mirror of
https://github.com/MengMengCode/CLICD.git
synced 2026-08-06 13:54:44 +08:00
Compare commits
9 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| bb0c4f999d | |||
| 0c9f420474 | |||
| 9a826add87 | |||
| 63611dc932 | |||
| e6551bf4ae | |||
| 5bf2b6534a | |||
| 917afc3157 | |||
| c8081edbac | |||
| 95eb00a31d |
@@ -0,0 +1,15 @@
|
||||
# These are supported funding model platforms
|
||||
|
||||
github: # Replace with up to 4 GitHub Sponsors-enabled usernames e.g., [user1, user2]
|
||||
patreon: # Replace with a single Patreon username
|
||||
open_collective: # Replace with a single Open Collective username
|
||||
ko_fi: # Replace with a single Ko-fi username
|
||||
tidelift: # Replace with a single Tidelift platform-name/package-name e.g., npm/babel
|
||||
community_bridge: # Replace with a single Community Bridge project-name e.g., cloud-foundry
|
||||
liberapay: # Replace with a single Liberapay username
|
||||
issuehunt: # Replace with a single IssueHunt username
|
||||
lfx_crowdfunding: # Replace with a single LFX Crowdfunding project-name e.g., cloud-foundry
|
||||
polar: # Replace with a single Polar username
|
||||
buy_me_a_coffee: mengmengcode
|
||||
thanks_dev: # Replace with a single thanks.dev username
|
||||
custom: # Replace with up to 4 custom sponsorship URLs e.g., ['link1', 'link2']
|
||||
@@ -4,15 +4,6 @@
|
||||
|
||||
<h1 align="center">CLICD</h1>
|
||||
|
||||
<p align="center">
|
||||
<img alt="Release" src="https://img.shields.io/github/v/release/MengMengCode/CLICD?style=flat-square">
|
||||
<img alt="Stars" src="https://img.shields.io/github/stars/MengMengCode/CLICD?style=flat-square">
|
||||
<img alt="Forks" src="https://img.shields.io/github/forks/MengMengCode/CLICD?style=flat-square">
|
||||
<img alt="Downloads" src="https://img.shields.io/github/downloads/MengMengCode/CLICD/total?style=flat-square">
|
||||
<img alt="Last Commit" src="https://img.shields.io/github/last-commit/MengMengCode/CLICD?style=flat-square">
|
||||
<img alt="License" src="https://img.shields.io/github/license/MengMengCode/CLICD.svg?style=flat-square">
|
||||
</p>
|
||||
|
||||
<p align="center">
|
||||
<img alt="Go" src="https://img.shields.io/badge/Go-1.22-00ADD8?style=flat-square&logo=go&logoColor=white">
|
||||
<img alt="React" src="https://img.shields.io/badge/React-18-61DAFB?style=flat-square&logo=react&logoColor=111111">
|
||||
|
||||
@@ -2,12 +2,10 @@ package api
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"fmt"
|
||||
"net/http"
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
"unicode"
|
||||
|
||||
"clicd/internal/config"
|
||||
"clicd/internal/lxc"
|
||||
@@ -228,13 +226,38 @@ func createContainer(w http.ResponseWriter, r *http.Request) {
|
||||
if cfg.DiskGB < 1 {
|
||||
cfg.DiskGB = 5
|
||||
}
|
||||
if cfg.PortMappingCount < 2 {
|
||||
if cfg.PortMappingCount < 0 {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: "Port mapping count cannot be negative"})
|
||||
return
|
||||
}
|
||||
if cfg.WantsNAT() && cfg.PortMappingCount < 2 {
|
||||
cfg.PortMappingCount = 2
|
||||
} else if !cfg.WantsNAT() {
|
||||
cfg.PortMappingCount = 0
|
||||
cfg.ExtraPorts = nil
|
||||
}
|
||||
if cfg.PortMappingCount > 64 {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: "Port mapping count cannot exceed 64"})
|
||||
return
|
||||
}
|
||||
if cfg.IPv4Count < 0 || cfg.IPv6Count < 0 {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: "IP address count cannot be negative"})
|
||||
return
|
||||
}
|
||||
if cfg.IPv4Count > 64 || cfg.IPv6Count > 64 {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: "IP address count cannot exceed 64"})
|
||||
return
|
||||
}
|
||||
if !cfg.AssignIPv4 && len(cfg.PublicIPv4s) == 0 {
|
||||
cfg.IPv4Count = 0
|
||||
}
|
||||
if !cfg.AssignIPv6 && len(cfg.IPv6Addresses) == 0 {
|
||||
cfg.IPv6Count = 0
|
||||
}
|
||||
if !hasRequestedNetwork(cfg) {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: noNetworkSelectedMessage})
|
||||
return
|
||||
}
|
||||
if cfg.SnapshotLimit <= 0 {
|
||||
cfg.SnapshotLimit = config.DefaultSnapshotLimit
|
||||
}
|
||||
@@ -242,6 +265,10 @@ func createContainer(w http.ResponseWriter, r *http.Request) {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: err.Error()})
|
||||
return
|
||||
}
|
||||
if err := validateCreateSSHAuth(cfg); err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: err.Error()})
|
||||
return
|
||||
}
|
||||
if cfg.ExpiresAt != "" {
|
||||
expiresAt, ok := lxc.ParseExpiration(cfg.ExpiresAt)
|
||||
if !ok {
|
||||
@@ -405,24 +432,11 @@ func getRandomPort(w http.ResponseWriter, r *http.Request, id int) {
|
||||
jsonResponse(w, http.StatusNotFound, APIResponse{Success: false, Message: "Container not found"})
|
||||
return
|
||||
}
|
||||
// Find a random unused port between 10000-65535
|
||||
used := map[int]bool{}
|
||||
for _, pm := range c.PortMappings {
|
||||
used[pm.HostPort] = true
|
||||
}
|
||||
// Also check all containers
|
||||
for _, oc := range config.AppConfig.Containers {
|
||||
if oc.ID == id {
|
||||
continue
|
||||
}
|
||||
for _, pm := range oc.PortMappings {
|
||||
used[pm.HostPort] = true
|
||||
}
|
||||
}
|
||||
hostIP := strings.TrimSpace(r.URL.Query().Get("host_ip"))
|
||||
// Try random ports
|
||||
for tries := 0; tries < 100; tries++ {
|
||||
port := 10000 + (int(time.Now().UnixNano()) % 55535)
|
||||
if !used[port] {
|
||||
if lxc.HostPortAvailable(c, hostIP, port, "tcp") {
|
||||
jsonResponse(w, http.StatusOK, APIResponse{Success: true, Data: map[string]int{"port": port}})
|
||||
return
|
||||
}
|
||||
@@ -524,26 +538,7 @@ func resetSSHPassword(w http.ResponseWriter, r *http.Request, id int) {
|
||||
}
|
||||
|
||||
func validateSSHPassword(password string) error {
|
||||
if len(password) < 8 || len(password) > 64 {
|
||||
return fmt.Errorf("密码长度必须为 8-64 位")
|
||||
}
|
||||
hasLetter := false
|
||||
hasDigit := false
|
||||
for _, r := range password {
|
||||
if unicode.IsSpace(r) {
|
||||
return fmt.Errorf("密码不能包含空白字符")
|
||||
}
|
||||
if unicode.IsLetter(r) {
|
||||
hasLetter = true
|
||||
}
|
||||
if unicode.IsDigit(r) {
|
||||
hasDigit = true
|
||||
}
|
||||
}
|
||||
if !hasLetter || !hasDigit {
|
||||
return fmt.Errorf("密码至少需要包含字母和数字")
|
||||
}
|
||||
return nil
|
||||
return lxc.ValidateCustomSSHPassword(password)
|
||||
}
|
||||
|
||||
func addPortMapping(w http.ResponseWriter, r *http.Request, id int) {
|
||||
|
||||
@@ -85,6 +85,7 @@ type HostDiskProbe struct {
|
||||
Serial string `json:"serial"`
|
||||
SizeBytes uint64 `json:"size_bytes"`
|
||||
Type string `json:"type"`
|
||||
Virtual bool `json:"virtual"`
|
||||
Rotational bool `json:"rotational"`
|
||||
Mountpoints []string `json:"mountpoints"`
|
||||
Health string `json:"health"`
|
||||
@@ -201,6 +202,7 @@ type NetworkInfo struct {
|
||||
TXBps float64 `json:"tx_bps"`
|
||||
PublicIPv4 string `json:"public_ipv4"`
|
||||
PublicIPv4Interface string `json:"public_ipv4_interface"`
|
||||
PublicIPv4Addresses []lxc.PublicIPInfo `json:"public_ipv4_addresses"`
|
||||
PublicIPv6 string `json:"public_ipv6"`
|
||||
PublicIPv6Interface string `json:"public_ipv6_interface"`
|
||||
IPv6Prefixes []lxc.IPv6PrefixInfo `json:"ipv6_prefixes"`
|
||||
@@ -398,7 +400,8 @@ func getHostRates() (NetworkInfo, DiskIOInfo) {
|
||||
publicIPv4 := lxc.DetectPublicIPv4()
|
||||
network.PublicIPv4 = publicIPv4.Address
|
||||
network.PublicIPv4Interface = publicIPv4.Interface
|
||||
network.IPv6Prefixes = lxc.DetectPublicIPv6Prefixes()
|
||||
network.PublicIPv4Addresses = lxc.DetectFreePublicIPv4Candidates(0)
|
||||
network.IPv6Prefixes = lxc.DetectHostPublicIPv6Prefixes()
|
||||
if len(network.IPv6Prefixes) > 0 {
|
||||
network.PublicIPv6 = network.IPv6Prefixes[0].Address
|
||||
network.PublicIPv6Interface = network.IPv6Prefixes[0].Interface
|
||||
@@ -540,7 +543,7 @@ func getHostProbeReport() HostProbeReport {
|
||||
Disks: detectHostDisks(),
|
||||
NetworkInterfaces: detectHostNICs(),
|
||||
PublicIPv4: detectAllPublicIPv4(),
|
||||
IPv6Prefixes: lxc.DetectPublicIPv6Prefixes(),
|
||||
IPv6Prefixes: lxc.DetectHostPublicIPv6Prefixes(),
|
||||
Gateways: detectGateways(),
|
||||
GPUs: detectGPUs(),
|
||||
System: detectSystemProbe(),
|
||||
@@ -676,17 +679,23 @@ func detectHostDisks() []HostDiskProbe {
|
||||
}
|
||||
base := filepath.Join("/sys/block", name)
|
||||
path := "/dev/" + name
|
||||
model := strings.TrimSpace(readFirstExistingFile(filepath.Join(base, "device/model"), filepath.Join(base, "device/name")))
|
||||
vendor := strings.TrimSpace(readFirstExistingFile(filepath.Join(base, "device/vendor")))
|
||||
virtual := isVirtualBlockDevice(name, model, vendor)
|
||||
disk := HostDiskProbe{
|
||||
Name: name,
|
||||
Path: path,
|
||||
Model: strings.TrimSpace(readFirstExistingFile(filepath.Join(base, "device/model"), filepath.Join(base, "device/name"))),
|
||||
Model: model,
|
||||
Serial: strings.TrimSpace(readFirstExistingFile(filepath.Join(base, "device/serial"), filepath.Join(base, "serial"))),
|
||||
SizeBytes: readUintFile(filepath.Join(base, "size")) * 512,
|
||||
Type: detectDiskType(base, name),
|
||||
Type: detectDiskType(base, name, virtual),
|
||||
Virtual: virtual,
|
||||
Rotational: strings.TrimSpace(readFirstExistingFile(filepath.Join(base, "queue/rotational"))) == "1",
|
||||
Mountpoints: mounts[name],
|
||||
}
|
||||
disk.SMART = detectDiskSMART(path)
|
||||
if !virtual {
|
||||
disk.SMART = detectDiskSMART(path)
|
||||
}
|
||||
disk.Health = disk.SMARTHealth()
|
||||
disk.HealthDetail = disk.SMARTDetail()
|
||||
disks = append(disks, disk)
|
||||
@@ -695,7 +704,10 @@ func detectHostDisks() []HostDiskProbe {
|
||||
return disks
|
||||
}
|
||||
|
||||
func detectDiskType(base, name string) string {
|
||||
func detectDiskType(base, name string, virtual bool) string {
|
||||
if virtual {
|
||||
return "Virtual"
|
||||
}
|
||||
if strings.HasPrefix(name, "nvme") {
|
||||
return "NVMe"
|
||||
}
|
||||
@@ -705,7 +717,26 @@ func detectDiskType(base, name string) string {
|
||||
return "SSD"
|
||||
}
|
||||
|
||||
func isVirtualBlockDevice(name, model, vendor string) bool {
|
||||
lower := strings.ToLower(strings.TrimSpace(name + " " + model + " " + vendor))
|
||||
if strings.HasPrefix(name, "vd") || strings.HasPrefix(name, "xvd") {
|
||||
return true
|
||||
}
|
||||
for _, token := range []string{
|
||||
"qemu", "virtio", "virtual", "vmware", "vbox", "xen",
|
||||
"amazon elastic block store", "google persistentdisk", "microsoft",
|
||||
} {
|
||||
if strings.Contains(lower, token) {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func (disk HostDiskProbe) SMARTHealth() string {
|
||||
if disk.Virtual {
|
||||
return "virtual"
|
||||
}
|
||||
if disk.SMART.Available && disk.Health != "" {
|
||||
return disk.Health
|
||||
}
|
||||
@@ -713,6 +744,9 @@ func (disk HostDiskProbe) SMARTHealth() string {
|
||||
}
|
||||
|
||||
func (disk HostDiskProbe) SMARTDetail() string {
|
||||
if disk.Virtual {
|
||||
return "虚拟磁盘,真实 SMART/寿命/通电数据需在物理宿主机查看"
|
||||
}
|
||||
return disk.SMART.Detail()
|
||||
}
|
||||
|
||||
@@ -1437,7 +1471,7 @@ func commandCheck(key, label string, required bool, cmd string, fallback string)
|
||||
ok := commandExists(cmd)
|
||||
detail := "missing"
|
||||
if ok {
|
||||
detail = strings.TrimSpace(runCommandOutput(2*time.Second, "sh", "-c", cmd+" --version 2>&1 | head -n 1"))
|
||||
detail = commandVersionDetail(cmd)
|
||||
if detail == "" {
|
||||
detail = "installed"
|
||||
}
|
||||
@@ -1447,6 +1481,15 @@ func commandCheck(key, label string, required bool, cmd string, fallback string)
|
||||
return HostEnvCheck{Key: key, Label: label, OK: ok, Required: required, Detail: detail}
|
||||
}
|
||||
|
||||
func commandVersionDetail(cmd string) string {
|
||||
switch cmd {
|
||||
case "ip":
|
||||
return strings.TrimSpace(runCommandOutput(2*time.Second, "sh", "-c", "ip -V 2>&1 | head -n 1"))
|
||||
default:
|
||||
return strings.TrimSpace(runCommandOutput(2*time.Second, "sh", "-c", cmd+" --version 2>&1 | head -n 1"))
|
||||
}
|
||||
}
|
||||
|
||||
func certbotCheck() HostEnvCheck {
|
||||
check := HostEnvCheck{Key: "certbot", Label: "Certbot 证书工具 >= 5.4", Required: false, Detail: "missing"}
|
||||
if !commandExists("certbot") {
|
||||
|
||||
@@ -0,0 +1,80 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"clicd/internal/config"
|
||||
)
|
||||
|
||||
type webSSHOriginSettingsRequest struct {
|
||||
Origins []string `json:"origins"`
|
||||
WebSSHAllowedOrigins []string `json:"webssh_allowed_origins"`
|
||||
}
|
||||
|
||||
type webSSHOriginSettingsResponse struct {
|
||||
Origins []string `json:"origins"`
|
||||
CurrentOrigin string `json:"current_origin,omitempty"`
|
||||
}
|
||||
|
||||
func HandleWebSSHOriginSettings(w http.ResponseWriter, r *http.Request) {
|
||||
switch r.Method {
|
||||
case http.MethodGet:
|
||||
jsonResponse(w, http.StatusOK, APIResponse{Success: true, Data: webSSHOriginSettingsStatus(r)})
|
||||
case http.MethodPut:
|
||||
updateWebSSHOriginSettings(w, r)
|
||||
default:
|
||||
jsonResponse(w, http.StatusMethodNotAllowed, APIResponse{Success: false, Message: "Method not allowed"})
|
||||
}
|
||||
}
|
||||
|
||||
func updateWebSSHOriginSettings(w http.ResponseWriter, r *http.Request) {
|
||||
var req webSSHOriginSettingsRequest
|
||||
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: "Invalid request body"})
|
||||
return
|
||||
}
|
||||
origins := req.Origins
|
||||
if len(origins) == 0 && len(req.WebSSHAllowedOrigins) > 0 {
|
||||
origins = req.WebSSHAllowedOrigins
|
||||
}
|
||||
normalized, err := config.NormalizeAllowedOrigins(origins)
|
||||
if err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: err.Error()})
|
||||
return
|
||||
}
|
||||
config.AppConfig.WebSSHAllowedOrigins = normalized
|
||||
if err := config.SaveConfig(); err != nil {
|
||||
jsonResponse(w, http.StatusInternalServerError, APIResponse{Success: false, Message: "Save Origin allowlist failed"})
|
||||
return
|
||||
}
|
||||
auditRequest(r, "settings.webssh_origins", "WebSSH Origin", "origins="+strings.Join(normalized, ","), true, "")
|
||||
jsonResponse(w, http.StatusOK, APIResponse{Success: true, Message: "Origin allowlist saved", Data: webSSHOriginSettingsStatus(r)})
|
||||
}
|
||||
|
||||
func webSSHOriginSettingsStatus(r *http.Request) webSSHOriginSettingsResponse {
|
||||
origins := config.AppConfig.WebSSHAllowedOrigins
|
||||
if origins == nil {
|
||||
origins = []string{}
|
||||
}
|
||||
return webSSHOriginSettingsResponse{
|
||||
Origins: origins,
|
||||
CurrentOrigin: requestOrigin(r),
|
||||
}
|
||||
}
|
||||
|
||||
func requestOrigin(r *http.Request) string {
|
||||
host := strings.TrimSpace(r.Host)
|
||||
if host == "" {
|
||||
return ""
|
||||
}
|
||||
scheme := "http"
|
||||
if r.TLS != nil {
|
||||
scheme = "https"
|
||||
}
|
||||
if forwarded := strings.TrimSpace(r.Header.Get("X-Forwarded-Proto")); forwarded != "" {
|
||||
scheme = strings.ToLower(strings.Split(forwarded, ",")[0])
|
||||
}
|
||||
return scheme + "://" + host
|
||||
}
|
||||
+236
-19
@@ -1,7 +1,9 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"net/netip"
|
||||
"sort"
|
||||
"strconv"
|
||||
|
||||
@@ -21,12 +23,24 @@ type nat4Route struct {
|
||||
LXCName string `json:"lxc_name"`
|
||||
Status string `json:"status"`
|
||||
IP string `json:"ip"`
|
||||
HostIP string `json:"host_ip"`
|
||||
HostPort int `json:"host_port"`
|
||||
ContainerPort int `json:"container_port"`
|
||||
Protocol string `json:"protocol"`
|
||||
Description string `json:"description"`
|
||||
}
|
||||
|
||||
type ipv4Route struct {
|
||||
ContainerID int `json:"container_id"`
|
||||
ContainerName string `json:"container_name"`
|
||||
LXCName string `json:"lxc_name"`
|
||||
Status string `json:"status"`
|
||||
Address string `json:"address"`
|
||||
Interface string `json:"interface"`
|
||||
PrefixLen int `json:"prefix_len,omitempty"`
|
||||
Gateway string `json:"gateway,omitempty"`
|
||||
}
|
||||
|
||||
type ipv6Route struct {
|
||||
ContainerID int `json:"container_id"`
|
||||
ContainerName string `json:"container_name"`
|
||||
@@ -38,30 +52,78 @@ type ipv6Route struct {
|
||||
}
|
||||
|
||||
type routingResponse struct {
|
||||
NAT4 routeCapacity `json:"nat4"`
|
||||
IPv6 routeCapacity `json:"ipv6"`
|
||||
NAT4Mappings []nat4Route `json:"nat4_mappings"`
|
||||
IPv6Assignments []ipv6Route `json:"ipv6_assignments"`
|
||||
IPv6Prefixes []lxc.IPv6PrefixInfo `json:"ipv6_prefixes"`
|
||||
NAT4 routeCapacity `json:"nat4"`
|
||||
IPv4 routeCapacity `json:"ipv4"`
|
||||
IPv6 routeCapacity `json:"ipv6"`
|
||||
HostPublicIPv4 lxc.PublicIPInfo `json:"host_public_ipv4"`
|
||||
PublicIPv4Addresses []lxc.PublicIPInfo `json:"public_ipv4_addresses"`
|
||||
IPv4Assignments []ipv4Route `json:"ipv4_assignments"`
|
||||
NAT4Mappings []nat4Route `json:"nat4_mappings"`
|
||||
IPv6Assignments []ipv6Route `json:"ipv6_assignments"`
|
||||
IPv6Prefixes []lxc.IPv6PrefixInfo `json:"ipv6_prefixes"`
|
||||
}
|
||||
|
||||
type routingPoolsRequest struct {
|
||||
Addresses *[]string `json:"addresses"`
|
||||
Items *[]config.PublicIPv4Assignment `json:"items"`
|
||||
IPv6Prefixes *[]config.PublicIPv6Prefix `json:"ipv6_prefixes"`
|
||||
}
|
||||
|
||||
type publicIPv4ScanRequest struct {
|
||||
CIDR string `json:"cidr"`
|
||||
Interface string `json:"interface"`
|
||||
Gateway string `json:"gateway"`
|
||||
Verify bool `json:"verify"`
|
||||
Limit int `json:"limit"`
|
||||
}
|
||||
|
||||
func HandleRouting(w http.ResponseWriter, r *http.Request) {
|
||||
if r.Method != http.MethodGet {
|
||||
switch r.Method {
|
||||
case http.MethodGet:
|
||||
handleRoutingGet(w, r)
|
||||
case http.MethodPut:
|
||||
handleRoutingPoolsUpdate(w, r)
|
||||
default:
|
||||
jsonResponse(w, http.StatusMethodNotAllowed, APIResponse{Success: false, Message: "Method not allowed"})
|
||||
}
|
||||
}
|
||||
|
||||
func HandleRoutingIPv4Scan(w http.ResponseWriter, r *http.Request) {
|
||||
if r.Method != http.MethodPost {
|
||||
jsonResponse(w, http.StatusMethodNotAllowed, APIResponse{Success: false, Message: "Method not allowed"})
|
||||
return
|
||||
}
|
||||
if !requireScope(w, r, "routing:write") {
|
||||
return
|
||||
}
|
||||
var req publicIPv4ScanRequest
|
||||
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: "Invalid request body"})
|
||||
return
|
||||
}
|
||||
results, err := lxc.ScanPublicIPv4Segment(req.CIDR, req.Interface, req.Gateway, req.Verify, req.Limit)
|
||||
if err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: err.Error()})
|
||||
return
|
||||
}
|
||||
jsonResponse(w, http.StatusOK, APIResponse{Success: true, Data: results})
|
||||
}
|
||||
|
||||
func handleRoutingGet(w http.ResponseWriter, r *http.Request) {
|
||||
if !requireScope(w, r, "routing:read") {
|
||||
return
|
||||
}
|
||||
|
||||
nat4Mappings := make([]nat4Route, 0)
|
||||
usedPorts := map[int]bool{}
|
||||
ipv4Assignments := make([]ipv4Route, 0)
|
||||
ipv6Assignments := make([]ipv6Route, 0)
|
||||
|
||||
const nat4StartPort = 20000
|
||||
const nat4EndPort = 65535
|
||||
|
||||
for _, c := range config.AppConfig.Containers {
|
||||
for i := range config.AppConfig.Containers {
|
||||
c := &config.AppConfig.Containers[i]
|
||||
for _, pm := range c.PortMappings {
|
||||
if pm.HostPort >= nat4StartPort && pm.HostPort <= nat4EndPort {
|
||||
usedPorts[pm.HostPort] = true
|
||||
@@ -72,30 +134,56 @@ func HandleRouting(w http.ResponseWriter, r *http.Request) {
|
||||
LXCName: c.LxcName(),
|
||||
Status: c.Status,
|
||||
IP: c.IP,
|
||||
HostIP: pm.HostIP,
|
||||
HostPort: pm.HostPort,
|
||||
ContainerPort: pm.ContainerPort,
|
||||
Protocol: pm.Protocol,
|
||||
Description: pm.Description,
|
||||
})
|
||||
}
|
||||
if c.IPv6 != "" {
|
||||
for _, ip := range c.PublicIPv4s {
|
||||
if ip.Address == "" {
|
||||
continue
|
||||
}
|
||||
ipv4Assignments = append(ipv4Assignments, ipv4Route{
|
||||
ContainerID: c.ID,
|
||||
ContainerName: c.Name,
|
||||
LXCName: c.LxcName(),
|
||||
Status: c.Status,
|
||||
Address: ip.Address,
|
||||
Interface: ip.Interface,
|
||||
PrefixLen: ip.PrefixLen,
|
||||
Gateway: ip.Gateway,
|
||||
})
|
||||
}
|
||||
c.NormalizeNetworkAssignments()
|
||||
for _, ip := range c.IPv6Addresses {
|
||||
if ip.Address == "" {
|
||||
continue
|
||||
}
|
||||
ipv6Assignments = append(ipv6Assignments, ipv6Route{
|
||||
ContainerID: c.ID,
|
||||
ContainerName: c.Name,
|
||||
LXCName: c.LxcName(),
|
||||
Status: c.Status,
|
||||
Address: c.IPv6,
|
||||
PrefixLen: c.IPv6PrefixLen,
|
||||
Interface: c.IPv6Interface,
|
||||
Address: ip.Address,
|
||||
PrefixLen: ip.PrefixLen,
|
||||
Interface: ip.Interface,
|
||||
})
|
||||
}
|
||||
}
|
||||
sort.SliceStable(nat4Mappings, func(i, j int) bool {
|
||||
if nat4Mappings[i].HostPort == nat4Mappings[j].HostPort {
|
||||
if nat4Mappings[i].HostIP != nat4Mappings[j].HostIP {
|
||||
return nat4Mappings[i].HostIP < nat4Mappings[j].HostIP
|
||||
}
|
||||
return nat4Mappings[i].ContainerName < nat4Mappings[j].ContainerName
|
||||
}
|
||||
return nat4Mappings[i].HostPort < nat4Mappings[j].HostPort
|
||||
})
|
||||
sort.SliceStable(ipv4Assignments, func(i, j int) bool {
|
||||
return ipv4Assignments[i].Address < ipv4Assignments[j].Address
|
||||
})
|
||||
sort.SliceStable(ipv6Assignments, func(i, j int) bool {
|
||||
return ipv6Assignments[i].Address < ipv6Assignments[j].Address
|
||||
})
|
||||
@@ -108,12 +196,16 @@ func HandleRouting(w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
|
||||
prefixes := lxc.DetectPublicIPv6Prefixes()
|
||||
ipv6Total := "0"
|
||||
ipv6Remaining := "0"
|
||||
if len(prefixes) > 0 {
|
||||
ipv6Total = lxc.IPv6PrefixCapacity(prefixes[0].PrefixLen)
|
||||
ipv6Remaining = subtractCapacity(ipv6Total, len(ipv6Assignments))
|
||||
hostPublicIPv4 := lxc.DetectPublicIPv4()
|
||||
publicIPv4s := lxc.DetectPublicIPv4Candidates()
|
||||
ipv4Total := len(publicIPv4s)
|
||||
ipv4Used := len(ipv4Assignments)
|
||||
ipv4Remaining := ipv4Total - ipv4Used
|
||||
if ipv4Remaining < 0 {
|
||||
ipv4Remaining = 0
|
||||
}
|
||||
ipv6Total := totalIPv6Capacity(prefixes)
|
||||
ipv6Remaining := subtractCapacity(ipv6Total, len(ipv6Assignments))
|
||||
|
||||
jsonResponse(w, http.StatusOK, APIResponse{
|
||||
Success: true,
|
||||
@@ -123,18 +215,143 @@ func HandleRouting(w http.ResponseWriter, r *http.Request) {
|
||||
Remaining: strconv.Itoa(nat4Remaining),
|
||||
Total: strconv.Itoa(totalNAT4Ports),
|
||||
},
|
||||
IPv4: routeCapacity{
|
||||
Used: ipv4Used,
|
||||
Remaining: strconv.Itoa(ipv4Remaining),
|
||||
Total: strconv.Itoa(ipv4Total),
|
||||
},
|
||||
IPv6: routeCapacity{
|
||||
Used: len(ipv6Assignments),
|
||||
Remaining: ipv6Remaining,
|
||||
Total: ipv6Total,
|
||||
},
|
||||
NAT4Mappings: nat4Mappings,
|
||||
IPv6Assignments: ipv6Assignments,
|
||||
IPv6Prefixes: prefixes,
|
||||
HostPublicIPv4: hostPublicIPv4,
|
||||
PublicIPv4Addresses: publicIPv4s,
|
||||
IPv4Assignments: ipv4Assignments,
|
||||
NAT4Mappings: nat4Mappings,
|
||||
IPv6Assignments: ipv6Assignments,
|
||||
IPv6Prefixes: prefixes,
|
||||
},
|
||||
})
|
||||
}
|
||||
|
||||
func handleRoutingPoolsUpdate(w http.ResponseWriter, r *http.Request) {
|
||||
if !requireScope(w, r, "routing:write") {
|
||||
return
|
||||
}
|
||||
var req routingPoolsRequest
|
||||
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: "Invalid request body"})
|
||||
return
|
||||
}
|
||||
|
||||
if req.Items != nil || req.Addresses != nil {
|
||||
items := []config.PublicIPv4Assignment{}
|
||||
if req.Items != nil {
|
||||
items = *req.Items
|
||||
} else if req.Addresses != nil {
|
||||
items = make([]config.PublicIPv4Assignment, 0, len(*req.Addresses))
|
||||
for _, address := range *req.Addresses {
|
||||
items = append(items, config.PublicIPv4Assignment{Address: address})
|
||||
}
|
||||
}
|
||||
normalized, err := lxc.NormalizePublicIPv4Pool(items)
|
||||
if err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: err.Error()})
|
||||
return
|
||||
}
|
||||
allowed := map[string]bool{}
|
||||
for _, item := range normalized {
|
||||
allowed[item.Address] = true
|
||||
}
|
||||
for _, c := range config.AppConfig.Containers {
|
||||
for _, item := range c.PublicIPv4s {
|
||||
if item.Address != "" && !allowed[item.Address] {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{
|
||||
Success: false,
|
||||
Message: "IPv4 " + item.Address + " is assigned to container " + c.Name + " and cannot be removed from the pool",
|
||||
})
|
||||
return
|
||||
}
|
||||
}
|
||||
}
|
||||
config.AppConfig.PublicIPv4Pool = normalized
|
||||
}
|
||||
|
||||
if req.IPv6Prefixes != nil {
|
||||
normalized, err := lxc.NormalizePublicIPv6Prefixes(*req.IPv6Prefixes)
|
||||
if err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: err.Error()})
|
||||
return
|
||||
}
|
||||
parsedPrefixes := make([]netip.Prefix, 0, len(normalized))
|
||||
for _, item := range normalized {
|
||||
prefix, err := netip.ParsePrefix(item.Prefix)
|
||||
if err == nil {
|
||||
parsedPrefixes = append(parsedPrefixes, prefix)
|
||||
}
|
||||
}
|
||||
for _, c := range config.AppConfig.Containers {
|
||||
c.NormalizeNetworkAssignments()
|
||||
for _, item := range c.IPv6Addresses {
|
||||
if item.Address == "" {
|
||||
continue
|
||||
}
|
||||
addr, err := netip.ParseAddr(item.Address)
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
contained := false
|
||||
for _, prefix := range parsedPrefixes {
|
||||
if prefix.Contains(addr) {
|
||||
contained = true
|
||||
break
|
||||
}
|
||||
}
|
||||
if !contained {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{
|
||||
Success: false,
|
||||
Message: "IPv6 " + item.Address + " is assigned to container " + c.Name + " and cannot be removed from the pool",
|
||||
})
|
||||
return
|
||||
}
|
||||
}
|
||||
}
|
||||
config.AppConfig.PublicIPv6Prefixes = normalized
|
||||
}
|
||||
|
||||
if err := config.SaveConfig(); err != nil {
|
||||
jsonResponse(w, http.StatusInternalServerError, APIResponse{Success: false, Message: "Failed to save configuration"})
|
||||
return
|
||||
}
|
||||
handleRoutingGet(w, r)
|
||||
}
|
||||
|
||||
func totalIPv6Capacity(prefixes []lxc.IPv6PrefixInfo) string {
|
||||
if len(prefixes) == 0 {
|
||||
return "0"
|
||||
}
|
||||
var total uint64
|
||||
for _, prefix := range prefixes {
|
||||
capacity := lxc.IPv6PrefixCapacity(prefix.PrefixLen)
|
||||
if capacity == "large" {
|
||||
return "large"
|
||||
}
|
||||
parsed, err := strconv.ParseUint(capacity, 10, 64)
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
if ^uint64(0)-total < parsed {
|
||||
return "large"
|
||||
}
|
||||
total += parsed
|
||||
}
|
||||
if total == 0 {
|
||||
return "0"
|
||||
}
|
||||
return strconv.FormatUint(total, 10)
|
||||
}
|
||||
|
||||
func subtractCapacity(total string, used int) string {
|
||||
if total == "" || total == "0" {
|
||||
return "0"
|
||||
|
||||
@@ -13,10 +13,16 @@ import (
|
||||
|
||||
var kvmManager = kvm.NewManager()
|
||||
|
||||
const noNetworkSelectedMessage = "请勾选任意一个可用网络"
|
||||
|
||||
func runtimeFromRequest(value string) string {
|
||||
return config.NormalizeVirtualization(value)
|
||||
}
|
||||
|
||||
func hasRequestedNetwork(cfg lxc.ContainerConfig) bool {
|
||||
return cfg.WantsNAT() || cfg.AssignIPv4 || len(cfg.PublicIPv4s) > 0 || cfg.AssignIPv6 || len(cfg.IPv6Addresses) > 0
|
||||
}
|
||||
|
||||
func runtimeFromTemplateID(templateID string) string {
|
||||
if kvm.FindImage(templateID) != nil {
|
||||
return config.VirtualizationKVM
|
||||
@@ -32,6 +38,26 @@ func createByRuntime(cfg lxc.ContainerConfig) error {
|
||||
return lxcManager.CreateContainer(cfg)
|
||||
}
|
||||
|
||||
func validateCreateSSHAuth(cfg lxc.ContainerConfig) error {
|
||||
if cfg.Virtualization == config.VirtualizationKVM && kvm.IsWindowsImage(cfg.TemplateID) {
|
||||
return nil
|
||||
}
|
||||
_, err := lxc.ResolveCreateSSHAccess(cfg)
|
||||
return err
|
||||
}
|
||||
|
||||
func validateReinstallSSHAuth(c *config.Container, templateID string, cfg lxc.ContainerConfig) error {
|
||||
if c != nil && c.IsKVM() && kvm.IsWindowsImage(templateID) {
|
||||
return nil
|
||||
}
|
||||
currentPassword := ""
|
||||
if c != nil {
|
||||
currentPassword = c.SSHPassword
|
||||
}
|
||||
_, err := lxc.ResolveReinstallSSHAccess(currentPassword, cfg)
|
||||
return err
|
||||
}
|
||||
|
||||
func startByRuntime(id int) error {
|
||||
c := config.FindContainer(id)
|
||||
if c != nil && c.IsKVM() {
|
||||
@@ -64,12 +90,12 @@ func destroyByRuntime(id int) error {
|
||||
return lxcManager.DestroyContainer(id)
|
||||
}
|
||||
|
||||
func reinstallByRuntime(id int, templateID string) error {
|
||||
func reinstallByRuntime(id int, templateID string, authConfig ...lxc.ContainerConfig) error {
|
||||
c := config.FindContainer(id)
|
||||
if c != nil && c.IsKVM() {
|
||||
return kvmManager.ReinstallContainer(id, templateID)
|
||||
return kvmManager.ReinstallContainer(id, templateID, authConfig...)
|
||||
}
|
||||
return lxcManager.ReinstallContainer(id, templateID)
|
||||
return lxcManager.ReinstallContainer(id, templateID, authConfig...)
|
||||
}
|
||||
|
||||
func resetPasswordByRuntime(id int, password string) (string, error) {
|
||||
|
||||
@@ -75,6 +75,10 @@ func (q *TaskQueue) enqueueTask(task *Task) {
|
||||
}
|
||||
|
||||
func (q *TaskQueue) Enqueue(containerID int, containerName string, taskType TaskType, templateID string, cfg *lxc.ContainerConfig) []string {
|
||||
return q.EnqueueWithAudit(containerID, containerName, taskType, templateID, cfg, "admin", "", "")
|
||||
}
|
||||
|
||||
func (q *TaskQueue) EnqueueWithAudit(containerID int, containerName string, taskType TaskType, templateID string, cfg *lxc.ContainerConfig, user string, ip string, userAgent string) []string {
|
||||
q.mu.Lock()
|
||||
defer q.mu.Unlock()
|
||||
|
||||
@@ -88,6 +92,9 @@ func (q *TaskQueue) Enqueue(containerID int, containerName string, taskType Task
|
||||
Status: "pending",
|
||||
CreatedAt: time.Now().Format("2006-01-02 15:04:05"),
|
||||
TemplateID: templateID,
|
||||
User: user,
|
||||
IP: ip,
|
||||
UserAgent: userAgent,
|
||||
}
|
||||
if cfg != nil {
|
||||
task.Config = *cfg
|
||||
@@ -343,7 +350,11 @@ func (q *TaskQueue) opWorker() {
|
||||
}
|
||||
}
|
||||
case TaskReinstall:
|
||||
err = reinstallByRuntime(task.ContainerID, task.TemplateID)
|
||||
if lxc.HasSSHAuthOptions(task.Config) {
|
||||
err = reinstallByRuntime(task.ContainerID, task.TemplateID, task.Config)
|
||||
} else {
|
||||
err = reinstallByRuntime(task.ContainerID, task.TemplateID)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -472,6 +483,7 @@ func HandleSingleTaskAction(w http.ResponseWriter, r *http.Request, id int, acti
|
||||
|
||||
var taskType TaskType
|
||||
var templateID string
|
||||
var taskConfig *lxc.ContainerConfig
|
||||
switch action {
|
||||
case "start":
|
||||
taskType = TaskStart
|
||||
@@ -483,7 +495,10 @@ func HandleSingleTaskAction(w http.ResponseWriter, r *http.Request, id int, acti
|
||||
taskType = TaskDelete
|
||||
case "reinstall":
|
||||
var req struct {
|
||||
TemplateID string `json:"template_id"`
|
||||
TemplateID string `json:"template_id"`
|
||||
SSHAuthMode string `json:"ssh_auth_mode,omitempty"`
|
||||
SSHPassword string `json:"ssh_password,omitempty"`
|
||||
SSHPublicKey string `json:"ssh_public_key,omitempty"`
|
||||
}
|
||||
json.NewDecoder(r.Body).Decode(&req)
|
||||
templateID = req.TemplateID
|
||||
@@ -501,13 +516,26 @@ func HandleSingleTaskAction(w http.ResponseWriter, r *http.Request, id int, acti
|
||||
jsonResponse(w, http.StatusForbidden, APIResponse{Success: false, Message: "Template is not enabled or downloaded"})
|
||||
return
|
||||
}
|
||||
authCfg := lxc.ContainerConfig{
|
||||
TemplateID: templateID,
|
||||
SSHAuthMode: req.SSHAuthMode,
|
||||
SSHPassword: req.SSHPassword,
|
||||
SSHPublicKey: req.SSHPublicKey,
|
||||
}
|
||||
if lxc.HasSSHAuthOptions(authCfg) {
|
||||
if err := validateReinstallSSHAuth(c, templateID, authCfg); err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: err.Error()})
|
||||
return
|
||||
}
|
||||
taskConfig = &authCfg
|
||||
}
|
||||
taskType = TaskReinstall
|
||||
default:
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: "Unknown action"})
|
||||
return
|
||||
}
|
||||
|
||||
ids := globalQueue.EnqueueBatchWithAudit(taskType, []int{id}, templateID, user, ip, userAgent)
|
||||
ids := globalQueue.EnqueueWithAudit(id, name, taskType, templateID, taskConfig, user, ip, userAgent)
|
||||
jsonResponse(w, http.StatusAccepted, APIResponse{
|
||||
Success: true,
|
||||
Message: "Task queued",
|
||||
@@ -575,8 +603,37 @@ func HandleBatchCreate(w http.ResponseWriter, r *http.Request) {
|
||||
jsonResponse(w, http.StatusForbidden, APIResponse{Success: false, Message: name + ": template is not enabled or downloaded"})
|
||||
return
|
||||
}
|
||||
if req.Containers[i].PortMappingCount < 2 {
|
||||
if req.Containers[i].PortMappingCount < 0 {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: name + ": port mapping count cannot be negative"})
|
||||
return
|
||||
}
|
||||
if req.Containers[i].WantsNAT() && req.Containers[i].PortMappingCount < 2 {
|
||||
req.Containers[i].PortMappingCount = 2
|
||||
} else if !req.Containers[i].WantsNAT() {
|
||||
req.Containers[i].PortMappingCount = 0
|
||||
req.Containers[i].ExtraPorts = nil
|
||||
}
|
||||
if req.Containers[i].PortMappingCount > 64 {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: name + ": port mapping count cannot exceed 64"})
|
||||
return
|
||||
}
|
||||
if req.Containers[i].IPv4Count < 0 || req.Containers[i].IPv6Count < 0 {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: name + ": IP address count cannot be negative"})
|
||||
return
|
||||
}
|
||||
if req.Containers[i].IPv4Count > 64 || req.Containers[i].IPv6Count > 64 {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: name + ": IP address count cannot exceed 64"})
|
||||
return
|
||||
}
|
||||
if !req.Containers[i].AssignIPv4 && len(req.Containers[i].PublicIPv4s) == 0 {
|
||||
req.Containers[i].IPv4Count = 0
|
||||
}
|
||||
if !req.Containers[i].AssignIPv6 && len(req.Containers[i].IPv6Addresses) == 0 {
|
||||
req.Containers[i].IPv6Count = 0
|
||||
}
|
||||
if !hasRequestedNetwork(req.Containers[i]) {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: name + ": " + noNetworkSelectedMessage})
|
||||
return
|
||||
}
|
||||
if req.Containers[i].SnapshotLimit <= 0 {
|
||||
req.Containers[i].SnapshotLimit = config.DefaultSnapshotLimit
|
||||
@@ -585,6 +642,10 @@ func HandleBatchCreate(w http.ResponseWriter, r *http.Request) {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: name + ": " + err.Error()})
|
||||
return
|
||||
}
|
||||
if err := validateCreateSSHAuth(req.Containers[i]); err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: name + ": " + err.Error()})
|
||||
return
|
||||
}
|
||||
requestNames[name] = true
|
||||
}
|
||||
ids := globalQueue.EnqueueBatchCreateWithAudit(req.Containers, requestActor(r), clientIP(r), r.UserAgent())
|
||||
@@ -602,9 +663,12 @@ func HandleBatchAction(w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
var req struct {
|
||||
Action string `json:"action"`
|
||||
Containers []int `json:"containers"`
|
||||
TemplateID string `json:"template_id,omitempty"`
|
||||
Action string `json:"action"`
|
||||
Containers []int `json:"containers"`
|
||||
TemplateID string `json:"template_id,omitempty"`
|
||||
SSHAuthMode string `json:"ssh_auth_mode,omitempty"`
|
||||
SSHPassword string `json:"ssh_password,omitempty"`
|
||||
SSHPublicKey string `json:"ssh_public_key,omitempty"`
|
||||
}
|
||||
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: "Invalid request body"})
|
||||
@@ -613,6 +677,7 @@ func HandleBatchAction(w http.ResponseWriter, r *http.Request) {
|
||||
|
||||
var taskType TaskType
|
||||
var requiredScope string
|
||||
var taskConfig *lxc.ContainerConfig
|
||||
switch req.Action {
|
||||
case "start":
|
||||
taskType = TaskStart
|
||||
@@ -635,6 +700,15 @@ func HandleBatchAction(w http.ResponseWriter, r *http.Request) {
|
||||
jsonResponse(w, http.StatusForbidden, APIResponse{Success: false, Message: "Template is not enabled or downloaded"})
|
||||
return
|
||||
}
|
||||
authCfg := lxc.ContainerConfig{
|
||||
TemplateID: req.TemplateID,
|
||||
SSHAuthMode: req.SSHAuthMode,
|
||||
SSHPassword: req.SSHPassword,
|
||||
SSHPublicKey: req.SSHPublicKey,
|
||||
}
|
||||
if lxc.HasSSHAuthOptions(authCfg) {
|
||||
taskConfig = &authCfg
|
||||
}
|
||||
taskType = TaskReinstall
|
||||
requiredScope = "container:reinstall"
|
||||
default:
|
||||
@@ -650,9 +724,28 @@ func HandleBatchAction(w http.ResponseWriter, r *http.Request) {
|
||||
jsonResponse(w, http.StatusForbidden, APIResponse{Success: false, Message: "Access denied to one or more containers"})
|
||||
return
|
||||
}
|
||||
if taskConfig != nil {
|
||||
if err := validateReinstallSSHAuth(c, req.TemplateID, *taskConfig); err != nil {
|
||||
jsonResponse(w, http.StatusBadRequest, APIResponse{Success: false, Message: c.Name + ": " + err.Error()})
|
||||
return
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
ids := globalQueue.EnqueueBatchWithAudit(taskType, req.Containers, req.TemplateID, requestActor(r), clientIP(r), r.UserAgent())
|
||||
var ids []string
|
||||
if taskConfig != nil {
|
||||
for _, id := range req.Containers {
|
||||
c := config.FindContainer(id)
|
||||
name := ""
|
||||
if c != nil {
|
||||
name = c.Name
|
||||
}
|
||||
queued := globalQueue.EnqueueWithAudit(id, name, taskType, req.TemplateID, taskConfig, requestActor(r), clientIP(r), r.UserAgent())
|
||||
ids = append(ids, queued...)
|
||||
}
|
||||
} else {
|
||||
ids = globalQueue.EnqueueBatchWithAudit(taskType, req.Containers, req.TemplateID, requestActor(r), clientIP(r), r.UserAgent())
|
||||
}
|
||||
jsonResponse(w, http.StatusAccepted, APIResponse{Success: true, Data: ids})
|
||||
}
|
||||
|
||||
|
||||
@@ -1,10 +1,9 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"net"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"strings"
|
||||
|
||||
"clicd/internal/config"
|
||||
|
||||
"github.com/gorilla/websocket"
|
||||
)
|
||||
@@ -17,19 +16,6 @@ var upgrader = websocket.Upgrader{
|
||||
if origin == "" {
|
||||
return true
|
||||
}
|
||||
originURL, err := url.Parse(origin)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
originHost := strings.ToLower(stripPort(originURL.Host))
|
||||
requestHost := strings.ToLower(stripPort(r.Host))
|
||||
return originHost != "" && originHost == requestHost
|
||||
return config.IsOriginAllowed(origin, r.Host)
|
||||
},
|
||||
}
|
||||
|
||||
func stripPort(host string) string {
|
||||
if parsedHost, _, err := net.SplitHostPort(host); err == nil {
|
||||
return parsedHost
|
||||
}
|
||||
return strings.Trim(host, "[]")
|
||||
}
|
||||
|
||||
@@ -17,10 +17,32 @@ import (
|
||||
type PortMapping struct {
|
||||
ContainerPort int `json:"container_port"`
|
||||
HostPort int `json:"host_port"`
|
||||
HostIP string `json:"host_ip,omitempty"`
|
||||
Protocol string `json:"protocol"`
|
||||
Description string `json:"description"`
|
||||
}
|
||||
|
||||
type PublicIPv4Assignment struct {
|
||||
Address string `json:"address"`
|
||||
Interface string `json:"interface,omitempty"`
|
||||
PrefixLen int `json:"prefix_len,omitempty"`
|
||||
Gateway string `json:"gateway,omitempty"`
|
||||
}
|
||||
|
||||
type IPv6Assignment struct {
|
||||
Address string `json:"address"`
|
||||
PrefixLen int `json:"prefix_len"`
|
||||
Interface string `json:"interface,omitempty"`
|
||||
}
|
||||
|
||||
type PublicIPv6Prefix struct {
|
||||
Address string `json:"address"`
|
||||
Prefix string `json:"prefix,omitempty"`
|
||||
PrefixLen int `json:"prefix_len"`
|
||||
Interface string `json:"interface,omitempty"`
|
||||
Gateway string `json:"gateway,omitempty"`
|
||||
}
|
||||
|
||||
// SavedTask for persisting task queue across restarts
|
||||
type SavedTask struct {
|
||||
ID string `json:"id"`
|
||||
@@ -68,50 +90,52 @@ type VMReadinessCheck struct {
|
||||
|
||||
// Container represents an LXC container configuration
|
||||
type Container struct {
|
||||
ID int `json:"id"`
|
||||
UUID string `json:"uuid"`
|
||||
Name string `json:"name"`
|
||||
Virtualization string `json:"virtualization,omitempty"`
|
||||
LXCName string `json:"lxc_name,omitempty"`
|
||||
KVMName string `json:"kvm_name,omitempty"`
|
||||
DiskImage string `json:"disk_image,omitempty"`
|
||||
MACAddress string `json:"mac_address,omitempty"`
|
||||
Template string `json:"template"`
|
||||
VCPU float64 `json:"vcpu"`
|
||||
RAMMB int `json:"ram_mb"`
|
||||
DiskGB int `json:"disk_gb"`
|
||||
NetworkBWMbps int `json:"network_bw_mbps"`
|
||||
MonthlyTrafficGB int `json:"monthly_traffic_gb"`
|
||||
TrafficMode string `json:"traffic_mode"` // "total" or "in_out"
|
||||
TrafficInGB int `json:"traffic_in_gb"` // 0 = unlimited
|
||||
TrafficOutGB int `json:"traffic_out_gb"` // 0 = unlimited
|
||||
TrafficUsedRX int64 `json:"traffic_used_rx"`
|
||||
TrafficUsedTX int64 `json:"traffic_used_tx"`
|
||||
TrafficResetDate string `json:"traffic_reset_date"`
|
||||
IOSpeedMBps int `json:"io_speed_mbps"`
|
||||
Status string `json:"status"`
|
||||
IP string `json:"ip"`
|
||||
IPv6 string `json:"ipv6"`
|
||||
IPv6PrefixLen int `json:"ipv6_prefix_len"`
|
||||
IPv6Interface string `json:"ipv6_interface"`
|
||||
VNCPort int `json:"vnc_port"`
|
||||
SSHPort int `json:"ssh_port"`
|
||||
SSHPassword string `json:"ssh_password"`
|
||||
SSHHostKey string `json:"ssh_host_key,omitempty"`
|
||||
PortMappings []PortMapping `json:"port_mappings"`
|
||||
PortMappingLimit int `json:"port_mapping_limit"`
|
||||
SnapshotLimit int `json:"snapshot_limit"`
|
||||
CreatedAt string `json:"created_at"`
|
||||
ExpiresAt string `json:"expires_at"`
|
||||
SnapshotScheduleEnabled bool `json:"snapshot_schedule_enabled"`
|
||||
SnapshotScheduleIntervalHours int `json:"snapshot_schedule_interval_hours"`
|
||||
SnapshotScheduleTime string `json:"snapshot_schedule_time"`
|
||||
SnapshotScheduleLastRun string `json:"snapshot_schedule_last_run"`
|
||||
SnapshotScheduleNextRun string `json:"snapshot_schedule_next_run"`
|
||||
SnapshotScheduleCreatedBy string `json:"snapshot_schedule_created_by"`
|
||||
PolicyBlocked bool `json:"policy_blocked"`
|
||||
PolicyBlockedReason string `json:"policy_blocked_reason,omitempty"`
|
||||
PolicyBlockedAt string `json:"policy_blocked_at,omitempty"`
|
||||
ID int `json:"id"`
|
||||
UUID string `json:"uuid"`
|
||||
Name string `json:"name"`
|
||||
Virtualization string `json:"virtualization,omitempty"`
|
||||
LXCName string `json:"lxc_name,omitempty"`
|
||||
KVMName string `json:"kvm_name,omitempty"`
|
||||
DiskImage string `json:"disk_image,omitempty"`
|
||||
MACAddress string `json:"mac_address,omitempty"`
|
||||
Template string `json:"template"`
|
||||
VCPU float64 `json:"vcpu"`
|
||||
RAMMB int `json:"ram_mb"`
|
||||
DiskGB int `json:"disk_gb"`
|
||||
NetworkBWMbps int `json:"network_bw_mbps"`
|
||||
MonthlyTrafficGB int `json:"monthly_traffic_gb"`
|
||||
TrafficMode string `json:"traffic_mode"` // "total" or "in_out"
|
||||
TrafficInGB int `json:"traffic_in_gb"` // 0 = unlimited
|
||||
TrafficOutGB int `json:"traffic_out_gb"` // 0 = unlimited
|
||||
TrafficUsedRX int64 `json:"traffic_used_rx"`
|
||||
TrafficUsedTX int64 `json:"traffic_used_tx"`
|
||||
TrafficResetDate string `json:"traffic_reset_date"`
|
||||
IOSpeedMBps int `json:"io_speed_mbps"`
|
||||
Status string `json:"status"`
|
||||
IP string `json:"ip"`
|
||||
PublicIPv4s []PublicIPv4Assignment `json:"public_ipv4s,omitempty"`
|
||||
IPv6 string `json:"ipv6"`
|
||||
IPv6PrefixLen int `json:"ipv6_prefix_len"`
|
||||
IPv6Interface string `json:"ipv6_interface"`
|
||||
IPv6Addresses []IPv6Assignment `json:"ipv6_addresses,omitempty"`
|
||||
VNCPort int `json:"vnc_port"`
|
||||
SSHPort int `json:"ssh_port"`
|
||||
SSHPassword string `json:"ssh_password"`
|
||||
SSHHostKey string `json:"ssh_host_key,omitempty"`
|
||||
PortMappings []PortMapping `json:"port_mappings"`
|
||||
PortMappingLimit int `json:"port_mapping_limit"`
|
||||
SnapshotLimit int `json:"snapshot_limit"`
|
||||
CreatedAt string `json:"created_at"`
|
||||
ExpiresAt string `json:"expires_at"`
|
||||
SnapshotScheduleEnabled bool `json:"snapshot_schedule_enabled"`
|
||||
SnapshotScheduleIntervalHours int `json:"snapshot_schedule_interval_hours"`
|
||||
SnapshotScheduleTime string `json:"snapshot_schedule_time"`
|
||||
SnapshotScheduleLastRun string `json:"snapshot_schedule_last_run"`
|
||||
SnapshotScheduleNextRun string `json:"snapshot_schedule_next_run"`
|
||||
SnapshotScheduleCreatedBy string `json:"snapshot_schedule_created_by"`
|
||||
PolicyBlocked bool `json:"policy_blocked"`
|
||||
PolicyBlockedReason string `json:"policy_blocked_reason,omitempty"`
|
||||
PolicyBlockedAt string `json:"policy_blocked_at,omitempty"`
|
||||
}
|
||||
|
||||
const (
|
||||
@@ -136,6 +160,101 @@ func (c *Container) IsKVM() bool {
|
||||
return c.Runtime() == VirtualizationKVM
|
||||
}
|
||||
|
||||
func (c *Container) NormalizeNetworkAssignments() bool {
|
||||
changed := false
|
||||
seenIPv4 := map[string]bool{}
|
||||
filteredIPv4 := make([]PublicIPv4Assignment, 0, len(c.PublicIPv4s))
|
||||
for _, item := range c.PublicIPv4s {
|
||||
item.Address = strings.TrimSpace(item.Address)
|
||||
item.Interface = strings.TrimSpace(item.Interface)
|
||||
item.Gateway = strings.TrimSpace(item.Gateway)
|
||||
if item.Address == "" || seenIPv4[item.Address] {
|
||||
if item.Address != "" {
|
||||
changed = true
|
||||
}
|
||||
continue
|
||||
}
|
||||
seenIPv4[item.Address] = true
|
||||
filteredIPv4 = append(filteredIPv4, item)
|
||||
}
|
||||
if len(filteredIPv4) != len(c.PublicIPv4s) {
|
||||
changed = true
|
||||
}
|
||||
c.PublicIPv4s = filteredIPv4
|
||||
|
||||
seenIPv6 := map[string]bool{}
|
||||
filteredIPv6 := make([]IPv6Assignment, 0, len(c.IPv6Addresses)+1)
|
||||
for _, item := range c.IPv6Addresses {
|
||||
item.Address = strings.TrimSpace(item.Address)
|
||||
item.Interface = strings.TrimSpace(item.Interface)
|
||||
if item.Address == "" || seenIPv6[item.Address] {
|
||||
if item.Address != "" {
|
||||
changed = true
|
||||
}
|
||||
continue
|
||||
}
|
||||
seenIPv6[item.Address] = true
|
||||
filteredIPv6 = append(filteredIPv6, item)
|
||||
}
|
||||
if strings.TrimSpace(c.IPv6) != "" && !seenIPv6[c.IPv6] {
|
||||
filteredIPv6 = append([]IPv6Assignment{{
|
||||
Address: c.IPv6,
|
||||
PrefixLen: c.IPv6PrefixLen,
|
||||
Interface: c.IPv6Interface,
|
||||
}}, filteredIPv6...)
|
||||
changed = true
|
||||
}
|
||||
if len(filteredIPv6) != len(c.IPv6Addresses) {
|
||||
changed = true
|
||||
}
|
||||
c.IPv6Addresses = filteredIPv6
|
||||
if len(c.IPv6Addresses) > 0 {
|
||||
first := c.IPv6Addresses[0]
|
||||
if c.IPv6 != first.Address || c.IPv6PrefixLen != first.PrefixLen || c.IPv6Interface != first.Interface {
|
||||
c.IPv6 = first.Address
|
||||
c.IPv6PrefixLen = first.PrefixLen
|
||||
c.IPv6Interface = first.Interface
|
||||
changed = true
|
||||
}
|
||||
} else if c.IPv6 != "" || c.IPv6PrefixLen != 0 || c.IPv6Interface != "" {
|
||||
c.IPv6 = ""
|
||||
c.IPv6PrefixLen = 0
|
||||
c.IPv6Interface = ""
|
||||
changed = true
|
||||
}
|
||||
return changed
|
||||
}
|
||||
|
||||
func (c *Container) PublicIPv4Addresses() []string {
|
||||
values := make([]string, 0, len(c.PublicIPv4s))
|
||||
for _, item := range c.PublicIPv4s {
|
||||
if item.Address != "" {
|
||||
values = append(values, item.Address)
|
||||
}
|
||||
}
|
||||
return values
|
||||
}
|
||||
|
||||
func (c *Container) PrimaryPublicIPv4() string {
|
||||
if len(c.PublicIPv4s) == 0 {
|
||||
return ""
|
||||
}
|
||||
return c.PublicIPv4s[0].Address
|
||||
}
|
||||
|
||||
func (c *Container) IPv6AddressStrings() []string {
|
||||
values := make([]string, 0, len(c.IPv6Addresses))
|
||||
for _, item := range c.IPv6Addresses {
|
||||
if item.Address != "" {
|
||||
values = append(values, item.Address)
|
||||
}
|
||||
}
|
||||
if len(values) == 0 && c.IPv6 != "" {
|
||||
values = append(values, c.IPv6)
|
||||
}
|
||||
return values
|
||||
}
|
||||
|
||||
// LxcName returns the internal LXC container name (ct-{id})
|
||||
func (c *Container) LxcName() string {
|
||||
if c.LXCName != "" {
|
||||
@@ -225,27 +344,30 @@ type SSLConfig struct {
|
||||
|
||||
// ClicdConfig is the main configuration structure
|
||||
type ClicdConfig struct {
|
||||
AdminUser string `json:"admin_user"`
|
||||
AdminPassHash string `json:"admin_pass_hash"`
|
||||
JWTSecret string `json:"jwt_secret"`
|
||||
Port int `json:"port"`
|
||||
DataDir string `json:"data_dir"`
|
||||
Containers []Container `json:"containers"`
|
||||
NextContainerID int `json:"next_container_id"`
|
||||
NextVNCPort int `json:"next_vnc_port"`
|
||||
NextSSHPort int `json:"next_ssh_port"`
|
||||
SetupComplete bool `json:"setup_complete"`
|
||||
SubUsers []SubUser `json:"sub_users"`
|
||||
ApiKeys []ApiKeyConfig `json:"api_keys"`
|
||||
AuditLogs []AuditLog `json:"audit_logs"`
|
||||
Tasks []SavedTask `json:"tasks"`
|
||||
LoginLogs []SavedLoginLog `json:"login_logs"`
|
||||
EnabledImages []string `json:"enabled_images"`
|
||||
Snapshots []Snapshot `json:"snapshots"`
|
||||
SecurityAutoShutdown bool `json:"security_auto_shutdown"`
|
||||
Language string `json:"language"`
|
||||
SSL SSLConfig `json:"ssl"`
|
||||
SSLCertificates map[string]SSLConfig `json:"ssl_certificates"`
|
||||
AdminUser string `json:"admin_user"`
|
||||
AdminPassHash string `json:"admin_pass_hash"`
|
||||
JWTSecret string `json:"jwt_secret"`
|
||||
Port int `json:"port"`
|
||||
DataDir string `json:"data_dir"`
|
||||
Containers []Container `json:"containers"`
|
||||
NextContainerID int `json:"next_container_id"`
|
||||
NextVNCPort int `json:"next_vnc_port"`
|
||||
NextSSHPort int `json:"next_ssh_port"`
|
||||
SetupComplete bool `json:"setup_complete"`
|
||||
SubUsers []SubUser `json:"sub_users"`
|
||||
ApiKeys []ApiKeyConfig `json:"api_keys"`
|
||||
AuditLogs []AuditLog `json:"audit_logs"`
|
||||
Tasks []SavedTask `json:"tasks"`
|
||||
LoginLogs []SavedLoginLog `json:"login_logs"`
|
||||
EnabledImages []string `json:"enabled_images"`
|
||||
Snapshots []Snapshot `json:"snapshots"`
|
||||
PublicIPv4Pool []PublicIPv4Assignment `json:"public_ipv4_pool"`
|
||||
PublicIPv6Prefixes []PublicIPv6Prefix `json:"public_ipv6_prefixes"`
|
||||
WebSSHAllowedOrigins []string `json:"webssh_allowed_origins"`
|
||||
SecurityAutoShutdown bool `json:"security_auto_shutdown"`
|
||||
Language string `json:"language"`
|
||||
SSL SSLConfig `json:"ssl"`
|
||||
SSLCertificates map[string]SSLConfig `json:"ssl_certificates"`
|
||||
}
|
||||
|
||||
var configPath string
|
||||
@@ -359,21 +481,24 @@ func InitConfig() (*ClicdConfig, error) {
|
||||
}
|
||||
|
||||
AppConfig = &ClicdConfig{
|
||||
AdminUser: adminUser,
|
||||
AdminPassHash: string(hash),
|
||||
JWTSecret: jwtSecret,
|
||||
Port: 8999,
|
||||
DataDir: dataDir,
|
||||
Containers: []Container{},
|
||||
NextContainerID: 1,
|
||||
NextVNCPort: 5900,
|
||||
NextSSHPort: 22000,
|
||||
SetupComplete: false,
|
||||
SubUsers: []SubUser{},
|
||||
AuditLogs: []AuditLog{},
|
||||
Tasks: []SavedTask{},
|
||||
LoginLogs: []SavedLoginLog{},
|
||||
Snapshots: []Snapshot{},
|
||||
AdminUser: adminUser,
|
||||
AdminPassHash: string(hash),
|
||||
JWTSecret: jwtSecret,
|
||||
Port: 8999,
|
||||
DataDir: dataDir,
|
||||
Containers: []Container{},
|
||||
NextContainerID: 1,
|
||||
NextVNCPort: 5900,
|
||||
NextSSHPort: 22000,
|
||||
SetupComplete: false,
|
||||
SubUsers: []SubUser{},
|
||||
AuditLogs: []AuditLog{},
|
||||
Tasks: []SavedTask{},
|
||||
LoginLogs: []SavedLoginLog{},
|
||||
Snapshots: []Snapshot{},
|
||||
PublicIPv4Pool: []PublicIPv4Assignment{},
|
||||
PublicIPv6Prefixes: []PublicIPv6Prefix{},
|
||||
WebSSHAllowedOrigins: []string{},
|
||||
}
|
||||
|
||||
if err := SaveConfig(); err != nil {
|
||||
@@ -424,6 +549,21 @@ func normalizeConfigDefaults(dataDir string) bool {
|
||||
AppConfig.Snapshots = make([]Snapshot, 0)
|
||||
changed = true
|
||||
}
|
||||
if AppConfig.PublicIPv4Pool == nil {
|
||||
AppConfig.PublicIPv4Pool = make([]PublicIPv4Assignment, 0)
|
||||
changed = true
|
||||
}
|
||||
if AppConfig.PublicIPv6Prefixes == nil {
|
||||
AppConfig.PublicIPv6Prefixes = make([]PublicIPv6Prefix, 0)
|
||||
changed = true
|
||||
}
|
||||
if AppConfig.WebSSHAllowedOrigins == nil {
|
||||
AppConfig.WebSSHAllowedOrigins = make([]string, 0)
|
||||
changed = true
|
||||
} else if normalized, err := NormalizeAllowedOrigins(AppConfig.WebSSHAllowedOrigins); err == nil && strings.Join(normalized, "\n") != strings.Join(AppConfig.WebSSHAllowedOrigins, "\n") {
|
||||
AppConfig.WebSSHAllowedOrigins = normalized
|
||||
changed = true
|
||||
}
|
||||
if AppConfig.SubUsers == nil {
|
||||
AppConfig.SubUsers = make([]SubUser, 0)
|
||||
changed = true
|
||||
@@ -546,6 +686,9 @@ func migrateLoadedConfig() bool {
|
||||
if ensureContainerSnapshotLimits() {
|
||||
changed = true
|
||||
}
|
||||
if ensureContainerNetworkAssignments() {
|
||||
changed = true
|
||||
}
|
||||
if ensureContainerSnapshotScheduleDefaults() {
|
||||
changed = true
|
||||
}
|
||||
@@ -608,13 +751,16 @@ func ensureContainerUUIDs() bool {
|
||||
func ensureContainerPortMappingLimits() bool {
|
||||
changed := false
|
||||
for i := range AppConfig.Containers {
|
||||
if AppConfig.Containers[i].PortMappingLimit <= 0 {
|
||||
if AppConfig.Containers[i].PortMappingLimit < 0 {
|
||||
limit := len(AppConfig.Containers[i].PortMappings)
|
||||
if limit < 2 {
|
||||
limit = 2
|
||||
}
|
||||
AppConfig.Containers[i].PortMappingLimit = limit
|
||||
changed = true
|
||||
} else if AppConfig.Containers[i].PortMappingLimit == 0 && len(AppConfig.Containers[i].PortMappings) > 0 {
|
||||
AppConfig.Containers[i].PortMappingLimit = len(AppConfig.Containers[i].PortMappings)
|
||||
changed = true
|
||||
}
|
||||
}
|
||||
return changed
|
||||
@@ -631,6 +777,16 @@ func ensureContainerSnapshotLimits() bool {
|
||||
return changed
|
||||
}
|
||||
|
||||
func ensureContainerNetworkAssignments() bool {
|
||||
changed := false
|
||||
for i := range AppConfig.Containers {
|
||||
if AppConfig.Containers[i].NormalizeNetworkAssignments() {
|
||||
changed = true
|
||||
}
|
||||
}
|
||||
return changed
|
||||
}
|
||||
|
||||
func migrateSubUsers() bool {
|
||||
changed := false
|
||||
for i := range AppConfig.SubUsers {
|
||||
|
||||
@@ -0,0 +1,136 @@
|
||||
package config
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"net"
|
||||
"net/url"
|
||||
"strings"
|
||||
)
|
||||
|
||||
// NormalizeAllowedOrigin accepts a browser Origin value such as
|
||||
// https://www.example.com and returns a canonical form for exact matching.
|
||||
func NormalizeAllowedOrigin(value string) (string, error) {
|
||||
value = strings.TrimSpace(value)
|
||||
if value == "" {
|
||||
return "", nil
|
||||
}
|
||||
u, err := url.Parse(value)
|
||||
if err != nil || u.Scheme == "" || u.Host == "" {
|
||||
return "", fmt.Errorf("Origin must include scheme and host: %s", value)
|
||||
}
|
||||
scheme := strings.ToLower(u.Scheme)
|
||||
if scheme != "http" && scheme != "https" {
|
||||
return "", fmt.Errorf("Origin scheme must be http or https: %s", value)
|
||||
}
|
||||
if (u.Path != "" && u.Path != "/") || u.RawQuery != "" || u.Fragment != "" {
|
||||
return "", fmt.Errorf("Origin must not include path, query, or fragment: %s", value)
|
||||
}
|
||||
host := normalizeOriginHostPort(u.Host, scheme)
|
||||
if host == "" {
|
||||
return "", fmt.Errorf("Origin host is required: %s", value)
|
||||
}
|
||||
return scheme + "://" + host, nil
|
||||
}
|
||||
|
||||
func NormalizeAllowedOrigins(values []string) ([]string, error) {
|
||||
result := make([]string, 0, len(values))
|
||||
seen := map[string]bool{}
|
||||
for _, value := range values {
|
||||
origin, err := NormalizeAllowedOrigin(value)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if origin == "" || seen[origin] {
|
||||
continue
|
||||
}
|
||||
seen[origin] = true
|
||||
result = append(result, origin)
|
||||
}
|
||||
return result, nil
|
||||
}
|
||||
|
||||
func IsOriginAllowed(origin string, requestHost string) bool {
|
||||
origin = strings.TrimSpace(origin)
|
||||
if origin == "" {
|
||||
return true
|
||||
}
|
||||
if isSameRequestOrigin(origin, requestHost) {
|
||||
return true
|
||||
}
|
||||
normalized, err := NormalizeAllowedOrigin(origin)
|
||||
if err != nil {
|
||||
return false
|
||||
}
|
||||
if AppConfig == nil {
|
||||
return false
|
||||
}
|
||||
for _, allowed := range AppConfig.WebSSHAllowedOrigins {
|
||||
allowed, err := NormalizeAllowedOrigin(allowed)
|
||||
if err == nil && normalized == allowed {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func isSameRequestOrigin(origin string, requestHost string) bool {
|
||||
u, err := url.Parse(origin)
|
||||
if err != nil || u.Host == "" {
|
||||
return false
|
||||
}
|
||||
originHost := normalizeHostOnly(u.Hostname())
|
||||
host := normalizeHostOnly(requestHost)
|
||||
if originHost == "" || host == "" {
|
||||
return false
|
||||
}
|
||||
if originHost == host {
|
||||
return true
|
||||
}
|
||||
return isLoopbackHost(originHost) && isLoopbackHost(host)
|
||||
}
|
||||
|
||||
func normalizeOriginHostPort(raw string, scheme string) string {
|
||||
host := raw
|
||||
port := ""
|
||||
if h, p, err := net.SplitHostPort(raw); err == nil {
|
||||
host = h
|
||||
port = p
|
||||
}
|
||||
host = normalizeHostOnly(host)
|
||||
if host == "" {
|
||||
return ""
|
||||
}
|
||||
if (scheme == "https" && port == "443") || (scheme == "http" && port == "80") {
|
||||
port = ""
|
||||
}
|
||||
if port != "" {
|
||||
return net.JoinHostPort(host, port)
|
||||
}
|
||||
if strings.Contains(host, ":") && net.ParseIP(host) != nil {
|
||||
return "[" + host + "]"
|
||||
}
|
||||
return host
|
||||
}
|
||||
|
||||
func normalizeHostOnly(raw string) string {
|
||||
raw = strings.TrimSpace(raw)
|
||||
if raw == "" {
|
||||
return ""
|
||||
}
|
||||
if h, _, err := net.SplitHostPort(raw); err == nil {
|
||||
raw = h
|
||||
}
|
||||
raw = strings.Trim(raw, "[]")
|
||||
if ip := net.ParseIP(raw); ip != nil {
|
||||
return strings.ToLower(ip.String())
|
||||
}
|
||||
return strings.TrimSuffix(strings.ToLower(raw), ".")
|
||||
}
|
||||
|
||||
func isLoopbackHost(host string) bool {
|
||||
if host == "localhost" {
|
||||
return true
|
||||
}
|
||||
ip := net.ParseIP(host)
|
||||
return ip != nil && ip.IsLoopback()
|
||||
}
|
||||
@@ -20,24 +20,33 @@ var (
|
||||
)
|
||||
|
||||
type savedTaskConfig struct {
|
||||
Name string `json:"name"`
|
||||
Virtualization string `json:"virtualization,omitempty"`
|
||||
TemplateID string `json:"template_id"`
|
||||
VCPU float64 `json:"vcpu"`
|
||||
CPUPercent int `json:"cpu_percent"`
|
||||
RAMMB int `json:"ram_mb"`
|
||||
DiskGB int `json:"disk_gb"`
|
||||
NetworkBWMbps int `json:"network_bw_mbps"`
|
||||
MonthlyTrafficGB int `json:"monthly_traffic_gb"`
|
||||
TrafficMode string `json:"traffic_mode"`
|
||||
TrafficInGB int `json:"traffic_in_gb"`
|
||||
TrafficOutGB int `json:"traffic_out_gb"`
|
||||
IOSpeedMBps int `json:"io_speed_mbps"`
|
||||
ExtraPorts []int `json:"extra_ports"`
|
||||
PortMappingCount int `json:"port_mapping_count"`
|
||||
SnapshotLimit int `json:"snapshot_limit"`
|
||||
AssignIPv6 bool `json:"assign_ipv6"`
|
||||
ExpiresAt string `json:"expires_at"`
|
||||
Name string `json:"name"`
|
||||
Virtualization string `json:"virtualization,omitempty"`
|
||||
TemplateID string `json:"template_id"`
|
||||
VCPU float64 `json:"vcpu"`
|
||||
CPUPercent int `json:"cpu_percent"`
|
||||
RAMMB int `json:"ram_mb"`
|
||||
DiskGB int `json:"disk_gb"`
|
||||
NetworkBWMbps int `json:"network_bw_mbps"`
|
||||
MonthlyTrafficGB int `json:"monthly_traffic_gb"`
|
||||
TrafficMode string `json:"traffic_mode"`
|
||||
TrafficInGB int `json:"traffic_in_gb"`
|
||||
TrafficOutGB int `json:"traffic_out_gb"`
|
||||
IOSpeedMBps int `json:"io_speed_mbps"`
|
||||
ExtraPorts []int `json:"extra_ports"`
|
||||
PortMappingCount int `json:"port_mapping_count"`
|
||||
AssignNAT *bool `json:"assign_nat,omitempty"`
|
||||
SnapshotLimit int `json:"snapshot_limit"`
|
||||
AssignIPv4 bool `json:"assign_ipv4"`
|
||||
IPv4Count int `json:"ipv4_count,omitempty"`
|
||||
PublicIPv4s []string `json:"public_ipv4s,omitempty"`
|
||||
AssignIPv6 bool `json:"assign_ipv6"`
|
||||
IPv6Count int `json:"ipv6_count,omitempty"`
|
||||
IPv6Addresses []string `json:"ipv6_addresses,omitempty"`
|
||||
SSHAuthMode string `json:"ssh_auth_mode,omitempty"`
|
||||
SSHPassword string `json:"ssh_password,omitempty"`
|
||||
SSHPublicKey string `json:"ssh_public_key,omitempty"`
|
||||
ExpiresAt string `json:"expires_at"`
|
||||
}
|
||||
|
||||
func parseSavedTaskConfig(raw string) savedTaskConfig {
|
||||
@@ -175,10 +184,28 @@ func ensureSchema() error {
|
||||
position INTEGER NOT NULL,
|
||||
container_port INTEGER NOT NULL,
|
||||
host_port INTEGER NOT NULL,
|
||||
host_ip TEXT,
|
||||
protocol TEXT,
|
||||
description TEXT,
|
||||
PRIMARY KEY (container_id, position)
|
||||
)`,
|
||||
`CREATE TABLE IF NOT EXISTS container_public_ipv4s (
|
||||
container_id INTEGER NOT NULL,
|
||||
position INTEGER NOT NULL,
|
||||
address TEXT NOT NULL,
|
||||
interface TEXT,
|
||||
prefix_len INTEGER,
|
||||
gateway TEXT,
|
||||
PRIMARY KEY (container_id, position)
|
||||
)`,
|
||||
`CREATE TABLE IF NOT EXISTS container_ipv6_addresses (
|
||||
container_id INTEGER NOT NULL,
|
||||
position INTEGER NOT NULL,
|
||||
address TEXT NOT NULL,
|
||||
prefix_len INTEGER,
|
||||
interface TEXT,
|
||||
PRIMARY KEY (container_id, position)
|
||||
)`,
|
||||
`CREATE TABLE IF NOT EXISTS sub_users (
|
||||
id TEXT PRIMARY KEY,
|
||||
username TEXT NOT NULL,
|
||||
@@ -253,8 +280,17 @@ func ensureSchema() error {
|
||||
cfg_traffic_out_gb INTEGER,
|
||||
cfg_io_speed_mbps INTEGER,
|
||||
cfg_port_mapping_count INTEGER,
|
||||
cfg_assign_nat INTEGER,
|
||||
cfg_snapshot_limit INTEGER,
|
||||
cfg_assign_ipv4 INTEGER,
|
||||
cfg_ipv4_count INTEGER,
|
||||
cfg_public_ipv4s TEXT,
|
||||
cfg_assign_ipv6 INTEGER,
|
||||
cfg_ipv6_count INTEGER,
|
||||
cfg_ipv6_addresses TEXT,
|
||||
cfg_ssh_auth_mode TEXT,
|
||||
cfg_ssh_password TEXT,
|
||||
cfg_ssh_public_key TEXT,
|
||||
cfg_expires_at TEXT
|
||||
)`,
|
||||
`CREATE TABLE IF NOT EXISTS task_extra_ports (
|
||||
@@ -308,6 +344,18 @@ func ensureSchemaMigrations() error {
|
||||
{"api_keys", "last_used_ip", "TEXT"},
|
||||
{"tasks", "ip", "TEXT"},
|
||||
{"tasks", "user_agent", "TEXT"},
|
||||
{"tasks", "cfg_assign_ipv4", "INTEGER"},
|
||||
{"tasks", "cfg_ipv4_count", "INTEGER"},
|
||||
{"tasks", "cfg_public_ipv4s", "TEXT"},
|
||||
{"tasks", "cfg_assign_nat", "INTEGER"},
|
||||
{"tasks", "cfg_ipv6_count", "INTEGER"},
|
||||
{"tasks", "cfg_ipv6_addresses", "TEXT"},
|
||||
{"tasks", "cfg_ssh_auth_mode", "TEXT"},
|
||||
{"tasks", "cfg_ssh_password", "TEXT"},
|
||||
{"tasks", "cfg_ssh_public_key", "TEXT"},
|
||||
{"port_mappings", "host_ip", "TEXT"},
|
||||
{"container_public_ipv4s", "prefix_len", "INTEGER"},
|
||||
{"container_public_ipv4s", "gateway", "TEXT"},
|
||||
} {
|
||||
if err := ensureColumn(column.table, column.name, column.def); err != nil {
|
||||
return err
|
||||
@@ -381,6 +429,15 @@ func loadConfigFromDB() (*ClicdConfig, bool, error) {
|
||||
if raw := strings.TrimSpace(meta["ssl_certificates"]); raw != "" {
|
||||
_ = json.Unmarshal([]byte(raw), &cfg.SSLCertificates)
|
||||
}
|
||||
if raw := strings.TrimSpace(meta["public_ipv4_pool"]); raw != "" {
|
||||
_ = json.Unmarshal([]byte(raw), &cfg.PublicIPv4Pool)
|
||||
}
|
||||
if raw := strings.TrimSpace(meta["public_ipv6_prefixes"]); raw != "" {
|
||||
_ = json.Unmarshal([]byte(raw), &cfg.PublicIPv6Prefixes)
|
||||
}
|
||||
if raw := strings.TrimSpace(meta["webssh_allowed_origins"]); raw != "" {
|
||||
_ = json.Unmarshal([]byte(raw), &cfg.WebSSHAllowedOrigins)
|
||||
}
|
||||
|
||||
if cfg.Containers, err = loadContainers(); err != nil {
|
||||
return nil, false, err
|
||||
@@ -424,6 +481,8 @@ func saveConfigToDB() error {
|
||||
|
||||
for _, table := range []string{
|
||||
"port_mappings",
|
||||
"container_public_ipv4s",
|
||||
"container_ipv6_addresses",
|
||||
"sub_user_container_names",
|
||||
"sub_user_container_uuids",
|
||||
"containers",
|
||||
@@ -475,6 +534,9 @@ func saveConfigToDB() error {
|
||||
func saveMeta(tx *sql.Tx) error {
|
||||
sslJSON, _ := json.Marshal(AppConfig.SSL)
|
||||
sslCertificatesJSON, _ := json.Marshal(AppConfig.SSLCertificates)
|
||||
publicIPv4PoolJSON, _ := json.Marshal(AppConfig.PublicIPv4Pool)
|
||||
publicIPv6PrefixesJSON, _ := json.Marshal(AppConfig.PublicIPv6Prefixes)
|
||||
webSSHAllowedOriginsJSON, _ := json.Marshal(AppConfig.WebSSHAllowedOrigins)
|
||||
values := map[string]string{
|
||||
"admin_user": AppConfig.AdminUser,
|
||||
"admin_pass_hash": AppConfig.AdminPassHash,
|
||||
@@ -489,6 +551,9 @@ func saveMeta(tx *sql.Tx) error {
|
||||
"language": NormalizeLanguage(AppConfig.Language),
|
||||
"ssl": string(sslJSON),
|
||||
"ssl_certificates": string(sslCertificatesJSON),
|
||||
"public_ipv4_pool": string(publicIPv4PoolJSON),
|
||||
"public_ipv6_prefixes": string(publicIPv6PrefixesJSON),
|
||||
"webssh_allowed_origins": string(webSSHAllowedOriginsJSON),
|
||||
"schema_version": "1",
|
||||
"updated_at": time.Now().Format("2006-01-02 15:04:05"),
|
||||
}
|
||||
@@ -524,8 +589,20 @@ func saveContainers(tx *sql.Tx) error {
|
||||
return err
|
||||
}
|
||||
for i, pm := range c.PortMappings {
|
||||
if _, err := tx.Exec(`INSERT INTO port_mappings(container_id, position, container_port, host_port, protocol, description)
|
||||
VALUES (?, ?, ?, ?, ?, ?)`, c.ID, i, pm.ContainerPort, pm.HostPort, pm.Protocol, pm.Description); err != nil {
|
||||
if _, err := tx.Exec(`INSERT INTO port_mappings(container_id, position, container_port, host_port, host_ip, protocol, description)
|
||||
VALUES (?, ?, ?, ?, ?, ?, ?)`, c.ID, i, pm.ContainerPort, pm.HostPort, pm.HostIP, pm.Protocol, pm.Description); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
for i, ip := range c.PublicIPv4s {
|
||||
if _, err := tx.Exec(`INSERT INTO container_public_ipv4s(container_id, position, address, interface, prefix_len, gateway)
|
||||
VALUES (?, ?, ?, ?, ?, ?)`, c.ID, i, ip.Address, ip.Interface, ip.PrefixLen, ip.Gateway); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
for i, ip := range c.IPv6Addresses {
|
||||
if _, err := tx.Exec(`INSERT INTO container_ipv6_addresses(container_id, position, address, prefix_len, interface)
|
||||
VALUES (?, ?, ?, ?, ?)`, c.ID, i, ip.Address, ip.PrefixLen, ip.Interface); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
@@ -590,14 +667,17 @@ func saveTasksDB(tx *sql.Tx) error {
|
||||
id, type, container_id, container_name, status, error, created_at, template_id, user, ip, user_agent,
|
||||
cfg_name, cfg_virtualization, cfg_template_id, cfg_vcpu, cfg_cpu_percent, cfg_ram_mb, cfg_disk_gb,
|
||||
cfg_network_bw_mbps, cfg_monthly_traffic_gb, cfg_traffic_mode, cfg_traffic_in_gb,
|
||||
cfg_traffic_out_gb, cfg_io_speed_mbps, cfg_port_mapping_count, cfg_snapshot_limit,
|
||||
cfg_assign_ipv6, cfg_expires_at
|
||||
) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)`,
|
||||
cfg_traffic_out_gb, cfg_io_speed_mbps, cfg_port_mapping_count, cfg_assign_nat, cfg_snapshot_limit,
|
||||
cfg_assign_ipv4, cfg_ipv4_count, cfg_public_ipv4s, cfg_assign_ipv6, cfg_ipv6_count, cfg_ipv6_addresses,
|
||||
cfg_ssh_auth_mode, cfg_ssh_password, cfg_ssh_public_key, cfg_expires_at
|
||||
) VALUES (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)`,
|
||||
task.ID, task.Type, task.ContainerID, task.ContainerName, task.Status, task.Error, task.CreatedAt, task.TemplateID, task.User, task.IP, task.UserAgent,
|
||||
cfg.Name, cfg.Virtualization, cfg.TemplateID, cfg.VCPU, cfg.CPUPercent, cfg.RAMMB, cfg.DiskGB,
|
||||
cfg.NetworkBWMbps, cfg.MonthlyTrafficGB, cfg.TrafficMode, cfg.TrafficInGB,
|
||||
cfg.TrafficOutGB, cfg.IOSpeedMBps, cfg.PortMappingCount, cfg.SnapshotLimit,
|
||||
boolInt(cfg.AssignIPv6), cfg.ExpiresAt,
|
||||
cfg.TrafficOutGB, cfg.IOSpeedMBps, cfg.PortMappingCount, boolPtrInt(cfg.AssignNAT), cfg.SnapshotLimit,
|
||||
boolInt(cfg.AssignIPv4), cfg.IPv4Count, encodeStringSlice(cfg.PublicIPv4s),
|
||||
boolInt(cfg.AssignIPv6), cfg.IPv6Count, encodeStringSlice(cfg.IPv6Addresses),
|
||||
cfg.SSHAuthMode, cfg.SSHPassword, cfg.SSHPublicKey, cfg.ExpiresAt,
|
||||
); err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -686,12 +766,21 @@ func loadContainers() ([]Container, error) {
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
result[i].PublicIPv4s, err = loadContainerPublicIPv4s(result[i].ID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
result[i].IPv6Addresses, err = loadContainerIPv6Addresses(result[i].ID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
result[i].NormalizeNetworkAssignments()
|
||||
}
|
||||
return result, nil
|
||||
}
|
||||
|
||||
func loadPortMappings(containerID int) ([]PortMapping, error) {
|
||||
rows, err := db.Query(`SELECT container_port, host_port, protocol, description FROM port_mappings WHERE container_id = ? ORDER BY position`, containerID)
|
||||
rows, err := db.Query(`SELECT container_port, host_port, host_ip, protocol, description FROM port_mappings WHERE container_id = ? ORDER BY position`, containerID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -699,14 +788,64 @@ func loadPortMappings(containerID int) ([]PortMapping, error) {
|
||||
result := []PortMapping{}
|
||||
for rows.Next() {
|
||||
var pm PortMapping
|
||||
if err := rows.Scan(&pm.ContainerPort, &pm.HostPort, &pm.Protocol, &pm.Description); err != nil {
|
||||
var hostIP sql.NullString
|
||||
if err := rows.Scan(&pm.ContainerPort, &pm.HostPort, &hostIP, &pm.Protocol, &pm.Description); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
pm.HostIP = hostIP.String
|
||||
result = append(result, pm)
|
||||
}
|
||||
return result, rows.Err()
|
||||
}
|
||||
|
||||
func loadContainerPublicIPv4s(containerID int) ([]PublicIPv4Assignment, error) {
|
||||
rows, err := db.Query(`SELECT address, interface, prefix_len, gateway FROM container_public_ipv4s WHERE container_id = ? ORDER BY position`, containerID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
defer rows.Close()
|
||||
result := []PublicIPv4Assignment{}
|
||||
for rows.Next() {
|
||||
var item PublicIPv4Assignment
|
||||
var iface sql.NullString
|
||||
var prefixLen sql.NullInt64
|
||||
var gateway sql.NullString
|
||||
if err := rows.Scan(&item.Address, &iface, &prefixLen, &gateway); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
item.Interface = iface.String
|
||||
if prefixLen.Valid {
|
||||
item.PrefixLen = int(prefixLen.Int64)
|
||||
}
|
||||
item.Gateway = gateway.String
|
||||
result = append(result, item)
|
||||
}
|
||||
return result, rows.Err()
|
||||
}
|
||||
|
||||
func loadContainerIPv6Addresses(containerID int) ([]IPv6Assignment, error) {
|
||||
rows, err := db.Query(`SELECT address, prefix_len, interface FROM container_ipv6_addresses WHERE container_id = ? ORDER BY position`, containerID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
defer rows.Close()
|
||||
result := []IPv6Assignment{}
|
||||
for rows.Next() {
|
||||
var item IPv6Assignment
|
||||
var prefixLen sql.NullInt64
|
||||
var iface sql.NullString
|
||||
if err := rows.Scan(&item.Address, &prefixLen, &iface); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if prefixLen.Valid {
|
||||
item.PrefixLen = int(prefixLen.Int64)
|
||||
}
|
||||
item.Interface = iface.String
|
||||
result = append(result, item)
|
||||
}
|
||||
return result, rows.Err()
|
||||
}
|
||||
|
||||
func loadSubUsers() ([]SubUser, error) {
|
||||
rows, err := db.Query(`SELECT id, username, password, pass_hash, access_code, created_at, token_version FROM sub_users ORDER BY created_at, id`)
|
||||
if err != nil {
|
||||
@@ -808,8 +947,9 @@ func loadTasks() ([]SavedTask, error) {
|
||||
id, type, container_id, container_name, status, error, created_at, template_id, user, ip, user_agent,
|
||||
cfg_name, cfg_virtualization, cfg_template_id, cfg_vcpu, cfg_cpu_percent, cfg_ram_mb, cfg_disk_gb,
|
||||
cfg_network_bw_mbps, cfg_monthly_traffic_gb, cfg_traffic_mode, cfg_traffic_in_gb,
|
||||
cfg_traffic_out_gb, cfg_io_speed_mbps, cfg_port_mapping_count, cfg_snapshot_limit,
|
||||
cfg_assign_ipv6, cfg_expires_at
|
||||
cfg_traffic_out_gb, cfg_io_speed_mbps, cfg_port_mapping_count, cfg_assign_nat, cfg_snapshot_limit,
|
||||
cfg_assign_ipv4, cfg_ipv4_count, cfg_public_ipv4s, cfg_assign_ipv6, cfg_ipv6_count, cfg_ipv6_addresses,
|
||||
cfg_ssh_auth_mode, cfg_ssh_password, cfg_ssh_public_key, cfg_expires_at
|
||||
FROM tasks ORDER BY created_at, id`)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
@@ -820,20 +960,39 @@ func loadTasks() ([]SavedTask, error) {
|
||||
for rows.Next() {
|
||||
var t SavedTask
|
||||
var cfg savedTaskConfig
|
||||
var assignIPv6 int
|
||||
var ip, userAgent sql.NullString
|
||||
var assignIPv4, assignIPv6 int
|
||||
var ip, userAgent, publicIPv4s, ipv6Addresses sql.NullString
|
||||
var sshAuthMode, sshPassword, sshPublicKey sql.NullString
|
||||
var assignNAT, ipv4Count, ipv6Count sql.NullInt64
|
||||
if err := rows.Scan(
|
||||
&t.ID, &t.Type, &t.ContainerID, &t.ContainerName, &t.Status, &t.Error, &t.CreatedAt, &t.TemplateID, &t.User, &ip, &userAgent,
|
||||
&cfg.Name, &cfg.Virtualization, &cfg.TemplateID, &cfg.VCPU, &cfg.CPUPercent, &cfg.RAMMB, &cfg.DiskGB,
|
||||
&cfg.NetworkBWMbps, &cfg.MonthlyTrafficGB, &cfg.TrafficMode, &cfg.TrafficInGB,
|
||||
&cfg.TrafficOutGB, &cfg.IOSpeedMBps, &cfg.PortMappingCount, &cfg.SnapshotLimit,
|
||||
&assignIPv6, &cfg.ExpiresAt,
|
||||
&cfg.TrafficOutGB, &cfg.IOSpeedMBps, &cfg.PortMappingCount, &assignNAT, &cfg.SnapshotLimit,
|
||||
&assignIPv4, &ipv4Count, &publicIPv4s, &assignIPv6, &ipv6Count, &ipv6Addresses,
|
||||
&sshAuthMode, &sshPassword, &sshPublicKey, &cfg.ExpiresAt,
|
||||
); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
t.IP = ip.String
|
||||
t.UserAgent = userAgent.String
|
||||
if assignNAT.Valid {
|
||||
value := assignNAT.Int64 != 0
|
||||
cfg.AssignNAT = &value
|
||||
}
|
||||
cfg.AssignIPv4 = assignIPv4 != 0
|
||||
if ipv4Count.Valid {
|
||||
cfg.IPv4Count = int(ipv4Count.Int64)
|
||||
}
|
||||
cfg.PublicIPv4s = decodeStringSlice(publicIPv4s.String)
|
||||
cfg.AssignIPv6 = assignIPv6 != 0
|
||||
if ipv6Count.Valid {
|
||||
cfg.IPv6Count = int(ipv6Count.Int64)
|
||||
}
|
||||
cfg.IPv6Addresses = decodeStringSlice(ipv6Addresses.String)
|
||||
cfg.SSHAuthMode = sshAuthMode.String
|
||||
cfg.SSHPassword = sshPassword.String
|
||||
cfg.SSHPublicKey = sshPublicKey.String
|
||||
result = append(result, t)
|
||||
configs = append(configs, cfg)
|
||||
}
|
||||
@@ -947,6 +1106,13 @@ func boolInt(value bool) int {
|
||||
return 0
|
||||
}
|
||||
|
||||
func boolPtrInt(value *bool) interface{} {
|
||||
if value == nil {
|
||||
return nil
|
||||
}
|
||||
return boolInt(*value)
|
||||
}
|
||||
|
||||
func btoa(value bool) string {
|
||||
if value {
|
||||
return "1"
|
||||
|
||||
+315
-91
@@ -364,8 +364,11 @@ func (m *Manager) CreateContainer(cfg lxc.ContainerConfig) error {
|
||||
if cfg.VCPU < 1 || cfg.VCPU != float64(int(cfg.VCPU)) {
|
||||
return fmt.Errorf("KVM vCPU must be a whole number and at least 1")
|
||||
}
|
||||
if cfg.PortMappingCount < 2 {
|
||||
if cfg.WantsNAT() && cfg.PortMappingCount < 2 {
|
||||
cfg.PortMappingCount = 2
|
||||
} else if !cfg.WantsNAT() {
|
||||
cfg.PortMappingCount = 0
|
||||
cfg.ExtraPorts = nil
|
||||
}
|
||||
if cfg.SnapshotLimit <= 0 {
|
||||
cfg.SnapshotLimit = config.DefaultSnapshotLimit
|
||||
@@ -403,18 +406,30 @@ func (m *Manager) defineContainer(id int, vmName string, cfg lxc.ContainerConfig
|
||||
seedPath := filepath.Join(m.instanceDir(vmName), "seed.iso")
|
||||
mac := randomMAC()
|
||||
sshPassword := generateRandomString(16)
|
||||
ipv6 := ""
|
||||
ipv6PrefixLen := 0
|
||||
ipv6Interface := ""
|
||||
if cfg.AssignIPv6 {
|
||||
assigned, prefixLen, iface, err := m.allocateIPv6ForContainer(id)
|
||||
sshPublicKey := ""
|
||||
if !IsWindowsImage(image.ID) {
|
||||
sshAccess, err := lxc.ResolveCreateSSHAccess(cfg)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
ipv6 = assigned
|
||||
ipv6PrefixLen = prefixLen
|
||||
ipv6Interface = iface
|
||||
sshPassword = sshAccess.Password
|
||||
sshPublicKey = sshAccess.PublicKey
|
||||
}
|
||||
publicIPv4s, err := lxc.AllocatePublicIPv4Assignments(id, cfg.PublicIPv4s, cfg.IPv4Count, cfg.AssignIPv4)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
|
||||
ipv6Assignments := []config.IPv6Assignment{}
|
||||
if cfg.AssignIPv6 || len(cfg.IPv6Addresses) > 0 {
|
||||
assigned, err := m.allocateIPv6AssignmentsForContainer(id, cfg.IPv6Addresses, cfg.IPv6Count, true)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
ipv6Assignments = assigned
|
||||
}
|
||||
ipv6List := configIPv6AssignmentAddresses(ipv6Assignments)
|
||||
defaultHostIP := lxc.DefaultPortMappingHostIP(publicIPv4s)
|
||||
|
||||
var xml string
|
||||
winAdminPassword := ""
|
||||
@@ -433,7 +448,7 @@ func (m *Manager) defineContainer(id int, vmName string, cfg lxc.ContainerConfig
|
||||
}
|
||||
winAdminPassword = generateWindowsPassword()
|
||||
unattendPath := filepath.Join(m.instanceDir(vmName), "unattend.iso")
|
||||
if err := createWindowsUnattendISO(unattendPath, cfg.Name, winAdminPassword, ipv6); err != nil {
|
||||
if err := createWindowsUnattendISO(unattendPath, cfg.Name, winAdminPassword, ipv6List); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
xml = windowsDomainXML(vmName, int(cfg.VCPU), cfg.RAMMB, diskPath, ImagePath(image.ID), unattendPath, mac, cfg.IOSpeedMBps, cfg.NetworkBWMbps)
|
||||
@@ -449,7 +464,7 @@ func (m *Manager) defineContainer(id int, vmName string, cfg lxc.ContainerConfig
|
||||
if err := createOverlayDisk(ImagePath(image.ID), diskPath, cfg.DiskGB); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
if err := createSeedISO(seedPath, vmName, cfg.Name, sshPassword, mac, ipv6, *image); err != nil {
|
||||
if err := createSeedISO(seedPath, vmName, cfg.Name, sshPassword, sshPublicKey, mac, ipv6List, *image); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
xml = domainXML(vmName, int(cfg.VCPU), cfg.RAMMB, diskPath, seedPath, mac, cfg.IOSpeedMBps, cfg.NetworkBWMbps, image.Desktop != "")
|
||||
@@ -465,20 +480,26 @@ func (m *Manager) defineContainer(id int, vmName string, cfg lxc.ContainerConfig
|
||||
|
||||
sshPort := 0
|
||||
portMappings := []config.PortMapping{}
|
||||
if allocatePorts {
|
||||
if allocatePorts && cfg.WantsNAT() {
|
||||
sshPort = config.AllocateSSHPort()
|
||||
if IsWindowsImage(image.ID) {
|
||||
// Windows: RDP (3389) instead of SSH (22)
|
||||
portMappings = []config.PortMapping{{
|
||||
ContainerPort: 3389,
|
||||
HostPort: sshPort,
|
||||
HostIP: defaultHostIP,
|
||||
Protocol: "tcp",
|
||||
Description: "RDP",
|
||||
}}
|
||||
} else {
|
||||
portMappings = lxc.SetupDefaultPortMappings(sshPort)
|
||||
if defaultHostIP != "" {
|
||||
for i := range portMappings {
|
||||
portMappings[i].HostIP = defaultHostIP
|
||||
}
|
||||
}
|
||||
}
|
||||
tempC := &config.Container{PortMappings: portMappings}
|
||||
tempC := &config.Container{ID: id, PublicIPv4s: publicIPv4s, PortMappings: portMappings}
|
||||
extraPorts := cfg.ExtraPorts
|
||||
if len(extraPorts) == 0 && cfg.PortMappingCount > 1 {
|
||||
extraPorts = allocateDefaultEqualPorts(tempC, cfg.PortMappingCount-1)
|
||||
@@ -490,6 +511,7 @@ func (m *Manager) defineContainer(id int, vmName string, cfg lxc.ContainerConfig
|
||||
tempC.PortMappings = append(tempC.PortMappings, config.PortMapping{
|
||||
ContainerPort: port,
|
||||
HostPort: port,
|
||||
HostIP: defaultHostIP,
|
||||
Protocol: "tcp",
|
||||
Description: fmt.Sprintf("Port-%d", port),
|
||||
})
|
||||
@@ -502,7 +524,7 @@ func (m *Manager) defineContainer(id int, vmName string, cfg lxc.ContainerConfig
|
||||
if trafficMode == "" {
|
||||
trafficMode = "total"
|
||||
}
|
||||
return &config.Container{
|
||||
container := &config.Container{
|
||||
ID: id,
|
||||
UUID: config.NewContainerUUID(),
|
||||
Name: cfg.Name,
|
||||
@@ -521,9 +543,8 @@ func (m *Manager) defineContainer(id int, vmName string, cfg lxc.ContainerConfig
|
||||
TrafficOutGB: cfg.TrafficOutGB,
|
||||
TrafficResetDate: now[:7],
|
||||
IOSpeedMBps: cfg.IOSpeedMBps,
|
||||
IPv6: ipv6,
|
||||
IPv6PrefixLen: ipv6PrefixLen,
|
||||
IPv6Interface: ipv6Interface,
|
||||
PublicIPv4s: publicIPv4s,
|
||||
IPv6Addresses: ipv6Assignments,
|
||||
Status: "stopped",
|
||||
SSHPort: sshPort,
|
||||
SSHPassword: func() string {
|
||||
@@ -537,7 +558,9 @@ func (m *Manager) defineContainer(id int, vmName string, cfg lxc.ContainerConfig
|
||||
SnapshotLimit: config.NormalizeSnapshotLimit(cfg.SnapshotLimit),
|
||||
CreatedAt: now,
|
||||
ExpiresAt: cfg.ExpiresAt,
|
||||
}, nil
|
||||
}
|
||||
container.NormalizeNetworkAssignments()
|
||||
return container, nil
|
||||
}
|
||||
|
||||
func (m *Manager) StartContainer(id int) error {
|
||||
@@ -548,6 +571,7 @@ func (m *Manager) StartContainer(id int) error {
|
||||
if err := m.validateHost(IsWindowsImage(c.Template)); err != nil {
|
||||
return err
|
||||
}
|
||||
lxc.EnsureAssignedPublicIPv4s(c.PublicIPv4s)
|
||||
name := c.VirshName()
|
||||
if err := m.ensureDomainDefinition(c); err != nil {
|
||||
fmt.Printf("Warning: failed to refresh KVM domain definition for %s: %v\n", name, err)
|
||||
@@ -598,7 +622,7 @@ func (m *Manager) StartContainer(id int) error {
|
||||
return err
|
||||
}
|
||||
}
|
||||
if c.IPv6 != "" {
|
||||
if c.IPv6 != "" || len(c.IPv6Addresses) > 0 {
|
||||
if err := m.applyIPv6Runtime(c); err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -662,7 +686,7 @@ func (m *Manager) DestroyContainer(id int) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
func (m *Manager) ReinstallContainer(id int, templateID string) error {
|
||||
func (m *Manager) ReinstallContainer(id int, templateID string, authConfig ...lxc.ContainerConfig) error {
|
||||
c := config.FindContainer(id)
|
||||
if c == nil {
|
||||
return fmt.Errorf("container not found: %d", id)
|
||||
@@ -694,6 +718,19 @@ func (m *Manager) ReinstallContainer(id int, templateID string) error {
|
||||
SnapshotLimit: c.SnapshotLimit,
|
||||
ExpiresAt: c.ExpiresAt,
|
||||
}
|
||||
if len(authConfig) > 0 && lxc.HasSSHAuthOptions(authConfig[0]) && !IsWindowsImage(templateID) {
|
||||
sshAccess, err := lxc.ResolveReinstallSSHAccess(c.SSHPassword, authConfig[0])
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if sshAccess.PublicKey != "" {
|
||||
cfg.SSHAuthMode = lxc.SSHAuthKey
|
||||
cfg.SSHPublicKey = sshAccess.PublicKey
|
||||
} else {
|
||||
cfg.SSHAuthMode = lxc.SSHAuthPassword
|
||||
}
|
||||
cfg.SSHPassword = sshAccess.Password
|
||||
}
|
||||
next, err := m.defineContainer(id, name, cfg, false)
|
||||
if err != nil {
|
||||
return err
|
||||
@@ -1559,7 +1596,7 @@ func createEmptyDisk(target string, diskGB int) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
func createWindowsUnattendISO(target, hostname, adminPassword, ipv6 string) error {
|
||||
func createWindowsUnattendISO(target, hostname, adminPassword string, ipv6s []string) error {
|
||||
tool := firstAvailableCommand("genisoimage", "mkisofs", "xorriso")
|
||||
if tool == "" {
|
||||
return fmt.Errorf("one of genisoimage, mkisofs, xorriso is required for Windows unattended setup")
|
||||
@@ -1585,13 +1622,13 @@ func createWindowsUnattendISO(target, hostname, adminPassword, ipv6 string) erro
|
||||
if err := os.WriteFile(filepath.Join(setupScriptsDir, "SetupComplete.cmd"), []byte(windowsSetupCompleteCMD()), 0600); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := os.WriteFile(filepath.Join(clicdDir, "FirstLogon.ps1"), []byte(windowsFirstLogonPowerShell(adminPassword, ipv6)), 0600); err != nil {
|
||||
if err := os.WriteFile(filepath.Join(clicdDir, "FirstLogon.ps1"), []byte(windowsFirstLogonPowerShell(adminPassword, ipv6s)), 0600); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := os.WriteFile(filepath.Join(dir, "SetupComplete.cmd"), []byte(windowsSetupCompleteCMD()), 0600); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := os.WriteFile(filepath.Join(dir, "FirstLogon.ps1"), []byte(windowsFirstLogonPowerShell(adminPassword, ipv6)), 0600); err != nil {
|
||||
if err := os.WriteFile(filepath.Join(dir, "FirstLogon.ps1"), []byte(windowsFirstLogonPowerShell(adminPassword, ipv6s)), 0600); err != nil {
|
||||
return err
|
||||
}
|
||||
_ = os.Remove(target)
|
||||
@@ -1701,7 +1738,7 @@ exit /b 0
|
||||
`
|
||||
}
|
||||
|
||||
func windowsFirstLogonPowerShell(adminPassword, ipv6 string) string {
|
||||
func windowsFirstLogonPowerShell(adminPassword string, ipv6s []string) string {
|
||||
commands := []string{
|
||||
"$ErrorActionPreference='Continue'",
|
||||
"$ProgressPreference='SilentlyContinue'",
|
||||
@@ -1731,9 +1768,10 @@ func windowsFirstLogonPowerShell(adminPassword, ipv6 string) string {
|
||||
"Get-Service QEMU-GA,qemu-ga -ErrorAction SilentlyContinue | Set-Service -StartupType Automatic",
|
||||
"Start-Service QEMU-GA,qemu-ga -ErrorAction SilentlyContinue",
|
||||
}
|
||||
if strings.TrimSpace(ipv6) != "" {
|
||||
ipv6s = normalizeKVMIPv6List(ipv6s)
|
||||
if len(ipv6s) > 0 {
|
||||
commands = append(commands,
|
||||
windowsIPv6PowerShell(strings.TrimSpace(ipv6)),
|
||||
windowsIPv6PowerShell(ipv6s),
|
||||
)
|
||||
}
|
||||
commands = append(commands,
|
||||
@@ -1743,17 +1781,24 @@ func windowsFirstLogonPowerShell(adminPassword, ipv6 string) string {
|
||||
return strings.Join(commands, "\r\n") + "\r\n"
|
||||
}
|
||||
|
||||
func windowsIPv6PowerShell(ipv6 string) string {
|
||||
ipv6 = strings.TrimSpace(ipv6)
|
||||
if ipv6 == "" {
|
||||
func windowsIPv6PowerShell(ipv6s []string) string {
|
||||
ipv6s = normalizeKVMIPv6List(ipv6s)
|
||||
if len(ipv6s) == 0 {
|
||||
return ""
|
||||
}
|
||||
quoted := make([]string, 0, len(ipv6s))
|
||||
for _, ipv6 := range ipv6s {
|
||||
quoted = append(quoted, "'"+strings.ReplaceAll(ipv6, "'", "''")+"'")
|
||||
}
|
||||
return strings.Join([]string{
|
||||
"$clicdIPv6=@(" + strings.Join(quoted, ",") + ")",
|
||||
"$iface=$null",
|
||||
"for ($i=0; $i -lt 60 -and -not $iface; $i++) { $iface=Get-NetAdapter | Where-Object { $_.Status -eq 'Up' -and $_.HardwareInterface } | Sort-Object ifIndex | Select-Object -First 1; if (-not $iface) { Start-Sleep -Seconds 5 } }",
|
||||
"if ($iface) {",
|
||||
" Get-NetIPAddress -InterfaceIndex $iface.ifIndex -AddressFamily IPv6 -ErrorAction SilentlyContinue | Where-Object { $_.IPAddress -eq '" + ipv6 + "' } | Remove-NetIPAddress -Confirm:$false -ErrorAction SilentlyContinue",
|
||||
" New-NetIPAddress -IPAddress '" + ipv6 + "' -PrefixLength 128 -InterfaceIndex $iface.ifIndex -SkipAsSource:$false -ErrorAction SilentlyContinue | Out-Null",
|
||||
" foreach ($ip in $clicdIPv6) {",
|
||||
" Get-NetIPAddress -InterfaceIndex $iface.ifIndex -AddressFamily IPv6 -ErrorAction SilentlyContinue | Where-Object { $_.IPAddress -eq $ip } | Remove-NetIPAddress -Confirm:$false -ErrorAction SilentlyContinue",
|
||||
" New-NetIPAddress -IPAddress $ip -PrefixLength 128 -InterfaceIndex $iface.ifIndex -SkipAsSource:$false -ErrorAction SilentlyContinue | Out-Null",
|
||||
" }",
|
||||
" Get-NetRoute -InterfaceIndex $iface.ifIndex -DestinationPrefix '::/0' -ErrorAction SilentlyContinue | Remove-NetRoute -Confirm:$false -ErrorAction SilentlyContinue",
|
||||
" New-NetRoute -DestinationPrefix '::/0' -InterfaceIndex $iface.ifIndex -NextHop '" + ipv6GatewayLinkLocal + "' -RouteMetric 100 -ErrorAction SilentlyContinue | Out-Null",
|
||||
" Set-DnsClientServerAddress -InterfaceIndex $iface.ifIndex -ServerAddresses @('2001:4860:4860::8888','2606:4700:4700::1111') -ErrorAction SilentlyContinue",
|
||||
@@ -1765,13 +1810,20 @@ func shellQuoteWindows(value string) string {
|
||||
return `"` + strings.ReplaceAll(value, `"`, `\"`) + `"`
|
||||
}
|
||||
|
||||
func createSeedISO(seedPath, instanceID, hostname, password, mac, ipv6 string, image Image) error {
|
||||
guestSetup := kvmSSHSetupScript(password)
|
||||
func createSeedISO(seedPath, instanceID, hostname, password, publicKey, mac string, ipv6s []string, image Image) error {
|
||||
guestSetup := kvmSSHSetupScript(password, publicKey)
|
||||
if desktopSetup := kvmDesktopSetupScript(image); desktopSetup != "" {
|
||||
guestSetup += "\n" + desktopSetup
|
||||
}
|
||||
if strings.TrimSpace(ipv6) != "" {
|
||||
guestSetup += "\n" + kvmIPv6SetupScript(ipv6)
|
||||
ipv6s = normalizeKVMIPv6List(ipv6s)
|
||||
if len(ipv6s) > 0 {
|
||||
guestSetup += "\n" + kvmIPv6SetupScript(ipv6s)
|
||||
}
|
||||
authorizedKeys := ""
|
||||
if publicKey != "" {
|
||||
authorizedKeys = fmt.Sprintf(`
|
||||
ssh_authorized_keys:
|
||||
- %s`, yamlSingleQuote(publicKey))
|
||||
}
|
||||
setupScript := indentScript(guestSetup, 4)
|
||||
userData := fmt.Sprintf(`#cloud-config
|
||||
@@ -1788,22 +1840,26 @@ chpasswd:
|
||||
type: text
|
||||
users:
|
||||
- name: root
|
||||
lock_passwd: false
|
||||
lock_passwd: false%s
|
||||
runcmd:
|
||||
- |
|
||||
%s
|
||||
`, hostname, password, setupScript)
|
||||
`, hostname, password, authorizedKeys, setupScript)
|
||||
metaData := fmt.Sprintf("instance-id: %s\nlocal-hostname: %s\n", instanceID, hostname)
|
||||
ipv6Block := ""
|
||||
if strings.TrimSpace(ipv6) != "" {
|
||||
if len(ipv6s) > 0 {
|
||||
addressLines := make([]string, 0, len(ipv6s))
|
||||
for _, ipv6 := range ipv6s {
|
||||
addressLines = append(addressLines, fmt.Sprintf(" - %s/128", ipv6))
|
||||
}
|
||||
ipv6Block = fmt.Sprintf(`
|
||||
addresses:
|
||||
- %s/128
|
||||
%s
|
||||
routes:
|
||||
- to: default
|
||||
via: %s
|
||||
on-link: true
|
||||
metric: 100`, ipv6, ipv6GatewayLinkLocal)
|
||||
metric: 100`, strings.Join(addressLines, "\n"), ipv6GatewayLinkLocal)
|
||||
}
|
||||
networkConfig := fmt.Sprintf(`version: 2
|
||||
ethernets:
|
||||
@@ -1834,6 +1890,42 @@ ethernets:
|
||||
return nil
|
||||
}
|
||||
|
||||
func configIPv6AssignmentAddresses(assignments []config.IPv6Assignment) []string {
|
||||
values := make([]string, 0, len(assignments))
|
||||
for _, item := range assignments {
|
||||
if strings.TrimSpace(item.Address) != "" {
|
||||
values = append(values, strings.TrimSpace(item.Address))
|
||||
}
|
||||
}
|
||||
return values
|
||||
}
|
||||
|
||||
func normalizeKVMIPv6List(values []string) []string {
|
||||
seen := map[string]bool{}
|
||||
result := make([]string, 0, len(values))
|
||||
for _, value := range values {
|
||||
value = strings.TrimSpace(value)
|
||||
if value == "" || seen[value] {
|
||||
continue
|
||||
}
|
||||
seen[value] = true
|
||||
result = append(result, value)
|
||||
}
|
||||
return result
|
||||
}
|
||||
|
||||
func shellQuotedKVMIPv6List(values []string) string {
|
||||
values = normalizeKVMIPv6List(values)
|
||||
if len(values) == 0 {
|
||||
return "''"
|
||||
}
|
||||
quoted := make([]string, 0, len(values))
|
||||
for _, value := range values {
|
||||
quoted = append(quoted, shellQuote(value))
|
||||
}
|
||||
return strings.Join(quoted, " ")
|
||||
}
|
||||
|
||||
func indentScript(script string, spaces int) string {
|
||||
prefix := strings.Repeat(" ", spaces)
|
||||
lines := strings.Split(strings.TrimRight(script, "\n"), "\n")
|
||||
@@ -1843,6 +1935,10 @@ func indentScript(script string, spaces int) string {
|
||||
return strings.Join(lines, "\n")
|
||||
}
|
||||
|
||||
func yamlSingleQuote(value string) string {
|
||||
return "'" + strings.ReplaceAll(value, "'", "''") + "'"
|
||||
}
|
||||
|
||||
func isKVMDesktopTemplate(templateID string) bool {
|
||||
image := FindImage(templateID)
|
||||
return image != nil && image.Desktop != ""
|
||||
@@ -2304,9 +2400,14 @@ func runKVMSSHScript(client *ssh.Client, script string, description string, time
|
||||
}
|
||||
}
|
||||
|
||||
func kvmSSHSetupScript(password string) string {
|
||||
func kvmSSHSetupScript(password string, publicKeys ...string) string {
|
||||
publicKey := ""
|
||||
if len(publicKeys) > 0 {
|
||||
publicKey = strings.TrimSpace(publicKeys[0])
|
||||
}
|
||||
return `set -u
|
||||
ROOT_PASSWORD=` + shellQuote(password) + `
|
||||
SSH_PUBLIC_KEY=` + shellQuote(publicKey) + `
|
||||
export DEBIAN_FRONTEND=noninteractive
|
||||
if command -v apt-get >/dev/null 2>&1; then
|
||||
if ! command -v sshd >/dev/null 2>&1 || ! command -v qemu-ga >/dev/null 2>&1; then
|
||||
@@ -2333,6 +2434,7 @@ fi
|
||||
mkdir -p /etc/ssh/sshd_config.d
|
||||
cat > /etc/ssh/sshd_config.d/99-clicd-root.conf <<'EOF'
|
||||
PermitRootLogin yes
|
||||
PubkeyAuthentication yes
|
||||
PasswordAuthentication yes
|
||||
KbdInteractiveAuthentication yes
|
||||
ChallengeResponseAuthentication yes
|
||||
@@ -2340,11 +2442,21 @@ EOF
|
||||
if [ -f /etc/ssh/sshd_config ]; then
|
||||
grep -q '^PermitRootLogin ' /etc/ssh/sshd_config && sed -i 's/^PermitRootLogin .*/PermitRootLogin yes/' /etc/ssh/sshd_config || printf '\nPermitRootLogin yes\n' >> /etc/ssh/sshd_config
|
||||
grep -q '^#PermitRootLogin ' /etc/ssh/sshd_config && sed -i 's/^#PermitRootLogin .*/PermitRootLogin yes/' /etc/ssh/sshd_config || true
|
||||
grep -q '^PubkeyAuthentication ' /etc/ssh/sshd_config && sed -i 's/^PubkeyAuthentication .*/PubkeyAuthentication yes/' /etc/ssh/sshd_config || printf '\nPubkeyAuthentication yes\n' >> /etc/ssh/sshd_config
|
||||
grep -q '^#PubkeyAuthentication ' /etc/ssh/sshd_config && sed -i 's/^#PubkeyAuthentication .*/PubkeyAuthentication yes/' /etc/ssh/sshd_config || true
|
||||
grep -q '^PasswordAuthentication ' /etc/ssh/sshd_config && sed -i 's/^PasswordAuthentication .*/PasswordAuthentication yes/' /etc/ssh/sshd_config || printf '\nPasswordAuthentication yes\n' >> /etc/ssh/sshd_config
|
||||
grep -q '^#PasswordAuthentication ' /etc/ssh/sshd_config && sed -i 's/^#PasswordAuthentication .*/PasswordAuthentication yes/' /etc/ssh/sshd_config || true
|
||||
grep -q '^KbdInteractiveAuthentication ' /etc/ssh/sshd_config && sed -i 's/^KbdInteractiveAuthentication .*/KbdInteractiveAuthentication yes/' /etc/ssh/sshd_config || printf '\nKbdInteractiveAuthentication yes\n' >> /etc/ssh/sshd_config
|
||||
grep -q '^#KbdInteractiveAuthentication ' /etc/ssh/sshd_config && sed -i 's/^#KbdInteractiveAuthentication .*/KbdInteractiveAuthentication yes/' /etc/ssh/sshd_config || true
|
||||
fi
|
||||
if [ -n "$SSH_PUBLIC_KEY" ]; then
|
||||
mkdir -p /root/.ssh
|
||||
touch /root/.ssh/authorized_keys
|
||||
grep -qxF "$SSH_PUBLIC_KEY" /root/.ssh/authorized_keys 2>/dev/null || printf '%s\n' "$SSH_PUBLIC_KEY" >> /root/.ssh/authorized_keys
|
||||
chmod 700 /root/.ssh
|
||||
chmod 600 /root/.ssh/authorized_keys
|
||||
chown -R root:root /root/.ssh 2>/dev/null || true
|
||||
fi
|
||||
if command -v chpasswd >/dev/null 2>&1; then
|
||||
printf 'root:%s\n' "$ROOT_PASSWORD" | chpasswd || true
|
||||
fi
|
||||
@@ -2575,7 +2687,7 @@ func (m *Manager) syncRunningNetworks() {
|
||||
} else if err != nil {
|
||||
fmt.Printf("Warning: failed to sync KVM network for %s: %v\n", c.Name, err)
|
||||
}
|
||||
if c.IPv6 != "" {
|
||||
if c.IPv6 != "" || len(c.IPv6Addresses) > 0 {
|
||||
if err := m.applyIPv6Runtime(c); err != nil {
|
||||
fmt.Printf("Warning: failed to sync KVM IPv6 for %s: %v\n", c.Name, err)
|
||||
}
|
||||
@@ -2589,7 +2701,7 @@ func (m *Manager) applyIPv6Guards() {
|
||||
if !c.IsKVM() || c.MACAddress == "" {
|
||||
continue
|
||||
}
|
||||
if c.IPv6 == "" {
|
||||
if c.IPv6 == "" && len(c.IPv6Addresses) == 0 {
|
||||
ensureKVMIPv6DenyRule("virbr0", c.MACAddress)
|
||||
continue
|
||||
}
|
||||
@@ -2935,13 +3047,12 @@ func (m *Manager) AssignIPv6(id int) (*config.Container, error) {
|
||||
return nil, fmt.Errorf("container is not a KVM VM: %d", id)
|
||||
}
|
||||
if c.IPv6 == "" {
|
||||
addr, prefixLen, iface, err := m.allocateIPv6ForContainer(id)
|
||||
assignments, err := m.allocateIPv6AssignmentsForContainer(id, nil, 1, true)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
c.IPv6 = addr
|
||||
c.IPv6PrefixLen = prefixLen
|
||||
c.IPv6Interface = iface
|
||||
c.IPv6Addresses = append(c.IPv6Addresses, assignments...)
|
||||
c.NormalizeNetworkAssignments()
|
||||
config.SaveConfig()
|
||||
}
|
||||
if err := m.applyIPv6Runtime(c); err != nil {
|
||||
@@ -2951,9 +3062,10 @@ func (m *Manager) AssignIPv6(id int) (*config.Container, error) {
|
||||
}
|
||||
|
||||
func (m *Manager) applyIPv6Runtime(c *config.Container) error {
|
||||
if c == nil || c.IPv6 == "" {
|
||||
if c == nil || (c.IPv6 == "" && len(c.IPv6Addresses) == 0) {
|
||||
return nil
|
||||
}
|
||||
c.NormalizeNetworkAssignments()
|
||||
if err := m.applyIPv6HostRuntime(c); err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -2964,7 +3076,13 @@ func (m *Manager) applyIPv6Runtime(c *config.Container) error {
|
||||
}
|
||||
}
|
||||
}
|
||||
ensureKVMIPv6NAT66(c.IPv6, c.IPv6Interface)
|
||||
for _, assignment := range c.IPv6Addresses {
|
||||
uplink := assignment.Interface
|
||||
if uplink == "" {
|
||||
uplink = c.IPv6Interface
|
||||
}
|
||||
ensureKVMIPv6NAT66(assignment.Address, uplink)
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -2980,9 +3098,10 @@ func shouldLogIPv6GuestWarning(id int) bool {
|
||||
}
|
||||
|
||||
func (m *Manager) applyIPv6HostRuntime(c *config.Container) error {
|
||||
if c == nil || c.IPv6 == "" {
|
||||
if c == nil || (c.IPv6 == "" && len(c.IPv6Addresses) == 0) {
|
||||
return nil
|
||||
}
|
||||
c.NormalizeNetworkAssignments()
|
||||
if c.IPv6Interface == "" {
|
||||
prefixes := lxc.DetectPublicIPv6Prefixes()
|
||||
if len(prefixes) == 0 {
|
||||
@@ -2990,6 +3109,14 @@ func (m *Manager) applyIPv6HostRuntime(c *config.Container) error {
|
||||
}
|
||||
c.IPv6Interface = prefixes[0].Interface
|
||||
c.IPv6PrefixLen = prefixes[0].PrefixLen
|
||||
for i := range c.IPv6Addresses {
|
||||
if c.IPv6Addresses[i].Interface == "" {
|
||||
c.IPv6Addresses[i].Interface = c.IPv6Interface
|
||||
}
|
||||
if c.IPv6Addresses[i].PrefixLen == 0 {
|
||||
c.IPv6Addresses[i].PrefixLen = c.IPv6PrefixLen
|
||||
}
|
||||
}
|
||||
config.SaveConfig()
|
||||
}
|
||||
runQuiet("sysctl", "-w", "net.ipv6.conf.all.forwarding=1")
|
||||
@@ -3001,14 +3128,20 @@ func (m *Manager) applyIPv6HostRuntime(c *config.Container) error {
|
||||
runQuiet("sysctl", "-w", "net.ipv6.conf."+bridge+".proxy_ndp=1")
|
||||
runQuiet("ip", "link", "set", bridge, "up")
|
||||
runQuiet("ip", "-6", "addr", "replace", ipv6GatewayLinkLocal+"/64", "dev", bridge)
|
||||
if out, err := exec.Command("ip", "-6", "route", "replace", c.IPv6+"/128", "dev", bridge).CombinedOutput(); err != nil {
|
||||
return fmt.Errorf("failed to add IPv6 VM route: %v, output: %s", err, string(out))
|
||||
for _, assignment := range c.IPv6Addresses {
|
||||
uplink := assignment.Interface
|
||||
if uplink == "" {
|
||||
uplink = c.IPv6Interface
|
||||
}
|
||||
if out, err := exec.Command("ip", "-6", "route", "replace", assignment.Address+"/128", "dev", bridge).CombinedOutput(); err != nil {
|
||||
return fmt.Errorf("failed to add IPv6 VM route: %v, output: %s", err, string(out))
|
||||
}
|
||||
if out, err := exec.Command("ip", "-6", "neigh", "replace", "proxy", assignment.Address, "dev", uplink).CombinedOutput(); err != nil {
|
||||
return fmt.Errorf("failed to add IPv6 proxy NDP: %v, output: %s", err, string(out))
|
||||
}
|
||||
ensureKVMIPv6ForwardRules(assignment.Address, bridge)
|
||||
ensureKVMIPv6AntiSpoofRules(assignment.Address, bridge, c.MACAddress)
|
||||
}
|
||||
if out, err := exec.Command("ip", "-6", "neigh", "replace", "proxy", c.IPv6, "dev", c.IPv6Interface).CombinedOutput(); err != nil {
|
||||
return fmt.Errorf("failed to add IPv6 proxy NDP: %v, output: %s", err, string(out))
|
||||
}
|
||||
ensureKVMIPv6ForwardRules(c.IPv6, bridge)
|
||||
ensureKVMIPv6AntiSpoofRules(c.IPv6, bridge, c.MACAddress)
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -3074,16 +3207,23 @@ func removeKVMIPv6Runtime(c *config.Container) {
|
||||
}
|
||||
bridge := "virbr0"
|
||||
removeKVMIPv6DenyRule(bridge, c.MACAddress)
|
||||
if c.IPv6 == "" {
|
||||
if c.IPv6 == "" && len(c.IPv6Addresses) == 0 {
|
||||
return
|
||||
}
|
||||
removeKVMIPv6NAT66(c.IPv6, c.IPv6Interface)
|
||||
removeKVMIPv6ForwardRules(c.IPv6, bridge)
|
||||
removeKVMIPv6AntiSpoofRules(c.IPv6, bridge, c.MACAddress)
|
||||
if c.IPv6Interface != "" {
|
||||
_ = exec.Command("ip", "-6", "neigh", "del", "proxy", c.IPv6, "dev", c.IPv6Interface).Run()
|
||||
c.NormalizeNetworkAssignments()
|
||||
for _, assignment := range c.IPv6Addresses {
|
||||
uplink := assignment.Interface
|
||||
if uplink == "" {
|
||||
uplink = c.IPv6Interface
|
||||
}
|
||||
removeKVMIPv6NAT66(assignment.Address, uplink)
|
||||
removeKVMIPv6ForwardRules(assignment.Address, bridge)
|
||||
removeKVMIPv6AntiSpoofRules(assignment.Address, bridge, c.MACAddress)
|
||||
if uplink != "" {
|
||||
_ = exec.Command("ip", "-6", "neigh", "del", "proxy", assignment.Address, "dev", uplink).Run()
|
||||
}
|
||||
_ = exec.Command("ip", "-6", "route", "del", assignment.Address+"/128", "dev", bridge).Run()
|
||||
}
|
||||
_ = exec.Command("ip", "-6", "route", "del", c.IPv6+"/128", "dev", bridge).Run()
|
||||
}
|
||||
|
||||
func removeKVMIPv6ForwardRules(ipv6 string, bridge string) {
|
||||
@@ -3147,13 +3287,14 @@ func deleteIP6Rule(rule []string) {
|
||||
}
|
||||
|
||||
func (m *Manager) applyGuestIPv6(c *config.Container) error {
|
||||
if c == nil || c.IPv6 == "" {
|
||||
if c == nil || (c.IPv6 == "" && len(c.IPv6Addresses) == 0) {
|
||||
return nil
|
||||
}
|
||||
c.NormalizeNetworkAssignments()
|
||||
if IsWindowsImage(c.Template) {
|
||||
return m.applyWindowsGuestIPv6(c)
|
||||
}
|
||||
script := kvmIPv6SetupScript(c.IPv6)
|
||||
script := kvmIPv6SetupScript(c.IPv6AddressStrings())
|
||||
if err := qemuGuestPing(c.VirshName()); err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -3167,14 +3308,15 @@ func (m *Manager) applyWindowsGuestIPv6(c *config.Container) error {
|
||||
if err := qemuGuestPing(c.VirshName()); err != nil {
|
||||
return err
|
||||
}
|
||||
script := windowsIPv6PowerShell(c.IPv6)
|
||||
script := windowsIPv6PowerShell(c.IPv6AddressStrings())
|
||||
return qemuGuestExecCommand(c.VirshName(), "powershell.exe", []string{"-NoProfile", "-ExecutionPolicy", "Bypass", "-Command", script}, 60*time.Second)
|
||||
}
|
||||
|
||||
func (m *Manager) applyGuestIPv6Runtime(c *config.Container) error {
|
||||
if c == nil || c.IPv6 == "" {
|
||||
if c == nil || (c.IPv6 == "" && len(c.IPv6Addresses) == 0) {
|
||||
return nil
|
||||
}
|
||||
c.NormalizeNetworkAssignments()
|
||||
qgaErr := m.applyGuestIPv6(c)
|
||||
if qgaErr == nil {
|
||||
return nil
|
||||
@@ -3187,7 +3329,7 @@ func (m *Manager) applyGuestIPv6Runtime(c *config.Container) error {
|
||||
}
|
||||
|
||||
func (m *Manager) applyGuestIPv6OverSSH(c *config.Container) error {
|
||||
if c == nil || c.IPv6 == "" {
|
||||
if c == nil || (c.IPv6 == "" && len(c.IPv6Addresses) == 0) {
|
||||
return nil
|
||||
}
|
||||
if IsWindowsImage(c.Template) {
|
||||
@@ -3206,12 +3348,13 @@ func (m *Manager) applyGuestIPv6OverSSH(c *config.Container) error {
|
||||
return err
|
||||
}
|
||||
defer client.Close()
|
||||
return runKVMSSHScript(client, kvmIPv6SetupScript(c.IPv6), "KVM IPv6", 60*time.Second)
|
||||
return runKVMSSHScript(client, kvmIPv6SetupScript(c.IPv6AddressStrings()), "KVM IPv6", 60*time.Second)
|
||||
}
|
||||
|
||||
func kvmIPv6SetupScript(ipv6 string) string {
|
||||
func kvmIPv6SetupScript(ipv6s []string) string {
|
||||
ipv6s = normalizeKVMIPv6List(ipv6s)
|
||||
return `set -eu
|
||||
IPV6_ADDR=` + shellQuote(ipv6) + `
|
||||
IPV6_ADDRS="` + strings.Join(ipv6s, " ") + `"
|
||||
IPV6_GW=` + shellQuote(ipv6GatewayLinkLocal) + `
|
||||
IFACE="$(ip -o -4 route show default 2>/dev/null | awk '{print $5; exit}')"
|
||||
if [ -z "$IFACE" ]; then
|
||||
@@ -3224,13 +3367,15 @@ fi
|
||||
sysctl -w net.ipv6.conf.all.disable_ipv6=0 >/dev/null 2>&1 || true
|
||||
sysctl -w net.ipv6.conf.default.disable_ipv6=0 >/dev/null 2>&1 || true
|
||||
sysctl -w net.ipv6.conf."$IFACE".disable_ipv6=0 >/dev/null 2>&1 || true
|
||||
ip -6 addr replace "$IPV6_ADDR/128" dev "$IFACE"
|
||||
for IPV6_ADDR in $IPV6_ADDRS; do
|
||||
ip -6 addr replace "$IPV6_ADDR/128" dev "$IFACE"
|
||||
done
|
||||
ip -6 route replace default via "$IPV6_GW" dev "$IFACE" onlink metric 100
|
||||
mkdir -p /usr/local/sbin /etc/systemd/system /etc/network/if-up.d /etc/local.d
|
||||
cat > /usr/local/sbin/clicd-kvm-ipv6-init <<'EOF'
|
||||
#!/bin/sh
|
||||
set -eu
|
||||
IPV6_ADDR=` + shellQuote(ipv6) + `
|
||||
IPV6_ADDRS="` + strings.Join(ipv6s, " ") + `"
|
||||
IPV6_GW=` + shellQuote(ipv6GatewayLinkLocal) + `
|
||||
IFACE="$(ip -o -4 route show default 2>/dev/null | awk '{print $5; exit}')"
|
||||
if [ -z "$IFACE" ]; then
|
||||
@@ -3240,7 +3385,9 @@ fi
|
||||
sysctl -w net.ipv6.conf.all.disable_ipv6=0 >/dev/null 2>&1 || true
|
||||
sysctl -w net.ipv6.conf.default.disable_ipv6=0 >/dev/null 2>&1 || true
|
||||
sysctl -w net.ipv6.conf."$IFACE".disable_ipv6=0 >/dev/null 2>&1 || true
|
||||
ip -6 addr replace "$IPV6_ADDR/128" dev "$IFACE"
|
||||
for IPV6_ADDR in $IPV6_ADDRS; do
|
||||
ip -6 addr replace "$IPV6_ADDR/128" dev "$IFACE"
|
||||
done
|
||||
ip -6 route replace default via "$IPV6_GW" dev "$IFACE" onlink metric 100
|
||||
EOF
|
||||
chmod +x /usr/local/sbin/clicd-kvm-ipv6-init
|
||||
@@ -3279,15 +3426,44 @@ chmod +x /etc/network/if-up.d/clicd-kvm-ipv6
|
||||
}
|
||||
|
||||
func (m *Manager) allocateIPv6ForContainer(id int) (string, int, string, error) {
|
||||
prefixes := lxc.DetectPublicIPv6Prefixes()
|
||||
if len(prefixes) == 0 {
|
||||
return "", 0, "", fmt.Errorf("public IPv6 allocation is unavailable: no usable public IPv6 prefix found")
|
||||
}
|
||||
prefixInfo := prefixes[0]
|
||||
prefix, err := netip.ParsePrefix(prefixInfo.Prefix)
|
||||
assignments, err := m.allocateIPv6AssignmentsForContainer(id, nil, 1, true)
|
||||
if err != nil {
|
||||
return "", 0, "", err
|
||||
}
|
||||
if len(assignments) == 0 {
|
||||
return "", 0, "", fmt.Errorf("no free IPv6 address")
|
||||
}
|
||||
return assignments[0].Address, assignments[0].PrefixLen, assignments[0].Interface, nil
|
||||
}
|
||||
|
||||
func (m *Manager) allocateIPv6AssignmentsForContainer(id int, requested []string, count int, auto bool) ([]config.IPv6Assignment, error) {
|
||||
if count <= 0 {
|
||||
count = 1
|
||||
}
|
||||
if len(requested) > count {
|
||||
count = len(requested)
|
||||
}
|
||||
prefixes := lxc.DetectPublicIPv6Prefixes()
|
||||
if len(prefixes) == 0 {
|
||||
return nil, fmt.Errorf("public IPv6 allocation is unavailable: no usable public IPv6 prefix found")
|
||||
}
|
||||
parsedPrefixes := make([]struct {
|
||||
info lxc.IPv6PrefixInfo
|
||||
prefix netip.Prefix
|
||||
}, 0, len(prefixes))
|
||||
for _, prefixInfo := range prefixes {
|
||||
prefix, err := netip.ParsePrefix(prefixInfo.Prefix)
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
parsedPrefixes = append(parsedPrefixes, struct {
|
||||
info lxc.IPv6PrefixInfo
|
||||
prefix netip.Prefix
|
||||
}{info: prefixInfo, prefix: prefix})
|
||||
}
|
||||
if len(parsedPrefixes) == 0 {
|
||||
return nil, fmt.Errorf("public IPv6 allocation is unavailable: no valid IPv6 prefix found")
|
||||
}
|
||||
|
||||
used := map[string]bool{}
|
||||
hostAddrs := map[string]bool{}
|
||||
@@ -3295,21 +3471,69 @@ func (m *Manager) allocateIPv6ForContainer(id int) (string, int, string, error)
|
||||
hostAddrs[p.Address] = true
|
||||
}
|
||||
for _, c := range config.AppConfig.Containers {
|
||||
if c.ID == id {
|
||||
continue
|
||||
}
|
||||
if c.IPv6 != "" {
|
||||
used[c.IPv6] = true
|
||||
}
|
||||
}
|
||||
for offset := uint64(0x2000 + id); offset < 0x100000; offset++ {
|
||||
addr, err := ipv6Add(prefix.Masked().Addr(), offset)
|
||||
if err != nil || !prefix.Contains(addr) {
|
||||
break
|
||||
}
|
||||
candidate := addr.String()
|
||||
if !used[candidate] && !hostAddrs[candidate] {
|
||||
return candidate, prefix.Bits(), prefixInfo.Interface, nil
|
||||
for _, ip := range c.IPv6Addresses {
|
||||
if ip.Address != "" {
|
||||
used[ip.Address] = true
|
||||
}
|
||||
}
|
||||
}
|
||||
return "", 0, "", fmt.Errorf("no free IPv6 address in %s", prefix.String())
|
||||
result := make([]config.IPv6Assignment, 0, count)
|
||||
selected := map[string]bool{}
|
||||
for _, raw := range requested {
|
||||
raw = strings.TrimSpace(raw)
|
||||
if raw == "" || selected[raw] {
|
||||
continue
|
||||
}
|
||||
addr, err := netip.ParseAddr(raw)
|
||||
if err != nil || !addr.Is6() {
|
||||
return nil, fmt.Errorf("requested IPv6 %s is not valid", raw)
|
||||
}
|
||||
matchIndex := -1
|
||||
for i, item := range parsedPrefixes {
|
||||
if item.prefix.Contains(addr) {
|
||||
matchIndex = i
|
||||
break
|
||||
}
|
||||
}
|
||||
if matchIndex < 0 {
|
||||
return nil, fmt.Errorf("requested IPv6 %s is not in the configured IPv6 prefixes", raw)
|
||||
}
|
||||
if hostAddrs[raw] {
|
||||
return nil, fmt.Errorf("requested IPv6 %s is used by host", raw)
|
||||
}
|
||||
if used[raw] {
|
||||
return nil, fmt.Errorf("requested IPv6 %s is already assigned", raw)
|
||||
}
|
||||
selected[raw] = true
|
||||
used[raw] = true
|
||||
result = append(result, config.IPv6Assignment{Address: raw, PrefixLen: parsedPrefixes[matchIndex].prefix.Bits(), Interface: parsedPrefixes[matchIndex].info.Interface})
|
||||
}
|
||||
if len(result) >= count || !auto {
|
||||
return result, nil
|
||||
}
|
||||
for _, item := range parsedPrefixes {
|
||||
for offset := uint64(0x2000 + id); offset < 0x100000; offset++ {
|
||||
addr, err := ipv6Add(item.prefix.Masked().Addr(), offset)
|
||||
if err != nil || !item.prefix.Contains(addr) {
|
||||
break
|
||||
}
|
||||
candidate := addr.String()
|
||||
if !used[candidate] && !hostAddrs[candidate] {
|
||||
used[candidate] = true
|
||||
result = append(result, config.IPv6Assignment{Address: candidate, PrefixLen: item.prefix.Bits(), Interface: item.info.Interface})
|
||||
if len(result) >= count {
|
||||
return result, nil
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
return nil, fmt.Errorf("no free IPv6 address in configured prefixes")
|
||||
}
|
||||
|
||||
func ipv6Add(base netip.Addr, offset uint64) (netip.Addr, error) {
|
||||
|
||||
+1121
-52
File diff suppressed because it is too large
Load Diff
+269
-83
@@ -218,24 +218,37 @@ func NewManager() *Manager {
|
||||
|
||||
// ContainerConfig defines container creation parameters
|
||||
type ContainerConfig struct {
|
||||
Name string `json:"name"`
|
||||
Virtualization string `json:"virtualization,omitempty"`
|
||||
TemplateID string `json:"template_id"`
|
||||
VCPU float64 `json:"vcpu"`
|
||||
CPUPercent int `json:"cpu_percent"`
|
||||
RAMMB int `json:"ram_mb"`
|
||||
DiskGB int `json:"disk_gb"`
|
||||
NetworkBWMbps int `json:"network_bw_mbps"`
|
||||
MonthlyTrafficGB int `json:"monthly_traffic_gb"`
|
||||
TrafficMode string `json:"traffic_mode"` // "total" or "in_out"
|
||||
TrafficInGB int `json:"traffic_in_gb"` // 0=unlimited
|
||||
TrafficOutGB int `json:"traffic_out_gb"` // 0=unlimited
|
||||
IOSpeedMBps int `json:"io_speed_mbps"`
|
||||
ExtraPorts []int `json:"extra_ports"`
|
||||
PortMappingCount int `json:"port_mapping_count"`
|
||||
SnapshotLimit int `json:"snapshot_limit"`
|
||||
AssignIPv6 bool `json:"assign_ipv6"`
|
||||
ExpiresAt string `json:"expires_at"`
|
||||
Name string `json:"name"`
|
||||
Virtualization string `json:"virtualization,omitempty"`
|
||||
TemplateID string `json:"template_id"`
|
||||
VCPU float64 `json:"vcpu"`
|
||||
CPUPercent int `json:"cpu_percent"`
|
||||
RAMMB int `json:"ram_mb"`
|
||||
DiskGB int `json:"disk_gb"`
|
||||
NetworkBWMbps int `json:"network_bw_mbps"`
|
||||
MonthlyTrafficGB int `json:"monthly_traffic_gb"`
|
||||
TrafficMode string `json:"traffic_mode"` // "total" or "in_out"
|
||||
TrafficInGB int `json:"traffic_in_gb"` // 0=unlimited
|
||||
TrafficOutGB int `json:"traffic_out_gb"` // 0=unlimited
|
||||
IOSpeedMBps int `json:"io_speed_mbps"`
|
||||
ExtraPorts []int `json:"extra_ports"`
|
||||
PortMappingCount int `json:"port_mapping_count"`
|
||||
AssignNAT *bool `json:"assign_nat,omitempty"`
|
||||
SnapshotLimit int `json:"snapshot_limit"`
|
||||
AssignIPv4 bool `json:"assign_ipv4"`
|
||||
IPv4Count int `json:"ipv4_count,omitempty"`
|
||||
PublicIPv4s []string `json:"public_ipv4s,omitempty"`
|
||||
AssignIPv6 bool `json:"assign_ipv6"`
|
||||
IPv6Count int `json:"ipv6_count,omitempty"`
|
||||
IPv6Addresses []string `json:"ipv6_addresses,omitempty"`
|
||||
SSHAuthMode string `json:"ssh_auth_mode,omitempty"`
|
||||
SSHPassword string `json:"ssh_password,omitempty"`
|
||||
SSHPublicKey string `json:"ssh_public_key,omitempty"`
|
||||
ExpiresAt string `json:"expires_at"`
|
||||
}
|
||||
|
||||
func (cfg ContainerConfig) WantsNAT() bool {
|
||||
return cfg.AssignNAT == nil || *cfg.AssignNAT
|
||||
}
|
||||
|
||||
// CreateContainer creates a new LXC container. Uses ct-{id} as LXC name internally.
|
||||
@@ -244,8 +257,11 @@ func (m *Manager) CreateContainer(cfg ContainerConfig) error {
|
||||
if tmpl == nil {
|
||||
return fmt.Errorf("template not found: %s", cfg.TemplateID)
|
||||
}
|
||||
if cfg.PortMappingCount < 2 {
|
||||
if cfg.WantsNAT() && cfg.PortMappingCount < 2 {
|
||||
cfg.PortMappingCount = 2
|
||||
} else if !cfg.WantsNAT() {
|
||||
cfg.PortMappingCount = 0
|
||||
cfg.ExtraPorts = nil
|
||||
}
|
||||
if cfg.SnapshotLimit <= 0 {
|
||||
cfg.SnapshotLimit = config.DefaultSnapshotLimit
|
||||
@@ -257,6 +273,10 @@ func (m *Manager) CreateContainer(cfg ContainerConfig) error {
|
||||
if config.FindContainerByName(cfg.Name) != nil {
|
||||
return fmt.Errorf("container name already exists: %s", cfg.Name)
|
||||
}
|
||||
sshAccess, err := ResolveCreateSSHAccess(cfg)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
// Allocate ID and build LXC name
|
||||
id := config.AllocateContainerID()
|
||||
@@ -296,50 +316,64 @@ func (m *Manager) CreateContainer(cfg ContainerConfig) error {
|
||||
return err
|
||||
}
|
||||
|
||||
ipv6 := ""
|
||||
ipv6PrefixLen := 0
|
||||
ipv6Interface := ""
|
||||
if cfg.AssignIPv6 {
|
||||
assigned, prefixLen, iface, err := m.allocateIPv6ForContainer(id)
|
||||
publicIPv4s, err := AllocatePublicIPv4Assignments(id, cfg.PublicIPv4s, cfg.IPv4Count, cfg.AssignIPv4)
|
||||
if err != nil {
|
||||
_ = m.cleanupContainerStorage(lxcName)
|
||||
return err
|
||||
}
|
||||
|
||||
ipv6Assignments := []config.IPv6Assignment{}
|
||||
if cfg.AssignIPv6 || len(cfg.IPv6Addresses) > 0 {
|
||||
assigned, err := m.allocateIPv6AssignmentsForContainer(id, cfg.IPv6Addresses, cfg.IPv6Count, true)
|
||||
if err != nil {
|
||||
_ = m.cleanupContainerStorage(lxcName)
|
||||
return err
|
||||
}
|
||||
ipv6 = assigned
|
||||
ipv6PrefixLen = prefixLen
|
||||
ipv6Interface = iface
|
||||
if err := m.applyIPv6Config(lxcName, ipv6); err != nil {
|
||||
ipv6Assignments = assigned
|
||||
if err := m.applyIPv6Config(lxcName, ipv6AssignmentAddresses(ipv6Assignments)...); err != nil {
|
||||
_ = m.cleanupContainerStorage(lxcName)
|
||||
return err
|
||||
}
|
||||
}
|
||||
|
||||
sshPort := config.AllocateSSHPort()
|
||||
sshPassword := generateRandomString(16)
|
||||
sshPassword := sshAccess.Password
|
||||
|
||||
// Setup default port mappings (SSH only)
|
||||
portMappings := SetupDefaultPortMappings(sshPort)
|
||||
tempC := &config.Container{PortMappings: portMappings}
|
||||
sshPort := 0
|
||||
portMappings := []config.PortMapping{}
|
||||
if cfg.WantsNAT() {
|
||||
sshPort = config.AllocateSSHPort()
|
||||
|
||||
extraPorts := cfg.ExtraPorts
|
||||
if len(extraPorts) == 0 && cfg.PortMappingCount > 1 {
|
||||
extraPorts = allocateDefaultEqualPorts(tempC, cfg.PortMappingCount-1)
|
||||
}
|
||||
for _, containerPort := range extraPorts {
|
||||
if containerPort <= 0 {
|
||||
continue
|
||||
// Setup default port mappings (SSH only)
|
||||
portMappings = SetupDefaultPortMappings(sshPort)
|
||||
defaultHostIP := defaultPortMappingHostIP(publicIPv4s)
|
||||
if defaultHostIP != "" {
|
||||
for i := range portMappings {
|
||||
portMappings[i].HostIP = defaultHostIP
|
||||
}
|
||||
}
|
||||
pm, err := normalizePortMapping(tempC, -1, config.PortMapping{
|
||||
ContainerPort: containerPort,
|
||||
HostPort: containerPort,
|
||||
Protocol: "tcp",
|
||||
Description: fmt.Sprintf("Port-%d", containerPort),
|
||||
})
|
||||
if err != nil {
|
||||
continue
|
||||
tempC := &config.Container{ID: id, PublicIPv4s: publicIPv4s, PortMappings: portMappings}
|
||||
|
||||
extraPorts := cfg.ExtraPorts
|
||||
if len(extraPorts) == 0 && cfg.PortMappingCount > 1 {
|
||||
extraPorts = allocateDefaultEqualPorts(tempC, cfg.PortMappingCount-1)
|
||||
}
|
||||
for _, containerPort := range extraPorts {
|
||||
if containerPort <= 0 {
|
||||
continue
|
||||
}
|
||||
pm, err := normalizePortMapping(tempC, -1, config.PortMapping{
|
||||
ContainerPort: containerPort,
|
||||
HostPort: containerPort,
|
||||
HostIP: defaultHostIP,
|
||||
Protocol: "tcp",
|
||||
Description: fmt.Sprintf("Port-%d", containerPort),
|
||||
})
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
tempC.PortMappings = append(tempC.PortMappings, pm)
|
||||
portMappings = tempC.PortMappings
|
||||
}
|
||||
tempC.PortMappings = append(tempC.PortMappings, pm)
|
||||
portMappings = tempC.PortMappings
|
||||
}
|
||||
|
||||
now := time.Now().Format("2006-01-02 15:04:05")
|
||||
@@ -368,9 +402,8 @@ func (m *Manager) CreateContainer(cfg ContainerConfig) error {
|
||||
IOSpeedMBps: cfg.IOSpeedMBps,
|
||||
Status: "stopped",
|
||||
IP: "",
|
||||
IPv6: ipv6,
|
||||
IPv6PrefixLen: ipv6PrefixLen,
|
||||
IPv6Interface: ipv6Interface,
|
||||
PublicIPv4s: publicIPv4s,
|
||||
IPv6Addresses: ipv6Assignments,
|
||||
VNCPort: 0,
|
||||
SSHPort: sshPort,
|
||||
SSHPassword: sshPassword,
|
||||
@@ -380,19 +413,27 @@ func (m *Manager) CreateContainer(cfg ContainerConfig) error {
|
||||
CreatedAt: now,
|
||||
ExpiresAt: cfg.ExpiresAt,
|
||||
}
|
||||
container.NormalizeNetworkAssignments()
|
||||
config.AddContainer(container)
|
||||
|
||||
// Pre-configure network and SSH in the rootfs before first boot.
|
||||
rootfsPath := filepath.Join(m.LxcPath, lxcName, "rootfs")
|
||||
m.preconfigureNetwork(rootfsPath, cfg.TemplateID)
|
||||
if ipv6 != "" {
|
||||
if err := installContainerIPv6Init(rootfsPath, ipv6); err != nil {
|
||||
if len(ipv6Assignments) > 0 {
|
||||
if err := installContainerIPv6Init(rootfsPath, ipv6AssignmentAddresses(ipv6Assignments)...); err != nil {
|
||||
fmt.Printf("Warning: failed to install IPv6 init in %s: %v\n", lxcName, err)
|
||||
}
|
||||
}
|
||||
if err := m.preconfigureSSH(rootfsPath, cfg.TemplateID); err != nil {
|
||||
fmt.Printf("Warning: failed to pre-configure SSH in %s: %v\n", lxcName, err)
|
||||
}
|
||||
if sshAccess.PublicKey != "" {
|
||||
if err := m.installRootAuthorizedKey(rootfsPath, sshAccess.PublicKey); err != nil {
|
||||
_ = m.cleanupContainerStorage(lxcName)
|
||||
config.RemoveContainer(id)
|
||||
return fmt.Errorf("failed to install SSH public key: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
if err := m.shiftRootfsForUnprivileged(lxcName); err != nil {
|
||||
_ = m.cleanupContainerStorage(lxcName)
|
||||
@@ -525,7 +566,7 @@ func (m *Manager) applyResourceLimits(lxcName string, cfg ContainerConfig) error
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
apparmorProfile, err := findAppArmorProfile()
|
||||
apparmorProfile, err := appArmorProfileForTemplate(cfg.TemplateID)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -940,6 +981,26 @@ func findAppArmorProfile() (string, error) {
|
||||
return "", errors.New("required LXC AppArmor profile not loaded")
|
||||
}
|
||||
|
||||
func appArmorProfileForTemplate(templateID string) (string, error) {
|
||||
if systemdTemplateNeedsUnconfinedAppArmor(templateID) {
|
||||
return "unconfined", nil
|
||||
}
|
||||
return findAppArmorProfile()
|
||||
}
|
||||
|
||||
func systemdTemplateNeedsUnconfinedAppArmor(templateID string) bool {
|
||||
id := strings.ToLower(strings.TrimSpace(templateID))
|
||||
if id == "" || strings.Contains(id, "alpine") {
|
||||
return false
|
||||
}
|
||||
for _, token := range []string{"ubuntu", "debian", "centos", "fedora", "rocky", "rockylinux", "archlinux"} {
|
||||
if strings.Contains(id, token) {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func unprivilegedIDMap() (int, int, error) {
|
||||
if err := ensureSubIDRange("/etc/subuid", "root", 100000, 65536); err != nil {
|
||||
return 0, 0, err
|
||||
@@ -1197,27 +1258,31 @@ func (m *Manager) StartContainer(id int) error {
|
||||
NetworkBWMbps: c.NetworkBWMbps,
|
||||
MonthlyTrafficGB: c.MonthlyTrafficGB,
|
||||
IOSpeedMBps: c.IOSpeedMBps,
|
||||
AssignIPv6: c.IPv6 != "",
|
||||
AssignIPv6: c.IPv6 != "" || len(c.IPv6Addresses) > 0,
|
||||
ExpiresAt: c.ExpiresAt,
|
||||
}); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
if c.IPv6 != "" {
|
||||
if err := m.applyIPv6Config(lxcName, c.IPv6); err != nil {
|
||||
if c.IPv6 != "" || len(c.IPv6Addresses) > 0 {
|
||||
c.NormalizeNetworkAssignments()
|
||||
if err := m.applyIPv6Config(lxcName, c.IPv6AddressStrings()...); err != nil {
|
||||
return err
|
||||
}
|
||||
if err := m.ApplyIPv6(id); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
EnsureAssignedPublicIPv4s(c.PublicIPv4s)
|
||||
|
||||
logFile := filepath.Join(os.TempDir(), "clicd-"+lxcName+"-start.log")
|
||||
os.Remove(logFile)
|
||||
cmd := exec.Command("lxc-start", "-n", lxcName, "-d", "--logfile", logFile, "--logpriority", "DEBUG")
|
||||
output, err := cmd.CombinedOutput()
|
||||
logFile, consoleLog, output, err := m.startLXCContainerDaemon(lxcName)
|
||||
if err != nil {
|
||||
return fmt.Errorf("failed to start container: %v, output: %s, lxc log: %s", err, string(output), tailFile(logFile, 80))
|
||||
config.UpdateContainerStatus(id, "stopped")
|
||||
return fmt.Errorf("failed to start container: %v, output: %s, lxc log: %s, console: %s", err, string(output), tailFile(logFile, 80), tailFile(consoleLog, 80))
|
||||
}
|
||||
if err := m.waitForLXCStartup(lxcName, logFile, consoleLog); err != nil {
|
||||
config.UpdateContainerStatus(id, "stopped")
|
||||
return err
|
||||
}
|
||||
|
||||
config.UpdateContainerStatus(id, "running")
|
||||
@@ -1262,7 +1327,7 @@ func (m *Manager) StartContainer(id int) error {
|
||||
if err := m.ApplyPortMappings(id); err != nil {
|
||||
fmt.Printf("Warning: failed to apply port mappings: %v\n", err)
|
||||
}
|
||||
if c.IPv6 != "" {
|
||||
if c.IPv6 != "" || len(c.IPv6Addresses) > 0 {
|
||||
if err := m.ApplyIPv6(id); err != nil {
|
||||
fmt.Printf("Warning: failed to apply IPv6 routing for %s: %v\n", lxcName, err)
|
||||
}
|
||||
@@ -1272,6 +1337,41 @@ func (m *Manager) StartContainer(id int) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
func (m *Manager) startLXCContainerDaemon(lxcName string) (string, string, []byte, error) {
|
||||
logFile := filepath.Join(os.TempDir(), "clicd-"+lxcName+"-start.log")
|
||||
consoleLog := filepath.Join(os.TempDir(), "clicd-"+lxcName+"-console.log")
|
||||
os.Remove(logFile)
|
||||
os.Remove(consoleLog)
|
||||
cmd := exec.Command("lxc-start", "-n", lxcName, "-d", "--logfile", logFile, "--logpriority", "DEBUG", "--console-log", consoleLog)
|
||||
output, err := cmd.CombinedOutput()
|
||||
return logFile, consoleLog, output, err
|
||||
}
|
||||
|
||||
func (m *Manager) waitForLXCStartup(lxcName, logFile, consoleLog string) error {
|
||||
runningChecks := 0
|
||||
lastStatus := "unknown"
|
||||
for retry := 0; retry < 10; retry++ {
|
||||
time.Sleep(1 * time.Second)
|
||||
status, err := m.GetContainerStatus(lxcName)
|
||||
if err != nil {
|
||||
lastStatus = "unknown"
|
||||
continue
|
||||
}
|
||||
lastStatus = status
|
||||
if status == "running" {
|
||||
runningChecks++
|
||||
if runningChecks >= 3 {
|
||||
return nil
|
||||
}
|
||||
continue
|
||||
}
|
||||
if runningChecks > 0 || retry >= 1 {
|
||||
break
|
||||
}
|
||||
}
|
||||
return fmt.Errorf("container exited immediately after start (status: %s), lxc log: %s, console: %s", lastStatus, tailFile(logFile, 80), tailFile(consoleLog, 80))
|
||||
}
|
||||
|
||||
// applyBandwidthLimit applies tc-based bandwidth limit on container's veth interface
|
||||
// ApplyContainerLimits re-applies resource limits (CPU, RAM, IO, BW) to a running container.
|
||||
func (m *Manager) ApplyContainerLimits(c *config.Container) error {
|
||||
@@ -1553,8 +1653,17 @@ func (m *Manager) DestroyContainer(id int) error {
|
||||
return fmt.Errorf("container not found: %d", id)
|
||||
}
|
||||
lxcName := c.LxcName()
|
||||
if c.IPv6 != "" && c.IPv6Interface != "" {
|
||||
removeHostIPv6Routing(c.IPv6, c.IPv6Interface)
|
||||
if c.IPv6 != "" || len(c.IPv6Addresses) > 0 {
|
||||
c.NormalizeNetworkAssignments()
|
||||
for _, assignment := range c.IPv6Addresses {
|
||||
uplink := assignment.Interface
|
||||
if uplink == "" {
|
||||
uplink = c.IPv6Interface
|
||||
}
|
||||
if uplink != "" {
|
||||
removeHostIPv6Routing(assignment.Address, uplink)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if err := m.StopContainer(id); err != nil {
|
||||
@@ -1799,6 +1908,11 @@ install_sshd() {
|
||||
return 1
|
||||
}
|
||||
|
||||
ensure_sshd_runtime_dir() {
|
||||
mkdir -p /run/sshd /var/run/sshd
|
||||
chmod 0755 /run/sshd /var/run/sshd 2>/dev/null || true
|
||||
}
|
||||
|
||||
set_sshd_option() {
|
||||
key="$1"
|
||||
value="$2"
|
||||
@@ -1825,11 +1939,13 @@ set_sshd_option() {
|
||||
|
||||
install_sshd || exit 30
|
||||
|
||||
mkdir -p /run/sshd /var/run/sshd /etc/ssh /etc/ssh/sshd_config.d
|
||||
mkdir -p /etc/ssh /etc/ssh/sshd_config.d
|
||||
ensure_sshd_runtime_dir
|
||||
ssh-keygen -A >/dev/null 2>&1 || true
|
||||
|
||||
cat >/etc/ssh/sshd_config.d/99-clicd.conf <<'EOF'
|
||||
PermitRootLogin yes
|
||||
PubkeyAuthentication yes
|
||||
PasswordAuthentication yes
|
||||
KbdInteractiveAuthentication no
|
||||
ChallengeResponseAuthentication no
|
||||
@@ -1837,6 +1953,7 @@ UsePAM no
|
||||
EOF
|
||||
|
||||
set_sshd_option PermitRootLogin yes
|
||||
set_sshd_option PubkeyAuthentication yes
|
||||
set_sshd_option PasswordAuthentication yes
|
||||
set_sshd_option KbdInteractiveAuthentication no
|
||||
set_sshd_option ChallengeResponseAuthentication no
|
||||
@@ -1858,6 +1975,7 @@ if command -v chkconfig >/dev/null 2>&1; then
|
||||
fi
|
||||
|
||||
SSHD_BIN="$(sshd_path)" || exit 32
|
||||
ensure_sshd_runtime_dir
|
||||
"$SSHD_BIN" -t -f /etc/ssh/sshd_config >/tmp/clicd-sshd-test.log 2>&1 || {
|
||||
cat /tmp/clicd-sshd-test.log
|
||||
exit 32
|
||||
@@ -1872,6 +1990,7 @@ if command -v systemctl >/dev/null 2>&1; then
|
||||
systemctl stop ssh.socket 2>/dev/null || true
|
||||
systemctl disable ssh.socket 2>/dev/null || true
|
||||
fi
|
||||
ensure_sshd_runtime_dir
|
||||
if command -v systemctl >/dev/null 2>&1 && [ -d /run/systemd/system ]; then
|
||||
systemctl restart ssh >/dev/null 2>&1 || systemctl restart sshd >/dev/null 2>&1 || true
|
||||
fi
|
||||
@@ -1882,9 +2001,22 @@ service ssh restart >/dev/null 2>&1 ||
|
||||
/etc/init.d/sshd restart >/dev/null 2>&1 ||
|
||||
true
|
||||
|
||||
ensure_sshd_runtime_dir
|
||||
|
||||
for i in 1 2 3 4 5; do
|
||||
if (ss -ltn 2>/dev/null || netstat -tln 2>/dev/null) | grep -Eq '(^|[[:space:]])[^[:space:]]*:22[[:space:]]'; then
|
||||
exit 0
|
||||
fi
|
||||
if pgrep -x sshd >/dev/null 2>&1; then
|
||||
exit 0
|
||||
fi
|
||||
sleep 1
|
||||
done
|
||||
|
||||
if ! (ss -ltn 2>/dev/null || netstat -tln 2>/dev/null) | grep -Eq '(^|[[:space:]])[^[:space:]]*:22[[:space:]]'; then
|
||||
pkill -x sshd >/dev/null 2>&1 || killall sshd >/dev/null 2>&1 || true
|
||||
rm -f /run/sshd.pid /var/run/sshd.pid
|
||||
ensure_sshd_runtime_dir
|
||||
"$SSHD_BIN" -f /etc/ssh/sshd_config >/dev/null 2>&1 || exit 32
|
||||
fi
|
||||
|
||||
@@ -1986,6 +2118,45 @@ func (m *Manager) setRootfsPassword(rootfsPath, password string) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
func (m *Manager) installRootAuthorizedKey(rootfsPath, publicKey string) error {
|
||||
key, err := NormalizeSSHPublicKey(publicKey)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if key == "" {
|
||||
return nil
|
||||
}
|
||||
sshDir := filepath.Join(rootfsPath, "root", ".ssh")
|
||||
if err := os.MkdirAll(sshDir, 0700); err != nil {
|
||||
return err
|
||||
}
|
||||
authPath := filepath.Join(sshDir, "authorized_keys")
|
||||
existing, _ := os.ReadFile(authPath)
|
||||
lines := strings.Split(string(existing), "\n")
|
||||
for _, line := range lines {
|
||||
if strings.TrimSpace(line) == key {
|
||||
_ = os.Chmod(sshDir, 0700)
|
||||
_ = os.Chmod(authPath, 0600)
|
||||
_ = os.Chown(sshDir, 0, 0)
|
||||
_ = os.Chown(authPath, 0, 0)
|
||||
return nil
|
||||
}
|
||||
}
|
||||
content := strings.TrimRight(string(existing), "\r\n")
|
||||
if content != "" {
|
||||
content += "\n"
|
||||
}
|
||||
content += key + "\n"
|
||||
if err := os.WriteFile(authPath, []byte(content), 0600); err != nil {
|
||||
return err
|
||||
}
|
||||
_ = os.Chmod(sshDir, 0700)
|
||||
_ = os.Chmod(authPath, 0600)
|
||||
_ = os.Chown(sshDir, 0, 0)
|
||||
_ = os.Chown(authPath, 0, 0)
|
||||
return nil
|
||||
}
|
||||
|
||||
func safeRootfsCommandArgs(args []string) ([]string, error) {
|
||||
if len(args) == 0 {
|
||||
return nil, fmt.Errorf("empty rootfs command")
|
||||
@@ -2383,7 +2554,7 @@ func copyRootfsContents(src, dst string) error {
|
||||
}
|
||||
|
||||
// ReinstallContainer reinstalls the container OS
|
||||
func (m *Manager) ReinstallContainer(id int, templateID string) error {
|
||||
func (m *Manager) ReinstallContainer(id int, templateID string, authConfig ...ContainerConfig) error {
|
||||
c := config.FindContainer(id)
|
||||
if c == nil {
|
||||
return fmt.Errorf("container not found: %d", id)
|
||||
@@ -2393,6 +2564,14 @@ func (m *Manager) ReinstallContainer(id int, templateID string) error {
|
||||
if tmpl == nil {
|
||||
return fmt.Errorf("template not found: %s", templateID)
|
||||
}
|
||||
authCfg := ContainerConfig{SSHAuthMode: SSHAuthKeep}
|
||||
if len(authConfig) > 0 {
|
||||
authCfg = authConfig[0]
|
||||
}
|
||||
sshAccess, err := ResolveReinstallSSHAccess(c.SSHPassword, authCfg)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
|
||||
lxcName := c.LxcName()
|
||||
|
||||
@@ -2425,14 +2604,15 @@ func (m *Manager) ReinstallContainer(id int, templateID string) error {
|
||||
NetworkBWMbps: c.NetworkBWMbps,
|
||||
MonthlyTrafficGB: c.MonthlyTrafficGB,
|
||||
IOSpeedMBps: c.IOSpeedMBps,
|
||||
AssignIPv6: c.IPv6 != "",
|
||||
AssignIPv6: c.IPv6 != "" || len(c.IPv6Addresses) > 0,
|
||||
ExpiresAt: c.ExpiresAt,
|
||||
}
|
||||
if err := m.applyResourceLimits(lxcName, cfg); err != nil {
|
||||
return err
|
||||
}
|
||||
if c.IPv6 != "" {
|
||||
if err := m.applyIPv6Config(lxcName, c.IPv6); err != nil {
|
||||
if c.IPv6 != "" || len(c.IPv6Addresses) > 0 {
|
||||
c.NormalizeNetworkAssignments()
|
||||
if err := m.applyIPv6Config(lxcName, c.IPv6AddressStrings()...); err != nil {
|
||||
return err
|
||||
}
|
||||
}
|
||||
@@ -2440,17 +2620,20 @@ func (m *Manager) ReinstallContainer(id int, templateID string) error {
|
||||
// Set root password and pre-configure network/SSH via chroot.
|
||||
rootfsPath := filepath.Join(m.LxcPath, lxcName, "rootfs")
|
||||
m.preconfigureNetwork(rootfsPath, templateID)
|
||||
if c.IPv6 != "" {
|
||||
if err := installContainerIPv6Init(rootfsPath, c.IPv6); err != nil {
|
||||
if c.IPv6 != "" || len(c.IPv6Addresses) > 0 {
|
||||
if err := installContainerIPv6Init(rootfsPath, c.IPv6AddressStrings()...); err != nil {
|
||||
fmt.Printf("Warning: failed to install IPv6 init in %s after reinstall: %v\n", lxcName, err)
|
||||
}
|
||||
}
|
||||
if c.SSHPassword == "" {
|
||||
c.SSHPassword = generateRandomString(16)
|
||||
}
|
||||
c.SSHPassword = sshAccess.Password
|
||||
if err := m.preconfigureSSH(rootfsPath, templateID); err != nil {
|
||||
fmt.Printf("Warning: failed to pre-configure SSH in %s after reinstall: %v\n", lxcName, err)
|
||||
}
|
||||
if sshAccess.PublicKey != "" {
|
||||
if err := m.installRootAuthorizedKey(rootfsPath, sshAccess.PublicKey); err != nil {
|
||||
return fmt.Errorf("failed to install SSH public key: %v", err)
|
||||
}
|
||||
}
|
||||
if err := m.shiftRootfsForUnprivileged(lxcName); err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -2470,14 +2653,17 @@ func (m *Manager) ReinstallContainer(id int, templateID string) error {
|
||||
config.SaveConfig()
|
||||
return err
|
||||
}
|
||||
logFile := filepath.Join(os.TempDir(), "clicd-"+lxcName+"-start.log")
|
||||
os.Remove(logFile)
|
||||
startCmd := exec.Command("lxc-start", "-n", lxcName, "-d", "--logfile", logFile, "--logpriority", "DEBUG")
|
||||
if output, err := startCmd.CombinedOutput(); err != nil {
|
||||
logFile, consoleLog, output, err := m.startLXCContainerDaemon(lxcName)
|
||||
if err != nil {
|
||||
fmt.Printf("Warning: failed to start container after reinstall: %v\n", err)
|
||||
c.Status = "stopped"
|
||||
config.SaveConfig()
|
||||
return fmt.Errorf("reinstalled but failed to start: %v, output: %s, lxc log: %s", err, string(output), tailFile(logFile, 80))
|
||||
return fmt.Errorf("reinstalled but failed to start: %v, output: %s, lxc log: %s, console: %s", err, string(output), tailFile(logFile, 80), tailFile(consoleLog, 80))
|
||||
}
|
||||
if err := m.waitForLXCStartup(lxcName, logFile, consoleLog); err != nil {
|
||||
c.Status = "stopped"
|
||||
config.SaveConfig()
|
||||
return fmt.Errorf("reinstalled but container did not stay running: %v", err)
|
||||
}
|
||||
|
||||
// Wait for network and install SSH
|
||||
@@ -2503,7 +2689,7 @@ func (m *Manager) ReinstallContainer(id int, templateID string) error {
|
||||
if c.NetworkBWMbps > 0 {
|
||||
m.applyBandwidthLimit(c.LxcName(), c.NetworkBWMbps)
|
||||
}
|
||||
if c.IPv6 != "" {
|
||||
if c.IPv6 != "" || len(c.IPv6Addresses) > 0 {
|
||||
if err := m.ApplyIPv6(id); err != nil {
|
||||
fmt.Printf("Warning: failed to apply IPv6 after reinstall: %v\n", err)
|
||||
}
|
||||
|
||||
+326
-26
@@ -2,8 +2,10 @@ package lxc
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"net/netip"
|
||||
"os/exec"
|
||||
"strconv"
|
||||
"strings"
|
||||
|
||||
"clicd/internal/config"
|
||||
)
|
||||
@@ -17,6 +19,7 @@ func (m *Manager) ApplyPortMappings(id int) error {
|
||||
if c.IP == "" {
|
||||
return fmt.Errorf("container has no IP")
|
||||
}
|
||||
EnsureAssignedPublicIPv4s(c.PublicIPv4s)
|
||||
tag := clicdTag(id)
|
||||
bridge := "lxcbr0"
|
||||
subnet := "10.0.3.0/24"
|
||||
@@ -27,35 +30,180 @@ func (m *Manager) ApplyPortMappings(id int) error {
|
||||
|
||||
EnsureForwardRules(bridge)
|
||||
m.CleanPortMappings(id)
|
||||
deleteBridgeMasquerade(subnet)
|
||||
|
||||
for _, pm := range c.PortMappings {
|
||||
cmd := exec.Command("iptables",
|
||||
"-t", "nat",
|
||||
"-I", "PREROUTING", "1",
|
||||
"-p", pm.Protocol,
|
||||
"--dport", fmt.Sprintf("%d", pm.HostPort),
|
||||
"-j", "DNAT",
|
||||
"--to-destination", fmt.Sprintf("%s:%d", c.IP, pm.ContainerPort),
|
||||
"-m", "comment", "--comment", fmt.Sprintf("clicd-%s-%d", tag, pm.HostPort),
|
||||
)
|
||||
output, err := cmd.CombinedOutput()
|
||||
if err != nil {
|
||||
fmt.Printf("Warning: failed to apply port mapping %d->%s:%d: %v, output: %s\n",
|
||||
pm.HostPort, c.IP, pm.ContainerPort, err, string(output))
|
||||
continue
|
||||
for _, hostIP := range expandPortMappingHostIPs(c, pm) {
|
||||
args := []string{
|
||||
"-t", "nat",
|
||||
"-I", "PREROUTING", "1",
|
||||
"-p", pm.Protocol,
|
||||
}
|
||||
if hostIP != "" {
|
||||
args = append(args, "-d", hostIP)
|
||||
}
|
||||
args = append(args,
|
||||
"--dport", fmt.Sprintf("%d", pm.HostPort),
|
||||
"-j", "DNAT",
|
||||
"--to-destination", fmt.Sprintf("%s:%d", c.IP, pm.ContainerPort),
|
||||
"-m", "comment", "--comment", fmt.Sprintf("clicd-%s-%s-%d", tag, natRuleIPTag(hostIP), pm.HostPort),
|
||||
)
|
||||
cmd := exec.Command("iptables", args...)
|
||||
output, err := cmd.CombinedOutput()
|
||||
if err != nil {
|
||||
fmt.Printf("Warning: failed to apply port mapping %s:%d->%s:%d: %v, output: %s\n",
|
||||
displayHostIP(hostIP), pm.HostPort, c.IP, pm.ContainerPort, err, string(output))
|
||||
continue
|
||||
}
|
||||
fmt.Printf("Port mapping: %s:%d -> %s:%d\n", displayHostIP(hostIP), pm.HostPort, c.IP, pm.ContainerPort)
|
||||
}
|
||||
fmt.Printf("Port mapping: host:%d -> %s:%d\n", pm.HostPort, c.IP, pm.ContainerPort)
|
||||
}
|
||||
|
||||
if exec.Command("iptables", "-t", "nat", "-C", "POSTROUTING", "-s", subnet, "-o", "eth+", "-j", "MASQUERADE").Run() != nil {
|
||||
exec.Command("iptables", "-t", "nat", "-I", "POSTROUTING", "1", "-s", subnet, "-o", "eth+", "-j", "MASQUERADE").Run()
|
||||
}
|
||||
applyIPv4EgressPolicy(c, bridge, subnet, tag)
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
func applyIPv4EgressPolicy(c *config.Container, bridge, subnet, tag string) {
|
||||
if c == nil || strings.TrimSpace(c.IP) == "" {
|
||||
return
|
||||
}
|
||||
if containerAllowsPublicIPv4Egress(c) {
|
||||
if _, ok := primaryPublicIPv4Assignment(c); ok {
|
||||
applyPublicIPv4SNAT(c, tag)
|
||||
return
|
||||
}
|
||||
ensureContainerMasquerade(c, tag)
|
||||
return
|
||||
}
|
||||
ensureIPv4EgressBlocked(c, bridge, subnet, tag)
|
||||
}
|
||||
|
||||
func containerAllowsPublicIPv4Egress(c *config.Container) bool {
|
||||
if c == nil {
|
||||
return false
|
||||
}
|
||||
if len(c.PublicIPv4s) > 0 {
|
||||
return true
|
||||
}
|
||||
return c.PortMappingLimit > 0 || len(c.PortMappings) > 0
|
||||
}
|
||||
|
||||
func ensureContainerMasquerade(c *config.Container, tag string) {
|
||||
args := []string{
|
||||
"-s", c.IP + "/32",
|
||||
"-m", "comment", "--comment", fmt.Sprintf("clicd-%s-masq", tag),
|
||||
"-j", "MASQUERADE",
|
||||
}
|
||||
if host := DetectPublicIPv4(); strings.TrimSpace(host.Interface) != "" {
|
||||
args = append([]string{"-o", strings.TrimSpace(host.Interface)}, args...)
|
||||
} else {
|
||||
args = append([]string{"-o", "eth+"}, args...)
|
||||
}
|
||||
ensureNATRule("POSTROUTING", args)
|
||||
}
|
||||
|
||||
func ensureIPv4EgressBlocked(c *config.Container, bridge, subnet, tag string) {
|
||||
args := []string{
|
||||
"-i", bridge,
|
||||
"-s", c.IP + "/32",
|
||||
"!", "-d", subnet,
|
||||
"-m", "comment", "--comment", fmt.Sprintf("clicd-%s-v4-egress-block", tag),
|
||||
"-j", "REJECT",
|
||||
}
|
||||
ensureFilterRule("FORWARD", args)
|
||||
}
|
||||
|
||||
func ensureNATRule(chain string, args []string) {
|
||||
check := append([]string{"-t", "nat", "-C", chain}, args...)
|
||||
if exec.Command("iptables", check...).Run() == nil {
|
||||
return
|
||||
}
|
||||
add := append([]string{"-t", "nat", "-I", chain, "1"}, args...)
|
||||
exec.Command("iptables", add...).Run()
|
||||
}
|
||||
|
||||
func ensureFilterRule(chain string, args []string) {
|
||||
check := append([]string{"-C", chain}, args...)
|
||||
if exec.Command("iptables", check...).Run() == nil {
|
||||
return
|
||||
}
|
||||
add := append([]string{"-I", chain, "1"}, args...)
|
||||
exec.Command("iptables", add...).Run()
|
||||
}
|
||||
|
||||
func deleteBridgeMasquerade(subnet string) {
|
||||
for exec.Command("iptables", "-t", "nat", "-D", "POSTROUTING", "-s", subnet, "-o", "eth+", "-j", "MASQUERADE").Run() == nil {
|
||||
}
|
||||
}
|
||||
|
||||
func applyPublicIPv4SNAT(c *config.Container, tag string) {
|
||||
if c == nil || strings.TrimSpace(c.IP) == "" {
|
||||
return
|
||||
}
|
||||
assignment, ok := primaryPublicIPv4Assignment(c)
|
||||
if !ok {
|
||||
return
|
||||
}
|
||||
hostIP := strings.TrimSpace(assignment.Address)
|
||||
if hostIP == "" {
|
||||
return
|
||||
}
|
||||
iface := strings.TrimSpace(assignment.Interface)
|
||||
if iface == "" {
|
||||
if info, ok := publicIPv4InfoByAddress(hostIP); ok {
|
||||
iface = strings.TrimSpace(info.Interface)
|
||||
}
|
||||
}
|
||||
if iface == "" {
|
||||
if host := DetectPublicIPv4(); host.Interface != "" {
|
||||
iface = host.Interface
|
||||
}
|
||||
}
|
||||
args := []string{
|
||||
"-t", "nat",
|
||||
"-I", "POSTROUTING", "1",
|
||||
"-s", c.IP + "/32",
|
||||
}
|
||||
if iface != "" {
|
||||
args = append(args, "-o", iface)
|
||||
}
|
||||
args = append(args,
|
||||
"-m", "comment", "--comment", fmt.Sprintf("clicd-%s-snat-%s", tag, natRuleIPTag(hostIP)),
|
||||
"-j", "SNAT", "--to-source", hostIP,
|
||||
)
|
||||
if output, err := exec.Command("iptables", args...).CombinedOutput(); err != nil {
|
||||
fmt.Printf("Warning: failed to apply public IPv4 SNAT %s -> %s: %v, output: %s\n", c.IP, hostIP, err, string(output))
|
||||
}
|
||||
}
|
||||
|
||||
func primaryPublicIPv4Assignment(c *config.Container) (config.PublicIPv4Assignment, bool) {
|
||||
if c == nil {
|
||||
return config.PublicIPv4Assignment{}, false
|
||||
}
|
||||
for _, item := range c.PublicIPv4s {
|
||||
if strings.TrimSpace(item.Address) != "" {
|
||||
return item, true
|
||||
}
|
||||
}
|
||||
return config.PublicIPv4Assignment{}, false
|
||||
}
|
||||
|
||||
func clicdTag(id int) string { return "c" + strconv.Itoa(id) }
|
||||
|
||||
func EnsureAllRunningPortMappings() {
|
||||
m := NewManager()
|
||||
for i := range config.AppConfig.Containers {
|
||||
c := &config.AppConfig.Containers[i]
|
||||
if c.Status != "running" || strings.TrimSpace(c.IP) == "" {
|
||||
continue
|
||||
}
|
||||
if err := m.ApplyPortMappings(c.ID); err != nil {
|
||||
fmt.Printf("Warning: failed to restore port mappings for %s: %v\n", c.Name, err)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// EnsureForwardRules makes sure iptables FORWARD chain allows bridge traffic.
|
||||
func EnsureForwardRules(bridge string) {
|
||||
if bridge == "" {
|
||||
@@ -81,8 +229,13 @@ func EnsureForwardRules(bridge string) {
|
||||
// CleanPortMappings removes all iptables rules for a container
|
||||
func (m *Manager) CleanPortMappings(id int) error {
|
||||
tag := clicdTag(id)
|
||||
for _, chain := range []string{"PREROUTING", "POSTROUTING"} {
|
||||
cmd := exec.Command("sh", "-c",
|
||||
fmt.Sprintf("iptables -t nat -L %s -n --line-numbers 2>/dev/null | grep 'clicd-%s-' | awk '{print $1}' | sort -rn | while read num; do iptables -t nat -D %s $num; done", chain, tag, chain))
|
||||
cmd.Run()
|
||||
}
|
||||
cmd := exec.Command("sh", "-c",
|
||||
fmt.Sprintf("iptables -t nat -L PREROUTING -n --line-numbers 2>/dev/null | grep 'clicd-%s' | awk '{print $1}' | sort -rn | while read num; do iptables -t nat -D PREROUTING $num; done", tag))
|
||||
fmt.Sprintf("iptables -S FORWARD 2>/dev/null | grep 'clicd-%s-' | sed 's/^-A /-D /' | while read rule; do iptables $rule; done", tag))
|
||||
cmd.Run()
|
||||
return nil
|
||||
}
|
||||
@@ -94,12 +247,26 @@ func SetupDefaultPortMappings(sshPort int) []config.PortMapping {
|
||||
}
|
||||
}
|
||||
|
||||
func DefaultPortMappingHostIP(assignments []config.PublicIPv4Assignment) string {
|
||||
if len(assignments) == 1 {
|
||||
return strings.TrimSpace(assignments[0].Address)
|
||||
}
|
||||
return ""
|
||||
}
|
||||
|
||||
func defaultPortMappingHostIP(assignments []config.PublicIPv4Assignment) string {
|
||||
return DefaultPortMappingHostIP(assignments)
|
||||
}
|
||||
|
||||
// AddPortMapping adds a NAT rule to a container
|
||||
func (m *Manager) AddPortMapping(id int, pm config.PortMapping) ([]config.PortMapping, error) {
|
||||
c := config.FindContainer(id)
|
||||
if c == nil {
|
||||
return nil, fmt.Errorf("container not found: %d", id)
|
||||
}
|
||||
if c.PortMappingLimit <= 0 {
|
||||
return nil, fmt.Errorf("container has no IPv4 NAT port quota")
|
||||
}
|
||||
if c.PortMappingLimit > 0 && len(c.PortMappings) >= c.PortMappingLimit {
|
||||
return nil, fmt.Errorf("port mapping quota exceeded: %d/%d", len(c.PortMappings), c.PortMappingLimit)
|
||||
}
|
||||
@@ -168,6 +335,17 @@ func normalizePortMapping(c *config.Container, skipIndex int, pm config.PortMapp
|
||||
if pm.Protocol == "" {
|
||||
pm.Protocol = "tcp"
|
||||
}
|
||||
pm.Protocol = strings.ToLower(strings.TrimSpace(pm.Protocol))
|
||||
pm.HostIP = strings.TrimSpace(pm.HostIP)
|
||||
if pm.HostIP != "" {
|
||||
addr, err := netip.ParseAddr(pm.HostIP)
|
||||
if err != nil || !addr.Is4() {
|
||||
return pm, fmt.Errorf("host_ip must be a valid IPv4 address")
|
||||
}
|
||||
if !containerHasPublicIPv4(c, pm.HostIP) {
|
||||
return pm, fmt.Errorf("host_ip %s is not assigned to this container", pm.HostIP)
|
||||
}
|
||||
}
|
||||
if pm.Description == "" {
|
||||
pm.Description = fmt.Sprintf("Port-%d", pm.ContainerPort)
|
||||
}
|
||||
@@ -179,8 +357,8 @@ func normalizePortMapping(c *config.Container, skipIndex int, pm config.PortMapp
|
||||
if i == skipIndex {
|
||||
continue
|
||||
}
|
||||
if existing.HostPort == pm.HostPort && existing.Protocol == pm.Protocol {
|
||||
return pm, fmt.Errorf("host port %d/%s already mapped in this container", pm.HostPort, pm.Protocol)
|
||||
if portMappingsConflict(c, pm, c, existing) {
|
||||
return pm, fmt.Errorf("host port %d/%s already mapped on the same IPv4 in this container", pm.HostPort, pm.Protocol)
|
||||
}
|
||||
}
|
||||
// Check all other containers (LXC + KVM) for port conflicts
|
||||
@@ -189,8 +367,9 @@ func normalizePortMapping(c *config.Container, skipIndex int, pm config.PortMapp
|
||||
continue
|
||||
}
|
||||
for _, existing := range oc.PortMappings {
|
||||
if existing.HostPort == pm.HostPort && existing.Protocol == pm.Protocol {
|
||||
return pm, fmt.Errorf("host port %d/%s already used by container %s (ID: %d)", pm.HostPort, pm.Protocol, oc.Name, oc.ID)
|
||||
oc := oc
|
||||
if portMappingsConflict(c, pm, &oc, existing) {
|
||||
return pm, fmt.Errorf("host port %d/%s already used on the same IPv4 by container %s (ID: %d)", pm.HostPort, pm.Protocol, oc.Name, oc.ID)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -204,7 +383,9 @@ func allocateDefaultEqualPorts(c *config.Container, count int) []int {
|
||||
used := map[int]bool{}
|
||||
// Mark current container's ports
|
||||
for _, pm := range c.PortMappings {
|
||||
used[pm.HostPort] = true
|
||||
for _, hostIP := range expandPortMappingHostIPs(c, pm) {
|
||||
used[hostPortKey(hostIP, pm.HostPort)] = true
|
||||
}
|
||||
used[pm.ContainerPort] = true
|
||||
}
|
||||
// Also mark all other containers' host ports (LXC + KVM)
|
||||
@@ -213,13 +394,17 @@ func allocateDefaultEqualPorts(c *config.Container, count int) []int {
|
||||
continue
|
||||
}
|
||||
for _, pm := range oc.PortMappings {
|
||||
used[pm.HostPort] = true
|
||||
oc := oc
|
||||
for _, hostIP := range expandPortMappingHostIPs(&oc, pm) {
|
||||
used[hostPortKey(hostIP, pm.HostPort)] = true
|
||||
}
|
||||
}
|
||||
}
|
||||
ports := make([]int, 0, count)
|
||||
next := 20000
|
||||
for len(ports) < count {
|
||||
if !used[next] {
|
||||
hostIP := c.PrimaryPublicIPv4()
|
||||
if !used[hostPortKey(hostIP, next)] && !used[next] {
|
||||
ports = append(ports, next)
|
||||
}
|
||||
next++
|
||||
@@ -229,3 +414,118 @@ func allocateDefaultEqualPorts(c *config.Container, count int) []int {
|
||||
}
|
||||
return ports
|
||||
}
|
||||
|
||||
func HostPortAvailable(c *config.Container, hostIP string, hostPort int, protocol string) bool {
|
||||
if c == nil || hostPort <= 0 {
|
||||
return false
|
||||
}
|
||||
pm := config.PortMapping{HostIP: strings.TrimSpace(hostIP), HostPort: hostPort, Protocol: protocol}
|
||||
for _, existing := range c.PortMappings {
|
||||
if portMappingsConflict(c, pm, c, existing) {
|
||||
return false
|
||||
}
|
||||
}
|
||||
for _, oc := range config.AppConfig.Containers {
|
||||
if oc.ID == c.ID {
|
||||
continue
|
||||
}
|
||||
oc := oc
|
||||
for _, existing := range oc.PortMappings {
|
||||
if portMappingsConflict(c, pm, &oc, existing) {
|
||||
return false
|
||||
}
|
||||
}
|
||||
}
|
||||
return true
|
||||
}
|
||||
|
||||
func expandPortMappingHostIPs(c *config.Container, pm config.PortMapping) []string {
|
||||
if strings.TrimSpace(pm.HostIP) != "" {
|
||||
return []string{strings.TrimSpace(pm.HostIP)}
|
||||
}
|
||||
if c != nil && len(c.PublicIPv4s) > 0 {
|
||||
values := make([]string, 0, len(c.PublicIPv4s))
|
||||
for _, item := range c.PublicIPv4s {
|
||||
if strings.TrimSpace(item.Address) != "" {
|
||||
values = append(values, strings.TrimSpace(item.Address))
|
||||
}
|
||||
}
|
||||
if len(values) > 0 {
|
||||
return values
|
||||
}
|
||||
}
|
||||
return []string{""}
|
||||
}
|
||||
|
||||
func containerHasPublicIPv4(c *config.Container, hostIP string) bool {
|
||||
if c == nil {
|
||||
return false
|
||||
}
|
||||
for _, item := range c.PublicIPv4s {
|
||||
if item.Address == hostIP {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func portMappingsConflict(aContainer *config.Container, a config.PortMapping, bContainer *config.Container, b config.PortMapping) bool {
|
||||
if a.HostPort != b.HostPort || !protocolsOverlap(a.Protocol, b.Protocol) {
|
||||
return false
|
||||
}
|
||||
aIPs := expandPortMappingHostIPs(aContainer, a)
|
||||
bIPs := expandPortMappingHostIPs(bContainer, b)
|
||||
for _, aIP := range aIPs {
|
||||
for _, bIP := range bIPs {
|
||||
if aIP == "" || bIP == "" || aIP == bIP {
|
||||
return true
|
||||
}
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
func protocolsOverlap(a, b string) bool {
|
||||
a = strings.ToLower(strings.TrimSpace(a))
|
||||
b = strings.ToLower(strings.TrimSpace(b))
|
||||
if a == "" {
|
||||
a = "tcp"
|
||||
}
|
||||
if b == "" {
|
||||
b = "tcp"
|
||||
}
|
||||
if a == b || a == "all" || b == "all" {
|
||||
return true
|
||||
}
|
||||
return (a == "tcp+udp" && (b == "tcp" || b == "udp")) ||
|
||||
(b == "tcp+udp" && (a == "tcp" || a == "udp"))
|
||||
}
|
||||
|
||||
func natRuleIPTag(ip string) string {
|
||||
ip = strings.TrimSpace(ip)
|
||||
if ip == "" {
|
||||
return "any"
|
||||
}
|
||||
return strings.ReplaceAll(ip, ".", "_")
|
||||
}
|
||||
|
||||
func displayHostIP(ip string) string {
|
||||
if strings.TrimSpace(ip) == "" {
|
||||
return "host"
|
||||
}
|
||||
return ip
|
||||
}
|
||||
|
||||
func hostPortKey(hostIP string, port int) int {
|
||||
if hostIP == "" {
|
||||
return port
|
||||
}
|
||||
sum := 0
|
||||
for _, r := range hostIP {
|
||||
sum = sum*31 + int(r)
|
||||
}
|
||||
if sum < 0 {
|
||||
sum = -sum
|
||||
}
|
||||
return port + (sum % 1000000 * 100000)
|
||||
}
|
||||
|
||||
@@ -0,0 +1,221 @@
|
||||
package lxc
|
||||
|
||||
import (
|
||||
"fmt"
|
||||
"strings"
|
||||
"unicode"
|
||||
|
||||
"golang.org/x/crypto/ssh"
|
||||
)
|
||||
|
||||
const (
|
||||
SSHAuthAutoPassword = "auto_password"
|
||||
SSHAuthPassword = "password"
|
||||
SSHAuthKey = "key"
|
||||
SSHAuthKeep = "keep"
|
||||
)
|
||||
|
||||
type SSHAccess struct {
|
||||
Mode string
|
||||
Password string
|
||||
PublicKey string
|
||||
}
|
||||
|
||||
func HasSSHAuthOptions(cfg ContainerConfig) bool {
|
||||
return strings.TrimSpace(cfg.SSHAuthMode) != "" ||
|
||||
strings.TrimSpace(cfg.SSHPassword) != "" ||
|
||||
strings.TrimSpace(cfg.SSHPublicKey) != ""
|
||||
}
|
||||
|
||||
func ResolveCreateSSHAccess(cfg ContainerConfig) (SSHAccess, error) {
|
||||
mode, err := resolveSSHAuthMode(cfg.SSHAuthMode, cfg.SSHPassword, cfg.SSHPublicKey, SSHAuthAutoPassword)
|
||||
if err != nil {
|
||||
return SSHAccess{}, err
|
||||
}
|
||||
if mode == SSHAuthKeep {
|
||||
mode = SSHAuthAutoPassword
|
||||
}
|
||||
|
||||
switch mode {
|
||||
case SSHAuthAutoPassword:
|
||||
return SSHAccess{Mode: mode, Password: generateRandomString(16)}, nil
|
||||
case SSHAuthPassword:
|
||||
password := strings.TrimSpace(cfg.SSHPassword)
|
||||
if password == "" {
|
||||
return SSHAccess{}, fmt.Errorf("请填写自定义 SSH 密码")
|
||||
}
|
||||
if err := ValidateCustomSSHPassword(password); err != nil {
|
||||
return SSHAccess{}, err
|
||||
}
|
||||
return SSHAccess{Mode: mode, Password: password}, nil
|
||||
case SSHAuthKey:
|
||||
publicKey, err := NormalizeSSHPublicKey(cfg.SSHPublicKey)
|
||||
if err != nil {
|
||||
return SSHAccess{}, err
|
||||
}
|
||||
if publicKey == "" {
|
||||
return SSHAccess{}, fmt.Errorf("请填写 SSH 公钥")
|
||||
}
|
||||
password := strings.TrimSpace(cfg.SSHPassword)
|
||||
if password == "" {
|
||||
password = generateRandomString(16)
|
||||
} else if err := ValidateCustomSSHPassword(password); err != nil {
|
||||
return SSHAccess{}, err
|
||||
}
|
||||
return SSHAccess{Mode: mode, Password: password, PublicKey: publicKey}, nil
|
||||
default:
|
||||
return SSHAccess{}, fmt.Errorf("不支持的 SSH 登录方式: %s", mode)
|
||||
}
|
||||
}
|
||||
|
||||
func ResolveReinstallSSHAccess(currentPassword string, cfg ContainerConfig) (SSHAccess, error) {
|
||||
mode, err := resolveSSHAuthMode(cfg.SSHAuthMode, cfg.SSHPassword, cfg.SSHPublicKey, SSHAuthKeep)
|
||||
if err != nil {
|
||||
return SSHAccess{}, err
|
||||
}
|
||||
|
||||
switch mode {
|
||||
case SSHAuthKeep:
|
||||
password := strings.TrimSpace(currentPassword)
|
||||
if password == "" {
|
||||
password = generateRandomString(16)
|
||||
}
|
||||
if err := validateRootPassword(password); err != nil {
|
||||
return SSHAccess{}, err
|
||||
}
|
||||
return SSHAccess{Mode: mode, Password: password}, nil
|
||||
case SSHAuthAutoPassword:
|
||||
return SSHAccess{Mode: mode, Password: generateRandomString(16)}, nil
|
||||
case SSHAuthPassword:
|
||||
password := strings.TrimSpace(cfg.SSHPassword)
|
||||
if password == "" {
|
||||
return SSHAccess{}, fmt.Errorf("请填写自定义 SSH 密码")
|
||||
}
|
||||
if err := ValidateCustomSSHPassword(password); err != nil {
|
||||
return SSHAccess{}, err
|
||||
}
|
||||
return SSHAccess{Mode: mode, Password: password}, nil
|
||||
case SSHAuthKey:
|
||||
publicKey, err := NormalizeSSHPublicKey(cfg.SSHPublicKey)
|
||||
if err != nil {
|
||||
return SSHAccess{}, err
|
||||
}
|
||||
if publicKey == "" {
|
||||
return SSHAccess{}, fmt.Errorf("请填写 SSH 公钥")
|
||||
}
|
||||
password := strings.TrimSpace(cfg.SSHPassword)
|
||||
if password != "" {
|
||||
if err := ValidateCustomSSHPassword(password); err != nil {
|
||||
return SSHAccess{}, err
|
||||
}
|
||||
} else {
|
||||
password = strings.TrimSpace(currentPassword)
|
||||
if password == "" {
|
||||
password = generateRandomString(16)
|
||||
}
|
||||
}
|
||||
if err := validateRootPassword(password); err != nil {
|
||||
return SSHAccess{}, err
|
||||
}
|
||||
return SSHAccess{Mode: mode, Password: password, PublicKey: publicKey}, nil
|
||||
default:
|
||||
return SSHAccess{}, fmt.Errorf("不支持的 SSH 登录方式: %s", mode)
|
||||
}
|
||||
}
|
||||
|
||||
func ValidateCustomSSHPassword(password string) error {
|
||||
if len(password) < 8 || len(password) > 64 {
|
||||
return fmt.Errorf("密码长度必须为 8-64 位")
|
||||
}
|
||||
hasLetter := false
|
||||
hasDigit := false
|
||||
for _, r := range password {
|
||||
if unicode.IsSpace(r) {
|
||||
return fmt.Errorf("密码不能包含空白字符")
|
||||
}
|
||||
if unicode.IsLetter(r) {
|
||||
hasLetter = true
|
||||
}
|
||||
if unicode.IsDigit(r) {
|
||||
hasDigit = true
|
||||
}
|
||||
}
|
||||
if !hasLetter || !hasDigit {
|
||||
return fmt.Errorf("密码至少需要包含字母和数字")
|
||||
}
|
||||
return validateRootPassword(password)
|
||||
}
|
||||
|
||||
func NormalizeSSHPublicKey(publicKey string) (string, error) {
|
||||
key := strings.TrimSpace(publicKey)
|
||||
if key == "" {
|
||||
return "", nil
|
||||
}
|
||||
if len(key) > 8192 {
|
||||
return "", fmt.Errorf("SSH 公钥长度不能超过 8192 字符")
|
||||
}
|
||||
if strings.ContainsAny(key, "\r\n") || strings.ContainsRune(key, '\x00') {
|
||||
return "", fmt.Errorf("SSH 公钥只能填写一行")
|
||||
}
|
||||
|
||||
fields := strings.Fields(key)
|
||||
if len(fields) < 2 {
|
||||
return "", fmt.Errorf("SSH 公钥格式不正确")
|
||||
}
|
||||
if !isSupportedSSHKeyType(fields[0]) {
|
||||
return "", fmt.Errorf("不支持的 SSH 公钥类型: %s", fields[0])
|
||||
}
|
||||
parsed, _, _, rest, err := ssh.ParseAuthorizedKey([]byte(key))
|
||||
if err != nil {
|
||||
return "", fmt.Errorf("SSH 公钥格式不正确")
|
||||
}
|
||||
if strings.TrimSpace(string(rest)) != "" {
|
||||
return "", fmt.Errorf("一次只能填写一个 SSH 公钥")
|
||||
}
|
||||
if !isSupportedSSHKeyType(parsed.Type()) {
|
||||
return "", fmt.Errorf("不支持的 SSH 公钥类型: %s", parsed.Type())
|
||||
}
|
||||
return key, nil
|
||||
}
|
||||
|
||||
func resolveSSHAuthMode(rawMode, password, publicKey, defaultMode string) (string, error) {
|
||||
mode := strings.ToLower(strings.TrimSpace(rawMode))
|
||||
mode = strings.ReplaceAll(mode, "-", "_")
|
||||
if mode == "" {
|
||||
if strings.TrimSpace(publicKey) != "" {
|
||||
return SSHAuthKey, nil
|
||||
}
|
||||
if strings.TrimSpace(password) != "" {
|
||||
return SSHAuthPassword, nil
|
||||
}
|
||||
return defaultMode, nil
|
||||
}
|
||||
|
||||
switch mode {
|
||||
case "auto", "auto_password", "generated", "generate":
|
||||
return SSHAuthAutoPassword, nil
|
||||
case "password", "custom_password":
|
||||
return SSHAuthPassword, nil
|
||||
case "key", "ssh_key", "public_key":
|
||||
return SSHAuthKey, nil
|
||||
case "keep", "retain", "keep_password":
|
||||
return SSHAuthKeep, nil
|
||||
default:
|
||||
return "", fmt.Errorf("不支持的 SSH 登录方式: %s", rawMode)
|
||||
}
|
||||
}
|
||||
|
||||
func isSupportedSSHKeyType(keyType string) bool {
|
||||
switch keyType {
|
||||
case "ssh-ed25519",
|
||||
"ssh-rsa",
|
||||
"ecdsa-sha2-nistp256",
|
||||
"ecdsa-sha2-nistp384",
|
||||
"ecdsa-sha2-nistp521",
|
||||
"sk-ssh-ed25519@openssh.com",
|
||||
"sk-ecdsa-sha2-nistp256@openssh.com":
|
||||
return true
|
||||
default:
|
||||
return false
|
||||
}
|
||||
}
|
||||
@@ -46,17 +46,17 @@ func GetTemplates() []Template {
|
||||
},
|
||||
{
|
||||
ID: "archlinux-current", Name: "Arch Linux",
|
||||
Distro: "archlinux", Release: "current", Arch: "amd64", Variant: "cloud",
|
||||
Distro: "archlinux", Release: "current", Arch: "amd64",
|
||||
Description: "Arch Linux (Rolling)",
|
||||
},
|
||||
{
|
||||
ID: "fedora-44", Name: "Fedora 44",
|
||||
Distro: "fedora", Release: "44", Arch: "amd64", Variant: "cloud",
|
||||
Distro: "fedora", Release: "44", Arch: "amd64",
|
||||
Description: "Fedora 44",
|
||||
},
|
||||
{
|
||||
ID: "rockylinux-10", Name: "Rocky Linux 10",
|
||||
Distro: "rockylinux", Release: "10", Arch: "amd64", Variant: "cloud",
|
||||
Distro: "rockylinux", Release: "10", Arch: "amd64",
|
||||
Description: "Rocky Linux 10",
|
||||
},
|
||||
}
|
||||
|
||||
@@ -4,9 +4,7 @@ import (
|
||||
"crypto/tls"
|
||||
"fmt"
|
||||
"log"
|
||||
"net"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"strings"
|
||||
|
||||
"clicd/internal/api"
|
||||
@@ -19,7 +17,7 @@ var webFS http.FileSystem
|
||||
// corsMiddleware adds CORS headers
|
||||
func corsMiddleware(next http.HandlerFunc) http.HandlerFunc {
|
||||
return func(w http.ResponseWriter, r *http.Request) {
|
||||
if origin := r.Header.Get("Origin"); origin != "" && isAllowedOrigin(origin, r.Host) {
|
||||
if origin := r.Header.Get("Origin"); origin != "" && config.IsOriginAllowed(origin, r.Host) {
|
||||
w.Header().Set("Access-Control-Allow-Origin", origin)
|
||||
w.Header().Set("Vary", "Origin")
|
||||
w.Header().Set("Access-Control-Allow-Credentials", "true")
|
||||
@@ -28,7 +26,7 @@ func corsMiddleware(next http.HandlerFunc) http.HandlerFunc {
|
||||
w.Header().Set("Access-Control-Allow-Headers", "Content-Type, Authorization, X-API-Key")
|
||||
|
||||
if r.Method == http.MethodOptions {
|
||||
if origin := r.Header.Get("Origin"); origin != "" && !isAllowedOrigin(origin, r.Host) {
|
||||
if origin := r.Header.Get("Origin"); origin != "" && !config.IsOriginAllowed(origin, r.Host) {
|
||||
w.WriteHeader(http.StatusForbidden)
|
||||
return
|
||||
}
|
||||
@@ -40,34 +38,6 @@ func corsMiddleware(next http.HandlerFunc) http.HandlerFunc {
|
||||
}
|
||||
}
|
||||
|
||||
func isAllowedOrigin(origin string, requestHost string) bool {
|
||||
u, err := url.Parse(origin)
|
||||
if err != nil || u.Host == "" {
|
||||
return false
|
||||
}
|
||||
originHost := normalizeHost(u.Host)
|
||||
host := normalizeHost(requestHost)
|
||||
if originHost == host {
|
||||
return true
|
||||
}
|
||||
return isLoopbackHost(originHost) && isLoopbackHost(host)
|
||||
}
|
||||
|
||||
func normalizeHost(host string) string {
|
||||
if h, _, err := net.SplitHostPort(host); err == nil {
|
||||
return strings.ToLower(h)
|
||||
}
|
||||
return strings.ToLower(host)
|
||||
}
|
||||
|
||||
func isLoopbackHost(host string) bool {
|
||||
if host == "localhost" {
|
||||
return true
|
||||
}
|
||||
ip := net.ParseIP(host)
|
||||
return ip != nil && ip.IsLoopback()
|
||||
}
|
||||
|
||||
// setupRoutes configures API and static routes
|
||||
func setupRoutes(mux *http.ServeMux) {
|
||||
// API routes
|
||||
@@ -78,6 +48,7 @@ func setupRoutes(mux *http.ServeMux) {
|
||||
mux.HandleFunc("/api/change-username", corsMiddleware(api.AdminMiddleware(api.HandleAdminUsernameChange)))
|
||||
mux.HandleFunc("/api/login-logs", corsMiddleware(api.AdminMiddleware(api.HandleLoginLogs)))
|
||||
mux.HandleFunc("/api/ssl", corsMiddleware(api.AdminMiddleware(api.HandleSSLSettings)))
|
||||
mux.HandleFunc("/api/webssh-origins", corsMiddleware(api.AdminMiddleware(api.HandleWebSSHOriginSettings)))
|
||||
mux.HandleFunc("/api/containers", corsMiddleware(api.AuthMiddleware(api.SubUserMiddleware(api.HandleContainers))))
|
||||
mux.HandleFunc("/api/containers/list", corsMiddleware(api.AuthMiddleware(api.SubUserMiddleware(api.HandleContainerListAlias))))
|
||||
mux.HandleFunc("/api/containers/", corsMiddleware(api.AuthMiddleware(api.SubUserMiddleware(api.HandleSingleContainer))))
|
||||
@@ -92,6 +63,7 @@ func setupRoutes(mux *http.ServeMux) {
|
||||
mux.HandleFunc("/api/host-info", corsMiddleware(api.AdminMiddleware(api.HandleHostInfo)))
|
||||
mux.HandleFunc("/api/host-report", corsMiddleware(api.AdminMiddleware(api.HandleHostReport)))
|
||||
mux.HandleFunc("/api/snapshots", corsMiddleware(api.AdminMiddleware(api.HandleSnapshots)))
|
||||
mux.HandleFunc("/api/routing/ipv4-scan", corsMiddleware(api.AdminMiddleware(api.HandleRoutingIPv4Scan)))
|
||||
mux.HandleFunc("/api/routing", corsMiddleware(api.AdminMiddleware(api.HandleRouting)))
|
||||
mux.HandleFunc("/api/ipv6/status", corsMiddleware(api.AdminMiddleware(api.HandleIPv6Status)))
|
||||
mux.HandleFunc("/api/tasks", corsMiddleware(api.AuthMiddleware(api.SubUserMiddleware(api.HandleTasks))))
|
||||
@@ -134,6 +106,7 @@ func setupRoutes(mux *http.ServeMux) {
|
||||
mux.HandleFunc("/api/v1/host-info", corsMiddleware(api.AuthMiddleware(api.HandleHostInfo)))
|
||||
mux.HandleFunc("/api/v1/host-report", corsMiddleware(api.AuthMiddleware(api.HandleHostReport)))
|
||||
mux.HandleFunc("/api/v1/snapshots", corsMiddleware(api.AuthMiddleware(api.ScopeMiddleware("snapshot:read", api.HandleSnapshots))))
|
||||
mux.HandleFunc("/api/v1/routing/ipv4-scan", corsMiddleware(api.AuthMiddleware(api.HandleRoutingIPv4Scan)))
|
||||
mux.HandleFunc("/api/v1/routing", corsMiddleware(api.AuthMiddleware(api.HandleRouting)))
|
||||
mux.HandleFunc("/api/v1/ipv6/status", corsMiddleware(api.AuthMiddleware(api.HandleIPv6Status)))
|
||||
mux.HandleFunc("/api/v1/tasks", corsMiddleware(api.AuthMiddleware(api.SubUserMiddleware(api.HandleTasks))))
|
||||
@@ -146,6 +119,7 @@ func setupRoutes(mux *http.ServeMux) {
|
||||
mux.HandleFunc("/api/v1/audit-logs", corsMiddleware(api.AuthMiddleware(api.HandleAuditLogs)))
|
||||
mux.HandleFunc("/api/v1/login-logs", corsMiddleware(api.AuthMiddleware(api.HandleLoginLogs)))
|
||||
mux.HandleFunc("/api/v1/ssl", corsMiddleware(api.AdminMiddleware(api.HandleSSLSettings)))
|
||||
mux.HandleFunc("/api/v1/webssh-origins", corsMiddleware(api.AdminMiddleware(api.HandleWebSSHOriginSettings)))
|
||||
mux.HandleFunc("/api/v1/security/alerts", corsMiddleware(api.AuthMiddleware(api.ScopeMiddleware("security:read", api.HandleSecurityAlerts))))
|
||||
mux.HandleFunc("/api/v1/security/check", corsMiddleware(api.AuthMiddleware(api.ScopeMiddleware("security:check", api.HandleSecurityCheck))))
|
||||
mux.HandleFunc("/api/v1/security/logs", corsMiddleware(api.AuthMiddleware(api.ScopeMiddleware("security:read", api.HandleSecurityLogs))))
|
||||
|
||||
@@ -1 +0,0 @@
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
package version
|
||||
|
||||
var (
|
||||
Version = "1.1.9"
|
||||
Version = "1.1.12"
|
||||
Repo = "MengMengCode/CLICD"
|
||||
)
|
||||
|
||||
|
||||
@@ -55,6 +55,7 @@ func main() {
|
||||
// Ensure iptables FORWARD rules allow managed bridge traffic.
|
||||
lxc.EnsureForwardRules("lxcbr0")
|
||||
lxc.EnsureForwardRules("virbr0")
|
||||
lxc.EnsureAllAssignedPublicIPv4s()
|
||||
|
||||
// Start expiry scanners (stops expired/over-traffic workloads every 30s)
|
||||
manager := lxc.NewManager()
|
||||
@@ -74,6 +75,7 @@ func main() {
|
||||
|
||||
// Clean up stale container configs (LXC dir was deleted but config remains)
|
||||
config.CleanStaleContainers()
|
||||
lxc.EnsureAllRunningPortMappings()
|
||||
|
||||
// Pre-warm SSH for containers already running after host boot or service restart.
|
||||
manager.StartSSHWarmupScanner()
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
{
|
||||
"name": "clicd-frontend",
|
||||
"private": true,
|
||||
"version": "1.1.9",
|
||||
"version": "1.1.12",
|
||||
"type": "module",
|
||||
"scripts": {
|
||||
"dev": "vite",
|
||||
|
||||
@@ -1,7 +1,9 @@
|
||||
import { useEffect, useMemo, useState, type ReactNode } from 'react'
|
||||
import { CalendarClock, X } from 'lucide-react'
|
||||
import { CalendarClock, RefreshCw, X } from 'lucide-react'
|
||||
import { batchCreate, getIPv6Status, getEnabledImages, getHostInfo, CreateContainerRequest, HostInfo, IPv6Status, Template } from '../services/api'
|
||||
import { useDialog } from './Dialog'
|
||||
import { useLanguage, type Language } from '../contexts/LanguageContext'
|
||||
import { generateSSHPassword, sshPasswordError, sshPublicKeyError, type SSHAuthMode } from '../utils/sshAuth'
|
||||
|
||||
interface CreateContainerModalProps {
|
||||
isOpen: boolean
|
||||
@@ -26,13 +28,24 @@ const defaultForm: CreateContainerRequest = {
|
||||
io_speed_mbps: 0,
|
||||
extra_ports: [],
|
||||
port_mapping_count: 2,
|
||||
assign_nat: true,
|
||||
snapshot_limit: 1,
|
||||
assign_ipv4: false,
|
||||
ipv4_count: 1,
|
||||
public_ipv4s: [],
|
||||
assign_ipv6: false,
|
||||
ipv6_count: 1,
|
||||
ipv6_addresses: [],
|
||||
ssh_auth_mode: 'auto_password',
|
||||
ssh_password: '',
|
||||
ssh_public_key: '',
|
||||
expires_at: '',
|
||||
}
|
||||
|
||||
export default function CreateContainerModal({ isOpen, onClose, onSuccess, existingNames = [] }: CreateContainerModalProps) {
|
||||
const dialog = useDialog()
|
||||
const { language } = useLanguage()
|
||||
const networkText = createNetworkText[language]
|
||||
const [templates, setTemplates] = useState<Template[]>([])
|
||||
const [loading, setLoading] = useState(false)
|
||||
const [batchCount, setBatchCount] = useState(1)
|
||||
@@ -74,16 +87,25 @@ export default function CreateContainerModal({ isOpen, onClose, onSuccess, exist
|
||||
}, [isOpen, form.virtualization])
|
||||
|
||||
const ipv6Available = !!ipv6Status?.available
|
||||
const ipv6Prefix = ipv6Status?.prefixes?.[0]?.prefix || ''
|
||||
const ipv6Prefixes = ipv6Status?.prefixes || []
|
||||
const ipv6Prefix = ipv6Prefixes.length > 1 ? `${ipv6Prefixes.length} prefixes configured` : (ipv6Prefixes[0]?.prefix || '')
|
||||
const publicIPv4s = hostInfo?.network.public_ipv4_addresses || []
|
||||
const ipv4Available = publicIPv4s.length > 0
|
||||
const manualIPv4s = form.public_ipv4s || []
|
||||
const maxVCPU = hostInfo?.cpu.cores || 64
|
||||
const maxRAMMB = hostInfo?.ram.total_mb ? Number(hostInfo.ram.total_mb) : undefined
|
||||
const maxDiskGB = hostInfo?.disk.total_gb ? Math.max(1, Math.floor(hostInfo.disk.total_gb)) : undefined
|
||||
const resourceErrors = validateResourceInputs(form, maxVCPU, maxRAMMB, maxDiskGB)
|
||||
const natEnabled = form.assign_nat !== false
|
||||
const natPortCount = natEnabled ? Math.max(2, form.port_mapping_count || 2) : 0
|
||||
const linuxTemplate = !isWindowsTemplate(form.template_id)
|
||||
const sshAuthMode = (form.ssh_auth_mode || 'auto_password') as SSHAuthMode
|
||||
|
||||
const autoPorts = useMemo(() => {
|
||||
const count = Math.max(2, form.port_mapping_count)
|
||||
if (!natEnabled) return []
|
||||
const count = natPortCount
|
||||
return Array.from({ length: count - 1 }, (_, index) => 22002 + index)
|
||||
}, [form.port_mapping_count])
|
||||
}, [natEnabled, natPortCount])
|
||||
|
||||
// SSH port preview (will be allocated sequentially, starting around 22000+)
|
||||
const sshPortPreview = 22000
|
||||
@@ -127,7 +149,19 @@ export default function CreateContainerModal({ isOpen, onClose, onSuccess, exist
|
||||
return
|
||||
}
|
||||
|
||||
if (!form.assign_ipv4 && !form.assign_ipv6 && form.assign_nat === false) {
|
||||
dialog.alert('提示', '请勾选任意一个可用网络')
|
||||
return
|
||||
}
|
||||
|
||||
const authError = validateSSHAuthInputs(form)
|
||||
if (authError) {
|
||||
dialog.alert('登录方式有误', authError)
|
||||
return
|
||||
}
|
||||
|
||||
const boundedForm = normalizeCreateForm(form)
|
||||
const wantsNAT = boundedForm.assign_nat !== false
|
||||
|
||||
// Build batch of containers
|
||||
const containers: CreateContainerRequest[] = []
|
||||
@@ -137,8 +171,11 @@ export default function CreateContainerModal({ isOpen, onClose, onSuccess, exist
|
||||
containers.push({
|
||||
...boundedForm,
|
||||
name,
|
||||
port_mapping_count: Math.max(2, boundedForm.port_mapping_count || 2),
|
||||
assign_nat: wantsNAT,
|
||||
port_mapping_count: wantsNAT ? Math.max(2, boundedForm.port_mapping_count || 2) : 0,
|
||||
snapshot_limit: Math.max(1, boundedForm.snapshot_limit || 3),
|
||||
ipv4_count: boundedForm.assign_ipv4 ? Math.max(1, boundedForm.ipv4_count || 1) : 0,
|
||||
ipv6_count: boundedForm.assign_ipv6 ? Math.max(1, boundedForm.ipv6_count || 1) : 0,
|
||||
extra_ports: [],
|
||||
})
|
||||
}
|
||||
@@ -229,21 +266,206 @@ export default function CreateContainerModal({ isOpen, onClose, onSuccess, exist
|
||||
|
||||
</Field>
|
||||
|
||||
<label className={`flex items-start gap-3 rounded-md border px-3 py-2 text-sm ${ipv6Available ? 'border-gray-200 bg-white' : 'border-gray-200 bg-gray-50 text-gray-400'}`}>
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={!!form.assign_ipv6}
|
||||
disabled={!ipv6Available}
|
||||
onChange={(event) => setForm({ ...form, assign_ipv6: event.target.checked })}
|
||||
className="mt-1"
|
||||
/>
|
||||
<span className="min-w-0">
|
||||
<span className="block font-medium text-gray-800">Public IPv6</span>
|
||||
<span className="block text-xs text-gray-500 truncate">
|
||||
{ipv6Available ? `Use ${ipv6Prefix}` : (ipv6Status?.reason || 'Checking IPv6 prefix...')}
|
||||
{linuxTemplate && (
|
||||
<div className="rounded-md border border-gray-200 bg-white px-3 py-3 text-sm">
|
||||
<div className="mb-2 font-medium text-gray-800">登录方式</div>
|
||||
<div className="grid grid-cols-3 gap-2">
|
||||
{([
|
||||
['auto_password', '自动生成密码'],
|
||||
['password', '自定义密码'],
|
||||
['key', 'SSH Key'],
|
||||
] as Array<[SSHAuthMode, string]>).map(([mode, label]) => (
|
||||
<button
|
||||
key={mode}
|
||||
type="button"
|
||||
onClick={() => setForm({ ...form, ssh_auth_mode: mode })}
|
||||
className={`rounded-md border px-3 py-2 text-xs font-medium transition-colors ${sshAuthMode === mode ? 'border-black bg-black text-white' : 'border-gray-300 text-gray-700 hover:bg-gray-50'}`}
|
||||
>
|
||||
{label}
|
||||
</button>
|
||||
))}
|
||||
</div>
|
||||
{sshAuthMode === 'password' && (
|
||||
<div className="mt-3 flex gap-2">
|
||||
<input
|
||||
type="text"
|
||||
value={form.ssh_password || ''}
|
||||
onChange={(event) => setForm({ ...form, ssh_password: event.target.value })}
|
||||
className={inputClass}
|
||||
placeholder="RootPass123"
|
||||
/>
|
||||
<button
|
||||
type="button"
|
||||
onClick={() => setForm({ ...form, ssh_password: generateSSHPassword() })}
|
||||
className="inline-flex h-10 w-10 shrink-0 items-center justify-center rounded-md border border-gray-300 text-gray-600 hover:bg-gray-50"
|
||||
title="生成密码"
|
||||
>
|
||||
<RefreshCw className="h-4 w-4" />
|
||||
</button>
|
||||
</div>
|
||||
)}
|
||||
{sshAuthMode === 'key' && (
|
||||
<textarea
|
||||
value={form.ssh_public_key || ''}
|
||||
onChange={(event) => setForm({ ...form, ssh_public_key: event.target.value })}
|
||||
className={`${inputClass} mt-3 min-h-20 resize-y font-mono text-xs`}
|
||||
placeholder="ssh-ed25519 AAAA..."
|
||||
/>
|
||||
)}
|
||||
</div>
|
||||
)}
|
||||
|
||||
<div className={`rounded-md border px-3 py-2 text-sm ${ipv4Available ? 'border-gray-200 bg-white' : 'border-gray-200 bg-gray-50 text-gray-400'}`}>
|
||||
<label className="flex items-start gap-3">
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={!!form.assign_ipv4}
|
||||
disabled={!ipv4Available}
|
||||
onChange={(event) => setForm({ ...form, assign_ipv4: event.target.checked, public_ipv4s: event.target.checked ? form.public_ipv4s : [] })}
|
||||
className="mt-1"
|
||||
/>
|
||||
<span className="min-w-0">
|
||||
<span className="block font-medium text-gray-800">{networkText.publicIPv4}</span>
|
||||
<span className="block text-xs text-gray-500">
|
||||
{ipv4Available ? formatAllocatableIPv4Count(publicIPv4s.length, language) : networkText.noAllocatableIPv4}
|
||||
</span>
|
||||
</span>
|
||||
</span>
|
||||
</label>
|
||||
</label>
|
||||
{form.assign_ipv4 && (
|
||||
<div className="mt-3 space-y-3 pl-6">
|
||||
<div className="grid grid-cols-2 gap-3">
|
||||
<label className="flex items-center gap-2 text-xs text-gray-600">
|
||||
<input
|
||||
type="radio"
|
||||
checked={manualIPv4s.length === 0}
|
||||
onChange={() => setForm({ ...form, public_ipv4s: [] })}
|
||||
/>
|
||||
Auto assign
|
||||
</label>
|
||||
<Field label="IPv4 count">
|
||||
<NumberInput
|
||||
value={form.ipv4_count || 1}
|
||||
min={1}
|
||||
max={Math.max(1, publicIPv4s.length)}
|
||||
onChange={(value) => setForm({ ...form, ipv4_count: Math.max(1, Math.round(value || 1)) })}
|
||||
/>
|
||||
</Field>
|
||||
</div>
|
||||
<div className="space-y-1.5">
|
||||
<label className="flex items-center gap-2 text-xs text-gray-600">
|
||||
<input
|
||||
type="radio"
|
||||
checked={manualIPv4s.length > 0}
|
||||
onChange={() => setForm({ ...form, public_ipv4s: publicIPv4s[0]?.address ? [publicIPv4s[0].address] : [], ipv4_count: 1 })}
|
||||
/>
|
||||
Manual select
|
||||
</label>
|
||||
{manualIPv4s.length > 0 && (
|
||||
<div className="grid gap-1.5 sm:grid-cols-2">
|
||||
{publicIPv4s.map((ip) => (
|
||||
<label key={`${ip.interface}-${ip.address}`} className="flex min-w-0 items-center gap-2 rounded border border-gray-200 px-2 py-1.5 text-xs text-gray-700">
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={manualIPv4s.includes(ip.address)}
|
||||
onChange={(event) => {
|
||||
const next = event.target.checked
|
||||
? [...manualIPv4s, ip.address]
|
||||
: manualIPv4s.filter((value) => value !== ip.address)
|
||||
setForm({ ...form, public_ipv4s: next, ipv4_count: Math.max(1, next.length || 1) })
|
||||
}}
|
||||
/>
|
||||
<span className="truncate font-mono">{ip.address}</span>
|
||||
<span className="shrink-0 text-gray-400">{ip.interface}</span>
|
||||
{ip.gateway && <span className="shrink-0 text-gray-400">gw {ip.gateway}</span>}
|
||||
</label>
|
||||
))}
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
|
||||
<div className={`rounded-md border px-3 py-2 text-sm ${ipv6Available ? 'border-gray-200 bg-white' : 'border-gray-200 bg-gray-50 text-gray-400'}`}>
|
||||
<div className="flex items-start justify-between gap-3">
|
||||
<label className="flex min-w-0 flex-1 items-start gap-3">
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={!!form.assign_ipv6}
|
||||
disabled={!ipv6Available}
|
||||
onChange={(event) => setForm({ ...form, assign_ipv6: event.target.checked })}
|
||||
className="mt-1"
|
||||
/>
|
||||
<span className="min-w-0">
|
||||
<span className="block font-medium text-gray-800">{networkText.publicIPv6}</span>
|
||||
<span className="block text-xs text-gray-500 truncate">
|
||||
{ipv6Available ? `${networkText.use} ${ipv6Prefix}` : (ipv6Status?.reason || networkText.checkingIPv6Prefix)}
|
||||
</span>
|
||||
</span>
|
||||
</label>
|
||||
{form.assign_ipv6 && (
|
||||
<span className="block w-24 shrink-0">
|
||||
<NumberInput
|
||||
value={form.ipv6_count || 1}
|
||||
min={1}
|
||||
max={64}
|
||||
onChange={(value) => setForm({ ...form, ipv6_count: Math.max(1, Math.round(value || 1)) })}
|
||||
/>
|
||||
</span>
|
||||
)}
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div className="rounded-md border border-gray-200 bg-white px-3 py-2 text-sm">
|
||||
<div className="flex items-start justify-between gap-3">
|
||||
<label className="flex min-w-0 flex-1 items-start gap-3">
|
||||
<input
|
||||
type="checkbox"
|
||||
checked={natEnabled}
|
||||
onChange={(event) => {
|
||||
const checked = event.target.checked
|
||||
setForm({
|
||||
...form,
|
||||
assign_nat: checked,
|
||||
port_mapping_count: checked ? Math.max(2, form.port_mapping_count || 2) : 0,
|
||||
extra_ports: [],
|
||||
})
|
||||
}}
|
||||
className="mt-1"
|
||||
/>
|
||||
<span className="min-w-0">
|
||||
<span className="block font-medium text-gray-800">{networkText.publicNAT}</span>
|
||||
<span className="block text-xs text-gray-500">
|
||||
{natEnabled ? formatNATPortCount(natPortCount, language) : networkText.noNATPorts}
|
||||
</span>
|
||||
</span>
|
||||
</label>
|
||||
{natEnabled && (
|
||||
<span className="block w-24 shrink-0">
|
||||
<NumberInput
|
||||
value={natPortCount}
|
||||
min={2}
|
||||
max={64}
|
||||
onChange={(value) => setForm({ ...form, port_mapping_count: Math.max(2, value || 2), assign_nat: true })}
|
||||
/>
|
||||
</span>
|
||||
)}
|
||||
</div>
|
||||
{natEnabled && (
|
||||
<div className="mt-2 pl-6">
|
||||
<div className="flex flex-wrap gap-1.5">
|
||||
<span className="inline-flex px-2 py-1 bg-emerald-50 text-emerald-700 rounded text-xs font-mono">
|
||||
{isWindowsTemplate(form.template_id) ? 'RDP' : 'SSH'}: {sshPortPreview} -> {isWindowsTemplate(form.template_id) ? 3389 : 22}
|
||||
</span>
|
||||
{autoPorts.map((port) => (
|
||||
<span key={port} className="inline-flex px-2 py-1 bg-gray-100 text-gray-700 rounded text-xs font-mono">
|
||||
{port} -> {port}
|
||||
</span>
|
||||
))}
|
||||
</div>
|
||||
</div>
|
||||
)}
|
||||
</div>
|
||||
|
||||
<div className="grid grid-cols-2 gap-4">
|
||||
<Field label="vCPU">
|
||||
@@ -319,25 +541,6 @@ export default function CreateContainerModal({ isOpen, onClose, onSuccess, exist
|
||||
)}
|
||||
</div>
|
||||
|
||||
<Field label="NAT 端口映射数量">
|
||||
<NumberInput
|
||||
value={form.port_mapping_count}
|
||||
min={2}
|
||||
max={64}
|
||||
onChange={(value) => setForm({ ...form, port_mapping_count: Math.max(2, value || 2) })}
|
||||
/>
|
||||
<div className="mt-2 flex flex-wrap gap-1.5">
|
||||
<span className="inline-flex px-2 py-1 bg-emerald-50 text-emerald-700 rounded text-xs font-mono">
|
||||
{isWindowsTemplate(form.template_id) ? 'RDP' : 'SSH'}: {sshPortPreview} -> {isWindowsTemplate(form.template_id) ? 3389 : 22}
|
||||
</span>
|
||||
{autoPorts.map((port) => (
|
||||
<span key={port} className="inline-flex px-2 py-1 bg-gray-100 text-gray-700 rounded text-xs font-mono">
|
||||
{port} -> {port}
|
||||
</span>
|
||||
))}
|
||||
</div>
|
||||
</Field>
|
||||
|
||||
<Field label="子用户快照上限">
|
||||
<NumberInput
|
||||
value={form.snapshot_limit}
|
||||
@@ -475,15 +678,40 @@ function validateResourceInputs(form: CreateContainerRequest, maxVCPU: number, m
|
||||
|
||||
function normalizeCreateForm(form: CreateContainerRequest): CreateContainerRequest {
|
||||
const normalized = applyTemplateDefaults(form)
|
||||
const wantsNAT = normalized.assign_nat !== false
|
||||
const wantsIPv4 = !!normalized.assign_ipv4
|
||||
const wantsIPv6 = !!normalized.assign_ipv6
|
||||
const linuxTemplate = !isWindowsTemplate(normalized.template_id)
|
||||
const sshAuthMode = linuxTemplate ? (normalized.ssh_auth_mode || 'auto_password') : 'auto_password'
|
||||
return {
|
||||
...normalized,
|
||||
vcpu: normalized.virtualization === 'kvm' ? Math.round(normalized.vcpu) : normalizeLXCvCPU(normalized.vcpu),
|
||||
ram_mb: Math.round(normalized.ram_mb),
|
||||
disk_gb: Math.round(normalized.disk_gb),
|
||||
assign_nat: wantsNAT,
|
||||
port_mapping_count: wantsNAT ? clampInt(normalized.port_mapping_count, 2, 64, 2) : 0,
|
||||
assign_ipv4: wantsIPv4,
|
||||
ipv4_count: wantsIPv4 ? clampInt(normalized.ipv4_count || 1, 1, 64, 1) : 0,
|
||||
public_ipv4s: wantsIPv4 ? (normalized.public_ipv4s || []) : [],
|
||||
assign_ipv6: wantsIPv6,
|
||||
ipv6_count: wantsIPv6 ? clampInt(normalized.ipv6_count || 1, 1, 64, 1) : 0,
|
||||
ipv6_addresses: wantsIPv6 ? (normalized.ipv6_addresses || []) : [],
|
||||
ssh_auth_mode: sshAuthMode,
|
||||
ssh_password: linuxTemplate && sshAuthMode === 'password' ? (normalized.ssh_password || '').trim() : '',
|
||||
ssh_public_key: linuxTemplate && sshAuthMode === 'key' ? (normalized.ssh_public_key || '').trim() : '',
|
||||
snapshot_limit: clampInt(normalized.snapshot_limit, 1, undefined, 3),
|
||||
}
|
||||
}
|
||||
|
||||
function validateSSHAuthInputs(form: CreateContainerRequest) {
|
||||
if (isWindowsTemplate(form.template_id)) return ''
|
||||
const mode = form.ssh_auth_mode || 'auto_password'
|
||||
if (mode === 'password') return sshPasswordError((form.ssh_password || '').trim())
|
||||
if (mode === 'key') return sshPublicKeyError(form.ssh_public_key || '')
|
||||
if (mode !== 'auto_password') return '请选择登录方式'
|
||||
return ''
|
||||
}
|
||||
|
||||
function applyTemplateDefaults(form: CreateContainerRequest): CreateContainerRequest {
|
||||
if (!isWindowsTemplate(form.template_id)) return form
|
||||
return {
|
||||
@@ -509,5 +737,38 @@ function clampInt(value: number, min: number, max?: number, fallback = min) {
|
||||
return Math.min(Math.max(next, min), max ?? next)
|
||||
}
|
||||
|
||||
const createNetworkText = {
|
||||
zh: {
|
||||
publicIPv4: '公网 IPv4',
|
||||
noAllocatableIPv4: '未检测到可分配公网 IPv4',
|
||||
publicIPv6: '公网 IPv6',
|
||||
use: '使用',
|
||||
checkingIPv6Prefix: '正在检测 IPv6 前缀...',
|
||||
publicNAT: '公网 NAT',
|
||||
noNATPorts: '不分配 NAT 端口',
|
||||
},
|
||||
en: {
|
||||
publicIPv4: 'Public IPv4',
|
||||
noAllocatableIPv4: 'No allocatable public IPv4 detected',
|
||||
publicIPv6: 'Public IPv6',
|
||||
use: 'Use',
|
||||
checkingIPv6Prefix: 'Checking IPv6 prefix...',
|
||||
publicNAT: 'Public NAT',
|
||||
noNATPorts: 'No NAT ports will be assigned',
|
||||
},
|
||||
} as const
|
||||
|
||||
function formatAllocatableIPv4Count(count: number, language: Language) {
|
||||
return language === 'en'
|
||||
? `${count} allocatable address${count === 1 ? '' : 'es'} detected`
|
||||
: `检测到 ${count} 个可分配地址`
|
||||
}
|
||||
|
||||
function formatNATPortCount(count: number, language: Language) {
|
||||
return language === 'en'
|
||||
? `${count} NAT ports will be assigned`
|
||||
: `将分配 ${count} 个 NAT 端口`
|
||||
}
|
||||
|
||||
const inputClass =
|
||||
'w-full px-3 py-2 border border-gray-300 rounded-md text-sm text-black bg-white focus:outline-none focus:ring-2 focus:ring-black focus:border-black'
|
||||
|
||||
@@ -734,9 +734,17 @@ const requestBodySamples: Record<string, Record<string, unknown>> = {
|
||||
port_mapping_count: 2,
|
||||
snapshot_limit: 1,
|
||||
assign_ipv6: true,
|
||||
ssh_auth_mode: 'auto_password',
|
||||
ssh_password: '',
|
||||
ssh_public_key: '',
|
||||
expires_at: '',
|
||||
},
|
||||
'POST /api/v1/containers/{id}/reinstall': { template_id: 'debian-bookworm' },
|
||||
'POST /api/v1/containers/{id}/reinstall': {
|
||||
template_id: 'debian-bookworm',
|
||||
ssh_auth_mode: 'keep',
|
||||
ssh_password: '',
|
||||
ssh_public_key: '',
|
||||
},
|
||||
'PUT /api/v1/containers/{id}/traffic-limit': {
|
||||
traffic_mode: 'total',
|
||||
monthly_traffic_gb: 100,
|
||||
@@ -788,6 +796,8 @@ const requestBodySamples: Record<string, Record<string, unknown>> = {
|
||||
port_mapping_count: 2,
|
||||
snapshot_limit: 1,
|
||||
assign_ipv6: true,
|
||||
ssh_auth_mode: 'key',
|
||||
ssh_public_key: 'ssh-ed25519 AAAA... user@example',
|
||||
},
|
||||
],
|
||||
},
|
||||
|
||||
@@ -78,6 +78,7 @@ import ResourceStatsPanel, {
|
||||
StatsRangeKey,
|
||||
statsRanges,
|
||||
} from '../components/ResourceStatsPanel'
|
||||
import { generateSSHPassword, sshPasswordError, sshPublicKeyError, type ReinstallSSHAuthMode } from '../utils/sshAuth'
|
||||
|
||||
const PUBLIC_HOST = window.location.hostname
|
||||
const inputClass = 'w-full px-3 py-2 border border-gray-300 rounded-md text-sm text-black bg-white focus:outline-none focus:ring-2 focus:ring-black focus:border-black'
|
||||
@@ -93,6 +94,7 @@ type MappingDraft = {
|
||||
index: number | null
|
||||
description: string
|
||||
host_port: string
|
||||
host_ip: string
|
||||
container_port: string
|
||||
protocol: string
|
||||
}
|
||||
@@ -101,6 +103,7 @@ const emptyDraft: MappingDraft = {
|
||||
index: null,
|
||||
description: '',
|
||||
host_port: '',
|
||||
host_ip: '',
|
||||
container_port: '',
|
||||
protocol: 'all',
|
||||
}
|
||||
@@ -133,6 +136,9 @@ export default function ContainerDetail() {
|
||||
const [showReinstall, setShowReinstall] = useState(false)
|
||||
const [templates, setTemplates] = useState<Template[]>([])
|
||||
const [selectedTemplate, setSelectedTemplate] = useState('')
|
||||
const [reinstallAuthMode, setReinstallAuthMode] = useState<ReinstallSSHAuthMode>('keep')
|
||||
const [reinstallPasswordDraft, setReinstallPasswordDraft] = useState('')
|
||||
const [reinstallPublicKeyDraft, setReinstallPublicKeyDraft] = useState('')
|
||||
const [reinstalling, setReinstalling] = useState(false)
|
||||
const [traffic, setTraffic] = useState<TrafficInfo | null>(null)
|
||||
const [subUser, setSubUser] = useState<SubUser | null>(null)
|
||||
@@ -411,6 +417,9 @@ export default function ContainerDetail() {
|
||||
setTemplates(res.data.data)
|
||||
setSelectedTemplate(res.data.data[0]?.id || '')
|
||||
}
|
||||
setReinstallAuthMode('keep')
|
||||
setReinstallPasswordDraft('')
|
||||
setReinstallPublicKeyDraft('')
|
||||
setShowReinstall(true)
|
||||
} catch (err) {
|
||||
console.error(err)
|
||||
@@ -432,9 +441,28 @@ export default function ContainerDetail() {
|
||||
|
||||
const handleReinstall = async () => {
|
||||
if (!containerIdentifier || !selectedTemplate) return
|
||||
const linuxTemplate = !isWindowsTemplate(selectedTemplate)
|
||||
if (linuxTemplate && reinstallAuthMode === 'password') {
|
||||
const validationError = sshPasswordError(reinstallPasswordDraft.trim())
|
||||
if (validationError) {
|
||||
await dialog.alert('密码格式不正确', validationError)
|
||||
return
|
||||
}
|
||||
}
|
||||
if (linuxTemplate && reinstallAuthMode === 'key') {
|
||||
const validationError = sshPublicKeyError(reinstallPublicKeyDraft)
|
||||
if (validationError) {
|
||||
await dialog.alert('SSH Key 格式不正确', validationError)
|
||||
return
|
||||
}
|
||||
}
|
||||
setReinstalling(true)
|
||||
try {
|
||||
await reinstallContainer(containerIdentifier, selectedTemplate)
|
||||
await reinstallContainer(containerIdentifier, selectedTemplate, linuxTemplate ? {
|
||||
ssh_auth_mode: reinstallAuthMode,
|
||||
ssh_password: reinstallAuthMode === 'password' ? reinstallPasswordDraft.trim() : '',
|
||||
ssh_public_key: reinstallAuthMode === 'key' ? reinstallPublicKeyDraft.trim() : '',
|
||||
} : undefined)
|
||||
setShowReinstall(false)
|
||||
setShowSSH(false)
|
||||
setShowVNC(false)
|
||||
@@ -448,23 +476,12 @@ export default function ContainerDetail() {
|
||||
}
|
||||
|
||||
const generateResetPassword = () => {
|
||||
const letters = 'ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz'
|
||||
const digits = '23456789'
|
||||
const symbols = '!@#$%*-_+='
|
||||
const all = letters + digits + symbols
|
||||
const pick = (chars: string) => chars[secureRandomInt(chars.length)]
|
||||
let password = pick(letters) + pick(digits)
|
||||
while (password.length < 16) password += pick(all)
|
||||
setResetPasswordDraft(secureShuffle(password.split('')).join(''))
|
||||
setResetPasswordDraft(generateSSHPassword())
|
||||
setResetPasswordResult('')
|
||||
}
|
||||
|
||||
const resetPasswordError = (password: string) => {
|
||||
if (password.length < 8 || password.length > 64) return '密码长度必须为 8-64 位'
|
||||
if (/\s/.test(password)) return '密码不能包含空白字符'
|
||||
if (!/[A-Za-z]/.test(password)) return '密码至少需要包含字母'
|
||||
if (!/\d/.test(password)) return '密码至少需要包含数字'
|
||||
return ''
|
||||
return sshPasswordError(password)
|
||||
}
|
||||
|
||||
const handleResetPassword = async () => {
|
||||
@@ -526,6 +543,7 @@ export default function ContainerDetail() {
|
||||
index,
|
||||
description: pm.description,
|
||||
host_port: String(pm.host_port),
|
||||
host_ip: pm.host_ip || '',
|
||||
container_port: String(pm.container_port),
|
||||
protocol: pm.protocol || 'all',
|
||||
})
|
||||
@@ -538,7 +556,11 @@ export default function ContainerDetail() {
|
||||
if (!(await ensureSubUserCanOperate())) return false
|
||||
if (draft.index === null && container) {
|
||||
const currentCount = container.port_mappings?.length || 0
|
||||
const limit = container.port_mapping_limit || Math.max(currentCount, 2)
|
||||
const limit = Math.max(container.port_mapping_limit || 0, currentCount)
|
||||
if (limit <= 0) {
|
||||
dialog.alert('未分配 IPv4 NAT', '该容器未分配 IPv4 NAT 端口配额。')
|
||||
return false
|
||||
}
|
||||
if (currentCount >= limit) {
|
||||
dialog.alert('端口配额已满', '已达到管理员分配的 NAT 端口配额。')
|
||||
return false
|
||||
@@ -563,6 +585,7 @@ export default function ContainerDetail() {
|
||||
const payload: PortMapping = {
|
||||
container_port: containerPort,
|
||||
host_port: hostPortVal,
|
||||
host_ip: isSubUser ? undefined : (draft.host_ip || undefined),
|
||||
protocol: protocolVal,
|
||||
description: draft.description.trim() || `Port-${containerPort}`,
|
||||
}
|
||||
@@ -732,15 +755,23 @@ export default function ContainerDetail() {
|
||||
const isRunning = container.status === 'running'
|
||||
const isKVM = (container.virtualization || 'lxc') === 'kvm'
|
||||
const isWindows = container.template?.includes('windows')
|
||||
const reinstallLinuxTemplate = !isWindowsTemplate(selectedTemplate)
|
||||
const canOpenVNC = isKVM && isRunning
|
||||
const isExpired = container.expires_at ? new Date(container.expires_at) < new Date() : false
|
||||
const isPolicyBlocked = !!container.policy_blocked
|
||||
const isSubUserPolicyBlocked = isSubUser && isPolicyBlocked
|
||||
const policyBlockedText = container.policy_blocked_reason || '虚拟机被策略临时封禁'
|
||||
const publicHost = hostInfo?.network.public_ipv4 || PUBLIC_HOST
|
||||
const publicIPv4s = container.public_ipv4s || []
|
||||
const assignedIPv4List = publicIPv4s.map((item) => item.address).filter(Boolean)
|
||||
const publicHost = assignedIPv4List[0] || hostInfo?.network.public_ipv4 || PUBLIC_HOST
|
||||
const ipv6List = (container.ipv6_addresses || [])
|
||||
.map((item) => item.address)
|
||||
.filter(Boolean)
|
||||
if (ipv6List.length === 0 && container.ipv6) ipv6List.push(container.ipv6)
|
||||
const maxVCPU = hostInfo?.cpu.cores || 64
|
||||
const maxRAMMB = hostInfo?.ram.total_mb ? Number(hostInfo.ram.total_mb) : undefined
|
||||
const sshCommand = `ssh -p ${container.ssh_port} root@${publicHost}`
|
||||
const publicEndpoint = container.ssh_port > 0 ? `${publicHost}:${container.ssh_port}` : '-'
|
||||
const sshCommand = container.ssh_port > 0 ? `ssh -p ${container.ssh_port} root@${publicHost}` : ''
|
||||
const editingSSH = draft.index !== null && !!container.port_mappings?.[draft.index] && (
|
||||
container.port_mappings[draft.index].description === 'SSH' || container.port_mappings[draft.index].container_port === 22 ||
|
||||
container.port_mappings[draft.index].description === 'RDP' || container.port_mappings[draft.index].container_port === 3389
|
||||
@@ -758,8 +789,9 @@ export default function ContainerDetail() {
|
||||
const netPct = Math.min(((usage?.network_rx_bps || 0) + (usage?.network_tx_bps || 0)) / (container.network_bw_mbps > 0 ? container.network_bw_mbps * 125000 : 125000000) * 100, 100)
|
||||
const diskIOBps = (usage?.disk_read_bps || 0) + (usage?.disk_write_bps || 0)
|
||||
const mappingCount = container.port_mappings?.length || 0
|
||||
const mappingLimit = container.port_mapping_limit || Math.max(mappingCount, 2)
|
||||
const canAddMapping = isSubUser ? mappingCount < mappingLimit && !isSubUserPolicyBlocked : true
|
||||
const mappingLimit = Math.max(container.port_mapping_limit || 0, mappingCount)
|
||||
const hasNATQuota = mappingLimit > 0
|
||||
const canAddMapping = hasNATQuota && mappingCount < mappingLimit && !isSubUserPolicyBlocked
|
||||
const managementUrl = subUser?.access_code
|
||||
? `${window.location.origin}/login?code=${encodeURIComponent(subUser.access_code)}`
|
||||
: ''
|
||||
@@ -828,8 +860,8 @@ export default function ContainerDetail() {
|
||||
<InfoTag color="blue">系统 {container.template}</InfoTag>
|
||||
<InfoTag color="slate">类型 {(container.virtualization || 'lxc').toUpperCase()}</InfoTag>
|
||||
<InfoTag color="emerald">内网 {container.ip || '-'}</InfoTag>
|
||||
<InfoTag color="amber">NAT {mappingCount} 条</InfoTag>
|
||||
<InfoTag color="violet">{isWindows ? 'RDP' : 'SSH'} {publicHost}:{container.ssh_port}</InfoTag>
|
||||
<InfoTag color="amber">IPv4 NAT {hasNATQuota ? `${mappingCount} 条` : '未分配'}</InfoTag>
|
||||
<InfoTag color="violet">{isWindows ? 'RDP' : 'SSH'} {publicEndpoint}</InfoTag>
|
||||
{isPolicyBlocked && <InfoTag color="red">策略封禁</InfoTag>}
|
||||
</div>
|
||||
</div>
|
||||
@@ -874,7 +906,7 @@ export default function ContainerDetail() {
|
||||
<>
|
||||
<ActionButton disabled={isSubUserPolicyBlocked} onClick={() => setShowNat(true)}>
|
||||
<Settings className="w-3.5 h-3.5" />
|
||||
NAT 管理
|
||||
IPv4 NAT 管理
|
||||
</ActionButton>
|
||||
</>
|
||||
<ActionButton onClick={() => setShowSnapshots(true)} disabled={!!taskStatus || !!snapshotBusy || isSubUserPolicyBlocked}>
|
||||
@@ -926,7 +958,7 @@ export default function ContainerDetail() {
|
||||
</div>
|
||||
) : isWindows ? (
|
||||
<>
|
||||
<PlainRow label="RDP 地址" value={`${publicHost}:${container.ssh_port}`} mono />
|
||||
<PlainRow label="RDP 地址" value={publicEndpoint} mono />
|
||||
<PlainRow label="用户名" value="Administrator" mono />
|
||||
<div className="flex items-center justify-between gap-3">
|
||||
<span className="text-gray-500">管理员密码</span>
|
||||
@@ -951,7 +983,7 @@ export default function ContainerDetail() {
|
||||
</>
|
||||
) : (
|
||||
<>
|
||||
<PlainRow label="SSH 地址" value={`${publicHost}:${container.ssh_port}`} mono copyValue={sshCommand} onCopy={copyText} />
|
||||
<PlainRow label="SSH 地址" value={publicEndpoint} mono copyValue={sshCommand} onCopy={copyText} />
|
||||
<PlainRow label="用户名" value="root" mono />
|
||||
<div className="flex items-center justify-between gap-3">
|
||||
<span className="text-gray-500">SSH 密码</span>
|
||||
@@ -993,8 +1025,9 @@ export default function ContainerDetail() {
|
||||
<PlainRow label="识别码" value={container.uuid || '-'} mono copyValue={container.uuid} onCopy={copyText} />
|
||||
<PlainRow label="状态" value={isRunning ? '运行中' : '已停止'} />
|
||||
<PlainRow label="内网 IP" value={container.ip || '-'} mono />
|
||||
<PlainRow label="IPv6" value={container.ipv6 || '-'} mono copyValue={container.ipv6} onCopy={copyText}>
|
||||
{!isSubUser && !container.ipv6 && (
|
||||
<PlainRow label="Public IPv4" value={assignedIPv4List.length ? assignedIPv4List.join(', ') : '-'} mono copyValue={assignedIPv4List[0]} onCopy={copyText} />
|
||||
<PlainRow label="IPv6" value={ipv6List.length ? ipv6List.join(', ') : '-'} mono copyValue={ipv6List[0]} onCopy={copyText}>
|
||||
{!isSubUser && ipv6List.length === 0 && (
|
||||
<button onClick={handleAssignIPv6} disabled={actionLoading === 'ipv6'} className="ml-1 px-1.5 py-0.5 text-[10px] text-gray-600 border border-gray-200 rounded hover:bg-gray-50 disabled:opacity-50">
|
||||
Assign
|
||||
</button>
|
||||
@@ -1386,7 +1419,7 @@ export default function ContainerDetail() {
|
||||
)}
|
||||
|
||||
{showNat && (
|
||||
<Modal title="NAT 端口管理" onClose={() => { setShowNat(false); setDraft(emptyDraft); setShowMappingEditor(false) }} wide extra={
|
||||
<Modal title="IPv4 NAT 端口管理" onClose={() => { setShowNat(false); setDraft(emptyDraft); setShowMappingEditor(false) }} wide extra={
|
||||
!isSubUser && canAddMapping && (
|
||||
<button onClick={openAddMapping} className="inline-flex items-center gap-1.5 px-3 py-1.5 bg-black text-white rounded-md text-xs hover:bg-gray-800">
|
||||
<Plus className="w-3.5 h-3.5" />添加映射
|
||||
@@ -1396,10 +1429,14 @@ export default function ContainerDetail() {
|
||||
<div className="space-y-5">
|
||||
<div className="flex items-center justify-between gap-4">
|
||||
<div className="text-xs text-gray-500">
|
||||
端口配额:<span className="font-mono text-gray-800">{mappingCount}/{mappingLimit}</span>
|
||||
{hasNATQuota ? (
|
||||
<>端口配额:<span className="font-mono text-gray-800">{mappingCount}/{mappingLimit}</span></>
|
||||
) : (
|
||||
<span>未分配 IPv4 NAT 端口配额</span>
|
||||
)}
|
||||
</div>
|
||||
{!isSubUser && !canAddMapping && (
|
||||
<div className="text-xs text-amber-600">已达到管理员分配的 NAT 端口配额</div>
|
||||
{!isSubUser && hasNATQuota && !canAddMapping && (
|
||||
<div className="text-xs text-amber-600">已达到管理员分配的 IPv4 NAT 端口配额</div>
|
||||
)}
|
||||
</div>
|
||||
<MappingTable mappings={container.port_mappings || []} publicHost={publicHost} onEdit={openEditMapping} onDelete={isSubUser ? () => {} : removeMapping} isSubUser={isSubUser} />
|
||||
@@ -1419,6 +1456,7 @@ export default function ContainerDetail() {
|
||||
canAddMapping={canAddMapping}
|
||||
saving={savingMapping}
|
||||
containerIdentifier={containerIdentifier}
|
||||
publicIPv4s={publicIPv4s}
|
||||
onCancel={() => { setShowMappingEditor(false); setDraft(emptyDraft) }}
|
||||
onSubmit={async () => {
|
||||
if (await submitMapping()) {
|
||||
@@ -1462,6 +1500,55 @@ export default function ContainerDetail() {
|
||||
))}
|
||||
</select>
|
||||
</Field>
|
||||
{reinstallLinuxTemplate && (
|
||||
<div className="rounded-md border border-gray-200 bg-white px-3 py-3 text-sm">
|
||||
<div className="mb-2 font-medium text-gray-800">登录方式</div>
|
||||
<div className="grid grid-cols-2 gap-2 sm:grid-cols-4">
|
||||
{([
|
||||
['keep', '保留当前密码'],
|
||||
['auto_password', '生成新密码'],
|
||||
['password', '自定义密码'],
|
||||
['key', 'SSH Key'],
|
||||
] as Array<[ReinstallSSHAuthMode, string]>).map(([mode, label]) => (
|
||||
<button
|
||||
key={mode}
|
||||
type="button"
|
||||
onClick={() => setReinstallAuthMode(mode)}
|
||||
className={`rounded-md border px-3 py-2 text-xs font-medium transition-colors ${reinstallAuthMode === mode ? 'border-black bg-black text-white' : 'border-gray-300 text-gray-700 hover:bg-gray-50'}`}
|
||||
>
|
||||
{label}
|
||||
</button>
|
||||
))}
|
||||
</div>
|
||||
{reinstallAuthMode === 'password' && (
|
||||
<div className="mt-3 flex gap-2">
|
||||
<input
|
||||
type="text"
|
||||
value={reinstallPasswordDraft}
|
||||
onChange={(event) => setReinstallPasswordDraft(event.target.value)}
|
||||
className={inputClass}
|
||||
placeholder="RootPass123"
|
||||
/>
|
||||
<button
|
||||
type="button"
|
||||
onClick={() => setReinstallPasswordDraft(generateSSHPassword())}
|
||||
className="inline-flex h-10 w-10 shrink-0 items-center justify-center rounded-md border border-gray-300 text-gray-600 hover:bg-gray-50"
|
||||
title="生成密码"
|
||||
>
|
||||
<RefreshCw className="h-4 w-4" />
|
||||
</button>
|
||||
</div>
|
||||
)}
|
||||
{reinstallAuthMode === 'key' && (
|
||||
<textarea
|
||||
value={reinstallPublicKeyDraft}
|
||||
onChange={(event) => setReinstallPublicKeyDraft(event.target.value)}
|
||||
className={`${inputClass} mt-3 min-h-20 resize-y font-mono text-xs`}
|
||||
placeholder="ssh-ed25519 AAAA..."
|
||||
/>
|
||||
)}
|
||||
</div>
|
||||
)}
|
||||
<div className="flex justify-end gap-3">
|
||||
<button onClick={() => setShowReinstall(false)} className="px-4 py-2 text-sm text-gray-700 hover:bg-gray-100 rounded-md">取消</button>
|
||||
<button onClick={handleReinstall} disabled={reinstalling} className="px-4 py-2 text-sm bg-black text-white rounded-md hover:bg-gray-800 disabled:opacity-50">
|
||||
@@ -1739,6 +1826,7 @@ function MappingEditor({
|
||||
canAddMapping,
|
||||
saving,
|
||||
containerIdentifier,
|
||||
publicIPv4s,
|
||||
onCancel,
|
||||
onSubmit,
|
||||
}: {
|
||||
@@ -1748,6 +1836,7 @@ function MappingEditor({
|
||||
canAddMapping: boolean
|
||||
saving: boolean
|
||||
containerIdentifier: string
|
||||
publicIPv4s: { address: string; interface?: string }[]
|
||||
onCancel: () => void
|
||||
onSubmit: () => void
|
||||
}) {
|
||||
@@ -1757,7 +1846,8 @@ function MappingEditor({
|
||||
|
||||
const fillRandomPort = async () => {
|
||||
try {
|
||||
const res = await api.get<APIResponse<{ port: number }>>(`/containers/${containerIdentifier}/random-port`)
|
||||
const params = draft.host_ip ? { host_ip: draft.host_ip } : undefined
|
||||
const res = await api.get<APIResponse<{ port: number }>>(`/containers/${containerIdentifier}/random-port`, { params })
|
||||
const port = res.data.data?.port || 0
|
||||
if (port > 0) updateDraft({ host_port: String(port) })
|
||||
} catch {
|
||||
@@ -1815,6 +1905,21 @@ function MappingEditor({
|
||||
)}
|
||||
</Field>
|
||||
|
||||
<Field label="Host IPv4">
|
||||
{isSubUser ? (
|
||||
<input value={draft.host_ip || 'All IPv4'} disabled className={disabledInputClass} />
|
||||
) : (
|
||||
<select value={draft.host_ip} onChange={(e) => updateDraft({ host_ip: e.target.value })} className={inputClass}>
|
||||
<option value="">All assigned IPv4</option>
|
||||
{publicIPv4s.map((ip) => (
|
||||
<option key={`${ip.interface}-${ip.address}`} value={ip.address}>
|
||||
{ip.address}{ip.interface ? ` (${ip.interface})` : ''}
|
||||
</option>
|
||||
))}
|
||||
</select>
|
||||
)}
|
||||
</Field>
|
||||
|
||||
<Field label="内部端口">
|
||||
<input
|
||||
value={draft.container_port}
|
||||
@@ -1854,6 +1959,7 @@ function MappingTable({ mappings, publicHost, onEdit, onDelete, compact = false,
|
||||
<tr>
|
||||
<TableHead>名称</TableHead>
|
||||
<TableHead>协议</TableHead>
|
||||
<TableHead>Host IPv4</TableHead>
|
||||
<TableHead>外部端口</TableHead>
|
||||
<TableHead>内部端口</TableHead>
|
||||
{!compact && <th className="text-right px-3 py-2 text-xs font-medium text-gray-500">操作</th>}
|
||||
@@ -1869,7 +1975,8 @@ function MappingTable({ mappings, publicHost, onEdit, onDelete, compact = false,
|
||||
{isSSH && <span className="ml-2 px-1.5 py-0.5 rounded bg-emerald-50 text-emerald-700 text-xs">默认</span>}
|
||||
</td>
|
||||
<td className="px-3 py-2 text-xs text-gray-500">{pm.protocol.toUpperCase()}</td>
|
||||
<td className="px-3 py-2 font-mono text-xs text-gray-800">{publicHost}:{pm.host_port}</td>
|
||||
<td className="px-3 py-2 font-mono text-xs text-gray-800">{pm.host_ip || publicHost || 'All IPv4'}</td>
|
||||
<td className="px-3 py-2 font-mono text-xs text-gray-800">{pm.host_port}</td>
|
||||
<td className="px-3 py-2 font-mono text-xs text-gray-800">{pm.container_port}</td>
|
||||
{!compact && (
|
||||
<td className="px-3 py-2">
|
||||
@@ -2093,30 +2200,8 @@ function TrafficBar({ container }: { container: Container }) {
|
||||
)
|
||||
}
|
||||
|
||||
function secureRandomInt(maxExclusive: number) {
|
||||
if (!Number.isSafeInteger(maxExclusive) || maxExclusive <= 0) {
|
||||
throw new Error('invalid random range')
|
||||
}
|
||||
const values = new Uint32Array(1)
|
||||
const maxUint32 = 0x100000000
|
||||
const limit = Math.floor(maxUint32 / maxExclusive) * maxExclusive
|
||||
let value = 0
|
||||
do {
|
||||
crypto.getRandomValues(values)
|
||||
value = values[0]
|
||||
} while (value >= limit)
|
||||
return value % maxExclusive
|
||||
}
|
||||
|
||||
function secureShuffle<T>(items: T[]) {
|
||||
const next = [...items]
|
||||
for (let i = next.length - 1; i > 0; i--) {
|
||||
const j = secureRandomInt(i + 1)
|
||||
const value = next[i]
|
||||
next[i] = next[j]
|
||||
next[j] = value
|
||||
}
|
||||
return next
|
||||
function isWindowsTemplate(templateID: string) {
|
||||
return templateID.toLowerCase().includes('windows')
|
||||
}
|
||||
|
||||
function getTemplateIcon(id: string): ReactNode {
|
||||
|
||||
@@ -704,14 +704,16 @@ function toPlaceholder(cfg: CreateContainerRequest): DisplayContainer {
|
||||
io_speed_mbps: cfg.io_speed_mbps,
|
||||
status: 'creating',
|
||||
ip: '',
|
||||
public_ipv4s: [],
|
||||
ipv6: '',
|
||||
ipv6_prefix_len: 0,
|
||||
ipv6_interface: '',
|
||||
ipv6_addresses: [],
|
||||
vnc_port: 0,
|
||||
ssh_port: 0,
|
||||
ssh_password: '',
|
||||
port_mappings: [],
|
||||
port_mapping_limit: 2,
|
||||
port_mapping_limit: cfg.assign_nat === false ? 0 : (cfg.port_mapping_count || 0),
|
||||
snapshot_limit: cfg.snapshot_limit || 3,
|
||||
created_at: '',
|
||||
expires_at: cfg.expires_at,
|
||||
|
||||
@@ -9,8 +9,12 @@ import {
|
||||
XCircle,
|
||||
} from 'lucide-react'
|
||||
import { getHostReport, HostProbeReport } from '../services/api'
|
||||
import { useLanguage, type Language } from '../contexts/LanguageContext'
|
||||
import { translateText } from '../utils/i18n'
|
||||
|
||||
export default function HostReport() {
|
||||
const { language } = useLanguage()
|
||||
const text = hostReportText[language]
|
||||
const [report, setReport] = useState<HostProbeReport | null>(null)
|
||||
const [loading, setLoading] = useState(true)
|
||||
|
||||
@@ -31,61 +35,61 @@ export default function HostReport() {
|
||||
}, [fetchReport])
|
||||
|
||||
return (
|
||||
<div className="space-y-6">
|
||||
<div className="space-y-6" data-no-translate>
|
||||
<div className="flex flex-wrap items-start justify-between gap-3">
|
||||
<div>
|
||||
<h1 className="text-2xl font-bold text-black">宿主机信息</h1>
|
||||
<p className="mt-1 text-sm text-gray-500">硬件、网络、磁盘健康与运行环境探测报告</p>
|
||||
<h1 className="text-2xl font-bold text-black">{text.title}</h1>
|
||||
<p className="mt-1 text-sm text-gray-500">{text.subtitle}</p>
|
||||
</div>
|
||||
<button onClick={fetchReport} disabled={loading} className="inline-flex items-center gap-1.5 rounded-md border border-gray-200 px-3 py-2 text-sm text-gray-600 hover:bg-gray-50 disabled:opacity-50">
|
||||
<RefreshCw className={`h-4 w-4 ${loading ? 'animate-spin' : ''}`} />
|
||||
刷新
|
||||
{text.refresh}
|
||||
</button>
|
||||
</div>
|
||||
|
||||
{loading && !report ? (
|
||||
<div className="rounded-lg border border-gray-200 bg-white py-14 text-center text-sm text-gray-400">正在探测宿主机环境...</div>
|
||||
<div className="rounded-lg border border-gray-200 bg-white py-14 text-center text-sm text-gray-400">{text.loading}</div>
|
||||
) : !report ? (
|
||||
<div className="rounded-lg border border-gray-200 bg-white py-14 text-center text-sm text-gray-400">暂未获取到宿主机信息</div>
|
||||
<div className="rounded-lg border border-gray-200 bg-white py-14 text-center text-sm text-gray-400">{text.emptyReport}</div>
|
||||
) : (
|
||||
<div className="space-y-5">
|
||||
<div className="grid gap-3 md:grid-cols-2 xl:grid-cols-4">
|
||||
<ProbeMetric icon={<Cpu className="h-4 w-4" />} label="CPU" value={report.cpu.model || 'Unknown'} sub={`${report.cpu.cores} 核 / ${report.cpu.threads} 线程`} />
|
||||
<ProbeMetric icon={<MemoryStick className="h-4 w-4" />} label="RAM" value={formatMB(report.memory.total_mb)} sub={`${formatMB(report.memory.used_mb)} 已用`} />
|
||||
<ProbeMetric icon={<HardDrive className="h-4 w-4" />} label="DISK" value={`${report.disks.length} 块硬盘`} sub={report.disks.map(d => d.type).filter(Boolean).join(' / ') || 'Unknown'} />
|
||||
<ProbeMetric icon={<Activity className="h-4 w-4" />} label="运行状态" value={report.system.uptime_text} sub={`${report.system.process_count} 个进程`} />
|
||||
<ProbeMetric icon={<Cpu className="h-4 w-4" />} label="CPU" value={report.cpu.model || 'Unknown'} sub={formatCPUThreads(report.cpu.cores, report.cpu.threads, language)} />
|
||||
<ProbeMetric icon={<MemoryStick className="h-4 w-4" />} label="RAM" value={formatMB(report.memory.total_mb)} sub={formatUsedMemory(report.memory.used_mb, language)} />
|
||||
<ProbeMetric icon={<HardDrive className="h-4 w-4" />} label="DISK" value={formatDiskCount(report.disks.length, language)} sub={report.disks.map(d => diskTypeLabel(d, language)).filter(Boolean).join(' / ') || 'Unknown'} />
|
||||
<ProbeMetric icon={<Activity className="h-4 w-4" />} label={text.runtimeStatus} value={translateDynamic(report.system.uptime_text, language)} sub={formatProcessCount(report.system.process_count, language)} />
|
||||
</div>
|
||||
|
||||
<ProbeSection title="系统概览">
|
||||
<ProbeSection title={text.systemOverview}>
|
||||
<ProbeRows rows={[
|
||||
['主机名', report.hostname],
|
||||
['操作系统', report.os],
|
||||
['内核', report.kernel],
|
||||
['生成时间', report.generated_at],
|
||||
['CPU 架构', report.cpu.architecture],
|
||||
['CPU 虚拟化指令', report.cpu.virtualization ? `支持 (${report.cpu.virtualization_key})` : '未检测到'],
|
||||
['CPU 核显', report.cpu.has_integrated_gpu ? '检测到' : '未检测到'],
|
||||
['显卡', report.gpus.length ? `${report.gpus.length} 个` : '未检测到'],
|
||||
['运行能力', runtimeModeLabel(report.runtime.support_mode)],
|
||||
['KVM 嵌套虚拟化', `${report.runtime.nested_virtualization ? '支持' : '未检测到'} (${report.runtime.nested_detail || '-'})`],
|
||||
[text.hostname, report.hostname],
|
||||
[text.os, report.os],
|
||||
[text.kernel, report.kernel],
|
||||
[text.generatedAt, report.generated_at],
|
||||
[text.cpuArch, report.cpu.architecture],
|
||||
[text.cpuVirtualization, report.cpu.virtualization ? `${text.supported} (${report.cpu.virtualization_key})` : text.notDetected],
|
||||
[text.cpuIntegratedGPU, report.cpu.has_integrated_gpu ? text.detected : text.notDetected],
|
||||
[text.gpu, report.gpus.length ? formatItemCount(report.gpus.length, language) : text.notDetected],
|
||||
[text.runtimeCapability, runtimeModeLabel(report.runtime.support_mode, language)],
|
||||
[text.kvmNested, `${report.runtime.nested_virtualization ? text.supported : text.notDetected} (${translateDynamic(report.runtime.nested_detail || '-', language)})`],
|
||||
]} />
|
||||
</ProbeSection>
|
||||
|
||||
<ProbeSection title="公网与路由">
|
||||
<ProbeSection title={text.publicNetwork}>
|
||||
<ProbeRows rows={[
|
||||
['公网 IPv4', report.public_ipv4.length ? report.public_ipv4.join('\n') : '未检测到'],
|
||||
['IPv4 地址', report.ipv4_addresses?.length ? report.ipv4_addresses.map(formatIPv4Address).join('\n') : '未检测到'],
|
||||
['IPv4 段', report.ipv4_prefixes?.length ? report.ipv4_prefixes.map(formatIPv4Prefix).join('\n') : '未检测到'],
|
||||
['IPv6 地址', report.ipv6_addresses.length ? report.ipv6_addresses.map(ip => `${ip.address}/${ip.prefix_len} (${ip.interface})`).join('\n') : '未检测到'],
|
||||
['IPv6 段', report.ipv6_prefixes?.length ? report.ipv6_prefixes.map(formatIPv6Prefix).join('\n') : '未检测到'],
|
||||
['网关', report.gateways.length ? report.gateways.map(g => `${g.family}: ${g.gateway || '-'} dev ${g.interface || '-'}`).join('\n') : '未检测到'],
|
||||
[text.publicIPv4, report.public_ipv4.length ? report.public_ipv4.join('\n') : text.notDetected],
|
||||
[text.ipv4Address, report.ipv4_addresses?.length ? report.ipv4_addresses.map(formatIPv4Address).join('\n') : text.notDetected],
|
||||
[text.ipv4Prefix, report.ipv4_prefixes?.length ? report.ipv4_prefixes.map(formatIPv4Prefix).join('\n') : text.notDetected],
|
||||
[text.ipv6Address, report.ipv6_addresses.length ? report.ipv6_addresses.map(ip => `${ip.address}/${ip.prefix_len} (${ip.interface})`).join('\n') : text.notDetected],
|
||||
[text.ipv6Prefix, report.ipv6_prefixes?.length ? report.ipv6_prefixes.map(formatIPv6Prefix).join('\n') : text.notDetected],
|
||||
[text.gateway, report.gateways.length ? report.gateways.map(g => `${g.family}: ${g.gateway || '-'} dev ${g.interface || '-'}`).join('\n') : text.notDetected],
|
||||
]} />
|
||||
</ProbeSection>
|
||||
|
||||
<ProbeTable
|
||||
title="内存条"
|
||||
empty="未检测到内存条明细,可能缺少 dmidecode 或权限受限"
|
||||
headers={['插槽', '容量', '类型', '频率', '厂商', '型号/序列号']}
|
||||
title={text.memoryModules}
|
||||
empty={text.noMemoryModules}
|
||||
headers={[text.slot, text.capacity, text.type, text.frequency, text.vendor, text.modelSerial]}
|
||||
rows={(report.memory.modules || []).map(m => [
|
||||
m.locator || '-',
|
||||
m.size || '-',
|
||||
@@ -97,29 +101,29 @@ export default function HostReport() {
|
||||
/>
|
||||
|
||||
<ProbeTable
|
||||
title="硬盘与健康"
|
||||
empty="未检测到硬盘"
|
||||
headers={['设备', '型号', '容量', '类型', '挂载点', '健康', '寿命', '通电', '读取', '写入', '命令数', '擦写']}
|
||||
title={text.disksHealth}
|
||||
empty={text.noDisks}
|
||||
headers={[text.device, text.model, text.capacity, text.type, text.mountPoint, text.health, text.lifetime, text.powerOn, text.reads, text.writes, text.commands, text.eraseCount]}
|
||||
rows={report.disks.map(d => [
|
||||
`${d.path || d.name}\n${d.serial || ''}`,
|
||||
d.model || '-',
|
||||
formatBytes(d.size_bytes),
|
||||
d.type || (d.rotational ? 'HDD' : 'SSD'),
|
||||
diskTypeLabel(d, language),
|
||||
d.mountpoints?.length ? d.mountpoints.join('\n') : '-',
|
||||
`${diskHealthLabel(d.health)}\n${d.health_detail || ''}`,
|
||||
formatLifeUsed(d.smart?.life_used_percent),
|
||||
d.smart?.power_on_hours ? `${d.smart.power_on_hours} 小时\n${formatPowerOnDays(d.smart.power_on_hours)}` : '-',
|
||||
formatBytes(d.smart?.read_data_bytes || 0),
|
||||
formatBytes(d.smart?.written_data_bytes || 0),
|
||||
formatCommands(d.smart?.read_commands, d.smart?.write_commands),
|
||||
formatWear(d.smart?.wear_leveling_count, d.smart?.erase_count, d.smart?.power_cycle_count),
|
||||
`${diskHealthLabel(d.health, language)}\n${diskHealthDetail(d, language)}`,
|
||||
d.virtual ? text.unsupported : formatLifeUsed(d.smart?.life_used_percent, language),
|
||||
d.virtual ? text.unsupported : (d.smart?.power_on_hours ? `${d.smart.power_on_hours} ${text.hours}\n${formatPowerOnDays(d.smart.power_on_hours, language)}` : '-'),
|
||||
d.virtual ? text.unsupported : formatBytes(d.smart?.read_data_bytes || 0),
|
||||
d.virtual ? text.unsupported : formatBytes(d.smart?.written_data_bytes || 0),
|
||||
d.virtual ? text.unsupported : formatCommands(d.smart?.read_commands, d.smart?.write_commands, language),
|
||||
d.virtual ? text.unsupported : formatWear(d.smart?.wear_leveling_count, d.smart?.erase_count, d.smart?.power_cycle_count, language),
|
||||
])}
|
||||
/>
|
||||
|
||||
<ProbeTable
|
||||
title="网卡"
|
||||
empty="未检测到网卡"
|
||||
headers={['网卡', '状态', '驱动/速率', 'MAC', 'IPv4', 'IPv6']}
|
||||
title={text.networkInterfaces}
|
||||
empty={text.noNetworkInterfaces}
|
||||
headers={[text.nic, text.status, text.driverSpeed, 'MAC', 'IPv4', 'IPv6']}
|
||||
rows={report.network_interfaces.map(n => [
|
||||
`${n.name}\n${n.model || ''}`,
|
||||
n.state || '-',
|
||||
@@ -131,25 +135,25 @@ export default function HostReport() {
|
||||
/>
|
||||
|
||||
<ProbeTable
|
||||
title="显卡"
|
||||
empty="未检测到显卡"
|
||||
headers={['名称', '厂商', '类型', '驱动']}
|
||||
rows={report.gpus.map(g => [g.name, g.vendor || '-', gpuTypeLabel(g.type), g.driver || '-'])}
|
||||
title={text.gpus}
|
||||
empty={text.noGPUs}
|
||||
headers={[text.name, text.vendor, text.type, text.driver]}
|
||||
rows={report.gpus.map(g => [g.name, g.vendor || '-', gpuTypeLabel(g.type, language), g.driver || '-'])}
|
||||
/>
|
||||
|
||||
<ProbeSection title="环境支持">
|
||||
<ProbeSection title={text.environmentSupport}>
|
||||
<div className="grid gap-2 md:grid-cols-2">
|
||||
{report.environment.map(item => (
|
||||
<div key={item.key} className="flex items-start gap-2 rounded-lg border border-gray-200 bg-white px-3 py-2">
|
||||
{item.ok ? <CheckCircle2 className="mt-0.5 h-4 w-4 shrink-0 text-green-600" /> : <XCircle className={`mt-0.5 h-4 w-4 shrink-0 ${item.required ? 'text-red-600' : 'text-amber-600'}`} />}
|
||||
<div className="min-w-0">
|
||||
<div className="flex flex-wrap items-center gap-2 text-xs font-medium text-gray-800">
|
||||
<span>{item.label}</span>
|
||||
<span>{translateDynamic(item.label, language)}</span>
|
||||
<span className={`rounded px-1.5 py-0.5 text-[10px] ${item.required ? 'bg-gray-100 text-gray-600' : 'bg-blue-50 text-blue-700'}`}>
|
||||
{item.required ? '必要' : '可选'}
|
||||
{item.required ? text.required : text.optional}
|
||||
</span>
|
||||
</div>
|
||||
<div className="mt-1 break-all font-mono text-[11px] text-gray-500">{item.detail || '-'}</div>
|
||||
<div className="mt-1 break-all font-mono text-[11px] text-gray-500">{translateDynamic(item.detail || '-', language)}</div>
|
||||
</div>
|
||||
</div>
|
||||
))}
|
||||
@@ -174,6 +178,153 @@ function ProbeMetric({ icon, label, value, sub }: { icon: ReactNode; label: stri
|
||||
)
|
||||
}
|
||||
|
||||
const hostReportText = {
|
||||
zh: {
|
||||
title: '宿主机信息',
|
||||
subtitle: '硬件、网络、磁盘健康与运行环境探测报告',
|
||||
refresh: '刷新',
|
||||
loading: '正在探测宿主机环境...',
|
||||
emptyReport: '暂未获取到宿主机信息',
|
||||
runtimeStatus: '运行状态',
|
||||
systemOverview: '系统概览',
|
||||
hostname: '主机名',
|
||||
os: '操作系统',
|
||||
kernel: '内核',
|
||||
generatedAt: '生成时间',
|
||||
cpuArch: 'CPU 架构',
|
||||
cpuVirtualization: 'CPU 虚拟化指令',
|
||||
cpuIntegratedGPU: 'CPU 核显',
|
||||
gpu: '显卡',
|
||||
runtimeCapability: '运行能力',
|
||||
kvmNested: 'KVM 嵌套虚拟化',
|
||||
supported: '支持',
|
||||
detected: '检测到',
|
||||
notDetected: '未检测到',
|
||||
publicNetwork: '公网与路由',
|
||||
publicIPv4: '公网 IPv4',
|
||||
ipv4Address: 'IPv4 地址',
|
||||
ipv4Prefix: 'IPv4 段',
|
||||
ipv6Address: 'IPv6 地址',
|
||||
ipv6Prefix: 'IPv6 段',
|
||||
gateway: '网关',
|
||||
memoryModules: '内存条',
|
||||
noMemoryModules: '未检测到内存条明细,可能缺少 dmidecode 或权限受限',
|
||||
slot: '插槽',
|
||||
capacity: '容量',
|
||||
type: '类型',
|
||||
frequency: '频率',
|
||||
vendor: '厂商',
|
||||
modelSerial: '型号/序列号',
|
||||
disksHealth: '硬盘与健康',
|
||||
noDisks: '未检测到硬盘',
|
||||
device: '设备',
|
||||
model: '型号',
|
||||
mountPoint: '挂载点',
|
||||
health: '健康',
|
||||
lifetime: '寿命',
|
||||
powerOn: '通电',
|
||||
reads: '读取',
|
||||
writes: '写入',
|
||||
commands: '命令数',
|
||||
eraseCount: '擦写',
|
||||
virtualDisk: '虚拟磁盘',
|
||||
virtualDiskDetail: '虚拟磁盘,真实 SMART/寿命/通电数据需在物理宿主机查看',
|
||||
unsupported: '不支持',
|
||||
hours: '小时',
|
||||
used: '已用',
|
||||
remaining: '剩余',
|
||||
read: '读',
|
||||
write: '写',
|
||||
wear: '磨损',
|
||||
erase: '擦写',
|
||||
powerCycles: '启停',
|
||||
networkInterfaces: '网卡',
|
||||
noNetworkInterfaces: '未检测到网卡',
|
||||
nic: '网卡',
|
||||
status: '状态',
|
||||
driverSpeed: '驱动/速率',
|
||||
gpus: '显卡',
|
||||
noGPUs: '未检测到显卡',
|
||||
name: '名称',
|
||||
driver: '驱动',
|
||||
environmentSupport: '环境支持',
|
||||
required: '必要',
|
||||
optional: '可选',
|
||||
},
|
||||
en: {
|
||||
title: 'Host Info',
|
||||
subtitle: 'Hardware, network, disk health, and runtime environment report',
|
||||
refresh: 'Refresh',
|
||||
loading: 'Probing host environment...',
|
||||
emptyReport: 'No host information available',
|
||||
runtimeStatus: 'Runtime Status',
|
||||
systemOverview: 'System Overview',
|
||||
hostname: 'Hostname',
|
||||
os: 'Operating System',
|
||||
kernel: 'Kernel',
|
||||
generatedAt: 'Generated At',
|
||||
cpuArch: 'CPU Architecture',
|
||||
cpuVirtualization: 'CPU Virtualization',
|
||||
cpuIntegratedGPU: 'CPU Integrated GPU',
|
||||
gpu: 'GPU',
|
||||
runtimeCapability: 'Runtime Capability',
|
||||
kvmNested: 'KVM Nested Virtualization',
|
||||
supported: 'Supported',
|
||||
detected: 'Detected',
|
||||
notDetected: 'Not detected',
|
||||
publicNetwork: 'Public Network & Routing',
|
||||
publicIPv4: 'Public IPv4',
|
||||
ipv4Address: 'IPv4 Addresses',
|
||||
ipv4Prefix: 'IPv4 Prefixes',
|
||||
ipv6Address: 'IPv6 Addresses',
|
||||
ipv6Prefix: 'IPv6 Prefixes',
|
||||
gateway: 'Gateway',
|
||||
memoryModules: 'Memory Modules',
|
||||
noMemoryModules: 'No memory module details detected. dmidecode may be missing or permissions may be limited.',
|
||||
slot: 'Slot',
|
||||
capacity: 'Capacity',
|
||||
type: 'Type',
|
||||
frequency: 'Frequency',
|
||||
vendor: 'Vendor',
|
||||
modelSerial: 'Model / Serial',
|
||||
disksHealth: 'Disks & Health',
|
||||
noDisks: 'No disks detected',
|
||||
device: 'Device',
|
||||
model: 'Model',
|
||||
mountPoint: 'Mount Point',
|
||||
health: 'Health',
|
||||
lifetime: 'Lifetime',
|
||||
powerOn: 'Power-on',
|
||||
reads: 'Reads',
|
||||
writes: 'Writes',
|
||||
commands: 'Commands',
|
||||
eraseCount: 'Erase Count',
|
||||
virtualDisk: 'Virtual Disk',
|
||||
virtualDiskDetail: 'Virtual disk. Real SMART, lifetime, and power-on data must be checked on the physical host.',
|
||||
unsupported: 'Unsupported',
|
||||
hours: 'hours',
|
||||
used: 'used',
|
||||
remaining: 'remaining',
|
||||
read: 'Read',
|
||||
write: 'Write',
|
||||
wear: 'Wear',
|
||||
erase: 'Erase',
|
||||
powerCycles: 'Power cycles',
|
||||
networkInterfaces: 'Network Interfaces',
|
||||
noNetworkInterfaces: 'No network interfaces detected',
|
||||
nic: 'NIC',
|
||||
status: 'Status',
|
||||
driverSpeed: 'Driver / Speed',
|
||||
gpus: 'GPUs',
|
||||
noGPUs: 'No GPUs detected',
|
||||
name: 'Name',
|
||||
driver: 'Driver',
|
||||
environmentSupport: 'Environment Support',
|
||||
required: 'Required',
|
||||
optional: 'Optional',
|
||||
},
|
||||
} as const
|
||||
|
||||
function ProbeSection({ title, children }: { title: string; children: ReactNode }) {
|
||||
return (
|
||||
<section>
|
||||
@@ -255,6 +406,26 @@ function formatMB(value: number) {
|
||||
return `${value} MB`
|
||||
}
|
||||
|
||||
function formatCPUThreads(cores: number, threads: number, language: Language) {
|
||||
return language === 'en' ? `${cores} cores / ${threads} threads` : `${cores} 核 / ${threads} 线程`
|
||||
}
|
||||
|
||||
function formatUsedMemory(usedMB: number, language: Language) {
|
||||
return language === 'en' ? `${formatMB(usedMB)} used` : `${formatMB(usedMB)} 已用`
|
||||
}
|
||||
|
||||
function formatDiskCount(count: number, language: Language) {
|
||||
return language === 'en' ? `${count} disk${count === 1 ? '' : 's'}` : `${count} 块硬盘`
|
||||
}
|
||||
|
||||
function formatProcessCount(count: number, language: Language) {
|
||||
return language === 'en' ? `${count} process${count === 1 ? '' : 'es'}` : `${count} 个进程`
|
||||
}
|
||||
|
||||
function formatItemCount(count: number, language: Language) {
|
||||
return language === 'en' ? `${count} item${count === 1 ? '' : 's'}` : `${count} 个`
|
||||
}
|
||||
|
||||
function formatBytes(value: number) {
|
||||
if (!value) return '-'
|
||||
const units = ['B', 'KB', 'MB', 'GB', 'TB', 'PB']
|
||||
@@ -267,20 +438,24 @@ function formatBytes(value: number) {
|
||||
return `${next.toFixed(index === 0 ? 0 : 1)} ${units[index]}`
|
||||
}
|
||||
|
||||
function formatLifeUsed(value?: number) {
|
||||
function formatLifeUsed(value: number | undefined, language: Language) {
|
||||
if (value === undefined || value === null) return '-'
|
||||
return `${value}% 已用\n${Math.max(0, 100 - value)}% 剩余`
|
||||
const text = hostReportText[language]
|
||||
return `${value}% ${text.used}\n${Math.max(0, 100 - value)}% ${text.remaining}`
|
||||
}
|
||||
|
||||
function formatPowerOnDays(hours: number) {
|
||||
function formatPowerOnDays(hours: number, language: Language) {
|
||||
const days = Math.floor(hours / 24)
|
||||
const rest = hours % 24
|
||||
return days > 0 ? `${days} 天 ${rest} 小时` : `${hours} 小时`
|
||||
return language === 'en'
|
||||
? (days > 0 ? `${days} days ${rest} hours` : `${hours} hours`)
|
||||
: (days > 0 ? `${days} 天 ${rest} 小时` : `${hours} 小时`)
|
||||
}
|
||||
|
||||
function formatCommands(read?: number, write?: number) {
|
||||
function formatCommands(read: number | undefined, write: number | undefined, language: Language) {
|
||||
if (!read && !write) return '-'
|
||||
return `读 ${formatCount(read || 0)}\n写 ${formatCount(write || 0)}`
|
||||
const text = hostReportText[language]
|
||||
return `${text.read} ${formatCount(read || 0)}\n${text.write} ${formatCount(write || 0)}`
|
||||
}
|
||||
|
||||
function formatCount(value: number) {
|
||||
@@ -291,38 +466,62 @@ function formatCount(value: number) {
|
||||
return `${value}`
|
||||
}
|
||||
|
||||
function formatWear(wear?: string, erase?: string, powerCycles?: number) {
|
||||
function formatWear(wear: string | undefined, erase: string | undefined, powerCycles: number | undefined, language: Language) {
|
||||
const text = hostReportText[language]
|
||||
const rows: string[] = []
|
||||
if (wear) rows.push(`磨损 ${wear}`)
|
||||
if (erase) rows.push(`擦写 ${erase}`)
|
||||
if (powerCycles) rows.push(`启停 ${powerCycles}`)
|
||||
if (wear) rows.push(`${text.wear} ${wear}`)
|
||||
if (erase) rows.push(`${text.erase} ${erase}`)
|
||||
if (powerCycles) rows.push(`${text.powerCycles} ${powerCycles}`)
|
||||
return rows.length ? rows.join('\n') : '-'
|
||||
}
|
||||
|
||||
function runtimeModeLabel(value: string) {
|
||||
function runtimeModeLabel(value: string, language: Language) {
|
||||
switch (value) {
|
||||
case 'kvm_lxc':
|
||||
return '支持 KVM + LXC'
|
||||
return language === 'en' ? 'KVM + LXC supported' : '支持 KVM + LXC'
|
||||
case 'lxc_only':
|
||||
return '仅支持 LXC'
|
||||
return language === 'en' ? 'LXC only' : '仅支持 LXC'
|
||||
default:
|
||||
return '未满足运行环境'
|
||||
return language === 'en' ? 'Runtime requirements not met' : '未满足运行环境'
|
||||
}
|
||||
}
|
||||
|
||||
function diskHealthLabel(value: string) {
|
||||
function diskHealthLabel(value: string, language: Language) {
|
||||
const text = hostReportText[language]
|
||||
switch (value) {
|
||||
case 'ok':
|
||||
return '健康'
|
||||
return language === 'en' ? 'Healthy' : '健康'
|
||||
case 'failed':
|
||||
return '异常'
|
||||
return language === 'en' ? 'Failed' : '异常'
|
||||
case 'virtual':
|
||||
return text.virtualDisk
|
||||
default:
|
||||
return '未知'
|
||||
return language === 'en' ? 'Unknown' : '未知'
|
||||
}
|
||||
}
|
||||
|
||||
function gpuTypeLabel(value: string) {
|
||||
if (value === 'integrated') return '核显'
|
||||
if (value === 'discrete') return '独显'
|
||||
function diskHealthDetail(d: { virtual?: boolean; health_detail?: string }, language: Language) {
|
||||
if (d.virtual) return hostReportText[language].virtualDiskDetail
|
||||
return translateDynamic(d.health_detail || '', language)
|
||||
}
|
||||
|
||||
function diskTypeLabel(d: { type?: string; rotational?: boolean; virtual?: boolean }, language: Language) {
|
||||
if (d.virtual || d.type === 'Virtual') return hostReportText[language].virtualDisk
|
||||
return d.type || (d.rotational ? 'HDD' : 'SSD')
|
||||
}
|
||||
|
||||
function gpuTypeLabel(value: string, language: Language) {
|
||||
if (value === 'integrated') return language === 'en' ? 'Integrated' : '核显'
|
||||
if (value === 'discrete') return language === 'en' ? 'Discrete' : '独显'
|
||||
return value || '-'
|
||||
}
|
||||
|
||||
function translateDynamic(value: string, language: Language) {
|
||||
if (language !== 'en' || !value) return value
|
||||
return translateText(value)
|
||||
.replace(/寿命已用\s*(\d+)%/g, 'Lifetime used $1%')
|
||||
.replace(/通电\s*(\d+)h/g, 'Power-on $1h')
|
||||
.replace(/写入\s*([^|]+)/g, 'Written $1')
|
||||
.replace(/读取\s*([^|]+)/g, 'Read $1')
|
||||
.replace(/介质错误\s*(\d+)/g, 'Media errors $1')
|
||||
}
|
||||
|
||||
@@ -128,7 +128,7 @@ export default function Login() {
|
||||
</form>
|
||||
</div>
|
||||
|
||||
<p className="text-center text-xs text-gray-400 mt-6">CLICD v1.1.9</p>
|
||||
<p className="text-center text-xs text-gray-400 mt-6">CLICD v1.1.12</p>
|
||||
</div>
|
||||
</div>
|
||||
)
|
||||
|
||||
+660
-234
File diff suppressed because it is too large
Load Diff
+114
-22
@@ -1,13 +1,16 @@
|
||||
import { Dispatch, SetStateAction, useCallback, useEffect, useState } from 'react'
|
||||
import { Clock, Globe, Lock, LogIn, Monitor, RefreshCw, ShieldCheck, Upload, UserCog } from 'lucide-react'
|
||||
import { Clock, Globe, Lock, LogIn, Monitor, RefreshCw, ShieldCheck, Terminal, Upload, UserCog } from 'lucide-react'
|
||||
import {
|
||||
changePassword,
|
||||
changeUsername,
|
||||
getLoginLogs,
|
||||
getSSLSettings,
|
||||
getWebSSHOriginSettings,
|
||||
LoginLog,
|
||||
SSLSettings,
|
||||
updateSSLSettings,
|
||||
updateWebSSHOriginSettings,
|
||||
WebSSHOriginSettings,
|
||||
} from '../services/api'
|
||||
import { useDialog } from '../components/Dialog'
|
||||
import { useAuth } from '../contexts/AuthContext'
|
||||
@@ -33,6 +36,9 @@ export default function Settings() {
|
||||
const [keyPEM, setKeyPEM] = useState('')
|
||||
const [applyNow, setApplyNow] = useState(true)
|
||||
const [savingSSL, setSavingSSL] = useState(false)
|
||||
const [webSSHOrigins, setWebSSHOrigins] = useState<WebSSHOriginSettings | null>(null)
|
||||
const [webSSHOriginsText, setWebSSHOriginsText] = useState('')
|
||||
const [savingWebSSHOrigins, setSavingWebSSHOrigins] = useState(false)
|
||||
|
||||
const fetchLogs = useCallback(async () => {
|
||||
try {
|
||||
@@ -60,12 +66,25 @@ export default function Settings() {
|
||||
}
|
||||
}, [])
|
||||
|
||||
const fetchWebSSHOrigins = useCallback(async () => {
|
||||
try {
|
||||
const res = await getWebSSHOriginSettings()
|
||||
const data = res.data.data
|
||||
if (!data) return
|
||||
setWebSSHOrigins(data)
|
||||
setWebSSHOriginsText((data.origins || []).join('\n'))
|
||||
} catch (err) {
|
||||
console.error(err)
|
||||
}
|
||||
}, [])
|
||||
|
||||
useEffect(() => {
|
||||
fetchLogs()
|
||||
fetchSSL()
|
||||
fetchWebSSHOrigins()
|
||||
const timer = setInterval(fetchLogs, 15000)
|
||||
return () => clearInterval(timer)
|
||||
}, [fetchLogs, fetchSSL])
|
||||
}, [fetchLogs, fetchSSL, fetchWebSSHOrigins])
|
||||
|
||||
const handleSSLModeChange = (mode: SSLSettings['mode']) => {
|
||||
setSSLMode(mode)
|
||||
@@ -101,6 +120,25 @@ export default function Settings() {
|
||||
}
|
||||
}
|
||||
|
||||
const handleSaveWebSSHOrigins = async () => {
|
||||
setSavingWebSSHOrigins(true)
|
||||
try {
|
||||
const origins = webSSHOriginsText.split(/\r?\n/).map(item => item.trim()).filter(Boolean)
|
||||
const res = await updateWebSSHOriginSettings(origins)
|
||||
const data = res.data.data
|
||||
if (data) {
|
||||
setWebSSHOrigins(data)
|
||||
setWebSSHOriginsText((data.origins || []).join('\n'))
|
||||
}
|
||||
dialog.alert('完成', 'Origin 白名单已保存')
|
||||
} catch (err: unknown) {
|
||||
const e = err as { response?: { data?: { message?: string } } }
|
||||
dialog.alert('失败', e.response?.data?.message || 'Origin 白名单保存失败')
|
||||
} finally {
|
||||
setSavingWebSSHOrigins(false)
|
||||
}
|
||||
}
|
||||
|
||||
const handleSaveAccount = async () => {
|
||||
if (!oldPwd) {
|
||||
dialog.alert('提示', '请输入当前密码以确认修改')
|
||||
@@ -159,26 +197,37 @@ export default function Settings() {
|
||||
</div>
|
||||
|
||||
<div className="grid items-start gap-6 xl:grid-cols-[minmax(0,1.15fr)_minmax(360px,0.85fr)]">
|
||||
<SSLCard
|
||||
ssl={ssl}
|
||||
sslEnabled={sslEnabled}
|
||||
sslMode={sslMode}
|
||||
sslTarget={sslTarget}
|
||||
sslEmail={sslEmail}
|
||||
certPEM={certPEM}
|
||||
keyPEM={keyPEM}
|
||||
applyNow={applyNow}
|
||||
savingSSL={savingSSL}
|
||||
onRefresh={fetchSSL}
|
||||
onEnabledChange={setSSLEnabled}
|
||||
onModeChange={handleSSLModeChange}
|
||||
onTargetChange={setSSLTarget}
|
||||
onEmailChange={setSSLEmail}
|
||||
onCertChange={setCertPEM}
|
||||
onKeyChange={setKeyPEM}
|
||||
onApplyNowChange={setApplyNow}
|
||||
onSave={handleSaveSSL}
|
||||
/>
|
||||
<div className="space-y-6">
|
||||
<SSLCard
|
||||
ssl={ssl}
|
||||
sslEnabled={sslEnabled}
|
||||
sslMode={sslMode}
|
||||
sslTarget={sslTarget}
|
||||
sslEmail={sslEmail}
|
||||
certPEM={certPEM}
|
||||
keyPEM={keyPEM}
|
||||
applyNow={applyNow}
|
||||
savingSSL={savingSSL}
|
||||
onRefresh={fetchSSL}
|
||||
onEnabledChange={setSSLEnabled}
|
||||
onModeChange={handleSSLModeChange}
|
||||
onTargetChange={setSSLTarget}
|
||||
onEmailChange={setSSLEmail}
|
||||
onCertChange={setCertPEM}
|
||||
onKeyChange={setKeyPEM}
|
||||
onApplyNowChange={setApplyNow}
|
||||
onSave={handleSaveSSL}
|
||||
/>
|
||||
|
||||
<WebSSHOriginCard
|
||||
settings={webSSHOrigins}
|
||||
originsText={webSSHOriginsText}
|
||||
saving={savingWebSSHOrigins}
|
||||
onOriginsTextChange={setWebSSHOriginsText}
|
||||
onRefresh={fetchWebSSHOrigins}
|
||||
onSave={handleSaveWebSSHOrigins}
|
||||
/>
|
||||
</div>
|
||||
|
||||
<div className="rounded-lg border border-gray-200 bg-white p-5">
|
||||
<h2 className="mb-4 flex items-center gap-2 text-sm font-semibold text-black">
|
||||
@@ -232,6 +281,49 @@ interface SSLCardProps {
|
||||
onSave: () => void
|
||||
}
|
||||
|
||||
interface WebSSHOriginCardProps {
|
||||
settings: WebSSHOriginSettings | null
|
||||
originsText: string
|
||||
saving: boolean
|
||||
onOriginsTextChange: (value: string) => void
|
||||
onRefresh: () => void
|
||||
onSave: () => void
|
||||
}
|
||||
|
||||
function WebSSHOriginCard(props: WebSSHOriginCardProps) {
|
||||
return (
|
||||
<div className="rounded-lg border border-gray-200 bg-white p-5">
|
||||
<div className="mb-4 flex items-center justify-between gap-3">
|
||||
<h2 className="flex items-center gap-2 text-sm font-semibold text-black">
|
||||
<Terminal className="h-4 w-4" />WebSSH Origin 白名单
|
||||
</h2>
|
||||
<button onClick={props.onRefresh} className="rounded-md border border-gray-200 p-1.5 text-gray-500 hover:bg-gray-50" title="刷新">
|
||||
<RefreshCw className="h-4 w-4" />
|
||||
</button>
|
||||
</div>
|
||||
<div className="space-y-3">
|
||||
<div>
|
||||
<label className="mb-1 block text-xs text-gray-500">允许的 Origin</label>
|
||||
<textarea
|
||||
value={props.originsText}
|
||||
onChange={(e) => props.onOriginsTextChange(e.target.value)}
|
||||
rows={5}
|
||||
className="w-full rounded-md border border-gray-300 bg-white px-3 py-2 font-mono text-xs text-black"
|
||||
/>
|
||||
</div>
|
||||
<div className="rounded-md border border-gray-100 bg-gray-50 p-3 text-xs text-gray-600">
|
||||
<div className="truncate font-mono" title={props.settings?.current_origin || ''}>当前面板来源:{props.settings?.current_origin || '-'}</div>
|
||||
<div className="mt-1">默认允许当前面板来源和本机回环来源;额外域名每行填写一个完整 Origin。</div>
|
||||
</div>
|
||||
<button onClick={props.onSave} disabled={props.saving} className="inline-flex w-full items-center justify-center gap-2 rounded-md bg-black px-4 py-2 text-sm text-white hover:bg-gray-800 disabled:opacity-50">
|
||||
<Upload className="h-4 w-4" />
|
||||
{props.saving ? '保存中...' : '保存 Origin 白名单'}
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
)
|
||||
}
|
||||
|
||||
function SSLCard(props: SSLCardProps) {
|
||||
const selectedSSL = props.ssl?.mode_certificates?.[props.sslMode]
|
||||
const modeOptions: Array<{ value: SSLSettings['mode']; label: string }> = [
|
||||
|
||||
@@ -40,10 +40,24 @@ export type ContainerIdentifier = number | string
|
||||
export interface PortMapping {
|
||||
container_port: number
|
||||
host_port: number
|
||||
host_ip?: string
|
||||
protocol: string
|
||||
description: string
|
||||
}
|
||||
|
||||
export interface PublicIPv4Assignment {
|
||||
address: string
|
||||
interface?: string
|
||||
prefix_len?: number
|
||||
gateway?: string
|
||||
}
|
||||
|
||||
export interface IPv6Assignment {
|
||||
address: string
|
||||
prefix_len: number
|
||||
interface?: string
|
||||
}
|
||||
|
||||
export interface Container {
|
||||
id: number
|
||||
uuid: string
|
||||
@@ -64,9 +78,11 @@ export interface Container {
|
||||
io_speed_mbps: number
|
||||
status: string
|
||||
ip: string
|
||||
public_ipv4s?: PublicIPv4Assignment[]
|
||||
ipv6: string
|
||||
ipv6_prefix_len: number
|
||||
ipv6_interface: string
|
||||
ipv6_addresses?: IPv6Assignment[]
|
||||
vnc_port: number
|
||||
ssh_port: number
|
||||
ssh_password: string
|
||||
@@ -114,11 +130,26 @@ export interface CreateContainerRequest {
|
||||
io_speed_mbps: number
|
||||
extra_ports: number[]
|
||||
port_mapping_count: number
|
||||
assign_nat?: boolean
|
||||
snapshot_limit: number
|
||||
assign_ipv4?: boolean
|
||||
ipv4_count?: number
|
||||
public_ipv4s?: string[]
|
||||
assign_ipv6: boolean
|
||||
ipv6_count?: number
|
||||
ipv6_addresses?: string[]
|
||||
ssh_auth_mode?: string
|
||||
ssh_password?: string
|
||||
ssh_public_key?: string
|
||||
expires_at: string
|
||||
}
|
||||
|
||||
export interface ReinstallContainerOptions {
|
||||
ssh_auth_mode?: string
|
||||
ssh_password?: string
|
||||
ssh_public_key?: string
|
||||
}
|
||||
|
||||
export interface IPv6PrefixInfo {
|
||||
interface: string
|
||||
address: string
|
||||
@@ -136,6 +167,17 @@ export interface IPv6Status {
|
||||
prefixes: IPv6PrefixInfo[]
|
||||
}
|
||||
|
||||
export interface PublicIPv4Info {
|
||||
interface: string
|
||||
address: string
|
||||
prefix: string
|
||||
prefix_len?: number
|
||||
subnet_mask?: string
|
||||
gateway?: string
|
||||
is_tunnel?: boolean
|
||||
source?: string
|
||||
}
|
||||
|
||||
export interface IPv4PrefixInfo {
|
||||
interface: string
|
||||
address: string
|
||||
@@ -163,6 +205,7 @@ export interface HostInfo {
|
||||
tx_bps: number
|
||||
public_ipv4?: string
|
||||
public_ipv4_interface?: string
|
||||
public_ipv4_addresses?: PublicIPv4Info[]
|
||||
public_ipv6?: string
|
||||
public_ipv6_interface?: string
|
||||
ipv6_prefixes?: IPv6PrefixInfo[]
|
||||
@@ -207,6 +250,7 @@ export interface HostProbeReport {
|
||||
serial: string
|
||||
size_bytes: number
|
||||
type: string
|
||||
virtual?: boolean
|
||||
rotational: boolean
|
||||
mountpoints: string[]
|
||||
health: string
|
||||
@@ -358,6 +402,17 @@ export const getSSLSettings = () =>
|
||||
export const updateSSLSettings = (data: UpdateSSLSettingsRequest) =>
|
||||
api.put<APIResponse<SSLSettings>>('/ssl', data)
|
||||
|
||||
export interface WebSSHOriginSettings {
|
||||
origins: string[]
|
||||
current_origin?: string
|
||||
}
|
||||
|
||||
export const getWebSSHOriginSettings = () =>
|
||||
api.get<APIResponse<WebSSHOriginSettings>>('/webssh-origins')
|
||||
|
||||
export const updateWebSSHOriginSettings = (origins: string[]) =>
|
||||
api.put<APIResponse<WebSSHOriginSettings>>('/webssh-origins', { origins })
|
||||
|
||||
// Containers
|
||||
export const getContainers = () =>
|
||||
api.get<APIResponse<Container[]>>('/containers')
|
||||
@@ -380,8 +435,8 @@ export const stopContainer = (id: ContainerIdentifier) =>
|
||||
export const restartContainer = (id: ContainerIdentifier) =>
|
||||
api.post<APIResponse>(`/containers/${id}/restart`)
|
||||
|
||||
export const reinstallContainer = (id: ContainerIdentifier, templateId: string) =>
|
||||
api.post<APIResponse>(`/containers/${id}/reinstall`, { template_id: templateId })
|
||||
export const reinstallContainer = (id: ContainerIdentifier, templateId: string, options?: ReinstallContainerOptions) =>
|
||||
api.post<APIResponse>(`/containers/${id}/reinstall`, { template_id: templateId, ...(options || {}) })
|
||||
|
||||
export const resetSSHPassword = (id: ContainerIdentifier, password?: string) =>
|
||||
api.post<APIResponse<{ password: string }>>(`/containers/${id}/reset-password`, password ? { password } : {})
|
||||
@@ -453,12 +508,24 @@ export interface NAT4Route {
|
||||
lxc_name: string
|
||||
status: string
|
||||
ip: string
|
||||
host_ip: string
|
||||
host_port: number
|
||||
container_port: number
|
||||
protocol: string
|
||||
description: string
|
||||
}
|
||||
|
||||
export interface IPv4Route {
|
||||
container_id: number
|
||||
container_name: string
|
||||
lxc_name: string
|
||||
status: string
|
||||
address: string
|
||||
interface: string
|
||||
prefix_len?: number
|
||||
gateway?: string
|
||||
}
|
||||
|
||||
export interface IPv6Route {
|
||||
container_id: number
|
||||
container_name: string
|
||||
@@ -471,15 +538,37 @@ export interface IPv6Route {
|
||||
|
||||
export interface RoutingInfo {
|
||||
nat4: RouteCapacity
|
||||
ipv4: RouteCapacity
|
||||
ipv6: RouteCapacity
|
||||
host_public_ipv4?: PublicIPv4Info
|
||||
public_ipv4_addresses: PublicIPv4Info[]
|
||||
ipv4_assignments: IPv4Route[]
|
||||
nat4_mappings: NAT4Route[]
|
||||
ipv6_assignments: IPv6Route[]
|
||||
ipv6_prefixes: IPv6PrefixInfo[]
|
||||
}
|
||||
|
||||
export interface PublicIPv4ScanResult extends PublicIPv4Info {
|
||||
status: string
|
||||
usable: boolean
|
||||
reason: string
|
||||
}
|
||||
|
||||
export const getRoutingInfo = () =>
|
||||
api.get<APIResponse<RoutingInfo>>('/routing')
|
||||
|
||||
export const updateRoutingPools = (payload: { items?: PublicIPv4Info[]; ipv6_prefixes?: IPv6PrefixInfo[] }) =>
|
||||
api.put<APIResponse<RoutingInfo>>('/routing', payload)
|
||||
|
||||
export const updateRoutingIPv4Pool = (items: PublicIPv4Info[]) =>
|
||||
updateRoutingPools({ items })
|
||||
|
||||
export const updateRoutingIPv6Prefixes = (ipv6_prefixes: IPv6PrefixInfo[]) =>
|
||||
updateRoutingPools({ ipv6_prefixes })
|
||||
|
||||
export const scanRoutingIPv4Segment = (payload: { cidr: string; interface: string; gateway: string; verify: boolean; limit?: number }) =>
|
||||
api.post<APIResponse<PublicIPv4ScanResult[]>>('/routing/ipv4-scan', payload)
|
||||
|
||||
// Templates
|
||||
export const getTemplates = () =>
|
||||
api.get<APIResponse<Template[]>>('/templates')
|
||||
|
||||
@@ -245,6 +245,7 @@ const exact: Record<string, string> = {
|
||||
'暂无登录记录': 'No login records',
|
||||
'暂无 NAT4 端口映射': 'No NAT4 port mappings',
|
||||
'暂无 IPv6 地址分配': 'No IPv6 assignments',
|
||||
'暂无可分配 IPv6 前缀': 'No allocatable IPv6 prefixes',
|
||||
'暂无镜像': 'No images',
|
||||
'暂无数据': 'No data',
|
||||
'容器': 'Container',
|
||||
@@ -327,6 +328,7 @@ const exact: Record<string, string> = {
|
||||
'地址': 'Address',
|
||||
'前缀': 'Prefix',
|
||||
'出口网卡': 'Uplink',
|
||||
'宿主地址': 'Host Address',
|
||||
'协议': 'Protocol',
|
||||
'说明': 'Description',
|
||||
'端口': 'Port',
|
||||
@@ -334,6 +336,12 @@ const exact: Record<string, string> = {
|
||||
'宿主机端口': 'Host Port',
|
||||
'容器 IPv4': 'Container IPv4',
|
||||
'IPv6 地址': 'IPv6 Address',
|
||||
'IPv6 前缀': 'IPv6 Prefix',
|
||||
'可分配 IPv6 前缀': 'Allocatable IPv6 Prefixes',
|
||||
'编辑前缀': 'Edit Prefixes',
|
||||
'添加 IPv6 前缀': 'Add IPv6 Prefix',
|
||||
'保存前缀': 'Save Prefixes',
|
||||
'服务商面板里的额外 IPv6 段不会自动出现在网卡里,请把可分配的前缀手动填入这里,例如 2401:b60:26:5e::2/64。': 'Extra IPv6 prefixes from the provider panel will not automatically appear on the NIC. Enter allocatable prefixes here manually, for example 2401:b60:26:5e::2/64.',
|
||||
'LXC 名称': 'LXC Name',
|
||||
'快照时间': 'Snapshot Time',
|
||||
'删除快照': 'Delete Snapshot',
|
||||
@@ -389,6 +397,13 @@ const exact: Record<string, string> = {
|
||||
'保存后自动重启服务并立即生效': 'Restart service automatically after saving',
|
||||
'保存中...': 'Saving...',
|
||||
'保存 SSL 设置': 'Save SSL Settings',
|
||||
'WebSSH Origin 白名单': 'WebSSH Origin Allowlist',
|
||||
'允许的 Origin': 'Allowed Origins',
|
||||
'当前面板来源:': 'Current panel origin:',
|
||||
'默认允许当前面板来源和本机回环来源;额外域名每行填写一个完整 Origin。': 'The current panel origin and local loopback origins are allowed by default. Add one full Origin per line.',
|
||||
'保存 Origin 白名单': 'Save Origin Allowlist',
|
||||
'Origin 白名单已保存': 'Origin allowlist saved',
|
||||
'Origin 白名单保存失败': 'Failed to save Origin allowlist',
|
||||
'登录日志': 'Login Logs',
|
||||
'首页': 'First',
|
||||
'上一页': 'Previous',
|
||||
@@ -730,6 +745,10 @@ const exact: Record<string, string> = {
|
||||
'厂商': 'Vendor',
|
||||
'型号/序列号': 'Model / Serial',
|
||||
'未检测到硬盘': 'No disks detected',
|
||||
'虚拟磁盘': 'Virtual Disk',
|
||||
'不支持': 'Unsupported',
|
||||
'虚拟磁盘,真实 SMART/寿命/通电数据需在物理宿主机查看': 'Virtual disk. Real SMART, lifetime, and power-on data must be checked on the physical host.',
|
||||
'虚拟Disk,真实 SMART/Lifetime/Power-on数据需在物理宿主机View': 'Virtual disk. Real SMART, lifetime, and power-on data must be checked on the physical host.',
|
||||
'型号': 'Model',
|
||||
'挂载点': 'Mount Point',
|
||||
'寿命': 'Lifetime',
|
||||
@@ -782,10 +801,16 @@ const artifactPatterns: RegExp[] = [
|
||||
/实时\s*Status/,
|
||||
/Create\s*Time/,
|
||||
/长期\s*Valid/,
|
||||
/虚拟Disk/,
|
||||
/宿主机View/,
|
||||
/SMART\/Lifetime\/Power-on数据/,
|
||||
]
|
||||
|
||||
const replacements: Array<[RegExp, string]> = [
|
||||
[/Back\s*列表/g, 'Back to list'],
|
||||
[/虚拟Disk,真实 SMART\/Lifetime\/Power-on数据需在物理宿主机View/g, 'Virtual disk. Real SMART, lifetime, and power-on data must be checked on the physical host.'],
|
||||
[/虚拟\s*Disk,真实 SMART\/Lifetime\/Power-on数据需在物理宿主机\s*View/g, 'Virtual disk. Real SMART, lifetime, and power-on data must be checked on the physical host.'],
|
||||
[/真实 SMART\/Lifetime\/Power-on数据需在物理宿主机View/g, 'Real SMART, lifetime, and power-on data must be checked on the physical host'],
|
||||
[/Search\s*名称、ID、UUID、IP/g, 'Search name, ID, UUID, IP'],
|
||||
[/All\s*类型/g, 'All types'],
|
||||
[/All\s*系统/g, 'All systems'],
|
||||
@@ -817,6 +842,7 @@ const replacements: Array<[RegExp, string]> = [
|
||||
[/告警列表\s*\((\d+)\)/g, 'Alert List ($1)'],
|
||||
[/共\s*(\d+)\s*个\s*Container/g, 'Total $1 containers'],
|
||||
[/共\s*(\d+)\s*个\s*容器/g, 'Total $1 containers'],
|
||||
[/(\d+)\s*个前缀,(\d+)\s*个地址已分配/g, '$1 prefixes, $2 addresses assigned'],
|
||||
[/共\s*(\d+)\s*条/g, 'Total $1'],
|
||||
[/共\s*(\d+)\s*个/g, 'Total $1 items'],
|
||||
[/,筛选后\s*(\d+)\s*个/g, ', filtered $1 items'],
|
||||
@@ -898,6 +924,11 @@ export function shouldTranslateText(value: string): boolean {
|
||||
|
||||
function cleanupTranslatedText(value: string): string {
|
||||
return value
|
||||
.replace(/虚拟Disk,真实 SMART\/Lifetime\/Power-on数据需在物理宿主机View/g, 'Virtual disk. Real SMART, lifetime, and power-on data must be checked on the physical host.')
|
||||
.replace(/Virtual Disk,真实 SMART\/Lifetime\/Power-on数据需在物理Host View/g, 'Virtual disk. Real SMART, lifetime, and power-on data must be checked on the physical host.')
|
||||
.replace(/Virtual Disk,真实 SMART\/Lifetime\/Power-on数据需在物理宿主机View/g, 'Virtual disk. Real SMART, lifetime, and power-on data must be checked on the physical host.')
|
||||
.replace(/虚拟\s*Disk/g, 'Virtual disk')
|
||||
.replace(/宿主机\s*View/g, 'physical host')
|
||||
.replace(/Back\s*List/g, 'Back to list')
|
||||
.replace(/Container\s*List/g, 'Container List')
|
||||
.replace(/Snapshot\s*List/g, 'Snapshot List')
|
||||
|
||||
@@ -0,0 +1,67 @@
|
||||
export type SSHAuthMode = 'auto_password' | 'password' | 'key'
|
||||
export type ReinstallSSHAuthMode = SSHAuthMode | 'keep'
|
||||
|
||||
const supportedKeyTypes = new Set([
|
||||
'ssh-ed25519',
|
||||
'ssh-rsa',
|
||||
'ecdsa-sha2-nistp256',
|
||||
'ecdsa-sha2-nistp384',
|
||||
'ecdsa-sha2-nistp521',
|
||||
'sk-ssh-ed25519@openssh.com',
|
||||
'sk-ecdsa-sha2-nistp256@openssh.com',
|
||||
])
|
||||
|
||||
export function generateSSHPassword() {
|
||||
const letters = 'ABCDEFGHJKLMNPQRSTUVWXYZabcdefghijkmnopqrstuvwxyz'
|
||||
const digits = '23456789'
|
||||
const symbols = '!@#$%*-_+='
|
||||
const all = letters + digits + symbols
|
||||
const pick = (chars: string) => chars[secureRandomInt(chars.length)]
|
||||
let password = pick(letters) + pick(digits)
|
||||
while (password.length < 16) password += pick(all)
|
||||
return secureShuffle(password.split('')).join('')
|
||||
}
|
||||
|
||||
export function sshPasswordError(password: string) {
|
||||
if (password.length < 8 || password.length > 64) return '密码长度必须为 8-64 位'
|
||||
if (/\s/.test(password)) return '密码不能包含空白字符'
|
||||
if (!/[A-Za-z]/.test(password)) return '密码至少需要包含字母'
|
||||
if (!/\d/.test(password)) return '密码至少需要包含数字'
|
||||
return ''
|
||||
}
|
||||
|
||||
export function sshPublicKeyError(publicKey: string) {
|
||||
const key = publicKey.trim()
|
||||
if (!key) return '请填写 SSH 公钥'
|
||||
if (key.length > 8192) return 'SSH 公钥长度不能超过 8192 字符'
|
||||
if (/[\r\n]/.test(key)) return 'SSH 公钥只能填写一行'
|
||||
const parts = key.split(/\s+/)
|
||||
if (parts.length < 2 || !supportedKeyTypes.has(parts[0])) return 'SSH 公钥格式不正确'
|
||||
return ''
|
||||
}
|
||||
|
||||
function secureRandomInt(maxExclusive: number) {
|
||||
if (!Number.isSafeInteger(maxExclusive) || maxExclusive <= 0) {
|
||||
throw new Error('invalid random range')
|
||||
}
|
||||
const values = new Uint32Array(1)
|
||||
const maxUint32 = 0x100000000
|
||||
const limit = Math.floor(maxUint32 / maxExclusive) * maxExclusive
|
||||
let value = 0
|
||||
do {
|
||||
crypto.getRandomValues(values)
|
||||
value = values[0]
|
||||
} while (value >= limit)
|
||||
return value % maxExclusive
|
||||
}
|
||||
|
||||
function secureShuffle<T>(items: T[]) {
|
||||
const next = [...items]
|
||||
for (let i = next.length - 1; i > 0; i--) {
|
||||
const j = secureRandomInt(i + 1)
|
||||
const value = next[i]
|
||||
next[i] = next[j]
|
||||
next[j] = value
|
||||
}
|
||||
return next
|
||||
}
|
||||
+5
-3
@@ -958,7 +958,7 @@ install_apk() {
|
||||
libvirt-client \
|
||||
libvirt-qemu
|
||||
|
||||
for pkg in lxcfs shadow conntrack-tools quota-tools e2fsprogs xfsprogs cloud-utils genisoimage xorriso; do
|
||||
for pkg in lxcfs shadow conntrack-tools quota-tools e2fsprogs xfsprogs cloud-utils genisoimage xorriso smartmontools; do
|
||||
apk add --no-cache "$pkg" >/dev/null 2>&1 || warn "可选依赖未安装:$pkg"
|
||||
done
|
||||
}
|
||||
@@ -987,12 +987,14 @@ install_apt() {
|
||||
xfsprogs \
|
||||
dnsmasq-base \
|
||||
qemu-kvm \
|
||||
qemu-system-x86 \
|
||||
qemu-utils \
|
||||
libvirt-daemon-system \
|
||||
libvirt-clients \
|
||||
cloud-image-utils \
|
||||
genisoimage \
|
||||
xorriso \
|
||||
smartmontools \
|
||||
virtinst \
|
||||
ovmf
|
||||
}
|
||||
@@ -1040,7 +1042,7 @@ install_dnf() {
|
||||
cloud-utils \
|
||||
genisoimage
|
||||
|
||||
for pkg in lxcfs xorriso edk2-ovmf; do
|
||||
for pkg in lxcfs xorriso edk2-ovmf smartmontools; do
|
||||
dnf install -y "$pkg" >/dev/null 2>&1 || warn "可选依赖未安装:$pkg"
|
||||
done
|
||||
}
|
||||
@@ -1075,7 +1077,7 @@ install_yum() {
|
||||
cloud-utils \
|
||||
genisoimage
|
||||
|
||||
for pkg in lxcfs xorriso edk2-ovmf; do
|
||||
for pkg in lxcfs xorriso edk2-ovmf smartmontools; do
|
||||
yum install -y "$pkg" >/dev/null 2>&1 || warn "可选依赖未安装:$pkg"
|
||||
done
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user