two/conf/agent/config.exemple.yml
GnomeZworc e00f456610
All checks were successful
Release Pipeline / set-release-target (push) Successful in 1s
Release Pipeline / upload-assets (agent.service, systemd/agent.service) (push) Successful in 3s
Release Pipeline / upload-assets (dhcp@.service, systemd/dhcp@.service) (push) Successful in 3s
Release Pipeline / upload-assets (dnsmasq@.service, systemd/dnsmasq@.service) (push) Successful in 3s
Release Pipeline / upload-assets (metadata@.service, systemd/metadata@.service) (push) Successful in 3s
Release Pipeline / upload-assets (run-dhcp-in-netns.sh, scripts/run-dhcp-in-netns.sh) (push) Successful in 3s
Release Pipeline / upload-assets (run-dnsmasq-in-netns.sh, scripts/run-dnsmasq-in-netns.sh) (push) Successful in 3s
Release Pipeline / build (metadata, amd64, linux) (push) Successful in 0s
Release Pipeline / build (agent, amd64, linux) (push) Successful in 0s
Release Pipeline / build (dhcp, amd64, linux) (push) Successful in 0s
Release Pipeline / checksums (push) Successful in 4s
Release Pipeline / release (push) Successful in 11s
Release Pipeline / build (push) Successful in 1m5s
Release Pipeline / publish (push) Successful in 0s
f-46: dhcp: add the dhcp binary, its unit and its wrapper #46
cmd/dhcp reçoit quatre paramètres en clair — interface, state, socket, conf —
sur le modèle de dnsmasq. Il ne compose aucun chemin, ne découpe aucun nom
composite et ignore le netns dans lequel il tourne : seul le wrapper en a besoin,
pour y entrer.

La boucle de lecture UDP est écrite à la main plutôt que confiée à
server4.Serve, qui lance une goroutine par datagramme sans borne et ne pose
aucun recover. Elle traite en ligne, réutilise un tampon de 1500 octets et pose
un recover par datagramme. NewIPv4UDPConn est conservé pour le SO_BROADCAST et
le bind à l'interface. Une réponse destinée à un client sans adresse part en
broadcast.

dhcp.run_dir n'est pas une clé de configuration : le wrapper code /run/two/dhcp
en dur et le Go utilise dhcpapi.DefaultRunDir, comme dhcp.DefaultConfDir pour
dnsmasq. Un test lit le script et vérifie que les deux s'accordent.

Le défaut dhcp.backend reste dnsmasq : un agent.yml de 0.1.0 se comporte comme
avant. deploy.sh et le pipeline publient le binaire, l'unit et le script.

La boucle est testée sur une vraie socket UDP en loopback. Neuf mutations, dont
une qui a révélé que le recover n'était couvert par rien.

Signed-off-by: GnomeZworc <nicolas.boufidjeline@g3e.fr>
2026-09-05 23:17:59 +02:00

82 lines
2.4 KiB
YAML

# Path to the Badger key-value database directory
database:
path: "/var/lib/two/data/"
# REST API server
api:
address: "0.0.0.0"
port: 8080
# Prometheus metrics server
prometheus:
address: "0.0.0.0"
port: 9090
# Worker pool that executes dispatched commands
worker:
# Number of concurrent worker goroutines
count: 4
# Maximum number of commands queued before Dispatch blocks
buffer_size: 100
# Timing for commands that wait on resource state transitions
dispatcher:
# How long (in seconds) to wait before giving up
timeout_seconds: 300
# Interval (in seconds) between each state check
poll_seconds: 2
# Bridge interface used when the requested iface_type is not found in interfaces
default_interface: br-000000
# Map of logical interface types to physical bridge names on this host
interfaces:
vms: br-000000
internet: br-000000
admin: br-000000
# Metadata server runtime directory (cloud-init files per VM)
metadata:
run_dir: "/run/two/metadata"
# DHCP backend used for the subnets created by this agent.
# dnsmasq : dnsmasq@ instances driven by generated config files
# two : the built-in dhcp binary, driven over a unix socket
# Switching backends is a manual operation: drain the hypervisor, change this
# value, restart the agent. There is no hot migration.
# The per-subnet control socket and state file live in /run/two/dhcp, which is
# not configurable: the wrapper script hardcodes it too.
dhcp:
backend: dnsmasq
# QEMU runtime paths
qemu:
# UEFI firmware (requires apt install ovmf on Debian/Ubuntu)
ovmf_code_path: "/usr/share/OVMF/OVMF_CODE.fd"
ovmf_vars_template: "/usr/share/OVMF/OVMF_VARS.fd"
# Per-VM UEFI variable store (writable copy, created at start / deleted at stop)
uefi_vars_dir: "/run/two/vms/efi"
# QEMU Unix socket directories
serial_dir: "/run/two/vms/serial"
monitor_dir: "/run/two/vms/monitor"
qmp_dir: "/run/two/vms/qmp"
# Consistency watchdog: periodically checks that resources marked running in the
# database still exist on the system, and reports the gaps. Read-only, never repairs.
# A persisting gap is reported at every tick (no deduplication).
watchdog:
enabled: true
interval_seconds: 60
# Admin API (read-only DB inspection, loopback only)
admin:
enabled: false
address: "127.0.0.1"
port: 9091
# Logging configuration
logger:
# Log level: debug, info, warn, error (default: info)
level: info
# Force debug level regardless of level setting (default: false)
debug: false