mirror of
https://github.com/dockur/proxmox.git
synced 2026-07-27 16:54:51 +07:00
feat: Provide host access through system.lan (#101)
This commit is contained in:
+63
-10
@@ -157,9 +157,31 @@ detectInterface() {
|
|||||||
return 0
|
return 0
|
||||||
}
|
}
|
||||||
|
|
||||||
|
defaultGateway() {
|
||||||
|
|
||||||
|
ip -4 route list default dev "$1" 2>/dev/null |
|
||||||
|
awk '$1 == "default" { for (i = 1; i < NF; i++) if ($i == "via") { print $(i + 1); exit } }' || :
|
||||||
|
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
|
addUpstream() {
|
||||||
|
|
||||||
|
local upstream="$1"
|
||||||
|
|
||||||
|
[ -n "$upstream" ] || return 1
|
||||||
|
|
||||||
|
if ! ip address add "$upstream/32" dev "$BRIDGE"; then
|
||||||
|
warn "failed to add upstream IP alias."
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
return 0
|
||||||
|
}
|
||||||
|
|
||||||
detectAddresses() {
|
detectAddresses() {
|
||||||
|
|
||||||
GATEWAY=$(ip route list dev "$DEV" | awk '/^default/ { print $3 }' | head -n 1)
|
GATEWAY=$(defaultGateway "$DEV")
|
||||||
{ UPLINK=$(ip address show dev "$DEV" | grep inet | awk '/inet / { print $2 }' | cut -f1 -d/ | head -n 1); } 2>/dev/null || :
|
{ UPLINK=$(ip address show dev "$DEV" | grep inet | awk '/inet / { print $2 }' | cut -f1 -d/ | head -n 1); } 2>/dev/null || :
|
||||||
|
|
||||||
IP6=""
|
IP6=""
|
||||||
@@ -295,15 +317,19 @@ configureDNS() {
|
|||||||
local fa="$1"
|
local fa="$1"
|
||||||
local mask="$2"
|
local mask="$2"
|
||||||
local gateway="$3"
|
local gateway="$3"
|
||||||
|
local upstream="${4:-}"
|
||||||
local base="${gateway%.*}"
|
local base="${gateway%.*}"
|
||||||
local file="/etc/dnsmasq.d/$fa.conf"
|
local file="/etc/dnsmasq.d/$fa.conf"
|
||||||
local mtu_option=""
|
local mtu_option=""
|
||||||
local filter_dns=""
|
local filter_dns=""
|
||||||
|
local upstream_entry=""
|
||||||
|
|
||||||
if [[ "$LAN_MTU" != "0" && "$LAN_MTU" != "1500" ]]; then
|
if [[ "$LAN_MTU" != "0" && "$LAN_MTU" != "1500" ]]; then
|
||||||
mtu_option="dhcp-option=option:mtu,$LAN_MTU"
|
mtu_option="dhcp-option=option:mtu,$LAN_MTU"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
[ -n "$upstream" ] && upstream_entry="address=/system.lan/$upstream"
|
||||||
|
|
||||||
# Avoid returning IPv6 records when the active network mode is IPv4-only.
|
# Avoid returning IPv6 records when the active network mode is IPv4-only.
|
||||||
if isNAT || [ -z "$IP6" ]; then
|
if isNAT || [ -z "$IP6" ]; then
|
||||||
filter_dns="filter-AAAA"
|
filter_dns="filter-AAAA"
|
||||||
@@ -317,7 +343,7 @@ configureDNS() {
|
|||||||
except-interface=lo
|
except-interface=lo
|
||||||
|
|
||||||
# IPv4 DHCP range
|
# IPv4 DHCP range
|
||||||
dhcp-range=set:${fa},${base}.2,${base}.254
|
dhcp-range=set:${fa},${base}.2,${base}.253
|
||||||
|
|
||||||
# Set gateway address
|
# Set gateway address
|
||||||
dhcp-option=option:netmask,$mask
|
dhcp-option=option:netmask,$mask
|
||||||
@@ -326,6 +352,7 @@ configureDNS() {
|
|||||||
$mtu_option
|
$mtu_option
|
||||||
|
|
||||||
address=/host.lan/$gateway
|
address=/host.lan/$gateway
|
||||||
|
$upstream_entry
|
||||||
$filter_dns
|
$filter_dns
|
||||||
|
|
||||||
# DHCP settings
|
# DHCP settings
|
||||||
@@ -630,7 +657,9 @@ showTableCleanupError() {
|
|||||||
applyTables() {
|
applyTables() {
|
||||||
|
|
||||||
local subnet="$1"
|
local subnet="$1"
|
||||||
local silent="${2:-N}"
|
local upstream="${2:-}"
|
||||||
|
local gateway="${3:-}"
|
||||||
|
local silent="${4:-N}"
|
||||||
local table_error
|
local table_error
|
||||||
local rule_tag="PROXMOX_NAT"
|
local rule_tag="PROXMOX_NAT"
|
||||||
|
|
||||||
@@ -646,6 +675,22 @@ applyTables() {
|
|||||||
return 1
|
return 1
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Forward the reserved system.lan alias to the container upstream gateway.
|
||||||
|
if [ -n "$upstream" ] && [ -n "$gateway" ]; then
|
||||||
|
|
||||||
|
if ! runTableRule "$silent" table_error \
|
||||||
|
iptables -t nat -A PREROUTING \
|
||||||
|
-i "$BRIDGE" \
|
||||||
|
-s "$subnet" \
|
||||||
|
-d "$upstream" \
|
||||||
|
-m comment --comment "$rule_tag" \
|
||||||
|
-j DNAT --to-destination "$gateway"; then
|
||||||
|
tableError "$silent" "$table_error"
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
fi
|
||||||
|
|
||||||
# Allow traffic from the VM bridge to any external interface.
|
# Allow traffic from the VM bridge to any external interface.
|
||||||
if ! runTableRule "$silent" table_error \
|
if ! runTableRule "$silent" table_error \
|
||||||
iptables -A FORWARD \
|
iptables -A FORWARD \
|
||||||
@@ -772,6 +817,8 @@ hasTaggedRules() {
|
|||||||
configureTables() {
|
configureTables() {
|
||||||
|
|
||||||
local subnet="$1"
|
local subnet="$1"
|
||||||
|
local upstream="${2:-}"
|
||||||
|
local gateway="${3:-}"
|
||||||
local preferred
|
local preferred
|
||||||
local alternate_save
|
local alternate_save
|
||||||
local preferred_clean="N"
|
local preferred_clean="N"
|
||||||
@@ -837,7 +884,7 @@ configureTables() {
|
|||||||
preferred_clean="Y"
|
preferred_clean="Y"
|
||||||
|
|
||||||
# Try the preferred backend without reporting provisional failures.
|
# Try the preferred backend without reporting provisional failures.
|
||||||
if applyTables "$subnet" "Y"; then
|
if applyTables "$subnet" "$upstream" "$gateway" "Y"; then
|
||||||
checkExistingTables
|
checkExistingTables
|
||||||
return 0
|
return 0
|
||||||
fi
|
fi
|
||||||
@@ -876,7 +923,7 @@ configureTables() {
|
|||||||
# Remove rules left by a previous run from the alternate backend.
|
# Remove rules left by a previous run from the alternate backend.
|
||||||
if clearTables; then
|
if clearTables; then
|
||||||
|
|
||||||
if applyTables "$subnet" "Y"; then
|
if applyTables "$subnet" "$upstream" "$gateway" "Y"; then
|
||||||
checkExistingTables
|
checkExistingTables
|
||||||
return 0
|
return 0
|
||||||
fi
|
fi
|
||||||
@@ -930,7 +977,7 @@ configureTables() {
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
# Repeat the preferred backend once to show its actual failure.
|
# Repeat the preferred backend once to show its actual failure.
|
||||||
if applyTables "$subnet" "N"; then
|
if applyTables "$subnet" "$upstream" "$gateway" "N"; then
|
||||||
checkExistingTables
|
checkExistingTables
|
||||||
return 0
|
return 0
|
||||||
fi
|
fi
|
||||||
@@ -945,7 +992,7 @@ configureTables() {
|
|||||||
|
|
||||||
configureNAT() {
|
configureNAT() {
|
||||||
|
|
||||||
local base subnet
|
local base subnet upstream=""
|
||||||
local forwarding=""
|
local forwarding=""
|
||||||
local tuntap="TUN device is missing. $ADD_ERR --device /dev/net/tun"
|
local tuntap="TUN device is missing. $ADD_ERR --device /dev/net/tun"
|
||||||
|
|
||||||
@@ -1002,15 +1049,21 @@ configureNAT() {
|
|||||||
createBridge "$gateway" || return 1
|
createBridge "$gateway" || return 1
|
||||||
createTap "$tuntap" || return 1
|
createTap "$tuntap" || return 1
|
||||||
|
|
||||||
|
# Reserve the final usable address for access to the upstream gateway.
|
||||||
|
if [ -n "$GATEWAY" ]; then
|
||||||
|
upstream="$base.254"
|
||||||
|
addUpstream "$upstream" || upstream=""
|
||||||
|
fi
|
||||||
|
|
||||||
# Use the lowest effective VM-LAN MTU, without mutating the uplink MTU.
|
# Use the lowest effective VM-LAN MTU, without mutating the uplink MTU.
|
||||||
if [[ "$LAN_MTU" != "0" ]]; then
|
if [[ "$LAN_MTU" != "0" ]]; then
|
||||||
LAN_MTU=$(minMTU "$LAN_MTU" "$(getMTU "$BRIDGE")" "$(getMTU "$TAP")")
|
LAN_MTU=$(minMTU "$LAN_MTU" "$(getMTU "$BRIDGE")" "$(getMTU "$TAP")")
|
||||||
fi
|
fi
|
||||||
|
|
||||||
configureTables "$subnet" || return 1
|
configureTables "$subnet" "$upstream" "$GATEWAY" || return 1
|
||||||
|
|
||||||
setInterfaces "$BRIDGE" "$TAP" "$gateway" || return 1
|
setInterfaces "$BRIDGE" "$TAP" "$gateway" || return 1
|
||||||
configureDNS "$BRIDGE" "$MASK" "$gateway" || return 1
|
configureDNS "$BRIDGE" "$MASK" "$gateway" "$upstream" || return 1
|
||||||
|
|
||||||
showBridgeInfo "$subnet" "$gateway"
|
showBridgeInfo "$subnet" "$gateway"
|
||||||
|
|
||||||
@@ -1234,7 +1287,7 @@ showBridgeInfo() {
|
|||||||
display=$(formatAddress "$gateway" "$PREFIX" || true)
|
display=$(formatAddress "$gateway" "$PREFIX" || true)
|
||||||
|
|
||||||
local base="${gateway%.*}"
|
local base="${gateway%.*}"
|
||||||
local dhcp="$base.2-$base.254"
|
local dhcp="$base.2-$base.253"
|
||||||
local line="❯ Bridge: $BRIDGE | Gateway: $display | DHCP: $dhcp"
|
local line="❯ Bridge: $BRIDGE | Gateway: $display | DHCP: $dhcp"
|
||||||
|
|
||||||
if [[ "$PREFIX" != "24" ]]; then
|
if [[ "$PREFIX" != "24" ]]; then
|
||||||
|
|||||||
Reference in New Issue
Block a user