192 lines
5.3 KiB
Bash
Executable file
192 lines
5.3 KiB
Bash
Executable file
#!/bin/sh
|
|
|
|
# This script generates Fedora images for Uncloud.
|
|
|
|
# Depends on the following packages (as of Fedora 31):
|
|
# qemu-img util-linux coreutils dnf curl e2fsprogs
|
|
|
|
# Run locally (without network) with:
|
|
# qemu-system-x86_64 -enable-kvm -m 1G -drive file=$IMAGE,format=qcow2
|
|
|
|
set -e
|
|
set -x
|
|
|
|
# XXX: Handle command-line arguments?
|
|
RELEASE=31
|
|
ARCH=x86_64
|
|
IMAGE_PATH=fedora-uncloud-$RELEASE-$(date +%+F).img.qcow2
|
|
IMAGE_SIZE=10G
|
|
NBD_DEVICE=/dev/nbd5
|
|
|
|
cleanup() {
|
|
# The order here is important.
|
|
umount /mnt/dev/pts 2>/dev/null || true
|
|
umount /mnt/dev/shm 2>/dev/null || true
|
|
umount /mnt/dev 2>/dev/null || true
|
|
umount /mnt/proc 2>/dev/null || true
|
|
umount /mnt/run 2>/dev/null || true
|
|
umount /mnt/sys 2>/dev/null || true
|
|
umount /mnt/boot 2>/dev/null || true
|
|
umount /mnt 2>/dev/null || true
|
|
qemu-nbd --disconnect "$NBD_DEVICE" || true
|
|
}
|
|
|
|
run_root() {
|
|
chroot /mnt /usr/bin/env \
|
|
PATH=/sbin:/usr/sbin:/bin:/usr/bin \
|
|
sh -c "$*"
|
|
}
|
|
|
|
if [ "$(whoami)" != 'root' ]; then
|
|
echo "This script must be run as root." >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [ ! -f '/etc/fedora-release' ]; then
|
|
echo "WARNING: this script has been designed to run on a Fedora system." >&2
|
|
echo "WARNING: Not running Fedora. Giving you 5 seconds to abort." >&2
|
|
sleep 5
|
|
fi
|
|
|
|
# Create base QCOW2 image.
|
|
qemu-img create -f qcow2 "$IMAGE_PATH" "$IMAGE_SIZE"
|
|
modprobe nbd max_part=16
|
|
qemu-nbd --connect="$NBD_DEVICE" "$IMAGE_PATH"
|
|
|
|
# Don't forget to cleanup, even if the script crash.
|
|
trap cleanup EXIT
|
|
|
|
# Create partition table, format partitions.
|
|
sfdisk --no-reread "$NBD_DEVICE" <<EOF
|
|
1M,500M,L,*
|
|
,,L
|
|
EOF
|
|
|
|
mkfs.ext4 "${NBD_DEVICE}p1"
|
|
mkfs.ext4 "${NBD_DEVICE}p2"
|
|
|
|
# Mount partitions, install base OS.
|
|
# Note: we could use the @Core package group but it pulls quite a lot of
|
|
# 'unwanted' dependencies. Run `dnf group info Core` for details.
|
|
|
|
mount "${NBD_DEVICE}p2" /mnt
|
|
mkdir /mnt/boot
|
|
mount "${NBD_DEVICE}p1" /mnt/boot
|
|
|
|
dnf -y \
|
|
--releasever=$RELEASE \
|
|
--installroot=/mnt \
|
|
--disablerepo='*' \
|
|
--enablerepo=fedora \
|
|
--enablerepo=updates install \
|
|
--setopt=install_weak_deps=False \
|
|
basesystem systemd systemd-udev passwd dnf fedora-release procps-ng \
|
|
iproute iputils vim-minimal
|
|
|
|
mount --bind /dev /mnt/dev
|
|
mount --bind /dev/pts /mnt/dev/pts
|
|
mount --bind /dev/shm /mnt/dev/shm
|
|
mount --bind /proc /mnt/proc
|
|
mount --bind /run /mnt/run
|
|
mount --bind /sys /mnt/sys
|
|
|
|
# Required to resolve package mirror in chroot.
|
|
cp /etc/resolv.conf /mnt/etc/resolv.conf
|
|
|
|
# Initialize /etc/hosts.
|
|
cat > /mnt/etc/hosts << EOF
|
|
127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
|
|
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
|
|
|
|
EOF
|
|
|
|
# Use haveged as entropy source.
|
|
run_root dnf -y install haveged
|
|
run_root systemctl enable haveged
|
|
|
|
# Accept router advertisements for SLAAC.
|
|
run_root sysctl -w net.ipv6.conf.all.accept_ra=1
|
|
|
|
# Install RDNSSD for DNS discovery from router advertisement. The service is enabled by default.
|
|
run_root dnf -y install ndisc6
|
|
cat > /mnt/etc/systemd/system/rdnssd.service << EOF
|
|
[Unit]
|
|
Description=IPv6 Recursive DNS Server discovery Daemon
|
|
Documentation=man:rdnssd(8)
|
|
Before=network.target
|
|
Requires=network.target
|
|
|
|
[Service]
|
|
Type=forking
|
|
ExecStartPre=/bin/mkdir -p /var/run/rdnssd
|
|
ExecStartPre=/bin/chown nobody /var/run/rdnssd
|
|
ExecStartPre=/bin/chmod 0755 /var/run/rdnssd
|
|
ExecStart=/sbin/rdnssd -p /var/run/rdnssd.pid -H /etc/rdnssd/merge-hook
|
|
PIDFile=/var/run/rdnssd.pid
|
|
Restart=on-failure
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|
|
EOF
|
|
run_root systemctl enable rdnssd
|
|
|
|
# Initialize base services.
|
|
run_root systemd-machine-id-setup
|
|
|
|
run_root ln -sf /usr/share/zoneinfo/UTC /etc/localtime
|
|
run_root systemctl enable systemd-timesyncd.service
|
|
|
|
# Install kernel and bootloader.
|
|
# Note: linux-firmware is not required our environment and takes almost 200M
|
|
# uncompressed but is a direct dependency of kernel-core...
|
|
run_root dnf -y install kernel grub2
|
|
|
|
# XXX: do we need virtio support for uncloud?
|
|
# Add support for virtio block devices at boot time.
|
|
cat > /mnt/etc/dracut.conf.d/virtio-blk.conf <<EOF
|
|
add_drivers="virtio-blk"
|
|
EOF
|
|
kernel_version=$(ls /mnt/boot | grep "vmlinuz.*.$ARCH" | cut -d- -f2-)
|
|
run_root dracut --force --kver $kernel_version
|
|
|
|
# Configure grub2.
|
|
run_root grub2-install --target=i386-pc "${NBD_DEVICE}"
|
|
run_root grub2-mkconfig -o /boot/grub2/grub.cfg
|
|
|
|
# Install en configure SSH daemon.
|
|
run_root dnf -y install openssh-server
|
|
run_root systemctl enable sshd
|
|
|
|
# Generate fstab file.
|
|
boot_uuid=$(blkid --match-tag UUID --output value "${NBD_DEVICE}p1")
|
|
root_uuid=$(blkid --match-tag UUID --output value "${NBD_DEVICE}p2")
|
|
cat >>/mnt/etc/fstab <<EOF
|
|
UUID=$boot_uuid /boot ext4 rw,relatime,data=ordered 0 2
|
|
UUID=$root_uuid / ext4 rw,relatime,data=ordered 0 1
|
|
EOF
|
|
|
|
# Reset systemd's environment.
|
|
run_root rm -f /etc/machine-id
|
|
run_root touch /etc/machine-id
|
|
rm -f /var/lib/systemd/random-seed
|
|
|
|
# Remove temporary files and reclaim freed disk space.
|
|
# Note: build logs could be removed as well.
|
|
run_root dnf clean all
|
|
|
|
# Manually install uncloud-init.
|
|
uncloud_init_dir=/tmp/uncloud-init
|
|
run_root dnf install -y git curl grep make
|
|
|
|
mkdir -p "$uncloud_init_dir"
|
|
run_root git clone https://code.ungleich.ch/uncloud/uncloud-init.git "$uncloud_init_dir"
|
|
run_root make -C "$uncloud_init_dir" install
|
|
run_root rm -r "$uncloud_init_dir"
|
|
|
|
run_root systemctl enable uncloud-init
|
|
|
|
# Remove resolv.conf: will be handled by uncloud-init.
|
|
run_root rm /etc/resolv.conf
|
|
|
|
# Make sure everything is written to disk before exiting.
|
|
sync
|