View difference between Paste ID: skCiDPPh and NZiERQsY
SHOW: | | - or go back to the newest paste.
1
# Synchronize the system clock to the NTP servers and then synchronize
2
# hardware clock with that.
3
synchronize_clock()
4
{
5
  # Synchronize the system clock using NTP.
6
  ntpdate clock.redhat.com
7
8
  # Synchronize the hardware clock to the system clock.
9
  hwclock --systohc
10
}
11
12
13
# Install SSH keys. We hardcode a key used for internal OpenShift
14
# development, but the hardcoded key can be replaced with another or
15
# with a wget command to download a key from elsewhere.
16
install_ssh_keys()
17
{
18
  mkdir -p /root/.ssh
19
  chmod 700 /root/.ssh
20
  cat >> /root/.ssh/authorized_keys << KEYS
21
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDkMc2jArUbWICi0071HXrt5uofQam11duqo5KEDWUZGtHuMTzuoZ0XEtzpqoRSidya9HjbJ5A4qUJBrvLZ07l0OIjENQ0Kvz83alVGFrEzVVUSZyiy6+yM9Ksaa/XAYUwCibfaFFqS9aVpVdY0qwaKrxX1ycTuYgNAw3WUvkHagdG54/79M8BUkat4uNiot0bKg6VLSI1QzNYV6cMJeOzz7WzHrJhbPrgXNKmgnAwIKQOkbATYB+YmDyHpA4m/O020dWDk9vWFmlxHLZqddCVGAXFyQnXoFTszFP4wTVOu1q2MSjtPexujYjTbBBxraKw9vrkE25YZJHvbZKMsNm2b libra_onprem
22
KEYS
23
}
24
25
26
configure_rhel_repo()
27
{
28
  # In order for the %post section to succeed, it must have a way of
29
  # installing from RHEL. The post section cannot access the method that
30
  # was used in the base install. This configures a RHEL yum repo which
31
  # you must supply.
32-
#  cat > /etc/yum.repos.d/rhel.repo <<YUM
32+
  cat > /etc/yum.repos.d/openshift.repo <<YUM
33-
#[rhel6]
33+
[openshift-origin-nightly]
34-
#name=RHEL 6 base OS
34+
name=OpenShift Origin Nightly
35-
#baseurl=${CONF_RHEL_REPO}
35+
baseurl=https://mirror.openshift.com/pub/origin-server/nightly/fedora-18/latest/x86_64/
36
enabled=1
37
gpgcheck=0
38
39
[openshift-origin-deps]
40-
#exclude=tomcat6*
40+
name=OpenShift Origin Dependancies
41
baseurl=https://mirror.openshift.com/pub/origin-server/release/1/fedora-18/dependancies/x86_64/
42
enabled=1
43
gpgcheck=0
44
45
[openshift-origin-release]
46
name=OpenShift Origin Release
47
baseurl=https://mirror.openshift.com/pub/origin-server/release/1/fedora-18/packages/x86_64/
48
enabled=1
49
gpgcheck=0
50
51
YUM
52
}
53
54
configure_optional_repo()
55
{
56
#  cat > /etc/yum.repos.d/rheloptional.repo <<YUM
57
#[rhel6_optional]
58
#name=RHEL 6 Optional
59
#baseurl=${CONF_RHEL_OPTIONAL_REPO}
60
#enabled=1
61
#gpgcheck=0
62-
#  cat > /etc/yum.repos.d/openshift-client.repo <<YUM
62+
63-
#[openshift_client]
63+
64-
#name=OpenShift Client
64+
65-
#baseurl=${CONF_REPOS_BASE}/Client/x86_64/os/
65+
66
}
67
68
configure_client_tools_repo()
69
{
70
  # Enable repo with the puddle for broker packages.
71
  cat > /etc/yum.repos.d/openshift-rhc.repo <<YUM
72
[openshift_rhc]
73
name=OpenShift Client Tools
74
baseurl=https://mirror.openshift.com/pub/rubygem-rhc/nightly/rpms/
75
enabled=1
76
gpgcheck=0
77
78
YUM
79
}
80
81
configure_broker_repo()
82
{
83
  # Enable repo with the puddle for broker packages.
84
#  cat > /etc/yum.repos.d/openshift-infrastructure.repo <<YUM
85
#[openshift_infrastructure]
86
#name=OpenShift Infrastructure
87
#baseurl=${CONF_REPOS_BASE}/Infrastructure/x86_64/os/
88
#enabled=1
89
#gpgcheck=0
90
#priority=1
91
#sslverify=false
92
#
93
#YUM
94
}
95
96
configure_node_repo()
97
{
98
  # Enable repo with the puddle for node packages.
99
#  cat > /etc/yum.repos.d/openshift-node.repo <<YUM
100
#[openshift_node]
101
#name=OpenShift Node
102
#baseurl=${CONF_REPOS_BASE}/Node/x86_64/os/
103
#enabled=1
104
#gpgcheck=0
105
#priority=1
106
#sslverify=false
107
#
108
#YUM
109
}
110
111
configure_jbosseap_cartridge_repo()
112
{
113
  # Enable repo with the puddle for the JBossEAP cartridge package.
114
#  cat > /etc/yum.repos.d/openshift-jboss.repo <<YUM
115
#[openshift_jbosseap]
116
#name=OpenShift JBossEAP
117
#baseurl=${CONF_REPOS_BASE}/JBoss_EAP6_Cartridge/x86_64/os/
118
#enabled=1
119
#gpgcheck=0
120
#priority=1
121
#sslverify=false
122
#
123
#YUM
124
}
125
126
configure_jbosseap_repo()
127
{
128
  # The JBossEAP cartridge depends on Red Hat's JBoss packages.
129
#
130
#  if [ "x${CONF_JBOSS_REPO_BASE}" != "x" ]
131
#  then
132
  ## configure JBossEAP repo
133
#    cat <<YUM > /etc/yum.repos.d/jbosseap.repo
134
#[jbosseap]
135
#name=jbosseap
136
#baseurl=${CONF_JBOSS_REPO_BASE}/jbeap/6/os
137
#enabled=1
138
#priority=3
139
#gpgcheck=0
140
#
141
#YUM
142
#
143
#  fi
144
}
145
146
configure_jbossews_repo()
147
{
148
  # The JBossEWS cartridge depends on Red Hat's JBoss packages.
149
#  if [ "x${CONF_JBOSS_REPO_BASE}" != "x" ]
150
#  then
151
  ## configure JBossEWS repo
152
#    cat <<YUM > /etc/yum.repos.d/jbossews.repo
153
#[jbossews]
154
#name=jbossews
155
#baseurl=${CONF_JBOSS_REPO_BASE}/jbews/2/os
156
#enabled=1
157
#priority=3
158
#gpgcheck=0
159
#
160
#YUM
161
#
162
#  fi
163
}
164
165
yum_install_or_exit()
166
{
167
  yum install $*
168
  if [ $? -ne 0 ]
169
  then
170
echo "yum install failed; aborting installation. Please ensure you have configured the relevant repos/subscriptions."
171
    exit 1
172
  fi
173
}
174
175
# Install the client tools.
176
install_rhc_pkg()
177
{
178
  yum install -y rhc
179
  # set up the system express.conf so this broker will be used by default
180
  echo -e "\nlibra_server = '${broker_hostname}'" >> /etc/openshift/express.conf
181
}
182
183
# Install broker-specific packages.
184
install_broker_pkgs()
185
{
186
  pkgs="openshift-origin-broker"
187
  pkgs="$pkgs openshift-origin-broker-util"
188
  pkgs="$pkgs rubygem-openshift-origin-msg-broker-mcollective"
189
  pkgs="$pkgs rubygem-openshift-origin-auth-remote-user"
190
  pkgs="$pkgs rubygem-openshift-origin-dns-nsupdate"
191
  pkgs="$pkgs openshift-origin-console"
192
193
  yum_install_or_exit -y $pkgs
194
}
195
196
# Currently, ruby193-rubygem-passenger-native creates
197
# /usr/var/log/passenger-analytics as its log directory, but our
198
# software expects it to be at /var/log/passenger-analytics, and the
199
# broker doesn't work if this folder isn't present and
200
# accessible. This function fixes that.
201
fix_passenger()
202
{
203
  mkdir /var/log/passenger-analytics
204
  chmod 750 /var/log/passenger-analytics
205
  chown apache:apache /var/log/passenger-analytics
206
}
207
208
# Install node-specific packages.
209
install_node_pkgs()
210
{
211
  pkgs="rubygem-openshift-origin-node ruby193-rubygem-passenger-native"
212
  pkgs="$pkgs openshift-origin-port-proxy"
213
  pkgs="$pkgs openshift-origin-node-util"
214
  # We use semanage in this script, so we need to install
215
  # policycoreutils-python.
216
  pkgs="$pkgs policycoreutils-python"
217
218
  yum_install_or_exit -y $pkgs
219
}
220
221
# Install any cartridges developers may want.
222
install_cartridges()
223
{
224
  # Following are cartridge rpms that one may want to install here:
225
  if is_true "$node_v2_enable"
226
  then
227
    # Embedded cron support. This is required on node hosts.
228
    carts="openshift-origin-cartridge-cron"
229
230
    # diy app.
231
    carts="$carts openshift-origin-cartridge-diy"
232
233
    # haproxy support.
234
    carts="$carts openshift-origin-cartridge-haproxy"
235
236
    # JBossEWS support.
237
    # Note: Be sure to subscribe to the JBossEWS entitlements during the
238
    # base install or in configure_jbossews_repo.
239
    carts="$carts openshift-origin-cartridge-jbossews"
240
 
241
    # JBossEAP support.
242
    # Note: Be sure to subscribe to the JBossEAP entitlements during the
243
    # base install or in configure_jbosseap_repo.
244
    carts="$carts openshift-origin-cartridge-jbosseap"
245
 
246
    # Jenkins server for continuous integration.
247
    carts="$carts openshift-origin-cartridge-jenkins"
248
 
249
    # Embedded jenkins client.
250
    carts="$carts openshift-origin-cartridge-jenkins-client"
251
 
252
    # Embedded MySQL.
253
    carts="$carts openshift-origin-cartridge-mysql"
254
 
255
    # mod_perl support.
256
    carts="$carts openshift-origin-cartridge-perl"
257
  
258
    # PHP support.
259
    carts="$carts openshift-origin-cartridge-php"
260
  
261
    # Embedded PostgreSQL.
262
    carts="$carts openshift-origin-cartridge-postgresql"
263
  
264
    # Python support.
265
    carts="$carts openshift-origin-cartridge-python"
266
  
267
    # Ruby Rack support running on Phusion Passenger
268
    carts="$carts openshift-origin-cartridge-ruby"
269
  else
270
    # Embedded cron support. This is required on node hosts.
271
    carts="openshift-origin-cartridge-cron-1.4"
272
273
    # diy app.
274
    carts="$carts openshift-origin-cartridge-diy-0.1"
275
276
    # haproxy-1.4 support.
277
    carts="$carts openshift-origin-cartridge-haproxy-1.4"
278
279
    # JBossEWS1.0 support.
280
    # Note: Be sure to subscribe to the JBossEWS entitlements during the
281
    # base install or in configure_jbossews_repo.
282
    carts="$carts openshift-origin-cartridge-jbossews-1.0"
283
284
    # JBossEAP6.0 support.
285
    # Note: Be sure to subscribe to the JBossEAP entitlements during the
286
    # base install or in configure_jbosseap_repo.
287
    carts="$carts openshift-origin-cartridge-jbosseap-6.0"
288
289
    # Jenkins server for continuous integration.
290
    carts="$carts openshift-origin-cartridge-jenkins-1.4"
291
292
    # Embedded jenkins client.
293
    carts="$carts openshift-origin-cartridge-jenkins-client-1.4"
294
295
    # Embedded MySQL.
296
    carts="$carts openshift-origin-cartridge-mysql-5.1"
297
298
    # mod_perl support.
299
    carts="$carts openshift-origin-cartridge-perl-5.10"
300
301
    # PHP 5.3 support.
302
    carts="$carts openshift-origin-cartridge-php-5.3"
303
304
    # Embedded PostgreSQL.
305
    carts="$carts openshift-origin-cartridge-postgresql-8.4"
306
307
    # Python 2.6 support.
308
    carts="$carts openshift-origin-cartridge-python-2.6"
309
310
    # Ruby Rack support running on Phusion Passenger (Ruby 1.8).
311
    carts="$carts openshift-origin-cartridge-ruby-1.8"
312
313
    # Ruby Rack support running on Phusion Passenger (Ruby 1.9).
314
    carts="$carts openshift-origin-cartridge-ruby-1.9-scl"
315
  fi
316
317
  # When dependencies are missing, e.g. JBoss subscriptions,
318
  # still install as much as possible.
319
  carts="$carts --skip-broken"
320
321
  yum install -y $carts
322
}
323
324
# Fix up SELinux policy on the broker.
325
configure_selinux_policy_on_broker()
326
{
327
  # We combine these setsebool commands into a single semanage command
328
  # because separate commands take a long time to run.
329
  (
330
    # Allow console application to access executable and writable memory
331
    echo boolean -m --on httpd_execmem
332
333
    # Allow the broker to write files in the http file context.
334
    echo boolean -m --on httpd_unified
335
336
    # Allow the broker to access the network.
337
    echo boolean -m --on httpd_can_network_connect
338
    echo boolean -m --on httpd_can_network_relay
339
340
    # Enable some passenger-related permissions.
341
    #
342
    # The name may change at some future point, at which point we will
343
    # need to delete the httpd_run_stickshift line below and enable the
344
    # httpd_run_openshift line.
345
    echo boolean -m --on httpd_run_stickshift
346
    #echo boolean -m --on httpd_run_openshift
347
348
    # Allow the broker to communicate with the named service.
349
    echo boolean -m --on allow_ypbind
350
  ) | semanage -i -
351
352
  fixfiles -R ruby193-rubygem-passenger restore
353
  fixfiles -R ruby193-mod_passenger restore
354
355
  restorecon -rv /var/run
356
  # This should cover everything in the SCL, including passenger
357
  restorecon -rv /opt
358
}
359
360
# Fix up SELinux policy on the node.
361
configure_selinux_policy_on_node()
362
{
363
  # We combine these setsebool commands into a single semanage command
364
  # because separate commands take a long time to run.
365
  (
366
    # Allow the node to write files in the http file context.
367
    echo boolean -m --on httpd_unified
368
369
    # Allow the node to access the network.
370
    echo boolean -m --on httpd_can_network_connect
371
    echo boolean -m --on httpd_can_network_relay
372
373
    # Allow httpd on the node to read gear data.
374
    #
375
    # The name may change at some future point, at which point we will
376
    # need to delete the httpd_run_stickshift line below and enable the
377
    # httpd_run_openshift line.
378
    echo boolean -m --on httpd_run_stickshift
379
    #echo boolean -m --on httpd_run_openshift
380
    echo boolean -m --on httpd_read_user_content
381
    echo boolean -m --on httpd_enable_homedirs
382
383
    # Enable polyinstantiation for gear data.
384
    echo boolean -m --on allow_polyinstantiation
385
  ) | semanage -i -
386
387
388
  restorecon -rv /var/run
389
  restorecon -rv /usr/sbin/mcollectived /var/log/mcollective.log /var/run/mcollectived.pid
390
  restorecon -rv /var/lib/openshift /etc/openshift/node.conf /etc/httpd/conf.d/openshift
391
}
392
393
configure_pam_on_node()
394
{
395
  sed -i -e 's|pam_selinux|pam_openshift|g' /etc/pam.d/sshd
396
397
  for f in "runuser" "runuser-l" "sshd" "su" "system-auth-ac"
398
  do
399
t="/etc/pam.d/$f"
400
    if ! grep -q "pam_namespace.so" "$t"
401
    then
402
echo -e "session\t\trequired\tpam_namespace.so no_unmount_on_close" >> "$t"
403
    fi
404
done
405
406
  # if the user does not exist on the system an error will show up in
407
  # /var/log/secure.
408
  user_list="root,adm,apache"
409
  for user in gdm activemq mongodb; do
410
id -u "$user" >/dev/null 2>&1
411
      if [ X"$?" == X"0" ]; then
412
user_list="${user_list},${user}"
413
      fi
414
done
415
echo "/tmp \$HOME/.tmp/ user:iscript=/usr/sbin/oo-namespace-init ${user_list}" > /etc/security/namespace.d/tmp.conf
416
  echo "/dev/shm tmpfs tmpfs:mntopts=size=5M:iscript=/usr/sbin/oo-namespace-init ${user_list}" > /etc/security/namespace.d/shm.conf
417
}
418
419
configure_cgroups_on_node()
420
{
421
  cp -vf /opt/rh/ruby193/root/usr/share/gems/doc/openshift-origin-node-*/cgconfig.conf /etc/cgconfig.conf
422
  restorecon -rv /etc/cgconfig.conf
423
  mkdir -p /cgroup
424
  restorecon -rv /cgroup
425
  chkconfig cgconfig on
426
  chkconfig cgred on
427
  chkconfig openshift-cgroups on
428
}
429
430
configure_quotas_on_node()
431
{
432
  # Get the mountpoint for /var/lib/openshift (should be /).
433
  geardata_mnt=$(df -P /var/lib/openshift 2>/dev/null | tail -n 1 | awk '{ print $6 }')
434
435
  if ! [ x"$geardata_mnt" != x ]
436
  then
437
echo 'Could not enable quotas for gear data: unable to determine mountpoint.'
438
  else
439
    # Enable user quotas for the device housing /var/lib/openshift.
440
    sed -i -e "/^[^[:blank:]]\\+[[:blank:]]\\+${geardata_mnt////\/\\+[[:blank:]]}/{/usrquota/! s/[[:blank:]]\\+/,usrquota&/4;}" /etc/fstab
441
442
    # Remount to get quotas enabled immediately.
443
    mount -o remount "${geardata_mnt}"
444
445
    # Generate user quota info for the mount point.
446
    quotacheck -cmug "${geardata_mnt}"
447
448
    # fix up selinux perms
449
    restorecon "${geardata_mnt}"aquota.user
450
451
    # (re)enable quotas
452
    quotaon "${geardata_mnt}"
453
  fi
454
}
455
456
# Turn some sysctl knobs.
457
configure_sysctl_on_node()
458
{
459
  # Increase kernel semaphores to accomodate many httpds.
460
  echo "kernel.sem = 250 32000 32 4096" >> /etc/sysctl.conf
461
462
  # Move ephemeral port range to accommodate app proxies.
463
  echo "net.ipv4.ip_local_port_range = 15000 35530" >> /etc/sysctl.conf
464
465
  # Increase the connection tracking table size.
466
  echo "net.netfilter.nf_conntrack_max = 1048576" >> /etc/sysctl.conf
467
468
  # Reload sysctl.conf to get the new settings.
469
  #
470
  # Note: We could add -e here to ignore errors that are caused by
471
  # options appearing in sysctl.conf that correspond to kernel modules
472
  # that are not yet loaded. On the other hand, adding -e might cause
473
  # us to miss some important error messages.
474
  sysctl -p /etc/sysctl.conf
475
}
476
477
478
configure_sshd_on_node()
479
{
480
  # Configure sshd to pass the GIT_SSH environment variable through.
481
  echo 'AcceptEnv GIT_SSH' >> /etc/ssh/sshd_config
482
483
  # Up the limits on the number of connections to a given node.
484
  perl -p -i -e "s/^#MaxSessions .*$/MaxSessions 40/" /etc/ssh/sshd_config
485
  perl -p -i -e "s/^#MaxStartups .*$/MaxStartups 40/" /etc/ssh/sshd_config
486
}
487
488
# Configure MongoDB datastore.
489
configure_datastore()
490
{
491
  # Install MongoDB.
492
  yum_install_or_exit -y mongodb-server
493
494
  # Require authentication.
495
  perl -p -i -e "s/^#auth = .*$/auth = true/" /etc/mongodb.conf
496
497
  # Use a smaller default size for databases.
498
  if [ "x`fgrep smallfiles=true /etc/mongodb.conf`x" != "xsmallfiles=truex" ]
499
  then
500
echo 'smallfiles=true' >> /etc/mongodb.conf
501
  fi
502
503
  # Iff mongod is running on a separate host from the broker, open up
504
  # the firewall to allow the broker host to connect.
505
  if broker
506
  then
507
echo 'The broker and data store are on the same host.'
508
    echo 'Skipping firewall and mongod configuration;'
509
    echo 'mongod will only be accessible over localhost).'
510
  else
511
echo 'The broker and data store are on separate hosts.'
512
513
    echo 'Configuring the firewall to allow connections to mongod...'
514
    lokkit --nostart --port=27017:tcp
515
516
    echo 'Configuring mongod to listen on external interfaces...'
517
    perl -p -i -e "s/^bind_ip = .*$/bind_ip = 0.0.0.0/" /etc/mongodb.conf
518
  fi
519
520
  # Configure mongod to start on boot.
521
  chkconfig mongod on
522
523
  # Start mongod so we can perform some administration now.
524
  service mongod start
525
526
  # The init script lies to us as of version 2.0.2-1.el6_3: The start
527
  # and restart actions return before the daemon is ready to accept
528
  # connections (appears to take time to initialize the journal). Thus
529
  # we need the following to wait until the daemon is really ready.
530
  echo "Waiting for MongoDB to start ($(date +%H:%M:%S))..."
531
  while :
532
  do
533
echo exit | mongo && break
534
sleep 5
535
  done
536
echo "MongoDB is ready! ($(date +%H:%M:%S))"
537
538
  if is_false "$CONF_NO_DATASTORE_AUTH_FOR_LOCALHOST"
539
  then
540
    # Add an administrative user and a user that the broker will use.
541
    mongo <<EOF
542
use admin
543
db.addUser("${mongodb_admin_user}", "${mongodb_admin_password}")
544
545
db.auth("${mongodb_admin_user}", "${mongodb_admin_password}")
546
547
use ${mongodb_name}
548
db.addUser("${mongodb_broker_user}", "${mongodb_broker_password}")
549
EOF
550
  else
551
    # Add a user that the broker will use.
552
    mongo <<EOF
553
use ${mongodb_name}
554
db.addUser("${mongodb_broker_user}", "${mongodb_broker_password}")
555
EOF
556
  fi
557
}
558
559
560
# Open up services required on the node for apps and developers.
561
configure_port_proxy()
562
{
563
  lokkit --nostart --port=35531-65535:tcp
564
565
  chkconfig openshift-port-proxy on
566
}
567
568
configure_gears()
569
{
570
  # Make sure that gears are restarted on reboot.
571
  chkconfig openshift-gears on
572
}
573
574
575
# Enable services to start on boot for the node.
576
enable_services_on_node()
577
{
578
  # We use --nostart below because activating the configuration here
579
  # will produce errors. Anyway, we only need the configuration
580
  # activated Anaconda reboots, so --nostart makes sense in any case.
581
582
  lokkit --nostart --service=ssh
583
  lokkit --nostart --service=https
584
  lokkit --nostart --service=http
585
586
  # Allow connections to openshift-node-web-proxy
587
  lokkit --nostart --port=8000:tcp
588
  lokkit --nostart --port=8443:tcp
589
590
  chkconfig httpd on
591
  chkconfig network on
592
  is_false "$CONF_NO_NTP" && chkconfig ntpd on
593
  chkconfig sshd on
594
  chkconfig oddjobd on
595
  chkconfig openshift-node-web-proxy on
596
}
597
598
599
# Enable services to start on boot for the broker and fix up some issues.
600
enable_services_on_broker()
601
{
602
  # We use --nostart below because activating the configuration here
603
  # will produce errors. Anyway, we only need the configuration
604
  # activated after Anaconda reboots, so --nostart makes sense.
605
606
  lokkit --nostart --service=ssh
607
  lokkit --nostart --service=https
608
  lokkit --nostart --service=http
609
610
  chkconfig httpd on
611
  chkconfig network on
612
  is_false "$CONF_NO_NTP" && chkconfig ntpd on
613
  chkconfig sshd on
614
615
  # Remove VirtualHost from the default ssl.conf to prevent a warning
616
   sed -i '/VirtualHost/,/VirtualHost/ d' /etc/httpd/conf.d/ssl.conf
617
618
  # make sure mcollective client log is created with proper ownership.
619
  # if root owns it, the broker (apache user) can't log to it.
620
  touch /var/log/mcollective-client.log
621
  chown apache:root /var/log/mcollective-client.log
622
}
623
624
625
# Configure mcollective on the broker to use qpid.
626
configure_mcollective_for_qpid_on_broker()
627
{
628
  yum_install_or_exit -y mcollective-client
629
630
  cat <<EOF > /etc/mcollective/client.cfg
631
topicprefix = /topic/
632
main_collective = mcollective
633
collectives = mcollective
634
libdir = /opt/rh/ruby193/root/usr/libexec/mcollective
635
loglevel = debug
636
logfile = /var/log/mcollective-client.log
637
638
# Plugins
639
securityprovider = psk
640
plugin.psk = unset
641
connector = qpid
642
plugin.qpid.host = ${broker_hostname}
643
plugin.qpid.secure = false
644
plugin.qpid.timeout = 5
645
646
# Facts
647
factsource = yaml
648
plugin.yaml = /etc/mcollective/facts.yaml
649
EOF
650
651
}
652
653
654
# Configure mcollective on the broker to use qpid.
655
configure_mcollective_for_qpid_on_node()
656
{
657
  yum_install_or_exit -y mcollective openshift-origin-msg-node-mcollective
658
659
  cat <<EOF > /etc/mcollective/server.cfg
660
topicprefix = /topic/
661
main_collective = mcollective
662
collectives = mcollective
663
libdir = /opt/rh/ruby193/root/usr/libexec/mcollective
664
logfile = /var/log/mcollective.log
665
loglevel = debug
666
daemonize = 1
667
direct_addressing = n
668
669
# Plugins
670
securityprovider = psk
671
plugin.psk = unset
672
connector = qpid
673
plugin.qpid.host = ${broker_hostname}
674
plugin.qpid.secure = false
675
plugin.qpid.timeout = 5
676
677
# Facts
678
factsource = yaml
679
plugin.yaml = /etc/mcollective/facts.yaml
680
EOF
681
682
  chkconfig mcollective on
683
}
684
685
686
# Configure mcollective on the broker to use ActiveMQ.
687
configure_mcollective_for_activemq_on_broker()
688
{
689
  yum_install_or_exit -y mcollective-client
690
691
  cat <<EOF > /etc/mcollective/client.cfg
692
topicprefix = /topic/
693
main_collective = mcollective
694
collectives = mcollective
695
libdir = /opt/rh/ruby193/root/usr/libexec/mcollective
696
logfile = /var/log/mcollective-client.log
697
loglevel = debug
698
699
# Plugins
700
securityprovider=psk
701
plugin.psk=unset
702
703
connector = stomp
704
plugin.stomp.host = ${activemq_hostname}
705
plugin.stomp.port = 61613
706
plugin.stomp.user = ${mcollective_user}
707
plugin.stomp.password = ${mcollective_password}
708
EOF
709
}
710
711
712
# Configure mcollective on the node to use ActiveMQ.
713
configure_mcollective_for_activemq_on_node()
714
{
715
  yum_install_or_exit -y mcollective openshift-origin-msg-node-mcollective
716
717
  cat <<EOF > /etc/mcollective/server.cfg
718
topicprefix = /topic/
719
main_collective = mcollective
720
collectives = mcollective
721
libdir = /opt/rh/ruby193/root/usr/libexec/mcollective
722
logfile = /var/log/mcollective.log
723
loglevel = debug
724
daemonize = 1
725
direct_addressing = n
726
registerinterval = 30
727
728
# Plugins
729
securityprovider = psk
730
plugin.psk = unset
731
732
connector = stomp
733
plugin.stomp.host = ${activemq_hostname}
734
plugin.stomp.port = 61613
735
plugin.stomp.user = ${mcollective_user}
736
plugin.stomp.password = ${mcollective_password}
737
738
# Facts
739
factsource = yaml
740
plugin.yaml = /etc/mcollective/facts.yaml
741
EOF
742
743
  chkconfig mcollective on
744
}
745
746
747
# Configure ActiveMQ.
748
configure_activemq()
749
{
750
  # Install the service.
751
  yum_install_or_exit -y activemq
752
753
  cat <<EOF > /etc/activemq/activemq.xml
754
<!--
755
Licensed to the Apache Software Foundation (ASF) under one or more
756
contributor license agreements. See the NOTICE file distributed with
757
this work for additional information regarding copyright ownership.
758
The ASF licenses this file to You under the Apache License, Version 2.0
759
(the "License"); you may not use this file except in compliance with
760
the License. You may obtain a copy of the License at
761
762
http://www.apache.org/licenses/LICENSE-2.0
763
764
Unless required by applicable law or agreed to in writing, software
765
distributed under the License is distributed on an "AS IS" BASIS,
766
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
767
See the License for the specific language governing permissions and
768
limitations under the License.
769
-->
770
<beans
771
xmlns="http://www.springframework.org/schema/beans"
772
xmlns:amq="http://activemq.apache.org/schema/core"
773
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
774
xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans-2.0.xsd
775
http://activemq.apache.org/schema/core http://activemq.apache.org/schema/core/activemq-core.xsd">
776
777
<!-- Allows us to use system properties as variables in this configuration file -->
778
<bean class="org.springframework.beans.factory.config.PropertyPlaceholderConfigurer">
779
<property name="locations">
780
<value>file:\${activemq.conf}/credentials.properties</value>
781
</property>
782
</bean>
783
784
<!--
785
The <broker> element is used to configure the ActiveMQ broker.
786
-->
787
<broker xmlns="http://activemq.apache.org/schema/core" brokerName="${activemq_hostname}" dataDirectory="\${activemq.data}">
788
789
<!--
790
For better performances use VM cursor and small memory limit.
791
For more information, see:
792
793
http://activemq.apache.org/message-cursors.html
794
795
Also, if your producer is "hanging", it's probably due to producer flow control.
796
For more information, see:
797
http://activemq.apache.org/producer-flow-control.html
798
-->
799
800
<destinationPolicy>
801
<policyMap>
802
<policyEntries>
803
<policyEntry topic=">" producerFlowControl="true" memoryLimit="1mb">
804
<pendingSubscriberPolicy>
805
<vmCursor />
806
</pendingSubscriberPolicy>
807
</policyEntry>
808
<policyEntry queue=">" producerFlowControl="true" memoryLimit="1mb">
809
<!-- Use VM cursor for better latency
810
For more information, see:
811
812
http://activemq.apache.org/message-cursors.html
813
814
<pendingQueuePolicy>
815
<vmQueueCursor/>
816
</pendingQueuePolicy>
817
-->
818
</policyEntry>
819
</policyEntries>
820
</policyMap>
821
</destinationPolicy>
822
823
824
<!--
825
The managementContext is used to configure how ActiveMQ is exposed in
826
JMX. By default, ActiveMQ uses the MBean server that is started by
827
the JVM. For more information, see:
828
829
http://activemq.apache.org/jmx.html
830
-->
831
<managementContext>
832
<managementContext createConnector="false"/>
833
</managementContext>
834
835
<!--
836
Configure message persistence for the broker. The default persistence
837
mechanism is the KahaDB store (identified by the kahaDB tag).
838
For more information, see:
839
840
http://activemq.apache.org/persistence.html
841
-->
842
<persistenceAdapter>
843
<kahaDB directory="\${activemq.data}/kahadb"/>
844
</persistenceAdapter>
845
846
<!-- add users for mcollective -->
847
848
<plugins>
849
<statisticsBrokerPlugin/>
850
<simpleAuthenticationPlugin>
851
<users>
852
<authenticationUser username="${mcollective_user}" password="${mcollective_password}" groups="mcollective,everyone"/>
853
<authenticationUser username="admin" password="${activemq_admin_password}" groups="mcollective,admin,everyone"/>
854
</users>
855
</simpleAuthenticationPlugin>
856
<authorizationPlugin>
857
<map>
858
<authorizationMap>
859
<authorizationEntries>
860
<authorizationEntry queue=">" write="admins" read="admins" admin="admins" />
861
<authorizationEntry topic=">" write="admins" read="admins" admin="admins" />
862
<authorizationEntry topic="mcollective.>" write="mcollective" read="mcollective" admin="mcollective" />
863
<authorizationEntry queue="mcollective.>" write="mcollective" read="mcollective" admin="mcollective" />
864
<authorizationEntry topic="ActiveMQ.Advisory.>" read="everyone" write="everyone" admin="everyone"/>
865
</authorizationEntries>
866
</authorizationMap>
867
</map>
868
</authorizationPlugin>
869
</plugins>
870
871
<!--
872
The systemUsage controls the maximum amount of space the broker will
873
use before slowing down producers. For more information, see:
874
http://activemq.apache.org/producer-flow-control.html
875
If using ActiveMQ embedded - the following limits could safely be used:
876
877
<systemUsage>
878
<systemUsage>
879
<memoryUsage>
880
<memoryUsage limit="20 mb"/>
881
</memoryUsage>
882
<storeUsage>
883
<storeUsage limit="1 gb"/>
884
</storeUsage>
885
<tempUsage>
886
<tempUsage limit="100 mb"/>
887
</tempUsage>
888
</systemUsage>
889
</systemUsage>
890
-->
891
<systemUsage>
892
<systemUsage>
893
<memoryUsage>
894
<memoryUsage limit="64 mb"/>
895
</memoryUsage>
896
<storeUsage>
897
<storeUsage limit="100 gb"/>
898
</storeUsage>
899
<tempUsage>
900
<tempUsage limit="50 gb"/>
901
</tempUsage>
902
</systemUsage>
903
</systemUsage>
904
905
<!--
906
The transport connectors expose ActiveMQ over a given protocol to
907
clients and other brokers. For more information, see:
908
909
http://activemq.apache.org/configuring-transports.html
910
-->
911
<transportConnectors>
912
<transportConnector name="openwire" uri="tcp://0.0.0.0:61616"/>
913
<transportConnector name="stomp" uri="stomp://0.0.0.0:61613"/>
914
</transportConnectors>
915
916
</broker>
917
918
<!--
919
Enable web consoles, REST and Ajax APIs and demos
920
921
Take a look at \${ACTIVEMQ_HOME}/conf/jetty.xml for more details
922
-->
923
<import resource="jetty.xml"/>
924
925
</beans>
926
<!-- END SNIPPET: example -->
927
EOF
928
929
  # secure the ActiveMQ console
930
  sed -i -e '/name="authenticate"/s/false/true/' /etc/activemq/jetty.xml
931
932
  # only add the host property if it's not already there
933
  # (so you can run the script multiple times)
934
  grep '<property name="host" value="127.0.0.1" />' /etc/activemq/jetty.xml > /dev/null
935
  if [ $? -ne 0 ]; then
936
sed -i -e '/name="port"/a<property name="host" value="127.0.0.1" />' /etc/activemq/jetty.xml
937
  fi
938
939
sed -i -e "/admin:/s/admin,/${activemq_admin_password},/" /etc/activemq/jetty-realm.properties
940
941
942
  # Allow connections to ActiveMQ.
943
  lokkit --nostart --port=61613:tcp
944
945
  # Configure ActiveMQ to start on boot.
946
  chkconfig activemq on
947
}
948
949
950
# Configure qpid. Deprecated for ActiveMQ.
951
configure_qpid()
952
{
953
  if [[ "x`fgrep auth= /etc/qpidd.conf`" == xauth* ]]
954
  then
955
sed -i -e 's/auth=yes/auth=no/' /etc/qpidd.conf
956
  else
957
echo "auth=no" >> /etc/qpidd.conf
958
  fi
959
960
  # Allow connections to qpidd.
961
  lokkit --nostart --port=5672:tcp
962
963
  # Configure qpidd to start on boot.
964
  chkconfig qpidd on
965
}
966
967
968
# Configure BIND.
969
configure_named()
970
{
971
  yum_install_or_exit -y bind bind-utils
972
973
  # $keyfile will contain a new DNSSEC key for our domain.
974
  keyfile=/var/named/${domain}.key
975
976
  if [ "x$bind_key" = x ]
977
  then
978
    # Generate the new key for the domain.
979
    pushd /var/named
980
    rm -f /var/named/K${domain}*
981
    dnssec-keygen -a HMAC-MD5 -b 512 -n USER -r /dev/urandom ${domain}
982
    bind_key="$(grep Key: K${domain}*.private | cut -d ' ' -f 2)"
983
    popd
984
fi
985
986
  # Ensure we have a key for service named status to communicate with BIND.
987
  rndc-confgen -a -r /dev/urandom
988
  restorecon /etc/rndc.* /etc/named.*
989
  chown root:named /etc/rndc.key
990
  chmod 640 /etc/rndc.key
991
992
  # Set up DNS forwarding.
993
  cat <<EOF > /var/named/forwarders.conf
994
forwarders { ${nameservers} } ;
995
EOF
996
  restorecon /var/named/forwarders.conf
997
  chmod 644 /var/named/forwarders.conf
998
999
  # Install the configuration file for the OpenShift Enterprise domain
1000
  # name.
1001
  rm -rf /var/named/dynamic
1002
  mkdir -p /var/named/dynamic
1003
1004
1005
  # Create the initial BIND database.
1006
  nsdb=/var/named/dynamic/${domain}.db
1007
  cat <<EOF > $nsdb
1008
\$ORIGIN .
1009
\$TTL 1 ; 1 seconds (for testing only)
1010
${domain} IN SOA ${named_hostname}. hostmaster.${domain}. (
1011
2011112904 ; serial
1012
60 ; refresh (1 minute)
1013
15 ; retry (15 seconds)
1014
1800 ; expire (30 minutes)
1015
10 ; minimum (10 seconds)
1016
)
1017
NS ${named_hostname}.
1018
MX 10 mail.${domain}.
1019
\$ORIGIN ${domain}.
1020
${named_hostname%.${domain}} A ${named_ip_addr}
1021
EOF
1022
1023
  # Add A records any other components that are being installed locally.
1024
  broker && echo "${broker_hostname%.${domain}} A ${broker_ip_addr}" >> $nsdb
1025
  node && echo "${node_hostname%.${domain}} A ${node_ip_addr}${nl}" >> $nsdb
1026
  activemq && echo "${activemq_hostname%.${domain}} A ${cur_ip_addr}${nl}" >> $nsdb
1027
  datastore && echo "${datastore_hostname%.${domain}} A ${cur_ip_addr}${nl}" >> $nsdb
1028
  echo >> $nsdb
1029
1030
  # Install the key for the OpenShift Enterprise domain.
1031
  cat <<EOF > /var/named/${domain}.key
1032
key ${domain} {
1033
algorithm HMAC-MD5;
1034
secret "${bind_key}";
1035
};
1036
EOF
1037
1038
  chown named:named -R /var/named
1039
  restorecon -rv /var/named
1040
1041
  # Replace named.conf.
1042
  cat <<EOF > /etc/named.conf
1043
// named.conf
1044
//
1045
// Provided by Red Hat bind package to configure the ISC BIND named(8) DNS
1046
// server as a caching only nameserver (as a localhost DNS resolver only).
1047
//
1048
// See /usr/share/doc/bind*/sample/ for example named configuration files.
1049
//
1050
1051
options {
1052
listen-on port 53 { any; };
1053
directory "/var/named";
1054
dump-file "/var/named/data/cache_dump.db";
1055
statistics-file "/var/named/data/named_stats.txt";
1056
memstatistics-file "/var/named/data/named_mem_stats.txt";
1057
allow-query { any; };
1058
recursion yes;
1059
1060
/* Path to ISC DLV key */
1061
bindkeys-file "/etc/named.iscdlv.key";
1062
1063
// set forwarding to the next nearest server (from DHCP response
1064
forward only;
1065
include "forwarders.conf";
1066
};
1067
1068
logging {
1069
channel default_debug {
1070
file "data/named.run";
1071
severity dynamic;
1072
};
1073
};
1074
1075
// use the default rndc key
1076
include "/etc/rndc.key";
1077
controls {
1078
inet 127.0.0.1 port 953
1079
allow { 127.0.0.1; } keys { "rndc-key"; };
1080
};
1081
1082
include "/etc/named.rfc1912.zones";
1083
1084
include "${domain}.key";
1085
1086
zone "${domain}" IN {
1087
type master;
1088
file "dynamic/${domain}.db";
1089
allow-update { key ${domain} ; } ;
1090
};
1091
EOF
1092
  chown root:named /etc/named.conf
1093
  chcon system_u:object_r:named_conf_t:s0 -v /etc/named.conf
1094
1095
  # Configure named to start on boot.
1096
  lokkit --nostart --service=dns
1097
  chkconfig named on
1098
1099
  # Start named so we can perform some updates immediately.
1100
  service named start
1101
}
1102
1103
1104
# Make resolv.conf point to our named service, which will resolve the
1105
# host names used in this installation of OpenShift. Our named service
1106
# will forward other requests to some other DNS servers.
1107
update_resolv_conf()
1108
{
1109
  # Update resolv.conf to use our named.
1110
  #
1111
  # We will keep any existing entries so that we have fallbacks that
1112
  # will resolve public addresses even when our private named is
1113
  # nonfunctional. However, our private named must appear first in
1114
  # order for hostnames private to our OpenShift PaaS to resolve.
1115
  sed -i -e "1i# The named we install for our OpenShift PaaS must appear first.\\nnameserver ${named_ip_addr}\\n" /etc/resolv.conf
1116
}
1117
1118
1119
# Update the controller configuration.
1120
configure_controller()
1121
{
1122
  if [ "x$broker_auth_salt" = "x" ]
1123
  then
1124
echo "Warning: broker authentication salt is empty!"
1125
  fi
1126
1127
  # Configure the console with the correct domain
1128
  sed -i -e "s/^DOMAIN_SUFFIX=.*$/DOMAIN_SUFFIX=${domain}/" \
1129
      /etc/openshift/console.conf
1130
1131
  # Configure the broker with the correct hostname, and use random salt
1132
  # to the data store (the host running MongoDB).
1133
  sed -i -e "s/^CLOUD_DOMAIN=.*$/CLOUD_DOMAIN=${domain}/" \
1134
      /etc/openshift/broker.conf
1135
  echo AUTH_SALT=${broker_auth_salt} >> /etc/openshift/broker.conf
1136
1137
  if ! datastore
1138
  then
1139
    #mongo not installed locally, so point to given hostname
1140
    sed -i -e "s/^MONGO_HOST_PORT=.*$/MONGO_HOST_PORT=\"${datastore_hostname}:27017\"/" /etc/openshift/broker.conf
1141
  fi
1142
1143
  # configure MongoDB access
1144
  sed -i -e "s/MONGO_PASSWORD=.*$/MONGO_PASSWORD=\"${mongodb_broker_password}\"/
1145
s/MONGO_USER=.*$/MONGO_USER=\"${mongodb_broker_user}\"/
1146
s/MONGO_DB=.*$/MONGO_DB=\"${mongodb_name}\"/" \
1147
      /etc/openshift/broker.conf
1148
1149
  # Configure the broker service to start on boot.
1150
  chkconfig openshift-broker on
1151
  chkconfig openshift-console on
1152
}
1153
1154
# Configure the broker to use the remote-user authentication plugin.
1155
configure_remote_user_auth_plugin()
1156
{
1157
  cp /etc/openshift/plugins.d/openshift-origin-auth-remote-user.conf{.example,}
1158
}
1159
1160
# Configure the broker to use the MongoDB-based authentication plugin.
1161
#
1162
# NB: It is assumed that configure_datastore has previously been run on
1163
# this host to install and configure MongoDB.
1164
configure_mongo_auth_plugin()
1165
{
1166
  cp /etc/openshift/plugins.d/openshift-origin-auth-mongo.conf{.example,}
1167
1168
  if ! datastore
1169
  then
1170
    # MongoDB is running on a remote host, so we must modify the
1171
    # plug-in configuration to point it to that host.
1172
    sed -i -e "s/^MONGO_HOST_PORT=.*$/MONGO_HOST_PORT=\"${datastore_hostname}:27017\"/" /etc/openshift/plugins.d/openshift-origin-auth-mongo.conf
1173
  fi
1174
1175
  # We must specify the --host, --username, and --password options iff the
1176
  # datastore is being installed on the current host.
1177
  if datastore
1178
  then
1179
mongo_opts=""
1180
  else
1181
mongo_opts="--host ${datastore_hostname} --username openshift --password mooo"
1182
  fi
1183
1184
  # The init script is broken as of version 2.0.2-1.el6_3: The start
1185
  # and restart actions return before the daemon is ready to accept
1186
  # connections (it appears to take time to initialize the journal).
1187
  # Thus we need the following hack to wait until the daemon is ready.
1188
  echo "Waiting for MongoDB to start ($(date +%H:%M:%S))..."
1189
  while :
1190
  do
1191
echo exit | mongo $mongo_opts && break
1192
sleep 5
1193
  done
1194
echo "MongoDB is ready! ($(date +%H:%M:%S))"
1195
1196
  hashed_password="$(printf 'admin' | md5sum -b | cut -d' ' -f1)"
1197
  hashed_salted_password="$(printf '%s' "$hashed_password$broker_auth_salt" | md5sum | cut -d' ' -f1)"
1198
1199
  # Add user "admin" with password "admin" for oo-register-user.
1200
  mongo $mongodb_name $mongo_opts --eval 'db.auth_user.update({"_id":"admin"}, {"_id":"admin","user":"admin","password":"'"$hashed_salted_password"'"}, true)'
1201
}
1202
1203
configure_messaging_plugin()
1204
{
1205
  cp /etc/openshift/plugins.d/openshift-origin-msg-broker-mcollective.conf{.example,}
1206
}
1207
1208
# Configure the broker to use the BIND DNS plug-in.
1209
configure_dns_plugin()
1210
{
1211
  if [ "x$bind_key" = x ]
1212
  then
1213
echo 'WARNING: No key has been set for communication with BIND.'
1214
    echo 'You will need to modify the value of BIND_KEYVALUE in'
1215
    echo '/etc/openshift/plugins.d/openshift-origin-dns-nsupdate.conf'
1216
    echo 'after installation.'
1217
  fi
1218
1219
mkdir -p /etc/openshift/plugins.d
1220
  cat <<EOF > /etc/openshift/plugins.d/openshift-origin-dns-nsupdate.conf
1221
BIND_SERVER="${named_ip_addr}"
1222
BIND_PORT=53
1223
BIND_KEYNAME="${domain}"
1224
BIND_KEYVALUE="${bind_key}"
1225
BIND_ZONE="${domain}"
1226
EOF
1227
}
1228
1229
# Configure httpd for authentication.
1230
configure_httpd_auth()
1231
{
1232
  # Install the Apache configuration file.
1233
  cp /var/www/openshift/broker/httpd/conf.d/openshift-origin-auth-remote-user-basic.conf.sample \
1234
     /var/www/openshift/broker/httpd/conf.d/openshift-origin-auth-remote-user.conf
1235
1236
  cp /var/www/openshift/console/httpd/conf.d/openshift-origin-auth-remote-user-basic.conf.sample \
1237
     /var/www/openshift/console/httpd/conf.d/openshift-origin-auth-remote-user.conf
1238
1239
  # The above configuration file configures Apache to use
1240
  # /etc/openshift/htpasswd for its password file.
1241
  #
1242
  # Here we create a test user:
1243
  htpasswd -bc /etc/openshift/htpasswd "$openshift_user1" "$openshift_password1"
1244
  #
1245
  # Use the following command to add more users:
1246
  #
1247
  # htpasswd /etc/openshift/htpasswd username
1248
1249
  # TODO: In the future, we will want to edit
1250
  # /etc/openshift/plugins.d/openshift-origin-auth-remote-user.conf to
1251
  # put in a random salt.
1252
}
1253
1254
# if the broker and node are on the same machine we need to manually update the
1255
# nodes.db
1256
fix_broker_routing()
1257
{
1258
  cat <<EOF >> /var/lib/openshift/.httpd.d/nodes.txt
1259
__default__ REDIRECT:/console
1260
__default__/console TOHTTPS:127.0.0.1:8118/console
1261
__default__/broker TOHTTPS:127.0.0.1:8080/broker
1262
EOF
1263
1264
  httxt2dbm -f DB -i /etc/httpd/conf.d/openshift/nodes.txt -o /etc/httpd/conf.d/openshift/nodes.db
1265
  chown root:apache /etc/httpd/conf.d/openshift/nodes.txt /etc/httpd/conf.d/openshift/nodes.db
1266
  chmod 750 /etc/httpd/conf.d/openshift/nodes.txt /etc/httpd/conf.d/openshift/nodes.db
1267
}
1268
1269
configure_access_keys_on_broker()
1270
{
1271
  # Generate a broker access key for remote apps (Jenkins) to access
1272
  # the broker.
1273
  openssl genrsa -out /etc/openshift/server_priv.pem 2048
1274
  openssl rsa -in /etc/openshift/server_priv.pem -pubout > /etc/openshift/server_pub.pem
1275
1276
  # If a key pair already exists, delete it so that the ssh-keygen
1277
  # command will not have to ask the user what to do.
1278
  rm -f /root/.ssh/rsync_id_rsa /root/.ssh/rsync_id_rsa.pub
1279
1280
  # Generate a key pair for moving gears between nodes from the broker
1281
  ssh-keygen -t rsa -b 2048 -P "" -f /root/.ssh/rsync_id_rsa
1282
  cp ~/.ssh/rsync_id_rsa* /etc/openshift/
1283
  # the .pub key needs to go on nodes, but there is no good way
1284
  # to script that generically. Nodes should not have password-less
1285
  # access to brokers to copy the .pub key, but this can be performed
1286
  # manually:
1287
  # # scp root@broker:/etc/openshift/rsync_id_rsa.pub /root/.ssh/
1288
  # the above step will ask for the root password of the broker machine
1289
  # # cat /root/.ssh/rsync_id_rsa.pub >> /root/.ssh/authorized_keys
1290
  # # rm /root/.ssh/rsync_id_rsa.pub
1291
}
1292
1293
configure_wildcard_ssl_cert_on_node()
1294
{
1295
  # Generate a 2048 bit key and self-signed cert
1296
  cat << EOF | openssl req -new -rand /dev/urandom \
1297
-newkey rsa:2048 -nodes -keyout /etc/pki/tls/private/localhost.key \
1298
-x509 -days 3650 -extensions v3_req \
1299
-out /etc/pki/tls/certs/localhost.crt 2> /dev/null
1300
XX
1301
SomeState
1302
SomeCity
1303
SomeOrganization
1304
SomeOrganizationalUnit
1305
*.${domain}
1306
root@${domain}
1307
EOF
1308
1309
  # Generate a cert signing request (example)
1310
  #openssl req -new -in /etc/pki/tls/private/localhost.key -out /etc/pki/tls/certs/localhost.csr
1311
}
1312
1313
configure_broker_ssl_cert()
1314
{
1315
  # Generate a 2048 bit key and self-signed cert
1316
  cat << EOF | openssl req -new -rand /dev/urandom \
1317
-newkey rsa:2048 -nodes -keyout /etc/pki/tls/private/localhost.key \
1318
-x509 -days 3650 -extensions v3_req \
1319
-out /etc/pki/tls/certs/localhost.crt 2> /dev/null
1320
XX
1321
SomeState
1322
SomeCity
1323
SomeOrganization
1324
SomeOrganizationalUnit
1325
${broker_hostname}
1326
root@${domain}
1327
EOF
1328
}
1329
1330
# Configure IP address and hostname.
1331
configure_network()
1332
{
1333
  # Append some stuff to the DHCP configuration.
1334
  cat <<EOF >> /etc/dhcp/dhclient-eth0.conf
1335
1336
prepend domain-name-servers ${named_ip_addr};
1337
supersede host-name "${hostname%.${domain}}";
1338
supersede domain-name "${domain}";
1339
prepend domain-search "${domain}";
1340
EOF
1341
}
1342
1343
# Set the hostname
1344
configure_hostname()
1345
{
1346
  sed -i -e "s/HOSTNAME=.*/HOSTNAME=${hostname}/" /etc/sysconfig/network
1347
  hostname "${hostname}"
1348
}
1349
1350
# Set some parameters in the OpenShift node configuration file.
1351
configure_node()
1352
{
1353
  sed -i -e "s/^PUBLIC_IP=.*$/PUBLIC_IP=${node_ip_addr}/;
1354
s/^CLOUD_DOMAIN=.*$/CLOUD_DOMAIN=${domain}/;
1355
s/^PUBLIC_HOSTNAME=.*$/PUBLIC_HOSTNAME=${hostname}/;
1356
s/^BROKER_HOST=.*$/BROKER_HOST=${broker_hostname}/" \
1357
      /etc/openshift/node.conf
1358
1359
  echo $broker_hostname > /etc/openshift/env/OPENSHIFT_BROKER_HOST
1360
  echo $domain > /etc/openshift/env/OPENSHIFT_CLOUD_DOMAIN
1361
1362
  if is_true "$node_v2_enable"
1363
  then
1364
mkdir -p /var/lib/openshift/.settings
1365
    touch /var/lib/openshift/.settings/v2_cartridge_format
1366
  fi
1367
}
1368
1369
# Run the cronjob installed by openshift-origin-msg-node-mcollective immediately
1370
# to regenerate facts.yaml.
1371
update_openshift_facts_on_node()
1372
{
1373
  /etc/cron.minutely/openshift-facts
1374
}
1375
1376
echo_installation_intentions()
1377
{
1378
  echo "The following components should be installed:"
1379
  for component in $components
1380
  do
1381
if eval $component
1382
    then
1383
printf '\t%s.\n' $component
1384
    fi
1385
done
1386
1387
echo "Configuring with broker with hostname ${broker_hostname}."
1388
  node && echo "Configuring node with hostname ${node_hostname}."
1389
  echo "Configuring with named with IP address ${named_ip_addr}."
1390
  broker && echo "Configuring with datastore with hostname ${datastore_hostname}."
1391
  echo "Configuring with activemq with hostname ${activemq_hostname}."
1392
}
1393
1394
# Modify console message to show install info
1395
configure_console_msg()
1396
{
1397
  # add the IP to /etc/issue for convenience
1398
  echo "Install-time IP address: ${cur_ip_addr}" >> /etc/issue
1399
  echo_installation_intentions >> /etc/issue
1400
  echo "Check /root/anaconda-post.log to see the %post output." >> /etc/issue
1401
  echo >> /etc/issue
1402
}
1403
1404
1405
1406
########################################################################
1407
1408
#
1409
# Parse the kernel command-line, define variables with the parameters
1410
# specified on it, and define functions broker() and node(), which
1411
# return true or false as appropriate based on whether we are
1412
# configuring the host as a broker or as a node.
1413
#
1414
1415
# Parse /proc/cmdline so that from, e.g., "foo=bar baz" we get
1416
# CONF_FOO=bar and CONF_BAZ=true in the environment.
1417
parse_cmdline()
1418
{
1419
  for word in $(cat /proc/cmdline)
1420
  do
1421
key="${word%%\=*}"
1422
    case "$word" in
1423
      (*=*) val="${word#*\=}" ;;
1424
      (*) val=true ;;
1425
    esac
1426
eval "CONF_${key^^}"'="$val"'
1427
  done
1428
}
1429
1430
is_true()
1431
{
1432
  for arg
1433
  do
1434
    [[ x$arg =~ x(1|true) ]] || return 1
1435
  done
1436
1437
return 0
1438
}
1439
1440
is_false()
1441
{
1442
  for arg
1443
  do
1444
    [[ x$arg =~ x(1|true) ]] || return 0
1445
  done
1446
1447
return 1
1448
}
1449
1450
# For each component, this function defines a constant function that
1451
# returns either true or false. For example, there will be a named
1452
# function indicating whether we are currently installing the named
1453
# service. We can use 'if named; then ...; fi' or just 'named && ...'
1454
# to run the given commands if, and only if, named is being installed
1455
# on this host.
1456
#
1457
# The following functions will be defined:
1458
#
1459
# activemq
1460
# broker
1461
# datastore
1462
# named
1463
# node
1464
#
1465
# For each component foo, we also set a $foo_hostname variable with the
1466
# hostname for that logical host. We use hostnames in configuration
1467
# files wherever possible. The only places where this is not possible
1468
# is where we are referencing the named service; in such places, we use
1469
# $named_ip_addr, which is also set by this function. It is possible
1470
# that one host runs multiple services, in which case more than one
1471
# hostname will resolve to the same IP address.
1472
#
1473
# We also set the $domain variable, which is the domain that will be
1474
# used when configuring BIND and assigning hostnames for the various
1475
# hosts in the OpenShift PaaS.
1476
#
1477
# We also set the $repos_base variable with the base URL for the yum
1478
# repositories that will be used to download OpenShift RPMs. The value
1479
# of this variable can be changed to use a custom repository or puddle.
1480
#
1481
# We also set the $cur_ip_addr variable to the IP address of the host
1482
# running this script, based on the output of the `ip addr show` command
1483
#
1484
# In addition, the $nameservers variable will be set to
1485
# a semicolon-delimited list of nameservers, suitable for use in
1486
# named.conf, based on the existing contents of /etc/resolv.conf, and
1487
# the $bind_key variable will be set to the value of CONF_BIND_KEY.
1488
#
1489
# The following variables will be defined:
1490
#
1491
# activemq_hostname
1492
# bind_key
1493
# broker_hostname
1494
# cur_ip_addr
1495
# domain
1496
# datastore_hostname
1497
# named_hostname
1498
# named_ip_addr
1499
# nameservers
1500
# node_hostname
1501
# repos_base
1502
#
1503
# This function makes use of variables that may be set by parse_cmdline
1504
# based on the content of /proc/cmdline or may be hardcoded by modifying
1505
# this file. All of these variables are optional; best attempts are
1506
# made at determining reasonable defaults.
1507
#
1508
# The following variables are used:
1509
#
1510
# CONF_ACTIVEMQ_HOSTNAME
1511
# CONF_BIND_KEY
1512
# CONF_BROKER_HOSTNAME
1513
# CONF_BROKER_IP_ADDR
1514
# CONF_DATASTORE_HOSTNAME
1515
# CONF_DOMAIN
1516
# CONF_INSTALL_COMPONENTS
1517
# CONF_NAMED_HOSTNAME
1518
# CONF_NAMED_IP_ADDR
1519
# CONF_NODE_HOSTNAME
1520
# CONF_NODE_IP_ADDR
1521
# CONF_NODE_V2_ENABLE
1522
# CONF_REPOS_BASE
1523
set_defaults()
1524
{
1525
  # Following are the different components that can be installed:
1526
  components='broker node named activemq datastore'
1527
1528
  # By default, each component is _not_ installed.
1529
  for component in $components
1530
  do
1531
eval "$component() { false; }"
1532
  done
1533
1534
  # But any or all components may be explicity enabled.
1535
  for component in ${CONF_INSTALL_COMPONENTS//,/ }
1536
  do
1537
eval "$component() { :; }"
1538
  done
1539
1540
  # If nothing is explicitly enabled, enable everything.
1541
  installing_something=0
1542
  for component in $components
1543
  do
1544
if eval $component
1545
    then
1546
installing_something=1
1547
      break
1548
fi
1549
done
1550
if [ $installing_something = 0 ]
1551
  then
1552
for component in $components
1553
    do
1554
eval "$component() { :; }"
1555
    done
1556
fi
1557
1558
  # Following are some settings used in subsequent steps.
1559
1560
  # Where to find the OpenShift repositories; just the base part before
1561
  # splitting out into Infrastructure/Node/etc.
1562
  repos_base_default='https://mirror.openshift.com/pub/origin-server/nightly/enterprise/2012-11-15'
1563
  repos_base="${CONF_REPOS_BASE:-${repos_base_default}}"
1564
1565
  # There a no defaults for these. Customers should be using
1566
  # subscriptions via RHN. Internally we use private systems.
1567
  rhel_repo="$CONF_RHEL_REPO"
1568
  jboss_repo_base="$CONF_JBOSS_REPO_BASE"
1569
  rhel_optional_repo="$CONF_RHEL_OPTIONAL_REPO"
1570
1571
  # The domain name for the OpenShift Enterprise installation.
1572
  domain="${CONF_DOMAIN:-example.com}"
1573
1574
  # hostnames to use for the components (could all resolve to same host)
1575
  broker_hostname="${CONF_BROKER_HOSTNAME:-broker.${domain}}"
1576
  node_hostname="${CONF_NODE_HOSTNAME:-node.${domain}}"
1577
  named_hostname="${CONF_NAMED_HOSTNAME:-ns1.${domain}}"
1578
  activemq_hostname="${CONF_ACTIVEMQ_HOSTNAME:-activemq.${domain}}"
1579
  datastore_hostname="${CONF_DATASTORE_HOSTNAME:-datastore.${domain}}"
1580
1581
  # The hostname name for this host.
1582
  # Note: If this host is, e.g., both a broker and a datastore, we want
1583
  # to go with the broker hostname and not the datastore hostname.
1584
  if broker
1585
  then hostname="$broker_hostname"
1586
  elif node
1587
  then hostname="$node_hostname"
1588
  elif named
1589
  then hostname="$named_hostname"
1590
  elif activemq
1591
  then hostname="$activemq_hostname"
1592
  elif datastore
1593
  then hostname="$datastore_hostname"
1594
  fi
1595
1596
  # Grab the IP address set during installation.
1597
  cur_ip_addr="$(/sbin/ip addr show dev eth0 | awk '/inet / { split($2,a,"/"); print a[1]; }')"
1598
1599
  # Unless otherwise specified, the broker is assumed to be the current
1600
  # host.
1601
  broker_ip_addr="${CONF_BROKER_IP_ADDR:-$cur_ip_addr}"
1602
1603
  # Unless otherwise specified, the node is assumed to be the current
1604
  # host.
1605
  node_ip_addr="${CONF_NODE_IP_ADDR:-$cur_ip_addr}"
1606
1607
  node_v2_enable="${CONF_NODE_V2_ENABLE:-false}"
1608
1609
  # Unless otherwise specified, the named service, data store, and
1610
  # ActiveMQ service are assumed to be the current host if we are
1611
  # installing the component now or the broker host otherwise.
1612
  if named
1613
  then
1614
named_ip_addr="${CONF_NAMED_IP_ADDR:-$cur_ip_addr}"
1615
  else
1616
named_ip_addr="${CONF_NAMED_IP_ADDR:-$broker_ip_addr}"
1617
  fi
1618
1619
  # The nameservers to which named on the broker will forward requests.
1620
  # This should be a list of IP addresses with a semicolon after each.
1621
  nameservers="$(awk '/nameserver/ { printf "%s; ", $2 }' /etc/resolv.conf)"
1622
1623
  # Set $bind_key to the value of $CONF_BIND_KEY if the latter is
1624
  # non-empty.
1625
  [ "x$CONF_BIND_KEY" != x ] && bind_key="$CONF_BIND_KEY"
1626
1627
  # Generate a random salt for the broker authentication.
1628
  randomized=$(openssl rand -base64 20)
1629
  broker && broker_auth_salt="${CONF_BROKER_AUTH_SALT:-${randomized}}"
1630
1631
  # Set default passwords
1632
  #
1633
  # This is the admin password for the ActiveMQ admin console, which
1634
  # is not needed by OpenShift but might be useful in troubleshooting.
1635
  activemq && activemq_admin_password="${CONF_ACTIVEMQ_ADMIN_PASSWORD:-${randomized//[![:alnum:]]}}"
1636
1637
  # This is the user and password shared between broker and node for
1638
  # communicating over the mcollective topic channels in ActiveMQ.
1639
  # Must be the same on all broker and node hosts.
1640
  mcollective_user="${CONF_MCOLLECTIVE_USER:-mcollective}"
1641
  mcollective_password="${CONF_MCOLLECTIVE_PASSWORD:-marionette}"
1642
1643
  # These are the username and password of the administrative user
1644
  # that will be created in the MongoDB datastore. These credentials
1645
  # are not used by in this script or by OpenShift, but an
1646
  # administrative user must be added to MongoDB in order for it to
1647
  # enforce authentication.
1648
  mongodb_admin_user="${CONF_MONGODB_ADMIN_USER:-admin}"
1649
  mongodb_admin_password="${CONF_MONGODB_ADMIN_PASSWORD:-${CONF_MONGODB_PASSWORD:-mongopass}}"
1650
1651
  # These are the username and password of the normal user that will
1652
  # be created for the broker to connect to the MongoDB datastore. The
1653
  # broker application's MongoDB plugin is also configured with these
1654
  # values.
1655
  mongodb_broker_user="${CONF_MONGODB_BROKER_USER:-openshift}"
1656
  mongodb_broker_password="${CONF_MONGODB_BROKER_PASSWORD:-${CONF_MONGODB_PASSWORD:-mongopass}}"
1657
1658
  # This is the name of the database in MongoDB in which the broker
1659
  # will store data.
1660
  mongodb_name="${CONF_MONGODB_NAME:-openshift_broker}"
1661
1662
  # This user and password are entered in the /etc/openshift/htpasswd
1663
  # file as a demo/test user. You will likely want to remove it after
1664
  # installation (or just use a different auth method).
1665
  broker && openshift_user1="${CONF_OPENSHIFT_USER1:-demo}"
1666
  broker && openshift_password1="${CONF_OPENSHIFT_PASSWORD1:-changeme}"
1667
}
1668
1669
1670
########################################################################
1671
1672
# Note: parse_cmdline is only needed for kickstart and not if this %post
1673
# section is extracted and executed on a running system.
1674
parse_cmdline
1675
1676
set_defaults
1677
1678
echo_installation_intentions
1679
#configure_console_msg
1680
1681
is_false "$CONF_NO_NTP" && synchronize_clock
1682
is_false "$CONF_NO_SSH_KEYS" && install_ssh_keys
1683
1684
1685
# enable subscriptions / repositories according to requested method
1686
case "$CONF_INSTALL_METHOD" in
1687
  (yum)
1688
    configure_rhel_repo
1689
    if is_true "$CONF_OPTIONAL_REPO"
1690
    then
1691
configure_optional_repo
1692
    fi
1693
1694
if activemq || broker || datastore
1695
    then
1696
configure_broker_repo
1697
    fi
1698
node && configure_node_repo
1699
    node && configure_jbosseap_cartridge_repo
1700
    node && configure_jbosseap_repo
1701
    node && configure_jbossews_repo
1702
    broker && configure_client_tools_repo
1703
    ;;
1704
  (rhn)
1705
     echo "Register with RHN using an activation key"
1706
     rhnreg_ks --activationkey=${CONF_RHN_REG_ACTKEY} --profilename=${hostname}
1707
     yum-config-manager --setopt=rhel-x86_64-server-6.priority=2 rhel-x86_64-server-6 --save
1708
     yum-config-manager --setopt="rhel-x86_64-server-6.exclude=tomcat6*" rhel-x86_64-server-6 --save
1709
1710
     for channel in rhel-x86_64-server-6-osop-1-rhc rhel-x86_64-server-6-osop-1-infrastructure
1711
     do
1712
broker && rhn-channel --add --channel ${channel} --user ${CONF_RHN_REG_NAME} --password ${CONF_RHN_REG_PASS}
1713
       yum-config-manager --setopt=${channel}.priority=1 ${channel} --save
1714
     done
1715
for channel in rhel-x86_64-server-6-osop-1-node rhel-x86_64-server-6-osop-1-jbosseap
1716
     do
1717
node && rhn-channel --add --channel ${channel} --user ${CONF_RHN_REG_NAME} --password ${CONF_RHN_REG_PASS}
1718
       yum-config-manager --setopt=${channel}.priority=1 ${channel} --save
1719
     done
1720
for channel in jbappplatform-6-x86_64-server-6-rpm jb-ews-1-x86_64-server-6-rpm
1721
     do
1722
node && rhn-channel --add --channel ${channel} --user ${CONF_RHN_REG_NAME} --password ${CONF_RHN_REG_PASS}
1723
       yum-config-manager --setopt=${channel}.priority=3 ${channel} --save
1724
     done
1725
1726
if is_true "$CONF_OPTIONAL_REPO"
1727
     then
1728
rhn-channel --add --channel rhel-x86_64-server-optional-6 --user ${CONF_RHN_REG_NAME} --password ${CONF_RHN_REG_PASS}
1729
     fi
1730
     ;;
1731
  (sm)
1732
     #sm_reg_name / CONF_SM_REG_NAME
1733
     #sm_reg_pass / CONF_SM_REG_PASS
1734
     #sm_reg_pool / CONF_SM_REG_POOL
1735
     echo "sam"
1736
     ;;
1737
esac
1738
1739
# Install yum-plugin-priorities
1740
yum clean all; yum install -y yum-plugin-priorities
1741
1742
yum update -y
1743
1744
# Note: configure_named must run before configure_controller if we are
1745
# installing both named and broker on the same host.
1746
named && configure_named
1747
1748
update_resolv_conf
1749
1750
configure_network
1751
configure_hostname
1752
1753
datastore && configure_datastore
1754
1755
#broker && configure_qpid
1756
activemq && configure_activemq
1757
1758
#broker && configure_mcollective_for_qpid_on_broker
1759
broker && configure_mcollective_for_activemq_on_broker
1760
1761
#node && configure_mcollective_for_qpid_on_node
1762
node && configure_mcollective_for_activemq_on_node
1763
1764
broker && install_broker_pkgs
1765
broker && fix_passenger
1766
node && install_node_pkgs
1767
node && install_cartridges
1768
broker && install_rhc_pkg
1769
1770
broker && enable_services_on_broker
1771
node && enable_services_on_node
1772
1773
node && configure_pam_on_node
1774
node && configure_cgroups_on_node
1775
node && configure_quotas_on_node
1776
1777
broker && configure_selinux_policy_on_broker
1778
node && configure_selinux_policy_on_node
1779
1780
node && configure_sysctl_on_node
1781
node && configure_sshd_on_node
1782
1783
broker && configure_controller
1784
broker && configure_remote_user_auth_plugin
1785
broker && configure_access_keys_on_broker
1786
#broker && configure_mongo_auth_plugin
1787
broker && configure_messaging_plugin
1788
broker && configure_dns_plugin
1789
broker && configure_httpd_auth
1790
broker && configure_broker_ssl_cert
1791
1792
node && configure_port_proxy
1793
node && configure_gears
1794
node && configure_node
1795
node && configure_wildcard_ssl_cert_on_node
1796
node && update_openshift_facts_on_node
1797
1798
node && broker && fix_broker_routing
1799
1800
echo "Installation and configuration is complete;"
1801
echo "please reboot to start all services properly."