From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 54C451FF0EF for ; Sun, 02 Aug 2026 05:37:23 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id EBC57215E2; Sun, 02 Aug 2026 05:37:03 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=neatech-ar.20251104.gappssmtp.com; s=20251104; t=1785641801; x=1786246601; darn=lists.proxmox.com; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=2Rj4GKBli096Ld1bNPpRo7CfA1y4zRQV15RDtnt6/9Y=; b=uLUQ63akvBsbrkkSMLdeNj31jY9hEYeyqqWrHK2jF5uBBW1y8iAFV5NMY3ckAdciDY lKvr66I5BcG1BuXvYOpC2EjTEsCWHIUyU9ZTv5n5UnZxryLGRHVDlf/nJo77V4qqPl6b +DbDSpDQlSRIj4xKDF6qlccetp7NEwA+1iRjuxQJ/dg8GwTp/INQcCBDIpy6fLbUw0Xq 1l/CZkuY8MAbQLBQNx3BguuqK18jzbr8MmBWw8UTJd3unLlCqeIs2H6Ka7aRZjAWdK+N kk5lIClOkyXxHtWWvV2EFr4n4Hd7vASBMKhEq6ux/WU0rjVeCnbwn5QzSv/m6siMGoT/ Q2FA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785641801; x=1786246601; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=2Rj4GKBli096Ld1bNPpRo7CfA1y4zRQV15RDtnt6/9Y=; b=j3Ai4FrI789RzlJrqGB7gUlZcsJ+udYQ34p1QF0eVGEerJjfxljMRIIFfhxUz6n2uQ 7FlpP3+WZFR2tlcJFfiemAzBdh2/fLE/i04a2DjVZb3Hb/HsunCoSrWXg3zlkqNaMFWO NiW3PSN/Q9dAppv+d3N66eXQYWHR+Vi8Lq7crMMmfrA1LphyLmlGxFM+ZDOUzDSozNLm HStuBnLkdl75GwL5/uVoBP4NB8nFt767YBHfAcJ1x8qw//x0luaCCDWVHXwomOuKukDh OLmhKCeDIc7+b6TbPrFUUl+4/71ygZnCSqYp1m3ix5y2DRc23+K9GYllKtAsB3xeDoYF 8lcA== X-Gm-Message-State: AOJu0YxVnOh+q3HNu0gWq1zstVHqe3HFincC2KgUyQ4/XzS+pxBt/McB vmyHpn9Mxo8/A6APG1bBAi05bekTO5gP3Uilmljc3vgwiFkC1SzcGcQ3wdhsy6HRj8cr/xO3cjX R5Pfsluk= X-Gm-Gg: AR+sD11Tn9CzuXhgXh7WRZ3ZR7FlZGBh3qnwCJNVcGhLTKbRksL7QugDQ7WUPQ5ydoP 3LFmxnEhmL3UW8u9hSxmV0iJlstAC7XdVH17qUkzLyoLwKTVtvCzGv8g7Buua+5D824v2X5tWry zQu5N9nZH6gLHYnRWqYXDPKvJGyRJ42oSlb6r37x4oge2EOIZWutgg8vMQqlydJ/aorr0MQ3RNv 0fbX/8/7EHZRCW8JV0VYE4iXp4/fVWX5vrq0EKLfFidmBlGOtQYEhr1v9/+LK9jVVmMewco13lW /SKOmUOrSN+d01Cgy+VQ1jcbKPrwbuHJIZLCwpGDpRjuO2N48Li0XzeMHBayfKcPVkB4xjJCbzL na98tN/2FUcJC27kowTgX1mXB0yCW3REB8JU0u1rSlLOujq1sFzDOexgbEnDCzbpaOpz80OEj5v 0GWQn65l//QQy1+/LhkQqNWY2eKPXJQfwhO3FJMo/4AmF0xqKFa7bUZpzy82xaOBm/umoJk82b/ yANmI5bP4kNdnB7JZ+kxacg1FVtWlSpJpQudM7xvUzW5cgLKa7K4v2i X-Received: by 2002:a17:903:2f8d:b0:2c9:ed4a:c3a4 with SMTP id d9443c01a7336-2d052064a84mr71571605ad.0.1785641800717; Sat, 01 Aug 2026 20:36:40 -0700 (PDT) From: Joaquin Varela To: pve-devel@lists.proxmox.com Subject: [PATCH docs v2 5/5] zfsnvme: document host ACL and cloud-init prerequisites Date: Sun, 2 Aug 2026 00:36:30 -0300 Message-ID: <66df01fad4474cd63c8cf3e1c6331a90124faf71.1785636981.git.joaquinvarela@neatech.ar> X-Mailer: git-send-email 2.54.0.windows.1 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 AWL 0.024 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DMARC_PASS -0.1 DMARC pass policy RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record Message-ID-Hash: TFLN2WRJNRR7X7M2QEZLFQ7YSPZ5MR4V X-Message-ID-Hash: TFLN2WRJNRR7X7M2QEZLFQ7YSPZ5MR4V X-MailFrom: joaquinvarela@neatech.ar X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header CC: Joaquin Varela X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Document the complete Host NQN allow-list required for atomic target reconstruction. Warn dedicated targets to disable guest cloud-init datasource discovery so a cidata ZVOL cannot be mistaken for host provisioning media. Signed-off-by: Joaquin Varela --- pve-storage-zfsnvme.adoc | 25 +++++++++++++++++++++++-- 1 file changed, 23 insertions(+), 2 deletions(-) diff --git a/pve-storage-zfsnvme.adoc b/pve-storage-zfsnvme.adoc index edfb938..9d2c2f0 100644 --- a/pve-storage-zfsnvme.adoc +++ b/pve-storage-zfsnvme.adoc @@ -38,8 +38,20 @@ target using systemd, load the transport at boot and verify the configfs mount: The target configuration below configfs is derived state. It does not need a separate persistence service: after the module and ZFS pool are available, the -backend reconstructs subsystems, namespaces, UUIDs, ACLs, and ports from the -ZFS user properties during activation. +backend reconstructs namespaces and UUIDs from ZFS user properties, and +reconstructs the subsystem, host ACLs, and ports from the shared storage +configuration during activation. + +Do not leave cloud-init device discovery enabled on a dedicated Linux target. +A guest cloud-init ZVOL contains a `cidata` filesystem and can otherwise be +mistaken for the target host's own NoCloud datasource during boot. After the +target host is provisioned, remove cloud-init or disable it according to the +distribution's documentation. For distributions supporting the standard +disable marker, use: + +---- +# touch /etc/cloud/cloud-init.disabled +---- Each {pve} node needs `nvme-cli`, the `nvme-tcp` module, native NVMe multipath, a unique `/etc/nvme/hostnqn`, and `/etc/nvme/hostid`. Interface names listed in @@ -76,6 +88,14 @@ explicit interface prevents a failed data path from reconnecting over the management network. Activation fails before changing target state if any configured interface is missing on the local node. +nvme-host-nqns:: + +Comma-separated contents of `/etc/nvme/hostnqn` from every cluster node that +may activate the storage. The complete allow-list lets any one node restore all +host ACLs before publishing the subsystem after a target reboot. Activation +fails if the local node's Host NQN is absent. Update this property before +enabling the storage on a newly added cluster node. + dhchap-key:: NVMe DH-HMAC-CHAP secret in `DHHC-1` representation. The value is handled as a @@ -127,6 +147,7 @@ zfsnvme: nvme-shared subsysnqn nqn.2026-07.example:pve-nvme nvme-portals 10.10.1.10:4420,10.10.2.10:4420 nvme-host-ifaces ens20,ens21 + nvme-host-nqns nqn.2014-08.org.nvmexpress:uuid:11111111-1111-1111-1111-111111111111,nqn.2014-08.org.nvmexpress:uuid:22222222-2222-2222-2222-222222222222 blocksize 16k sparse 1 nvme-iopolicy round-robin -- 2.54.0.windows.1