fix(vm_provision_mixin): write Cloud-Init snippet via SSH, not the upload API

Real Proxmox's POST /nodes/{node}/storage/{storage}/upload only accepts
content in {iso, vztmpl, import} — content='snippets' is rejected
outright with a 400 ("does not have a value in the enumeration").
Snippets can only be written directly to the storage's filesystem path.

Found live, right after the previous multipart-upload fix: the VM
shell, disk import, and node-scoped storage selection all succeeded,
then create_vm_from_cloud_init failed with a 400 at the snippet write
step. Resolves the storage's path via the cluster storage config and
writes the file over SSH (base64-piped, to survive arbitrary YAML
content safely).
This commit is contained in:
Christian Manivong
2026-07-07 23:24:05 +02:00
parent 86af2cb7a7
commit 685d9b67ae
2 changed files with 110 additions and 71 deletions
+32 -14
View File
@@ -2,7 +2,7 @@
from __future__ import annotations from __future__ import annotations
import io import base64
import logging import logging
import time import time
import yaml import yaml
@@ -130,6 +130,25 @@ class ProxmoxVMProvisionMixin:
"No storage with content='images' found. Configure a storage for VM disks." "No storage with content='images' found. Configure a storage for VM disks."
) )
def _get_storage_path(self, storage: str) -> str:
"""Resolve a storage's filesystem path on the node.
Needed to write Cloud-Init snippets directly: Proxmox's
/storage/{s}/upload API only accepts content in {iso, vztmpl,
import} — "snippets" is rejected outright, so snippets must be
written straight to the filesystem instead. Only dir-backed storages
(dir, nfs, cifs, cephfs) expose "path"; those are also the only
storage types Proxmox itself allows content='snippets' on.
"""
config = self._api.storage(storage).get()
path = config.get("path")
if not path:
raise ValueError(
f"Storage '{storage}' has no filesystem path (content='snippets' "
"requires a dir/nfs/cifs/cephfs-backed storage)"
)
return path
def get_image_storages(self) -> List[StorageTargetDict]: def get_image_storages(self) -> List[StorageTargetDict]:
"""List node-available storage pools suitable for a new VM's root disk.""" """List node-available storage pools suitable for a new VM's root disk."""
targets: List[StorageTargetDict] = [] targets: List[StorageTargetDict] = []
@@ -336,20 +355,19 @@ class ProxmoxVMProvisionMixin:
) )
filename = f"{vmid}-user-data.yaml" filename = f"{vmid}-user-data.yaml"
_logger.debug(f"Uploading Cloud-Init snippet {filename} to {snippet_storage}") _logger.debug(f"Writing Cloud-Init snippet {filename} to {snippet_storage}")
# Upload to snippet storage. Proxmox's upload endpoint expects the # Proxmox's /storage/{s}/upload API only accepts content in
# "filename" parameter to BE the file (multipart), not a name # {iso, vztmpl, import} — "snippets" is rejected outright
# string with separate content — proxmoxer only builds a # ("does not have a value in the enumeration"). Snippets can only
# multipart request when the value is an io.IOBase instance, # be written directly to the filesystem, so resolve the storage's
# otherwise it silently sends everything as a plain # backing path and write the file over SSH instead.
# form-urlencoded POST, which real Proxmox rejects by dropping storage_path = self._get_storage_path(snippet_storage)
# the connection (RemoteDisconnected, no HTTP response at all). encoded = base64.b64encode(user_data_yaml.encode("utf-8")).decode("ascii")
file_obj = io.BytesIO(user_data_yaml.encode("utf-8")) self._run_node_command(
file_obj.name = filename f"mkdir -p {storage_path}/snippets && "
self._node_api().storage(snippet_storage).upload.post( f"echo {encoded} | base64 -d > {storage_path}/snippets/{filename}",
content="snippets", timeout=30,
filename=file_obj,
) )
# Step 7: Configure Cloud-Init references and SSH keys # Step 7: Configure Cloud-Init references and SSH keys
+78 -57
View File
@@ -2,7 +2,7 @@
from __future__ import annotations from __future__ import annotations
import io import base64
import pytest import pytest
from unittest.mock import MagicMock, patch from unittest.mock import MagicMock, patch
@@ -76,6 +76,7 @@ def test_create_vm_from_cloud_init_single_nic():
# Mock API hierarchy # Mock API hierarchy
mock_api = MagicMock() mock_api = MagicMock()
mock_api.cluster.nextid.get.return_value = 101 mock_api.cluster.nextid.get.return_value = 101
mock_api.storage.return_value.get.return_value = {"path": "/var/lib/vz"}
mock_node = MagicMock() mock_node = MagicMock()
mock_node.storage.get.return_value = [ mock_node.storage.get.return_value = [
@@ -103,11 +104,6 @@ def test_create_vm_from_cloud_init_single_nic():
mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"} mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"}
mock_node.tasks.return_value = mock_task mock_node.tasks.return_value = mock_task
# Mock storage upload
mock_storage = MagicMock()
mock_storage.upload.post.return_value = {"filename": "snippets:snippets/101-user-data.yaml"}
mock_node.storage.return_value = mock_storage
with patch("time.sleep"): with patch("time.sleep"):
result = mixin.create_vm_from_cloud_init( result = mixin.create_vm_from_cloud_init(
name="test-vm", name="test-vm",
@@ -132,14 +128,15 @@ def test_create_vm_from_cloud_init_single_nic():
assert "tag=10" in net_call_args[1]["net0"] assert "tag=10" in net_call_args[1]["net0"]
assert "vmbr0" in net_call_args[1]["net0"] assert "vmbr0" in net_call_args[1]["net0"]
# Regression: the snippet must be uploaded as an actual file (io.IOBase), # Regression: the snippet must be written directly to the filesystem via
# not a plain filename string with a separate "data" field — proxmoxer # SSH, not uploaded via the /storage/upload API — real Proxmox rejects
# only builds a real multipart request for io.IOBase values, and real # content='snippets' on that endpoint outright (see
# Proxmox drops the connection outright for anything else (see # test_create_vm_writes_snippet_via_ssh_with_correct_content for the
# test_create_vm_uploads_snippet_as_file_object for the dedicated check). # dedicated check).
upload_kwargs = mock_storage.upload.post.call_args[1] write_cmd = next(
assert "data" not in upload_kwargs c[0][0] for c in mixin._run_node_command.call_args_list if "snippets/101-user-data.yaml" in c[0][0]
assert isinstance(upload_kwargs["filename"], io.IOBase) )
assert "/var/lib/vz/snippets" in write_cmd
def test_create_vm_from_cloud_init_dual_nic_trunk(): def test_create_vm_from_cloud_init_dual_nic_trunk():
@@ -150,6 +147,7 @@ def test_create_vm_from_cloud_init_dual_nic_trunk():
# Mock API hierarchy # Mock API hierarchy
mock_api = MagicMock() mock_api = MagicMock()
mock_api.cluster.nextid.get.return_value = 102 mock_api.cluster.nextid.get.return_value = 102
mock_api.storage.return_value.get.return_value = {"path": "/var/lib/vz"}
mock_node = MagicMock() mock_node = MagicMock()
mock_node.storage.get.return_value = [ mock_node.storage.get.return_value = [
@@ -177,11 +175,6 @@ def test_create_vm_from_cloud_init_dual_nic_trunk():
mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"} mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"}
mock_node.tasks.return_value = mock_task mock_node.tasks.return_value = mock_task
# Mock storage upload
mock_storage = MagicMock()
mock_storage.upload.post.return_value = {"filename": "snippets:snippets/102-user-data.yaml"}
mock_node.storage.return_value = mock_storage
with patch("time.sleep"): with patch("time.sleep"):
result = mixin.create_vm_from_cloud_init( result = mixin.create_vm_from_cloud_init(
name="wireshark-sat-1", name="wireshark-sat-1",
@@ -265,6 +258,7 @@ def test_create_vm_with_disk_resize():
# Mock API hierarchy # Mock API hierarchy
mock_api = MagicMock() mock_api = MagicMock()
mock_api.cluster.nextid.get.return_value = 103 mock_api.cluster.nextid.get.return_value = 103
mock_api.storage.return_value.get.return_value = {"path": "/var/lib/vz"}
mock_node = MagicMock() mock_node = MagicMock()
mock_node.storage.get.return_value = [ mock_node.storage.get.return_value = [
@@ -293,11 +287,6 @@ def test_create_vm_with_disk_resize():
mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"} mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"}
mock_node.tasks.return_value = mock_task mock_node.tasks.return_value = mock_task
# Mock storage upload
mock_storage = MagicMock()
mock_storage.upload.post.return_value = {"filename": "snippets:snippets/103-user-data.yaml"}
mock_node.storage.return_value = mock_storage
with patch("time.sleep"): with patch("time.sleep"):
result = mixin.create_vm_from_cloud_init( result = mixin.create_vm_from_cloud_init(
name="big-vm", name="big-vm",
@@ -722,6 +711,42 @@ def test_find_default_image_storage_excludes_storage_restricted_to_other_nodes()
assert storage == "local-zfs" assert storage == "local-zfs"
# ---------------------------------------------------------------------------
# _get_storage_path
# ---------------------------------------------------------------------------
def test_get_storage_path_returns_path_from_cluster_config():
mixin = ProxmoxVMProvisionMixin()
mixin._api = MagicMock()
mixin._api.storage.return_value.get.return_value = {
"storage": "local",
"type": "dir",
"path": "/var/lib/vz",
}
path = mixin._get_storage_path("local")
assert path == "/var/lib/vz"
mixin._api.storage.assert_called_with("local")
def test_get_storage_path_raises_when_storage_has_no_path():
"""A storage type without a filesystem path (e.g. lvmthin, zfspool) can't
back content='snippets' at all — Proxmox itself only allows that content
type on dir/nfs/cifs/cephfs storages, so this should never actually be
reached for a real snippet storage, but must fail clearly if it is."""
mixin = ProxmoxVMProvisionMixin()
mixin._api = MagicMock()
mixin._api.storage.return_value.get.return_value = {
"storage": "local-lvm",
"type": "lvmthin",
}
with pytest.raises(ValueError, match="path"):
mixin._get_storage_path("local-lvm")
def test_create_vm_from_cloud_init_with_real_world_storage_shape(): def test_create_vm_from_cloud_init_with_real_world_storage_shape():
"""Regression: real Proxmox servers omit "enabled" for never-toggled storages """Regression: real Proxmox servers omit "enabled" for never-toggled storages
(observed live: local-lvm/local-zfs/fast-zfs all had content=images but no (observed live: local-lvm/local-zfs/fast-zfs all had content=images but no
@@ -733,6 +758,7 @@ def test_create_vm_from_cloud_init_with_real_world_storage_shape():
mock_api = MagicMock() mock_api = MagicMock()
mock_api.cluster.nextid.get.return_value = 104 mock_api.cluster.nextid.get.return_value = 104
mock_api.storage.return_value.get.return_value = {"path": "/var/lib/vz"}
mock_node = MagicMock() mock_node = MagicMock()
mock_node.storage.get.return_value = [ mock_node.storage.get.return_value = [
@@ -760,10 +786,6 @@ def test_create_vm_from_cloud_init_with_real_world_storage_shape():
mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"} mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"}
mock_node.tasks.return_value = mock_task mock_node.tasks.return_value = mock_task
mock_storage = MagicMock()
mock_storage.upload.post.return_value = {"filename": "snippets:snippets/104-user-data.yaml"}
mock_node.storage.return_value = mock_storage
with patch("time.sleep"): with patch("time.sleep"):
result = mixin.create_vm_from_cloud_init( result = mixin.create_vm_from_cloud_init(
name="real-shape-vm", name="real-shape-vm",
@@ -786,6 +808,7 @@ def test_create_vm_from_cloud_init_explicit_storage_skips_auto_detect():
mock_api = MagicMock() mock_api = MagicMock()
mock_api.cluster.nextid.get.return_value = 105 mock_api.cluster.nextid.get.return_value = 105
mock_api.storage.return_value.get.return_value = {"path": "/var/lib/vz"}
mock_node = MagicMock() mock_node = MagicMock()
mock_node.storage.get.return_value = [ mock_node.storage.get.return_value = [
@@ -813,10 +836,6 @@ def test_create_vm_from_cloud_init_explicit_storage_skips_auto_detect():
mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"} mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"}
mock_node.tasks.return_value = mock_task mock_node.tasks.return_value = mock_task
mock_storage = MagicMock()
mock_storage.upload.post.return_value = {"filename": "snippets:snippets/105-user-data.yaml"}
mock_node.storage.return_value = mock_storage
with patch("time.sleep"): with patch("time.sleep"):
result = mixin.create_vm_from_cloud_init( result = mixin.create_vm_from_cloud_init(
name="explicit-storage-vm", name="explicit-storage-vm",
@@ -901,21 +920,22 @@ def test_get_image_storages_excludes_storage_restricted_to_other_nodes():
# --------------------------------------------------------------------------- # ---------------------------------------------------------------------------
def test_create_vm_uploads_snippet_as_file_object_with_correct_content(): def test_create_vm_writes_snippet_via_ssh_with_correct_content():
"""Regression: real Proxmox's /storage/{s}/upload endpoint expects the """Regression: real Proxmox's /storage/{s}/upload endpoint rejects
"filename" parameter to be the file itself (multipart). proxmoxer only content='snippets' outright ("value 'snippets' does not have a value in
builds a multipart request when the value is an io.IOBase instance — the enumeration 'iso, vztmpl, import'") — that endpoint only handles
passing a plain string (with a separate, nonexistent "data" field, as the ISOs, container templates, and imports. Snippets can only be written
old code did) makes proxmoxer send a normal form-urlencoded POST instead, directly to the storage's filesystem path, so this must go through SSH
which real Proxmox responds to by closing the connection outright (_run_node_command), not the upload API.
(observed live: requests.exceptions.ConnectionError / (observed live: 400 Bad Request from Proxmox, right after the earlier
RemoteDisconnected('Remote end closed connection without response'), multipart-upload fix had already gotten past a prior RemoteDisconnected
after the VM shell and disk import had already succeeded).""" bug at the same step — two distinct real-world failures at this line)."""
mixin = ProxmoxVMProvisionMixin() mixin = ProxmoxVMProvisionMixin()
mixin._node_name = "pve1" mixin._node_name = "pve1"
mock_api = MagicMock() mock_api = MagicMock()
mock_api.cluster.nextid.get.return_value = 106 mock_api.cluster.nextid.get.return_value = 106
mock_api.storage.return_value.get.return_value = {"path": "/mnt/pve/snippet-nfs"}
mock_node = MagicMock() mock_node = MagicMock()
mock_node.storage.get.return_value = [ mock_node.storage.get.return_value = [
@@ -941,28 +961,29 @@ def test_create_vm_uploads_snippet_as_file_object_with_correct_content():
mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"} mock_task.status.get.return_value = {"status": "stopped", "exitstatus": "OK"}
mock_node.tasks.return_value = mock_task mock_node.tasks.return_value = mock_task
mock_storage = MagicMock()
mock_storage.upload.post.return_value = {"filename": "local:snippets/106-user-data.yaml"}
mock_node.storage.return_value = mock_storage
with patch("time.sleep"): with patch("time.sleep"):
mixin.create_vm_from_cloud_init( mixin.create_vm_from_cloud_init(
name="upload-shape-vm", name="write-shape-vm",
image_url="https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2", image_url="https://cloud.debian.org/images/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2",
cpu=2, cpu=2,
memory=2048, memory=2048,
nics=[{"bridge": "vmbr0"}], nics=[{"bridge": "vmbr0"}],
cloud_init_config={"hostname": "upload-shape-vm", "chpasswd": {"expire": False}}, cloud_init_config={"hostname": "write-shape-vm", "chpasswd": {"expire": False}},
) )
upload_call = mock_storage.upload.post.call_args # No call to the upload API at all — snippets aren't a valid content
assert upload_call[1]["content"] == "snippets" # type there.
assert "data" not in upload_call[1] mock_node.storage.assert_not_called()
file_obj = upload_call[1]["filename"] write_cmd = next(
assert isinstance(file_obj, io.IOBase) c[0][0]
assert file_obj.name == "106-user-data.yaml" for c in mixin._run_node_command.call_args_list
file_obj.seek(0) if "snippets/106-user-data.yaml" in c[0][0]
content = file_obj.read().decode("utf-8") )
assert "mkdir -p /mnt/pve/snippet-nfs/snippets" in write_cmd
assert "/mnt/pve/snippet-nfs/snippets/106-user-data.yaml" in write_cmd
encoded = write_cmd.split("echo ", 1)[1].split(" | base64 -d")[0]
content = base64.b64decode(encoded).decode("utf-8")
assert content.startswith("#cloud-config\n") assert content.startswith("#cloud-config\n")
assert "hostname: upload-shape-vm" in content assert "hostname: write-shape-vm" in content