From 76bf053cf54de6cf83e09d4c1c23e59298d41c90 Mon Sep 17 00:00:00 2001 From: Christian Pointner Date: Sun, 31 May 2020 18:45:31 +0200 Subject: ubuntu/vm: install special kernel image package --- chaos-at-home/ch-hroottest.yml | 13 ++ chaos-at-home/host_vars/ch-hroottest.yml | 10 ++ inventory/host_vars/ch-hroottest-vm1.yml | 29 ++++ inventory/host_vars/ch-hroottest.yml | 50 +++++++ inventory/hosts.ini | 6 + roles/installer/debian/preseed/defaults/main.yml | 2 + .../preseed/templates/preseed_ubuntu-bionic.cfg.j2 | 4 + .../preseed/templates/preseed_ubuntu-focal.cfg.j2 | 4 + .../preseed/templates/preseed_ubuntu-xenial.cfg.j2 | 4 + .../preseed_xubuntu-eoan-desktop-with-raid.cfg.j2 | 166 --------------------- .../templates/preseed_xubuntu-focal-desktop.cfg.j2 | 4 + roles/vm/install/tasks/main.yml | 1 + 12 files changed, 127 insertions(+), 166 deletions(-) create mode 100644 chaos-at-home/ch-hroottest.yml create mode 100644 chaos-at-home/host_vars/ch-hroottest.yml create mode 100644 inventory/host_vars/ch-hroottest-vm1.yml create mode 100644 inventory/host_vars/ch-hroottest.yml delete mode 100644 roles/installer/debian/preseed/templates/preseed_xubuntu-eoan-desktop-with-raid.cfg.j2 diff --git a/chaos-at-home/ch-hroottest.yml b/chaos-at-home/ch-hroottest.yml new file mode 100644 index 00000000..52be7e88 --- /dev/null +++ b/chaos-at-home/ch-hroottest.yml @@ -0,0 +1,13 @@ +--- +- name: Basic Setup + hosts: ch-hroottest + roles: + - role: base + - role: sshd + - role: zsh + - role: apt-repo/base + - role: zfs/base + - role: apt-repo/spreadspace + - role: zfs/sanoid + - role: vm/host + - role: installer/debian/base diff --git a/chaos-at-home/host_vars/ch-hroottest.yml b/chaos-at-home/host_vars/ch-hroottest.yml new file mode 100644 index 00000000..22a0adec --- /dev/null +++ b/chaos-at-home/host_vars/ch-hroottest.yml @@ -0,0 +1,10 @@ +$ANSIBLE_VAULT;1.2;AES256;chaos-at-home +61656635353564323861633431623065636363373833663366346335636638323539376536616263 +6338613065616430373633363761363438346663646130310a363264643035333435646535316435 +62623330333030353264646537353662613264663963356234656638313837636530663362326639 +6138636236313964380a303739376536663463383066333737396261663639653966356234313462 +32336431343537366437653065613063396465316461393664643562343639313330666362376435 +34656336353230623039643933326439306662313165353762343638663832633639356464333439 +38656430353330646433396463386363373033373763636462363561343063313362396431323735 +37333432663430653431316232373038373033306466666133323863623864626566636339316166 +66653164333363643236666339356535633035386633343363343266336162626531 diff --git a/inventory/host_vars/ch-hroottest-vm1.yml b/inventory/host_vars/ch-hroottest-vm1.yml new file mode 100644 index 00000000..53a910e8 --- /dev/null +++ b/inventory/host_vars/ch-hroottest-vm1.yml @@ -0,0 +1,29 @@ +--- +vm_host: ch-hroottest + +install: + host: "{{ vm_host }}" + mem: 4096 + numcpu: 4 + disks: + primary: /dev/sda + scsi: + sda: + type: zfs + name: root + size: 20g + interfaces: + - bridge: br-public + name: primary0 + autostart: True + +network: + nameservers: "{{ hostvars[vm_host].vm_host.network.dns }}" + domain: "{{ host_domain }}" + systemd_link: + interfaces: "{{ install.interfaces }}" + primary: + interface: primary0 + ip: "{{ hostvars[vm_host].vm_host.network.bridges.public.prefix | ipaddr(hostvars[vm_host].vm_host.network.bridges.public.offsets[inventory_hostname]) | ipaddr('address') }}" + mask: "{{ hostvars[vm_host].vm_host.network.bridges.public.prefix | ipaddr('netmask') }}" + gateway: "{{ hostvars[vm_host].vm_host.network.bridges.public.prefix | ipaddr('address') }}" diff --git a/inventory/host_vars/ch-hroottest.yml b/inventory/host_vars/ch-hroottest.yml new file mode 100644 index 00000000..5de56794 --- /dev/null +++ b/inventory/host_vars/ch-hroottest.yml @@ -0,0 +1,50 @@ +--- +install: + cloud: + credentials: "{{ vault_hroot_robot_account }}" + server_name: "{{ host_name }}" + disks: + layout: sata_raid + root_lvm_size: 10G + +network: {} + + +apt_repo_components: +- main +- contrib ## for zfs +- non-free ## for microcode updates + + +zfs_arc_size: + min: "{{ 1 * 1024 * 1024 * 1024 }}" + max: "{{ 4 * 1024 * 1024 * 1024 }}" + +zfs_zpools: + storage: + mountpoint: /srv/storage + create_vdevs: mirror /dev/disk/by-id/ata-SAMSUNG_HD753LJ_S13UJ1LS801071-part3 /dev/disk/by-id/ata-SAMSUNG_HD753LJ_S13UJ1BQ802393-part3 + +zfs_sanoid_modules: + storage/vm: + use_template: production + recursive: yes + process_children_only: yes + + +vm_host: + network: + dns: + - 213.133.100.100 + - 213.133.98.98 + - 213.133.99.99 + bridges: + public: + prefix: 192.168.250.254/24 + offsets: + ch-hroottest-vm1: 100 + nat: yes + zfs: + default: + pool: storage + name: vm diff --git a/inventory/hosts.ini b/inventory/hosts.ini index 2e55d5dd..8e96f240 100644 --- a/inventory/hosts.ini +++ b/inventory/hosts.ini @@ -24,6 +24,8 @@ ch-router host_name=router ch-router-obsd host_name=router ch-gw-lan host_name=gw-lan ch-jump host_name=jump ansible_port=2342 ansible_host=ch-jump +ch-hroottest host_name=hroot-test +ch-hroottest-vm1 host_name=hroot-test-vm1 [chaos-at-home:children] mz-chaos-at-home @@ -232,6 +234,7 @@ r3-cccamp19-dione r3-cccamp19-helene sk-2019vm sk-tomnext +ch-hroottest [kvmguests] emc-master @@ -254,12 +257,14 @@ ele-gwhetzner ele-mur sk-tomnext-nc sk-tomnext-hp +ch-hroottest-vm1 [hroot] sk-2019 sk-cloudia sk-2019vm sk-tomnext +ch-hroottest [hcloud] ch-mimas2 @@ -276,6 +281,7 @@ emc-master lw-master sk-testvm sk-torrent +ch-hroottest-vm1 [hetzner:children] hroot diff --git a/roles/installer/debian/preseed/defaults/main.yml b/roles/installer/debian/preseed/defaults/main.yml index 18cfd952..a864c1bd 100644 --- a/roles/installer/debian/preseed/defaults/main.yml +++ b/roles/installer/debian/preseed/defaults/main.yml @@ -3,3 +3,5 @@ #preseed_force_net_ifnames_policy: path preseed_no_netplan: no + +preseed_virtual_machine: no diff --git a/roles/installer/debian/preseed/templates/preseed_ubuntu-bionic.cfg.j2 b/roles/installer/debian/preseed/templates/preseed_ubuntu-bionic.cfg.j2 index 7b305091..85a77f38 100644 --- a/roles/installer/debian/preseed/templates/preseed_ubuntu-bionic.cfg.j2 +++ b/roles/installer/debian/preseed/templates/preseed_ubuntu-bionic.cfg.j2 @@ -142,6 +142,10 @@ d-i preseed/late_command string \ lvremove -f {{ hostvars[install_hostname].host_name }}/dummy; \ in-target bash -c "swapoff -a; sed -e '/^\/swapfile/d' -i /etc/fstab; rm -f /swapfile"; \ in-target bash -c "apt-get update -q && apt-get full-upgrade -y -q"; \ +{% if preseed_virtual_machine %} + in-target bash -c "apt-get install -y -q --no-install-recommends linux-image-virtual"; \ + in-target bash -c "apt-get purge -y -q linux-image-generic intel-microcode amd64-microcode iucode-tool linux-firmware"; \ +{% endif %} {% if preseed_no_netplan %} in-target bash -c "apt-get purge -y -q netplan.io && apt-get autoremove -y -q && rm -rf /etc/netplan"; \ {% endif %} diff --git a/roles/installer/debian/preseed/templates/preseed_ubuntu-focal.cfg.j2 b/roles/installer/debian/preseed/templates/preseed_ubuntu-focal.cfg.j2 index fec5ff3c..093bfdc5 100644 --- a/roles/installer/debian/preseed/templates/preseed_ubuntu-focal.cfg.j2 +++ b/roles/installer/debian/preseed/templates/preseed_ubuntu-focal.cfg.j2 @@ -142,6 +142,10 @@ d-i preseed/late_command string \ lvremove -f {{ hostvars[install_hostname].host_name }}/dummy; \ in-target bash -c "swapoff -a; sed -e '/^\/swapfile/d' -i /etc/fstab; rm -f /swapfile"; \ in-target bash -c "apt-get update -q && apt-get full-upgrade -y -q"; \ +{% if preseed_virtual_machine %} + in-target bash -c "apt-get install -y -q --no-install-recommends linux-image-virtual"; \ + in-target bash -c "apt-get purge -y -q linux-image-generic intel-microcode amd64-microcode iucode-tool linux-firmware"; \ +{% endif %} {% if preseed_no_netplan %} in-target bash -c "apt-get purge -y -q netplan.io && apt-get autoremove -y -q && rm -rf /etc/netplan"; \ {% endif %} diff --git a/roles/installer/debian/preseed/templates/preseed_ubuntu-xenial.cfg.j2 b/roles/installer/debian/preseed/templates/preseed_ubuntu-xenial.cfg.j2 index 5315f54b..bb510710 100644 --- a/roles/installer/debian/preseed/templates/preseed_ubuntu-xenial.cfg.j2 +++ b/roles/installer/debian/preseed/templates/preseed_ubuntu-xenial.cfg.j2 @@ -138,6 +138,10 @@ d-i finish-install/reboot_in_progress note d-i preseed/late_command string \ lvremove -f {{ hostvars[install_hostname].host_name }}/dummy; \ in-target bash -c "apt-get update -q && apt-get full-upgrade -y -q"; \ +{% if preseed_virtual_machine %} + in-target bash -c "apt-get install -y -q --no-install-recommends linux-image-virtual"; \ + in-target bash -c "apt-get purge -y -q linux-image-generic intel-microcode amd64-microcode iucode-tool linux-firmware"; \ +{% endif %} in-target bash -c "sed -e 's/^allow-hotplug/auto/' -i /etc/network/interfaces"; \ {% if preseed_force_net_ifnames_policy is defined %} mkdir -p /target/etc/systemd/network; \ diff --git a/roles/installer/debian/preseed/templates/preseed_xubuntu-eoan-desktop-with-raid.cfg.j2 b/roles/installer/debian/preseed/templates/preseed_xubuntu-eoan-desktop-with-raid.cfg.j2 deleted file mode 100644 index 678d1779..00000000 --- a/roles/installer/debian/preseed/templates/preseed_xubuntu-eoan-desktop-with-raid.cfg.j2 +++ /dev/null @@ -1,166 +0,0 @@ -######################################################################### -# spreadspace preseed file for Ubuntu eoan based Workstations -######################################################################### - -d-i debian-installer/language string en -d-i debian-installer/country string AT -d-i debian-installer/locale string de_AT.UTF-8 -d-i localechooser/preferred-locale string de_AT.UTF-8 -d-i localechooser/supported-locales multiselect de_DE.UTF-8, en_US.UTF-8 -d-i keyboard-configuration/xkb-keymap select de -## TODO: this still doesn't work properly... -d-i keyboard-configuration/layout select German (Austria) -d-i keyboard-configuration/layoutcode string at -d-i keyboard-configuration/layoutcode string nodeadkeys -d-i console-setup/ask_detect boolean false - -d-i hw-detect/load_firmware boolean false - -{% if preseed_no_netplan %} -d-i netcfg/do_not_use_netplan boolean true -{% endif %} -d-i netcfg/choose_interface select {{ install_interface | default(hostvars[install_hostname].network_cooked.primary.interface) }} -{% if 'install_dhcp' in hostvars[install_hostname] and hostvars[install_hostname].install_dhcp %} -d-i netcfg/disable_dhcp boolean false -d-i netcfg/disable_autoconfig boolean false -{% else %} -d-i netcfg/disable_dhcp boolean true -d-i netcfg/disable_autoconfig boolean true -d-i netcfg/get_ipaddress string {{ hostvars[install_hostname].network_cooked.primary.ip }} -d-i netcfg/get_netmask string {{ hostvars[install_hostname].network_cooked.primary.mask }} -d-i netcfg/get_gateway string {{ hostvars[install_hostname].network_cooked.primary.gateway }} -d-i netcfg/get_nameservers string {{ hostvars[install_hostname].network_cooked.nameservers | join(' ') }} -d-i netcfg/confirm_static boolean true -{% endif %} - -d-i netcfg/hostname string {{ hostvars[install_hostname].host_name }} -d-i netcfg/get_hostname string {{ hostvars[install_hostname].host_name }} -d-i netcfg/domain string {{ hostvars[install_hostname].network_cooked.domain }} -d-i netcfg/get_domain string {{ hostvars[install_hostname].network_cooked.domain }} -d-i netcfg/wireless_wep string - - -d-i mirror/country string manual -d-i mirror/http/hostname string {{ apt_repo_providers[hostvars[install_hostname].apt_repo_provider].ubuntu }} -d-i mirror/http/directory string /ubuntu -d-i mirror/http/proxy string - - -d-i passwd/make-user boolean false -d-i passwd/root-login boolean true -d-i passwd/root-password password this-very-very-secure-password-will-be-removed-by-latecommand -d-i passwd/root-password-again password this-very-very-secure-password-will-be-removed-by-latecommand - - -d-i clock-setup/utc boolean true -d-i time/zone string Europe/Vienna -d-i clock-setup/ntp boolean false - -d-i partman-auto/disk string /dev/sda /dev/sdb - -d-i partman-auto/method string raid -d-i partman-auto/purge_lvm_from_device boolean true -d-i partman-auto-lvm/new_vg_name string {{ hostvars[install_hostname].host_name }} -d-i partman-auto-lvm/guided_size string max - -d-i partman-lvm/device_remove_lvm boolean true -d-i partman-md/device_remove_md boolean true -d-i partman-md/confirm boolean true -d-i partman-md/confirm_nooverwrite boolean true -d-i partman-lvm/confirm boolean true -d-i partman-lvm/confirm_nooverwrite boolean true - -d-i partman/choose_label string dos -d-i partman/default_label string dos -d-i partman-auto/choose_recipe select boot-root -d-i partman-auto/expert_recipe string \ - boot-root :: \ - 256 512 256 raid \ - $lvmignore{ } $primary{ } method{ raid } \ - . \ - 1000 10000 -1 raid \ - $lvmignore{ } $primary{ } method{ raid } \ - . \ - 15360 10000 20480 ext4 \ - $defaultignore{ } $lvmok{ } \ - in_vg{ {{ hostvars[install_hostname].host_name }} } \ - method{ format } format{ } \ - use_filesystem{ } filesystem{ ext4 } \ - mountpoint{ / } \ - . \ - 768 10000 768 ext4 \ - $defaultignore{ } $lvmok{ } \ - in_vg{ {{ hostvars[install_hostname].host_name }} } \ - method{ format } format{ } \ - use_filesystem{ } filesystem{ ext4 } \ - mountpoint{ /var/log } \ - options/nodev{ nodev } options/noatime{ noatime } \ - options/noexec{ noexec } \ - . \ - 20480 10000 40960 ext4 \ - $defaultignore{ } $lvmok{ } \ - in_vg{ {{ hostvars[install_hostname].host_name }} } \ - method{ format } format{ } \ - use_filesystem{ } filesystem{ ext4 } \ - mountpoint{ /home } \ - . \ - 16 20000 -1 ext4 \ - $defaultignore{ } $lvmok{ } \ - in_vg{ {{ hostvars[install_hostname].host_name }} } \ - lv_name{ dummy } \ - . - -d-i partman-auto-raid/recipe string \ - 1 2 0 ext4 /boot \ - /dev/sda1#/dev/sdb1 \ - . \ - 1 2 0 lvm - \ - /dev/sda2#/dev/sdb2 \ - . - -d-i partman-basicfilesystems/no_swap true -d-i partman-partitioning/confirm_write_new_label boolean true -d-i partman/choose_partition select finish -d-i partman/confirm boolean true -d-i partman/confirm_nooverwrite boolean true - - -d-i base-installer/install-recommends boolean false -d-i apt-setup/security_host string {{ apt_repo_providers[hostvars[install_hostname].apt_repo_provider].ubuntu }} - -tasksel tasksel/first multiselect xubuntu-desktop -d-i pkgsel/include string openssh-server python python-apt ifupdown -d-i pkgsel/upgrade select safe-upgrade -popularity-contest popularity-contest/participate boolean false -d-i pkgsel/update-policy select none - -d-i grub-installer/choose_bootdev string /dev/sda /dev/sdb -d-i grub-installer/bootdev string /dev/sda /dev/sdb -d-i grub-installer/only_debian boolean true -d-i grub-installer/with_other_os boolean false - -d-i nobootloader/confirmation_common boolean true - -d-i finish-install/reboot_in_progress note - - -d-i preseed/late_command string \ - lvremove -f {{ hostvars[install_hostname].host_name }}/dummy; \ - in-target bash -c "swapoff -a; sed -e '/^\/swapfile/d' -i /etc/fstab; rm -f /swapfile"; \ - in-target bash -c "apt-get update -q && apt-get full-upgrade -y -q"; \ -{% if preseed_no_netplan %} - in-target bash -c "apt-get purge -y -q netplan.io && apt-get autoremove -y -q && rm -rf /etc/netplan"; \ -{% endif %} - in-target bash -c "sed -e 's/^allow-hotplug/auto/' -i /etc/network/interfaces"; \ -{% if preseed_force_net_ifnames_policy is defined %} - mkdir -p /target/etc/systemd/network; \ - in-target bash -c "echo '[Link]' > /etc/systemd/network/90-namepolicy.link"; \ - in-target bash -c "echo 'NamePolicy={{ preseed_force_net_ifnames_policy }}' >> /etc/systemd/network/90-namepolicy.link"; \ - in-target bash -c "update-initramfs -u"; \ -{% endif %} - in-target bash -c "passwd -d root && passwd -l root"; \ -{% if hostvars[install_hostname].ansible_port is defined %} - in-target bash -c "sed -e 's/^\(\s*#*\s*Port.*\)/Port {{ hostvars[install_hostname].ansible_port }}/' -i /etc/ssh/sshd_config"; \ -{% endif %} - mkdir -p -m 0700 /target/root/.ssh; \ - cp /authorized_keys /target/root/.ssh/ diff --git a/roles/installer/debian/preseed/templates/preseed_xubuntu-focal-desktop.cfg.j2 b/roles/installer/debian/preseed/templates/preseed_xubuntu-focal-desktop.cfg.j2 index 9a8a0d25..bf4395a6 100644 --- a/roles/installer/debian/preseed/templates/preseed_xubuntu-focal-desktop.cfg.j2 +++ b/roles/installer/debian/preseed/templates/preseed_xubuntu-focal-desktop.cfg.j2 @@ -145,6 +145,10 @@ d-i preseed/late_command string \ lvremove -f {{ hostvars[install_hostname].host_name }}/dummy; \ in-target bash -c "swapoff -a; sed -e '/^\/swapfile/d' -i /etc/fstab; rm -f /swapfile"; \ in-target bash -c "apt-get update -q && apt-get full-upgrade -y -q"; \ +{% if preseed_virtual_machine %} + in-target bash -c "apt-get install -y -q --no-install-recommends linux-image-virtual"; \ + in-target bash -c "apt-get purge -y -q linux-image-generic intel-microcode amd64-microcode iucode-tool linux-firmware"; \ +{% endif %} {% if preseed_no_netplan %} in-target bash -c "apt-get purge -y -q netplan.io && apt-get autoremove -y -q && rm -rf /etc/netplan"; \ {% endif %} diff --git a/roles/vm/install/tasks/main.yml b/roles/vm/install/tasks/main.yml index 4fa673c5..45dd2278 100644 --- a/roles/vm/install/tasks/main.yml +++ b/roles/vm/install/tasks/main.yml @@ -39,6 +39,7 @@ vars: ssh_keys_root: "{{ hostvars[install_hostname].ssh_keys_root }}" preseed_tmpdir: "{{ tmpdir.path }}" + preseed_virtual_machine: yes preseed_force_net_ifnames_policy: path preseed_no_netplan: yes install_interface: enp1s1 -- cgit v1.2.3