3 \me@sddlZddlZddlZddlZddlmZddlmZmZm Z ddlm Z ddlm Z m Z ddlmZmZddlmZddlmZdd lmZejeZee jgZd5Zd ZGdddZddZ ej!ej"gZ#Gddde j$Z%Gddde%Z&ddZ'ddZ(ddZ)ddZ*ddZ+d d!Z,d"d#Z-d$d%Z.d&d'Z/d(d)Z0d*d+Z1d6d-d.Z2d/d0Z3d1d2Z4e&e j5ffe%e j5e j6ffgZ7d3d4Z8dS)7N)List)dminetsources) url_helper)utilwarnings) EventScope EventType)NoDHCPLeaseError)EphemeralIPNetwork)ec2 datasourceEc2 strict_idwarnc@s,eZdZdZdZdZdZdZdZdZ dZ d S) CloudNamesZaliyunZawsZ brightboxZzstacke24cloudZoutscaleunknownzno-ec2-metadataN) __name__ __module__ __qualname__ALIYUNAWS BRIGHTBOXZSTACKE24CLOUDOUTSCALEUNKNOWNNO_EC2_METADATAr r #/usr/lib/python3.6/DataSourceEc2.pyr!srcCs|jdkod|jkS)Nizmeta-data/tags/)codeurl) exceptionr r r!skip_404_tag_errors1sr%csxeZdZUdZdddgZdZdddgZeed Z d Z d Z e j Zd ZejejejejejhiZfd dZddZddZddZeddZeddZeddZeddZ eddZ!edd Z"ed!d"Z#d#d$Z$d%d&Z%d'd(Z&d)d*Z'd+d,Z(ed-d.Z)ed/d0Z*d1d2Z+ed3d4Z,efd5d6Z-d7d8Z.dDd9d:Z/d;d<Z0d=d>Z1dEd?d@Z2dFdBdCZ3Z4S)G DataSourceEc2rzhttp://169.254.169.254zhttp://[fd00:ec2::254]zhttp://instance-data.:8773z 2009-04-04z 2021-03-23z 2018-09-24z 2016-09-02x2NFcstt|j|||d|_dS)N)superr&__init__metadata_address)selfsys_cfgdistropaths) __class__r r!r*dszDataSourceEc2.__init__cCstS)z5Return the cloud name as identified during _get_data.)identify_platform)r,r r r!_get_cloud_namehszDataSourceEc2._get_cloud_namecCsFttj|jttd\}}tjd||j|j |dkrF|jt j krFdS|jt j krVdS|j rtjrrtjddSyVt|j|jddd8}|jrd|jnd }tjtjd ||jd |_WdQRXWntk rdSXntjtjd |jd |_|jsdS|jjd d|_|jjd d|_|jjdijdijdi|_dS)Nrz0strict_mode: %s, cloud_name=%s cloud_platform=%strueFz1FreeBSD doesn't support running dhclient with -sfT)ipv4ipv6 zCrawl of metadata service)logfuncmsgfuncz meta-dataz user-datadynamiczinstance-identitydocument)rN)read_strict_moderget_cfg_by_pathr-STRICT_ID_PATHSTRICT_ID_DEFAULTLOGdebug cloud_nameplatformrrrperform_dhcp_setupZ is_FreeBSDr r.fallback_interface state_msglog_timecrawl_metadataZ_crawled_metadatar getmetadataZ userdata_rawidentity)r,Z strict_modeZ_sleepZnetwrGr r r! _get_datalsV      zDataSourceEc2._get_datacCsN|js dS|jjdijdi}x(|jdijD]\}}d|kr2dSq2WdS)z6Report if this instance type is Ec2 Classic (non-vpc).Fnetwork interfacesmacszvpc-idT)rKrJitems)r,Z ifaces_mdZ_macZmac_datar r r!is_classic_instancesz!DataSourceEc2.is_classic_instancecCs|js dS|jjdS)Nzami-launch-index)rKrJ)r,r r r! launch_indexszDataSourceEc2.launch_indexcCs.t|dstjj|_|js(tjj|_|jS)N_platform_type)hasattrr&dsnamelowerrT)r,r r r!rDs    zDataSourceEc2.platformcCsdS)Nzlatest/api/tokenr )r,r r r!api_token_routeszDataSourceEc2.api_token_routecCsdS)NZ21600r )r,r r r!imdsv2_token_ttl_secondssz&DataSourceEc2.imdsv2_token_ttl_secondscCsdS)NzX-aws-ec2-metadata-tokenr )r,r r r!imdsv2_token_put_headersz%DataSourceEc2.imdsv2_token_put_headercCs |jdS)Nz -ttl-seconds)rZ)r,r r r!imdsv2_token_req_headersz%DataSourceEc2.imdsv2_token_req_headercCs |j|jgS)N)rZr[)r,r r r!imdsv2_token_redactsz!DataSourceEc2.imdsv2_token_redactcCsd}|j}x|jD]}|j|j|}ytj|||jd}Wn2tjk rn}ztj d||WYdd}~XqX|j dkrtj d||S|j dkrd}tj |||j qW|j S) aEGet the best supported api version from the metadata service. Loop through all extended support metadata versions in order and return the most-fully featured metadata api version discovered. If extended_metadata_versions aren't present, return the datasource's min_metadata_version. z{0}/{1}/meta-data/instance-id)r#headersheaders_redactzurl %s raised exception %sNz#Found preferred metadata version %siz0Metadata api version %s not present. Headers: %s) _get_headersextended_metadata_versionsformatr+uhelpreadurlr\UrlErrorrArBr"r]min_metadata_version)r,Zurl_tmplr]Zapi_verr#Zresper9r r r!get_metadata_api_versions$      z&DataSourceEc2.get_metadata_api_versioncCsh|jtjkrZt|ddsF|j}tj||j|j|j |j dj di|_ |j j d|j dS|j dSdS)NrL) headers_cbr^ exception_cbr<Z instanceIdz instance-id)rCrrgetattrrhr get_instance_identityr+r`r\_refresh_stale_aws_token_cbrJrLrK)r, api_versionr r r!get_instance_ids    zDataSourceEc2.get_instance_idc Cs|jtkrdSg}i}|j}d}x*|D]"}dj||}|j||||<q&Wtjdd}d}|j} y0tj || j | j tj |j |j||jdd \}}Wntjk rYnX|r|r||_||SdS)aGet an API token for EC2 Instance Metadata Service. On EC2. IMDS will always answer an API token, unless the instance owner has disabled the IMDS HTTP endpoint or the network topology conflicts with the configured hop-limit. NPUTz{0}/{1}zFetching Ec2 IMDSv2 API TokenF) urlsmax_waittimeout status_cbrirjrequest_methodr^Zconnect_synchronously)rC IDMSV2_SUPPORTED_CLOUD_PLATFORMSrXrbappendrArBget_url_paramsrc wait_for_urlmax_wait_secondstimeout_secondswarningr`_imds_exception_cbr\re _api_token) r,mdurlsrqurl2baseurl_pathrur#curresponse url_paramsr r r!_maybe_fetch_api_tokens>      z$DataSourceEc2._maybe_fetch_api_tokenc Csv|j}|j}|jdkrdS|jd|j}dd|D}t|t|krdtjdtt|t|t |rr|}ntj d|j}|j |}| o|j t kr g}i}dj|jd }d } x*|D]"} d j| |} |j| | || <qWtj} tj||j|jtj |j|j| d \} } | r || }|r<||_tjd |jn2|j t krTtj dntjd|ttj| t|S)NrF metadata_urlscSsg|]}tj|r|qSr )rZis_resolvable_url).0xr r r! Csz;DataSourceEc2.wait_for_metadata_service..z,Removed the following from metadata urls: %sz+Empty metadata url list! using default listz{ver}/meta-data/instance-id)ZverZGETz{0}/{1})rqrrrsrtr^riruzUsing metadata source: '%s'z)IMDS's HTTP endpoint is probably disabledz(Giving up on md from %s after %s seconds)ds_cfgrxrzrJrsetrArBlistlenr|rrCrvrbrfrwtimercryr{r\r`r+Zcriticalintbool)r,ZmcfgrrZfilteredr+rqrrrur#rZ start_time_r r r!wait_for_metadata_service:s^            z'DataSourceEc2.wait_for_metadata_servicecCsd|jkrdSd}|jd}t|ts6tjd|dSx6|jD]*\}}||krV|}P|dkr@|dkr@|}q@W|dkrtjd|dS|}|jdsd|}tjj |r|S|j tjj |}|rtjd|||S|dkrdS|S) Nzblock-device-mappingz+block-device-mapping not a dictionary: '%s'Z ephemeralZ ephemeral0z Unable to convert %s to a device/z/dev/%szRemapped device name %s => %s) rK isinstancedictrArBrQ startswithospathexistsZ _remap_devicebasename)r,namefoundZbdmZentnameZdeviceZofoundZremappedr r r!device_name_to_devices8       z#DataSourceEc2.device_name_to_devicec CsPy6|jtjkr&|jjd|jddS|jddSWntk rJdSXdS)NZavailabilityZoneZ placementzavailability-zone)rCrrrLrJrKKeyError)r,r r r!availability_zones zDataSourceEc2.availability_zonecCsT|jtjkr6|jjd}|jr2| r2|jdd}|S|j}|dk rP|ddSdS)Nregionr)rCrrrLrJr)r,rZazr r r!rs    zDataSourceEc2.regioncCs,|sdS|jtjkr(ttj|tt|dS)N)rCrrwarn_if_necessaryrr>r?r@)r,cfgZis_new_instancer r r!activates   zDataSourceEc2.activatecCs|jtjkr|jS|jdkr*tjddSd}td|jkoD|jtj k}|rjtj dt j tj d|j d|j}|jjd}t|trt||t j|jddd }|jrtj|j|_|jtjjtj|jtjjtjn tjd |||_|jS) z@Return a network config dict for rendering ENI or netplan files.Nz8Unexpected call to network_config when metadata is None.rNzPMetadata 'network' not present: Refreshing stale metadata from prior to upgrade.zRe-crawl of metadata service)r8r9r:Zapply_full_imds_network_configT) fallback_nicfull_network_configz%Metadata 'network' key not valid: %s.)_network_configrUNSETrKrAr|rrCrrrBrrHget_datarFrJrr#convert_ec2_metadata_network_configZget_cfg_option_boolrrRcopydeepcopyZdefault_update_eventsr NETWORKaddr BOOT BOOT_LEGACY)r,resultZno_network_metadata_on_awsZifaceZnet_mdr r r!network_configsF           zDataSourceEc2.network_configcs:|jdkr4t|dd}|r(||_d|_n tt|jS|jS)Nr)Z_fallback_interfacerkrr)r&rF)r,Z _legacy_fbnic)r0r r!rFs   z DataSourceEc2.fallback_interfacec Cs |js iS|j}|j}i}|jtkr:|j}|j}d}n&|jtjkrTd}}t }n d}}}yxt j ||j |j ||d}tj||d<t j||j |j |||d|d<|jtjkrt j||j |j ||d}d|i|d<Wn&tk rtjtd|j iSX||d <|S) zCrawl metadata service when available. @returns: Dictionary of crawled metadata content containing the keys: meta-data, user-data and dynamic. N)rir^rjz user-data)rir^rjZretrieval_exception_ignore_cbz meta-datazinstance-identityr;z'Failed reading from metadata address %sZ_metadata_api_version)rrhr\rCrvrm#_skip_or_refresh_stale_aws_token_cbrrr%r Zget_instance_userdatar+r`rZmaybe_b64decodeZget_instance_metadatarrl ExceptionZlogexcrA) r,rnZredactZcrawled_metadataZexc_cbZ exc_cb_udZskip_cbZ raw_userdatarLr r r!rI$sX     zDataSourceEc2.crawl_metadatacCs|jtkrdS|dkr|j}tjd|j|i}dj|j|j}yt j |||j dd}Wn0t j k r}ztj d||dSd}~XnX|jS)zRequest new metadata API token. @param seconds: The lifetime of the token in seconds @return: The API token or None if unavailable. Nz!Refreshing Ec2 metadata API tokenz{}/{}rp)r]r^ruz/Unable to get API token: %s raised exception %s)rCrvrYrArBr[rbr+rXrcrdr\rer|contents)r,ZsecondsZrequest_headerZ token_urlrrgr r r!_refresh_api_token\s$     z DataSourceEc2._refresh_api_tokencCs$tjtj||}|sdS|j||S)zSCallback will not retry on SKIP_USERDATA_CODES or if no token is available.F)r Zskip_retry_on_codesZSKIP_USERDATA_CODESrm)r,r9r$Zretryr r r!rys  z1DataSourceEc2._skip_or_refresh_stale_aws_token_cbcCs*t|tjr&|jdkr&tjdd|_dS)z=Exception handler for Ec2 to refresh token if token is stale.iz+Clearing cached Ec2 API token due to expiryNT)rrcrer"rArBr~)r,r9r$r r r!rms z)DataSourceEc2._refresh_stale_aws_token_cbcCsDt|tjr@|jr@|jdkr@|jdkr2tjdn tjd|dS)a2Fail quickly on proper AWS if IMDSv2 rejects API token request Guidance from Amazon is that if IMDSv2 had disabled token requests by returning a 403, or cloud-init malformed requests resulting in other 40X errors, we want the datasource detection to fail quickly without retries as those symptoms will likely not be resolved by retries. Exceptions such as requests.ConnectionError due to IMDS being temporarily unroutable or unavailable will still retry due to the callsite wait_for_url. iizLEc2 IMDS endpoint returned a 403 error. HTTP endpoint is disabled. Aborting.z2Fatal error while requesting Ec2 IMDSv2 API tokensN)rrcrer"rAr|)r,r9r$r r r!r}s  z DataSourceEc2._imds_exception_cbr7cCsN|jtkriS|j|ji}|j|kr(|S|jsB|j|_|jsBiS|j|jiS)zReturn a dict of headers for accessing a url. If _api_token is unset on AWS, attempt to refresh the token via a PUT and then return the updated token header. )rCrvr[rYrXr~rrZ)r,r#Zrequest_token_headerr r r!r`s    zDataSourceEc2._get_headers)N)N)r7)5rrrrVrrfrarstrZ url_max_waitZ url_timeoutr~rrrrEr rr ZBOOT_NEW_INSTANCErrZHOTPLUGZsupported_update_eventsr*r2rMrRpropertyrSrDrXrYrZr[r\rhrorrrrrrrrFrIrrrmr}r` __classcell__r r )r0r!r&9sZ   8      2I3  = 8   r&cs$eZdZdZdZfddZZS)DataSourceEc2LocalayDatasource run at init-local which sets up network to query metadata. In init-local, no network is available. This subclass sets up minimal networking with dhclient on a viable nic so that it can talk to the metadata service. If the metadata service provides network configuration then render the network configuration for that instance based on metadata. Tcs8tjtjf}|j|kr*tjd||jdStt|jS)Nz+Local Ec2 mode only supported on %s, not %sF) rrrrCrArBr)rr)r,Zsupported_platforms)r0r r!rs  zDataSourceEc2Local.get_data)rrr__doc__rErrr r )r0r!rsrcCs8yt|Stk r2}ztj||Sd}~XnXdS)N)parse_strict_mode ValueErrorrAr|)cfgvaldefaultrgr r r!r=s  r=cCs|dkr d S|dkrd S|s d S|jd\}}}|d krHtd||f|ry t|}Wqtk r}ztd ||f|WYdd}~XqXnd}||fS)NTr3Ffalserr,zUInvalid mode '%s' in strict_id setting '%s': Expected one of 'true', 'false', 'warn'.z;sz#identify_platform..z'calling %s with %s raised exception: %s) _collect_platform_datarrrrrrrrAr|)rZchecksZcheckerrrgr r r!r11s   r1c Csi}ytjdj}d|d<Wn&tk rDtjd}d|d<YnX|dkrRd}|j|d<tjd }|dkrtd}|j|d <tjd }|dkrd}|j|d <tjd }|r|ndj|d<tjd}|r|ndj|d<|S)aReturns a dictionary of platform info from dmi or /sys/hypervisor. Keys in the dictionary are as follows: uuid: system-uuid from dmi or /sys/hypervisor uuid_source: 'hypervisor' (/sys/hypervisor/uuid) or 'dmi' serial: dmi 'system-serial-number' (/sys/.../product_serial) asset_tag: 'dmidecode -s chassis-asset-tag' vendor: dmi 'system-manufacturer' (/sys/.../sys_vendor) product_name: dmi 'system-product-name' (/sys/.../system-manufacturer) On Ec2 instances experimentation is that product_serial is upper case, and product_uuid is lower case. This returns lower case values for both. z/sys/hypervisor/uuidrrz system-uuidrNr7rzsystem-serial-numberrzchassis-asset-tagrzsystem-manufacturerrzsystem-product-namer)rZ load_filestriprrZ read_dmi_datarW)rrrrrrr r r!rHs.         rTc Csdid}|stj}|dd}|sx|jD]\}}||kr0Pq0Wddd|ji|d}|j|} | jd rxd|d <||d |<|Sd } xt|jD]\}}|j|} | sqt| jd | d} d| di} d| dd|ji|d}| jd rd|d <| |d<t| ||d<|ds(|jd||d |<qWt |d dkrx<|d j D],}|d |jd|d |jddqXW|S)aConvert ec2 metadata to network config version 2 data dict. @param: network_md: 'network' portion of EC2 metadata. generally formed as {"interfaces": {"macs": {}} where 'macs' is a dictionary with mac address as key and contents like: {"device-number": "0", "interface-id": "...", "local-ipv4s": ...} @param: macs_to_nics: Optional dict of mac addresses and nic names. If not provided, get_interfaces_by_mac is called to get it from the OS. @param: fallback_nic: Optionally provide the primary nic interface name. This nic will be guaranteed to minimally have a dhcp4 configuration. @param: full_network_config: Boolean set True to configure all networking presented by IMDS. This includes rendering secondary IPv4 and IPv6 addresses on all NICs and rendering network config on secondary NICs. If False, only the primary nic will be configured and only with dhcp (IPv4/IPv6). @return A dict of network config version 2 based on the metadata and macs. )version ethernetsrOrPTFZ macaddress)dhcp4dhcp6matchzset-nameipv6srrrz device-numberrz route-metricd)rzdhcp4-overridesrrzset-namezdhcp6-overrides addresseszdhcp4-overridesN) rZget_interfaces_by_macrQrWrJsortedrget_secondary_addressespoprkeys) Z network_mdZ macs_to_nicsrrZnetcfgZ macs_metadatamacZnic_nameZ dev_config nic_metadataZnic_idxZ dhcp_overrider r r!rwsR            rcCs|jd}|jd}g}tt|to.t|dkrH|jt|d||dtt|to^t|dkrx|jt|d||dt|S)zParse interface-specific nic metadata and return any secondary IPs :return: List of secondary IPv4 or IPv6 addresses to configure on the interface z local-ipv4srrzsubnet-ipv4-cidr-blockZ24zsubnet-ipv6-cidr-blockZ128)rJrrrrextend_get_secondary_addressesr)rrZipv4srrr r r!rs  rc Csg}|j|}|}| s*t|jddkrPd|kr6dnd}tjd|||||n|jdd}x(|ddD]} |jdj| |d qlW|S) zReturn list of IP addresses as CIDRs for secondary IPs The CIDR prefix will be default_prefix if cidr_key is absent or not parseable in nic_metadata. rrr4r5zJCould not parse %s %s for mac %s. %s network config prefix defaults to /%srNz {ip}/{prefix})ipprefix)rJrsplitrAr|rwrb) rZcidr_keyrZipsZdefault_prefixrZcidrrZip_typerr r r!rs  rcCs tj|tS)N)rZlist_from_depends datasources)Zdependsr r r!get_datasource_listsr)rrr)NNT)9rZloggingrrZtypingrZ cloudinitrrrrrcrrZcloudinit.eventr r Zcloudinit.net.dhcpr Zcloudinit.net.ephemeralr Zcloudinit.sources.helpersr Z getLoggerrrA frozensetZ NOT_FOUNDZSKIP_METADATA_URL_CODESr?r@rr%rrrvZ DataSourcer&rr=rrrrrrrrr1rrrrZDEP_FILESYSTEMZ DEP_NETWORKrrr r r r! sT         !  0 H