From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by lists.proxmox.com (Postfix) with ESMTPS id B03BF60E4F for ; Mon, 19 Oct 2020 21:03:00 +0200 (CEST) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id A56BD2F23F for ; Mon, 19 Oct 2020 21:02:30 +0200 (CEST) Received: from proxmox-new.maurer-it.com (proxmox-new.maurer-it.com [212.186.127.180]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by firstgate.proxmox.com (Proxmox) with ESMTPS id E395D2F17B for ; Mon, 19 Oct 2020 21:02:24 +0200 (CEST) Received: from proxmox-new.maurer-it.com (localhost.localdomain [127.0.0.1]) by proxmox-new.maurer-it.com (Proxmox) with ESMTP id AB0A345E06 for ; Mon, 19 Oct 2020 21:02:24 +0200 (CEST) From: Stoiko Ivanov To: pmg-devel@lists.proxmox.com Date: Mon, 19 Oct 2020 21:02:06 +0200 Message-Id: <20201019190209.11495-10-s.ivanov@proxmox.com> X-Mailer: git-send-email 2.20.1 In-Reply-To: <20201019190209.11495-1-s.ivanov@proxmox.com> References: <20201019190209.11495-1-s.ivanov@proxmox.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 0 AWL -0.302 Adjusted score from AWL reputation of From: address KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment RCVD_IN_DNSWL_MED -2.3 Sender listed at https://www.dnswl.org/, medium trust SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record URIBL_SBL 0.644 Contains an URL's NS IP listed in the Spamhaus SBL blocklist [backup.pm] URIBL_SBL_A 0.1 Contains URL's A record listed in the Spamhaus SBL blocklist [backup.pm] Subject: [pmg-devel] [RFC pmg-api 09/12] add initial SectionConfig for pbs X-BeenThere: pmg-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox Mail Gateway development discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Oct 2020 19:03:00 -0000 add a SectionConfig definition to hold information about PBS-remotes used for backing up PMG. Mostly adapted from the PBSPlugin.pm in pve-storage. Signed-off-by: Stoiko Ivanov --- debian/dirs | 1 + src/Makefile | 1 + src/PMG/PBSConfig.pm | 168 +++++++++++++++++++++++++++++++++++++++++++ 3 files changed, 170 insertions(+) create mode 100644 src/PMG/PBSConfig.pm diff --git a/debian/dirs b/debian/dirs index f7ac2e7..f138bb4 100644 --- a/debian/dirs +++ b/debian/dirs @@ -1,4 +1,5 @@ /etc/pmg /etc/pmg/dkim +/etc/pmg/pbs /var/lib/pmg /var/lib/pmg/backup diff --git a/src/Makefile b/src/Makefile index a460048..001cb57 100644 --- a/src/Makefile +++ b/src/Makefile @@ -67,6 +67,7 @@ LIBSOURCES = \ PMG/Unpack.pm \ PMG/Backup.pm \ PMG/PBSTools.pm \ + PMG/PBSConfig.pm \ PMG/RuleCache.pm \ PMG/Statistic.pm \ PMG/UserConfig.pm \ diff --git a/src/PMG/PBSConfig.pm b/src/PMG/PBSConfig.pm new file mode 100644 index 0000000..d290161 --- /dev/null +++ b/src/PMG/PBSConfig.pm @@ -0,0 +1,168 @@ +package PMG::PBSConfig; + +# section config implementation for PBS integration in PMG + +use strict; +use warnings; + +use PVE::Tools qw(extract_param); +use PVE::SectionConfig; +use PVE::JSONSchema qw(get_standard_option); +use PMG::PBSTools; + +use base qw(PVE::SectionConfig); + +my $inotify_file_id = 'pmg-pbs.conf'; +my $secret_dir = '/etc/pmg/pbs'; +my $config_filename = "${secret_dir}/pbs.conf"; + +my $get_secret_dir = sub { + return $secret_dir; +}; + +my $defaultData = { + propertyList => { + type => { description => "Section type." }, + remote => { + description => "Proxmox Backup Server ID.", + type => 'string', format => 'pve-configid', + }, + }, +}; + +sub properties { + return { + datastore => { + description => "Proxmox backup server datastore name.", + type => 'string', + }, + server => { + description => "Proxmox backup server address.", + type => 'string', format => 'address', + maxLength => 256, + }, + disable => { + description => "Flag to disable/deactivate the entry.", + type => 'boolean', + optional => 1, + }, + password => { + description => "Password for the user on the Proxmox backup server.", + type => 'string', + optional => 1, + }, + username => get_standard_option('pmg-email-address', { + description => "Username on the Proxmox backup server" + }), + # openssl s_client -connect :8007 2>&1 |openssl x509 -fingerprint -sha256 + fingerprint => get_standard_option('fingerprint-sha256'), + 'encryption-key' => { + description => "Encryption key. Use 'autogen' to generate one automatically without passphrase.", + type => 'string', + optional => 1, + }, + }; +} + +sub options { + return { + server => { fixed => 1 }, + datastore => { fixed => 1 }, + disable => { optional => 1}, + username => { optional => 1 }, + password => { optional => 1 }, + 'encryption-key' => { optional => 1 }, + fingerprint => { optional => 1 }, + }; +} + +sub type { + return 'pbs'; +} + +sub private { + return $defaultData; +} + +sub parse_config { + my ($class, $filename, $raw) = @_; + + my $cfg = $class->SUPER::parse_config($filename, $raw); + + PMG::PBSTools::set_secret_dir($secret_dir); + + return $cfg; +} + +sub write_config { + my ($class, $filename, $cfg) = @_; + + foreach my $pbs (keys %{$cfg->{ids}}) { + my $data = $cfg->{ids}->{$pbs}; + + my $password = extract_param($data, 'password'); + PMG::PBSTools::pbs_set_password($data, $pbs, $password) if defined($password); + + my $encryption_key = extract_param($data, 'encryption-key'); + PMG::PBSTools::pbs_set_encryption_key($data, $pbs, $encryption_key) if defined($encryption_key); + } + + $class->SUPER::write_config($filename, $cfg); +} + +sub new { + my ($type) = @_; + + my $class = ref($type) || $type; + + my $cfg = PVE::INotify::read_file($inotify_file_id); + + return bless $cfg, $class; +} + +sub write { + my ($self) = @_; + + PVE::INotify::write_file($inotify_file_id, $self); +} + +my $lockfile = "/var/lock/pmgpbsconfig.lck"; + +sub lock_config { + my ($code, $errmsg) = @_; + + my $p = PVE::Tools::lock_file($lockfile, undef, $code); + if (my $err = $@) { + $errmsg ? die "$errmsg: $err" : die $err; + } +} + + +__PACKAGE__->register(); +__PACKAGE__->init(); + +sub read_pmg_pbs_conf { + my ($filename, $fh) = @_; + + local $/ = undef; # slurp mode + + my $raw = defined($fh) ? <$fh> : ''; + + return __PACKAGE__->parse_config($filename, $raw); +} + +sub write_pmg_pbs_conf { + my ($filename, $fh, $cfg) = @_; + + my $raw = __PACKAGE__->write_config($filename, $cfg); + + PVE::Tools::safe_print($filename, $fh, $raw); +} + +PVE::INotify::register_file($inotify_file_id, $config_filename, + \&read_pmg_pbs_conf, + \&write_pmg_pbs_conf, + undef, + always_call_parser => 1); + +1; -- 2.20.1