opennebula-docker: fix virsh permission

This commit is contained in:
Nico Schottelius 2026-08-19 22:00:15 +02:00
commit 627032fd6c
3 changed files with 141 additions and 0 deletions

View file

@ -0,0 +1,20 @@
FROM debian:trixie
COPY opennebula-virsh /etc/sudoers.d
COPY entrypoint.sh /
RUN apt-get update
RUN apt-get install -y gnupg2 openssh-server strace sudo wget ceph-common
RUN wget -q -O- https://downloads.opennebula.io/repo/repo2.key | gpg --dearmor --yes --output /etc/apt/keyrings/opennebula.gpg
RUN echo "deb [signed-by=/etc/apt/keyrings/opennebula.gpg] https://downloads.opennebula.io/repo/7.1/Debian/13 stable opennebula" > /etc/apt/sources.list.d/opennebula.list
RUN apt-get update && apt-get install -y --no-install-recommends opennebula-node-kvm
RUN mv /usr/bin/virsh /usr/bin/virsh.orig
COPY virsh /usr/bin/virsh
RUN chmod a=rx /usr/bin/virsh
COPY virtlogd.conf /etc/libvirt/virtlogd.conf
RUN chmod a+r /etc/libvirt/virtlogd.conf
ENTRYPOINT ["/entrypoint.sh"]

View file

@ -1,3 +1,6 @@
* 0.4.3, 2026-08-19
- Include virtlogd.conf to log to stderr
- Fix permissions on virsh to be world executable
* 0.4.2, 2026-08-19
- Include virtlogd
* 0.4.1, 2026-08-19

View file

@ -0,0 +1,118 @@
# Master virtlogd daemon configuration file
#
#################################################################
#
# Logging controls
#
# Logging level: 4 errors, 3 warnings, 2 information, 1 debug
# basically 1 will log everything possible
#
# WARNING: USE OF THIS IS STRONGLY DISCOURAGED.
#
# WARNING: It outputs too much information to practically read.
# WARNING: The "log_filters" setting is recommended instead.
#
# WARNING: Journald applies rate limiting of messages and so libvirt
# WARNING: will limit "log_level" to only allow values 3 or 4 if
# WARNING: journald is the current output.
#
# WARNING: USE OF THIS IS STRONGLY DISCOURAGED.
#log_level = 3
# Logging filters:
# A filter allows to select a different logging level for a given category
# of logs. The format for a filter is:
#
# level:match
#
# where 'match' is a string which is matched against the category
# given in the VIR_LOG_INIT() at the top of each libvirt source
# file, e.g., "remote", "qemu", or "util.json". The 'match' in the
# filter matches using shell wildcard syntax (see 'man glob(7)').
# The 'match' is always treated as a substring match. IOW a match
# string 'foo' is equivalent to '*foo*'.
#
# 'level' is the minimal level where matching messages should
# be logged:
#
# 1: DEBUG
# 2: INFO
# 3: WARNING
# 4: ERROR
#
# Multiple filters can be defined in a single @log_filters, they just need
# to be separated by spaces. Note that libvirt performs "first" match, i.e.
# if there are concurrent filters, the first one that matches will be applied,
# given the order in @log_filters.
#
# For the virtlogd daemon, a typical need is to capture information
# from the logging code and some of the utility code. Some utility
# code is very verbose and is generally not desired. A suitable filter
# string for debugging might be to turn off object, json & event logging,
# but enable the rest of the util and the logging code:
#
#log_filters="1:logging 4:object 4:json 4:event 1:util"
# Logging outputs:
# An output is one of the places to save logging information
# The format for an output can be:
# level:stderr
# output goes to stderr
# level:syslog:name
# use syslog for the output and use the given name as the ident
# level:file:file_path
# output to a file, with the given filepath
# level:journald
# output to journald logging system
# In all cases 'level' is the minimal priority, acting as a filter
# 1: DEBUG
# 2: INFO
# 3: WARNING
# 4: ERROR
#
# Multiple outputs can be defined, they just need to be separated by spaces.
# e.g. to log all warnings and errors to syslog under the virtlogd ident:
#log_outputs="3:syslog:virtlogd"
#
# The maximum number of concurrent client connections to allow
# on primary socket
#max_clients = 1024
# The maximum number of concurrent client connections to allow
# on administrative socket
#admin_max_clients = 5
# Maximum file size before rolling over. Defaults to 2 MB
#
# Setting max_size to zero will disable rollover entirely.
# NOTE: disabling rollover exposes the host filesystem to
# denial of service from a malicious guest.
#
# Beware that a logrotate config file might be installed too,
# to handle cases where virtlogd is disabled. To ensure that
# the logrotate config is a no-op when virtlogd is running,
# make sure that max_size here is smaller than size listed
# in the logrotate config.
#max_size = 2097152
# Maximum number of backup files to keep. Defaults to 3,
# not including the primary active file
#max_backups = 3
# Maximum age for log files to live after the last modification.
# Defaults to 0, which means "forever".
#
# WARNING: since virtlogd has no way to differentiate which files it used to
# manage, the garbage collection mechanism will collect ALL files, once its age
# reach max_age_days. Use only if you know what you mean.
#max_age_days = 0
# Root of all logs managed by virtlogd. Used to GC logs from obsolete machines.
#
# WARNING: all files under this location potentially can be GC-ed. See the
# warning for max_age_days.
#log_root = "/var/log/libvirt"
log_outputs="2:stderr"