ungleich-tools/opennebula-images/arch-build-opennebula-image.sh

170 lines
5.2 KiB
Bash
Executable File

#!/bin/sh
# This script generates Debian images for OpenNebula.
#
# Test image locally (without network) with:
# qemu-system-x86_64 -enable-kvm -m 1G -drive file=$IMAGE,format=qcow2
set -e
set -x
# XXX: Handle command-line arguments?
IMAGE_PATH=arch-$(date --iso-8601).img.qcow2
IMAGE_SIZE=10G
NBD_DEVICE=/dev/nbd0
ONE_CONTEXT_VERSION=6.8.1
ONE_CONTEXT_SOURCE_ARCHIVE="https://github.com/OpenNebula/one-apps/archive/refs/tags/v${ONE_CONTEXT_VERSION:?}.tar.gz"
cleanup() {
# The order here is important.
umount /mnt/dev/pts 2>/dev/null || true
umount /mnt/dev/shm 2>/dev/null || true
umount /mnt/dev 2>/dev/null || true
umount /mnt/proc 2>/dev/null || true
umount /mnt/run 2>/dev/null || true
umount /mnt/sys 2>/dev/null || true
umount /mnt/boot 2>/dev/null || true
umount /mnt 2>/dev/null || true
qemu-nbd --disconnect "$NBD_DEVICE" || true
}
run_root() {
chroot /mnt /usr/bin/env \
PATH=/sbin:/usr/sbin:/bin:/usr/bin \
sh -c "$*"
}
if [ "$(whoami)" != 'root' ]; then
echo "This script must be run as root." >&2
exit 1
fi
if [ "$(lsb_release --short --id)" != "Arch" ]; then
echo "WARNING: this script has been designed to run on Arch Linux." >&2
echo "WARNING: Not running Arch. Giving you 5 seconds to abort." >&2
sleep 5
fi
# Create base QCOW2 image.
qemu-img create -f qcow2 "$IMAGE_PATH" "$IMAGE_SIZE"
modprobe nbd max_part=16
qemu-nbd --connect="$NBD_DEVICE" "$IMAGE_PATH"
# Wait for qemu-nbd to settle.
sleep 1
# Don't forget to cleanup, even if the script crash.
trap cleanup EXIT
# Create partition table, format partitions.
sfdisk --no-reread "$NBD_DEVICE" <<EOF
1M,500M,L,*
,,L
EOF
mkfs.ext4 "${NBD_DEVICE}p1"
mkfs.ext4 "${NBD_DEVICE}p2"
# Mount partitions, install base OS.
mount "${NBD_DEVICE}p2" /mnt
mkdir /mnt/boot
mount "${NBD_DEVICE}p1" /mnt/boot
# Install base system.
pacstrap /mnt base base-devel openssh
mount --bind /dev /mnt/dev
mount --bind /dev/pts /mnt/dev/pts
mount --bind /dev/shm /mnt/dev/shm
mount --bind /proc /mnt/proc
mount --bind /run /mnt/run
mount --bind /sys /mnt/sys
# Required to resolve package mirror in chroot.
cp /etc/resolv.conf /mnt/etc/resolv.conf
# Initialize /etc/hosts.
cat > /mnt/etc/hosts << EOF
127.0.0.1 localhost localhost.localdomain localhost4 localhost4.localdomain4
::1 localhost localhost.localdomain localhost6 localhost6.localdomain6
EOF
# Configure package sources and update package index.
cat > /mnt/etc/pacman.d/mirrorlist << EOF
##
## Arch Linux repository mirrorlist
## Generated on 2024-03-07
##
## Switzerland
Server = http://pkg.adfinis.com/archlinux/\$repo/os/\$arch
Server = https://pkg.adfinis.com/archlinux/\$repo/os/\$arch
Server = http://mirror.init7.net/archlinux/\$repo/os/\$arch
Server = https://mirror.init7.net/archlinux/\$repo/os/\$arch
Server = http://mirror.metanet.ch/archlinux/\$repo/os/\$arch
Server = https://mirror.metanet.ch/archlinux/\$repo/os/\$arch
Server = http://mirror.puzzle.ch/archlinux/\$repo/os/\$arch
Server = https://mirror.puzzle.ch/archlinux/\$repo/os/\$arch
Server = https://mirror.ungleich.ch/mirror/packages/archlinux/\$repo/os/\$arch
EOF
run_root pacman -Syu --noconfirm
# Initalize base services.
run_root systemd-machine-id-setup
# Generate fstab file.
boot_uuid=$(blkid --match-tag UUID --output value "${NBD_DEVICE}p1")
root_uuid=$(blkid --match-tag UUID --output value "${NBD_DEVICE}p2")
cat >>/mnt/etc/fstab <<EOF
UUID=${boot_uuid:?} /boot ext4 rw,relatime,data=ordered 0 2
UUID=${root_uuid:?} / ext4 rw,relatime,data=ordered 0 1
EOF
# Guest networking is to be handled by the one-context package.
# See https://github.com/OpenNebula/one-apps for details.
run_root pacman -Sy curl tar rsync --noconfirm
run_root curl -L "$ONE_CONTEXT_SOURCE_ARCHIVE" -o one-context.tar.gz
run_root tar xf one-context.tar.gz
run_root rsync -ravh "one-apps-${ONE_CONTEXT_VERSION:?}/context-linux/src/"* /
run_root rm -r "one-apps-${ONE_CONTEXT_VERSION:?}"
run_root cp -r /usr/lib/systemd/system/one-context.service##arch.one /usr/lib/systemd/system/one-context.service
run_root systemctl enable one-context.service
run_root ln -sf /usr/share/zoneinfo/UTC /etc/localtime
run_root systemctl enable systemd-timesyncd.service
# Install kernel and generate initramfs.
run_root ln -s /usr/lib/modules /lib/modules
run_root pacman -Sy mkinitcpio linux linux-firmware --noconfirm
sed -i '/MODULES=/c\MODULES=(virtio virtio_blk virtio_pci virtio_net)' /mnt/etc/mkinitcpio.conf
run_root mkinitcpio -p linux
# Install and configure bootloader.
run_root pacman -Sy grub --noconfirm
run_root grub-install --target=i386-pc "${NBD_DEVICE}"
run_root grub-mkconfig -o /boot/grub/grub.cfg
# Install and configure a SSH daemon.
run_root pacman -Sy openssh netctl --noconfirm
run_root systemctl enable sshd
# Install haveged due to lack of entropy in ONE environment.
run_root pacman -Sy haveged --noconfirm
run_root systemctl enable haveged.service
# Make sure core services are enabled.
run_root systemctl enable systemd-networkd
run_root systemctl enable systemd-resolved
run_root systemctl enable systemd-timesyncd
# Reset systemd's environment.
run_root rm -f /etc/machine-id
run_root touch /etc/machine-id
rm -f /var/lib/systemd/random-seed
echo "arch" > /mnt/etc/hostname
# Make sure everything is written to disk before exiting.
sync