Richard Felkl | d59c565 | 2018-02-08 13:14:05 +0100 | [diff] [blame] | 1 | #!/bin/bash -xe |
azvyagintsev | 6d45385 | 2018-02-26 16:56:37 +0200 | [diff] [blame] | 2 | |
azvyagintsev | 5a38855 | 2018-04-03 21:25:23 +0300 | [diff] [blame] | 3 | UBUNTU_BASEURL="${UBUNTU_BASEURL:-mirror://mirrors.ubuntu.com/mirrors.txt}" |
azvyagintsev | 6d45385 | 2018-02-26 16:56:37 +0200 | [diff] [blame] | 4 | |
Richard Felkl | d59c565 | 2018-02-08 13:14:05 +0100 | [diff] [blame] | 5 | ## Base packages and setup |
| 6 | export DEBIAN_FRONTEND=noninteractive |
azvyagintsev | 4053eb2 | 2018-03-29 16:21:51 +0300 | [diff] [blame] | 7 | echo -e '#!/bin/sh\nexit 101' > /usr/sbin/policy-rc.d |
Richard Felkl | d59c565 | 2018-02-08 13:14:05 +0100 | [diff] [blame] | 8 | chmod +x /usr/sbin/policy-rc.d |
| 9 | |
azvyagintsev | 4053eb2 | 2018-03-29 16:21:51 +0300 | [diff] [blame] | 10 | # Configure apt. Please refer to |
| 11 | # https://github.com/Mirantis/reclass-system-salt-model/blob/master/linux/system/single/debian.yml |
| 12 | # and keep those structures with same naming convention - to prevent |
| 13 | # misconfiguration between base system and salt state. |
Richard Felkl | d59c565 | 2018-02-08 13:14:05 +0100 | [diff] [blame] | 14 | echo "Acquire::CompressionTypes::Order gz;" >/etc/apt/apt.conf.d/99compression-workaround-salt |
azvyagintsev | 6d45385 | 2018-02-26 16:56:37 +0200 | [diff] [blame] | 15 | echo "Acquire::EnableSrvRecords false;" >/etc/apt/apt.conf.d/99enablesrvrecords-false |
azvyagintsev | c86fbaf | 2018-03-02 18:57:03 +0200 | [diff] [blame] | 16 | echo "Acquire::http::Pipeline-Depth 0;" > /etc/apt/apt.conf.d/99aws-s3-mirrors-workaround-salt |
| 17 | echo "APT::Install-Recommends false;" > /etc/apt/apt.conf.d/99dont_install_recommends-salt |
| 18 | echo "APT::Install-Suggests false;" > /etc/apt/apt.conf.d/99dont_install_suggests-salt |
| 19 | echo "Acquire::Languages none;" > /etc/apt/apt.conf.d/99dont_acquire_all_languages-salt |
| 20 | echo "APT::Periodic::Update-Package-Lists 0;" > /etc/apt/apt.conf.d/99dont_update_package_list-salt |
| 21 | echo "APT::Periodic::Download-Upgradeable-Packages 0;" > /etc/apt/apt.conf.d/99dont_update_download_upg_packages-salt |
| 22 | echo "APT::Periodic::Unattended-Upgrade 0;" > /etc/apt/apt.conf.d/99disable_unattended_upgrade-salt |
Richard Felkl | d59c565 | 2018-02-08 13:14:05 +0100 | [diff] [blame] | 23 | |
azvyagintsev | 6d45385 | 2018-02-26 16:56:37 +0200 | [diff] [blame] | 24 | sysctl -w fs.file-max=100000 |
Richard Felkl | d59c565 | 2018-02-08 13:14:05 +0100 | [diff] [blame] | 25 | # Overwrite default mirrors |
azvyagintsev | 6d45385 | 2018-02-26 16:56:37 +0200 | [diff] [blame] | 26 | echo "deb [arch=amd64] ${UBUNTU_BASEURL} xenial main restricted multiverse universe" > /etc/apt/sources.list |
| 27 | echo "deb [arch=amd64] ${UBUNTU_BASEURL} xenial-updates main restricted multiverse universe" >> /etc/apt/sources.list |
| 28 | echo "deb [arch=amd64] ${UBUNTU_BASEURL} xenial-security main restricted multiverse universe" >> /etc/apt/sources.list |
| 29 | #echo "deb [arch=amd64] ${UBUNTU_BASEURL} xenial-backports main restricted multiverse universe" >> /etc/apt/sources.list |
Richard Felkl | d59c565 | 2018-02-08 13:14:05 +0100 | [diff] [blame] | 30 | |
| 31 | apt-get clean |
| 32 | apt-get update |
| 33 | |
| 34 | # Useful tools |
azvyagintsev | 0f697cf | 2018-06-22 11:44:13 +0300 | [diff] [blame^] | 35 | EXTRA_PKGS="byobu curl ethtool iputils-ping lsof strace tcpdump traceroute wget iptables" |
| 36 | # Pretty tools |
| 37 | EXTRA_PKGS="${EXTRA_PKGS} byobu htop tmux tree vim-nox mc" |
| 38 | # Common prerequisites |
| 39 | EXTRA_PKGS="${EXTRA_PKGS} apt-transport-https libmnl0 python-apt python-m2crypto python-psutil acpid" |
| 40 | apt-get -y install ${EXTRA_PKGS} |
Richard Felkl | d59c565 | 2018-02-08 13:14:05 +0100 | [diff] [blame] | 41 | |
| 42 | # Cleanup old kernels, ensure latest is installed via virtual package |
Richard Felkl | d59c565 | 2018-02-08 13:14:05 +0100 | [diff] [blame] | 43 | if [ ! -f /tmp/no_install_kernel ]; then |
azvyagintsev | 0f697cf | 2018-06-22 11:44:13 +0300 | [diff] [blame^] | 44 | apt-get purge -y linux-image-* linux-headers-* | grep -v 'is not installed, so not removed' |
azvyagintsev | 6d45385 | 2018-02-26 16:56:37 +0200 | [diff] [blame] | 45 | apt-get install -y linux-image-virtual-lts-xenial linux-image-extra-virtual-lts-xenial |
Richard Felkl | d59c565 | 2018-02-08 13:14:05 +0100 | [diff] [blame] | 46 | |
| 47 | # Update grub cmdline |
| 48 | sed -i 's|GRUB_CMDLINE_LINUX_DEFAULT=.*|GRUB_CMDLINE_LINUX_DEFAULT="console=tty0 console=ttyS0,115200n8"|g' /etc/default/grub |
| 49 | sed -i 's|GRUB_CMDLINE_LINUX=.*|GRUB_CMDLINE_LINUX="console=tty0 console=ttyS0,115200n8"|g' /etc/default/grub |
| 50 | update-grub |
| 51 | fi |
| 52 | |
| 53 | apt-get -y upgrade |
| 54 | apt-get -y dist-upgrade |
| 55 | |
| 56 | apt-get autoremove --purge |
| 57 | |
| 58 | # Tmux fixes |
| 59 | cat << 'EOF' >> /etc/tmux.conf |
| 60 | set -g default-terminal "screen-256color" |
| 61 | set -g set-titles on |
| 62 | set -g xterm-keys on |
| 63 | EOF |
| 64 | |
| 65 | # Setup cloud-init |
| 66 | apt-get -y install cloud-init |
| 67 | |
azvyagintsev | 0adfe68 | 2018-06-13 16:29:40 +0300 | [diff] [blame] | 68 | # FIXME: move to cluster model |
| 69 | # Disable services |
| 70 | disable_services="apt-daily.timer apt-daily-upgrade.timer lxc.service snapd.service snapd.socket" |
| 71 | for s in ${disable_services}; do |
| 72 | systemctl disable ${s} || true |
| 73 | systemctl stop ${s} || true |
| 74 | done |