Total Pageviews

Showing posts with label vmware. Show all posts
Showing posts with label vmware. Show all posts

Monday, 26 August 2024

Custom NAT Gateway and DNS for VMware Fusion



由于电脑使用了 Surge 并开启了 Enhanced Mode 来做全局透明代理,现在希望 VMware Fusion 的虚拟机也自动使用这个代理。其实打开 Enhanced Mode 之后无需配置虚拟机即可直接享受透明代理的。但是这样在 Surge Dashboard 中看到的所有连接都是来源于 vmnet-natd 这个进程,十分不方便监控。

为此,可以手动在虚拟机中修改网关和 DNS 服务器来使 Surge 能够分辨出流量来自哪台虚拟机。但这在我的场景下还是有点麻烦,因为需要不停的重装虚拟机等操作,每一次都需要重新配置。本文将介绍如何修改 VMware Fusion 的 vmnet-dhcpd 配置文件来使虚拟机自动获取自定义的网关和 DNS 服务器。

Modify dhcpd.conf

此处假定需要修改的是默认 NAT 虚拟网络的配置,即 vmnet8 其它自定义网络同理(桥接除外)。配置文件位于 /Library/Preferences/VMware Fusion/vmnet8/dhcpd.conf ,里面的内容主体如下:

###### VMNET DHCP Configuration. Start of "DO NOT MODIFY SECTION" #####
# ...

# Written at: 02/22/2020 01:40:51
allow unknown-clients;
default-lease-time 1800;                # default is 30 minutes
max-lease-time 7200;                    # default is 2 hours

subnet 172.16.69.0 netmask 255.255.255.0 {
    ...
    option domain-name-servers 172.16.69.2;
    ...
    option routers 172.16.69.2;
}
...
####### VMNET DHCP Configuration. End of "DO NOT MODIFY SECTION" #######

注意其中被 DO NOT MODIFY SECTION 包起来的部分,这一部分信息是根据 /Library/Preferences/VMware Fusion/networking 自动生成的,如子网网段等配置,而我需要修改的是其中 domain-name-servers 和 routers 两个 networking 文件中无法配置的选项。因此,我们需要在这个 section 之后复制一段 subnet 的配置,将其中的两个选项改成自定义的值即可:

###### VMNET DHCP Configuration. Start of "DO NOT MODIFY SECTION" #####
# ...

# Written at: 02/22/2020 01:40:51
allow unknown-clients;
default-lease-time 1800;                # default is 30 minutes
max-lease-time 7200;                    # default is 2 hours

subnet 172.16.69.0 netmask 255.255.255.0 {
    ...
    option domain-name-servers 172.16.69.2;
    ...
    option routers 172.16.69.2;
}
...
####### VMNET DHCP Configuration. End of "DO NOT MODIFY SECTION" #######
subnet 172.16.69.0 netmask 255.255.255.0 {
    ...
    option domain-name-servers 198.18.0.2;
    ...
    option routers 172.16.69.1;
}

这样一来,在 VMware Fusion 重启之后改配置也将得到保留,且会覆盖其自动生成的 subnet 配置。注意若之后通过任何方式修改了 vmnet8 的 DHCP 子网网段,此处也需要手动修改。

Reconfigure Virtual Network

接下来需要重启 vmnet-dhcpd 使配置生效,这需要借助 VMware Fusion 自带的 vmnet-cli 工具。如果 Fusion 是通过 brew cask 安装的 ,那么它已经被软链接到 PATH 之中了;否则可以在 /Applications/VMware Fusion.app/Contents/Library/vmnet-cli 找到它。

依次执行如下命令即可:

# alias vmnet-cli='/Applications/VMware Fusion.app/Contents/Library/vmnet-cli'
sudo vmnet-cli --stop
sudo vmnet-cli --configure
sudo vmnet-cli --start

至此,在虚拟机中禁用再开启相应网卡,即可自动获取新的配置了。

Wednesday, 8 April 2020

Open vSwitch


https://travis-ci.org/openvswitch/ovs.png https://ci.appveyor.com/api/projects/status/github/openvswitch/ovs?branch=master&svg=true&retina=true 

What is Open vSwitch?

Open vSwitch is a multilayer software switch licensed under the open source Apache 2 license. Our goal is to implement a production quality switch platform that supports standard management interfaces and opens the forwarding functions to programmatic extension and control.
Open vSwitch is well suited to function as a virtual switch in VM environments. In addition to exposing standard control and visibility interfaces to the virtual networking layer, it was designed to support distribution across multiple physical servers. Open vSwitch supports multiple Linux-based virtualization technologies including Xen/XenServer, KVM, and VirtualBox.
The bulk of the code is written in platform-independent C and is easily ported to other environments. The current release of Open vSwitch supports the following features:
  • Standard 802.1Q VLAN model with trunk and access ports
  • NIC bonding with or without LACP on upstream switch
  • NetFlow, sFlow(R), and mirroring for increased visibility
  • QoS (Quality of Service) configuration, plus policing
  • Geneve, GRE, VXLAN, STT, and LISP tunneling
  • 802.1ag connectivity fault management
  • OpenFlow 1.0 plus numerous extensions
  • Transactional configuration database with C and Python bindings
  • High-performance forwarding using a Linux kernel module
The included Linux kernel module supports Linux 3.10 and up.
Open vSwitch can also operate entirely in userspace without assistance from a kernel module. This userspace implementation should be easier to port than the kernel-based switch. OVS in userspace can access Linux or DPDK devices. Note Open vSwitch with userspace datapath and non DPDK devices is considered experimental and comes with a cost in performance.

What's here?

The main components of this distribution are:
  • ovs-vswitchd, a daemon that implements the switch, along with a companion Linux kernel module for flow-based switching.
  • ovsdb-server, a lightweight database server that ovs-vswitchd queries to obtain its configuration.
  • ovs-dpctl, a tool for configuring the switch kernel module.
  • Scripts and specs for building RPMs for Citrix XenServer and Red Hat Enterprise Linux. The XenServer RPMs allow Open vSwitch to be installed on a Citrix XenServer host as a drop-in replacement for its switch, with additional functionality.
  • ovs-vsctl, a utility for querying and updating the configuration of ovs-vswitchd.
  • ovs-appctl, a utility that sends commands to running Open vSwitch daemons.
Open vSwitch also provides some tools:
  • ovs-ofctl, a utility for querying and controlling OpenFlow switches and controllers.
  • ovs-pki, a utility for creating and managing the public-key infrastructure for OpenFlow switches.
  • ovs-testcontroller, a simple OpenFlow controller that may be useful for testing (though not for production).
  • A patch to tcpdump that enables it to parse OpenFlow messages.

What other documentation is available?

To install Open vSwitch on a regular Linux or FreeBSD host, please read the installation guide. For specifics around installation on a specific platform, refer to one of the other installation guides
For answers to common questions, refer to the FAQ.
To learn about some advanced features of the Open vSwitch software switch, read the tutorial.

Each Open vSwitch userspace program is accompanied by a manpage. Many of the manpages are customized to your configuration as part of the build process, so we recommend building Open vSwitch before reading the manpages.

Tuesday, 19 November 2019

ESXi and Mini PC

The last choice of home network solution.


Intro

Four years ago, I replaced my Xiaomi router to Netgear R6300v2 since I need to run Shadowsocks on my router. After that, I bought a Mac mini and built a 15TB RAID storage system. I found that my network could only reach 20Mbps through Shadowsocks due to poor CPU performance of my Netgear R6300v2 after China Telecom offered me 100Mbps FTTH. I tried to add a fan to cool down the temperature but it's to no avail. Finally I replaced my router once again with a mini pc with four ethernet port and few UniFi AP.
An OpenWrt is running in mini PC and a HASS and UniFi Controller is running in my Mac mini. I found that it's a waste of performance only running a OpenWrt in my dual core Celeron CPU, 4G RAM mini PC. Finally I found ESXi, a bare-metal hypervisor that installs directly onto a physical server. I'm going to install ESXi on my mini PC and all OS will be running in virtual machine.

Install ESXi

First you can download VMware vSphere Hypervisor (ESXi ISO) image for free after you registered for it.
You can know about your devices compatibility in VMware Compatibility Guide. There is some third party driver for ESXi. You can customize your own ISO with drivers that are not originally included using ESXi-Customizer.
If you forget to integrate SATA driver in to your ISO image, you can follow this instruction.

Install Virtual System

There is two way to install an operating system in ESXi. One is installing from an ISO image. The other is convert existing img file to an ESXi compatible vmdk file.

Setup ESXi network

If you want use setup a router OS (eg. OpenWrt, RouterOS, iKuai) in your ESXi, you have setup at lease two vSwitch, one is for LAN and the other is for WAN. And the last thing you need to do is add port group to a vSwitch.
It's recommended to set two network card with static IP and DHCP. So that you can reach your ESXi system easily as an LAN device via DHCP. And you can reach via static IP in case your router OS is broken.

Setup Additional Entropy

How to Setup Additional Entropy for Cloud Servers Using Haveged

Install UniFi Controller on Ubuntu

It's recommended to use Ubuntu 14.04 LTS.

Thanks

Saturday, 20 July 2019

vSphere Integrated Containers

vSphere Integrated Containers Engine is a container runtime for vSphere. 

vSphere Integrated Containers Engine (VIC Engine) is a container runtime for vSphere, allowing developers familiar with Docker to develop in containers and deploy them alongside traditional VM-based workloads on vSphere clusters, and allowing for these workloads to be managed through the vSphere UI in a way familiar to existing vSphere admins.
See VIC Engine Architecture for a high level overview.

Support and Troubleshooting

For general questions, visit the vSphere Integrated Containers Engine channel. If you do not have an @vmware.com or @emc.com email address, sign up at https://code.vmware.com/join to get an invitation.

Project Status

VIC Engine now provides:
  • support for most of the Docker commands for core container, image, volume and network lifecycle operations. Several docker compose commands are also supported. See the complete list of supported commands here.
  • vCenter support, leveraging DRS for initial placement. vMotion is also supported.
  • volume support for standard datastores such as vSAN and iSCSI datastores. NFS shares are also supported. See --volume-store - SIOC is not integrated but can be set as normal.
  • direct mapping of vSphere networks --container-network - NIOC is not integrated but can be set as normal.
  • dual-mode management - IP addresses are reported as normal via vSphere UI, guest shutdown via the UI will trigger delivery of container STOPSIGNAL, restart will relaunch container process.
  • client authentication - basic authentication via client certificates known as tlsverify.
  • integration with the VIC Management Portal (Admiral) for Docker image content trust.
  • integration with the vSphere Platform Services Controller (PSC) for Single Sign-on (SSO) for docker commands such as docker login.
  • an install wizard in the vSphere HTML5 client, as a more interactive alternative to installing via the command line. See details here.
  • support for a standard Docker Container Host (DCH) deployed and managed as a container on VIC Engine. This can be used to run docker commands that are not currently supported by VIC Engine (docker build, docker push). See details here.
We are working hard to add functionality while building out our foundation so continue to watch the repo for new features. Initial focus is on the production end of the CI pipeline, building backwards towards developer laptop scenarios.

Installing

After building the binaries (see the Building section), pick up the correct binary based on your OS, and install the Virtual Container Host (VCH) with the following command. For Linux:
bin/vic-machine-linux create --target <target-host>[/datacenter] --image-store <datastore name> --name <vch-name> --user <username> --password <password> --thumbprint <certificate thumbprint> --compute-resource <cluster or resource pool name> --tls-cname <FQDN, *.wildcard.domain, or static IP>
See vic-machine-$OS create --help for usage information. A more in-depth example can be found here.

Deleting

The installed VCH can be deleted using vic-machine-$OS delete.
See vic-machine-$OS delete --help for usage information. A more in-depth example can be found here.

Contributing

See CONTRIBUTING for details on submitting changes and the contribution workflow.

Building

Building the project is done with a combination of make and containers, with gcr.io/eminent-nation-87317/vic-build-image:tdnf being the common container base. This requires Docker installed. If gcr.io is not accessible you can follow the steps in Dockerfile to build this image.
To build as closely as possible to the formal build, you need the Go 1.8 toolchain and Drone.io installed:
drone exec
To build inside a Docker container:
docker run -v $GOPATH/bin:/go/bin -v $(pwd):/go/src/github.com/vmware/vic gcr.io/eminent-nation-87317/vic-build-image:tdnf make all
To build directly, you also need the Go 1.8 toolchain installed:
make all
There are three primary components generated by a full build, found in $BIN (the ./bin directory by default). The make targets used are the following:
  1. vic-machine - make vic-machine
  2. appliance.iso - make appliance
  3. bootstrap.iso - make bootstrap

Building binaries for development

Some of the project binaries can only be built on Linux. If you are developing on a Mac or Windows OS, then the easiest way to facilitate a build is by utilizing the project's Vagrantfile. The Vagrantfile will share the directory where the file is executed and set the GOPATH based on that share.
To build the component binaries, ensure GOPATH is set, then issue the following command in the root directory:
make components
This will install required tools and build the component binaries tether-linux, rpctool and server binaries docker-engine-server, port-layer-server. The binaries will be created in the $BIN directory, ./bin by default.
To run unit tests after a successful build, issue the following:
make test
Running "make" every time causes Go dependency regeneration for each component, so that "make" can rebuild only those components that are changed. However, such regeneration may take significant amount of time when it is not really needed. To fight that developers can use cached dependencies that can be enabled by defining the environment variable VIC_CACHE_DEPS. As soon as it is set, infra/scripts/go-deps.sh will read cached version of dependencies if those exist.
export VIC_CACHE_DEPS=1
This is important to note that as soon as you add a new package or an internal project dependency that didn't exist before, those dependencies should be regenerated to reflect latest changes. It can be done just by running:
make cleandeps
After that next "make" run will regenerate dependencies from scratch.
To enable generation of non-stripped binaries, the following environment variable can be set:
export VIC_DEBUG_BUILD=true

Updating the appliance with newly built binaries

After building any of the binaries for the appliance VM (vicadmin, vic-init, port-layer-server, or the docker personality), run make push to replace the binaries on your VCH with the newly built ones.
make push will prompt you for information that it needs, or you can set your GOVC environment variables, as well as VIC_NAME (name of your VCH) and VIC_KEY with a path to your SSH key in order to run make push noninteractively.
Replace individual components with one of: make push-portlayer, make push-vicadmin, make push-docker, or make push-vic-init.

Managing vendor/ directory

To build the VIC Engine dependencies, ensure GOPATH is set, then issue the following.
make gvt vendor
This will install the gvt utility and retrieve the build dependencies via gvt restore.

Building the ISOs

The component binaries above are packaged into ISO files, appliance.iso and bootstrap.iso, that are used by the installer. The generation of the ISOs is split into the following targets:
iso-base, appliance-staging, bootstrap-staging, appliance, and bootstrap
Generation of the ISOs involves authoring a new root filesystem, meaning running a package manager (currently tdnf) and packing/unpacking archives. This is done with gcr.io/eminent-nation-87317/vic-build-image:tdnf being the build container. This requires Docker installed. If gcr.io is not accessible you can follow the steps in Dockerfile to build this image. To generate the ISOs:
make isos
The appliance and bootstrap ISOs are bootable CD images used to start the VMs that make up VIC Engine. To build the image, issue the following.
docker run -v $(pwd):/go/src/github.com/vmware/vic gcr.io/eminent-nation-87317/vic-build-image:tdnf make isos
The iso image will be created in $BIN

Building Custom ISOs

Please reference this document to build your custom isos.

Building with CI

PRs to this repository will trigger builds on our Drone CI.
To build locally with Drone:
Ensure that you have Docker 1.6 or higher installed. Install the Drone command line tools. From the root directory of the vic repository run drone exec

Common Build Problems

  1. Builds may fail when building either the appliance.iso or bootstrap.iso with the error: cap_set_file failed - Operation not supported
    Cause: Some Ubuntu and Debian based systems ship with a defective aufs driver, which Docker uses as its default backing store. This driver does not support extended file capabilities such as cap_set_file
    Solution: Edit the /etc/default/docker file, add the option --storage-driver=overlay to the DOCKER_OPTSsettings, and restart Docker.
  2. go vet fails when doing a make all
    Cause: Apparently some caching takes place in $GOPATH/pkg/linux_amd64/github.com/vmware/vic and can cause go vet to fail when evaluating outdated files in this cache.
    Solution: Delete everything under $GOPATH/pkg/linux_amd64/github.com/vmware/vic and re-run make all.
  3. vic-machine upgrade integration tests fail due to BUILD_NUMBER being set incorrectly when building locally
    Cause: vic-machine checks the build number of its binary to determine upgrade status and a locally-built vic-machine binary may not have the BUILD_NUMBER set correctly. Upon running vic-machine upgrade, it may fail with the message foo-VCH has same or newer version x than installer version y. No upgrade is available.
    Solution: Set BUILD_NUMBER to a high number at the top of the Makefile - BUILD_NUMBER ?= 9999999999. Then, re-build binaries - sudo make distclean && sudo make clean && sudo make all and run vic-machine upgrade with the new binary.

Integration Tests

VIC Engine Integration Test Suite includes instructions to run locally.

Debugging with DLV

VIC Engine DLV Debugging with DLV includes instruction on how to use dlv.

Saturday, 11 November 2017

VMware-tools for Linux之安裝筆記

有一些人在討論如何安裝 VMware-tools for Linux。
分享一下我的做法,希望對需要的人有幫助。

先前我的問題是找不到 vmware-linux-tools.tag.gz

以下是我的做法:

我的環境:Windows 2000 Pro (host),Debian Linux (client)
真實的環境:Win2k and Debian Dual boot。

在 Windows 下安裝 VMware 時,它 default 的安裝目錄為 C:\Program Files\VMware\VMware Workstation。
在裡面有 linux.iso。

安裝 VMware tools for Linux 的部分 (用Windows 開機):
1. 在 Linux client cdrom 的設定, 讓它使用 C:\Program Files\VMware\VMware Workstatio\linux.iso 這個檔案
2. 開始 Linux virtual machine
3. 在 text mode 的情況下,login linux as root

$ mount /mnt/cdrom (你 cdrom 的 mount point 可能會不一樣)
$ cd /mnt/cdrom
$ mkdir /root/temp
$ cp vmware-linux-tools.tag.gz /root/temp
$ cd /root/temp
$ umount /mnt/cdrom
$ tar xzvf vmware-linux-tools.tag.gz
$ cd vmware-tools-distrib
$ ./vmware-install.pl

4. 接下來跟著指令做就 ok 了
5. 有可能會要 compile kernel module (depends on your kernel version)
6. 它會幫你 compile module,不過你會需要 kernel-source,kernel-header,and gcc installed

after all this,you can remove "/root/temp"

在 Client machine,share folder 會出現在 /mnt/hgfs/folder

在 Windows host 和 Linux client 下是 ok 的。
在 Linux host 和 Linux client 還在測試中...

參考:
http://www.vmware.com/support/ws45/doc/new_guest_tools_ws.html#1008207