diff --git a/mk_acos.sh b/mk_acos.sh new file mode 100755 index 0000000..724170f --- /dev/null +++ b/mk_acos.sh @@ -0,0 +1,117 @@ +#!/bin/sh +if [ `id -u` -ne 0 ] +then + echo "Запуск скрипта $0 возможет только от пользователя root (uid=0)" + exit 1 +fi + +ROOT=root +REPO_MAIN=repo +BRANCH=alt/x86_64/coreos/stable +DEVICE=/dev/sdb +OS_NAME=alt-coreos +MOUNT_DIR=/tmp/acos +REPO_LOCAL=$MOUNT_DIR/ostree/repo + +mkdir $ROOT +tar xf out/acos-latest-x86_64.tar -C $ROOT --exclude=./dev/tty --exclude=./dev/tty0 --exclude=./dev/console --exclude=./dev/urandom --exclude=./dev/random --exclude=./dev/full --exclude=./dev/zero --exclude=/dev/null --exclude=./dev/pts/ptmx --exclude=./dev/null + +##################### +apt-get remove -y -o "RPM::RootDir=$PWD/root" NetworkManager-daemon openresolv etcnet +rm -rf $ROOT/etc/net/ +rm -f $ROOT/etc/resolv.conf +ln -sf /run/systemd/resolve/resolv.conf $ROOT/etc/resolv.conf +apt-get install -o "RPM::RootDir=$PWD/root" dracut-network-055-alt2.noarch.rpm +apt-get install -o "RPM::RootDir=$PWD/root" ignition +##################### + +#Вынести в m-i-p +chroot $ROOT systemctl enable ignition-firstboot-complete.service ostree-remount.service sshd docker +sed -i 's/^LABEL=ROOT\t/LABEL=boot\t/g' $ROOT/etc/fstab +sed -i 's/^AcceptEnv /#AcceptEnv /g' $ROOT/etc/openssh/sshd_config +sed -i 's/^# WHEEL_USERS ALL=(ALL) ALL$/WHEEL_USERS ALL=(ALL) ALL/g' $ROOT/etc/sudoers +sed -i 's|^HOME=/home$|HOME=/var/home|g' $ROOT/etc/default/useradd +echo "blacklist floppy" > $ROOT/etc/modprobe.d/blacklist-floppy.conf +mkdir $ROOT/sysroot +ln -s sysroot/ostree $ROOT/ostree + +mv -f $ROOT/home $ROOT/opt $ROOT/srv $ROOT/mnt $ROOT/var/ +mv -f $ROOT/root $ROOT/var/roothome +mv -f $ROOT/usr/local $ROOT/var/usrlocal +ln -sf var/home $ROOT/home +ln -sf var/opt $ROOT/opt +ln -sf var/srv $ROOT/srv +ln -sf var/roothome $ROOT/root +ln -sf ../var/usrlocal $ROOT/usr/local +ln -sf var/mnt $ROOT/mnt + +chroot $ROOT chgrp wheel /usr/bin/sudo /bin/su +chroot $ROOT chmod 710 /usr/bin/sudo /bin/su +chroot $ROOT chmod ug+s /usr/bin/sudo /bin/su + +KERNEL=`find $ROOT/boot/ -type f -name "vmlinuz-*"` +SHA=`sha256sum "$KERNEL" | awk '{print $1;}'` +mv "$KERNEL" "$KERNEL-$SHA" +rm -f $ROOT/boot/vmlinuz +rm -f $ROOT/boot/initrd* + +cat < $ROOT/ostree.conf +d /run/ostree 0755 root root - +f /run/ostree/initramfs-mount-var 0755 root root - +EOF +chroot $ROOT dracut --reproducible --gzip -v --no-hostonly \ + -f /boot/initramfs-$SHA \ + --add ignition --add ostree \ + --include /ostree.conf /etc/tmpfiles.d/ostree.conf \ + --include /etc/systemd/network/eth0.network /etc/systemd/network/eth0.network \ + --omit-drivers=floppy --omit=nfs --omit=lvm --omit=iscsi \ + --kver `ls $ROOT/lib/modules` +rm -f $ROOT/ostree.conf +rm -rf $ROOT/usr/etc +mv $ROOT/etc $ROOT/usr/etc + +mv $ROOT/var ./var +mkdir $ROOT/var + +#Создание главного ostree-репозитория и коммита в нем +ostree init --repo=$REPO_MAIN --mode=archive +ostree commit --repo=$REPO_MAIN --tree=dir=$ROOT -b $BRANCH --no-xattrs --no-bindings --parent=none --mode-ro-executables --add-metadata-string=version=sisyphus.`date +%Y%m%d`.0.0 +exit 0; + + +#На диске, на который выполняется установка создать файловую систему и минимальный набор каталогов для ostree. Метка boot нужна для поиска раздела в ignition. +parted $DEVICE mktable msdos +parted -a optimal $DEVICE mkpart primary ext4 2MIB 100% +parted $DEVICE set 1 boot on +mkfs.ext4 -L boot "$DEVICE"1 +mkdir $MOUNT_DIR +mount "$DEVICE"1 $MOUNT_DIR +ostree admin init-fs --modern $MOUNT_DIR + +#Установить GRUB +grub-install --root-directory=$MOUNT_DIR $DEVICE +ln -s ../loader/grub.cfg $MOUNT_DIR/boot/grub/grub.cfg + +#Выполнить развертывание операционной системы из репозитория ostree. +ostree pull-local --repo $REPO_LOCAL $REPO_MAIN $BRANCH +ostree config --repo $REPO_LOCAL set sysroot.bootloader grub2 +ostree refs --repo $REPO_LOCAL --create alt:$BRANCH $BRANCH +ostree admin os-init $OS_NAME --sysroot $MOUNT_DIR +OSTREE_BOOT_PARTITION="/boot" ostree admin deploy alt:$BRANCH --sysroot $MOUNT_DIR --os $OS_NAME \ + --karg-append=ignition.platform.id=metal --karg-append=\$ignition_firstboot \ + --karg-append=net.ifnames=0 --karg-append=biosdevname=0 \ + --karg-append=quiet --karg-append=root=UUID=`blkid --match-tag UUID -o value "$DEVICE"1` + +# --karg-append=ignition.platform.id=metal --karg-append=ignition.config.url=http://31.184.254.102/tmp/example2.ign \ + +rm -r $MOUNT_DIR/ostree/deploy/$OS_NAME/var +mv var $MOUNT_DIR/ostree/deploy/$OS_NAME/var +touch $MOUNT_DIR/ostree/deploy/$OS_NAME/var/.ostree-selabeled + +#Создать конфигурационные файлы ignition +mkdir $MOUNT_DIR/ignition +cp config.ign $MOUNT_DIR/ignition/ +touch $MOUNT_DIR/boot/ignition.firstboot + +#Установить пароль рута в новой системе +chroot $MOUNT_DIR/ostree/boot.1/$OS_NAME/*/0/ passwd diff --git a/mk_acos_repo.sh b/mk_acos_repo.sh new file mode 100755 index 0000000..5d21897 --- /dev/null +++ b/mk_acos_repo.sh @@ -0,0 +1,87 @@ +#!/bin/sh +set -e + +if [ `id -u` -ne 0 ] +then + echo "Запуск скрипта $0 возможет только от пользователя root (uid=0)" + exit 1 +fi + +MAIN_ROOT=root +MAIN_REPO=repo +BRANCH=alt/x86_64/containeros/stable +ACOS_ROOT=acos_root + +mkdir $MAIN_ROOT +tar xf out/acos-latest-x86_64.tar -C $MAIN_ROOT --exclude=./dev/tty --exclude=./dev/tty0 --exclude=./dev/console --exclude=./dev/urandom --exclude=./dev/random --exclude=./dev/full --exclude=./dev/zero --exclude=/dev/null --exclude=./dev/pts/ptmx --exclude=./dev/null + +##################### +apt-get remove -y -o "RPM::RootDir=$PWD/root" NetworkManager-daemon openresolv etcnet +rm -rf $MAIN_ROOT/etc/net/ +rm -f $MAIN_ROOT/etc/resolv.conf +ln -sf /run/systemd/resolve/resolv.conf $MAIN_ROOT/etc/resolv.conf +apt-get install -o "RPM::RootDir=$PWD/root" dracut-network-055-alt2.noarch.rpm +apt-get install -o "RPM::RootDir=$PWD/root" ignition +##################### + +#Вынести в m-i-p +chroot $MAIN_ROOT systemctl enable ignition-firstboot-complete.service ostree-remount.service sshd docker +sed -i 's/^LABEL=ROOT\t/LABEL=boot\t/g' $MAIN_ROOT/etc/fstab +sed -i 's/^AcceptEnv /#AcceptEnv /g' $MAIN_ROOT/etc/openssh/sshd_config +sed -i 's/^# WHEEL_USERS ALL=(ALL) ALL$/WHEEL_USERS ALL=(ALL) ALL/g' $MAIN_ROOT/etc/sudoers +sed -i 's|^HOME=/home$|HOME=/var/home|g' $MAIN_ROOT/etc/default/useradd +echo "blacklist floppy" > $MAIN_ROOT/etc/modprobe.d/blacklist-floppy.conf +mkdir $MAIN_ROOT/sysroot +ln -s sysroot/ostree $MAIN_ROOT/ostree + +mv -f $MAIN_ROOT/home $MAIN_ROOT/opt $MAIN_ROOT/srv $MAIN_ROOT/mnt $MAIN_ROOT/var/ +mv -f $MAIN_ROOT/root $MAIN_ROOT/var/roothome +mv -f $MAIN_ROOT/usr/local $MAIN_ROOT/var/usrlocal +ln -sf var/home $MAIN_ROOT/home +ln -sf var/opt $MAIN_ROOT/opt +ln -sf var/srv $MAIN_ROOT/srv +ln -sf var/roothome $MAIN_ROOT/root +ln -sf ../var/usrlocal $MAIN_ROOT/usr/local +ln -sf var/mnt $MAIN_ROOT/mnt + +chroot $MAIN_ROOT chgrp wheel /usr/bin/sudo /bin/su +chroot $MAIN_ROOT chmod 710 /usr/bin/sudo /bin/su +chroot $MAIN_ROOT chmod ug+s /usr/bin/sudo /bin/su + +KERNEL=`find $MAIN_ROOT/boot/ -type f -name "vmlinuz-*"` +SHA=`sha256sum "$KERNEL" | awk '{print $1;}'` +mv "$KERNEL" "$KERNEL-$SHA" +rm -f $MAIN_ROOT/boot/vmlinuz +rm -f $MAIN_ROOT/boot/initrd* + +cat < $MAIN_ROOT/ostree.conf +d /run/ostree 0755 root root - +f /run/ostree/initramfs-mount-var 0755 root root - +EOF +chroot $MAIN_ROOT dracut --reproducible --gzip -v --no-hostonly \ + -f /boot/initramfs-$SHA \ + --add ignition --add ostree \ + --include /ostree.conf /etc/tmpfiles.d/ostree.conf \ + --include /etc/systemd/network/eth0.network /etc/systemd/network/eth0.network \ + --omit-drivers=floppy --omit=nfs --omit=lvm --omit=iscsi \ + --kver `ls $MAIN_ROOT/lib/modules` +rm -f $MAIN_ROOT/ostree.conf +rm -rf $MAIN_ROOT/usr/etc +mv $MAIN_ROOT/etc $MAIN_ROOT/usr/etc + +tar -cJf var.tar.xz -C $MAIN_ROOT var +rm -rf $MAIN_ROOT/var/* + +#Создание главного ostree-репозитория и коммита в нем +ostree init --repo=$MAIN_REPO --mode=archive +ostree commit --repo=$MAIN_REPO --tree=dir=$MAIN_ROOT -b $BRANCH \ + --no-xattrs --no-bindings --parent=none --mode-ro-executables \ + --add-metadata-string=version=sisyphus.`date +%Y%m%d`.0.0 + +mkdir $ACOS_ROOT +ostree admin init-fs --modern $ACOS_ROOT +ostree pull-local --repo $ACOS_ROOT/ostree/repo $MAIN_REPO $BRANCH +tar -cJf acos_root.tar.xz -C $ACOS_ROOT `ls $ACOS_ROOT` + + +#rm -rf root repo var.tar.xz acos_root acos_root.tar.xz \ No newline at end of file