had a few people ask if they could put their own name on the VMs they sell so had a go and wrote it up, in my own time for something to do over the weekend.
covers smbios1 and args for types 0/2/3/11 (serial from the vm name, sku from cores and memory), the seabios splash via -boot splash, rebuilding pve-edk2-firmware with a different Logo.bmp, dpkg-divert for the widget toolkit logo, and an apt hook that warns when your branded ovmf is older than the one proxmox now ships.
also tried an option rom that swaps the logo and the BGRT at boot without touching proxmox firmware. works on OVMF_CODE_4M.secboot.fd with the ms vars and secure boot enforcing.
couple of questions for staff if they're reading:
- OvmfPkgIa32X64.dsc sets PcdOptionRomImageVerificationPolicy to 0x00, so unsigned option roms run with secure boot on. is that deliberate for ipxe or worth tightening?
- the pre-start hookscript runs inside the config lock and config_to_command uses the conf loaded before it, so a hook can't change the start it's in. intended?
all tested on qemu 10.2.2 with proxmox firmware, not on a node yet thats for tomorow, so if anyone tries the option rom on 9.x let me know how it goes.
https://blogs.damiendye.uk/en/proxmox/branding-a-proxmox-vm/
code: https://github.com/damo2929/RebrandPCIRom
covers smbios1 and args for types 0/2/3/11 (serial from the vm name, sku from cores and memory), the seabios splash via -boot splash, rebuilding pve-edk2-firmware with a different Logo.bmp, dpkg-divert for the widget toolkit logo, and an apt hook that warns when your branded ovmf is older than the one proxmox now ships.
also tried an option rom that swaps the logo and the BGRT at boot without touching proxmox firmware. works on OVMF_CODE_4M.secboot.fd with the ms vars and secure boot enforcing.
couple of questions for staff if they're reading:
- OvmfPkgIa32X64.dsc sets PcdOptionRomImageVerificationPolicy to 0x00, so unsigned option roms run with secure boot on. is that deliberate for ipxe or worth tightening?
- the pre-start hookscript runs inside the config lock and config_to_command uses the conf loaded before it, so a hook can't change the start it's in. intended?
all tested on qemu 10.2.2 with proxmox firmware, not on a node yet thats for tomorow, so if anyone tries the option rom on 9.x let me know how it goes.
https://blogs.damiendye.uk/en/proxmox/branding-a-proxmox-vm/
code: https://github.com/damo2929/RebrandPCIRom
Last edited: