From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) by lore.proxmox.com (Postfix) with ESMTPS id C68451FF15C for ; Wed, 8 Jan 2025 13:10:39 +0100 (CET) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 87762189BA; Wed, 8 Jan 2025 13:10:13 +0100 (CET) To: pve-devel@lists.proxmox.com Date: Wed, 8 Jan 2025 13:08:59 +0100 In-Reply-To: <20250108120903.5344-1-lou.lecrivain@wdz.de> References: <20250108120903.5344-1-lou.lecrivain@wdz.de> MIME-Version: 1.0 Message-ID: List-Id: Proxmox VE development discussion List-Post: From: Lou Lecrivain via pve-devel Precedence: list Cc: Lou Lecrivain X-Mailman-Version: 2.1.29 X-BeenThere: pve-devel@lists.proxmox.com List-Subscribe: , List-Unsubscribe: , List-Archive: Reply-To: Proxmox VE development discussion List-Help: Subject: [pve-devel] SPAM: [PATCH pve-network v2 4/7] ipam: nautobot: base plugin + enhance errors Content-Type: multipart/mixed; boundary="===============3093552435131125721==" Errors-To: pve-devel-bounces@lists.proxmox.com Sender: "pve-devel" --===============3093552435131125721== Content-Type: message/rfc822 Content-Disposition: inline Return-Path: X-Original-To: pve-devel@lists.proxmox.com Delivered-To: pve-devel@lists.proxmox.com Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits)) (No client certificate requested) by lists.proxmox.com (Postfix) with ESMTPS id 67042CB061 for ; Wed, 8 Jan 2025 13:10:12 +0100 (CET) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id 42601184D1 for ; Wed, 8 Jan 2025 13:09:42 +0100 (CET) Received: from smtp.smtpout.orange.fr (smtp-72.smtpout.orange.fr [80.12.242.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by firstgate.proxmox.com (Proxmox) with ESMTPS for ; Wed, 8 Jan 2025 13:09:41 +0100 (CET) Received: from localhost ([176.139.8.107]) by smtp.orange.fr with ESMTPA id VUsTt0gcHv8EoVUsWtUuwP; Wed, 08 Jan 2025 13:09:41 +0100 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=orange.fr; s=t20230301; t=1736338181; bh=RtP68yo0AgLRdm/hr7QK4+10OS70KL4wev4mq1UcAaw=; h=From:To:Subject:Date:Message-Id:MIME-Version; b=o9JQNq/sDyFjAxQmLykvTPzb5vEGSLulaDVp8UpBt49KYVzK2cG8ffLQg6Mrjpgto plbhhU07z8GJc3q6kgpXh3VkKdjquLEKxN8ybWerVJko8RHbOOxWLrmY5Ufwzy+xVp RXgxEgWtHA7BcFIDYyakHutUMG+Es+xb/FaG241yJrnPmLl782eS9tQEh/N8f6NThy 7GaivfNhDAHaMSK61EPaHtZzQ8dtdAxZ1KAgxqYEpgyLjRlaNktYWDMnUkL35Fu+vV 6Fn04JDEiZGvMhtyNoeWgcc8NsL791Dr2Y2MWT0SbXTLNppfq3mN9gaKfuxerYU4aA t9G2KCW3iOBAQ== X-ME-Helo: localhost X-ME-Auth: bG91LmxlY3JpdmFpbkBvcmFuZ2UuZnI= X-ME-Date: Wed, 08 Jan 2025 13:09:41 +0100 X-ME-IP: 176.139.8.107 From: Lou Lecrivain To: pve-devel@lists.proxmox.com subject: SPAM: [PATCH pve-network v2 4/7] ipam: nautobot: base plugin + enhance errors Date: Wed, 8 Jan 2025 13:08:59 +0100 Message-Id: <20250108120903.5344-8-lou.lecrivain@wdz.de> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20250108120903.5344-1-lou.lecrivain@wdz.de> References: <20250108120903.5344-1-lou.lecrivain@wdz.de> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-SPAM-LEVEL: Spam detection results: 4 AWL -0.080 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_REJECT 0.1 DMARC reject policy FREEMAIL_FORGED_FROMDOMAIN 0.001 2nd level domains in From and EnvelopeFrom freemail headers are different FREEMAIL_FROM 0.001 Sender email is commonly abused enduser mail provider HEADER_FROM_DIFFERENT_DOMAINS 0.24 From and EnvelopeFrom 2nd level mail domains are different KAM_DMARC_REJECT 6 DKIM has Failed or SPF has failed on the message and the domain has a DMARC reject policy RCVD_IN_DNSWL_NONE -0.0001 Sender listed at https://www.dnswl.org/, no trust RCVD_IN_MSPIKE_H4 0.001 Very Good reputation (+4) RCVD_IN_MSPIKE_WL 0.001 Mailspike good senders SPF_HELO_PASS -0.001 SPF: HELO matches SPF record SPF_PASS -0.001 SPF: sender matches SPF record added error handling in helpers Signed-off-by: lou lecrivain --- src/PVE/Network/SDN/Ipams/NautobotPlugin.pm | 126 ++++++++++++++++++-- 1 file changed, 113 insertions(+), 13 deletions(-) diff --git a/src/PVE/Network/SDN/Ipams/NautobotPlugin.pm b/src/PVE/Network/SDN/Ipams/NautobotPlugin.pm index 22867df..79ac04d 100644 --- a/src/PVE/Network/SDN/Ipams/NautobotPlugin.pm +++ b/src/PVE/Network/SDN/Ipams/NautobotPlugin.pm @@ -7,7 +7,7 @@ use PVE::Cluster; use PVE::Tools; use NetAddr::IP; -use base('PVE::Network::SDN::Ipams::NetboxPlugin'); +use base('PVE::Network::SDN::Ipams::Plugin'); sub type { return 'nautobot'; @@ -51,7 +51,7 @@ sub add_subnet { my $namespace = $plugin_config->{namespace}; my $headers = default_headers($plugin_config); - my $internalid = PVE::Network::SDN::Ipams::NetboxPlugin::get_prefix_id($url, $cidr, $headers); + my $internalid = get_prefix_id($url, $cidr, $headers, $noerr); #create subnet if (!$internalid) { @@ -66,6 +66,27 @@ sub add_subnet { } } +sub del_subnet { + my ($class, $plugin_config, $subnetid, $subnet, $noerr) = @_; + + my $cidr = $subnet->{cidr}; + my $url = $plugin_config->{url}; + my $headers = default_headers($plugin_config); + + my $internalid = get_prefix_id($url, $cidr, $headers, $noerr); + return if !$internalid; + + # TODO check that prefix is empty before deletion + return; + + eval { + PVE::Network::SDN::api_request("DELETE", "$url/ipam/prefixes/$internalid/", $headers); + }; + if ($@) { + die "error deleting subnet in Nautobot: $@" if !$noerr; + } +} + sub add_ip { my ($class, $plugin_config, $subnetid, $subnet, $ip, $hostname, $mac, $vmid, $is_gateway, $noerr) = @_; @@ -89,7 +110,7 @@ sub add_ip { if ($@) { if($is_gateway) { - die "error adding subnet ip to ipam: ip $ip already exists: $@" if !PVE::Network::SDN::Ipams::NetboxPlugin::is_ip_gateway($url, $ip, $headers) && !$noerr; + die "error adding subnet ip to ipam: ip $ip already exists: $@" if !$noerr && !is_ip_gateway($url, $ip, $headers, $noerr); } else { die "error adding subnet ip to ipam: ip $ip already exists: $@" if !$noerr; } @@ -105,7 +126,8 @@ sub add_next_freeip { my $namespace = $plugin_config->{namespace}; my $headers = default_headers($plugin_config); - my $internalid = PVE::Network::SDN::Ipams::NetboxPlugin::get_prefix_id($url, $cidr, $headers); + my $internalid = get_prefix_id($url, $cidr, $headers, $noerr); + die "cannot find prefix $cidr in Nautobot" if !$internalid; my $description = "mac:$mac" if $mac; @@ -133,7 +155,7 @@ sub add_range_next_freeip { # ranges are not supported natively in nautobot, hence why we have to get a little hacky. my $minimal_size = NetAddr::IP->new($range->{'start-address'}) - NetAddr::IP->new($cidr); - my $internalid = PVE::Network::SDN::Ipams::NetboxPlugin::get_prefix_id($url, $cidr, $headers); + my $internalid = get_prefix_id($url, $cidr, $headers, $noerr); my $ip = eval { my $result = PVE::Network::SDN::api_request("GET", "$url/ipam/prefixes/$internalid/available-ips/?limit=$minimal_size", $headers); @@ -174,8 +196,8 @@ sub update_ip { my $params = { address => "$ip/$mask", type => "dhcp", dns_name => $hostname, description => $description, namespace => $namespace, status => default_ip_status()}; - my $ip_id = PVE::Network::SDN::Ipams::NetboxPlugin::get_ip_id($url, $ip, $headers); - die "can't find ip $ip in ipam" if !$ip_id; + my $ip_id = get_ip_id($url, $ip, $headers, $noerr); + die "can't find ip $ip in ipam" if !$noerr && !$ip_id; eval { PVE::Network::SDN::api_request("PATCH", "$url/ipam/ip-addresses/$ip_id/", $headers, $params); @@ -186,6 +208,26 @@ sub update_ip { } +sub del_ip { + my ($class, $plugin_config, $subnetid, $subnet, $ip, $noerr) = @_; + + return if !$ip; + + my $url = $plugin_config->{url}; + my $headers = default_headers($plugin_config); + + my $ip_id = get_ip_id($url, $ip, $headers, $noerr); + die "can't find ip $ip in ipam" if !$ip_id && !$noerr; + + eval { + PVE::Network::SDN::api_request("DELETE", "$url/ipam/ip-addresses/$ip_id/", $headers); + }; + if ($@) { + die "error deleting ip $ip : $@" if !$noerr; + } +} + + sub verify_api { my ($class, $plugin_config) = @_; @@ -196,8 +238,8 @@ sub verify_api { # check that the namespace exists AND that default IP active status # exists AND that we have indeed API access eval { - get_namespace_id($url, $namespace, $headers) // die "namespace $namespace does not exist"; - get_status_id($url, default_ip_status(), $headers) // die "default IP status ". default_ip_status() . " not found"; + get_namespace_id($url, $namespace, $headers, 0) // die "namespace $namespace does not exist"; + get_status_id($url, default_ip_status(), $headers, 0) // die "default IP status ". default_ip_status() . " not found"; }; if ($@) { die "Can't use nautobot api: $@"; @@ -242,22 +284,80 @@ sub get_ips_within_range { return grep($start_address <= NetAddr::IP->new($_) <= $end_address, @list); } +sub get_ip_id { + my ($url, $ip, $headers, $noerr) = @_; + + my $result = eval { + return PVE::Network::SDN::api_request("GET", "$url/ipam/ip-addresses/?q=$ip", $headers); + }; + if ($@) { + die "error while querying for ip $ip id: $@" if !$noerr; + } + + my $data = @{$result->{results}}[0]; + my $ip_id = $data->{id}; + return $ip_id; +} + +sub get_prefix_id { + my ($url, $cidr, $headers, $noerr) = @_; + + my $result = eval { + return PVE::Network::SDN::api_request("GET", "$url/ipam/prefixes/?q=$cidr", $headers); + }; + if ($@) { + die "error while querying for cidr $cidr prefix id: $@" if !$noerr; + } + + my $data = @{$result->{results}}[0]; + my $internalid = $data->{id}; + return $internalid; +} + sub get_namespace_id { - my ($url, $namespace, $headers) = @_; + my ($url, $namespace, $headers, $noerr) = @_; + + my $result = eval { + return PVE::Network::SDN::api_request("GET", "$url/ipam/namespaces/?q=$namespace", $headers); + }; + if ($@) { + die "error while querying for namespace $namespace id: $@" if !$noerr; + } - my $result = PVE::Network::SDN::api_request("GET", "$url/ipam/namespaces/?q=$namespace", $headers); my $data = @{$result->{results}}[0]; my $internalid = $data->{id}; return $internalid; } sub get_status_id { - my ($url, $status, $headers) = @_; + my ($url, $status, $headers, $noerr) = @_; + + my $result = eval { + return PVE::Network::SDN::api_request("GET", "$url/extras/statuses/?q=$status", $headers); + }; + if ($@) { + die "error while querying for status $status id: $@" if !$noerr; + } - my $result = PVE::Network::SDN::api_request("GET", "$url/extras/statuses/?q=$status", $headers); my $data = @{$result->{results}}[0]; my $internalid = $data->{id}; return $internalid; } +sub is_ip_gateway { + my ($url, $ip, $headers, $noerr) = @_; + + my $result = eval { + return PVE::Network::SDN::api_request("GET", "$url/ipam/ip-addresses/?q=$ip", $headers); + }; + if ($@) { + die "error while checking if $ip is a gateway" if !$noerr; + } + + my $data = @{$result->{results}}[0]; + my $description = $data->{description}; + my $is_gateway = 1 if $description eq 'gateway'; + return $is_gateway; +} + 1; -- 2.39.5 --===============3093552435131125721== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ pve-devel mailing list pve-devel@lists.proxmox.com https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel --===============3093552435131125721==--