mirror of
https://github.com/xcat2/confluent.git
synced 2026-09-29 00:31:09 +00:00
Compare commits
35 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| a54a9a5d09 | |||
| 9b79da9522 | |||
| 04c2b1a322 | |||
| 559a7ca7b8 | |||
| 0a10311fea | |||
| 715bcb2f50 | |||
| 8d5ad0d4a6 | |||
| 1387a67b61 | |||
| 4b08273379 | |||
| e0c3232180 | |||
| bd95f00680 | |||
| bfecaa389d | |||
| 7aca7a19f9 | |||
| c400671ad7 | |||
| c96955b369 | |||
| 2bb519c158 | |||
| e5c33cacd5 | |||
| 03f0f16ed8 | |||
| 0f815dc7d3 | |||
| dbdc99905d | |||
| 2d665fb816 | |||
| 26e0fa8c91 | |||
| 83da1359df | |||
| 0f1581f8f7 | |||
| 13d4d1dd98 | |||
| db5c31030d | |||
| 6f484aab53 | |||
| 64b8893b80 | |||
| f13df801fd | |||
| ee1a763c68 | |||
| f138b4513c | |||
| d8a2671dd6 | |||
| 14efec3603 | |||
| 00589d06f5 | |||
| 334ce65919 |
@@ -24,25 +24,17 @@ a confluent server.
|
||||
%setup -n %{name}-%{version} -n %{name}-%{version}
|
||||
|
||||
%build
|
||||
%if "%{dist}" == ".el8"
|
||||
python3 setup.py build
|
||||
%else
|
||||
%if "%{dist}" == ".el9"
|
||||
python3 setup.py build
|
||||
%else
|
||||
%if "%{dist}" == ".el7"
|
||||
python2 setup.py build
|
||||
%endif
|
||||
%else
|
||||
python3 setup.py build
|
||||
%endif
|
||||
|
||||
%install
|
||||
%if "%{dist}" == ".el8"
|
||||
python3 setup.py install --single-version-externally-managed -O1 --root=$RPM_BUILD_ROOT --record=INSTALLED_FILES --install-scripts=/opt/confluent/bin --install-purelib=/opt/confluent/lib/python
|
||||
%else
|
||||
%if "%{dist}" == ".el9"
|
||||
python3 setup.py install --single-version-externally-managed -O1 --root=$RPM_BUILD_ROOT --record=INSTALLED_FILES --install-scripts=/opt/confluent/bin --install-purelib=/opt/confluent/lib/python
|
||||
%else
|
||||
%if "%{dist}" == ".el7"
|
||||
python2 setup.py install --single-version-externally-managed -O1 --root=$RPM_BUILD_ROOT --record=INSTALLED_FILES --install-scripts=/opt/confluent/bin --install-purelib=/opt/confluent/lib/python
|
||||
%endif
|
||||
%else
|
||||
python3 setup.py install --single-version-externally-managed -O1 --root=$RPM_BUILD_ROOT --record=INSTALLED_FILES --install-scripts=/opt/confluent/bin --install-purelib=/opt/confluent/lib/python
|
||||
%endif
|
||||
|
||||
|
||||
@@ -52,3 +44,4 @@ rm -rf $RPM_BUILD_ROOT
|
||||
%files -f INSTALLED_FILES
|
||||
%license /opt/confluent/share/licenses/confluent_client/LICENSE
|
||||
%defattr(-,root,root)
|
||||
/opt/confluent
|
||||
|
||||
@@ -20,3 +20,4 @@ for i in /ssh/*.ca; do
|
||||
done
|
||||
mkdir -p /sysroot/opt/confluent/bin
|
||||
cp /opt/confluent/bin/apiclient /sysroot/opt/confluent/bin
|
||||
cp /opt/confluent/bin/apiclient /sysroot/etc/confluent/
|
||||
|
||||
@@ -79,5 +79,9 @@ if [ -e /tmp/installdisk -a ! -e /tmp/partitioning ]; then
|
||||
echo ignoredisk --only-use $(cat /tmp/installdisk) >> /tmp/partitioning
|
||||
echo autopart --nohome $LUKSPARTY >> /tmp/partitioning
|
||||
fi
|
||||
python /etc/confluent/apiclient /confluent-public/os/$confluent_profile/kickstart.custom -o /tmp/kickstart.custom
|
||||
if [ -f /opt/confluent/bin/apiclient ]; then
|
||||
python /opt/confluent/bin/apiclient /confluent-public/os/$confluent_profile/kickstart.custom -o /tmp/kickstart.custom
|
||||
else
|
||||
python /etc/confluent/apiclient /confluent-public/os/$confluent_profile/kickstart.custom -o /tmp/kickstart.custom
|
||||
fi
|
||||
kill $logshowpid
|
||||
|
||||
@@ -10,6 +10,8 @@
|
||||
nodename=$(grep ^NODENAME /etc/confluent/confluent.info|awk '{print $2}')
|
||||
export confluent_mgr confluent_profile nodename
|
||||
cp -a /etc/confluent /mnt/sysimage/etc
|
||||
mkdir -p /mnt/sysimage/opt/confluent/bin
|
||||
cp /opt/confluent/bin/apiclient /mnt/sysimage/opt/confluent/bin/
|
||||
chmod -R og-rwx /mnt/sysimage/etc/confluent
|
||||
cp /tmp/functions /mnt/sysimage/etc/confluent/
|
||||
hostnamectl set-hostname $nodename
|
||||
|
||||
@@ -42,11 +42,20 @@ echo lang $locale > /tmp/langinfo
|
||||
echo keyboard --vckeymap=$keymap >> /tmp/langinfo
|
||||
tz=$(grep ^timezone: /etc/confluent/confluent.deploycfg)
|
||||
tz=${tz#timezone: }
|
||||
MVER=$(grep VERSION_ID /etc/os-release|cut -d = -f 2 |cut -d . -f 1|cut -d '"' -f 2)
|
||||
ntpsrvs=""
|
||||
if grep ^ntpservers: /etc/confluent/confluent.deploycfg > /dev/null; then
|
||||
ntpsrvs="--ntpservers="$(sed -n '/^ntpservers:/,/^[^-]/p' /etc/confluent/confluent.deploycfg|sed 1d|sed '$d' | sed -e 's/^- //' | paste -sd,)
|
||||
if [ "$MVER" -ge 9 ]; then
|
||||
if grep ^ntpservers: /etc/confluent/confluent.deploycfg > /dev/null; then
|
||||
for ntpsrv in $(sed -n '/^ntpservers:/,/^[^-]/p' /etc/confluent/confluent.deploycfg|sed 1d|sed '$d' | sed -e 's/^- //'); do
|
||||
echo timesource --ntp-server $ntpsrv >> /tmp/timezone
|
||||
done
|
||||
fi
|
||||
else
|
||||
if grep ^ntpservers: /etc/confluent/confluent.deploycfg > /dev/null; then
|
||||
ntpsrvs="--ntpservers="$(sed -n '/^ntpservers:/,/^[^-]/p' /etc/confluent/confluent.deploycfg|sed 1d|sed '$d' | sed -e 's/^- //' | paste -sd,)
|
||||
fi
|
||||
fi
|
||||
echo timezone $ntpsrvs $tz --utc > /tmp/timezone
|
||||
echo timezone $ntpsrvs $tz --utc >> /tmp/timezone
|
||||
rootpw=$(grep ^rootpassword /etc/confluent/confluent.deploycfg | awk '{print $2}')
|
||||
if [ "$rootpw" = null ]; then
|
||||
echo "rootpw --lock" > /tmp/rootpw
|
||||
|
||||
@@ -69,7 +69,11 @@ if args[0] == 'restore':
|
||||
if options.interactivepassword:
|
||||
password = getpass.getpass('Enter password to restore backup: ')
|
||||
try:
|
||||
cfm.init(True)
|
||||
cfm.statelessmode = True
|
||||
cfm.restore_db_from_directory(dumpdir, password)
|
||||
cfm.statelessmode = False
|
||||
cfm.ConfigManager.wait_for_sync(True)
|
||||
if owner != 0:
|
||||
for targdir in os.walk('/etc/confluent'):
|
||||
os.chown(targdir[0], owner, group)
|
||||
|
||||
@@ -565,6 +565,8 @@ def _load_dict_from_dbm(dpath, tdb):
|
||||
currdict[tks] = cPickle.loads(dbe[tk]) # nosec
|
||||
tk = dbe.nextkey(tk)
|
||||
except dbm.error:
|
||||
if os.path.exists(tdb):
|
||||
raise
|
||||
return
|
||||
|
||||
|
||||
@@ -2604,7 +2606,13 @@ class ConfigManager(object):
|
||||
with _dirtylock:
|
||||
dirtyglobals = copy.deepcopy(_cfgstore['dirtyglobals'])
|
||||
del _cfgstore['dirtyglobals']
|
||||
globalf = dbm.open(os.path.join(cls._cfgdir, "globals"), 'c', 384) # 0600
|
||||
try:
|
||||
globalf = dbm.open(os.path.join(cls._cfgdir, "globals"), 'c', 384) # 0600
|
||||
except dbm.error:
|
||||
if not fullsync:
|
||||
raise
|
||||
os.remove(os.path.join(cls._cfgdir, "globals"))
|
||||
globalf = dbm.open(os.path.join(cls._cfgdir, "globals"), 'c', 384) # 0600
|
||||
try:
|
||||
for globalkey in dirtyglobals:
|
||||
if globalkey in _cfgstore['globals']:
|
||||
@@ -2617,8 +2625,15 @@ class ConfigManager(object):
|
||||
globalf.close()
|
||||
if fullsync or 'collectivedirty' in _cfgstore:
|
||||
if len(_cfgstore.get('collective', ())) > 1:
|
||||
collectivef = dbm.open(os.path.join(cls._cfgdir, "collective"),
|
||||
'c', 384)
|
||||
try:
|
||||
collectivef = dbm.open(os.path.join(cls._cfgdir, 'collective'),
|
||||
'c', 384)
|
||||
except dbm.error:
|
||||
if not fullsync:
|
||||
raise
|
||||
os.remove(os.path.join(cls._cfgdir, 'collective'))
|
||||
collectivef = dbm.open(os.path.join(cls._cfgdir, 'collective'),
|
||||
'c', 384)
|
||||
try:
|
||||
if fullsync:
|
||||
colls = _cfgstore['collective']
|
||||
@@ -2645,7 +2660,13 @@ class ConfigManager(object):
|
||||
currdict = _cfgstore['main']
|
||||
for category in currdict:
|
||||
_mkpath(pathname)
|
||||
dbf = dbm.open(os.path.join(pathname, category), 'c', 384) # 0600
|
||||
try:
|
||||
dbf = dbm.open(os.path.join(pathname, category), 'c', 384) # 0600
|
||||
except dbm.error:
|
||||
if not fullsync:
|
||||
raise
|
||||
os.remove(os.path.join(pathname, category))
|
||||
dbf = dbm.open(os.path.join(pathname, category), 'c', 384) # 0600
|
||||
try:
|
||||
for ck in currdict[category]:
|
||||
dbf[ck] = cPickle.dumps(currdict[category][ck], protocol=cPickle.HIGHEST_PROTOCOL)
|
||||
@@ -2665,7 +2686,13 @@ class ConfigManager(object):
|
||||
currdict = _cfgstore['tenant'][tenant]
|
||||
for category in dkdict:
|
||||
_mkpath(pathname)
|
||||
dbf = dbm.open(os.path.join(pathname, category), 'c', 384) # 0600
|
||||
try:
|
||||
dbf = dbm.open(os.path.join(pathname, category), 'c', 384) # 0600
|
||||
except dbm.error:
|
||||
if not fullsync:
|
||||
raise
|
||||
os.remove(os.path.join(pathname, category))
|
||||
dbf = dbm.open(os.path.join(pathname, category), 'c', 384) # 0600
|
||||
try:
|
||||
for ck in dkdict[category]:
|
||||
if ck not in currdict[category]:
|
||||
|
||||
@@ -429,6 +429,8 @@ def handle_api_request(configmanager, inputdata, operation, pathcomponents):
|
||||
return (msg.KeyValueData({'rescan': 'started'}),)
|
||||
|
||||
elif operation in ('update', 'create'):
|
||||
if pathcomponents == ['discovery', 'register']:
|
||||
return
|
||||
if 'node' not in inputdata:
|
||||
raise exc.InvalidArgumentException('Missing node name in input')
|
||||
mac = _get_mac_from_query(pathcomponents)
|
||||
|
||||
@@ -12,6 +12,7 @@
|
||||
# See the License for the specific language governing permissions and
|
||||
# limitations under the License.
|
||||
|
||||
import confluent.util as util
|
||||
import errno
|
||||
import eventlet
|
||||
import socket
|
||||
@@ -31,6 +32,17 @@ class NodeHandler(object):
|
||||
self.info = info
|
||||
self.configmanager = configmanager
|
||||
targsa = [None]
|
||||
self.ipaddr = None
|
||||
self.relay_url = None
|
||||
self.relay_server = None
|
||||
self.web_ip = None
|
||||
self.web_port = None
|
||||
# if this is a remote registered component, prefer to use the agent forwarder
|
||||
if info.get('forwarder_url', False):
|
||||
self.relay_url = info['forwarder_url']
|
||||
self.relay_server = info['forwarder_server']
|
||||
self.relay_token = info['forwarder_token']
|
||||
return
|
||||
# first let us prefer LLA if possible, since that's most stable
|
||||
for sa in info['addresses']:
|
||||
if sa[0].startswith('fe80'):
|
||||
@@ -103,11 +115,8 @@ class NodeHandler(object):
|
||||
def https_cert(self):
|
||||
if self._fp:
|
||||
return self._fp
|
||||
if ':' in self.ipaddr:
|
||||
ip = '[{0}]'.format(self.ipaddr)
|
||||
else:
|
||||
ip = self.ipaddr
|
||||
wc = webclient.SecureHTTPConnection(ip, verifycallback=self._savecert)
|
||||
ip, port = self.get_web_port_and_ip()
|
||||
wc = webclient.SecureHTTPConnection(ip, verifycallback=self._savecert, port=port)
|
||||
try:
|
||||
wc.connect()
|
||||
except IOError as ie:
|
||||
@@ -123,3 +132,32 @@ class NodeHandler(object):
|
||||
self._certfailreason = 2
|
||||
return None
|
||||
return self._fp
|
||||
|
||||
def get_web_port_and_ip(self):
|
||||
if self.web_ip:
|
||||
return self.web_ip, self.web_port
|
||||
# get target ip and port, either direct or relay as applicable
|
||||
if self.relay_url:
|
||||
kv = util.TLSCertVerifier(self.configmanager, self.relay_server,
|
||||
'pubkeys.tls_hardwaremanager').verify_cert
|
||||
w = webclient.SecureHTTPConnection(self.relay_server, verifycallback=kv)
|
||||
relaycreds = self.configmanager.get_node_attributes(self.relay_server, 'secret.*', decrypt=True)
|
||||
relaycreds = relaycreds.get(self.relay_server, {})
|
||||
relayuser = relaycreds.get('secret.hardwaremanagementuser', {}).get('value', None)
|
||||
relaypass = relaycreds.get('secret.hardwaremanegementpassword', {}).get('value', None)
|
||||
if not relayuser or not relaypass:
|
||||
raise Exception('No credentials for {0}'.format(self.relay_server))
|
||||
w.set_basic_credentials(relayuser, relaypass)
|
||||
w.connect()
|
||||
w.request('GET', self.relay_url)
|
||||
r = w.getresponse()
|
||||
rb = r.read()
|
||||
if r.code != 302:
|
||||
raise Exception('Unexpected return from forwarder')
|
||||
newurl = r.getheader('Location')
|
||||
self.web_port = int(newurl.rsplit(':', 1)[-1][:-1])
|
||||
self.web_ip = self.relay_server
|
||||
else:
|
||||
self.web_port = 443
|
||||
self.web_ip = self.ipaddr
|
||||
return self.web_ip, self.web_port
|
||||
|
||||
@@ -135,7 +135,8 @@ class NodeHandler(bmchandler.NodeHandler):
|
||||
{nodename: {'hardwaremanagement.manager': self.ipaddr}})
|
||||
|
||||
def _webconfigcreds(self, username, password):
|
||||
wc = webclient.SecureHTTPConnection(self.ipaddr, 443, verifycallback=self._validate_cert)
|
||||
ip, port = self.get_web_port_and_ip()
|
||||
wc = webclient.SecureHTTPConnection(ip, port, verifycallback=self._validate_cert)
|
||||
wc.connect()
|
||||
authdata = { # start by trying factory defaults
|
||||
'user': 'USERID',
|
||||
|
||||
@@ -67,7 +67,8 @@ class NodeHandler(immhandler.NodeHandler):
|
||||
return None
|
||||
|
||||
def scan(self):
|
||||
c = webclient.SecureHTTPConnection(self.ipaddr, 443,
|
||||
ip, port = self.get_web_port_and_ip()
|
||||
c = webclient.SecureHTTPConnection(ip, port,
|
||||
verifycallback=self.validate_cert)
|
||||
i = c.grab_json_response('/api/providers/logoninfo')
|
||||
modelname = i.get('items', [{}])[0].get('machine_name', None)
|
||||
@@ -279,8 +280,9 @@ class NodeHandler(immhandler.NodeHandler):
|
||||
isdefault = True
|
||||
errinfo = {}
|
||||
if self._wc is None:
|
||||
ip, port = self.get_web_port_and_ip()
|
||||
self._wc = webclient.SecureHTTPConnection(
|
||||
self.ipaddr, 443, verifycallback=self.validate_cert)
|
||||
ip, port, verifycallback=self.validate_cert)
|
||||
self._wc.connect()
|
||||
nodename = None
|
||||
if self.nodename:
|
||||
@@ -409,7 +411,21 @@ class NodeHandler(immhandler.NodeHandler):
|
||||
rsp, status = wc.grab_json_response_with_status(
|
||||
'/api/function',
|
||||
{'USER_UserModify': '{0},{1},,1,4,0,0,0,0,,8,,,'.format(uid, username)})
|
||||
if status == 200 and rsp.get('return', 0) == 13:
|
||||
wc.set_basic_credentials(self._currcreds[0], self._currcreds[1])
|
||||
status = 503
|
||||
while status != 200:
|
||||
rsp, status = wc.grab_json_response_with_status(
|
||||
'/redfish/v1/AccountService/Accounts/{0}'.format(uid),
|
||||
{'UserName': username}, method='PATCH')
|
||||
if status != 200:
|
||||
rsp = json.loads(rsp)
|
||||
if rsp.get('error', {}).get('code', 'Unknown') in ('Base.1.8.GeneralError', 'Base.1.12.GeneralError'):
|
||||
eventlet.sleep(10)
|
||||
else:
|
||||
break
|
||||
self.tmppasswd = None
|
||||
wc.grab_json_response('/api/providers/logout')
|
||||
self._currcreds = (username, passwd)
|
||||
|
||||
def _convert_sha256account(self, user, passwd, wc):
|
||||
@@ -501,6 +517,7 @@ class NodeHandler(immhandler.NodeHandler):
|
||||
'Request to use default credentials, but refused by target after it has been changed to {0}'.format(self.tmppasswd))
|
||||
if not isdefault:
|
||||
self._setup_xcc_account(user, passwd, wc)
|
||||
wc = self.wc
|
||||
self._convert_sha256account(user, passwd, wc)
|
||||
cd = self.configmanager.get_node_attributes(
|
||||
nodename, ['secret.hardwaremanagementuser',
|
||||
@@ -519,6 +536,20 @@ class NodeHandler(immhandler.NodeHandler):
|
||||
_, _ = nwc.grab_json_response_with_status(
|
||||
'/redfish/v1/Managers/1/NetworkProtocol',
|
||||
{'IPMI': {'ProtocolEnabled': True}}, method='PATCH')
|
||||
rsp, status = nwc.grab_json_response_with_status(
|
||||
'/redfish/v1/AccountService/Accounts/1')
|
||||
if status == 200:
|
||||
allowable = rsp.get('AccountTypes@Redfish.AllowableValues', [])
|
||||
current = rsp.get('AccountTypes', [])
|
||||
if 'IPMI' in allowable and 'IPMI' not in current:
|
||||
current.append('IPMI')
|
||||
updateinf = {
|
||||
'AccountTypes': current,
|
||||
'Password': self._currcreds[1]
|
||||
}
|
||||
rsp, status = nwc.grab_json_response_with_status(
|
||||
'/redfish/v1/AccountService/Accounts/1',
|
||||
updateinf, method='PATCH')
|
||||
if ('hardwaremanagement.manager' in cd and
|
||||
cd['hardwaremanagement.manager']['value'] and
|
||||
not cd['hardwaremanagement.manager']['value'].startswith(
|
||||
|
||||
@@ -29,6 +29,10 @@ import atexit
|
||||
import confluent.auth as auth
|
||||
import confluent.config.conf as conf
|
||||
import confluent.config.configmanager as configmanager
|
||||
try:
|
||||
import anydbm as dbm
|
||||
except ModuleNotFoundError:
|
||||
import dbm
|
||||
import confluent.consoleserver as consoleserver
|
||||
import confluent.core as confluentcore
|
||||
import confluent.httpapi as httpapi
|
||||
@@ -62,8 +66,10 @@ import os
|
||||
import glob
|
||||
import signal
|
||||
import socket
|
||||
import subprocess
|
||||
import time
|
||||
import traceback
|
||||
import tempfile
|
||||
import uuid
|
||||
|
||||
|
||||
@@ -232,8 +238,21 @@ def sanity_check():
|
||||
assure_ownership('/etc/confluent/srvcert.pem')
|
||||
|
||||
|
||||
def migrate_db():
|
||||
tdir = tempfile.mkdtemp()
|
||||
subprocess.check_call(['python3', '-c', 'pass'])
|
||||
subprocess.check_call(['python2', '/opt/confluent/bin/confluentdbutil', 'dump', '-u', tdir])
|
||||
subprocess.check_call(['python3', '/opt/confluent/bin/confluentdbutil', 'restore', '-u', tdir])
|
||||
subprocess.check_call(['rm', '-rf', tdir])
|
||||
configmanager.init()
|
||||
|
||||
|
||||
def run(args):
|
||||
setlimits()
|
||||
try:
|
||||
configmanager.ConfigManager(None)
|
||||
except dbm.error:
|
||||
migrate_db()
|
||||
try:
|
||||
signal.signal(signal.SIGUSR1, dumptrace)
|
||||
except AttributeError:
|
||||
|
||||
@@ -124,19 +124,21 @@ class SshShell(conapi.Console):
|
||||
self.ssh.set_missing_host_key_policy(
|
||||
HostKeyHandler(self.nodeconfig, self.node))
|
||||
try:
|
||||
self.datacallback('\r\nConnecting to {}...'.format(self.node))
|
||||
self.ssh.connect(self.node, username=self.username,
|
||||
password=self.password, allow_agent=False,
|
||||
look_for_keys=False)
|
||||
except paramiko.AuthenticationException:
|
||||
except paramiko.AuthenticationException as e:
|
||||
self.ssh.close()
|
||||
self.inputmode = 0
|
||||
self.username = b''
|
||||
self.password = b''
|
||||
self.datacallback('\r\nError connecting to {0}:\r\n {1}\r\n'.format(self.node, str(e)))
|
||||
self.datacallback('\r\nlogin as: ')
|
||||
return
|
||||
except paramiko.ssh_exception.NoValidConnectionsError as e:
|
||||
self.ssh.close()
|
||||
self.datacallback(str(e))
|
||||
self.datacallback('\r\nError connecting to {0}:\r\n {1}\r\n'.format(self.node, str(e)))
|
||||
self.inputmode = 0
|
||||
self.username = b''
|
||||
self.password = b''
|
||||
@@ -162,10 +164,20 @@ class SshShell(conapi.Console):
|
||||
'and permissions on /etc/ssh/*key)\r\n' \
|
||||
'Press Enter to close...'
|
||||
self.datacallback('\r\n' + warn)
|
||||
|
||||
return
|
||||
except Exception as e:
|
||||
self.ssh.close()
|
||||
self.ssh.close()
|
||||
self.inputmode = 0
|
||||
self.username = b''
|
||||
self.password = b''
|
||||
warn = 'Error connecting to {0}:\r\n {1}\r\n'.format(self.node, str(e))
|
||||
self.datacallback('\r\n' + warn)
|
||||
self.datacallback('\r\nlogin as: ')
|
||||
return
|
||||
self.inputmode = 2
|
||||
self.connected = True
|
||||
self.datacallback('Connected\r\n')
|
||||
self.shell = self.ssh.invoke_shell(width=self.width,
|
||||
height=self.height)
|
||||
self.rxthread = eventlet.spawn(self.recvdata)
|
||||
|
||||
@@ -10,6 +10,7 @@ import eventlet.green.socket as socket
|
||||
import eventlet.green.subprocess as subprocess
|
||||
import confluent.discovery.handlers.xcc as xcc
|
||||
import confluent.discovery.handlers.tsm as tsm
|
||||
import confluent.discovery.core as disco
|
||||
import base64
|
||||
import hmac
|
||||
import hashlib
|
||||
@@ -112,7 +113,6 @@ def handle_request(env, start_response):
|
||||
start_response('401', [])
|
||||
yield 'Unauthorized'
|
||||
return
|
||||
|
||||
ea = cfg.get_node_attributes(nodename, ['crypted.selfapikey', 'deployment.apiarmed'])
|
||||
eak = ea.get(
|
||||
nodename, {}).get('crypted.selfapikey', {}).get('hashvalue', None)
|
||||
@@ -152,6 +152,16 @@ def handle_request(env, start_response):
|
||||
operation = env['REQUEST_METHOD']
|
||||
if operation not in ('HEAD', 'GET') and 'CONTENT_LENGTH' in env and int(env['CONTENT_LENGTH']) > 0:
|
||||
reqbody = env['wsgi.input'].read(int(env['CONTENT_LENGTH']))
|
||||
if env['PATH_INFO'] == '/self/register_discovered':
|
||||
rb = json.loads(reqbody)
|
||||
addrs = rb.get('addresses', [])
|
||||
rb['addresses'] = []
|
||||
for addr in addrs:
|
||||
rb['addresses'].append(tuple(addr))
|
||||
disco.detected(rb)
|
||||
start_response('200 OK', [])
|
||||
yield 'Registered'
|
||||
return
|
||||
if env['PATH_INFO'] == '/self/bmcconfig':
|
||||
hmattr = cfg.get_node_attributes(nodename, 'hardwaremanagement.*')
|
||||
hmattr = hmattr.get(nodename, {})
|
||||
|
||||
@@ -41,6 +41,10 @@ class _ShellHandler(consoleserver.ConsoleHandler):
|
||||
return
|
||||
#return super().feedbuffer(data)
|
||||
|
||||
def get_recent(self):
|
||||
retdata, connstate = super(_ShellHandler, self).get_recent()
|
||||
return '', connstate
|
||||
|
||||
def _got_disconnected(self):
|
||||
self.connectstate = 'closed'
|
||||
self._send_rcpts({'connectstate': self.connectstate})
|
||||
|
||||
@@ -13,13 +13,17 @@ BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-buildroot
|
||||
Prefix: %{_prefix}
|
||||
BuildArch: noarch
|
||||
Requires: confluent_vtbufferd
|
||||
%if "%{dist}" == ".el7"
|
||||
Requires: python-pyghmi >= 1.0.34, python-eventlet, python-greenlet, python-pycryptodomex >= 3.4.7, confluent_client == %{version}, python-pyparsing, python-paramiko, python-dnspython, python-netifaces, python2-pyasn1 >= 0.2.3, python-pysnmp >= 4.3.4, python-lxml, python-eficompressor, python-setuptools, python-dateutil, python2-websocket-client python2-msgpack python-libarchive-c python-yaml python-monotonic
|
||||
%else
|
||||
%if "%{dist}" == ".el8"
|
||||
Requires: python3-pyghmi >= 1.0.34, python3-eventlet, python3-greenlet, python3-pycryptodomex >= 3.4.7, confluent_client == %{version}, python3-pyparsing, python3-paramiko, python3-dns, python3-netifaces, python3-pyasn1 >= 0.2.3, python3-pysnmp >= 4.3.4, python3-lxml, python3-eficompressor, python3-setuptools, python3-dateutil, python3-enum34, python3-asn1crypto, python3-cffi, python3-pyOpenSSL, python3-monotonic, python3-websocket-client python3-msgpack python3-libarchive-c python3-yaml openssl iproute
|
||||
%else
|
||||
%if "%{dist}" == ".el9"
|
||||
Requires: python3-pyghmi >= 1.0.34, python3-eventlet, python3-greenlet, python3-pycryptodomex >= 3.4.7, confluent_client == %{version}, python3-pyparsing, python3-paramiko, python3-dns, python3-netifaces, python3-pyasn1 >= 0.2.3, python3-pysnmp >= 4.3.4, python3-lxml, python3-eficompressor, python3-setuptools, python3-dateutil, python3-cffi, python3-pyOpenSSL, python3-websocket-client python3-msgpack python3-libarchive-c python3-yaml openssl iproute
|
||||
%else
|
||||
Requires: python-pyghmi >= 1.0.34, python-eventlet, python-greenlet, python-pycryptodomex >= 3.4.7, confluent_client == %{version}, python-pyparsing, python-paramiko, python-dnspython, python-netifaces, python2-pyasn1 >= 0.2.3, python-pysnmp >= 4.3.4, python-lxml, python-eficompressor, python-setuptools, python-dateutil, python2-websocket-client python2-msgpack python-libarchive-c python-yaml python-monotonic
|
||||
Requires: python3-pyghmi >= 1.0.34, python3-eventlet, python3-greenlet, python3-pycryptodome >= 3.4.7, confluent_client == %{version}, python3-pyparsing, python3-paramiko, python3-dnspython, python3-netifaces, python3-pyasn1 >= 0.2.3, python3-pysnmp >= 4.3.4, python3-lxml, python3-eficompressor, python3-setuptools, python3-dateutil, python3-cffi, python3-pyOpenSSL, python3-websocket-client python3-msgpack python3-libarchive-c python3-PyYAML openssl iproute
|
||||
%endif
|
||||
%endif
|
||||
%endif
|
||||
Vendor: Jarrod Johnson <jjohnson2@lenovo.com>
|
||||
@@ -32,25 +36,17 @@ Server for console management and systems management aggregation
|
||||
%setup -n %{name}-%{version} -n %{name}-%{version}
|
||||
|
||||
%build
|
||||
%if "%{dist}" == ".el8"
|
||||
python3 setup.py build
|
||||
%else
|
||||
%if "%{dist}" == ".el9"
|
||||
python3 setup.py build
|
||||
%else
|
||||
%if "%{dist}" == ".el7"
|
||||
python2 setup.py build
|
||||
%endif
|
||||
%else
|
||||
python3 setup.py build
|
||||
%endif
|
||||
|
||||
%install
|
||||
%if "%{dist}" == ".el8"
|
||||
python3 setup.py install --single-version-externally-managed -O1 --root=$RPM_BUILD_ROOT --record=INSTALLED_FILES.bare --install-purelib=/opt/confluent/lib/python --install-scripts=/opt/confluent/bin
|
||||
%else
|
||||
%if "%{dist}" == ".el9"
|
||||
python3 setup.py install --single-version-externally-managed -O1 --root=$RPM_BUILD_ROOT --record=INSTALLED_FILES.bare --install-purelib=/opt/confluent/lib/python --install-scripts=/opt/confluent/bin
|
||||
%else
|
||||
%if "%{dist}" == ".el7"
|
||||
python2 setup.py install --single-version-externally-managed -O1 --root=$RPM_BUILD_ROOT --record=INSTALLED_FILES.bare --install-purelib=/opt/confluent/lib/python --install-scripts=/opt/confluent/bin
|
||||
%endif
|
||||
%else
|
||||
python3 setup.py install --single-version-externally-managed -O1 --root=$RPM_BUILD_ROOT --record=INSTALLED_FILES.bare --install-purelib=/opt/confluent/lib/python --install-scripts=/opt/confluent/bin
|
||||
%endif
|
||||
for file in $(grep confluent/__init__.py INSTALLED_FILES.bare); do
|
||||
rm $RPM_BUILD_ROOT/$file
|
||||
@@ -101,3 +97,4 @@ rm -rf $RPM_BUILD_ROOT
|
||||
%files -f INSTALLED_FILES
|
||||
%license /opt/confluent/share/licenses/confluent_server/LICENSE
|
||||
%defattr(-,root,root)
|
||||
/opt/confluent
|
||||
|
||||
@@ -0,0 +1,10 @@
|
||||
import confluent.config.configmanager as cfm
|
||||
import sys
|
||||
c = cfm.ConfigManager(None)
|
||||
cfg = c.get_node_attributes(sys.argv[1], 'secret.*', decrypt=True)
|
||||
for node in cfg:
|
||||
for attr in cfg[node]:
|
||||
val = cfg[node][attr]['value']
|
||||
if not isinstance(val, str):
|
||||
val = val.decode('utf8')
|
||||
print('{}: {}'.format(attr, val))
|
||||
+18
@@ -0,0 +1,18 @@
|
||||
DEVICES="/dev/sda /dev/sdb"
|
||||
RAIDLEVEL=1
|
||||
mdadm --detail /dev/md*|grep 'Version : 1.0' >& /dev/null && exit 0
|
||||
lvm vgchange -a n
|
||||
mdadm -S -s
|
||||
NUMDEVS=$(for dev in $DEVICES; do
|
||||
echo wipefs -a $dev
|
||||
done|wc -l)
|
||||
for dev in $DEVICES; do
|
||||
wipefs -a $dev
|
||||
done
|
||||
# must use older metadata format to leave disks looking normal for uefi
|
||||
mdadm -C /dev/md/raid $DEVICES -n $NUMDEVS -e 1.0 -l $RAIDLEVEL
|
||||
# shut and restart array to prime things for anaconda
|
||||
mdadm -S -s
|
||||
mdadm --assemble --scan
|
||||
readlink /dev/md/raid|sed -e 's/.*\///' > /tmp/installdisk
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
DEVICES="/dev/sda /dev/sdb"
|
||||
RAIDLEVEL=1
|
||||
mdadm --detail /dev/md* | grep imsm >& /dev/null && exit 0
|
||||
lvm vgchange -a n
|
||||
mdadm -S -s
|
||||
NUMDEVS=$(for dev in $DEVICES; do
|
||||
echo wipefs -a $dev
|
||||
done|wc -l)
|
||||
for dev in $DEVICES; do
|
||||
wipefs -a $dev
|
||||
done
|
||||
mdadm -C /dev/md/imsm0 $DEVICES -n $NUMDEVS -e imsm
|
||||
mdadm -C /dev/md/md0_0 /dev/md/imsm0 -n $NUMDEVS -l $RAIDLEVEL
|
||||
mdadm -S -s
|
||||
mdadm --assemble --scan
|
||||
Reference in New Issue
Block a user