-
Notifications
You must be signed in to change notification settings - Fork 1.4k
wip: systemvm: enable IPv6 link-local on the control network #13795
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -573,10 +573,42 @@ setup_dnsmasq() { | |
| fi | ||
| } | ||
|
|
||
| enable_ipv6_link_local() { | ||
| local eth=$1 | ||
| log_it "Enabling IPv6 link-local on interface $eth" | ||
| # Generate the link-local address with EUI-64 based on the MAC address so | ||
| # the address can be calculated by the Management Server | ||
| sysctl -w net.ipv6.conf.${eth}.addr_gen_mode=0 | ||
| # Only a link-local address is wanted, no SLAAC/RA configuration | ||
| sysctl -w net.ipv6.conf.${eth}.accept_ra=0 | ||
| sysctl -w net.ipv6.conf.${eth}.autoconf=0 | ||
| sysctl -w net.ipv6.conf.${eth}.disable_ipv6=0 | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. tested this on a lab and it gets undone a few seconds later, so the feature doesnt survive a boot. this sets the runtime value only. the template ships end state, address gone and sshd only on v4: showed it directly on the vm: so the design is fine by the way, once i left ipv6 on and restarted sshd it worked end to end over can we clear the persistent one too?
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Thanks! I had a manual script checking a few things, didn't notice it was gone right after. Let me look into that, I now have a better lab to test this again. My goal is to remove IPv4 entirely. We now have a complete allocation mechanism for IPv4 for this control cidr which is a lot of code and database entries which shouldn't be needed. First step is adding IPv6, making sure its stable and then remove IPv4 in a future PR.
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. sounds good, happy to test again once its updated |
||
|
|
||
| # Wait for Duplicate Address Detection to complete so the address can be bound | ||
| LINK_LOCAL_IP6="" | ||
| local i | ||
| for i in $(seq 1 10); do | ||
| LINK_LOCAL_IP6=$(ip -6 addr show dev ${eth} scope link -tentative | grep -Po '(?<=inet6 )fe80:[0-9a-f:]+' | head -1) | ||
| [ -n "$LINK_LOCAL_IP6" ] && break | ||
| sleep 1 | ||
| done | ||
|
|
||
| if [ -n "$LINK_LOCAL_IP6" ]; then | ||
| log_it "Interface $eth has IPv6 link-local address $LINK_LOCAL_IP6" | ||
| else | ||
| log_it "No IPv6 link-local address appeared on interface $eth" | ||
| fi | ||
| } | ||
|
|
||
| setup_sshd(){ | ||
| local ip=$1 | ||
| local eth=$2 | ||
| [ -f /etc/ssh/sshd_config ] && sed -i -e "s/^[#]*ListenAddress.*$/ListenAddress $ip/" /etc/ssh/sshd_config | ||
| [ -f /etc/ssh/sshd_config ] && sed -i -e "/^ListenAddress fe80/d" -e "s/^[#]*ListenAddress.*$/ListenAddress $ip/" /etc/ssh/sshd_config | ||
| enable_ipv6_link_local $eth | ||
| if [ -n "$LINK_LOCAL_IP6" ]; then | ||
| log_it "Configuring sshd to also listen on ${LINK_LOCAL_IP6}%${eth}" | ||
| sed -i -e "/^ListenAddress $ip$/a ListenAddress ${LINK_LOCAL_IP6}%${eth}" /etc/ssh/sshd_config | ||
|
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. this writes the v6 ListenAddress but nothing rechecks the address is still there when sshd actually starts. on my lab it ended up pointing at an address that no longer existed: sshd was fine with it and just bound v4, so no harm this time. but if it ever refused to start we'd have a systemvm with no way in. worth only adding the line when the address is actually up at sshd start?
Contributor
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Same goes for IPv4 ofcourse, we never check if the address exists, we assume it does. This needs fixing somewhere else.
Collaborator
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. fair enough, ok to fix that separately |
||
| fi | ||
| sed -i "/3922/s/eth./$eth/" /etc/iptables/rules.v4 | ||
| } | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
this is calculated from the mac, it never checks the vm actually has the address. so the field always shows something even when ipv6 is off on the systemvm.
on my lab both systemvms reported a
linklocalip6while nothing was listening on it.is that the intent, a value you can always compute? if so maybe say so in the field description, otherwise someone will read it as "this address works".
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
The calculated address is always the same. It never changes or will be different. This is an RFC for IPv6 where the link-local is persistent. That's the great thing about it.
Calculate instead of store. Saves a lot of code.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
makes sense that it never changes. can we say in the field description that its calculated, so nobody reads it as the address being up?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Well, isn't this a basic IPv6 knowledge? Link Local IPv6 always exists and you don't need to do anything about it.