path = node_def_file.relative_to(
+ TEMPLATES_DIR).parent.parts
+ multi_nodes.append(current_multi_path)
+ logger.debug("Multi nodes: {}".format(multi_nodes))
+ return multi_nodes
+ except Exception as err:
+ logger.error("Failed to find multi nodes: {}".format(err))
+
+
+# check if a node is inside a list of nodes
+def inside_nodes_list(node_path, nodes_list):
+ match = False
+ # compare with all items in list
+ for list_item in nodes_list:
+ # continue only if lengths are equal
+ if len(list_item) == len(node_path):
+ # match parts of nodes paths one by one
+ for element_id in list(range(len(node_path))):
+ # break is items does not match
+ if not (node_path[element_id] == list_item[element_id] or
+ list_item[element_id] == 'node.tag'):
+ break
+ # match as tag node only if both nodes have the same length
+ elif ((node_path[element_id] == list_item[element_id] or
+ list_item[element_id] == 'node.tag') and
+ element_id == len(node_path) - 1):
+ match = True
+ # break if we have a match
+ if match is True:
+ break
+ return match
+
+
+# convert string to command (action + path + value)
+def string_to_command(stringcmd):
+ # regex to split string to action + path + value
+ regex_filter = re.compile(
+ r'^(?P<cmd_action>set|delete) (?P<cmd_path>[^\']+)( \'(?P<cmd_value>.*)\')*$'
+ )
+ if regex_filter.search(stringcmd):
+ # command structure
+ command = {
+ 'cmd_action':
+ regex_filter.search(stringcmd).group('cmd_action'),
+ 'cmd_path':
+ regex_filter.search(stringcmd).group('cmd_path').split(),
+ 'cmd_value':
+ regex_filter.search(stringcmd).group('cmd_value')
+ }
+ return command
+ else:
+ return None
+
+
+# helper: mark nodes as tag in config, if this is necessary
+def mark_tag(config, node_path, tag_nodes):
+ current_node_path = []
+ # check and mark each element in command path if necessary
+ for current_node in node_path:
+ current_node_path.append(current_node)
+ if inside_nodes_list(current_node_path, tag_nodes):
+ logger.debug(
+ "Marking node as tag: \"{}\"".format(current_node_path))
+ config.set_tag(current_node_path)
+
+
+# apply "set" command
+def apply_command_set(config, tag_nodes, multi_nodes, command):
+ # if a node is multi type add value instead replacing
+ replace_option = not inside_nodes_list(command['cmd_path'], multi_nodes)
+ if not replace_option:
+ logger.debug("{} is a multi node, adding value".format(
+ command['cmd_path']))
+
+ config.set(command['cmd_path'],
+ command['cmd_value'],
+ replace=replace_option)
+
+ # mark configured nodes as tag, if this is necessary
+ mark_tag(config, command['cmd_path'], tag_nodes)
+
+
+# apply "delete" command
+def apply_command_delete(config, command):
+ # delete a value
+ if command['cmd_value']:
+ config.delete_value(command['cmd_path'], command['cmd_value'])
+ # otherwise delete path
+ else:
+ config.delete(command['cmd_path'])
+
+
+# apply command
+def apply_commands(config, commands_list):
+ # get all tag and multi nodes
+ tag_nodes = get_tag_nodes()
+ multi_nodes = get_multi_nodes()
+
+ # roll through configration commands
+ for command_line in commands_list:
+ # convert command to format, appliable to configuration
+ command = string_to_command(command_line)
+ # if conversion is successful, apply the command
+ if command:
+ logger.debug("Configuring command: \"{}\"".format(command_line))
+ try:
+ if command['cmd_action'] == 'set':
+ apply_command_set(config, tag_nodes, multi_nodes, command)
+ if command['cmd_action'] == 'delete':
+ apply_command_delete(config, command)
+ except Exception as err:
+ logger.error("Unable to configure command: {}".format(err))
+
+
+# main config handler
+def handle(name, cfg, cloud, log, _args):
+ # Get commands list to configure
+ commands_list = cfg.get('vyos_config_commands', [])
+ logger.debug("Commands to configure: {}".format(commands_list))
+
+ if commands_list:
+ # open configuration file
+ if Path(CFG_FILE_MAIN).exists():
+ config_file_path = CFG_FILE_MAIN
+ else:
+ config_file_path = CFG_FILE_DEFAULT
+
+ logger.debug("Using configuration file: {}".format(config_file_path))
+ with open(config_file_path, 'r') as f:
+ config_file = f.read()
+ # load a file content into a config object
+ config = ConfigTree(config_file)
+
+ # Add configuration from the vyos_config_commands cloud-config section
+ try:
+ apply_commands(config, commands_list)
+ except Exception as err:
+ logger.error(
+ "Failed to apply configuration commands: {}".format(err))
+
+ # save a new configuration file
+ try:
+ with open(config_file_path, 'w') as f:
+ f.write(config.to_string())
+ logger.debug(
+ "Configuration file saved: {}".format(config_file_path))
+ except Exception as err:
+ logger.error("Failed to write config into the file {}: {}".format(
+ config_file_path, err))
diff --git a/config/cloud.cfg.tmpl b/config/cloud.cfg.tmpl
index 0847ab3d..be06edfc 100644
--- a/config/cloud.cfg.tmpl
+++ b/config/cloud.cfg.tmpl
@@ -1,36 +1,44 @@
-## template:jinja
-# The top level settings are used as module
-# and system configuration.
+# This will cause the set+update hostname module to not operate (if true)
+preserve_hostname: true
+# Do not change SSH password-based authentication settings
+ssh_pwauth: unchanged
+
+# Configuring Azure datasource
datasource:
Azure:
agent_command: [/usr/bin/python3, -u, /usr/sbin/waagent, -start]
-# This will cause the set+update hostname module to not operate (if true)
-preserve_hostname: true
+# disable customization for VMware
+disable_vmware_customization: true
-users:
- - default
+# The modules that run in the 'init' stage
+cloud_init_modules:
# The modules that run in the 'config' stage
cloud_config_modules:
- - vyos
+ - vyos
+ - write_files
+ - vyos_userdata
# The modules that run in the 'final' stage
cloud_final_modules:
- - runcmd
+# Users, necessary for Cloud-init 18.4
+users:
+ - default
# System and/or distro specific settings
# (not accessible to handlers/transforms)
system_info:
- # This will affect which distro class gets used
- distro: debian
- # Default user name + that default users groups (if added/used)
- default_user:
- name: vyos
- # Other config here will be given to the distro class and/or path classes
- paths:
- cloud_dir: /opt/vyatta/etc/config/cloud/
- templates_dir: /etc/cloud/templates/
- upstart_dir: /etc/init/
+ # This will affect which distro class gets used
+ distro: debian
+ # Default user name + that default users groups (if added/used)
+ default_user:
+ name: vyos
+ # Other config here will be given to the distro class and/or path classes
+ paths:
+ cloud_dir: /opt/vyatta/etc/config/cloud/
+ templates_dir: /etc/cloud/templates/
+ upstart_dir: /etc/init/
+