cobbler自動化部署工具
cobbler簡介
RHEL7默認提供的cobbler是2.6.9版本的,cobbler譯文”補鞋匠“網絡安裝套件cobbler可以同時管理DHCP;DNS;YUM等,現在隨便一家互聯網公司機器數量成千上萬,這個時候我們就不能那個U盤,或者光盤一臺臺的裝,然後誕生了PXE+TFTP+DHCP+Kickstart(俗稱PXE)然而PXE不能同時部署多種版本的系統,然而cobbler可以部署多種系統如centos5,6,7;redhat 5,6,7;cobbler還可以部署windows系統。該工具由python語言開發,支持web界面管理十分靈活。
PXE自動化部署參考:http://mictiger.blog.51cto.com/4854014/1577008
配置yum源
cobbler centos源沒有cobbler包組,它是由epel提供,但是其依賴的軟件包又是centos所提供,所以我們配置centos,epel 兩個yum源
[root@cobbler yum.repos.d]# cat aliyun.repo [epel] name=ailiyun baseurl=http://mirrors.aliyun.com/epel/7/x86_64/ enabled=1 gpgcheck=0 [centos] name=cobbler baseurl=http://mirrors.aliyun.com/centos/7/os/x86_64/ enabled=1 gpgcheck=0
開始安裝
[root@cobbler yum.repos.d]# yum install cobbler cobbler-web pykickstart debmirror [root@cobbler ~]# rpm -qi cobbler Name : cobbler Version : 2.6.9 Release : 1.el7 Architecture: noarch Install Date: Thu 20 Aug 2015 09:00:46 PM CST Group : Applications/System Size : 2177634 License : GPLv2+ Signature : RSA/SHA256, Wed 24 Jun 2015 04:36:07 AM CST, Key ID 6a2faea2352c64e5 Source RPM : cobbler-2.6.9-1.el7.src.rpm Build Date : Tue 23 Jun 2015 02:06:19 AM CST Build Host : buildppc-02.phx2.fedoraproject.org Relocations : (not relocatable) Packager : Fedora Project Vendor : Fedora Project URL : http://www.cobblerd.org/ Summary : Boot server configurator Description : Cobbler is a network install server. Cobbler supports PXE, ISO virtualized installs, and re-installing existing Linux machines. The last two modes use a helper tool, 'koan', that integrates with cobbler. There is also a web interface 'cobbler-web'. Cobbler's advanced features include importing distributions from DVDs and rsync mirrors, kickstart templating, integrated yum mirroring, and built-in DHCP/DNS Management. Cobbler has a XMLRPC API for integration with other applications.
啓動cobbler,httpd服務
[root@cobbler ~]# systemctl start httpd.service [root@cobbler ~]# systemctl start cobblerd.service
關閉selinux
[root@cobbler ~]# cat /etc/selinux/config # This file controls the state of SELinux on the system. # SELINUX= can take one of these three values: # enforcing - SELinux security policy is enforced. # permissive - SELinux prints warnings instead of enforcing. # disabled - No SELinux policy is loaded. SELINUX=disabled # SELINUXTYPE= can take one of these two values: # targeted - Targeted processes are protected, # minimum - Modification of targeted policy. Only selected processes are protected. # mls - Multi Level Security protection. SELINUXTYPE=targeted [root@cobbler ~]# getenforce Permissive 或者 Disabled [root@cobbler ~]# cobbler check The following are potential configuration items that you may want to fix: 1 : The 'server' field in /etc/cobbler/settings must be set to something other than localhost, or kickstarting features will not work. This should be a resolvable hostname or IP for the boot server as reachable by all machines that will use it. 2 : For PXE to be functional, the 'next_server' field in /etc/cobbler/settings must be set to something other than 127.0.0.1, and should match the IP of the boot server on the PXE network. 3 : SELinux is enabled. Please review the following wiki page for details on ensuring cobbler works correctly in your SELinux environment: https://github.com/cobbler/cobbler/wiki/Selinux 4 : change 'disable' to 'no' in /etc/xinetd.d/tftp 5 : some network boot-loaders are missing from /var/lib/cobbler/loaders, you may run 'cobbler get-loaders' to download them, or, if you only want to handle x86/x86_64 netbooting, you may ensure that you have installed a *recent* version of the syslinux package installed and can ignore this message entirely. Files in this directory, should you want to support all architectures, should include pxelinux.0, menu.c32, elilo.efi, and yaboot. The 'cobbler get-loaders' command is the easiest way to resolve these requirements. 6 : file /etc/xinetd.d/rsync does not exist 7 : debmirror package is not installed, it will be required to manage debian deployments and repositories 8 : The default password used by the sample templates for newly installed machines (default_password_crypted in /etc/cobbler/settings) is still set to 'cobbler' and should be changed, try: "openssl passwd -1 -salt 'random-phrase-here' 'your-password-here'" to generate new one 9 : fencing tools were not found, and are required to use the (optional) power management features. install cman or fence-agents to use them Restart cobblerd and then run 'cobbler sync' to apply changes.
解決以上報告信息
修改參數
修改 /etc/cobbler/settings next_server: 192.168.3.100 server: 192.168.3.100 [root@cobbler ~]# cobbler get-loaders 如果網絡不行可以直接去 http://cobbler.github.com/loaders/下載COPYING.elilo COPYING.syslinux COPYING.yaboot elilo-ia64.efi grub-x86_64.efi grub-x86.efi menu.c32 pxelinux.0 README yaboot這些軟件包 [root@cobbler ~]# cobbler get-loaders task started: 2015-08-20_215034_get_loaders task started (id=Download Bootloader Content, time=Thu Aug 20 21:50:34 2015) downloading http://cobbler.github.com/loaders/README to /var/lib/cobbler/loaders/README [root@cobbler ~]# yum install fence-agents cman 註釋/etc/debmirror.conf 中以下兩項 #@dists="sid"; #@arches="i386"; [root@cobbler ~]# openssl passwd -1 -salt `openssl rand -hex 4` Password: $1$a6a60411$ltytuO4WzxCYFOJhNFIlh1 [root@cobbler ~]# vim /etc/cobbler/settings default_password_crypted: "$1$a6a60411$ltytuO4WzxCYFOJhNFIlh1"
檢查是否配置完成
[root@cobbler ~]# cobbler check No configuration problems found. All systems go. 安裝配置DHCP [root@cobbler ~]# yum install dhcp [root@cobbler loaders]# vim /etc/dhcp/dhcpd.conf default-lease-time 86400; max-lease-time 7200; log-facility local7; subnet 192.168.3.0 netmask 255.255.255.0 { range 192.168.3.105 192.168.3.120; option routers 192.168.3.100; } next-server 192.168.3.100; filename="pxelinux.0";
準備安裝yum
[root@cobbler media]# mkdir centos6 [root@cobbler media]# mkdir centos7 [root@cobbler ~]# mount -o loop CentOS-6.6-x86_64-bin-DVD1.iso /media/centos6 [root@cobbler ~]# mount -o loop CentOS-7.0-1406-x86_64-DVD.iso /media/centos7
安裝system-config-kickstart 用於編寫ks.cfg文件基於系統的anaconda-ks.cfg這個文件是本系統安裝中的配置
[root@cobbler ~]# yum install system-config-kickstart [root@cobbler ~]# system-config-kickstart
導入系統鏡像
[root@cobbler ~]# cobbler import --name="centos6" --path=/media/centos6 [root@cobbler ~]# cobbler distro list centos6-x86_64 [root@cobbler cobbler]# cobbler profile add --name=centos6.6 --distro=centos6-x86_64 --kickstart=/var/lib/cobbler/kickstarts/centos6.cfg [root@cobbler cobbler]# cobbler profile list centos6-x86_64 centos6.6
配置完成後一定要sync
[root@cobbler ~]# cobbler sync task started: 2015-08-22_011824_sync task started (id=Sync, time=Sat Aug 22 01:18:24 2015) running pre-sync triggers cleaning trees removing: /var/www/cobbler/images/centos6-x86_64 removing: /var/lib/tftpboot/pxelinux.cfg/default removing: /var/lib/tftpboot/grub/images removing: /var/lib/tftpboot/grub/grub-x86_64.efi removing: /var/lib/tftpboot/grub/grub-x86.efi removing: /var/lib/tftpboot/grub/efidefault removing: /var/lib/tftpboot/images/centos6-x86_64 removing: /var/lib/tftpboot/s390x/profile_list copying bootloaders trying hardlink /var/lib/cobbler/loaders/pxelinux.0 -> /var/lib/tftpboot/pxelinux.0 copying: /var/lib/cobbler/loaders/pxelinux.0 -> /var/lib/tftpboot/pxelinux.0 trying hardlink /var/lib/cobbler/loaders/menu.c32 -> /var/lib/tftpboot/menu.c32 copying: /var/lib/cobbler/loaders/menu.c32 -> /var/lib/tftpboot/menu.c32 trying hardlink /var/lib/cobbler/loaders/yaboot -> /var/lib/tftpboot/yaboot copying: /var/lib/cobbler/loaders/yaboot -> /var/lib/tftpboot/yaboot trying hardlink /var/lib/cobbler/loaders/grub-x86_64.efi -> /var/lib/tftpboot/grub/grub-x86_64.efi trying hardlink /var/lib/cobbler/loaders/grub-x86.efi -> /var/lib/tftpboot/grub/grub-x86.efi copying distros to tftpboot copying files for distro: centos6-x86_64 trying hardlink /var/www/cobbler/ks_mirror/centos6/images/pxeboot/vmlinuz -> /var/lib/tftpboot/images/centos6-x86_64/vmlinuz trying hardlink /var/www/cobbler/ks_mirror/centos6/images/pxeboot/initrd.img -> /var/lib/tftpboot/images/centos6-x86_64/initrd.img copying images generating PXE configuration files generating PXE menu structure copying files for distro: centos6-x86_64 trying hardlink /var/www/cobbler/ks_mirror/centos6/images/pxeboot/vmlinuz -> /var/www/cobbler/images/centos6-x86_64/vmlinuz trying hardlink /var/www/cobbler/ks_mirror/centos6/images/pxeboot/initrd.img -> /var/www/cobbler/images/centos6-x86_64/initrd.img Writing template files for centos6-x86_64 rendering TFTPD files generating /etc/xinetd.d/tftp processing boot_files for distro: centos6-x86_64 cleaning link caches running post-sync triggers running python triggers from /var/lib/cobbler/triggers/sync/post/* running python trigger cobbler.modules.sync_post_restart_services running shell triggers from /var/lib/cobbler/triggers/sync/post/* running python triggers from /var/lib/cobbler/triggers/change/* running python trigger cobbler.modules.scm_track running shell triggers from /var/lib/cobbler/triggers/change/* *** TASK COMPLETE ***
查看是否配置成功
[root@cobbler cobbler]# cat /var/lib/tftpboot/pxelinux.cfg/default DEFAULT menu PROMPT 0 MENU TITLE Cobbler | http://cobbler.github.com TIMEOUT 200 TOTALTIMEOUT 6000 ONTIMEOUT local LABEL local MENU LABEL (local) MENU DEFAULT LOCALBOOT -1 LABEL centos6-x86_64 kernel /images/centos6-x86_64/vmlinuz MENU LABEL centos6-x86_64 append initrd=/images/centos6-x86_64/initrd.img ksdevice=bootif lang= kssendmac text ks=http://192.168.3.100/cblr/svc/op/ks/profile/centos6-x86_64 ipappend 2 LABEL centos6.6 kernel /images/centos6-x86_64/vmlinuz MENU LABEL centos6.6 append initrd=/images/centos6-x86_64/initrd.img ksdevice=bootif lang= kssendmac text ks=http://192.168.3.100/cblr/svc/op/ks/profile/centos6.6 ipappend 2
開始安裝
配置cobbler安裝Centos7
[root@cobbler ~]# cobbler import --name="centos7" --path=/media/centos7 task started: 2015-08-22_014024_import task started (id=Media import, time=Sat Aug 22 01:40:24 2015) Found a candidate signature: breed=redhat, version=rhel6 Found a candidate signature: breed=redhat, version=rhel7 Found a matching signature: breed=redhat, version=rhel7 Adding distros from path /var/www/cobbler/ks_mirror/centos7: creating new distro: centos7-x86_64 trying symlink: /var/www/cobbler/ks_mirror/centos7 -> /var/www/cobbler/links/centos7-x86_64 creating new profile: centos7-x86_64 associating repos checking for rsync repo(s) checking for rhn repo(s) checking for yum repo(s) starting descent into /var/www/cobbler/ks_mirror/centos7 for centos7-x86_64 processing repo at : /var/www/cobbler/ks_mirror/centos7 need to process repo/comps: /var/www/cobbler/ks_mirror/centos7 looking for /var/www/cobbler/ks_mirror/centos7/repodata/*comps*.xml Keeping repodata as-is :/var/www/cobbler/ks_mirror/centos7/repodata *** TASK COMPLETE *** [root@cobbler ~]# cobbler distro list centos6-x86_64 centos7-x86_64
出現以下問題是要將做好的ks移動到 /var/lib/cobbler/kickstarts/ 這個路徑是專門存放ks文件模板的
[root@cobbler ks]# cobbler profile add --distro="centos7-x86_64" --name=centos7 --kickstart=/root/ks/centos7.cfg exception on server: 'Invalid kickstart template file location /root/ks/centos7.cfg, it is not inside /var/lib/cobbler/kickstarts/'
[root@cobbler ks]# cobbler profile add --distro="centos7-x86_64" --name=centos7 --kickstart=/var/lib/cobbler/kickstarts/centos7.cfg [root@cobbler ks]# cobbler sync task started: 2015-08-22_015615_sync task started (id=Sync, time=Sat Aug 22 01:56:15 2015) running pre-sync triggers cleaning trees removing: /var/www/cobbler/images/centos6-x86_64 removing: /var/www/cobbler/images/centos7-x86_64 removing: /var/lib/tftpboot/pxelinux.cfg/default removing: /var/lib/tftpboot/grub/images removing: /var/lib/tftpboot/grub/grub-x86_64.efi removing: /var/lib/tftpboot/grub/grub-x86.efi removing: /var/lib/tftpboot/grub/efidefault removing: /var/lib/tftpboot/images/centos6-x86_64 removing: /var/lib/tftpboot/images/centos7-x86_64 removing: /var/lib/tftpboot/s390x/profile_list copying bootloaders trying hardlink /var/lib/cobbler/loaders/pxelinux.0 -> /var/lib/tftpboot/pxelinux.0 copying: /var/lib/cobbler/loaders/pxelinux.0 -> /var/lib/tftpboot/pxelinux.0 trying hardlink /var/lib/cobbler/loaders/menu.c32 -> /var/lib/tftpboot/menu.c32 copying: /var/lib/cobbler/loaders/menu.c32 -> /var/lib/tftpboot/menu.c32 trying hardlink /var/lib/cobbler/loaders/yaboot -> /var/lib/tftpboot/yaboot copying: /var/lib/cobbler/loaders/yaboot -> /var/lib/tftpboot/yaboot trying hardlink /var/lib/cobbler/loaders/grub-x86_64.efi -> /var/lib/tftpboot/grub/grub-x86_64.efi trying hardlink /var/lib/cobbler/loaders/grub-x86.efi -> /var/lib/tftpboot/grub/grub-x86.efi copying distros to tftpboot copying files for distro: centos7-x86_64 trying hardlink /var/www/cobbler/ks_mirror/centos7/images/pxeboot/vmlinuz -> /var/lib/tftpboot/images/centos7-x86_64/vmlinuz trying hardlink /var/www/cobbler/ks_mirror/centos7/images/pxeboot/initrd.img -> /var/lib/tftpboot/images/centos7-x86_64/initrd.img copying files for distro: centos6-x86_64 trying hardlink /var/www/cobbler/ks_mirror/centos6/images/pxeboot/vmlinuz -> /var/lib/tftpboot/images/centos6-x86_64/vmlinuz trying hardlink /var/www/cobbler/ks_mirror/centos6/images/pxeboot/initrd.img -> /var/lib/tftpboot/images/centos6-x86_64/initrd.img copying images generating PXE configuration files generating PXE menu structure copying files for distro: centos7-x86_64 trying hardlink /var/www/cobbler/ks_mirror/centos7/images/pxeboot/vmlinuz -> /var/www/cobbler/images/centos7-x86_64/vmlinuz trying hardlink /var/www/cobbler/ks_mirror/centos7/images/pxeboot/initrd.img -> /var/www/cobbler/images/centos7-x86_64/initrd.img Writing template files for centos7-x86_64 copying files for distro: centos6-x86_64 trying hardlink /var/www/cobbler/ks_mirror/centos6/images/pxeboot/vmlinuz -> /var/www/cobbler/images/centos6-x86_64/vmlinuz trying hardlink /var/www/cobbler/ks_mirror/centos6/images/pxeboot/initrd.img -> /var/www/cobbler/images/centos6-x86_64/initrd.img Writing template files for centos6-x86_64 rendering TFTPD files generating /etc/xinetd.d/tftp processing boot_files for distro: centos7-x86_64 processing boot_files for distro: centos6-x86_64 cleaning link caches running post-sync triggers running python triggers from /var/lib/cobbler/triggers/sync/post/* running python trigger cobbler.modules.sync_post_restart_services running shell triggers from /var/lib/cobbler/triggers/sync/post/* running python triggers from /var/lib/cobbler/triggers/change/* running python trigger cobbler.modules.scm_track running shell triggers from /var/lib/cobbler/triggers/change/* *** TASK COMPLETE *** [root@cobbler ks]# cobbler profile list centos6-x86_64 centos6.6 centos7 centos7-x86_64
開始安裝
附上我自己的ks文件參考
[root@cobbler ks]# cat centos6.cfg #platform=x86, AMD64, or Intel EM64T #version=DEVEL # Install OS instead of upgrade install # Keyboard layouts keyboard 'us'# Reboot after installation reboot # Root password rootpw --iscrypted $1$JrbIN3YW$buJKv8Y7FfZhCEhOg/eD01 # System timezone timezone Asia/Chongqing --isUtc # Use network installation url --url="http://192.168.3.100/cobbler/ks_mirror/centos6/" # System language lang en_US # Firewall configuration firewall --disabled # Network information network --bootproto=dhcp --device=eth0 # System authorization information auth --useshadow --passalgo=sha512 # Use graphical install graphical firstboot --disable # SELinux configuration selinux --disabled # Installation logging level logging --level=info # System bootloader configuration bootloader --append="crashkernel=auto rhgb quiet" --location=mbr --driveorder="sda" # Clear the Master Boot Record zerombr # Partition clearing information clearpart --all --initlabel # Disk partitioning information part /boot --fstype="ext4" --size=500 part pv.008002 --grow --size=1 %packages @base @basic-desktop @core @debugging @desktop Platform Development @desktop-debugging @desktop-platform @development tools @directory-client @fonts @input-methods @internet-browser @java-platform @legacy-x @network-file-system-client @print-client @remote-desktop-clients @server Platform Development @server-platform @server-policy @x11 %end
centos7 ks文件
[root@cobbler ks]# cat centos7.cfg #platform=x86, AMD64, or Intel EM64T #version=DEVEL # Install OS instead of upgrade install # X Window System configuration information xconfig --startxonboot # Keyboard layouts # old format: keyboard us # new format: keyboard --vckeymap=us --xlayouts='us' # Halt after installation reboot # Root password rootpw --iscrypted $1$L7lKtlWj$DvBzrvndeOQd7EHfRGOnj/ # System timezone timezone Asia/Chongqing --isUtc --nontp # Use network installation url --url="http://192.168.3.100/cobbler/ks_mirror/centos7/" # System language lang en_US --addsupport=zh_CN.UTF-8 # Firewall configuration firewall --disabled # Network information network --bootproto=dhcp --device=eno16777736 network --bootproto=dhcp --device=None # System authorization information auth --useshadow --passalgo=sha512 # Use graphical install graphical # Run the Setup Agent on first boot firstboot --enable # SELinux configuration selinux --disabled ignoredisk --only-use=sda # System bootloader configuration bootloader --location=mbr --boot-drive=sda # Clear the Master Boot Record zerombr # Partition clearing information clearpart --all --initlabel # Disk partitioning information part pv.10 --fstype="lvmpv" --ondisk=sda --size=35339 part /boot --fstype="xfs" --ondisk=sda --size=500 volgroup centos --pesize=4096 pv.10 logvol / --fstype="xfs" --grow --maxsize=51200 --size=1024 --name=root --vgname=centos logvol swap --fstype="swap" --size=2064 --name=swap --vgname=centos %packages @base @core @desktop-debugging @dial-up @directory-client @fonts @guest-agents @guest-desktop-agents @input-methods @internet-browser @java-platform @kde-desktop @multimedia @network-file-system-client @print-client @x11 %end
cobbler web界面配置
使用系統用戶(pam)或者configfile定義用戶登錄管理cobbler web
[authentication] #module = authn_configfile (默認值) module = authn_pam
[root@cobbler ~]# vim /etc/cobbler/modules.conf [root@cobbler ~]# useradd cobbler [root@cobbler ~]# echo "cobbler" | passwd --stdin cobbler Changing password for user cobbler. passwd: all authentication tokens updated successfully. [root@cobbler ~]# vim /etc/cobbler/users.conf [admins] admin = "cobbler"
[root@cobbler ~]# vim /etc/cobbler/modules.conf [authentication] module = authn_configfile [root@cobbler ~]# htdigest /etc/cobbler/users.digest "Cobbler" admin Adding user admin in realm Cobbler New password: Re-type new password:
未完待續