public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Stefan Hanreich <s.hanreich@proxmox.com>
To: pve-devel@lists.proxmox.com
Subject: [pve-devel] [PATCH pve-manager 3/8] pvestatd: add network resource to status reporting
Date: Thu, 30 Oct 2025 16:48:37 +0100	[thread overview]
Message-ID: <20251030154851.540408-31-s.hanreich@proxmox.com> (raw)
In-Reply-To: <20251030154851.540408-1-s.hanreich@proxmox.com>

From: Gabriel Goller <g.goller@proxmox.com>

The new network resource will act as the top-level resource for all
SDN / networking entities. The network resource contains a
network_type field, which indicates the type of networking resource -
similar to how the storage plugin handles different types of storages.
For now, it only contains SDN fabrics.

In the future, SDN zones, which are currently contained in the sdn
resource, will move to the network resource as well. To prepare for
this move, add support for the zone type in the API endpoint. To make
extending the resource with additional types easier, we ignore all
unknown network types in the API endpoint, so a node only returns the
types of network resources it can handle. This allows for easily
adding new types of network resources, without having to worry about
backwards-compatibility.

The main reason for moving over to a new resource type is the current
ID schema of the SDN resource, which is 'sdn/{zone_id}'. This makes it
hard to extend without the possibility of ID collisions. Additionally,
since the ID is used in several places throughout the backend / UI,
changing the schema would break compatibility with nodes that are on
an earlier version and would be an API break as well.

Co-authored-by: Stefan Hanreich <s.hanreich@proxmox.com>
Signed-off-by: Gabriel Goller <g.goller@proxmox.com>
Signed-off-by: Stefan Hanreich <s.hanreich@proxmox.com>
---
 PVE/API2/Cluster.pm     | 62 ++++++++++++++++++++++++++++++++++++++++-
 PVE/Service/pvestatd.pm | 17 +++++++++++
 2 files changed, 78 insertions(+), 1 deletion(-)

diff --git a/PVE/API2/Cluster.pm b/PVE/API2/Cluster.pm
index 479803960..34523fd7e 100644
--- a/PVE/API2/Cluster.pm
+++ b/PVE/API2/Cluster.pm
@@ -251,7 +251,8 @@ __PACKAGE__->register_method({
                 type => {
                     description => "Resource type.",
                     type => 'string',
-                    enum => ['node', 'storage', 'pool', 'qemu', 'lxc', 'openvz', 'sdn'],
+                    enum =>
+                        ['node', 'storage', 'pool', 'qemu', 'lxc', 'openvz', 'sdn', 'network'],
                 },
                 status => {
                     description => "Resource type dependent status.",
@@ -431,6 +432,23 @@ __PACKAGE__->register_method({
                     optional => 1,
                     default => 0,
                 },
+                network => {
+                    description => "The name of a Network entity (for type 'network').",
+                    type => "string",
+                    optional => 1,
+                },
+                network_type => {
+                    description => "The type of network resource (for type 'network').",
+                    type => "string",
+                    enum => ["fabric"],
+                    optional => 1,
+                },
+                protocol => {
+                    description =>
+                        "The protocol of a fabric (for type 'network', network_type 'fabric').",
+                    type => "string",
+                    optional => 1,
+                },
             },
         },
     },
@@ -620,6 +638,48 @@ __PACKAGE__->register_method({
             }
         }
 
+        if (!$param->{type} || $param->{type} eq 'network') {
+            my $nodes = PVE::Cluster::get_node_kv("network");
+
+            for my $node (sort keys $nodes->%*) {
+                my $node_config = decode_json($nodes->{$node});
+
+                for my $id (sort keys $node_config->%*) {
+                    my $entry = $node_config->{$id};
+
+                    if ($entry->{network_type} eq 'fabric') {
+                        next
+                            if !$rpcenv->check_any(
+                                $authuser,
+                                "/sdn/fabrics/$entry->{network}",
+                                ['SDN.Audit', 'SDN.Allocate'],
+                                1,
+                            );
+                    } elsif ($entry->{network_type} eq 'zone') {
+                        next
+                            if !$rpcenv->check(
+                                $authuser,
+                                "/sdn/zones/$entry->{network}",
+                                ['SDN.Audit'],
+                                1,
+                            );
+                    } else {
+                        # unknown type, so most likely introduced in a newer
+                        # version - avoid leaking information by suppressing any
+                        # unknown sdn types in the returned array.
+                        next;
+                    }
+
+                    push $res->@*,
+                        {
+                            "id" => "network/$node/$entry->{network_type}/$entry->{network}",
+                            "node" => $node,
+                            $entry->%*,
+                        };
+                }
+            }
+        }
+
         return $res;
     },
 });
diff --git a/PVE/Service/pvestatd.pm b/PVE/Service/pvestatd.pm
index 618d6139a..862bf8b43 100755
--- a/PVE/Service/pvestatd.pm
+++ b/PVE/Service/pvestatd.pm
@@ -15,6 +15,7 @@ use PVE::CpuSet;
 use Filesys::Df;
 use PVE::INotify;
 use PVE::Network;
+use PVE::RS::SDN::Fabrics;
 use PVE::NodeConfig;
 use PVE::Cluster qw(cfs_read_file);
 use PVE::Storage;
@@ -775,6 +776,18 @@ sub update_sdn_status {
     }
 }
 
+sub update_network_status {
+    my ($fabric_status) = PVE::RS::SDN::Fabrics::status();
+
+    my $network_status = {};
+
+    for my $fabric (values $fabric_status->%*) {
+        $network_status->{"fabric/$fabric->{network}"} = $fabric;
+    }
+
+    PVE::Cluster::broadcast_node_kv("network", encode_json($network_status));
+}
+
 my $broadcast_version_info_done = 0;
 my sub broadcast_version_info : prototype() {
     if (
@@ -840,6 +853,10 @@ sub update_status {
     $err = $@;
     syslog('err', "sdn status update error: $err") if $err;
 
+    eval { update_network_status(); };
+    $err = $@;
+    syslog('err', "network status update error: $err") if $err;
+
     eval { broadcast_version_info(); };
     $err = $@;
     syslog('err', "version info update error: $err") if $err;
-- 
2.47.3


_______________________________________________
pve-devel mailing list
pve-devel@lists.proxmox.com
https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel


  parent reply	other threads:[~2025-10-30 15:59 UTC|newest]

Thread overview: 36+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2025-10-30 15:48 [pve-devel] [PATCH common/manager/network/proxmox{-ve-rs, -perl-rs} 00/35] Improve status reporting for SDN / networking Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-common 1/2] iproute2: add helper for detecting bridge members Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-common 2/2] iproute2: add helper for querying vlan information Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 1/6] frr: make room for deserialization structs Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 2/6] frr: add deserialization types for openfabric and ospf Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 3/6] ve-config: add helper function to iterate over all nodes in all fabrics Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 4/6] ve-config: add optional tag property to vnet Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 5/6] frr: fix some route deserialization types Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-ve-rs 6/6] frr: add deserialization types for EVPN Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 01/10] pve-rs: firewall: cargo: fmt Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 02/10] pve-rs: firewall: add missing documentation comments Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 03/10] pve-rs: cargo: bump proxmox-apt and proxmox-ve-config versions Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 04/10] pve-rs: fabrics: update proxmox-frr import path Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 05/10] pve-rs: fabrics: fix clippy lint warnings Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 06/10] pve-rs: fabrics: add function to get status of fabric Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 07/10] pve-rs: fabrics: add function to get l2vpn and l3vpn routes for evpn Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 08/10] pve-rs: fabrics: add function to get routes learned by a fabric Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 09/10] pve-rs: fabrics: add function to get the interfaces used for " Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH proxmox-perl-rs 10/10] pve-rs: fabrics: add function to get the neighbors " Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 1/9] refactor: rework api module structure for the /nodes/{node}/sdn subdir Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 2/9] fabrics: add fabrics status to SDN::status function Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 3/9] sdn: status: add zone type to sdn resource Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 4/9] api: nodes: fabrics: add endpoint for querying route status Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 5/9] api: nodes: fabrics: add endpoint for querying neighbor information Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 6/9] api: nodes: fabrics: add endpoint for querying interface status Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 7/9] api: nodes: zones: add bridge status Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 8/9] api: nodes: zones: add ip vrf endpoint for evpn zones Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-network 9/9] api: nodes: vnets: add mac-vrf endpoint for evpn vnets Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 1/8] api: nodes: use new status module for sdn subdirectory Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 2/8] refactor: ui: sdn browser: parametrize zone content panel Stefan Hanreich
2025-10-30 15:48 ` Stefan Hanreich [this message]
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 4/8] pvestatd: sdn: adapt to changes in status reporting Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 5/8] ui: resource tree: add network resource Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 6/8] ui: sdn browser: Add ip-vrf panel for evpn zones Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 7/8] ui: sdn browser: add mac vrf panel Stefan Hanreich
2025-10-30 15:48 ` [pve-devel] [PATCH pve-manager 8/8] ui: sdn browser: add zone bridge view Stefan Hanreich

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20251030154851.540408-31-s.hanreich@proxmox.com \
    --to=s.hanreich@proxmox.com \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal