mirror of
https://github.com/cirruslabs/orchard.git
synced 2026-09-30 03:51:43 +02:00
Support "tart run"'s --net-softnet-allow and --net-softnet-block (#361)
* Support "tart run"'s --net-softnet-allow and --net-softnet-block * Use ghcr.io/cirruslabs/macos-tahoe-base:latest by default
This commit is contained in:
@@ -20,6 +20,8 @@ var cpu uint64
|
||||
var memory uint64
|
||||
var diskSize uint64
|
||||
var netSoftnet bool
|
||||
var netSoftnetAllow []string
|
||||
var netSoftnetBlock []string
|
||||
var netBridged string
|
||||
var headless bool
|
||||
var nested bool
|
||||
@@ -47,6 +49,12 @@ func newCreateVMCommand() *cobra.Command {
|
||||
command.Flags().Uint64Var(&diskSize, "disk-size", 0, "resize the VMs disk to the specified size in GB "+
|
||||
"(no resizing is done by default and VM's image default size is used)")
|
||||
command.Flags().BoolVar(&netSoftnet, "net-softnet", false, "whether to use Softnet network isolation")
|
||||
command.Flags().StringSliceVar(&netSoftnetAllow, "net-softnet-allow", []string{},
|
||||
"comma-separated list of CIDRs to allow the traffic to when using Softnet isolation, see "+
|
||||
"\"tart run\"'s help for \"--net-softnet-block\" for more details; automatically enables --net-softnet")
|
||||
command.Flags().StringSliceVar(&netSoftnetBlock, "net-softnet-block", []string{},
|
||||
"comma-separated list of CIDRs to block the traffic to when using Softnet isolation, see "+
|
||||
"\"tart run\"'s help for \"--net-softnet-block\" for more details; automatically enables --net-softnet")
|
||||
command.Flags().StringVar(&netBridged, "net-bridged", "", "whether to use Bridged network mode")
|
||||
command.Flags().BoolVar(&headless, "headless", true, "whether to run without graphics")
|
||||
command.Flags().BoolVar(&nested, "nested", false, "enable nested virtualization")
|
||||
@@ -101,19 +109,22 @@ func runCreateVM(cmd *cobra.Command, args []string) error {
|
||||
Meta: v1.Meta{
|
||||
Name: name,
|
||||
},
|
||||
Image: image,
|
||||
CPU: cpu,
|
||||
Memory: memory,
|
||||
DiskSize: diskSize,
|
||||
NetSoftnet: netSoftnet,
|
||||
NetBridged: netBridged,
|
||||
Headless: headless,
|
||||
Nested: nested,
|
||||
Username: username,
|
||||
Password: password,
|
||||
RandomSerial: randomSerial,
|
||||
Labels: labels,
|
||||
HostDirs: hostDirs,
|
||||
Image: image,
|
||||
CPU: cpu,
|
||||
Memory: memory,
|
||||
DiskSize: diskSize,
|
||||
NetSoftnetDeprecated: netSoftnet,
|
||||
NetSoftnet: netSoftnet,
|
||||
NetSoftnetAllow: netSoftnetAllow,
|
||||
NetSoftnetBlock: netSoftnetBlock,
|
||||
NetBridged: netBridged,
|
||||
Headless: headless,
|
||||
Nested: nested,
|
||||
Username: username,
|
||||
Password: password,
|
||||
RandomSerial: randomSerial,
|
||||
Labels: labels,
|
||||
HostDirs: hostDirs,
|
||||
}
|
||||
|
||||
// Convert resources
|
||||
|
||||
@@ -92,7 +92,9 @@ func runGetVM(cmd *cobra.Command, args []string) error {
|
||||
|
||||
table.AddRow("Disk size", diskSize)
|
||||
|
||||
table.AddRow("Softnet enabled", vm.NetSoftnet)
|
||||
table.AddRow("Softnet enabled", vm.NetSoftnetDeprecated || vm.NetSoftnet)
|
||||
table.AddRow("Softnet allowed CIDRs", strings.Join(vm.NetSoftnetAllow, "\n"))
|
||||
table.AddRow("Softnet blocked CIDRs", strings.Join(vm.NetSoftnetBlock, "\n"))
|
||||
table.AddRow("Bridged networking interface", nonEmptyOrNone(vm.NetBridged))
|
||||
table.AddRow("Headless mode", vm.Headless)
|
||||
table.AddRow("Nested virtualization", vm.Nested)
|
||||
|
||||
@@ -43,6 +43,13 @@ func (controller *Controller) createVM(ctx *gin.Context) responder.Responder {
|
||||
vm.RestartCount = 0
|
||||
vm.UID = uuid.New().String()
|
||||
|
||||
// Softnet-specific logic: automatically enable Softnet when NetSoftnetAllow or NetSoftnetBlock are set
|
||||
// and propagate deprecated and non-deprecated boolean fields into each other
|
||||
if vm.NetSoftnetDeprecated || vm.NetSoftnet || len(vm.NetSoftnetAllow) != 0 || len(vm.NetSoftnetBlock) != 0 {
|
||||
vm.NetSoftnetDeprecated = true
|
||||
vm.NetSoftnet = true
|
||||
}
|
||||
|
||||
// Provide resource defaults
|
||||
if vm.Resources == nil {
|
||||
vm.Resources = make(v1.Resources)
|
||||
|
||||
@@ -1,3 +1,3 @@
|
||||
package imageconstant
|
||||
|
||||
const DefaultMacosImage = "ghcr.io/cirruslabs/macos-sequoia-base:latest"
|
||||
const DefaultMacosImage = "ghcr.io/cirruslabs/macos-tahoe-base:latest"
|
||||
|
||||
@@ -336,9 +336,15 @@ func (vm *VM) cloneAndConfigure(ctx context.Context) error {
|
||||
func (vm *VM) run(ctx context.Context) error {
|
||||
var runArgs = []string{"run"}
|
||||
|
||||
if vm.Resource.NetSoftnet {
|
||||
if vm.Resource.NetSoftnetDeprecated || vm.Resource.NetSoftnet {
|
||||
runArgs = append(runArgs, "--net-softnet")
|
||||
}
|
||||
if len(vm.Resource.NetSoftnetAllow) != 0 {
|
||||
runArgs = append(runArgs, "--net-softnet-allow", strings.Join(vm.Resource.NetSoftnetAllow, ","))
|
||||
}
|
||||
if len(vm.Resource.NetSoftnetBlock) != 0 {
|
||||
runArgs = append(runArgs, "--net-softnet-block", strings.Join(vm.Resource.NetSoftnetBlock, ","))
|
||||
}
|
||||
if vm.Resource.NetBridged != "" {
|
||||
runArgs = append(runArgs, fmt.Sprintf("--net-bridged=%s", vm.Resource.NetBridged))
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user