mirror of
https://github.com/xcat2/confluent.git
synced 2026-09-29 08:41:00 +00:00
Compare commits
6 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| dec118a985 | |||
| 38eb0d7b10 | |||
| ae338daa43 | |||
| 6ad3f0d70c | |||
| c0b9bb3ab1 | |||
| b32755b0d3 |
@@ -391,8 +391,13 @@ class Command(object):
|
||||
cacert = None
|
||||
certreqs = ssl.CERT_NONE
|
||||
knownhosts = True
|
||||
self.connection = ssl.wrap_socket(self.connection, ca_certs=cacert,
|
||||
cert_reqs=certreqs)
|
||||
tlsctx = ssl.create_default_context()
|
||||
if certreqs == ssl.CERT_NONE:
|
||||
tlsctx.check_hostname = False
|
||||
tlsctx.verify_mode = certreqs
|
||||
if cacert:
|
||||
tlsctx.load_verify_locations(cacert)
|
||||
self.connection = tlsctx.wrap_socket(self.connection, server_hostname=server)
|
||||
if knownhosts:
|
||||
certdata = self.connection.getpeercert(binary_form=True)
|
||||
fingerprint = 'sha512$' + hashlib.sha512(certdata).hexdigest()
|
||||
|
||||
@@ -31,7 +31,7 @@ cp -a debian debian13
|
||||
mkdir -p debian13/initramfs/usr
|
||||
mv debian13/initramfs/lib debian13/initramfs/usr/
|
||||
mv el10/initramfs/usr el10/initramfs/var
|
||||
for os in rhvh4 el7 genesis el8 suse15 debian debian13 ubuntu20.04 ubuntu22.04 ubuntu24.04 coreos el9 el10; do
|
||||
for os in rhvh4 el7 genesis el8 suse15 debian debian13 ubuntu20.04 ubuntu22.04 ubuntu24.04 ubuntu26.04 coreos el9 el10; do
|
||||
mkdir ${os}out
|
||||
cd ${os}out
|
||||
if [ -d ../${os}bin ]; then
|
||||
@@ -88,7 +88,7 @@ mkdir -p %{buildroot}/opt/confluent/share/licenses/confluent_osdeploy/
|
||||
mkdir -p %{buildroot}/opt/confluent/lib/osdeploy/common
|
||||
cp common/initramfs/opt/confluent/bin/apiclient %{buildroot}/opt/confluent/lib/osdeploy/common
|
||||
|
||||
for os in rhvh4 el7 el8 el9 el10 debian debian13 genesis suse15 ubuntu20.04 ubuntu22.04 ubuntu24.04 esxi6 esxi7 esxi8 coreos; do
|
||||
for os in rhvh4 el7 el8 el9 el10 debian debian13 genesis suse15 ubuntu20.04 ubuntu22.04 ubuntu24.04 ubuntu26.04 esxi6 esxi7 esxi8 coreos; do
|
||||
mkdir -p %{buildroot}/opt/confluent/lib/osdeploy/$os/initramfs/aarch64/
|
||||
cp ${os}out/addons.* %{buildroot}/opt/confluent/lib/osdeploy/$os/initramfs/aarch64/
|
||||
if [ -d ${os}disklessout ]; then
|
||||
|
||||
@@ -33,7 +33,7 @@ cp -a debian debian13
|
||||
mkdir -p debian13/initramfs/usr
|
||||
mv debian13/initramfs/lib debian13/initramfs/usr/
|
||||
mv el10/initramfs/usr el10/initramfs/var
|
||||
for os in rhvh4 el7 genesis el8 suse15 debian debian13 ubuntu18.04 ubuntu20.04 ubuntu22.04 ubuntu24.04 coreos el9 el10; do
|
||||
for os in rhvh4 el7 genesis el8 suse15 debian debian13 ubuntu18.04 ubuntu20.04 ubuntu22.04 ubuntu24.04 ubuntu26.04 coreos el9 el10; do
|
||||
mkdir ${os}out
|
||||
cd ${os}out
|
||||
if [ -d ../${os}bin ]; then
|
||||
@@ -49,7 +49,7 @@ for os in rhvh4 el7 genesis el8 suse15 debian debian13 ubuntu18.04 ubuntu20.04 u
|
||||
mv ../addons.cpio .
|
||||
cd ..
|
||||
done
|
||||
for os in el7 el8 suse15 el9 el10 ubuntu20.04 ubuntu22.04 ubuntu24.04; do
|
||||
for os in el7 el8 suse15 el9 el10 ubuntu20.04 ubuntu22.04 ubuntu24.04 ubuntu26.04; do
|
||||
mkdir ${os}disklessout
|
||||
cd ${os}disklessout
|
||||
if [ -d ../${os}bin ]; then
|
||||
@@ -89,7 +89,7 @@ cp -a esxi7 esxi9
|
||||
%install
|
||||
mkdir -p %{buildroot}/opt/confluent/share/licenses/confluent_osdeploy/
|
||||
cp LICENSE %{buildroot}/opt/confluent/share/licenses/confluent_osdeploy/
|
||||
for os in rhvh4 el7 el8 el9 el10 genesis suse15 ubuntu20.04 debian debian13 ubuntu18.04 ubuntu22.04 ubuntu24.04 esxi6 esxi7 esxi8 esxi9 coreos; do
|
||||
for os in rhvh4 el7 el8 el9 el10 genesis suse15 ubuntu20.04 debian debian13 ubuntu18.04 ubuntu22.04 ubuntu24.04 ubuntu26.04 esxi6 esxi7 esxi8 esxi9 coreos; do
|
||||
mkdir -p %{buildroot}/opt/confluent/lib/osdeploy/$os/initramfs
|
||||
mkdir -p %{buildroot}/opt/confluent/lib/osdeploy/$os/profiles
|
||||
cp ${os}out/addons.* %{buildroot}/opt/confluent/lib/osdeploy/$os/initramfs
|
||||
|
||||
@@ -37,10 +37,20 @@ else
|
||||
chroot . custom-installation/confluent/bin/clortho $NODENAME $MGR > /root/custom-installation/confluent/confluent.apikey
|
||||
APIKEY=$(cat /root/custom-installation/confluent/confluent.apikey)
|
||||
done
|
||||
MGR=[$MGR]
|
||||
nic=$(grep ^MANAGER /custom-installation/confluent/confluent.info|grep fe80::|sed -e s/.*%//|head -n 1)
|
||||
nic=$(ip link |grep ^$nic:|awk '{print $2}')
|
||||
DEVICE=${nic%:}
|
||||
if echo "$MGR" | grep -q ':'; then
|
||||
# IPv6 manager: wrap address in brackets and resolve interface from scoped manager entry.
|
||||
MGR=[$MGR]
|
||||
nic=$(grep ^MANAGER /custom-installation/confluent/confluent.info|grep fe80::|sed -e s/.*%//|head -n 1)
|
||||
nic=$(ip link |grep ^$nic:|awk '{print $2}')
|
||||
DEVICE=${nic%:}
|
||||
else
|
||||
# IPv4 routed deployment: use previously detected NIC, fallback to route lookup.
|
||||
if [ -f /tmp/autodetectnic ]; then
|
||||
DEVICE=$(cat /tmp/autodetectnic)
|
||||
else
|
||||
DEVICE=$(ip route get ${MGR} 2>/dev/null | head -1 | sed -n 's/.*dev \([^ ]*\).*/\1/p')
|
||||
fi
|
||||
fi
|
||||
IP=done
|
||||
fi
|
||||
if [ -z "$MGTIFACE" ]; then
|
||||
|
||||
@@ -97,6 +97,62 @@ while ! grep NODENAME /custom-installation/confluent/confluent.info; do
|
||||
echo -n $(grep ^apitoken: cnflnt.yml|awk '{print $2}') > $hmackeyfile
|
||||
cd -
|
||||
umount $tmnt
|
||||
elif confluentsrv=$(sed -n 's/.*confluent=\([^ ]*\).*/\1/p' /proc/cmdline); [ ! -z "$confluentsrv" ]; then
|
||||
echo "confluent= kernel arg found: $confluentsrv" > /dev/console 2>&1
|
||||
. /scripts/functions
|
||||
|
||||
rmmod cdc_ether 2> /dev/null
|
||||
rm -rf /run/net* /run/dhcpcd /var/lib/dhcpcd
|
||||
for dev in $(ip a|grep MULTICAST|awk '{print $2}'|sed -e s/://); do
|
||||
ip a flush $dev
|
||||
echo 1 > /proc/sys/net/ipv6/conf/$dev/addr_gen_mode 2>/dev/null
|
||||
echo 0 > /proc/sys/net/ipv6/conf/$dev/addr_gen_mode 2>/dev/null
|
||||
done
|
||||
unset DEVICE DEVICE6 IP IP6 dev
|
||||
|
||||
echo "Starting DHCP configure_networking..." > /dev/console 2>&1
|
||||
configure_networking
|
||||
echo "DHCP done, DEVICE=$DEVICE" > /dev/console 2>&1
|
||||
echo $DEVICE > /tmp/autodetectnic
|
||||
|
||||
RETRIES=0
|
||||
while [ $RETRIES -lt 5 ]; do
|
||||
if openssl s_client -connect $confluentsrv:443 </dev/null > /dev/null 2>&1; then
|
||||
echo "TLS connectivity to $confluentsrv OK" > /dev/console 2>&1
|
||||
break
|
||||
fi
|
||||
RETRIES=$((RETRIES + 1))
|
||||
echo "Cannot reach $confluentsrv:443, retry $RETRIES/5..." > /dev/console 2>&1
|
||||
sleep 3
|
||||
done
|
||||
|
||||
if [ $RETRIES -ge 5 ]; then
|
||||
echo "Failed to reach $confluentsrv after 5 retries, falling back to copernicus" > /dev/console 2>&1
|
||||
/opt/confluent/bin/copernicus -t > /custom-installation/confluent/confluent.info
|
||||
continue
|
||||
fi
|
||||
|
||||
myids="uuid=$(cat /sys/devices/virtual/dmi/id/product_uuid)"
|
||||
for mac in $(ip link | grep 'link/ether' | awk '{print $2}'); do
|
||||
myids="$myids/mac=$mac"
|
||||
done
|
||||
echo "Calling whoami with IDs: $myids" > /dev/console 2>&1
|
||||
|
||||
myname=$( (printf "GET /confluent-api/self/whoami HTTP/1.0\r\nHost: $confluentsrv\r\nCONFLUENT_IDS: $myids\r\n\r\n"; sleep 3) \
|
||||
| openssl s_client -connect $confluentsrv:443 -quiet 2>/dev/null \
|
||||
| tail -1 | tr -d '\r\n')
|
||||
|
||||
echo "whoami returned: '$myname'" > /dev/console 2>&1
|
||||
|
||||
if [ ! -z "$myname" ]; then
|
||||
MGR=$confluentsrv
|
||||
echo "NODENAME: $myname" > /custom-installation/confluent/confluent.info
|
||||
echo "MANAGER: $confluentsrv" >> /custom-installation/confluent/confluent.info
|
||||
echo "EXTMGRINFO: $confluentsrv||1" >> /custom-installation/confluent/confluent.info
|
||||
else
|
||||
echo "whoami returned empty, retrying in 10s..." > /dev/console 2>&1
|
||||
sleep 10
|
||||
fi
|
||||
else
|
||||
/opt/confluent/bin/copernicus -t > /custom-installation/confluent/confluent.info
|
||||
fi
|
||||
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
ubuntu22.04/
|
||||
+1
@@ -0,0 +1 @@
|
||||
ubuntu20.04-diskless/
|
||||
@@ -373,7 +373,7 @@ def _rpc_rename_nodes(tenant, renamemap):
|
||||
|
||||
|
||||
def _rpc_rename_nodegroups(tenant, renamemap):
|
||||
ConfigManager(tenant)._true_rename_nodegroups(renamemap)
|
||||
ConfigManager(tenant)._true_rename_groups(renamemap)
|
||||
|
||||
|
||||
def _rpc_set_group_attributes(tenant, attribmap, autocreate):
|
||||
|
||||
+1
-1
@@ -214,7 +214,7 @@ def capture_remote(args):
|
||||
subprocess.check_call(['rsync', __file__, '{0}:/run/imgutil/capenv/'.format(targ)])
|
||||
finfo = subprocess.check_output(['ssh', targ, 'python3', '/run/imgutil/capenv/imgutil', 'getfingerprint']).decode('utf8')
|
||||
finfo = json.loads(finfo)
|
||||
if finfo['oscategory'] not in ('el8', 'el9', 'ubuntu20.04', 'ubuntu22.04'):
|
||||
if finfo['oscategory'] not in ('el8', 'el9', 'ubuntu20.04', 'ubuntu22.04', 'ubuntu24.04', 'ubuntu26.04'):
|
||||
sys.stderr.write('Not yet supported for capture: ' + repr(finfo) + '\n')
|
||||
sys.exit(1)
|
||||
unmet = finfo.get('unmetprereqs', [])
|
||||
|
||||
+1
-1
@@ -12,7 +12,7 @@ fi
|
||||
OLDINSECURE=$(nodeattrib $TARGNODE deployment.useinsecureprotocols -b 2> /dev/null |grep -v inherited|awk '{print $3}')
|
||||
nodedefine $TARGNODE deployment.profile=$TARGPROF deployment.useinsecureprotocols= deployment.pendingprofile=$TARGPROF
|
||||
confetty set /nodes/$TARGNODE/deployment/ident_image=create
|
||||
REMTMP=$(ssh $TARGNODE $(mktemp -d))
|
||||
REMTMP=$(ssh $TARGNODE mktemp -d)
|
||||
scp /var/lib/confluent/private/identity_files/$TARGNODE.json $TARGNODE:$REMTMP
|
||||
rm /var/lib/confluent/private/identity_files/$TARGNODE.*
|
||||
rm /var/lib/confluent/private/identity_images/$TARGNODE.*
|
||||
|
||||
+1
-1
@@ -19,7 +19,7 @@ if [ "$FWACTIVE" == 1 ]; then systemctl stop firewalld; fi
|
||||
opt/confluent/bin/copernicus > /etc/confluent/confluent.info
|
||||
#opt/confluent/bin/clortho $TARGNODE $DEPLOYSRV > /etc/confluent/confluent.apikey
|
||||
. /etc/confluent/functions
|
||||
confluentpython opt/confluent/bin/apiclient -i $TAGRIDENT /confluent-api/self/deploycfg2 > /etc/confluent/confluent.deploycfg
|
||||
confluentpython opt/confluent/bin/apiclient -i $TARGIDENT /confluent-api/self/deploycfg2 > /etc/confluent/confluent.deploycfg
|
||||
if [ "$FWACTIVE" == 1 ]; then systemctl start firewalld; fi
|
||||
cp opt/confluent/bin/apiclient /opt/confluent/bin
|
||||
#curl -sg -H "CONFLUENT_APIKEY: $(cat /etc/confluent/confluent.apikey)" -H "CONFLUENT_NODENAME: $TARGNODE" https://$UDEPLOYSRV/confluent-api/self/deploycfg2 > /etc/confluent/confluent.deploycfg
|
||||
|
||||
Reference in New Issue
Block a user