XCP-ng
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login
    • Profile
    • Following 0
    • Followers 1
    • Topics 3
    • Posts 83
    • Groups 0
    bvitnikB Offline
    1. Home
    2. bvitnik

    bvitnik

    @bvitnik

    40
    Reputation
    2.1k
    Profile views
    83
    Posts
    1
    Followers
    0
    Following
    Joined
    Last Online

    bvitnik Unfollow Follow
    • RE: Custom config / cloud-init

      @Pilow password: as a global option and passwd: or plain_text_passwd: under users: key are two different things. The first one sets the password for the default user, ubuntu on Ubuntu if I recall correctly, while the others set password for the user specified in the users: key.

      Read the docs people 😁

      posted in Management
      bvitnikB
      bvitnik
    • RE: Copy VM with new ID

      What he is talking about is Security Identifier (SID) and is specific to Windows. Each Windows machine must have a unique SID in an AD environment. Cloned machines will have identical SID which is bad.

      The solution to this problem is sysprep, a Windows tool that will reset SID and other parameters so that each Windows installation is uniquely identifiable. This is something done inside a machine, of course, and is not something that can be done on HV level. VMware, and Hyper-V as seen here, have integrated support for invoking sysprep (or equivalent) during the machine cloning process. This is achieved by sending a signal to the management agent inside a machine (e.g. VMware Guest Tools).

      As far as I know, XenServer/XCP-ng management agent is rudimentary and does not have this functionality. In world of XenServer/XCP-ng, machine has to be syspreped manually before it is cloned.

      posted in Management
      bvitnikB
      bvitnik
    • RE: Custom config / cloud-init

      @acebmxer Great. These are some YAML basics. You should read more about it ☺ . Following AI instructions without understanding is not going to take you far.

      posted in Management
      bvitnikB
      bvitnik
    • RE: Ansible with Xen Orchestra

      @john-c

      I feel your pain, however, the main difference between VMware support in Ansible and XenServer/XCP-ng is that VMware has a whole working group with a dozen of regular members and contributors:

      https://github.com/ansible/community/wiki/VMware

      Major contributors are all Red Hat or VMware employees i.e. people paid to do it. There is no such thing for XenServer/XCP-ng. Citrix never showed any interest in supporting Ansible. Netscaler is the only Citrix product that has a decent Ansible support.

      To help you better understand how Ansible as a project works, here are some points from my personal adventure:

      • To be able to contribute new modules to Ansible or any of the official collections, you need to implement extensive unit and integration tests. I understand the requirement. Ansible/Red Hat wants to maintain a high level of quality and to easily (and in automated way) detect any regressions. That's all good but implementing tests is harder and more work than implementing modules themselves. What's very very helpful in case of VMware is that there is a whole simulator called govcsim developed by VMware. You can test your modules against the simulator with ease and automate all the tests with little effort. To my knowledge, there is no simulator available for XenAPI. If such simulator does exist, it is most likely kept in secret by Citrix. If Citrix was ever to release this simulator, that would be a HUGE step forward.
      • If you want to contribute new modules to Ansible or any of the official collections, someone has to review your code. Not many people are willing to do so and have the power to include your code to Ansible. As a matter of fact, finding reviewers and begging them for help is the hardest thing of all. I had some tremendous luck to acquire the interest of Abhijeet Kasurde, one of the top Ansible guys, to review my code and to eventually include xenserver_guest_* modules into Ansible. The guy handles VMware in Ansible... surprise! 😀 My xenserver_guest module was included without any unit or integration tests but for other modules I had to implement them. Luckily, they were simple and I had a luck to find a reviewer for tests also. When I wanted to upgrade xenserver_guest module with new functionality, they required unit and integration tests. I eventually implemented tests for xenserver_guest module but it was a huge undertaking and the amount of code involved easily dwarfed the module itself. I basically ended up implementing a barebone XenAPI simulator. This is where I hit a road block. No one, even the people that initially supported me, wanted to review this monstrosity of test+simulator. It was never included in Ansible.
      • If you don't want to rely on external reviewers then you have to form a team, or if possible, a work group. That way you can review each others code and include it in Ansible without external support. Everything is pretty much handled by bots. If you gain a high enough status in Ansible project, you could get permissions to merge the code yourself without relying on anyone, not even bots. Should I mention that I failed to ever find any good Python programmer that is into Ansible and interested enough to form a team with me?
      • You can skip all this struggle if you just maintain you own collection of modules but then you cannot rely on existing Ansible tooling that will do all the testing, linting, sanity checks, spell checks and such. You are on your own.

      After a lot of struggle I eventually lost any interest as I was wasting a lot of time and life had to go on. Not much people showed interest in xenserver_guest_* Ansible modules either. My employer also ditched XenServer/XCP-ng in favor of VMware a few years back. Even with all the Broadcom/VMware situation, we got a super good deal with Broadcom because of our deployment size and commitment so we are sticking with VMWare.

      All in all, if Ansible support for XenServer/XCP-ng and Xen Orchestra on par with VMware support is ever to see the light of day, these prerequisites are required:

      • Publicly available XenAPI simulator is a must
      • A working group of at least three people with knowledge in Python, Ansible and XenAPI committed to the cause
      • Possibly corporate and financial backing by Citrix, Vates? or some other third party

      Having any official Ansible support for XenServer/XCP-ng was (and is) a miracle to this day. A miracle I was blessed with and a huge learning experience for me.

      Sorry for the long post. It is not my intention to discourage people but I think everyone should understand why XenServer/XCP-ng does not enjoy better Ansible support. There is much much more to it than just having a willingness to do anything.

      posted in Infrastructure as Code
      bvitnikB
      bvitnik
    • RE: XCP-ng 8.0.0 Release Candidate

      Just to confirm. After copying new install.img to my PXE environment, unattended installation went smoothly with my answer file.

      posted in News
      bvitnikB
      bvitnik
    • RE: New project - XenAdminQt - a cross-platform GNU/Linux, macOS, Windows native thick client

      @benapetr This looks phenomenal. Will have to give it a try.

      This is a nice coincidence. Just the other day one of my younger colleagues boasted about making XCP-ng Center work under Wine... everything just works™. It would save a number of folks having to have a Windows VM on stand by just for the XCP-ng Center. Oh boy, how he was disappointed when I showed him everything that does not work 😁 ... but with this, there is still hope.

      posted in News
      bvitnikB
      bvitnik
    • RE: Deploy VMs using Ansible

      A milestone has been achieved 😱 . All of my modules have been merged upstream. I've updated the first post with new info.

      That will most probably be all for Ansible 2.8. I'm keeping some improvements and possibly more modules for Ansible 2.9. Currently, I'm thinking about what other modules could be useful so I could implement them. Any suggestion or wish would be much appreciated.

      posted in Development
      bvitnikB
      bvitnik
    • RE: Booting to Dracut (I trusted ChatGPT)

      @nuentes Oh no, no. Your system is not destroyed beyond repair. It can be repaired. It's just that it is almost impossible or too much of a hustle for anyone to try to help you over forum. Someone has to sit in front of your machine to do it.

      My only guess is that ChatGPT instructed you to make changes based on a CentOS system but XCP-ng and Xen virtualization in general is much different than regular CentOS. It has two stage boot process. First the Xen kernel boots and then a special virtual machine called Dom0 is booted. What you are accessing and reconfiguring is in fact this VM, not the underlying "system". So it's like a two layer system and some configuration must be done on Xen layer, some on Dom0 layer. I'm unfortunately unfamiliar with exact specifics on kernel and initrd image generation for this case so I can't spot where thing have gone wrong.

      In short terms. Instead of going back and forth and trying a lot of different things, it's more time saving and simpler to reinstall the system and restore metadata if you already have a backup.

      posted in XCP-ng
      bvitnikB
      bvitnik
    • RE: Guest running kernel 6.8 hangs after a while

      Has anyone been able to install Ubuntu 24.04 in VM from current official ISO? It seems that official ISOs (i.e. installer) still use unpatched kernel 6.8.0-22. Are there any newer ISO builds that I'm not aware of?

      EDIT:
      Sorry. False alarm. I screwed up my PXE settings. There was some leftover kernel and initrd images from beta versions of ISO. Kernel and initrd from latest ISOs work properly.

      posted in XCP-ng
      bvitnikB
      bvitnik
    • RE: Custom config / cloud-init

      @acebmxer Did you do:

      cloud-init clean --logs --seed
      

      before converting the VM to template?

      Also, network configuration is not part of the cloud-config (aka user data). In XO, there is a separate field called "Network config" where it should be specified. See examples at the end of the guide I pasted earlier. network: key should also be removed (commented in the examples).

      posted in Management
      bvitnikB
      bvitnik
    • RE: cloud-init Cloud Config use of {name}

      @bug-meister Ah. That's cloud-init's support for templating user-data. The issue is that with these templates you only have access to the info available inside the VM itself. No outside data can be used for templating unless it is somehow passed to the VM (inject a file, set xenstore values...)

      posted in Infrastructure as Code
      bvitnikB
      bvitnik
    • RE: cloud-init Cloud Config use of {name}

      @bug-meister Nope. This is not Jinja nor any other kind of templating engine. This is a simple search-and-replace kind of implementation and is limited to name and %, the later being VM index. From the docs:

      Xen Orchestra offers the ability to insert variables such as the virtual machine name {name} or a virtual machine index %. However, the expressive power is limited to the graphical interface. For instance, it is not possible to build a series of virtual machines with complex values or from external data.

      Reference:

      • https://docs.xcp-ng.org/guides/create-use-custom-xcpng-ubuntu-templates/

      In other words, there is no advanced templating of cloud-init configuration but you could probably template it outside XenOrchestra and apply it via Terraform:

      • https://registry.terraform.io/providers/vatesfr/xenorchestra/latest/docs/resources/vm
      posted in Infrastructure as Code
      bvitnikB
      bvitnik
    • RE: XCP-ng 8.3 updates announcements and testing

      @TeddyAstie Thanks

      posted in News
      bvitnikB
      bvitnik
    • RE: XCP-ng 8.3 updates announcements and testing

      @gleh said:

      Disable Viridian in the "Other install media" template by default. As a reminder, Windows VMs must use Windows templates.

      What is the rationale for disabling Viridian? Does it have any negative effects for non Windows VMs?

      posted in News
      bvitnikB
      bvitnik
    • RE: HA causes reboot of xcp-ng nodes

      @carloum70 I can't really help you with anything specific but I must make a note that when analyzing network setup you must also take into account the Open vSwitch. Looking at the classic Linux networking, bridging and routing facilities is not enough to get you the full picture.

      For example, if I remember correctly, Active-Active bonding (non LACP) is implemented by Open vSwitch with so called balance-slb mode. This mode is not available with classic Linux kernel bonding options. What you are seeing (duplicated IPs) is maybe perfectly normal for this kind of setup with Open vSwitch.

      I would search for the cause of the issue somewhere else like network congestion. Heart beats are very sensitive to network congestion and can easily fail if you do not dedicate network links for this kind of traffic. If you are sharing the links over which heart beats are sent with some high traffic stuff (storage maybe?), it can easily make problems.

      UPDATE: unfortunately I don't have access to these kind of bonded setups any more so I can't check if the configuration differs in any way from yours. My home lab thingies are single network interface only.

      posted in Management
      bvitnikB
      bvitnik
    • RE: How to reliably determine VDI format (vhd, qcow2, raw) via XAPI across versions

      @dthenot Thanks a lot for the information. I did some more testing on my end and I've now noticed differences in handling VDI format across different SR types (local LVM and EXT). Should I expect even more differences across remote SR types like LVMoHBA or NFS or are these differences more like block based vs file system based SRs?

      Any way, it looks like I have to consult the following keys:

      • image-format
      • vdi_type
      • type

      In my tests, local EXT SRs tend to have only one of them, while local LVM SRs tend to have first two or all three, depends which one was used when creating the VDI.

      posted in Development
      bvitnikB
      bvitnik
    • RE: How to reliably determine VDI format (vhd, qcow2, raw) via XAPI across versions

      @dthenot Aaaaah, so it even depends on the SR type. That also explains the difference I'm seeing in my lab with 8.1 vs 8.3. The first one uses LVM backed SR and the other one uses file system (ext) backed SR.

      I'll have to investigate this a little bit more.

      Was image-format key added by you (XCP-ng team) and is specific to XCP-ng or was it used at any point in XenServer also?

      posted in Development
      bvitnikB
      bvitnik
    • How to reliably determine VDI format (vhd, qcow2, raw) via XAPI across versions

      Hi,

      It has come to my attention that in recent times there was some change in how VDI format is tracked in XAPI database, especially with arrival of QCOW2 support, first in XenServer (GFS2 SRs only) and then in XCP-ng 8.3 (other SR types).

      Currently, I have access to XCP-ng 8.1 and 8.3 (with latest updates) and I'm seeing these differences:

      XCP-ng 8.1:

      $ xe vdi-param-list uuid=SOMEUUID
      ...
                     sm-config (MRO): vdi_type: vhd
      ...
      

      XCP-ng 8.3:

      $ xe vdi-param-list uuid=SOMEUUID
      ...
                     sm-config (MRO): image-format: vhd
      ...
      

      So it seems what was earlier vdi_type is now image-format key in the sm-config parameter of a VDI.

      On the other hand, some people are reporting having both keys present in sm-config, e.g.:

      ...
                     sm-config (MRO): image-format: vhd; vdi_type: vhd
      ...
      

      Neither are well documented and I can't find any official info on what keys in sm-config are supported and what is their purpose. Maybe devs can shed some light on this?

      To add to the confusion, official XenServer documentation mentiones a key called just type when creating raw VDIs:

      xe vdi-create sr-uuid=sr-uuid type=user virtual-size=virtual-size \
              name-label=VDI name sm-config:type=raw
      

      In my testing this transparently gets renamed to image-format in the latest version of XCP-ng.

      The reason this bothers me is that I was asked to implement reporting of VDI format in my Ansible modules for XCP-ng but now I'm not sure how to do it across all of the supported versions of XenServer and XCP-ng. Currently it looks like I should try to get vdi_type and fallback to image-format if the first one is not found but I'm not certain if these keys are interchangable and have the same purpose or they just happen to sometimes have the same value. Also, ISO image VDIs seems to be missing any format indication.

      Any info on this subject is well appreciated. Thanks.

      posted in Development
      bvitnikB
      bvitnik
    • RE: New project - XenAdminQt - a cross-platform GNU/Linux, macOS, Windows native thick client

      @Tristis-Oris maybe a few comparative screenshots would help 🙂

      posted in News
      bvitnikB
      bvitnik
    • RE: New project - XenAdminQt - a cross-platform GNU/Linux, macOS, Windows native thick client

      @benapetr just a small notice, at least in 0.0.5 version. When adding an NFS ISO library SR, there is no choice for NFS version (v3 and v4) like in XCP-ng Center. The XAPI then defaults to v3 which did not work in my environment.

      posted in News
      bvitnikB
      bvitnik