[2024-feb-29] Sad news: Eric Layton aka Nocturnal Slacker aka vtel57 passed away on Feb 26th, shortly after hospitalization. He was one of our Wiki's most prominent admins. He will be missed.
Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revisionNext revisionBoth sides next revision | ||
howtos:emulators:helper_script_for_managing_qemu_virtual_machines [2016/09/01 07:05 (UTC)] – [Networking] louigi600 | howtos:emulators:helper_script_for_managing_qemu_virtual_machines [2016/09/01 09:25 (UTC)] – [Using Qemu from Unprivileged Users] louigi600 | ||
---|---|---|---|
Line 361: | Line 361: | ||
I like to write a single script qemu-nethelper and have qemu-ifup and qemu-ifdown linked to it. The qemu-system-* emulators all execute / | I like to write a single script qemu-nethelper and have qemu-ifup and qemu-ifdown linked to it. The qemu-system-* emulators all execute / | ||
- | As mentioned above newer versions of qemu (I think 1.1+) automatically create the tap device so the qemu-nethelper only needs to do the bridging. Now to make things a lot easier I like to have the host on which I run VMs with br0 configured at boot and then the qemu-nethelper only needs to add the tap device to the bridge, making it extremely simple. If br0 is already configured at boot then you need not restart any iptables so long as the chains use the bridge devices | + | As mentioned above newer versions of qemu (I think 1.1+) automatically create the tap device so the qemu-nethelper only needs to do the bridging. Now to make things a lot easier I like to have the host on which I run VMs with br0 configured at boot and then the qemu-nethelper only needs to add the tap device to the bridge, making it extremely simple. If br0 is already configured at boot then you need not restart any iptables so long as the chains use the bridge devices |
#!/bin/bash | #!/bin/bash | ||
NAME=$(basename $0) | NAME=$(basename $0) | ||
- | | + | |
{ / | { / | ||
/ | / | ||
Line 383: | Line 383: | ||
esac | esac | ||
+ | ===== Using Qemu from Unprivileged Users ===== | ||
+ | Using root for doing your everyday tasks is commonly discouraged so let's see how we can work around using qemu from unprivileged users. | ||
+ | Some say that it's sufficient to give sudo execution on / | ||
+ | |||
+ | User_Alias QEMUERS = al, john, jack | ||
+ | | ||
+ | Cmnd_Alias QEMUCMD = / | ||
+ | | ||
+ | QEMUERS ALL=(ALL) NOPASSWD: QEMU | ||
+ | |||
+ | This would be sufficient to run the VMs as any of the unprivileged users in QEMUERS user alias (al, john, jack) but the management script would need to run sudo qemu-system-* .... this is easy to obtain: | ||
+ | |||
+ | [ $(/ | ||
+ | eval $(echo "$CMD &" | ||
+ | |||
+ | Alternatively you could give privileges to execute the management script as root. | ||
===== Examples ===== | ===== Examples ===== | ||
Here are examples of the dialogs that user would see wile creating, starting, stopping and deleting a VM. | Here are examples of the dialogs that user would see wile creating, starting, stopping and deleting a VM. |