summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorChristian Pointner <equinox@spreadspace.org>2020-02-14 00:09:17 +0100
committerChristian Pointner <equinox@spreadspace.org>2020-02-14 00:09:21 +0100
commitf06e7c3a463220d050ed617d9ce8bfef7e5a0595 (patch)
treeef6619238ba0eb9a2e0d91df1c41e8d9c3d64d78
parentsshd: make ssh-allow-any-user check nicer (diff)
added ele-calypso
-rw-r--r--dan/ele-calypso.yml7
-rw-r--r--inventory/group_vars/elevate-festival/main.yml5
-rw-r--r--inventory/host_vars/ele-calypso.yml13
-rw-r--r--inventory/hosts.ini1
-rw-r--r--roles/installer/debian/preseed/templates/preseed_debian-buster-with-raid.cfg.j2148
5 files changed, 172 insertions, 2 deletions
diff --git a/dan/ele-calypso.yml b/dan/ele-calypso.yml
new file mode 100644
index 00000000..e3f9527b
--- /dev/null
+++ b/dan/ele-calypso.yml
@@ -0,0 +1,7 @@
+---
+- name: Basic Setup
+ hosts: ele-calypso
+ roles:
+ - role: base
+ - role: sshd
+ - role: zsh
diff --git a/inventory/group_vars/elevate-festival/main.yml b/inventory/group_vars/elevate-festival/main.yml
index 87da2237..418fc09d 100644
--- a/inventory/group_vars/elevate-festival/main.yml
+++ b/inventory/group_vars/elevate-festival/main.yml
@@ -13,6 +13,7 @@ network_zones:
ele-media: 200
ele-telesto: 201
ele-thetys: 202
+ ele-calypso: 203
ele-dione: 210
ele-helene: 211
# TODO: move this to mgmt zone
@@ -54,6 +55,7 @@ network_zones:
ele-sw-forum0: 10
ele-sw-forum1: 11
+ ele-br-forum1: 18
ele-br-forum0: 19
ele-ap-forum0: 110
ele-ap-forum1: 111
@@ -71,11 +73,10 @@ network_zones:
ele-ap-orpheum0: 140
ele-sw-uhrturm0: 50
- ele-br-uhrturm2: 57
ele-br-uhrturm1: 58
ele-br-uhrturm0: 59
- ele-br-grieskai0: 69
+ ele-br-tub0: 69
ele-dol-mixer: 200
ele-dol-translator: 201
diff --git a/inventory/host_vars/ele-calypso.yml b/inventory/host_vars/ele-calypso.yml
new file mode 100644
index 00000000..7ffdd701
--- /dev/null
+++ b/inventory/host_vars/ele-calypso.yml
@@ -0,0 +1,13 @@
+---
+preseed_template_name: "debian-buster-with-raid"
+
+install: {}
+
+network:
+ nameservers: "{{ network_zones.lan.dns }}"
+ domain: "{{ host_domain }}"
+ primary:
+ interface: eno1
+ ip: "{{ network_zones.lan.prefix | ipaddr(network_zones.lan.offsets[inventory_hostname]) | ipaddr('address') }}"
+ mask: "{{ network_zones.lan.prefix | ipaddr('netmask') }}"
+ gateway: "{{ network_zones.lan.gateway }}"
diff --git a/inventory/hosts.ini b/inventory/hosts.ini
index 26674ac9..804494f9 100644
--- a/inventory/hosts.ini
+++ b/inventory/hosts.ini
@@ -179,6 +179,7 @@ ele-media host_name=media
ele-router
ele-telesto host_name=telesto
ele-thetys host_name=thetys
+ele-calypso host_name=calypso
ele-dione host_name=dione
ele-helene host_name=helene
ele-uhrturm host_name=uhrturm
diff --git a/roles/installer/debian/preseed/templates/preseed_debian-buster-with-raid.cfg.j2 b/roles/installer/debian/preseed/templates/preseed_debian-buster-with-raid.cfg.j2
new file mode 100644
index 00000000..b4a7e846
--- /dev/null
+++ b/roles/installer/debian/preseed/templates/preseed_debian-buster-with-raid.cfg.j2
@@ -0,0 +1,148 @@
+#########################################################################
+# spreadspace preseed file for Debian buster based VMs
+#########################################################################
+
+d-i debian-installer/language string en
+d-i debian-installer/country string AT
+d-i debian-installer/locale string en_US.UTF-8
+d-i keyboard-configuration/xkb-keymap select us
+
+d-i hw-detect/load_firmware boolean false
+
+d-i netcfg/choose_interface select {{ install_interface | default(hostvars[hostname].network_cooked.primary.interface) }}
+{% if 'install_dhcp' in hostvars[hostname] and hostvars[hostname].install_dhcp %}
+d-i netcfg/disable_dhcp boolean false
+d-i netcfg/disable_autoconfig boolean false
+{% else %}
+d-i netcfg/disable_dhcp boolean true
+d-i netcfg/disable_autoconfig boolean true
+d-i netcfg/get_ipaddress string {{ hostvars[hostname].network_cooked.primary.ip }}
+d-i netcfg/get_netmask string {{ hostvars[hostname].network_cooked.primary.mask }}
+d-i netcfg/get_gateway string {{ hostvars[hostname].network_cooked.primary.gateway }}
+d-i netcfg/get_nameservers string {{ hostvars[hostname].network_cooked.nameservers | join(' ') }}
+d-i netcfg/confirm_static boolean true
+{% endif %}
+
+d-i netcfg/hostname string {{ hostvars[hostname].host_name }}
+d-i netcfg/get_hostname string {{ hostvars[hostname].host_name }}
+d-i netcfg/domain string {{ hostvars[hostname].network_cooked.domain }}
+d-i netcfg/get_domain string {{ hostvars[hostname].network_cooked.domain }}
+d-i netcfg/wireless_wep string
+
+
+d-i mirror/country string manual
+d-i mirror/http/hostname string {{ apt_repo_providers[(hostvars[hostname].apt_repo_provider | default('default'))].debian }}
+d-i mirror/http/directory string /debian
+d-i mirror/http/proxy string
+
+
+d-i passwd/make-user boolean false
+d-i passwd/root-password password this-very-very-secure-password-will-be-removed-by-latecommand
+d-i passwd/root-password-again password this-very-very-secure-password-will-be-removed-by-latecommand
+
+
+d-i clock-setup/utc boolean true
+d-i time/zone string Europe/Vienna
+d-i clock-setup/ntp boolean false
+
+d-i partman-auto/disk string /dev/sda /dev/sdb
+
+d-i partman-auto/method string raid
+d-i partman-auto/purge_lvm_from_device boolean true
+d-i partman-auto-lvm/new_vg_name string {{ hostvars[hostname].host_name }}
+d-i partman-auto-lvm/guided_size string max
+
+d-i partman-lvm/device_remove_lvm boolean true
+d-i partman-md/device_remove_md boolean true
+d-i partman-md/confirm boolean true
+d-i partman-md/confirm_nooverwrite boolean true
+d-i partman-lvm/confirm boolean true
+d-i partman-lvm/confirm_nooverwrite boolean true
+
+d-i partman/choose_label string dos
+d-i partman/default_label string dos
+d-i partman-auto/choose_recipe select boot-root
+d-i partman-auto/expert_recipe string \
+ boot-root :: \
+ 256 512 256 raid \
+ $lvmignore{ } $primary{ } method{ raid } \
+ . \
+ 1000 10000 -1 raid \
+ $lvmignore{ } $primary{ } method{ raid } \
+ . \
+ 15360 10000 20480 ext4 \
+ $defaultignore{ } $lvmok{ } \
+ in_vg{ {{ hostvars[hostname].host_name }} } \
+ method{ format } format{ } \
+ use_filesystem{ } filesystem{ ext4 } \
+ mountpoint{ / } \
+ . \
+ 768 10000 768 ext4 \
+ $defaultignore{ } $lvmok{ } \
+ in_vg{ {{ hostvars[hostname].host_name }} } \
+ method{ format } format{ } \
+ use_filesystem{ } filesystem{ ext4 } \
+ mountpoint{ /var/log } \
+ options/nodev{ nodev } options/noatime{ noatime } \
+ options/noexec{ noexec } \
+ . \
+ 20480 10000 20480 ext4 \
+ $defaultignore{ } $lvmok{ } \
+ in_vg{ {{ hostvars[hostname].host_name }} } \
+ method{ format } format{ } \
+ use_filesystem{ } filesystem{ ext4 } \
+ mountpoint{ /home } \
+ . \
+ 16 20000 -1 ext4 \
+ $defaultignore{ } $lvmok{ } \
+ in_vg{ {{ hostvars[hostname].host_name }} } \
+ lv_name{ dummy } \
+ .
+
+d-i partman-auto-raid/recipe string \
+ 1 2 0 ext4 /boot \
+ /dev/sda1#/dev/sdb1 \
+ . \
+ 1 2 0 lvm - \
+ /dev/sda2#/dev/sdb2 \
+ .
+
+d-i partman-basicfilesystems/no_swap true
+d-i partman-partitioning/confirm_write_new_label boolean true
+d-i partman/choose_partition select finish
+d-i partman/confirm boolean true
+d-i partman/confirm_nooverwrite boolean true
+
+
+d-i base-installer/install-recommends boolean false
+d-i apt-setup/security_host string {{ apt_repo_providers[(hostvars[hostname].apt_repo_provider | default('default'))].debian }}
+
+tasksel tasksel/first multiselect
+d-i pkgsel/include string openssh-server python python-apt
+d-i pkgsel/upgrade select safe-upgrade
+popularity-contest popularity-contest/participate boolean false
+
+d-i grub-installer/choose_bootdev string /dev/sda /dev/sdb
+d-i grub-installer/bootdev string /dev/sda /dev/sdb
+d-i grub-installer/only_debian boolean true
+d-i grub-installer/with_other_os boolean false
+
+d-i finish-install/reboot_in_progress note
+
+
+d-i preseed/late_command string \
+ lvremove -f {{ hostvars[hostname].host_name }}/dummy; \
+ in-target bash -c "apt-get update -q && apt-get full-upgrade -y -q"; \
+ in-target bash -c "sed -e 's/^allow-hotplug/auto/' -i /etc/network/interfaces"; \
+{% if preseed_force_net_ifnames_policy is defined %}
+ mkdir -p /target/etc/systemd/network; \
+ in-target bash -c "echo '[Link]' > /etc/systemd/network/90-namepolicy.link"; \
+ in-target bash -c "echo 'NamePolicy={{ preseed_force_net_ifnames_policy }}' >> /etc/systemd/network/90-namepolicy.link"; \
+ in-target bash -c "update-initramfs -u"; \
+{% endif %}
+ in-target bash -c "passwd -d root && passwd -l root"; \
+{% if hostvars[hostname].ansible_port is defined %}
+ in-target bash -c "sed -e 's/^\(\s*#*\s*Port.*\)/Port {{ hostvars[hostname].ansible_port }}/' -i /etc/ssh/sshd_config"; \
+{% endif %}
+ mkdir -p -m 0700 /target/root/.ssh; \
+ cp /authorized_keys /target/root/.ssh/