blob: 7bd7a022b97b02bb0fdb0462f6a9c519c4e22fb0 [file] [log] [blame]
| # All the data below will be stored as a string object
#cloud-config, see http://cloudinit.readthedocs.io/en/latest/topics/examples.html
ssh_pwauth: True
users:
- name: root
sudo: ALL=(ALL) NOPASSWD:ALL
shell: /bin/bash
ssh_authorized_keys:
{% for key in config.underlay.ssh_keys %}
- ssh-rsa {{ key['public'] }}
{% endfor %}
disable_root: false
chpasswd:
list: |
root:r00tme
expire: False
bootcmd:
# Block access to SSH while node is preparing
#- cloud-init-per once sudo iptables -A INPUT -p tcp --dport 22 -j DROP
- cloud-init-per once sudo ifdown ens4
# Enable root access
- cloud-init-per once sudo sed -i -e '/^PermitRootLogin/s/^.*$/PermitRootLogin yes/' /etc/ssh/sshd_config
- cloud-init-per once sudo service sshd restart
output:
all: '| tee -a /var/log/cloud-init-output.log /dev/tty0'
runcmd:
# Prepare network connection
- sudo ifdown ens3
- sudo ifup ens3
#- sudo route add default gw {gateway} {interface_name}
# Purge the unattended-upgrades package (Workaround for PROD-17904, PROD-18736)"
- echo "APT::Periodic::Update-Package-Lists 0;" > /etc/apt/apt.conf.d/99dont_update_package_list-salt
- echo "APT::Periodic::Download-Upgradeable-Packages 0;" > /etc/apt/apt.conf.d/99dont_update_download_upg_packages-salt
- echo "APT::Periodic::Unattended-Upgrade 0;" > /etc/apt/apt.conf.d/99disable_unattended_upgrade-salt
- apt-get -y purge unattended-upgrades
# Stop currently running apt-daily service, source: https://unix.stackexchange.com/a/315517
- systemctl stop apt-daily.service
- systemctl kill --kill-who=all apt-daily.service
- while ! (systemctl list-units --all apt-daily.service | fgrep -q dead); do sleep 1; done
# Configure dhclient
- sudo echo "nameserver {gateway}" >> /etc/resolvconf/resolv.conf.d/base
- sudo resolvconf -u
# Enable grub menu using updated config below
- update-grub
# Create swap
#- fallocate -l 16G /swapfile
#- chmod 600 /swapfile
#- mkswap /swapfile
#- swapon /swapfile
#- echo "/swapfile none swap defaults 0 0" >> /etc/fstab
############## TCP Cloud cfg01 node ##################
- echo "Preparing base OS"
- echo "nameserver 172.18.208.44" >> /etc/resolv.conf;
- apt-get clean
- apt-get update
# Ensure that the salt-master service is ready to receive requests
- salt-key -y -D
- service salt-master restart
- service salt-minion restart
- apt-get install -y salt-formula-*
- for f in $(ls -1 /usr/share/salt-formulas/reclass/service); do ln -s /usr/share/salt-formulas/reclass/service/$f /srv/salt/reclass/classes/service/ || true; done
- salt-call --timeout=180 test.ping
########################################################
# Node is ready, allow SSH access
#- echo "Allow SSH access ..."
#- sudo iptables -D INPUT -p tcp --dport 22 -j DROP
- sudo ifup ens4
########################################################
write_files:
- path: /etc/default/grub.d/97-enable-grub-menu.cfg
content: |
GRUB_RECORDFAIL_TIMEOUT=30
GRUB_TIMEOUT=3
GRUB_TIMEOUT_STYLE=menu
- path: /etc/network/interfaces
content: |
auto ens3
iface ens3 inet dhcp
auto ens4
iface ens4 inet dhcp
- path: /root/.ssh/config
owner: root:root
permissions: '0600'
content: |
Host *
ServerAliveInterval 300
ServerAliveCountMax 10
StrictHostKeyChecking no
UserKnownHostsFile /dev/null
# Fix hardcoded IP address in the minion.conf
- path: /etc/salt/minion.d/minion.conf
content: |
master: 127.0.0.1
id: cfg01.{{ DOMAIN_NAME }}