diff --git a/debian-devuan-netboot.sh b/debian-devuan-netboot.sh index eb0d381..2858ae4 100755 --- a/debian-devuan-netboot.sh +++ b/debian-devuan-netboot.sh @@ -43,7 +43,7 @@ echo '* * * * * root ip -o -6 addr show | grep -E -v " lo |one" > /etc/issue' > mkdir -p ${chroot_dir}/root/.ssh -for key in balazs dominique jinguk nico; do +for key in fnux balazs dominique jinguk nico; do curl -s ${keyurl}/${key}.pub >> ${chroot_dir}/root/.ssh/authorized_keys done diff --git a/mikrotik-setup.sh b/mikrotik-setup.sh old mode 100644 new mode 100755 diff --git a/mikrotik-update.sh b/mikrotik-update.sh index 934ea47..5d1c281 100755 --- a/mikrotik-update.sh +++ b/mikrotik-update.sh @@ -1,4 +1,4 @@ -#!/bin +#!/bin/sh # Nico Schottelius, 2019-12-02 # Update mikrotik routers to the latest package diff --git a/monit-ceph-create-start b/monit-ceph-create-start index 9b9cb58..a44efa0 100755 --- a/monit-ceph-create-start +++ b/monit-ceph-create-start @@ -20,15 +20,28 @@ if echo $to_monitor | grep ^osd; then depends="${depends}, ${to_monitor}-whoami" osd="yes" osdid=$(echo $to_monitor | cut -d. -f2) -fi + cat > "$conf" < "$conf" < "$conf" <> "$conf" </dev/null || true + umount /mnt/dev/shm 2>/dev/null || true + umount /mnt/dev 2>/dev/null || true + umount /mnt/proc 2>/dev/null || true + umount /mnt/run 2>/dev/null || true + umount /mnt/sys 2>/dev/null || true + umount /mnt/boot 2>/dev/null || true + umount /mnt 2>/dev/null || true + losetup -d "$LOOPBACK_DEVICE" +} + +run_root() { + chroot /mnt /usr/bin/env \ + PATH=/sbin:/usr/sbin:/bin:/usr/bin \ + sh -c "$*" +} + +if [ "$(whoami)" != 'root' ]; then + echo "This script must be run as root." >&2 + exit 1 +fi + +if [ ! -f '/etc/centos-release' ]; then + echo "WARNING: this script has been designed to run on a CentOS system." >&2 + echo "WARNING: Not running CentOS. Giving you 5 seconds to abort." >&2 + sleep 5 +fi + +# Install requirements +yum install -y qemu cryptsetup dnf + +# Create base RAW image (no LOOPBACK support in RHEL/CentOS). +qemu-img create -f raw "$IMAGE_PATH" "$IMAGE_SIZE" +losetup "$LOOPBACK_DEVICE" "$IMAGE_PATH" + +# Don't forget to cleanup, even if the script crash. +trap cleanup EXIT + +# Create partition table, format partitions. +parted --script "$LOOPBACK_DEVICE" \ + mklabel msdos \ + mkpart primary ext4 1M 500M \ + mkpart primary ext4 500M 100% + +partprobe "$LOOPBACK_DEVICE" + +mkfs.ext4 "${LOOPBACK_DEVICE}p1" +echo -n "$LUKS_PASSPHRASE" | cryptsetup luksFormat -v -d - "${LOOPBACK_DEVICE}p2" +echo -n "$LUKS_PASSPHRASE" | cryptsetup open -v -d - "${LOOPBACK_DEVICE}p2" "$LUKS_DEVICE_NAME" +mkfs.ext4 "$LUKS_DEVICE" + +# Mount partitions, install base OS. +mount "${LUKS_DEVICE}" /mnt +mkdir /mnt/boot +mount "${LOOPBACK_DEVICE}p1" /mnt/boot + +# Add --setopt=reposdir=rpm-repositories if you do not run on CentOS 7. +dnf -y \ + --releasever=$RELEASE \ + --installroot=/mnt \ + --disablerepo='*' \ + --enablerepo=base \ + --enablerepo=extras \ + --setopt=install_weak_deps=False install \ + bash basesystem systemd dnf centos-release cryptsetup dnf + +mount --bind /dev /mnt/dev +mount --bind /dev/pts /mnt/dev/pts +mount --bind /dev/shm /mnt/dev/shm +mount --bind /proc /mnt/proc +mount --bind /run /mnt/run +mount --bind /sys /mnt/sys + +# Guest networking is to be handled by the one-context package. +# See https://github.com/OpenNebula/addon-context-linux for details. +# Note: as of writing, one-context does not support NetworkManager or +# systemd-networkd. + +# Required to resolve package mirror in chroot. +cp /etc/resolv.conf /mnt/etc/resolv.conf + +# Initialize /etc/hosts. +cat > /mnt/etc/hosts << EOF +127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4 +::1 localhost localhost.localdomain localhost6 localhost6.localdomain6 +EOF + +# Install one-context RPM and hope things works as expected. +curl -L "$ONE_CONTEXT_RPM_URL" > "/mnt$ONE_CONTEXT_RPM_PATH" +run_root dnf -y install "$ONE_CONTEXT_RPM_PATH" +run_root rm "$ONE_CONTEXT_RPM_PATH" +for script in $DISABLED_ONE_SCRIPTS; do + run_root rm "/etc/one-context.d/$script" +done + +# Install resize2fs, which is required to resize the root file-system. +run_root dnf -y install e2fsprogs + +# Initalize base services. +run_root systemd-machine-id-setup +run_root ln -sf /usr/share/zoneinfo/UTC /etc/localtime + +# Install and configure NTP client. +run_root dnf install -y chrony +run_root systemctl enable chronyd.service + +# Install kernel and bootloader. +# Note: linux-firmware is not required our environment and takes almost 200M +# uncompressed but is a direct dependency of kernel-core... +run_root dnf -y install kernel grub2 + +# Add support for virtio block devices at boot time, configure bootloader. +cat > /mnt/etc/dracut.conf.d/virtio-blk.conf <> /mnt/etc/crypttab + +run_root dracut -v --force --kver $kernel_version +run_root grub2-install --target=i386-pc "${LOOPBACK_DEVICE}" +run_root grub2-mkconfig -o /boot/grub2/grub.cfg + +# Install en configure SSH daemon. +run_root dnf -y install openssh-server +run_root systemctl enable sshd + +# Generate fstab file. +boot_uuid=$(blkid -o value "${LOOPBACK_DEVICE}p1" | head -n 1) +root_uuid=$(blkid -o value "$LUKS_DEVICE" | head -n 1) +cat >>/mnt/etc/fstab < /mnt/etc/resolv.conf +cp /etc/resolv.conf /mnt/etc/resolv.conf tzsetup -s -C /mnt UTC cat >>/mnt/etc/ssh/sshd_config </dev/null || true -sudo ip addr add 192.168.61.2/24 dev "$dev" +if [ "$dev" ]; then + sudo ip addr del 192.168.61.2/24 dev "$dev" 2>/dev/null || true + sudo ip addr add 192.168.61.2/24 dev "$dev" +fi # don't care about other/old known_host entries ssh-keygen -R ${viirb_ip} diff --git a/viirb-2-configure-fully-after-upgrade.sh b/viirb-2-configure-fully-after-upgrade.sh index f92a13c..16f704e 100755 --- a/viirb-2-configure-fully-after-upgrade.sh +++ b/viirb-2-configure-fully-after-upgrade.sh @@ -215,5 +215,5 @@ uci commit reboot EOF -echo "Wireguard public key: ${public_key}" +echo "Wireguard public key and id: ${id} ${public_key}" echo ${public_key} > ${viirb_hostname}.public_key