From f900fadd5300316320b4968b66bf2a59e77ff8d2 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Elan=20Ruusam=C3=A4e?= Date: Thu, 2 May 2013 13:23:23 +0300 Subject: [PATCH 1/6] add pld knife bootstrap script, based on ubuntu10.04-apt.erb --- lib/chef/knife/bootstrap/pld.erb | 48 ++++++++++++++++++++++++++++++++++++++++ 1 file changed, 48 insertions(+) create mode 100644 lib/chef/knife/bootstrap/pld.erb diff --git a/lib/chef/knife/bootstrap/pld.erb b/lib/chef/knife/bootstrap/pld.erb new file mode 100644 index 0000000..fb09899 --- /dev/null +++ b/lib/chef/knife/bootstrap/pld.erb @@ -0,0 +1,48 @@ +bash -c ' +<%= "export http_proxy=\"#{knife_config[:bootstrap_proxy]}\"" if knife_config[:bootstrap_proxy] -%> + +if [ ! -f /usr/bin/chef-client ]; then + poldek --up --noask -u chef +fi + +awk NF > /etc/chef/validation.pem <<'EOP' +<%= validation_key %> +EOP +chmod 0600 /etc/chef/validation.pem + +<% if @chef_config[:encrypted_data_bag_secret] -%> +awk NF > /etc/chef/encrypted_data_bag_secret <<'EOP' +<%= encrypted_data_bag_secret %> +EOP +chmod 0600 /etc/chef/encrypted_data_bag_secret +<% end -%> + +<%# Generate Ohai Hints -%> +<% unless @chef_config[:knife][:hints].nil? || @chef_config[:knife][:hints].empty? -%> +mkdir -p /etc/chef/ohai/hints + +<% @chef_config[:knife][:hints].each do |name, hash| -%> +cat > /etc/chef/ohai/hints/<%= name %>.json <<'EOP' +<%= hash.to_json %> +EOP +<% end -%> +<% end -%> + +<% unless @chef_config[:validation_client_name] == "chef-validator" -%> +[ `grep -qx "validation_client_name \"<%= @chef_config[:validation_client_name] %>\"" /etc/chef/client.rb` ] || echo "validation_client_name \"<%= @chef_config[:validation_client_name] %>\"" >> /etc/chef/client.rb +<% end -%> + +<% if @config[:chef_node_name] %> +[ `grep -qx "node_name \"<%= @config[:chef_node_name] %>\"" /etc/chef/client.rb` ] || echo "node_name \"<%= @config[:chef_node_name] %>\"" >> /etc/chef/client.rb +<% end -%> + +<% if knife_config[:bootstrap_proxy] %> +echo 'http_proxy "knife_config[:bootstrap_proxy]"' >> /etc/chef/client.rb +echo 'https_proxy "knife_config[:bootstrap_proxy]"' >> /etc/chef/client.rb +<% end -%> + +cat > /etc/chef/first-boot.json <<'EOP' +<%= first_boot.to_json %> +EOP + +<%= start_chef %>' -- 1.8.4 From ec04901ef1de7c3ee20492d63da4ebbade367df1 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Elan=20Ruusam=C3=A4e?= Date: Tue, 25 Jun 2013 09:43:24 +0300 Subject: [PATCH 2/6] create chef client as a whole if file is missing --- lib/chef/knife/bootstrap/pld.erb | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/lib/chef/knife/bootstrap/pld.erb b/lib/chef/knife/bootstrap/pld.erb index fb09899..741a94c 100644 --- a/lib/chef/knife/bootstrap/pld.erb +++ b/lib/chef/knife/bootstrap/pld.erb @@ -1,4 +1,4 @@ -bash -c ' +sh -c ' <%= "export http_proxy=\"#{knife_config[:bootstrap_proxy]}\"" if knife_config[:bootstrap_proxy] -%> if [ ! -f /usr/bin/chef-client ]; then @@ -28,6 +28,14 @@ EOP <% end -%> <% end -%> +# create client if none present +if [ ! -e /etc/chef/client.rb ]; then +cat > /etc/chef/client.rb <<'EOP' +<%= config_content %> +EOP +fi + +# update existing config <% unless @chef_config[:validation_client_name] == "chef-validator" -%> [ `grep -qx "validation_client_name \"<%= @chef_config[:validation_client_name] %>\"" /etc/chef/client.rb` ] || echo "validation_client_name \"<%= @chef_config[:validation_client_name] %>\"" >> /etc/chef/client.rb <% end -%> -- 1.8.4 From f969809806fe5e6f29fb0f93ceef806fa02288f6 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Elan=20Ruusam=C3=A4e?= Date: Thu, 11 Jul 2013 20:01:00 +0300 Subject: [PATCH 3/6] workaround for locale issues --- lib/chef/knife/bootstrap/pld.erb | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/lib/chef/knife/bootstrap/pld.erb b/lib/chef/knife/bootstrap/pld.erb index 741a94c..1b77097 100644 --- a/lib/chef/knife/bootstrap/pld.erb +++ b/lib/chef/knife/bootstrap/pld.erb @@ -53,4 +53,8 @@ cat > /etc/chef/first-boot.json <<'EOP' <%= first_boot.to_json %> EOP +# fix for locale issues +# also http://tickets.opscode.com/browse/OHAI-245 +export LC_ALL=en_US.utf8 + <%= start_chef %>' -- 1.8.4 From fb5b1b9522c227c333726561cc7860ba8258bb07 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Elan=20Ruusam=C3=A4e?= Date: Wed, 27 Nov 2013 11:48:25 +0200 Subject: [PATCH 4/6] do not use single quotes, the sh -c would break out from these --- lib/chef/knife/bootstrap/pld.erb | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/lib/chef/knife/bootstrap/pld.erb b/lib/chef/knife/bootstrap/pld.erb index 1b77097..ef3a5a5 100644 --- a/lib/chef/knife/bootstrap/pld.erb +++ b/lib/chef/knife/bootstrap/pld.erb @@ -5,13 +5,13 @@ if [ ! -f /usr/bin/chef-client ]; then poldek --up --noask -u chef fi -awk NF > /etc/chef/validation.pem <<'EOP' +awk NF > /etc/chef/validation.pem < EOP chmod 0600 /etc/chef/validation.pem <% if @chef_config[:encrypted_data_bag_secret] -%> -awk NF > /etc/chef/encrypted_data_bag_secret <<'EOP' +awk NF > /etc/chef/encrypted_data_bag_secret < EOP chmod 0600 /etc/chef/encrypted_data_bag_secret @@ -22,7 +22,7 @@ chmod 0600 /etc/chef/encrypted_data_bag_secret mkdir -p /etc/chef/ohai/hints <% @chef_config[:knife][:hints].each do |name, hash| -%> -cat > /etc/chef/ohai/hints/<%= name %>.json <<'EOP' +cat > /etc/chef/ohai/hints/<%= name %>.json < EOP <% end -%> @@ -30,7 +30,7 @@ EOP # create client if none present if [ ! -e /etc/chef/client.rb ]; then -cat > /etc/chef/client.rb <<'EOP' +cat > /etc/chef/client.rb < EOP fi @@ -45,11 +45,11 @@ fi <% end -%> <% if knife_config[:bootstrap_proxy] %> -echo 'http_proxy "knife_config[:bootstrap_proxy]"' >> /etc/chef/client.rb -echo 'https_proxy "knife_config[:bootstrap_proxy]"' >> /etc/chef/client.rb +echo http_proxy "knife_config[:bootstrap_proxy]" >> /etc/chef/client.rb +echo https_proxy "knife_config[:bootstrap_proxy]" >> /etc/chef/client.rb <% end -%> -cat > /etc/chef/first-boot.json <<'EOP' +cat > /etc/chef/first-boot.json < EOP -- 1.8.4 From 442721c2cf5ece493932d509d35253479ecf5ceb Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Elan=20Ruusam=C3=A4e?= Date: Wed, 27 Nov 2013 11:53:00 +0200 Subject: [PATCH 5/6] install gpg keys, install some essential programs --- lib/chef/knife/bootstrap/pld.erb | 29 ++++++++++++++++++++++++++++- 1 file changed, 28 insertions(+), 1 deletion(-) diff --git a/lib/chef/knife/bootstrap/pld.erb b/lib/chef/knife/bootstrap/pld.erb index ef3a5a5..5468b52 100644 --- a/lib/chef/knife/bootstrap/pld.erb +++ b/lib/chef/knife/bootstrap/pld.erb @@ -1,8 +1,35 @@ sh -c ' <%= "export http_proxy=\"#{knife_config[:bootstrap_proxy]}\"" if knife_config[:bootstrap_proxy] -%> +dist=$(rpm -E "%{pld_release}") +arch=$(rpm --qf "%{ARCH}" -q rpm) + +# be sure gpg keys are present +case "$dist" in +ac) + rpm -q gpg-pubkey-1bbd5459-461e5d1e || rpm --import /etc/pki/rpm-gpg/PLD-2.0-Ac-GPG-key.asc + ;; +th) + rpm -q gpg-pubkey-e64e7bf7-47b35206 || rpm --import /etc/pki/rpm-gpg/PLD-3.0-Th-GPG-key.asc + ;; +esac + +# some cookbook requires which +rpm -q which || poldek -u which + +# motd cookbook needs bash +rpm -q bash || poldek -u bash + +# chef 11.6 needs diff to show diffs (newer does it in ruby) +rpm -q diffutils || poldek -u diffutils + +# networking is not inited properly +# /sbin/ip is missing. Cant continue. +# ERROR: Networking is down. OpenSSH cant be run. +test -x /sbin/ip || poldek -u iproute2 --noask + if [ ! -f /usr/bin/chef-client ]; then - poldek --up --noask -u chef + poldek --up --noask -u chef fi awk NF > /etc/chef/validation.pem < Date: Wed, 27 Nov 2013 14:26:06 +0200 Subject: [PATCH 6/6] handle vserver bootstrap with json attribute vserver_name --- lib/chef/knife/bootstrap/pld.erb | 3 +++ 1 file changed, 3 insertions(+) diff --git a/lib/chef/knife/bootstrap/pld.erb b/lib/chef/knife/bootstrap/pld.erb index 5468b52..3b51b74 100644 --- a/lib/chef/knife/bootstrap/pld.erb +++ b/lib/chef/knife/bootstrap/pld.erb @@ -1,3 +1,6 @@ +<% if !first_boot['vserver_name'].nil? -%> +vserver <%= first_boot['vserver_name'] %> exec \ +<% end -%> sh -c ' <%= "export http_proxy=\"#{knife_config[:bootstrap_proxy]}\"" if knife_config[:bootstrap_proxy] -%> -- 1.8.4