Richard Felkl | 4c4829d | 2017-11-11 00:12:20 +0100 | [diff] [blame] | 1 | #!/bin/bash -xe |
alexz | d90608b | 2018-04-12 23:49:03 +0200 | [diff] [blame] | 2 | |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 3 | #============================================================================== |
Ivan Berezovskiy | 7718717 | 2018-09-14 15:47:36 +0400 | [diff] [blame] | 4 | # This file is no longer used for cfg node configuration. |
| 5 | # Please use master_config.yaml for that purpose. |
| 6 | #============================================================================== |
| 7 | |
| 8 | #============================================================================== |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 9 | # Required packages: |
| 10 | # apt-get install -y jq |
| 11 | #============================================================================== |
Petr Ruzicka | 6f9aea0 | 2018-06-19 16:46:01 +0200 | [diff] [blame] | 12 | export SALT_MASTER_DEPLOY_IP=${SALT_MASTER_DEPLOY_IP:-"172.16.164.15"} |
| 13 | export SALT_MASTER_MINION_ID=${SALT_MASTER_MINION_ID:-"cfg01.deploy-name.local"} |
| 14 | export DEPLOY_NETWORK_GW=${DEPLOY_NETWORK_GW:-"172.16.164.1"} |
| 15 | export DEPLOY_NETWORK_NETMASK=${DEPLOY_NETWORK_NETMASK:-"255.255.255.192"} |
Petr Ruzicka | a540745 | 2018-07-03 12:30:16 +0200 | [diff] [blame] | 16 | export DEPLOY_NETWORK_MTU=${DEPLOY_NETWORK_MTU:-"1500"} |
Petr Ruzicka | 6f9aea0 | 2018-06-19 16:46:01 +0200 | [diff] [blame] | 17 | export DNS_SERVERS=${DNS_SERVERS:-"8.8.8.8"} |
| 18 | export http_proxy=${http_proxy:-""} |
| 19 | export https_proxy=${https_proxy:-""} |
| 20 | export PIPELINES_FROM_ISO=${PIPELINES_FROM_ISO:-"true"} |
| 21 | export PIPELINE_REPO_URL=${PIPELINE_REPO_URL:-"https://github.com/Mirantis"} |
| 22 | export MCP_VERSION=${MCP_VERSION:-"stable"} |
| 23 | export MCP_SALT_REPO_KEY=${MCP_SALT_REPO_KEY:-"http://apt.mirantis.com/public.gpg"} |
| 24 | export MCP_SALT_REPO_URL=${MCP_SALT_REPO_URL:-"http://apt.mirantis.com/xenial"} |
Richard Felkl | 98b4534 | 2018-04-06 13:30:28 +0200 | [diff] [blame] | 25 | export MCP_SALT_REPO="deb [arch=amd64] $MCP_SALT_REPO_URL $MCP_VERSION salt" |
| 26 | export FORMULAS="salt-formula-*" |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 27 | # for cloning from aptly image use port 8088 |
Jiri Broulik | cee2053 | 2018-01-08 13:30:15 +0100 | [diff] [blame] | 28 | #export PIPELINE_REPO_URL=http://172.16.47.182:8088 |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 29 | # |
| 30 | SALT_OPTS="-l debug -t 10 --retcode-passthrough --no-color" |
Richard Felkl | 4c4829d | 2017-11-11 00:12:20 +0100 | [diff] [blame] | 31 | |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 32 | # Funcs ======================================================================= |
alexz | d90608b | 2018-04-12 23:49:03 +0200 | [diff] [blame] | 33 | function _post_maas_cfg(){ |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 34 | chmod 0755 /var/lib/maas/.maas_login.sh |
| 35 | source /var/lib/maas/.maas_login.sh |
| 36 | # disable backports for maas enlist pkg repo. Those operation enforce maas |
| 37 | # to re-create sources.list and drop [source] fetch-definition from it. |
| 38 | main_arch_id=$(maas ${PROFILE} package-repositories read | jq -r '.[] | select(.name=="main_archive") | .id') |
| 39 | maas ${PROFILE} package-repository update ${main_arch_id} "disabled_pockets=backports" || true |
| 40 | maas ${PROFILE} package-repository update ${main_arch_id} "disabled_components=multiverse" || true |
| 41 | maas ${PROFILE} package-repository update ${main_arch_id} "arches=amd64" || true |
| 42 | # Remove stale notifications, which appear during sources configuration. |
| 43 | for i in $(maas ${PROFILE} notifications read | jq '.[]| .id'); do |
| 44 | maas ${PROFILE} notification delete ${i} || true |
Pavel Cizinsky | 5f8fb09 | 2018-05-30 17:27:19 +0200 | [diff] [blame] | 45 | done |
alexz | d90608b | 2018-04-12 23:49:03 +0200 | [diff] [blame] | 46 | } |
| 47 | |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 48 | function process_formulas(){ |
| 49 | local RECLASS_ROOT=${RECLASS_ROOT:-/srv/salt/reclass/} |
| 50 | local FORMULAS_PATH=${FORMULAS_PATH:-/usr/share/salt-formulas} |
| 51 | |
| 52 | echo "Configuring formulas ..." |
| 53 | curl -s $MCP_SALT_REPO_KEY | apt-key add - |
| 54 | echo $MCP_SALT_REPO > /etc/apt/sources.list.d/mcp_salt.list |
| 55 | apt-get update |
| 56 | apt-get install -y $FORMULAS |
| 57 | |
| 58 | [ ! -d ${RECLASS_ROOT}/classes/service ] && mkdir -p ${RECLASS_ROOT}/classes/service |
| 59 | for formula_service in $(ls /usr/share/salt-formulas/reclass/service/); do |
| 60 | #Since some salt formula names contain "-" and in symlinks they should contain "_" adding replacement |
| 61 | formula_service=${formula_service//-/$'_'} |
Dennis Dmitriev | e00716b | 2018-07-05 14:50:45 +0300 | [diff] [blame] | 62 | if [ ! -L "${RECLASS_ROOT}/classes/service/${formula_service}" ]; then |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 63 | ln -sf ${FORMULAS_PATH}/reclass/service/${formula_service} ${RECLASS_ROOT}/classes/service/${formula_service} |
Dennis Dmitriev | e00716b | 2018-07-05 14:50:45 +0300 | [diff] [blame] | 64 | fi |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 65 | done |
| 66 | } |
| 67 | |
| 68 | function enable_services(){ |
| 69 | local services="postgresql.service salt-api salt-master salt-minion jenkins" |
| 70 | for s in ${services} ; do |
| 71 | systemctl enable ${s} || true |
| 72 | systemctl restart ${s} || true |
| 73 | done |
| 74 | } |
| 75 | |
| 76 | function process_network(){ |
| 77 | echo "Configuring network interfaces" |
| 78 | find /etc/network/interfaces.d/ -type f -delete |
| 79 | kill $(pidof /sbin/dhclient) || /bin/true |
| 80 | envsubst < /root/interfaces > /etc/network/interfaces |
| 81 | ip a flush dev ens3 |
| 82 | rm -f /var/run/network/ifstate.ens3 |
| 83 | if [[ $(grep -E '^\ *gateway\ ' /etc/network/interfaces) ]]; then |
| 84 | (ip r s | grep ^default) && ip r d default || /bin/true |
| 85 | fi; |
| 86 | ifup ens3 |
| 87 | } |
| 88 | |
azvyagintsev | 42a4762 | 2018-07-06 13:12:08 +0300 | [diff] [blame] | 89 | function process_maas(){ |
Ivan Berezovskiy | 6b938d9 | 2018-09-11 16:12:39 +0400 | [diff] [blame] | 90 | postgres_enabled=$(salt-call --out=text pillar.get postgresql:server:enabled | awk '{print $2}' | tr "[:upper:]" "[:lower:]") |
| 91 | if [[ "${postgres_enabled}" == "true" ]]; then |
| 92 | salt-call ${SALT_OPTS} state.sls postgresql.server |
| 93 | fi |
| 94 | |
azvyagintsev | 42a4762 | 2018-07-06 13:12:08 +0300 | [diff] [blame] | 95 | _region=$(salt-call --out=text pillar.get maas:region:enabled | awk '{print $2}' | tr "[:upper:]" "[:lower:]" ) |
| 96 | if [[ "${maas_cluster_enabled}" == 'true' ]]; then |
| 97 | salt-call ${SALT_OPTS} state.sls maas.cluster |
| 98 | else |
| 99 | echo 'WARNING: maas.cluster skipped!' |
| 100 | fi |
| 101 | if [[ "$_region" == 'true' ]]; then |
azvyagintsev | d453a71 | 2018-08-03 10:50:59 +0200 | [diff] [blame] | 102 | # FIXME MAAS still can fail in rare race condition. |
| 103 | salt-call ${SALT_OPTS} state.sls maas.region || salt-call ${SALT_OPTS} state.sls maas.region |
azvyagintsev | 42a4762 | 2018-07-06 13:12:08 +0300 | [diff] [blame] | 104 | else |
| 105 | echo 'WARNING: maas.region skipped!' |
| 106 | fi |
| 107 | # Don't move it under first cluster-only check! |
| 108 | if [[ "${maas_cluster_enabled}" == 'true' ]]; then |
| 109 | _post_maas_cfg |
| 110 | fi |
| 111 | } |
| 112 | |
| 113 | function process_jenkins(){ |
| 114 | _jjobs=$(salt-call --out=text pillar.get jenkins:client:job | awk '{print $2}') |
| 115 | if [[ "${_jjobs}" != '' ]]; then |
| 116 | salt-call ${SALT_OPTS} state.sls jenkins.client |
| 117 | fi |
| 118 | } |
| 119 | |
Petr Ruzicka | 6982da3 | 2018-08-09 15:11:06 +0200 | [diff] [blame] | 120 | failsafe_ssh_key(){ |
| 121 | if [ -f /mnt/root_auth_keys ]; then |
| 122 | echo "Installing failsafe public ssh key from /mnt/root_auth_keys to /root/.ssh/authorized_keys" |
| 123 | install -m 0700 -d /root/.ssh |
| 124 | cat /mnt/root_auth_keys >> /root/.ssh/authorized_keys |
| 125 | chmod 600 /root/.ssh/authorized_keys |
| 126 | sed -i 's/^PermitRootLogin.*/PermitRootLogin yes/g' /etc/ssh/sshd_config |
| 127 | sed -i 's/^PasswordAuthentication.*/PasswordAuthentication yes/g' /etc/ssh/sshd_config |
| 128 | service ssh restart |
| 129 | fi |
| 130 | } |
| 131 | |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 132 | # Body ======================================================================== |
| 133 | process_network |
Richard Felkl | 4c4829d | 2017-11-11 00:12:20 +0100 | [diff] [blame] | 134 | |
| 135 | echo "Preparing metadata model" |
| 136 | mount /dev/cdrom /mnt/ |
Leontii Istomin | 68553f1 | 2018-02-21 18:10:12 +0100 | [diff] [blame] | 137 | cp -rT /mnt/model/model /srv/salt/reclass |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 138 | chown -R root:root /srv/salt/reclass/* || true |
alexz | d90608b | 2018-04-12 23:49:03 +0200 | [diff] [blame] | 139 | chown -R root:root /srv/salt/reclass/.git* || true |
| 140 | chmod -R 644 /srv/salt/reclass/classes/cluster/* || true |
| 141 | chmod -R 644 /srv/salt/reclass/classes/system/* || true |
Richard Felkl | 4c4829d | 2017-11-11 00:12:20 +0100 | [diff] [blame] | 142 | |
Petr Ruzicka | 6982da3 | 2018-08-09 15:11:06 +0200 | [diff] [blame] | 143 | failsafe_ssh_key |
| 144 | |
Richard Felkl | 4c4829d | 2017-11-11 00:12:20 +0100 | [diff] [blame] | 145 | echo "Configuring salt" |
Richard Felkl | 4c4829d | 2017-11-11 00:12:20 +0100 | [diff] [blame] | 146 | envsubst < /root/minion.conf > /etc/salt/minion.d/minion.conf |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 147 | enable_services |
Dennis Dmitriev | e00716b | 2018-07-05 14:50:45 +0300 | [diff] [blame] | 148 | |
| 149 | # Wait for salt-master and salt-minion to wake up after restart |
| 150 | salt-call --timeout=120 test.ping |
| 151 | |
Richard Felkl | 4c4829d | 2017-11-11 00:12:20 +0100 | [diff] [blame] | 152 | while true; do |
| 153 | salt-key | grep "$SALT_MASTER_MINION_ID" && break |
| 154 | sleep 5 |
| 155 | done |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 156 | |
Richard Felkl | 4c4829d | 2017-11-11 00:12:20 +0100 | [diff] [blame] | 157 | find /var/lib/jenkins/jenkins.model.JenkinsLocationConfiguration.xml -type f -print0 | xargs -0 sed -i -e 's/10.167.4.15/'$SALT_MASTER_DEPLOY_IP'/g' |
| 158 | |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 159 | echo "updating local git repos" |
alexz | d90608b | 2018-04-12 23:49:03 +0200 | [diff] [blame] | 160 | if [[ "$PIPELINES_FROM_ISO" == "true" ]] ; then |
Jiri Broulik | cee2053 | 2018-01-08 13:30:15 +0100 | [diff] [blame] | 161 | cp -r /mnt/mk-pipelines/* /home/repo/mk/mk-pipelines/ |
| 162 | cp -r /mnt/pipeline-library/* /home/repo/mcp-ci/pipeline-library/ |
alexz | d90608b | 2018-04-12 23:49:03 +0200 | [diff] [blame] | 163 | umount /dev/cdrom || true |
Jiri Broulik | cee2053 | 2018-01-08 13:30:15 +0100 | [diff] [blame] | 164 | chown -R git:www-data /home/repo/mk/mk-pipelines/* |
| 165 | chown -R git:www-data /home/repo/mcp-ci/pipeline-library/* |
| 166 | else |
alexz | d90608b | 2018-04-12 23:49:03 +0200 | [diff] [blame] | 167 | umount /dev/cdrom || true |
| 168 | git clone --mirror "${PIPELINE_REPO_URL}/mk-pipelines.git" /home/repo/mk/mk-pipelines/ |
| 169 | git clone --mirror "${PIPELINE_REPO_URL}/pipeline-library.git" /home/repo/mcp-ci/pipeline-library/ |
Jiri Broulik | cee2053 | 2018-01-08 13:30:15 +0100 | [diff] [blame] | 170 | chown -R git:www-data /home/repo/mk/mk-pipelines/* |
| 171 | chown -R git:www-data /home/repo/mcp-ci/pipeline-library/* |
| 172 | fi |
| 173 | |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 174 | process_formulas |
Richard Felkl | 98b4534 | 2018-04-06 13:30:28 +0200 | [diff] [blame] | 175 | |
Richard Felkl | 4c4829d | 2017-11-11 00:12:20 +0100 | [diff] [blame] | 176 | salt-call saltutil.refresh_pillar |
| 177 | salt-call saltutil.sync_all |
alexz | d90608b | 2018-04-12 23:49:03 +0200 | [diff] [blame] | 178 | if ! $(reclass -n ${SALT_MASTER_MINION_ID} > /dev/null ) ; then |
| 179 | echo "ERROR: Reclass render failed!" |
| 180 | exit 1 |
Jiri Broulik | 0173a27 | 2018-04-11 10:56:35 +0200 | [diff] [blame] | 181 | fi |
| 182 | |
Dennis Dmitriev | b5c17a0 | 2018-07-06 13:07:49 +0300 | [diff] [blame] | 183 | salt-call ${SALT_OPTS} state.sls linux.network,linux,openssh |
Dennis Dmitriev | e00716b | 2018-07-05 14:50:45 +0300 | [diff] [blame] | 184 | # PROD-21179: Run salt.minion.ca to prepare CA certificate before salt.minion.cert is used |
| 185 | salt-call ${SALT_OPTS} state.sls salt.minion.ca |
Dennis Dmitriev | b5c17a0 | 2018-07-06 13:07:49 +0300 | [diff] [blame] | 186 | salt-call ${SALT_OPTS} state.sls salt |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 187 | salt-call ${SALT_OPTS} pkg.install salt-master,salt-minion |
Dennis Dmitriev | e00716b | 2018-07-05 14:50:45 +0300 | [diff] [blame] | 188 | |
Jiri Broulik | 6b7ca67 | 2018-04-19 13:16:32 +0200 | [diff] [blame] | 189 | sleep 5 |
Dennis Dmitriev | e00716b | 2018-07-05 14:50:45 +0300 | [diff] [blame] | 190 | # Wait for salt-master and salt-minion to wake up after restart |
| 191 | salt-call --timeout=120 test.ping |
| 192 | |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 193 | salt-call ${SALT_OPTS} state.sls salt |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 194 | salt-call ${SALT_OPTS} state.sls reclass |
Jiri Broulik | 1261ca3 | 2018-01-18 15:30:25 +0100 | [diff] [blame] | 195 | |
azvyagintsev | 42a4762 | 2018-07-06 13:12:08 +0300 | [diff] [blame] | 196 | maas_cluster_enabled=$(salt-call --out=text pillar.get maas:cluster:enabled | awk '{print $2}' | tr "[:upper:]" "[:lower:]" ) |
| 197 | process_maas |
alexz | d90608b | 2018-04-12 23:49:03 +0200 | [diff] [blame] | 198 | |
| 199 | ssh-keyscan cfg01 > /var/lib/jenkins/.ssh/known_hosts || true |
| 200 | |
azvyagintsev | 42a4762 | 2018-07-06 13:12:08 +0300 | [diff] [blame] | 201 | process_jenkins |
Richard Felkl | 4c4829d | 2017-11-11 00:12:20 +0100 | [diff] [blame] | 202 | |
azvyagintsev | b2a5579 | 2018-06-05 17:38:17 +0300 | [diff] [blame] | 203 | stop_services="salt-api salt-master salt-minion jenkins maas-rackd.service maas-regiond.service postgresql.service" |
| 204 | for s in ${stop_services} ; do |
| 205 | systemctl stop ${s} || true |
| 206 | sleep 1 |
| 207 | done |
| 208 | sync |
Dmitry Stremkouski | a94b5f3 | 2017-12-02 00:41:54 +0300 | [diff] [blame] | 209 | reboot |