Repository navigation
Add Proxmox VE LXC runtime backend - #34
philip-ulrich wants to merge 10 commits into
Conversation
a7392d6 to
3451b7f
Compare
3451b7f to
9c9afe6
Compare
|
Still testing, fixing, and adjusting things, but this should be most of the way there. I’m not comfortable taking it out of draft yet, but you’re welcome to start reviewing and providing feedback. I’ll stop amending existing commits so it’s easier to see what changed since your last review. A few notes beyond the PR description:
One other thing worth noting, I intentionally left everything "deployment method agnostic" so that we don't have to make any panel changes. There are things that could be cleaned up a little bit if we added some panel controls for pve vs docker. But it was written initially for me so that I could get it working without having to maintain two forks if you didn't want it upstream. 😄 |
d63013d to
e5a0d98
Compare
|
Should be good now. Might have follow up PR(s) in a week or so. We'll be moving 50+ servers into the panel with more to come after. We should quickly find issues if they exist. |
Wings now allocates Proxmox container IDs at or above runtime.pve_lxc.min_vmid (default 200) so auto-created guests stay clear of manually created infrastructure containers below the floor. When /cluster/nextid points below the floor, the allocator scans the cluster inventory across all guest types for the first free ID.
Adds a native Proxmox VE 9.2 LXC runtime so Wings can create, adopt, run, stop, replace, and destroy game-server containers without Docker. Runtime selection remains behind
ServerExecutor:autoprefers reachable Docker, otherwise chooses local PVE, and persists that decision so installing Docker later does not move existing workloads.The PVE path maps panel CPU, memory, storage, allocations, mounts, devices, console, installation helpers, networking, firewall policy, backups, and cgroup telemetry onto native LXC primitives. It uses node-scoped ownership tags, retries advisory VMID allocation collisions, refreshes mutable OCI tags by resolved digest, bounds every local command and task/config-helper wait, waits for stop completion before destroy, scopes wildcard ports by address family, and skips transiently disappearing containers during used-port discovery.
OCI template downloads are serialized without blocking unrelated container provisioning. Installer status files are owner-writable rather than world-writable, helper log readers recover from truncation, and static networks no longer receive the host-managed DHCP marker.
Firewall policy remains panel-authoritative. When the datacenter firewall is enabled, Wings writes only its tagged VM rules and source-file IP sets, preserves administrator rules, uses the panel's default-allow semantics, and emits a protocol/port-free terminal drop for “deny everything else.”
autoclears stale Wings guest rules before falling back to host nftables or iptables. Firewall reload and reconciliation now hold one operation lock, including cleanup of the remembered VMID.Native Tundra integration uses
pid:<init-pid>references. Wings requires the connected daemon to advertiseprocess_container_refsand fails closed when the capability is absent. The runtime-neutral resolver now lives as source on thecodex/process-container-refscompanion branch instead of an out-of-tree patch in this repository.Operator documentation is integrated into the existing Wings installation, configuration, and private-network sections on the
codex/pve-lxc-runtime-docswebsite branch. Known initial limitations are documented there: PVE does not currently provide Docker-equivalent exit/OOM metadata; panel entrypoint overrides, CPU pinning, unlimited memory/swap, digest-form image references, and private-registry credentials are rejected explicitly.Validation:
main; review follow-ups are preserved as separate commitscargo fmt --all -- --checkcargo clippy -p wings-rs --bin wings-rs -- -D warningsRUSTFLAGS="-D warnings"; 11 Docker-socket integration tests ignored9c9afe6installed on a PVE 9.2.2 test node running Wings 1.2.4 (sha256:4ebc68a47fad1caf3a66bef41926ecf729c633ae5731c83ab196d32ab4782c16)process_container_refsand adopted the process-backed server referencecargo clippy --all-targets -- -D warningsis not currently a repository gate because pre-existing test modules contain hundreds of denied unwrap/indexing/assertion lints; the production binary target is clean.