4 LIBDIR="$(dirname "$(dirname "$(dirname "$PWD")")")"
8 source $LIBDIR/env/lib/common.sh
10 if [[ $EUID -ne 0 ]]; then
11 echo "This script must be run as root"
15 IMAGE_URL=http://172.22.0.1/images/${BM_IMAGE}
16 IMAGE_CHECKSUM=http://172.22.0.1/images/${BM_IMAGE}.md5sum
18 function clone_repos {
20 if [[ -d ${BMOPATH} && "${FORCE_REPO_UPDATE}" == "true" ]]; then
23 if [ ! -d "${BMOPATH}" ] ; then
25 git clone "${BMOREPO}"
29 git checkout "${BMOBRANCH}"
34 function get_default_interface_ipaddress {
36 local _default_interface=$(awk '$2 == 00000000 { print $1 }' /proc/net/route)
37 local _ipv4address=$(ip addr show dev $_default_interface | awk '$1 == "inet" { sub("/.*", "", $2); print $2 }')
38 eval $_ip="'$_ipv4address'"
41 function create_ssh_key {
42 #ssh key for compute node to communicate back to bootstrap server
43 mkdir -p $BUILD_DIR/ssh_key
44 ssh-keygen -C "compute.icn.akraino.lfedge.org" -f $BUILD_DIR/ssh_key/id_rsa
45 cat $BUILD_DIR/ssh_key/id_rsa.pub >> $HOME/.ssh/authorized_keys
48 function set_compute_key {
49 _SSH_LOCAL_KEY=$(cat $BUILD_DIR/ssh_key/id_rsa)
52 - path: /opt/ssh_id_rsa
60 function deprovision_compute_node {
62 if kubectl get baremetalhost $name -n metal3 &>/dev/null; then
63 kubectl patch baremetalhost $name -n metal3 --type merge \
64 -p '{"spec":{"image":{"url":"","checksum":""}}}'
68 function set_compute_ssh_config {
69 get_default_interface_ipaddress default_addr
71 - path: /root/.ssh/config
75 Host bootstrapmachine $default_addr
76 HostName $default_addr
77 IdentityFile /opt/ssh_id_rsa
79 - path: /etc/apt/sources.list
83 deb [trusted=yes] ssh://$USER@$default_addr:$LOCAL_APT_REPO ./
87 # documentation for the values below may be found at
88 # https://cloudinit.readthedocs.io/en/latest/topics/modules.html
89 function create_userdata {
93 COMPUTE_NODE_FQDN="$name.akraino.icn.org"
95 # validate that the user isn't expecting the deprecated
96 # COMPUTE_NODE_PASSWORD to be used
97 if [ "$password" != "${COMPUTE_NODE_PASSWORD:-$password}" ]; then
99 COMPUTE_NODE_PASSWORD "$COMPUTE_NODE_PASSWORD" not equal to nodes.json $name password "$password".
100 Unset COMPUTE_NODE_PASSWORD and retry.
105 printf "#cloud-config\n" > $name-userdata.yaml
106 if [ -n "$password" ]; then
107 if [ -n "$username" ]; then
108 passwd=$(mkpasswd --method=SHA-512 --rounds 4096 "$password")
109 printf "users:" >> $name-userdata.yaml
110 printf "\n - name: ""%s" "$username" >> $name-userdata.yaml
111 printf "\n lock_passwd: False" >> $name-userdata.yaml # necessary to allow password login
112 printf "\n passwd: ""%s" "$passwd" >> $name-userdata.yaml
113 printf "\n sudo: \"ALL=(ALL) NOPASSWD:ALL\"" >> $name-userdata.yaml
115 printf "password: ""%s" "$password" >> $name-userdata.yaml
117 printf "\nchpasswd: {expire: False}\n" >> $name-userdata.yaml
118 printf "ssh_pwauth: True\n" >> $name-userdata.yaml
121 if [ -n "$COMPUTE_NODE_FQDN" ]; then
122 printf "fqdn: ""%s" "$COMPUTE_NODE_FQDN" >> $name-userdata.yaml
123 printf "\n" >> $name-userdata.yaml
125 printf "disable_root: false\n" >> $name-userdata.yaml
126 printf "ssh_authorized_keys:\n - " >> $name-userdata.yaml
128 if [ ! -f $HOME/.ssh/id_rsa.pub ]; then
129 yes y | ssh-keygen -t rsa -N "" -f $HOME/.ssh/id_rsa
132 cat $HOME/.ssh/id_rsa.pub >> $name-userdata.yaml
133 cloud_init_scripts >> $name-userdata.yaml
134 printf "\n" >> $name-userdata.yaml
137 create_networkdata() {
139 node_networkdata $name > $name-networkdata.json
142 function launch_baremetal_operator {
143 docker pull $IRONIC_BAREMETAL_IMAGE
144 kubectl apply -f bmo/namespace/namespace.yaml
145 kubectl apply -f bmo/rbac/service_account.yaml -n metal3
146 kubectl apply -f bmo/rbac/role.yaml -n metal3
147 kubectl apply -f bmo/rbac/role_binding.yaml
148 kubectl apply -f bmo/crds/metal3.io_baremetalhosts_crd.yaml
149 kubectl apply -f bmo/operator/no_ironic/operator.yaml -n metal3
152 function remove_baremetal_operator {
153 kubectl delete -f bmo/operator/no_ironic/operator.yaml -n metal3
154 kubectl delete -f bmo/crds/metal3.io_baremetalhosts_crd.yaml
155 kubectl delete -f bmo/rbac/role_binding.yaml
156 kubectl delete -f bmo/rbac/role.yaml -n metal3
157 kubectl delete -f bmo/rbac/service_account.yaml -n metal3
158 kubectl delete -f bmo/namespace/namespace.yaml
161 function cloud_init_scripts {
162 # The "intel_iommu=on iommu=pt" kernel command line is necessary
166 - path: /var/lib/cloud/scripts/per-instance/set_kernel_cmdline.sh
172 grub_file=${1:-"/etc/default/grub"}
173 kernel_parameters="intel_iommu=on iommu=pt"
174 sed -i~ "/^GRUB_CMDLINE_LINUX=/{h;s/\(=\".*\)\"/\1 ${kernel_parameters}\"/};\${x;/^$/{s//GRUB_CMDLINE_LINUX=\"${kernel_parameters}\"/;H};x}" "$grub_file"
180 function apply_userdata_credential {
182 cat <<EOF > ./$name-user-data-credential.yaml
185 userData: $(base64 -w 0 $name-userdata.yaml)
188 name: $name-user-data
192 kubectl apply -n metal3 -f $name-user-data-credential.yaml
195 apply_networkdata_credential() {
197 cat <<EOF > ./$name-network-data-credential.yaml
200 networkData: $(base64 -w 0 $name-networkdata.json)
203 name: $name-network-data
207 kubectl apply -n metal3 -f $name-network-data-credential.yaml
210 function make_bm_hosts {
211 while IFS=',' read -r name ipmi_username ipmi_password ipmi_address os_username os_password os_image_name; do
212 create_userdata $name $os_username $os_password
213 apply_userdata_credential $name
214 create_networkdata $name
215 apply_networkdata_credential $name
217 GO111MODULE=auto go run $GOPATH/src/github.com/metal3-io/baremetal-operator/cmd/make-bm-worker/main.go \
218 -address "ipmi://$ipmi_address" \
219 -password "$ipmi_password" \
220 -user "$ipmi_username" \
221 "$name" > $name-bm-node.yaml
223 printf " image:" >> $name-bm-node.yaml
224 printf "\n url: ""%s" "$IMAGE_URL" >> $name-bm-node.yaml
225 printf "\n checksum: ""%s" "$IMAGE_CHECKSUM" >> $name-bm-node.yaml
226 printf "\n userData:" >> $name-bm-node.yaml
227 printf "\n name: ""%s" "$name""-user-data" >> $name-bm-node.yaml
228 printf "\n namespace: metal3" >> $name-bm-node.yaml
229 printf "\n networkData:" >> $name-bm-node.yaml
230 printf "\n name: ""%s" "$name""-network-data" >> $name-bm-node.yaml
231 printf "\n namespace: metal3" >> $name-bm-node.yaml
232 printf "\n rootDeviceHints:" >> $name-bm-node.yaml
233 printf "\n minSizeGigabytes: 48\n" >> $name-bm-node.yaml
234 kubectl apply -f $name-bm-node.yaml -n metal3
238 function configure_nodes {
239 if [ ! -d $IRONIC_DATA_DIR ]; then
240 mkdir -p $IRONIC_DATA_DIR
243 #make sure nodes.json file in /opt/ironic/ are configured
244 if [ ! -f $IRONIC_DATA_DIR/nodes.json ]; then
245 cp $PWD/nodes.json.sample $IRONIC_DATA_DIR/nodes.json
249 function remove_bm_hosts {
250 while IFS=',' read -r name ipmi_username ipmi_password ipmi_address os_username os_password os_image_name; do
251 deprovision_compute_node $name
256 while IFS=',' read -r name ipmi_username ipmi_password ipmi_address os_username os_password os_image_name; do
257 kubectl delete --ignore-not-found=true bmh $name -n metal3
258 kubectl delete --ignore-not-found=true secrets $name-bmc-secret -n metal3
259 kubectl delete --ignore-not-found=true secrets $name-user-data -n metal3
260 if [ -f $name-bm-node.yaml ]; then
261 rm -rf $name-bm-node.yaml
264 if [ -f $name-user-data-credential.yaml ]; then
265 rm -rf $name-user-data-credential.yaml
268 if [ -f $name-userdata.yaml ]; then
269 rm -rf $name-userdata.yaml
276 if [ -f $IRONIC_DATA_DIR/nodes.json ]; then
277 rm -rf $IRONIC_DATA_DIR/nodes.json
281 function apply_bm_hosts {
282 list_nodes | make_bm_hosts
285 function deprovision_all_hosts {
286 list_nodes | remove_bm_hosts
289 if [ "$1" == "launch" ]; then
291 launch_baremetal_operator
295 if [ "$1" == "deprovision" ]; then
297 deprovision_all_hosts
301 if [ "$1" == "provision" ]; then
307 if [ "$1" == "clean" ]; then
313 if [ "$1" == "remove" ]; then
314 remove_baremetal_operator
318 echo "Usage: metal3.sh"
319 echo "launch - Launch the metal3 operator"
320 echo "provision - provision baremetal node as specified in common.sh"
321 echo "deprovision - deprovision baremetal node as specified in common.sh"
322 echo "clean - clean all the bmh resources"
323 echo "remove - remove baremetal operator"
326 #Following code is tested for the offline mode
327 #Will be intergrated for the offline mode for ICNi v.0.1.0 beta
331 #set_compute_ssh_config