-#!/bin/bash
-set +ex
+#!/usr/bin/env bash
+set -eu -o pipefail
-LIBDIR="$(dirname "$(dirname "$(dirname "$PWD")")")"
+SCRIPTDIR="$(readlink -f $(dirname ${BASH_SOURCE[0]}))"
+LIBDIR="$(dirname $(dirname $(dirname ${SCRIPTDIR})))/env/lib"
eval "$(go env)"
-source $LIBDIR/env/lib/common.sh
+source $LIBDIR/common.sh
if [[ $EUID -ne 0 ]]; then
echo "This script must be run as root"
exit 1
fi
-IMAGE_URL=http://172.22.0.1/images/${BM_IMAGE}
-IMAGE_CHECKSUM=http://172.22.0.1/images/${BM_IMAGE}.md5sum
-
-function get_default_inteface_ipaddress {
- local _ip=$1
- local _default_interface=$(awk '$2 == 00000000 { print $1 }' /proc/net/route)
- local _ipv4address=$(ip addr show dev $_default_interface | awk '$1 == "inet" { sub("/.*", "", $2); print $2 }')
- eval $_ip="'$_ipv4address'"
-}
-
-function create_ssh_key {
- #ssh key for compute node to communicate back to bootstrap server
- mkdir -p $BUILD_DIR/ssh_key
- ssh-keygen -C "compute.icn.akraino.lfedge.org" -f $BUILD_DIR/ssh_key/id_rsa
- cat $BUILD_DIR/ssh_key/id_rsa.pub >> $HOME/.ssh/authorized_keys
-}
-
-function set_compute_key {
- _SSH_LOCAL_KEY=$(cat $BUILD_DIR/ssh_key/id_rsa)
- cat << EOF
-write_files:
-- path: /opt/ssh_id_rsa
- owner: root:root
- permissions: '0600'
- content: |
- $_SSH_LOCAL_KEY
-EOF
-}
-
function deprovision_compute_node {
name="$1"
- kubectl patch baremetalhost $name -n metal3 --type merge \
- -p '{"spec":{"image":{"url":"","checksum":""}}}'
-}
-
-function set_compute_ssh_config {
- get_default_inteface_ipaddress default_addr
- cat << EOF
-- path: /root/.ssh/config
- owner: root:root
- permissions: '0600'
- content: |
- Host bootstrapmachine $default_addr
- HostName $default_addr
- IdentityFile /opt/ssh_id_rsa
- User $USER
-- path: /etc/apt/sources.list
- owner: root:root
- permissions: '0665'
- content: |
- deb [trusted=yes] ssh://$USER@$default_addr:$LOCAL_APT_REPO ./
-EOF
+ if kubectl get baremetalhost $name -n metal3 &>/dev/null; then
+ kubectl patch baremetalhost $name -n metal3 --type merge \
+ -p '{"spec":{"image":{"url":"","checksum":""}}}'
+ fi
}
function create_userdata {
name="$1"
+ username="$2"
+ password="$3"
COMPUTE_NODE_FQDN="$name.akraino.icn.org"
- printf "#cloud-config\n" > $name-userdata.yaml
- if [ -n "$COMPUTE_NODE_PASSWORD" ]; then
- printf "password: ""%s" "$COMPUTE_NODE_PASSWORD" >> $name-userdata.yaml
- printf "\nchpasswd: {expire: False}\n" >> $name-userdata.yaml
- printf "ssh_pwauth: True\n" >> $name-userdata.yaml
- fi
- if [ -n "$COMPUTE_NODE_FQDN" ]; then
- printf "fqdn: ""%s" "$COMPUTE_NODE_FQDN" >> $name-userdata.yaml
- printf "\n" >> $name-userdata.yaml
+ # validate that the user isn't expecting the deprecated
+ # COMPUTE_NODE_PASSWORD to be used
+ if [ "$password" != "${COMPUTE_NODE_PASSWORD:-$password}" ]; then
+ cat <<EOF
+COMPUTE_NODE_PASSWORD "$COMPUTE_NODE_PASSWORD" not equal to nodes.json $name password "$password".
+Unset COMPUTE_NODE_PASSWORD and retry.
+EOF
+ exit 1
fi
- printf "disable_root: false\n" >> $name-userdata.yaml
- printf "ssh_authorized_keys:\n - " >> $name-userdata.yaml
- if [ ! -f $HOME/.ssh/id_rsa.pub ]; then
- yes y | ssh-keygen -t rsa -N "" -f $HOME/.ssh/id_rsa
+ printf " userData:\n" >>${SCRIPTDIR}/machines-values.yaml
+ if [ -n "$username" ]; then
+ printf " name: ${username}\n" >>${SCRIPTDIR}/machines-values.yaml
fi
-
- cat $HOME/.ssh/id_rsa.pub >> $name-userdata.yaml
- network_config_files >> $name-userdata.yaml
- printf "\n" >> $name-userdata.yaml
-}
-
-function launch_baremetal_operator {
- if [ -d $GOPATH/src/github.com/metal3-io/baremetal-operator ]; then
- rm -rf $GOPATH/src/github.com/metal3-io/baremetal-operator
+ if [ -n "$password" ]; then
+ passwd=$(mkpasswd --method=SHA-512 --rounds 4096 "$password")
+ printf " hashedPassword: ${passwd}\n" >>${SCRIPTDIR}/machines-values.yaml
fi
- docker pull integratedcloudnative/baremetal-operator:v1.0-icn
- docker tag integratedcloudnative/baremetal-operator:v1.0-icn \
- quay.io/metal3-io/baremetal-operator:master
-
- mkdir -p $GOPATH/src/github.com/metal3-io
- pushd $GOPATH/src/github.com/metal3-io
- git clone --single-branch --branch v1.0-icn \
- https://github.com/akraino-icn/baremetal-operator.git
- kubectl apply -f baremetal-operator/deploy/namespace/namespace.yaml
- kubectl apply -f baremetal-operator/deploy/rbac/service_account.yaml -n metal3
- kubectl apply -f baremetal-operator/deploy/rbac/role.yaml -n metal3
- kubectl apply -f baremetal-operator/deploy/rbac/role_binding.yaml
- kubectl apply -f baremetal-operator/deploy/crds/metal3.io_baremetalhosts_crd.yaml
- kubectl apply -f baremetal-operator/deploy/operator/no_ironic/operator.yaml -n metal3
- popd
-}
-
-function remove_baremetal_operator {
- if [ ! -d $GOPATH/src/github.com/metal3-io/baremetal-operator ]; then
- pushd $GOPATH/src/github.com/metal3-io
- git clone --single-branch --branch v1.0-icn \
- https://github.com/akraino-icn/baremetal-operator.git
- popd
+ if [ -n "$COMPUTE_NODE_FQDN" ]; then
+ printf " fqdn: ${COMPUTE_NODE_FQDN}\n" >>${SCRIPTDIR}/machines-values.yaml
fi
- pushd $GOPATH/src/github.com/metal3-io
- kubectl delete -f baremetal-operator/deploy/operator/no_ironic/operator.yaml -n metal3
- kubectl delete -f baremetal-operator/deploy/crds/metal3.io_baremetalhosts_crd.yaml
- kubectl delete -f baremetal-operator/deploy/rbac/role_binding.yaml
- kubectl delete -f baremetal-operator/deploy/rbac/role.yaml -n metal3
- kubectl delete -f baremetal-operator/deploy/rbac/service_account.yaml -n metal3
- kubectl delete -f baremetal-operator/deploy/namespace/namespace.yaml
- popd
- rm -rf $GOPATH/src/github.com/metal3-io/baremetal-operator
-}
+ if [ ! -f $HOME/.ssh/id_rsa.pub ]; then
+ yes y | ssh-keygen -t rsa -N "" -f $HOME/.ssh/id_rsa
+ fi
-function network_config_files {
- cat << 'EOF'
-write_files:
-- path: /opt/ironic_net.sh
- owner: root:root
- permissions: '0777'
- content: |
- #!/usr/bin/env bash
- set -xe
- for intf in /sys/class/net/*; do
- sudo ifconfig `basename $intf` up
- sudo dhclient -nw `basename $intf`
- done
-EOF
-cat << EOF
-- path: /opt/user_net.sh
- owner: root:root
- permissions: '0777'
- content: |
- #!/usr/bin/env bash
- set -xe
- route add default gw $PROVIDER_NETWORK_GATEWAY
- sed -i -e 's/^#DNS=.*/DNS=$PROVIDER_NETWORK_DNS/g' /etc/systemd/resolved.conf
- systemctl daemon-reload
- systemctl restart systemd-resolved
-runcmd:
- - [ /opt/ironic_net.sh ]
- - [ /opt/user_net.sh ]
-EOF
+ printf " sshAuthorizedKey: $(cat $HOME/.ssh/id_rsa.pub)\n" >>${SCRIPTDIR}/machines-values.yaml
}
-function apply_userdata_credential {
+create_networkdata() {
name="$1"
- cat <<EOF > ./$name-user-data-credential.yaml
-apiVersion: v1
-data:
- userData: $(base64 -w 0 $name-userdata.yaml)
-kind: Secret
-metadata:
- name: $name-user-data
- namespace: metal3
-type: Opaque
-EOF
- kubectl apply -n metal3 -f $name-user-data-credential.yaml
+ node_networkdata $name >>${SCRIPTDIR}/machines-values.yaml
}
function make_bm_hosts {
- while read -r name username password address; do
- create_userdata $name
- apply_userdata_credential $name
-
- go run $GOPATH/src/github.com/metal3-io/baremetal-operator/cmd/make-bm-worker/main.go \
- -address "ipmi://$address" \
- -password "$password" \
- -user "$username" \
- "$name" > $name-bm-node.yaml
-
- printf " image:" >> $name-bm-node.yaml
- printf "\n url: ""%s" "$IMAGE_URL" >> $name-bm-node.yaml
- printf "\n checksum: ""%s" "$IMAGE_CHECKSUM" >> $name-bm-node.yaml
- printf "\n userData:" >> $name-bm-node.yaml
- printf "\n name: ""%s" "$name""-user-data" >> $name-bm-node.yaml
- printf "\n namespace: metal3\n" >> $name-bm-node.yaml
- kubectl apply -f $name-bm-node.yaml -n metal3
+ while IFS=',' read -r name ipmi_username ipmi_password ipmi_address boot_mac os_username os_password os_image_name; do
+ printf " ${name}:\n" >>${SCRIPTDIR}/machines-values.yaml
+ printf " bmcUsername: ${ipmi_username}\n" >>${SCRIPTDIR}/machines-values.yaml
+ printf " bmcPassword: ${ipmi_password}\n" >>${SCRIPTDIR}/machines-values.yaml
+ printf " bmcAddress: ipmi://${ipmi_address}\n" >>${SCRIPTDIR}/machines-values.yaml
+ if [[ ! -z ${boot_mac} ]]; then
+ printf " bootMACAddress: ${boot_mac}\n" >>${SCRIPTDIR}/machines-values.yaml
+ fi
+ printf " imageName: ${BM_IMAGE}\n" >>${SCRIPTDIR}/machines-values.yaml
+ create_userdata $name $os_username $os_password
+ create_networkdata $name
done
}
#make sure nodes.json file in /opt/ironic/ are configured
if [ ! -f $IRONIC_DATA_DIR/nodes.json ]; then
- cp $PWD/nodes.json.sample $IRONIC_DATA_DIR/nodes.json
+ cp ${SCRIPTDIR}/nodes.json.sample $IRONIC_DATA_DIR/nodes.json
fi
}
-function remove_bm_hosts {
- while read -r name username password address; do
+function deprovision_bm_hosts {
+ while IFS=',' read -r name ipmi_username ipmi_password ipmi_address boot_mac os_username os_password os_image_name; do
deprovision_compute_node $name
done
}
-function cleanup {
- while read -r name username password address; do
- kubectl delete bmh $name -n metal3
- kubectl delete secrets $name-bmc-secret -n metal3
- kubectl delete secrets $name-user-data -n metal3
- if [ -f $name-bm-node.yaml ]; then
- rm -rf $name-bm-node.yaml
- fi
-
- if [ -f $name-user-data-credential.yaml ]; then
- rm -rf $name-user-data-credential.yaml
- fi
-
- if [ -f $name-userdata.yaml ]; then
- rm -rf $name-userdata.yaml
- fi
- done
-}
-
function clean_all {
- list_nodes | cleanup
+ helm -n metal3 uninstall machines
+ rm -f ${SCRIPTDIR}/machines-values.yaml
if [ -f $IRONIC_DATA_DIR/nodes.json ]; then
rm -rf $IRONIC_DATA_DIR/nodes.json
fi
}
function apply_bm_hosts {
+ printf "machines:\n" >${SCRIPTDIR}/machines-values.yaml
list_nodes | make_bm_hosts
+ helm -n metal3 install machines ${SCRIPTDIR}/../../machines --create-namespace -f ${SCRIPTDIR}/machines-values.yaml
}
function deprovision_all_hosts {
- list_nodes | remove_bm_hosts
+ list_nodes | deprovision_bm_hosts
}
-if [ "$1" == "launch" ]; then
- launch_baremetal_operator
- exit 0
-fi
-
if [ "$1" == "deprovision" ]; then
configure_nodes
deprovision_all_hosts
exit 0
fi
-if [ "$1" == "remove" ]; then
- remove_baremetal_operator
- exit 0
-fi
-
echo "Usage: metal3.sh"
-echo "launch - Launch the metal3 operator"
echo "provision - provision baremetal node as specified in common.sh"
echo "deprovision - deprovision baremetal node as specified in common.sh"
echo "clean - clean all the bmh resources"
-echo "remove - remove baremetal operator"
exit 1
-
-#Following code is tested for the offline mode
-#Will be intergrated for the offline mode for ICNi v.0.1.0 beta
-#create_ssh_key
-#create_userdata
-#set_compute_key
-#set_compute_ssh_config