4 ms·
I, for one, am displeased with .yaml. I recently had a major footgun incident where a Debian VPS was rendered completely unbootable because of Ubuntu netplan's
by esbeeb 3y ago
I, for one, am displeased with .yaml. I recently had a major footgun incident where a Debian VPS was rendered completely unbootable because of Ubuntu netplan's highly-annoying use of YAML (where I had done the slightest misconfiguration, and to my eye it looked perfect, and my changes successfully passed the parser of "netplan try"). Yes, that's right - the server needed to be rebooted in rescue mode; it wasn't just merely stranded with no working network interfaces, where the web-based serial console would have been enough to undo the footgun gunshot. Nightmare!
The solution was to uninstall netplan.io Debian package where it didn't belong - get that YAML out of there. My hosting provider, OVH, figured it would be a good idea to shoehorn netplan - with its accursed YAML - into Debian for Network configuration. Bad move.
+1 for TOML. I love it's usage in innernet config files to set up new clients with a single generated "invitation" file.
- ArchOversight 3y agoIt's not your hosting provider that did that, it's the Debian project.
- rubatuga 3y agoAre you sure? Debian from what I understand uses standard /etc/network/interfaces
- mkj 3y agoDebian doesn't usually use netplan? It's written by Canonical for Ubuntu.
- vbernat 3y agoThis is now part of the cloud images for Debian.
- esbeeb 3y agoAnd then OVH makes you hand-configure your IPv6 address, with netmask and IPv6 gateway - no DHCP6 for their VPS servers. Then they put the footgun in your hand by not mentioning the double-quotes requirements which YAML has for IPv6-with-netmask.
- totallywrong 3y agoBrought to you by the creators of Snap. Yeah that's probably the real issue. Don't touch anything by Canonical.
- deleted 3y ago[deleted]
- jeroenhd 3y agoI've broken plenty of networks by adding typos to /etc/network/interfaces and then running ifdown;ifup. Misconfiguration can happen no matter what format your config files are in.
- esbeeb 3y agoHere's what my serious error likely was: not putting double quotes around IPv6 addresses with netmask, as is seen in this example YAML snippet: allowed-ips: [0.0.0.0/0, "2001:fe:ad:de:ad:be:ef:1/24"] Note that the IPv4 addy didn't need the double quotes, but the IPv6 addy did. The parser should have picked this mistake up, and the server shouldn't have been crippled to the extent of needing a rescue. More docs seen here: https://netplan.readthedocs.io/en/latest/netplan-yaml/ https://netplan.readthedocs.io/en/latest/netplan-yaml/
- deleted 3y ago[deleted]
- AceJohnny2 3y agoYes, without the quotes, the IPv6 address gets interpreted a YAML mapping/dict because of the colon(s). Perhaps the trap is the complacency that YAML induces by not requiring quotes around keys/values, and so text risks being interpreted in unexpected ways. The infamous Norway Problem has the same root cause.
- esbeeb 3y ago...and TOML would have dodged this, because it requires the double-quotes in both cases (IPv4 and 6), like you say.
- xelxebar 3y ago> Yes, without the quotes, the IPv6 address gets interpreted a YAML mapping/dict because of the colon(s). This is incorrect. The colon needs to be followed by whitespace for it to indicate a key-value pair. You can check this with the reference parser (and a bunch of others!) online: https://play.yaml.io/main/parser?input=YWxsb3dlZC1pcHM6IFswLjAuMC4wLzAsIDIwMDE6ZmU6YWQ6ZGU6YWQ6YmU6ZWY6MS8yNF0K https://play.yaml.io/main/parser?input=YWxsb3dlZC1pcHM6IFswL...
- bravetraveler 3y agoRegardless of the styling, Netplan is such a footgun! I'm not convinced they'd define a sane schema for either. Like you've noticed... the trying logic is naive. IIRC if this passes the mild sniff test it will go ahead and apply. It can't realize changes on specific/named interfaces -- it insists on all or nothing.
- amluto 3y agoIn my rather short experience with netplan, I found: As above, you can’t ask netplan to sanity check a config. You can’t create a draft configuration, apply it, and save it if it works well. Every self-respecting network config system since at least Cisco IOS can do this (and does it by default!). Interface renaming can’t filter by being a physical interface, which means that the system tries, and fails, to rename VLANs, because their MAC matches something that should be renamed. (networkd can handle this, but the networkd config written by netplan is wrong.) Deleting virtual interfaces (e.g. VLANs) seems to be essentially unsupported, at least on 20.04. I think it’s slightly, but only slightly, better in newer releases. Not impressed.
- bravetraveler 3y agoOuch, quite a lot of 'learning'! Color me unimpressed, too. I've grown to enjoy NetworkManager. I know, like all things, that is probably controversial to some. Two things I really appreciate about it: - You can 'up' a connection/interface in an idempotent way; only changing whatever is needed. - it's *very* scriptable. Values can be given with +/- operators I was surprised/frustrated with networkd initially, but enjoy it now. It getting involved with packet forwarding was an unwanted surprise during a modernization effort.
- codethief 3y agoWhat's your experience been with innernet?
- esbeeb 3y agoWhen you have a linux-only scenario - say on your laptop, and servers, which is my case - innernet's simplicity and fairly-good elegance is tough to beat. As soon as Windows/MacOS/Android/iOS clients want in on the fun, alas, you'll need something more complicated than innernet to accommodate these other clients.
- codethief 3y agoThanks, that's good to know!
- linsomniac 3y agoUnpopular opinion I guess, but I really like netplan. I like having the vlan, bonding, ip, routing, dns configs all in one place, and it's worked well for me over 4-5 years.