diff --git a/deploy/00crds.yaml b/deploy/00crds.yaml index c8c69f5..e9963a2 100644 --- a/deploy/00crds.yaml +++ b/deploy/00crds.yaml @@ -2072,9 +2072,7 @@ spec: name: v1alpha1 schema: openAPIV3Schema: - description: |- - ProxyVM is the Schema for a registered Proxy VM used in Hot-Add data copy migrations. - The controller validates SSH connectivity and required components on the referenced VM. + description: ProxyVM is the Schema for the proxyvms API. properties: apiVersion: description: |- @@ -2096,12 +2094,28 @@ spec: spec: description: ProxyVMSpec defines the desired state of ProxyVM properties: + sshKeyPairRef: + description: |- + LocalObjectReference contains enough information to let you locate the + referenced object inside the same namespace. + properties: + name: + default: "" + description: |- + Name of the referent. + This field is effectively required, but due to backwards compatibility is + allowed to be empty. Instances of this type with an empty value here are + almost certainly wrong. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + type: object + x-kubernetes-map-type: atomic vmName: - description: VMName is the display name of the Proxy VM in vCenter. type: string vmwareCredsRef: - description: VMwareCredsRef references the VMwareCreds used to locate - and connect to the Proxy VM. + description: |- + LocalObjectReference contains enough information to let you locate the + referenced object inside the same namespace. properties: name: default: "" @@ -2122,27 +2136,17 @@ spec: description: ProxyVMStatus defines the observed state of ProxyVM properties: attachedDiskCount: - description: |- - AttachedDiskCount is the number of source-snapshot disks currently attached - to this Proxy VM across all active Hot-Add migrations. Max 60. type: integer componentsVerified: - description: ComponentsVerified lists each required component and - whether it was found. items: description: ProxyVMComponentCheck records whether a required component was found on the Proxy VM. properties: message: - description: Message provides detail for missing components. type: string name: - description: Name is the component name (e.g. "lsblk", "qemu-nbd", - "sshd"). type: string present: - description: Present indicates whether the component was found - in PATH. type: boolean required: - name @@ -2150,21 +2154,13 @@ spec: type: object type: array ipAddress: - description: IPAddress is the IP address discovered from vCenter guest - info. type: string lastValidationTime: - description: LastValidationTime records when the last verification - completed. format: date-time type: string validationMessage: - description: ValidationMessage contains a human-readable summary of - the last validation result. type: string validationStatus: - description: 'ValidationStatus is one of: Pending, Verifying, Ready, - VerificationFailed.' type: string type: object type: object @@ -2857,6 +2853,12 @@ spec: items: type: string type: array + openstackServerGroup: + description: |- + OpenstackServerGroup is the ID of the OpenStack server group used for VM placement scheduling. + When set, the agent VM is placed according to the server group's policy. + If empty, default OpenStack scheduling applies. + type: string openstackVolumeType: description: |- OpenstackVolumeType is the volume type for the root disk of the VM diff --git a/deploy/04ui.yaml b/deploy/04ui.yaml index f0a62cb..5149224 100644 --- a/deploy/04ui.yaml +++ b/deploy/04ui.yaml @@ -20,6 +20,10 @@ spec: imagePullPolicy: IfNotPresent ports: - containerPort: 80 + envFrom: + - configMapRef: + name: pf9-env + optional: true volumeMounts: - name: pf9-logs mountPath: /var/log/pf9 diff --git a/deploy/05controller-deployment.yaml b/deploy/05controller-deployment.yaml index 20951eb..813c1ff 100644 --- a/deploy/05controller-deployment.yaml +++ b/deploy/05controller-deployment.yaml @@ -41,7 +41,8 @@ spec: envFrom: - configMapRef: name: pf9-env - image: quay.io/platform9/vjailbreak-controller:v0.4.6 + optional: true + image: quay.io/platform9/vjailbreak-controller:v0.4.7 imagePullPolicy: IfNotPresent lifecycle: preStop: diff --git a/deploy/06vpwned-deployment.yaml b/deploy/06vpwned-deployment.yaml index ee6b8a3..0f2a756 100644 --- a/deploy/06vpwned-deployment.yaml +++ b/deploy/06vpwned-deployment.yaml @@ -20,20 +20,41 @@ spec: type: RollingUpdate template: metadata: + annotations: + container.apparmor.security.beta.kubernetes.io/vpwned: unconfined labels: app: vpwned-sdk spec: + affinity: + nodeAffinity: + requiredDuringSchedulingIgnoredDuringExecution: + nodeSelectorTerms: + - matchExpressions: + - key: node-role.kubernetes.io/control-plane + operator: Exists containers: - - envFrom: + - env: + - name: DBUS_SYSTEM_BUS_ADDRESS + value: unix:path=/run/dbus/system_bus_socket + envFrom: - configMapRef: name: pf9-env - image: quay.io/platform9/vjailbreak-vpwned:v0.4.6 + optional: true + image: quay.io/platform9/vjailbreak-vpwned:v0.4.7 imagePullPolicy: IfNotPresent name: vpwned ports: - containerPort: 3001 protocol: TCP resources: {} + securityContext: + allowPrivilegeEscalation: false + capabilities: + add: + - DAC_OVERRIDE + drop: + - ALL + runAsUser: 0 terminationMessagePath: /dev/termination-log terminationMessagePolicy: File volumeMounts: @@ -42,6 +63,18 @@ spec: readOnly: true - mountPath: /home/ubuntu name: vddk-storage + - mountPath: /run/dbus/system_bus_socket + name: dbus-socket + - mountPath: /etc/systemd/timesyncd.conf.d + name: timesyncd-conf-dir + - mountPath: /usr/share/zoneinfo + name: host-zoneinfo + readOnly: true + - mountPath: /etc/pf9 + name: pf9-config + - mountPath: /var/log/pf9 + name: pf9-logs + readOnly: true dnsConfig: options: - name: ndots @@ -61,4 +94,24 @@ spec: path: /home/ubuntu type: DirectoryOrCreate name: vddk-storage + - hostPath: + path: /run/dbus/system_bus_socket + type: Socket + name: dbus-socket + - hostPath: + path: /etc/systemd/timesyncd.conf.d + type: DirectoryOrCreate + name: timesyncd-conf-dir + - hostPath: + path: /usr/share/zoneinfo + type: Directory + name: host-zoneinfo + - hostPath: + path: /etc/pf9 + type: Directory + name: pf9-config + - hostPath: + path: /var/log/pf9 + type: DirectoryOrCreate + name: pf9-logs --- \ No newline at end of file diff --git a/deploy/07ui-deployment.yaml b/deploy/07ui-deployment.yaml index adce031..b956d36 100644 --- a/deploy/07ui-deployment.yaml +++ b/deploy/07ui-deployment.yaml @@ -24,23 +24,20 @@ spec: serviceAccountName: ui-manager-sa containers: - name: vjailbreak-ui-container - image: quay.io/platform9/vjailbreak-ui:v0.4.6 + image: quay.io/platform9/vjailbreak-ui:v0.4.7 imagePullPolicy: IfNotPresent ports: - containerPort: 80 + envFrom: + - configMapRef: + name: pf9-env + optional: true volumeMounts: - name: nginx-shadow-htpasswd mountPath: /etc/nginx/shadow - - name: pf9-logs - mountPath: /var/log/pf9 - readOnly: true volumes: - name: nginx-shadow-htpasswd hostPath: path: /etc/htpasswd type: FileOrCreate - - name: pf9-logs - hostPath: - path: /var/log/pf9 - type: DirectoryOrCreate --- \ No newline at end of file diff --git a/deploy/installer.yaml b/deploy/installer.yaml index 692c588..7bb0788 100644 --- a/deploy/installer.yaml +++ b/deploy/installer.yaml @@ -2072,9 +2072,7 @@ spec: name: v1alpha1 schema: openAPIV3Schema: - description: |- - ProxyVM is the Schema for a registered Proxy VM used in Hot-Add data copy migrations. - The controller validates SSH connectivity and required components on the referenced VM. + description: ProxyVM is the Schema for the proxyvms API. properties: apiVersion: description: |- @@ -2096,12 +2094,28 @@ spec: spec: description: ProxyVMSpec defines the desired state of ProxyVM properties: + sshKeyPairRef: + description: |- + LocalObjectReference contains enough information to let you locate the + referenced object inside the same namespace. + properties: + name: + default: "" + description: |- + Name of the referent. + This field is effectively required, but due to backwards compatibility is + allowed to be empty. Instances of this type with an empty value here are + almost certainly wrong. + More info: https://kubernetes.io/docs/concepts/overview/working-with-objects/names/#names + type: string + type: object + x-kubernetes-map-type: atomic vmName: - description: VMName is the display name of the Proxy VM in vCenter. type: string vmwareCredsRef: - description: VMwareCredsRef references the VMwareCreds used to locate - and connect to the Proxy VM. + description: |- + LocalObjectReference contains enough information to let you locate the + referenced object inside the same namespace. properties: name: default: "" @@ -2122,27 +2136,17 @@ spec: description: ProxyVMStatus defines the observed state of ProxyVM properties: attachedDiskCount: - description: |- - AttachedDiskCount is the number of source-snapshot disks currently attached - to this Proxy VM across all active Hot-Add migrations. Max 60. type: integer componentsVerified: - description: ComponentsVerified lists each required component and - whether it was found. items: description: ProxyVMComponentCheck records whether a required component was found on the Proxy VM. properties: message: - description: Message provides detail for missing components. type: string name: - description: Name is the component name (e.g. "lsblk", "qemu-nbd", - "sshd"). type: string present: - description: Present indicates whether the component was found - in PATH. type: boolean required: - name @@ -2150,21 +2154,13 @@ spec: type: object type: array ipAddress: - description: IPAddress is the IP address discovered from vCenter guest - info. type: string lastValidationTime: - description: LastValidationTime records when the last verification - completed. format: date-time type: string validationMessage: - description: ValidationMessage contains a human-readable summary of - the last validation result. type: string validationStatus: - description: 'ValidationStatus is one of: Pending, Verifying, Ready, - VerificationFailed.' type: string type: object type: object @@ -2857,6 +2853,12 @@ spec: items: type: string type: array + openstackServerGroup: + description: |- + OpenstackServerGroup is the ID of the OpenStack server group used for VM placement scheduling. + When set, the agent VM is placed according to the server group's policy. + If empty, default OpenStack scheduling applies. + type: string openstackVolumeType: description: |- OpenstackVolumeType is the volume type for the root disk of the VM @@ -4738,7 +4740,8 @@ spec: envFrom: - configMapRef: name: pf9-env - image: quay.io/platform9/vjailbreak-controller:v0.4.6 + optional: true + image: quay.io/platform9/vjailbreak-controller:v0.4.7 imagePullPolicy: IfNotPresent lifecycle: preStop: @@ -4825,20 +4828,41 @@ spec: type: RollingUpdate template: metadata: + annotations: + container.apparmor.security.beta.kubernetes.io/vpwned: unconfined labels: app: vpwned-sdk spec: + affinity: + nodeAffinity: + requiredDuringSchedulingIgnoredDuringExecution: + nodeSelectorTerms: + - matchExpressions: + - key: node-role.kubernetes.io/control-plane + operator: Exists containers: - - envFrom: + - env: + - name: DBUS_SYSTEM_BUS_ADDRESS + value: unix:path=/run/dbus/system_bus_socket + envFrom: - configMapRef: name: pf9-env - image: quay.io/platform9/vjailbreak-vpwned:v0.4.6 + optional: true + image: quay.io/platform9/vjailbreak-vpwned:v0.4.7 imagePullPolicy: IfNotPresent name: vpwned ports: - containerPort: 3001 protocol: TCP resources: {} + securityContext: + allowPrivilegeEscalation: false + capabilities: + add: + - DAC_OVERRIDE + drop: + - ALL + runAsUser: 0 terminationMessagePath: /dev/termination-log terminationMessagePolicy: File volumeMounts: @@ -4847,6 +4871,18 @@ spec: readOnly: true - mountPath: /home/ubuntu name: vddk-storage + - mountPath: /run/dbus/system_bus_socket + name: dbus-socket + - mountPath: /etc/systemd/timesyncd.conf.d + name: timesyncd-conf-dir + - mountPath: /usr/share/zoneinfo + name: host-zoneinfo + readOnly: true + - mountPath: /etc/pf9 + name: pf9-config + - mountPath: /var/log/pf9 + name: pf9-logs + readOnly: true dnsConfig: options: - name: ndots @@ -4866,6 +4902,26 @@ spec: path: /home/ubuntu type: DirectoryOrCreate name: vddk-storage + - hostPath: + path: /run/dbus/system_bus_socket + type: Socket + name: dbus-socket + - hostPath: + path: /etc/systemd/timesyncd.conf.d + type: DirectoryOrCreate + name: timesyncd-conf-dir + - hostPath: + path: /usr/share/zoneinfo + type: Directory + name: host-zoneinfo + - hostPath: + path: /etc/pf9 + type: Directory + name: pf9-config + - hostPath: + path: /var/log/pf9 + type: DirectoryOrCreate + name: pf9-logs --- apiVersion: networking.k8s.io/v1 kind: Ingress @@ -4921,25 +4977,22 @@ spec: serviceAccountName: ui-manager-sa containers: - name: vjailbreak-ui-container - image: quay.io/platform9/vjailbreak-ui:v0.4.6 + image: quay.io/platform9/vjailbreak-ui:v0.4.7 imagePullPolicy: IfNotPresent ports: - containerPort: 80 + envFrom: + - configMapRef: + name: pf9-env + optional: true volumeMounts: - name: nginx-shadow-htpasswd mountPath: /etc/nginx/shadow - - name: pf9-logs - mountPath: /var/log/pf9 - readOnly: true volumes: - name: nginx-shadow-htpasswd hostPath: path: /etc/htpasswd type: FileOrCreate - - name: pf9-logs - hostPath: - path: /var/log/pf9 - type: DirectoryOrCreate --- apiVersion: v1 kind: Service diff --git a/image_builder/configs/env b/image_builder/configs/env index 6e53f80..030a6fb 100644 --- a/image_builder/configs/env +++ b/image_builder/configs/env @@ -1,4 +1,5 @@ # This file is used to set environment variables to be injected into v2v-helper # User can populate this file via cloud-init +TZ=UTC diff --git a/image_builder/configs/vjailbreak-settings.yaml b/image_builder/configs/vjailbreak-settings.yaml index bb63cad..1d70e67 100644 --- a/image_builder/configs/vjailbreak-settings.yaml +++ b/image_builder/configs/vjailbreak-settings.yaml @@ -20,9 +20,11 @@ data: VMWARE_CREDS_REQUEUE_AFTER_MINUTES: "60" # number of minutes to requeue after for vmware creds VALIDATE_RDM_OWNER_VMS: "true" # validate RDM owner VMs before migration DEPLOYMENT_NAME: vJailbreak + TIMEZONE: "" PERIODIC_SYNC_MAX_RETRIES: "3" # max number of retries for CBT sync PERIODIC_SYNC_RETRY_CAP: "3h" # max retry interval for CBT sync AUTO_FSTAB_UPDATE: "true" # automatically update fstab + DEFAULT_NETWORK_PERSISTENCE: "false" # default value for persist source network interfaces in migration form AUTO_PXE_BOOT_ON_CONVERSION: "false" # automatically set machine to PXE boot during cluster conversion V2V_HELPER_POD_CPU_REQUEST: "1000m" V2V_HELPER_POD_MEMORY_REQUEST: "2Gi" @@ -30,5 +32,7 @@ data: V2V_HELPER_POD_MEMORY_LIMIT: "5Gi" V2V_HELPER_POD_EPHEMERAL_STORAGE_REQUEST: "3Gi" V2V_HELPER_POD_EPHEMERAL_STORAGE_LIMIT: "3Gi" + NTP_SERVERS: "" HTTP_TIMEOUT_SECONDS: "30" # timeout for http calls in seconds + PROXY_VM_OVA_URL: "https://vjailbreak-dev.s3.us-west-2.amazonaws.com/hot-add/ha-proxy-vm.ova" # OVA template URL for deploying the Hot-Add Proxy VM diff --git a/releases/v0.4.7.md b/releases/v0.4.7.md new file mode 100644 index 0000000..fc04d73 --- /dev/null +++ b/releases/v0.4.7.md @@ -0,0 +1,69 @@ +# v0.4.7 + +- **Tag:** `v0.4.7` +- **Published:** 2026-07-02T10:52:42Z +- **Source release:** https://github.com/platform9/vjailbreak/releases/tag/v0.4.7 + +## Release Notes + +## What's Changed +* Fixed the missing --binding-profile '{"l2-port": true}' on ports created for VMs migrated onto L2-only networks in PCD by @spai-p9 in https://github.com/platform9/vjailbreak/pull/2015 +* [2007] Fix fstab rewrite incorrectly activating commented bind-mount entries by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/2011 +* [1058] Configure NTP servers and system timezone for the vJailbreak VM directly from the UI by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/1742 +* [1915] Added persist source network interfaces as a global setting by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2025 +* Detect if we are using virtio-scsi controller for windows and pass --blockdriver for conversion by @spai-p9 in https://github.com/platform9/vjailbreak/pull/2027 +* [1812] Fix volume cleanup when CreateTargetInstance times out by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/2026 +* [1975] Hot-Add Proxy VM UX improvements by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/2023 +* [1996] upgrade core components with guest OS migration fixes by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/2031 +* [1970] Add server group selection for agent scale-up to control placement affinity by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2032 +* [1979] VM selection refresh button now revalidates VMware credentials by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2034 +* [1872] Verify volume bootable state after SetBootable timeout by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2035 +* prebake proxy VM OVA into appliance image by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/2038 +* Fix: Check hardware version and migration type only then check for cbt by @spai-p9 in https://github.com/platform9/vjailbreak/pull/2037 +* [1980] Enhance user experience with new UI by @AbhijeetThakur in https://github.com/platform9/vjailbreak/pull/2040 +* UI side changes for Hot add proxy improvements by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/2030 +* Rename Firstboot-Scheduler.ps1 to 0-Firstboot-Scheduler.ps1 by @noaboa97 in https://github.com/platform9/vjailbreak/pull/1994 +* fix(v2v-helper): repair broken build on main by @valentin-pf9 in https://github.com/platform9/vjailbreak/pull/1945 +* [1750] UI for edit and retry by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2024 +* [2044] Consolidate edit-and-retry into single Retry action by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2021 +* #2047 : Need UI enhancement in hot add proxy changes by @AbhijeetThakur in https://github.com/platform9/vjailbreak/pull/2048 +* [2050] Optimize retry flow and add bulk retry by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2049 +* [2052] Fix Windows firstboot loop by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/2056 +* [1915] Added persist source network interfaces as a global setting by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2058 +* [2054] fix(retry): prefilled IP overrides not shown in Assign IP dialog on retry form by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2059 +* [2062] fix - ssh keypair name missmatch by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/2060 +* #2051: Converting disk shows copy disk inside the migration details page by @AbhijeetThakur in https://github.com/platform9/vjailbreak/pull/2063 +* #2067: Block/Grey out the already registered proxy vm, this could mismatch the secret by @AbhijeetThakur in https://github.com/platform9/vjailbreak/pull/2070 +* [2079] Fix ProxyVM showing Ready status while SSH validation is failing by @meghansh-pf9 in https://github.com/platform9/vjailbreak/pull/2080 +* #2068 #2078 #2069: VM is in conversion state but it shows Hot add transfer in UI and stuck in validating state by @AbhijeetThakur in https://github.com/platform9/vjailbreak/pull/2074 +* [2077] Fix: Reset to Defaults must skip NTP server & timezone while migration running by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2084 +* #2088: [UI] Windows VM should be blocked for selection as a proxy VM by @AbhijeetThakur in https://github.com/platform9/vjailbreak/pull/2089 +* [2093] feat: add debug-bundle API to vpwned by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2090 +* #2082: Debug logs, yamls are not present in logs fetched using log download button by @AbhijeetThakur in https://github.com/platform9/vjailbreak/pull/2092 +* Fix Host Entries tab: duplicate description text and low-visibility button by @sarika-pf9 in https://github.com/platform9/vjailbreak/pull/2099 + +## New Contributors +* @noaboa97 made their first contribution in https://github.com/platform9/vjailbreak/pull/1994 +* @valentin-pf9 made their first contribution in https://github.com/platform9/vjailbreak/pull/1945 + +## Highlights +**Migration details page**: Added new page which shows in depth state monitoring for migration lifecycle. + +**Vjailbreak Proxy**: +* End-to-end UI for registering a Proxy VM (SSH key upload, validation status), selecting Hot-Add as the copy method in the migration form, and monitoring hot-add-specific migration phases +* Verification now auto-installs missing dependencies on the Proxy VM during validation, eliminating the need for manual pre-configuration before registering + +**Advanced Configuration Management** + * Configure **NTP servers** and **system timezone** for vJailbreak VMs directly from the UI. + * Introduced **server group selection** for agent scale-up, enabling better placement and affinity control. + +**Enhanced Retry Experience** + * Introduced a new Edit & Retry capability, allowing users to modify migration settings and retry failed migrations without recreating the migration. + * Simplified recovery with a unified Retry action and support for Bulk Retry, reducing manual effort. + + +## Known Limitations + +**Proxy VM OVA requires ESXi 8.0 U2 or higher**: The bundled OVA template uses virtual hardware version vmx-21, which is incompatible with older ESXi hosts. Attempting to deploy it on ESXi 7.x will fail with an "unsupported hardware family" error. For ESXi 7.x environments, the Proxy VM must be created and configured manually instead of using the OVA deploy option. + +**Full Changelog**: https://github.com/platform9/vjailbreak/compare/v0.4.6...v0.4.7