Andrew Mercer
on this page

Offline image tools (libguestfs)

Part of the KVM overview. Change disk images without booting them: virt-customize, virt-edit, guestfish, virt-sysprep.

Work on a disk image without booting it. Shut the VM down first.

sudo dnf install libguestfs-tools        # or: apt install libguestfs-tools
export LIBGUESTFS_BACKEND=direct         # avoids libvirt permission problems (see troubleshooting)

Set the root password

virt-customize -a vm01.qcow2 --root-password random                 # prints the generated password
virt-customize -a vm01.qcow2 --root-password file:./rootpw

--root-password password:secret also works, but the password then appears in the process list and shell history.

Install packages, copy and edit files

virt-customize -a vm01.qcow2 --install vim,tmux --selinux-relabel     # relabel for SELinux guests
virt-customize -a vm01.qcow2 --copy-in ./sshd_config:/etc/ssh
virt-customize -a vm01.qcow2 --edit '/etc/ssh/sshd_config:s/^#PermitRootLogin.*/PermitRootLogin yes/'
virt-edit -a vm01.qcow2 /etc/iscsi/iscsid.conf -e 's/old/new/'
virt-ls -a vm01.qcow2 -l /etc
virt-cat -a vm01.qcow2 /etc/os-release

guestfish (interactive)

Manual alternative for a password reset:

openssl passwd -6                  # generates a SHA-512 crypt hash
guestfish --rw -a vm01.qcow2
><fs> run
><fs> list-filesystems
><fs> mount /dev/sda1 /
><fs> vi /etc/shadow               # replace the 2nd field of the user's line with the hash
><fs> quit

(openssl passwd -1 produces an MD5 hash, which is weak; use -6.)

Reference: https://www.cyberciti.biz/faq/how-to-reset-forgotten-root-password-for-linux-kvm-qcow2-image-vm

Templates

virt-sysprep -a vm01.qcow2 resets machine-specific state so the image can be reused. virt-sparsify --in-place vm01.qcow2 reclaims unused space.

libguestfs troubleshooting

Turn on debugging first:

export LIBGUESTFS_DEBUG=1 LIBGUESTFS_TRACE=1
libguestfs-test-tool

supermin: error: statvfs: No space left on device: /tmp or /var/tmp is too small for the appliance. Point it elsewhere:

mkdir -p ~/tmp
export TMPDIR=~/tmp TMP=~/tmp TEMP=~/tmp

error: could not create appliance through libvirt ... Permission denied (as uid 107): the libvirt backend cannot read your temp directory.

export LIBGUESTFS_BACKEND=direct