Merge pull request #46 from paulscherrerinstitute/busterOverlay

Debian system image
This commit is contained in:
Brian Clemens
2021-03-25 20:04:43 +09:00
committed by GitHub
25 changed files with 295 additions and 0 deletions

View File

@@ -44,6 +44,8 @@ lint:
all: vendor wwctl wwclient
debian: all
files: all
install -d -m 0755 $(DESTDIR)/usr/bin/
install -d -m 0755 $(DESTDIR)/var/warewulf/
@@ -64,6 +66,13 @@ files: all
# cp -r tftpboot/* /var/lib/tftpboot/warewulf/ipxe/
# restorecon -r /var/lib/tftpboot/warewulf
debfiles: debian
chmod +x $(DESTDIR)/var/warewulf/overlays/system/debian/init
chmod 600 $(DESTDIR)/var/warewulf/overlays/system/debian/etc/ssh/ssh*
chmod 644 $(DESTDIR)/var/warewulf/overlays/system/debian/etc/ssh/ssh*.pub.ww
mkdir -p $(DESTDIR)/var/warewulf/overlays/system/debian/warewulf/bin/
cp wwclient $(DESTDIR)/var/warewulf/overlays/system/debian/warewulf/bin/
wwctl:
cd cmd/wwctl; go build -mod vendor -tags "$(WW_BUILD_GO_BUILD_TAGS)" -o ../../wwctl
@@ -85,3 +94,6 @@ clean:
rm -f warewulf-$(VERSION).tar.gz
install: files
debinstall: files debfiles

View File

@@ -0,0 +1,24 @@
FROM debian
ENV DEBIAN_FRONTEND noninteractive
ENV RUNLEVEL 1
RUN apt-get update && apt-get install -y --no-install-recommends \
kmod \
systemd-sysv \
openssh-client \
openssh-server \
isc-dhcp-client \
pciutils \
strace \
nfs-common \
ethtool\
ifupdown \
linux-image-amd64 \
ifmetric \
netbase && \
rm -rf /var/lib/apt/lists/*
RUN echo "root:r00tr00t" | chpasswd
ENV DEBIAN_FRONTEND teletype

View File

@@ -0,0 +1,40 @@
FROM debian
ENV DEBIAN_FRONTEND noninteractive
ENV RUNLEVEL 1
RUN apt-get update && apt-get install -y --no-install-recommends \
kmod \
systemd-sysv \
openssh-client \
openssh-server \
isc-dhcp-client \
pciutils \
strace \
nfs-common \
ethtool\
ifupdown \
linux-image-amd64 \
ifmetric \
procserv \
netbase && \
rm -rf /var/lib/apt/lists/*
# EPICS hack for libreadline
RUN ln -s /lib/x86_64-linux-gnu/libreadline.so.7 /lib/x86_64-linux-gnu/libreadline.so.6
RUN ln -s /lib/x86_64-linux-gnu/libtinfo.so.6 /lib/x86_64-linux-gnu/libtinfo.so.5
# weed out stuff from the internal kernel
#RUN rm -rf \
# /lib/modules/*/kernel/drivers/gpu \
# /lib/modules/*/kernel/drivers/hwmon \
# /lib/modules/*/kernel/drivers/infiniband \
# /lib/modules/*/kernel/drivers/isdn \
# /lib/modules/*/kernel/drivers/media \
# /lib/modules/*/kernel/drivers/scsi \
# /lib/modules/*/kernel/drivers/usb \
# /lib/modules/*/kernel/drivers/net/usb \
# /lib/modules/*/kernel/drivers/net/wireless
ENV DEBIAN_FRONTEND teletype

View File

@@ -0,0 +1,21 @@
# Debian, Buster
## Docker container
### build and push
> PSI specific, change for upstream
change into your docker build directory
```bash
docker build -t docker.psi.ch:5000/debian:buster-slim .
docker push docker.psi.ch:5000/debian:buster-slim
```
### import docker container into warewulf
```bash
wwctl container import docker://docker.psi.ch:5000/debian:buster-slim debian-10:slim
```

View File

@@ -0,0 +1 @@
{{$.Id}}

View File

@@ -0,0 +1,9 @@
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).
source /etc/network/interfaces.d/*
# The loopback network interface
auto lo
iface lo inet loopback

View File

@@ -0,0 +1,7 @@
auto eno1
allow-hotplug eno1
iface eno1 inet static
address {{.NetDevs.eno1.Ipaddr}}
netmask {{.NetDevs.eno1.Netmask}}
gateway {{.NetDevs.eno1.Gateway}}

View File

@@ -0,0 +1,4 @@
# The facility network interface
allow-hotplug eno2
iface eno2 inet dhcp

View File

@@ -0,0 +1 @@
{{Include "/etc/warewulf/keys/ssh_host_dsa_key.pub"}}

View File

@@ -0,0 +1 @@
{{Include "/etc/warewulf/keys/ssh_host_dsa_key"}}

View File

@@ -0,0 +1 @@
{{Include "/etc/warewulf/keys/ssh_host_ecdsa_key.pub"}}

View File

@@ -0,0 +1 @@
{{Include "/etc/warewulf/keys/ssh_host_ecdsa_key"}}

View File

@@ -0,0 +1 @@
{{Include "/etc/warewulf/keys/ssh_host_ed25519_key.pub"}}

View File

@@ -0,0 +1 @@
{{Include "/etc/warewulf/keys/ssh_host_ed25519_key"}}

View File

@@ -0,0 +1 @@
{{Include "/etc/warewulf/keys/ssh_host_rsa_key.pub"}}

View File

@@ -0,0 +1 @@
{{Include "/etc/warewulf/keys/ssh_host_rsa_key"}}

View File

@@ -0,0 +1,14 @@
{{Include "/etc/warewulf/ssh/sshd_config"}}
# This is a Warewulf Template file.
#
# This file (suffix '.ww') will be automatically rewritten without the suffix
# when the overlay is rendered for the individual nodes. Here are some examples
# of macros and logic which can be used within this file:
#
# Node FQDN = {{.Id}}
# Node Group = {{.GroupName}}
# Network Config = {{.NetDevs.eth0.Ipaddr}}, {{.NetDevs.eth0.Hwaddr}}, etc.
#
# Goto the documentation pages for more information: http://www.hpcng.org/...

View File

@@ -0,0 +1 @@
{{Include "/etc/warewulf/warewulf.conf"}}

57
overlays/system/debian/init Executable file
View File

@@ -0,0 +1,57 @@
#!/bin/sh
#
# This is one of those types of files that you shouldn't edit unless you really
# know what you are doing and even then you should make a backup.
#
# Edit at your own risk! DANGER DANGER.
if test -f "/warewulf/config"; then
. /warewulf/config
else
echo "ERROR: Warewulf configuration file not found... rebooting in 1 minute"
sleep 60
/sbin/reboot
fi
echo "Warewulf v4 is now booting: ${WWHOSTNAME}"
echo "debian specific overlay"
echo "Mounting up kernel file systems"
mkdir /proc /dev /sys /run 2>/dev/null
mount -t proc proc /proc
mount -t devtmpfs devtmpfs /dev
mount -t sysfs sysfs /sys
mount -t tmpfs tmpfs /run
chmod 755 /warewulf/wwinit
echo "Checking Rootfs type"
ROOTFSTYPE=`stat -f -c "%T" /`
if test "${WWROOT}" = "initramfs"; then
echo "Provisioned to default initramfs file system: ${ROOTFSTYPE}"
echo "Calling WW Init"
exec /warewulf/wwinit
elif test "${WWROOT}" = "tmpfs"; then
if test "${ROOTFSTYPE}" == "tmpfs"; then
echo "ERROR: Switching the root file system requires the kernel argument: 'rootfstype=ramfs'"
else
echo "Setting up tmpfs root file system"
mkdir /newroot
mount wwroot /newroot -t tmpfs
echo "Moving RAMFS to TMPFS"
tar -cf - --exclude ./proc --exclude ./sys --exclude ./dev --exclude ./newroot . | tar -xf - -C /newroot
mkdir /newroot/proc /newroot/dev /newroot/sys /newroot/run 2>/dev/null
echo "Calling switch_root and invoking WW Init"
exec /sbin/switch_root /newroot /warewulf/wwinit
fi
else
echo "ERROR: Unknown Warewulf Root file system: ${WWROOT}"
fi
echo
echo "There was a problem with the provisioning process, rebooting in 1 minute..."
sleep 60
/sbin/reboot

View File

@@ -0,0 +1,9 @@
WWCONTAINER={{$.Container}}
WWHOSTNAME={{$.Id}}
WWROOT={{$.Root}}
WWINIT={{$.Init}}
WWIPMI_IPADDR="{{$.IpmiIpaddr}}"
WWIPMI_NETMASK="{{$.IpmiNetmask}}"
WWIPMI_GATEWAY="{{$.IpmiGateway}}"
WWIPMI_USER="{{$.IpmiUserName}}"
WWIPMI_PASSWORD="{{$.IpmiPassword}}"

View File

@@ -0,0 +1,6 @@
#!/bin/sh
. /warewulf/config
echo "Bringing up lo:127.0.0.1"
/sbin/ip link set dev lo up

View File

@@ -0,0 +1,24 @@
#!/bin/sh
. /warewulf/config
# This will eventually be optional
if true; then
if [ -f "/etc/pam.d/system-auth" ]; then
echo "FIXING: system-auth"
sed -i -e '/^account.*pam_unix\.so\s*$/s/\s*$/\ broken_shadow/' /etc/pam.d/system-auth
fi
if [ -f "/etc/pam.d/password-auth" ]; then
echo "FIXING: password-auth"
sed -i -e '/^account.*pam_unix\.so\s*$/s/\s*$/\ broken_shadow/' /etc/pam.d/password-auth
fi
if [ -f "/etc/pam.d/common-account" ]; then
echo "FIXING: common-account"
sed -i -e '/^account.*pam_unix\.so\s*$/s/\s*$/\ broken_shadow/' /etc/pam.d/common-account
fi
fi
chmod 755 /

View File

@@ -0,0 +1,6 @@
#!/bin/sh
. /warewulf/config
echo "Starting wwclient"
nohup /warewulf/bin/wwclient >/var/log/wwclient.log 2>&1 </dev/null &

View File

@@ -0,0 +1,35 @@
#!/bin/bash
. /warewulf/config
if test -z "$WWROOT"; then
echo "Skipping SELinux configuration: Warewulf Root device not set"
exit
fi
if test -f "/etc/sysconfig/selinux"; then
. /etc/sysconfig/selinux
else
echo "Skipping SELinux configuration: Host config not found: /etc/sysconfig/selinux"
exit
fi
if test "$WWROOT" == "initramfs"; then
echo "Skipping SELinux configuration: 'Root=initramfs'"
if test "$SELINUX" != "disabled"; then
echo "WARNING: SELinux prep is being skipped, but SELinux is enabled on host! This may"
echo "WARNING: cause the system to not work properly. Try setting 'Root=tmpfs'"
sleep 5
fi
exit
fi
if test "$SELINUX" == "disabled"; then
echo "Skipping SELinux setup per /etc/sysconfig/selinux"
elif grep -q "selinux=0" /proc/cmdline; then
echo "Skipping SELinux setup per kernel command line"
else
echo "Setting up SELinux"
/sbin/load_policy -i
/sbin/restorecon -r /
fi

View File

@@ -0,0 +1,17 @@
#!/bin/sh
echo "Hello from WWINIT"
. /warewulf/config
for i in /warewulf/init.d/*; do
NAME=`basename $i`
echo "Launching: $NAME"
sh "$i"
done
echo "Calling $WWINIT..."
echo
sleep 2
exec $WWINIT