2014-10-17 15:36:22 -07:00
|
|
|
/*
|
|
|
|
Copyright 2014 CoreOS, Inc.
|
|
|
|
|
|
|
|
Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
you may not use this file except in compliance with the License.
|
|
|
|
You may obtain a copy of the License at
|
|
|
|
|
|
|
|
http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
|
|
|
|
Unless required by applicable law or agreed to in writing, software
|
|
|
|
distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
See the License for the specific language governing permissions and
|
|
|
|
limitations under the License.
|
|
|
|
*/
|
|
|
|
|
2014-03-18 09:00:41 -07:00
|
|
|
package initialize
|
2014-03-04 16:36:05 -08:00
|
|
|
|
|
|
|
import (
|
2014-05-09 20:33:34 -07:00
|
|
|
"errors"
|
2014-03-12 16:52:32 -07:00
|
|
|
"fmt"
|
2014-03-04 16:36:05 -08:00
|
|
|
"log"
|
2014-06-18 12:08:10 -07:00
|
|
|
"path"
|
2014-03-04 16:36:05 -08:00
|
|
|
|
2014-09-21 19:37:39 -07:00
|
|
|
"github.com/coreos/coreos-cloudinit/config"
|
2014-06-18 12:08:10 -07:00
|
|
|
"github.com/coreos/coreos-cloudinit/network"
|
2014-03-18 09:00:41 -07:00
|
|
|
"github.com/coreos/coreos-cloudinit/system"
|
|
|
|
)
|
2014-03-05 14:30:38 -08:00
|
|
|
|
2014-05-09 20:33:34 -07:00
|
|
|
// CloudConfigFile represents a CoreOS specific configuration option that can generate
|
|
|
|
// an associated system.File to be written to disk
|
|
|
|
type CloudConfigFile interface {
|
|
|
|
// File should either return (*system.File, error), or (nil, nil) if nothing
|
|
|
|
// needs to be done for this configuration option.
|
2014-09-21 19:22:13 -07:00
|
|
|
File() (*system.File, error)
|
2014-05-09 20:33:34 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
// CloudConfigUnit represents a CoreOS specific configuration option that can generate
|
2014-06-05 16:12:40 -07:00
|
|
|
// associated system.Units to be created/enabled appropriately
|
2014-05-09 20:33:34 -07:00
|
|
|
type CloudConfigUnit interface {
|
2014-10-06 15:14:29 -07:00
|
|
|
Units() []system.Unit
|
2014-05-09 20:33:34 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
// Apply renders a CloudConfig to an Environment. This can involve things like
|
|
|
|
// configuring the hostname, adding new users, writing various configuration
|
|
|
|
// files to disk, and manipulating systemd services.
|
2014-09-21 16:46:58 -07:00
|
|
|
func Apply(cfg config.CloudConfig, env *Environment) error {
|
2014-03-12 22:30:24 -07:00
|
|
|
if cfg.Hostname != "" {
|
2014-03-18 09:00:41 -07:00
|
|
|
if err := system.SetHostname(cfg.Hostname); err != nil {
|
2014-03-12 22:30:24 -07:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
log.Printf("Set hostname to %s", cfg.Hostname)
|
|
|
|
}
|
|
|
|
|
2014-05-09 20:33:34 -07:00
|
|
|
for _, user := range cfg.Users {
|
|
|
|
if user.Name == "" {
|
|
|
|
log.Printf("User object has no 'name' field, skipping")
|
|
|
|
continue
|
2014-03-23 11:06:43 -07:00
|
|
|
}
|
2014-03-13 10:56:59 -07:00
|
|
|
|
2014-05-09 20:33:34 -07:00
|
|
|
if system.UserExists(&user) {
|
|
|
|
log.Printf("User '%s' exists, ignoring creation-time fields", user.Name)
|
|
|
|
if user.PasswordHash != "" {
|
|
|
|
log.Printf("Setting '%s' user's password", user.Name)
|
|
|
|
if err := system.SetUserPassword(user.Name, user.PasswordHash); err != nil {
|
|
|
|
log.Printf("Failed setting '%s' user's password: %v", user.Name, err)
|
2014-03-13 10:56:59 -07:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
2014-05-09 20:33:34 -07:00
|
|
|
} else {
|
|
|
|
log.Printf("Creating user '%s'", user.Name)
|
|
|
|
if err := system.CreateUser(&user); err != nil {
|
|
|
|
log.Printf("Failed creating user '%s': %v", user.Name, err)
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
2014-03-13 10:56:59 -07:00
|
|
|
|
2014-05-09 20:33:34 -07:00
|
|
|
if len(user.SSHAuthorizedKeys) > 0 {
|
|
|
|
log.Printf("Authorizing %d SSH keys for user '%s'", len(user.SSHAuthorizedKeys), user.Name)
|
|
|
|
if err := system.AuthorizeSSHKeys(user.Name, env.SSHKeyName(), user.SSHAuthorizedKeys); err != nil {
|
|
|
|
return err
|
2014-03-13 10:56:59 -07:00
|
|
|
}
|
2014-05-09 20:33:34 -07:00
|
|
|
}
|
|
|
|
if user.SSHImportGithubUser != "" {
|
|
|
|
log.Printf("Authorizing github user %s SSH keys for CoreOS user '%s'", user.SSHImportGithubUser, user.Name)
|
|
|
|
if err := SSHImportGithubUser(user.Name, user.SSHImportGithubUser); err != nil {
|
|
|
|
return err
|
2014-03-19 08:54:45 -07:00
|
|
|
}
|
2014-05-09 20:33:34 -07:00
|
|
|
}
|
|
|
|
if user.SSHImportURL != "" {
|
|
|
|
log.Printf("Authorizing SSH keys for CoreOS user '%s' from '%s'", user.Name, user.SSHImportURL)
|
|
|
|
if err := SSHImportKeysFromURL(user.Name, user.SSHImportURL); err != nil {
|
|
|
|
return err
|
2014-03-22 15:26:18 -07:00
|
|
|
}
|
2014-03-13 10:56:59 -07:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-03-13 11:39:31 -07:00
|
|
|
if len(cfg.SSHAuthorizedKeys) > 0 {
|
2014-03-18 09:00:41 -07:00
|
|
|
err := system.AuthorizeSSHKeys("core", env.SSHKeyName(), cfg.SSHAuthorizedKeys)
|
2014-03-04 16:36:05 -08:00
|
|
|
if err == nil {
|
|
|
|
log.Printf("Authorized SSH keys for core user")
|
|
|
|
} else {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-09-21 19:22:27 -07:00
|
|
|
var writeFiles []system.File
|
|
|
|
for _, file := range cfg.WriteFiles {
|
2014-10-23 11:46:08 -07:00
|
|
|
writeFiles = append(writeFiles, system.File{File: file})
|
2014-09-21 19:22:27 -07:00
|
|
|
}
|
|
|
|
|
2014-09-21 19:22:13 -07:00
|
|
|
for _, ccf := range []CloudConfigFile{
|
2014-10-23 11:46:08 -07:00
|
|
|
system.OEM{OEM: cfg.Coreos.OEM},
|
|
|
|
system.Update{Update: cfg.Coreos.Update, ReadConfig: system.DefaultReadConfig},
|
|
|
|
system.EtcHosts{EtcHosts: cfg.ManageEtcHosts},
|
2014-09-21 19:22:13 -07:00
|
|
|
} {
|
|
|
|
f, err := ccf.File()
|
2014-05-09 20:33:34 -07:00
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if f != nil {
|
2014-09-21 19:22:27 -07:00
|
|
|
writeFiles = append(writeFiles, *f)
|
2014-03-11 17:46:58 -07:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-09-21 19:22:38 -07:00
|
|
|
var units []system.Unit
|
|
|
|
for _, u := range cfg.Coreos.Units {
|
2014-10-23 11:46:08 -07:00
|
|
|
units = append(units, system.Unit{Unit: u})
|
2014-09-21 19:22:38 -07:00
|
|
|
}
|
|
|
|
|
2014-09-21 19:22:13 -07:00
|
|
|
for _, ccu := range []CloudConfigUnit{
|
2014-10-23 11:46:08 -07:00
|
|
|
system.Etcd{Etcd: cfg.Coreos.Etcd},
|
|
|
|
system.Fleet{Fleet: cfg.Coreos.Fleet},
|
2014-10-06 12:06:33 -07:00
|
|
|
system.Flannel{Flannel: cfg.Coreos.Flannel},
|
2014-10-23 11:46:08 -07:00
|
|
|
system.Update{Update: cfg.Coreos.Update, ReadConfig: system.DefaultReadConfig},
|
2014-09-21 19:22:13 -07:00
|
|
|
} {
|
2014-10-06 15:14:29 -07:00
|
|
|
units = append(units, ccu.Units()...)
|
2014-03-04 16:36:05 -08:00
|
|
|
}
|
|
|
|
|
2014-07-10 15:44:52 -07:00
|
|
|
wroteEnvironment := false
|
2014-09-21 19:22:27 -07:00
|
|
|
for _, file := range writeFiles {
|
2014-07-10 15:44:52 -07:00
|
|
|
fullPath, err := system.WriteFile(&file, env.Root())
|
2014-06-05 12:48:32 -07:00
|
|
|
if err != nil {
|
2014-05-09 20:33:34 -07:00
|
|
|
return err
|
2014-05-06 17:44:18 -07:00
|
|
|
}
|
2014-07-10 15:44:52 -07:00
|
|
|
if path.Clean(file.Path) == "/etc/environment" {
|
|
|
|
wroteEnvironment = true
|
|
|
|
}
|
|
|
|
log.Printf("Wrote file %s to filesystem", fullPath)
|
|
|
|
}
|
|
|
|
|
|
|
|
if !wroteEnvironment {
|
|
|
|
ef := env.DefaultEnvironmentFile()
|
|
|
|
if ef != nil {
|
|
|
|
err := system.WriteEnvFile(ef, env.Root())
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
log.Printf("Updated /etc/environment")
|
|
|
|
}
|
2014-05-06 17:44:18 -07:00
|
|
|
}
|
|
|
|
|
2014-06-18 12:08:10 -07:00
|
|
|
if env.NetconfType() != "" {
|
|
|
|
var interfaces []network.InterfaceGenerator
|
2014-08-18 12:20:25 -07:00
|
|
|
var err error
|
2014-06-18 12:08:10 -07:00
|
|
|
switch env.NetconfType() {
|
|
|
|
case "debian":
|
2014-08-18 12:20:25 -07:00
|
|
|
interfaces, err = network.ProcessDebianNetconf(cfg.NetworkConfig)
|
2014-08-15 18:14:34 -07:00
|
|
|
case "digitalocean":
|
|
|
|
interfaces, err = network.ProcessDigitalOceanNetconf(cfg.NetworkConfig)
|
2014-06-18 12:08:10 -07:00
|
|
|
default:
|
|
|
|
return fmt.Errorf("Unsupported network config format %q", env.NetconfType())
|
|
|
|
}
|
|
|
|
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
if err := system.WriteNetworkdConfigs(interfaces); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
if err := system.RestartNetwork(interfaces); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2014-06-05 17:40:53 -07:00
|
|
|
um := system.NewUnitManager(env.Root())
|
2014-09-21 19:22:38 -07:00
|
|
|
return processUnits(units, env.Root(), um)
|
2014-06-05 17:40:53 -07:00
|
|
|
|
|
|
|
}
|
|
|
|
|
|
|
|
// processUnits takes a set of Units and applies them to the given root using
|
|
|
|
// the given UnitManager. This can involve things like writing unit files to
|
|
|
|
// disk, masking/unmasking units, or invoking systemd
|
|
|
|
// commands against units. It returns any error encountered.
|
|
|
|
func processUnits(units []system.Unit, root string, um system.UnitManager) error {
|
2014-09-02 17:11:17 -07:00
|
|
|
type action struct {
|
2014-11-24 16:42:31 -08:00
|
|
|
unit system.Unit
|
2014-09-02 17:11:17 -07:00
|
|
|
command string
|
|
|
|
}
|
|
|
|
actions := make([]action, 0, len(units))
|
2014-05-09 20:33:34 -07:00
|
|
|
reload := false
|
2014-06-05 17:40:53 -07:00
|
|
|
for _, unit := range units {
|
2014-05-09 20:33:34 -07:00
|
|
|
if unit.Content != "" {
|
2014-11-24 16:42:31 -08:00
|
|
|
log.Printf("Writing unit %q to filesystem", unit.Name)
|
|
|
|
if err := um.PlaceUnit(unit); err != nil {
|
2014-05-09 20:33:34 -07:00
|
|
|
return err
|
2014-04-15 09:00:19 -07:00
|
|
|
}
|
2014-11-24 16:42:31 -08:00
|
|
|
log.Printf("Wrote unit %q", unit.Name)
|
2014-05-09 20:33:34 -07:00
|
|
|
reload = true
|
|
|
|
}
|
2014-03-19 15:52:24 -07:00
|
|
|
|
2014-05-09 20:33:34 -07:00
|
|
|
if unit.Mask {
|
2014-11-24 16:42:31 -08:00
|
|
|
log.Printf("Masking unit file %q", unit.Name)
|
|
|
|
if err := um.MaskUnit(unit); err != nil {
|
2014-06-03 16:49:26 -07:00
|
|
|
return err
|
|
|
|
}
|
|
|
|
} else if unit.Runtime {
|
2014-11-24 16:42:31 -08:00
|
|
|
log.Printf("Ensuring runtime unit file %q is unmasked", unit.Name)
|
|
|
|
if err := um.UnmaskUnit(unit); err != nil {
|
2014-05-09 20:33:34 -07:00
|
|
|
return err
|
2014-03-12 15:43:51 -07:00
|
|
|
}
|
2014-05-09 20:33:34 -07:00
|
|
|
}
|
2014-03-12 15:43:51 -07:00
|
|
|
|
2014-05-09 20:33:34 -07:00
|
|
|
if unit.Enable {
|
|
|
|
if unit.Group() != "network" {
|
2014-11-24 16:42:31 -08:00
|
|
|
log.Printf("Enabling unit file %q", unit.Name)
|
|
|
|
if err := um.EnableUnitFile(unit); err != nil {
|
2014-05-09 20:33:34 -07:00
|
|
|
return err
|
2014-03-24 14:12:52 -07:00
|
|
|
}
|
2014-11-24 16:42:31 -08:00
|
|
|
log.Printf("Enabled unit %q", unit.Name)
|
2014-05-09 20:33:34 -07:00
|
|
|
} else {
|
2014-11-24 16:42:31 -08:00
|
|
|
log.Printf("Skipping enable for network-like unit %q", unit.Name)
|
2014-03-12 15:43:51 -07:00
|
|
|
}
|
|
|
|
}
|
2014-03-19 15:52:24 -07:00
|
|
|
|
2014-05-09 20:33:34 -07:00
|
|
|
if unit.Group() == "network" {
|
2014-11-24 16:42:31 -08:00
|
|
|
networkd := system.Unit{Unit: config.Unit{Name: "systemd-networkd.service"}}
|
|
|
|
actions = append(actions, action{networkd, "restart"})
|
2014-05-09 20:33:34 -07:00
|
|
|
} else if unit.Command != "" {
|
2014-11-24 16:42:31 -08:00
|
|
|
actions = append(actions, action{unit, unit.Command})
|
2014-05-05 13:16:07 -07:00
|
|
|
}
|
2014-05-09 20:33:34 -07:00
|
|
|
}
|
2014-05-05 13:16:07 -07:00
|
|
|
|
2014-05-09 20:33:34 -07:00
|
|
|
if reload {
|
2014-06-05 17:40:53 -07:00
|
|
|
if err := um.DaemonReload(); err != nil {
|
2014-11-24 16:42:31 -08:00
|
|
|
return errors.New(fmt.Sprintf("failed systemd daemon-reload: %s", err))
|
2014-03-19 15:52:24 -07:00
|
|
|
}
|
2014-03-12 15:43:51 -07:00
|
|
|
}
|
|
|
|
|
2014-09-02 17:11:17 -07:00
|
|
|
for _, action := range actions {
|
2014-11-24 16:42:31 -08:00
|
|
|
log.Printf("Calling unit command %q on %q'", action.command, action.unit.Name)
|
|
|
|
res, err := um.RunUnitCommand(action.unit, action.command)
|
2014-05-09 20:33:34 -07:00
|
|
|
if err != nil {
|
|
|
|
return err
|
2014-04-01 16:02:12 -06:00
|
|
|
}
|
2014-11-24 16:42:31 -08:00
|
|
|
log.Printf("Result of %q on %q': %s", action.command, action.unit.Name, res)
|
2014-04-01 16:02:12 -06:00
|
|
|
}
|
|
|
|
|
2014-03-04 16:36:05 -08:00
|
|
|
return nil
|
|
|
|
}
|