From 46ae6ad6151e3a05d80a0d7cfd9e44841fb4bcfd Mon Sep 17 00:00:00 2001 From: Jan-Simon Möller Date: Tue, 16 Aug 2016 18:26:19 +0200 Subject: Initial version of the ci-management repo MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Based on the open-o template. Modified for AGL. v2 fixed host key and only pushing ci-management jobs. - fix macro vs. definition in file Change-Id: I2de02a572a5d8ca1bf6b7a56bfd2e30bfe18fa9a Signed-off-by: Jan-Simon Möller --- packer/provision/basebuild.sh | 4 + packer/provision/basebuild/.dummy | 0 packer/provision/baseline.sh | 168 ++++++++++++++++++++++++++++++++++++++ packer/provision/null_data.sh | 4 + packer/provision/rh-user_data.sh | 4 + packer/provision/system_reseal.sh | 38 +++++++++ 6 files changed, 218 insertions(+) create mode 100644 packer/provision/basebuild.sh create mode 100644 packer/provision/basebuild/.dummy create mode 100644 packer/provision/baseline.sh create mode 100644 packer/provision/null_data.sh create mode 100644 packer/provision/rh-user_data.sh create mode 100644 packer/provision/system_reseal.sh (limited to 'packer/provision') diff --git a/packer/provision/basebuild.sh b/packer/provision/basebuild.sh new file mode 100644 index 00000000..01445ff6 --- /dev/null +++ b/packer/provision/basebuild.sh @@ -0,0 +1,4 @@ +#!/bin/bash -x +# vim: set tw=4 sw=4 sts=4 et : + +# Presently nothing to do diff --git a/packer/provision/basebuild/.dummy b/packer/provision/basebuild/.dummy new file mode 100644 index 00000000..e69de29b diff --git a/packer/provision/baseline.sh b/packer/provision/baseline.sh new file mode 100644 index 00000000..36783554 --- /dev/null +++ b/packer/provision/baseline.sh @@ -0,0 +1,168 @@ +#!/bin/bash + +# vim: ts=4 sw=4 sts=4 et tw=72 : + +rh_systems() { + # Handle the occurance where SELINUX is actually disabled + SELINUX=$(grep -E '^SELINUX=(disabled|permissive|enforcing)$' /etc/selinux/config) + MODE=$(echo "$SELINUX" | cut -f 2 -d '=') + case "$MODE" in + permissive) + echo "************************************" + echo "** SYSTEM ENTERING ENFORCING MODE **" + echo "************************************" + # make sure that the filesystem is properly labelled. + # it could be not fully labeled correctly if it was just switched + # from disabled, the autorelabel misses some things + # skip relabelling on /dev as it will generally throw errors + restorecon -R -e /dev / + + # enable enforcing mode from the very start + setenforce enforcing + + # configure system for enforcing mode on next boot + sed -i 's/SELINUX=permissive/SELINUX=enforcing/' /etc/selinux/config + ;; + disabled) + sed -i 's/SELINUX=disabled/SELINUX=permissive/' /etc/selinux/config + touch /.autorelabel + + echo "*******************************************" + echo "** SYSTEM REQUIRES A RESTART FOR SELINUX **" + echo "*******************************************" + ;; + enforcing) + echo "*********************************" + echo "** SYSTEM IS IN ENFORCING MODE **" + echo "*********************************" + ;; + esac + + echo "---> Updating operating system" + yum clean all -q + yum install -y -q deltarpm + yum update -y -q + + # add in components we need or want on systems + echo "---> Installing base packages" + yum install -y -q @base https://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm + # separate group installs from package installs since a non-existing + # group with dnf based systems (F21+) will fail the install if such + # a group does not exist + yum install -y -q unzip xz puppet git perl-XML-XPath wget make + + # All of our systems require Java (because of Jenkins) + # Install all versions of the OpenJDK devel but force 1.7.0 to be the + # default + + echo "---> Configuring OpenJDK" + yum install -y -q 'java-*-openjdk-devel' + + FACTER_OS=$(/usr/bin/facter operatingsystem) + FACTER_OSVER=$(/usr/bin/facter operatingsystemrelease) + case "$FACTER_OS" in + Fedora) + if [ "$FACTER_OSVER" -ge "21" ] + then + echo "---> not modifying java alternatives as OpenJDK 1.7.0 does not exist" + else + alternatives --set java /usr/lib/jvm/jre-1.7.0-openjdk.x86_64/bin/java + alternatives --set java_sdk_openjdk /usr/lib/jvm/java-1.7.0-openjdk.x86_64 + fi + ;; + *) + alternatives --set java /usr/lib/jvm/jre-1.7.0-openjdk.x86_64/bin/java + alternatives --set java_sdk_openjdk /usr/lib/jvm/java-1.7.0-openjdk.x86_64 + ;; + esac +} + +ubuntu_systems() { + # Ignore SELinux since slamming that onto Ubuntu leads to + # frustration + + export DEBIAN_FRONTEND=noninteractive + cat <> /etc/apt/apt.conf +APT { + Get { + Assume-Yes "true"; + allow-change-held-packages "true"; + allow-downgrades "true"; + allow-remove-essential "true"; + }; +}; + +Dpkg::Options { + "--force-confdef"; + "--force-confold"; +}; + +EOF + + echo "---> Updating operating system" + apt-get update -qq > /dev/null + apt-get upgrade -qq > /dev/null + + # add in stuff we know we need + echo "---> Installing base packages" + apt-get install -qq unzip xz-utils puppet git libxml-xpath-perl make wget > /dev/null + + # install Java 7 + echo "---> Configuring OpenJDK" + apt-get install -qq openjdk-7-jdk > /dev/null + + # make jdk8 available + add-apt-repository -y ppa:openjdk-r/ppa > /dev/null + apt-get update -qq > /dev/null + # We need to force openjdk-8-jdk to install + apt-get install -qq openjdk-8-jdk > /dev/null + + # make sure that we still default to openjdk 7 + update-alternatives --set java /usr/lib/jvm/java-7-openjdk-amd64/jre/bin/java + update-alternatives --set javac /usr/lib/jvm/java-7-openjdk-amd64/bin/javac +} + +all_systems() { + # Allow jenkins access to update-alternatives command to switch java version + cat </etc/sudoers.d/89-jenkins-user-defaults +Defaults:jenkins !requiretty +jenkins ALL = NOPASSWD: /usr/bin/update-alternatives +EOF + + # Do any Distro specific installations here + echo "Checking distribution" + FACTER_OS=$(/usr/bin/facter operatingsystem) + case "$FACTER_OS" in + *) + echo "---> $FACTER_OS found" + echo "No extra steps for $FACTER_OS" + ;; + esac +} + +echo "---> Attempting to detect OS" +# upstream cloud images use the distro name as the initial user +ORIGIN=$(if [ -e /etc/redhat-release ] + then + echo redhat + else + echo ubuntu + fi) +#ORIGIN=$(logname) + +case "${ORIGIN}" in + fedora|centos|redhat) + echo "---> RH type system detected" + rh_systems + ;; + ubuntu) + echo "---> Ubuntu system detected" + ubuntu_systems + ;; + *) + echo "---> Unknown operating system" + ;; +esac + +# execute steps for all systems +all_systems diff --git a/packer/provision/null_data.sh b/packer/provision/null_data.sh new file mode 100644 index 00000000..3fa6a3c9 --- /dev/null +++ b/packer/provision/null_data.sh @@ -0,0 +1,4 @@ +#!/bin/bash +# vi: ts=4 sw=4 sts=4 et : + +# Nothing to do for Ubuntu specific provisioning diff --git a/packer/provision/rh-user_data.sh b/packer/provision/rh-user_data.sh new file mode 100644 index 00000000..6bddb244 --- /dev/null +++ b/packer/provision/rh-user_data.sh @@ -0,0 +1,4 @@ +#!/bin/bash +# vi: ts=4 sw=4 sts=4 et : + +/bin/sed -i 's/ requiretty/ !requiretty/' /etc/sudoers; diff --git a/packer/provision/system_reseal.sh b/packer/provision/system_reseal.sh new file mode 100644 index 00000000..f8bc7dc5 --- /dev/null +++ b/packer/provision/system_reseal.sh @@ -0,0 +1,38 @@ +#!/bin/bash + +# vim: sw=2 ts=2 sts=2 et : + +rm -rf /etc/Pegasus/*.cnf /etc/Pegasus/*.crt /etc/Pegasus/*.csr \ + /etc/Pegasus/*.pem /etc/Pegasus/*.srl /root/anaconda-ks.cfg \ + /root/anaconda-post.log /root/initial-setup-ks.cfg /root/install.log \ + /root/install.log.syslog /var/cache/fontconfig/* /var/cache/gdm/* \ + /var/cache/man/* /var/lib/AccountService/users/* /var/lib/fprint/* \ + /var/lib/logrotate.status /var/log/*.log* /var/log/BackupPC/LOG \ + /var/log/ConsoleKit/* /var/log/anaconda.syslog /var/log/anaconda/* \ + /var/log/apache2/*_log /var/log/apache2/*_log-* /var/log/apt/* \ + /var/log/aptitude* /var/log/audit/* /var/log/btmp* /var/log/ceph/*.log \ + /var/log/chrony/*.log /var/log/cron* /var/log/cups/*_log /var/log/debug* \ + /var/log/dmesg* /var/log/exim4/* /var/log/faillog* /var/log/gdm/* \ + /var/log/glusterfs/*glusterd.vol.log /var/log/glusterfs/glusterfs.log \ + /var/log/httpd/*log /var/log/installer/* /var/log/jetty/jetty-console.log \ + /var/log/journal/* /var/log/lastlog* /var/log/libvirt/libvirtd.log \ + /var/log/libvirt/lxc/*.log /var/log/libvirt/qemu/*.log \ + /var/log/libvirt/uml/*.log /var/log/lightdm/* /var/log/mail/* \ + /var/log/maillog* /var/log/messages* /var/log/ntp /var/log/ntpstats/* \ + /var/log/ppp/connect-errors /var/log/rhsm/* /var/log/sa/* /var/log/secure* \ + /var/log/setroubleshoot/*.log /var/log/spooler* /var/log/squid/*.log \ + /var/log/syslog* /var/log/tallylog* /var/log/tuned/tuned.log /var/log/wtmp* \ + /var/named/data/named.run + +rm -rf ~/.viminfo /etc/ssh/ssh*key* /root/.ssh/* + +# kill any cloud-init related bits +rm -rf /var/lib/cloud/* + +# clean-up any manual packer uploads +rm -rf /tmp/packer + +# Force a system sync and sleep to get around any SSD issues +echo "Forcing sync and sleep for 10sec" +sync +sleep 10 -- cgit 1.2.3-korg