# PVE

## Balloon

在 Monitor 中执行 `balloon 1024` 来把客户机内存设置为 1024MB。`info balloon` 查看自动分了多少内存。

## 容器使用

容器内非 root 用户无法使用 ping 时，运行 `sudo setcap 'cap_net_raw+p' /usr/bin/ping` 即可。

## ZFS

### Trim

ZFS 支持 trim 指令，但是 PVE 默认没有开启。不开启 trim 会潜在地影响 SSD 寿命或降低磁盘利用效率（如果 PVE 安装在 thin-provisioning 的虚拟机里）。

使用以下命令查询 trim 开启状态：

```bash
zpool get autotrim rpool
```

使用以下命令立即执行 trim：

```bash
zpool trim rpool
```

使用以下命令开启自动 trim：

```bash
zpool set autotrim=on rpool
```

TO-DO: 我记得某个情况下自动 trim 效果不好来着，以前还专门做过实验，但是结果忘了。

## 微码更新

PVE 仓库默认不带微码更新，可以用 Debian 的：<https://wiki.debian.org/Microcode>

要注意的是，从 Debian 12 (bookworm) 开始，要用“non-free-firmware”，添加到“/etc/apt/source.list”中每一行的末尾：

```none
deb http://ftp.ca.debian.org/debian bookworm main contrib non-free-firmware

deb http://ftp.ca.debian.org/debian bookworm-updates main contrib non-free-firmware

# security updates
deb http://security.debian.org bookworm-security main contrib non-free-firmware
```

完成后，根据你是 AMD 还是 Intel，运行

```bash
apt update
apt install amd64-microcode
```

或

```bash
apt update
apt install intel-microcode
```

重启后，执行 `dmesg | grep microcode`，如果输出中有“updated early”等字样，指示从哪个版本升级到了哪个版本即为成功。注意不是所有情况都会通过操作系统更新微码，例如较新的 BIOS 有时集成了最新的微码，就不需通过操作系统更新了。

### AMD

我使用的 AMD 5800H 截止本文更新时，微码更新无论是否安装，微码都是“0x0a50000d”版本。执行 `lscpu` 会输出以下 Vulnerability：

```none
  Spec rstack overflow:  Vulnerable: Safe RET, no microcode
```

在 <https://packages.debian.org/search?keywords=amd64-microcode> 中可知“testing”中有比“stable”更新的包，但是该版本也并不能提供更高版本的微码。

从[其他来源](https://github.com/divestedcg/real-ucode)发现 5800H 的最新微码应该是“0x0a50000f”，尚不清除该版本是否缓解了上述漏洞。

#### 关于 AMD Speculative Return Stack Overflow (SRSO) 的额外注意点

如果你执行 `lscpu` 时出现 `Spec rstack overflow:  Mitigation: Safe RET, no microcode`，这并不代表真的缓解了。[Linux 内核文档](https://docs.kernel.org/admin-guide/hw-vuln/srso.html)中提到该漏洞必须通过微码更新来缓解。实际上，如果你更新到最新内核，但不更新微码，该条信息会从“Mitigation”变为“Vulnerable”。也就是说，没有微码修复的 Mitigation 实际上是不完整的。

另见：<https://lore.kernel.org/lkml/20230814125249.GCZNojoW8pC+ToOews@fat_crate.local/T/>

## 观察有没有超内存

```bash
watch "tail -n +1 /proc/pressure/* && echo "" && free -h && echo "" && zramctl"
```

---

**Documents**

- [在集群中迁移客户机](https://notes.bleatingsheep.org/s/proxmox-ve/doc/5zyo6zug576k5lit6lb56e75a6i5oi35py6-JnoJCmDnaI)
- [给日日的 Proxmox VE 安装、使用、维护的注意事项](https://notes.bleatingsheep.org/s/proxmox-ve/doc/proxmox-ve-VUiIqjLgW6)
- [cloud-init 自定义 user-data](https://notes.bleatingsheep.org/s/proxmox-ve/doc/cloud-init-user-data-OMk3IeECEN)
- [Windows guest](https://notes.bleatingsheep.org/s/proxmox-ve/doc/windows-guest-3tv03P8Lhf)