2023-05-23 21:38:32 +02:00
|
|
|
"swtpm":
|
|
|
|
|
# Candidate paths for the executable
|
|
|
|
|
"executable": [ "/usr/bin/swtpm" ]
|
|
|
|
|
|
|
|
|
|
# Arguments may be specified as nested lists for better readability.
|
|
|
|
|
# The arguments are flattened before being passed to the process.
|
|
|
|
|
"arguments":
|
|
|
|
|
- "socket"
|
|
|
|
|
- "--tpm2"
|
|
|
|
|
- [ "--tpmstate", "dir=${ runtimeDir }" ]
|
|
|
|
|
- [ "--ctrl", "type=unixio,path=${ runtimeDir }/swtpm-sock,mode=0600" ]
|
|
|
|
|
- "--terminate"
|
|
|
|
|
|
|
|
|
|
"qemu":
|
|
|
|
|
# Candidate paths for the executable
|
|
|
|
|
"executable": [ "/usr/bin/qemu-system-x86_64" ]
|
|
|
|
|
|
|
|
|
|
# Arguments may be specified as nested lists for better readability.
|
|
|
|
|
# The arguments are flattened before being passed to the process.
|
|
|
|
|
# Unless otherwise noted, flags can be found on
|
|
|
|
|
# https://www.qemu.org/docs/master/system/invocation.html
|
|
|
|
|
#
|
|
|
|
|
# Useful links:
|
|
|
|
|
# - https://joonas.fi/2021/02/uefi-pc-boot-process-and-uefi-with-qemu/
|
|
|
|
|
"arguments":
|
2023-05-28 21:35:13 +02:00
|
|
|
# Qemu configuration
|
2023-05-23 21:38:32 +02:00
|
|
|
- "-no-user-config"
|
2023-05-28 21:35:13 +02:00
|
|
|
# * https://www.kernel.org/doc/Documentation/virtual/kvm/api.txt
|
|
|
|
|
- [ "-global", "kvm-pit.lost_tick_policy=delay" ]
|
2023-06-07 15:05:12 +02:00
|
|
|
# * Allow spawn for network setup (tap/bridge)
|
2023-05-28 21:35:13 +02:00
|
|
|
- [ "-sandbox", "on,obsolete=deny,elevateprivileges=deny,\
|
|
|
|
|
spawn=allow,resourcecontrol=deny" ]
|
|
|
|
|
- [ "-msg", "timestamp=on" ]
|
|
|
|
|
# * Qemu monitor connection
|
|
|
|
|
- [ "-chardev", "socket,id=charmonitor,\
|
|
|
|
|
path=${ runtimeDir }/monitor.sock,server=on,wait=off" ]
|
|
|
|
|
- [ "-mon", "chardev=charmonitor,id=monitor,mode=control" ]
|
|
|
|
|
|
|
|
|
|
# VM configuration
|
2023-05-23 21:38:32 +02:00
|
|
|
- [ "-name", "guest=${ vm.name },debug-threads=on" ]
|
|
|
|
|
- [ "-uuid", "${ vm.uuid }"]
|
2023-05-28 21:35:13 +02:00
|
|
|
# * Configure "modern" machine (pc-q35-7.0). USB is off, because we
|
|
|
|
|
# configure (better) xhci later. No VMWare IO port (obviously).
|
|
|
|
|
# For smm=on see https://scumjr.github.io/2016/01/04/playing-with-smm-and-qemu/.
|
|
|
|
|
# Configure ROM/EEPROM for UEFI.
|
2023-05-23 21:38:32 +02:00
|
|
|
- [ "-machine", "pc-q35-7.0,usb=off,vmport=off,dump-guest-core=off\
|
2023-06-08 13:43:11 +02:00
|
|
|
<#if vm.firmware?starts_with("secure")>,smm=on</#if>\
|
|
|
|
|
<#if firmwareRom??>,pflash0=fw-rom-device\
|
2023-05-23 21:38:32 +02:00
|
|
|
,pflash1=fw-eeprom-device</#if>,memory-backend=pc.ram,hpet=off" ]
|
2023-05-28 21:35:13 +02:00
|
|
|
# * https://bugzilla.redhat.com/show_bug.cgi?id=1170533, may be unnecessary
|
|
|
|
|
- [ "-global", "ICH9-LPC.disable_s3=1" ]
|
|
|
|
|
- [ "-global", "ICH9-LPC.disable_s4=1" ]
|
2023-05-23 21:38:32 +02:00
|
|
|
# {{- if .Values.vm.secureBoot }}
|
|
|
|
|
# -global driver=cfi.pflash01,property=secure,value=on
|
|
|
|
|
# -object '{"qom-type":"secret","id":"masterKey0","format":"raw","file":"/var/local/qemu/master-key.aes"}'
|
|
|
|
|
# {{- end }}
|
2023-06-08 13:43:11 +02:00
|
|
|
<#if firmwareRom??>
|
2023-05-28 21:35:13 +02:00
|
|
|
# * Provide ROM/EEPROM devices (instead of built-in BIOS)
|
2023-05-29 23:14:48 +02:00
|
|
|
- [ "-blockdev", "node-name=fw-rom-file,driver=file,cache.direct=on,\
|
2023-05-23 21:38:32 +02:00
|
|
|
filename=${ firmwareRom },auto-read-only=true,discard=unmap" ]
|
|
|
|
|
- [ "-blockdev", "node-name=fw-rom-device,driver=raw,\
|
|
|
|
|
read-only=true,file=fw-rom-file" ]
|
2023-05-29 23:14:48 +02:00
|
|
|
- [ "-blockdev", "node-name=fw-eeprom-file,driver=file,cache.direct=on,\
|
2023-06-08 13:43:11 +02:00
|
|
|
filename=${ firmwareVars },auto-read-only=true,discard=unmap" ]
|
2023-05-23 21:38:32 +02:00
|
|
|
- [ "-blockdev", "node-name=fw-eeprom-device,driver=raw,\
|
|
|
|
|
read-only=false,file=fw-eeprom-file" ]
|
2023-06-08 13:43:11 +02:00
|
|
|
</#if>
|
|
|
|
|
# https://wiki.debian.org/SecureBoot/VirtualMachine
|
|
|
|
|
<#if vm.firmware?starts_with("secure")>
|
|
|
|
|
- [ "-global", "driver=cfi.pflash01,property=secure,value=on" ]
|
|
|
|
|
</#if>
|
2023-05-28 21:35:13 +02:00
|
|
|
# * Provide RAM
|
2023-05-23 21:38:32 +02:00
|
|
|
- [ "-object", "memory-backend-ram,id=pc.ram,\
|
2023-05-28 21:35:13 +02:00
|
|
|
size=${ vm.maximumRam!"1G" }" ]
|
|
|
|
|
- [ "-m", "${ vm.maximumRam!"1G" }" ]
|
2023-05-29 23:14:48 +02:00
|
|
|
- [ "-device", "virtio-balloon-pci,id=balloon0" ]
|
2023-05-24 11:44:47 +02:00
|
|
|
<#if vm.useTpm>
|
|
|
|
|
# Attach TPM
|
|
|
|
|
- [ "-chardev", "socket,id=chrtpm,path=${ runtimeDir }/swtpm-sock" ]
|
|
|
|
|
- [ "-tpmdev", "emulator,id=tpm0,chardev=chrtpm" ]
|
|
|
|
|
- [ "-device", "tpm-tis,tpmdev=tpm0" ]
|
|
|
|
|
</#if>
|
|
|
|
|
- [ "-cpu", "${ vm.cpuModel }" ]
|
|
|
|
|
<#if vm.maximumCpus gt 1>
|
|
|
|
|
- [ "-smp", "${ vm.currentCpus },maxcpus=${ vm.maximumCpus }\
|
|
|
|
|
<#if vm.cpuSockets gt 0>,sockets=${ vm.cpuSockets }</#if>\
|
|
|
|
|
<#if vm.diesPerSocket gt 0>,cores=${ vm.diesPerSocket }</#if>\
|
|
|
|
|
<#if vm.coresPerDie gt 0>,cores=${ vm.coresPerDie }</#if>\
|
|
|
|
|
<#if vm.threadsPerCore gt 0>,cores=${ vm.threadsPerCore }</#if>" ]
|
|
|
|
|
</#if>
|
|
|
|
|
<#if vm.accelerator != "none">
|
|
|
|
|
- [ "-accel", "${ vm.accelerator }"]
|
|
|
|
|
</#if>
|
2023-05-28 21:35:13 +02:00
|
|
|
# (More devices:)
|
|
|
|
|
# * RTC
|
|
|
|
|
- [ "-rtc", "base=${ vm.rtcBase },clock=${ vm.rtcClock },driftfix=slew" ]
|
|
|
|
|
# On-board serial, made available as pty on host (not used)
|
|
|
|
|
- [ "-chardev", "pty,id=ptyserial0" ]
|
|
|
|
|
- [ "-device", "isa-serial,chardev=ptyserial0,id=serial0,index=0" ]
|
|
|
|
|
# * PCI Serial device(s) (more in SPICE configuration below)
|
|
|
|
|
# Best explanation found:
|
|
|
|
|
# https://fedoraproject.org/wiki/Features/VirtioSerial
|
|
|
|
|
- [ "-device", "virtio-serial-pci,id=virtio-serial0" ]
|
|
|
|
|
# - Guest agent serial connection
|
2023-05-29 23:14:48 +02:00
|
|
|
- [ "-device", "virtserialport,id=channel0,name=org.qemu.guest_agent.0,\
|
|
|
|
|
chardev=guest-agent-socket" ]
|
2023-05-28 21:35:13 +02:00
|
|
|
- [ "-chardev","socket,id=guest-agent-socket,\
|
|
|
|
|
path=${ runtimeDir }/org.qemu.guest_agent.0,server=on,wait=off" ]
|
|
|
|
|
# * USB Hub and devices (more in SPICE configuration below)
|
|
|
|
|
# https://qemu-project.gitlab.io/qemu/system/devices/usb.html
|
|
|
|
|
# https://github.com/qemu/qemu/blob/master/hw/usb/hcd-xhci.c
|
|
|
|
|
- [ "-device", "qemu-xhci,p2=15,p3=15,id=usb" ]
|
|
|
|
|
- [ "-device", "usb-tablet" ]
|
|
|
|
|
# * Random number generator
|
|
|
|
|
- [ "-object", "rng-random,id=objrng0,filename=/dev/random" ]
|
|
|
|
|
- [ "-device", "virtio-rng-pci,rng=objrng0,id=rng0" ]
|
|
|
|
|
# * Graphics and Audio Card
|
|
|
|
|
- [ "-device", "virtio-vga,id=video0,max_outputs=1" ]
|
|
|
|
|
- [ "-device", "ich9-intel-hda,id=sound0" ]
|
2023-06-07 15:03:11 +02:00
|
|
|
# Network
|
|
|
|
|
<#assign nwCounter = 0/>
|
|
|
|
|
<#list vm.network![] as itf>
|
|
|
|
|
<#switch itf.type!"tap">
|
|
|
|
|
<#case "tap">
|
|
|
|
|
- [ "-netdev", "bridge,id=hostnet${ nwCounter }" ]
|
|
|
|
|
- [ "-device", "${ itf.device },netdev=hostnet${ nwCounter }\
|
|
|
|
|
<#if itf.mac??>,mac=${ itf.mac }</#if>" ]
|
|
|
|
|
<#break>
|
|
|
|
|
<#case "user">
|
|
|
|
|
- [ "-netdev", "user,id=hostnet${ nwCounter }\
|
|
|
|
|
<#if itf.net??>,net=${ itf.net }</#if>" ]
|
|
|
|
|
- [ "-device", "${ itf.device },netdev=hostnet${ nwCounter }\
|
|
|
|
|
<#if itf.mac??>,mac=${ itf.mac }</#if>" ]
|
|
|
|
|
<#break>
|
|
|
|
|
</#switch>
|
|
|
|
|
<#assign nwCounter += 1/>
|
|
|
|
|
</#list>
|
2023-05-28 21:35:13 +02:00
|
|
|
# Drives
|
|
|
|
|
# * CD-Drives
|
|
|
|
|
<#assign cdCounter = 0/>
|
|
|
|
|
<#list vm.drives![] as drive>
|
|
|
|
|
<#if (drive.type!"hdd") == "ide-cd">
|
2023-05-29 23:14:48 +02:00
|
|
|
- [ "-drive", "id=drive-cdrom${ cdCounter },if=none,media=cdrom,cache=none\
|
2023-05-28 21:35:13 +02:00
|
|
|
<#if drive.file??>,file=${ drive.file }</#if>" ]
|
|
|
|
|
# (IDE is old, but faster than usb-storage. virtio-blk-pci does not
|
|
|
|
|
# work without file [empty drive])
|
|
|
|
|
- [ "-device", "ide-cd,id=cd${ cdCounter },drive=drive-cdrom${ cdCounter }\
|
|
|
|
|
<#if drive.bootindex??>,bootindex=${ drive.bootindex }</#if>" ]
|
|
|
|
|
<#assign cdCounter += 1/>
|
|
|
|
|
</#if>
|
|
|
|
|
</#list>
|
|
|
|
|
|
|
|
|
|
# - how to access the resource on the host (a file)
|
|
|
|
|
# - [ "-blockdev", "node-name=blockdev-cdrom-file,driver=file,\
|
|
|
|
|
# filename=/home/mnl/Downloads/archlinux-2023.05.03-x86_64.iso" ]
|
|
|
|
|
# - how to use the file (as sequence of literal blocks)
|
|
|
|
|
# - [ "-blockdev", "node-name=blockdev-cdrom-backend,driver=raw,\
|
|
|
|
|
# read-only=true,file=blockdev-cdrom-file" ]
|
|
|
|
|
# - the driver (what the guest sees)
|
|
|
|
|
# - [ "-device", "virtio-blk-pci,id=virtio-disk-cdrom,\
|
|
|
|
|
# drive=blockdev-cdrom-backend,bootindex=1" ]
|
|
|
|
|
|
2023-05-29 23:14:48 +02:00
|
|
|
# SPICE (display, channels ...)
|
|
|
|
|
# https://www.linux-kvm.org/page/SPICE
|
2023-05-30 18:04:31 +02:00
|
|
|
- [ "-spice", "port=${ vm.spice.port?c },disable-ticketing=on\
|
|
|
|
|
,seamless-migration=on" ]
|
2023-05-29 23:14:48 +02:00
|
|
|
- [ "-chardev", "spicevmc,id=vdagentdev,name=vdagent" ]
|
|
|
|
|
- [ "-device", "virtserialport,name=com.redhat.spice.0,\
|
|
|
|
|
chardev=vdagentdev" ]
|
|
|
|
|
# * Audio
|
|
|
|
|
- [ "-audiodev", "driver=spice,id=audio1" ]
|
|
|
|
|
- [ "-device", "hda-duplex,audiodev=audio1" ]
|
|
|
|
|
# * USB redirection
|
2023-05-30 18:04:31 +02:00
|
|
|
<#list 0..<vm.spice.usbRedirects as index>
|
|
|
|
|
- [ "-chardev", "spicevmc,id=charredir${ index },name=usbredir" ]
|
|
|
|
|
- [ "-device", "usb-redir,id=redir${ index },chardev=charredir${ index }" ]
|
|
|
|
|
</#list>
|