You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
178 lines
5.1 KiB
178 lines
5.1 KiB
#!/bin/sh |
|
|
|
# This script generates Debian images for Uncloud. |
|
# |
|
# Test image locally (without network) with: |
|
# qemu-system-x86_64 -enable-kvm -m 1G -drive file=$IMAGE,format=qcow2 |
|
|
|
set -e |
|
set -x |
|
|
|
# XXX: Handle command-line arguments? |
|
RELEASE=buster # 10 |
|
ARCH=amd64 |
|
IMAGE_PATH=debian-uncloud-$RELEASE-$(date --iso-8601).img.qcow2 |
|
IMAGE_SIZE=10G |
|
NBD_DEVICE=/dev/nbd0 |
|
APT_MIRROR=http://deb.debian.org/debian |
|
|
|
cleanup() { |
|
# The order here is important. |
|
umount /mnt/dev/pts 2>/dev/null || true |
|
umount /mnt/dev/shm 2>/dev/null || true |
|
umount /mnt/dev 2>/dev/null || true |
|
umount /mnt/proc 2>/dev/null || true |
|
umount /mnt/run 2>/dev/null || true |
|
umount /mnt/sys 2>/dev/null || true |
|
umount /mnt/boot 2>/dev/null || true |
|
umount /mnt 2>/dev/null || true |
|
qemu-nbd --disconnect "$NBD_DEVICE" || true |
|
} |
|
|
|
run_root() { |
|
chroot /mnt /usr/bin/env \ |
|
PATH=/sbin:/usr/sbin:/bin:/usr/bin \ |
|
sh -c "$*" |
|
} |
|
|
|
if [ "$(whoami)" != 'root' ]; then |
|
echo "This script must be run as root." >&2 |
|
exit 1 |
|
fi |
|
|
|
if [ "$(lsb_release --short --id)" != "Debian" ]; then |
|
echo "WARNING: this script has been designed to run on a Debian system." >&2 |
|
echo "WARNING: Not running Debian. Giving you 5 seconds to abort." >&2 |
|
sleep 5 |
|
fi |
|
|
|
# Create base QCOW2 image. |
|
qemu-img create -f qcow2 "$IMAGE_PATH" "$IMAGE_SIZE" |
|
modprobe nbd max_part=16 |
|
qemu-nbd --connect="$NBD_DEVICE" "$IMAGE_PATH" |
|
|
|
# Wait for qemu-nbd to settle. |
|
sleep 1 |
|
|
|
# Don't forget to cleanup, even if the script crash. |
|
trap cleanup EXIT |
|
|
|
# Create partition table, format partitions. |
|
sfdisk --no-reread "$NBD_DEVICE" <<EOF |
|
1M,500M,L,* |
|
,,L |
|
EOF |
|
|
|
mkfs.ext4 "${NBD_DEVICE}p1" |
|
mkfs.ext4 "${NBD_DEVICE}p2" |
|
|
|
# Mount partitions, install base OS. |
|
|
|
mount "${NBD_DEVICE}p2" /mnt |
|
mkdir /mnt/boot |
|
mount "${NBD_DEVICE}p1" /mnt/boot |
|
|
|
debootstrap \ |
|
--arch=$ARCH $RELEASE \ |
|
/mnt $APT_MIRROR |
|
|
|
mount --bind /dev /mnt/dev |
|
mount --bind /dev/pts /mnt/dev/pts |
|
mount --bind /dev/shm /mnt/dev/shm |
|
mount --bind /proc /mnt/proc |
|
mount --bind /run /mnt/run |
|
mount --bind /sys /mnt/sys |
|
|
|
# Required to resolve package mirror in chroot. |
|
cp /etc/resolv.conf /mnt/etc/resolv.conf |
|
|
|
# Initialize /etc/hosts. |
|
cat > /mnt/etc/hosts << EOF |
|
127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4 |
|
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6 |
|
|
|
EOF |
|
|
|
# Accept router advertisements for SLAAC. |
|
run_root sysctl -w net.ipv6.conf.all.accept_ra=1 |
|
|
|
# Configure package sources and update package index. |
|
cat >/mnt/etc/apt/sources.list <<EOF |
|
deb $APT_MIRROR $RELEASE main |
|
deb-src $APT_MIRROR $RELEASE main |
|
deb $APT_MIRROR $RELEASE-updates main |
|
deb-src $APT_MIRROR $RELEASE-updates main |
|
|
|
deb http://security.debian.org/debian-security $RELEASE/updates main |
|
deb-src http://security.debian.org/debian-security $RELEASE/updates main |
|
EOF |
|
run_root apt-get update |
|
|
|
# Initialize base services. |
|
run_root systemd-machine-id-setup |
|
|
|
run_root ln -sf /usr/share/zoneinfo/UTC /etc/localtime |
|
run_root systemctl enable systemd-timesyncd.service |
|
|
|
# Generate fstab file. |
|
boot_uuid=$(blkid --match-tag UUID --output value "${NBD_DEVICE}p1") |
|
root_uuid=$(blkid --match-tag UUID --output value "${NBD_DEVICE}p2") |
|
cat >>/mnt/etc/fstab <<EOF |
|
UUID=$boot_uuid /boot ext4 rw,relatime,data=ordered 0 2 |
|
UUID=$root_uuid / ext4 rw,relatime,data=ordered 0 1 |
|
EOF |
|
|
|
# Install kernel and bootloader. Do not autoconfigure grub. |
|
run_root echo "grub-pc grub-pc/install_devices_empty boolean true" | debconf-set-selections |
|
run_root DEBIAN_FRONTEND=noninteractive apt-get -y install locales linux-base linux-image-$ARCH grub-pc |
|
|
|
# Configure grub. |
|
run_root grub-install --target=i386-pc "${NBD_DEVICE}" |
|
sed -i "s/GRUB_CMDLINE_LINUX_DEFAULT=\"quiet\"/GRUB_CMDLINE_LINUX_DEFAULT=\"\"/" /mnt/etc/default/grub |
|
sed -i "s/GRUB_CMDLINE_LINUX=\"\"/GRUB_CMDLINE_LINUX=\"root=UUID=$root_uuid\"/" /mnt/etc/default/grub |
|
run_root grub-mkconfig -o /boot/grub/grub.cfg |
|
|
|
# Install en configure SSH daemon. The service is enabled by default. |
|
run_root apt-get -y install openssh-server |
|
|
|
# Use haveged as entropy source. |
|
run_root apt-get -y install haveged |
|
|
|
# Manually install uncloud-init. |
|
uncloud_init_dir=/tmp/uncloud-init |
|
run_root apt-get install -y git curl grep make |
|
|
|
mkdir -p "$uncloud_init_dir" |
|
run_root git clone https://code.ungleich.ch/uncloud/uncloud-init.git "$uncloud_init_dir" |
|
run_root make -C "$uncloud_init_dir" install |
|
run_root rm -r "$uncloud_init_dir" |
|
|
|
run_root systemctl enable uncloud-init |
|
|
|
# Reset systemd's environment. |
|
run_root rm -f /etc/machine-id |
|
run_root touch /etc/machine-id |
|
rm -f /var/lib/systemd/random-seed |
|
|
|
# Manually install uncloud-init. |
|
uncloud_init_dir=/tmp/uncloud-init |
|
run_root apt-get install -y git curl grep make |
|
|
|
mkdir -p "$uncloud_init_dir" |
|
run_root git clone https://code.ungleich.ch/uncloud/uncloud-init.git "$uncloud_init_dir" |
|
run_root make -C "$uncloud_init_dir" install |
|
run_root rm -r "$uncloud_init_dir" |
|
|
|
run_root systemctl enable uncloud-init |
|
|
|
# Install RDNSSD for DNS discovery from router advertisement. The service is enabled by default. |
|
run_root apt-get install -y rdnssd |
|
|
|
# Remove temporary files and reclaim freed disk space. |
|
run_root apt-get clean |
|
|
|
# Remove resolv.conf, as it is handled by uncloud-init. |
|
run_root rm /etc/resolv.conf |
|
|
|
# Make sure everything is written to disk before exiting. |
|
sync
|
|
|