X-Git-Url: https://iankelling.org/git/?a=blobdiff_plain;f=myfai-chboot-local;h=b2df864f129e32cbb2a1fdc5202192c115956b5d;hb=f0d1a07f2c696d1aace04763424fc6ad13751fb3;hp=9ba87dcd5ff8e2a88aa61308a45a1c35289d9c6c;hpb=1885f9677fdf2bfeac95285cf13a7d60273d096a;p=automated-distro-installer diff --git a/myfai-chboot-local b/myfai-chboot-local index 9ba87dc..b2df864 100755 --- a/myfai-chboot-local +++ b/myfai-chboot-local @@ -1,49 +1,111 @@ #!/bin/bash +# note, this script gets piped to bash, so cant cd to current dir set -eE -o pipefail trap 'echo "$0:$LINENO:error: \"$BASH_COMMAND\" returned $?" >&2' ERR + +fai_action_arg=I +fai_reboot_arg=,reboot case $1 in -h|--help) echo "see help from myfai-chboot" exit 0 ;; + -S) + fai_action_arg=S + fai_reboot_arg= + shift + ;; esac [[ $EUID == 0 ]] || exec sudo "${BASH_SOURCE}" "$@" -e() { echo "$@"; "$@"; } +e() { + echo "$*" + if ! "$@"; then + echo "$0: error: exit code $? from: $*" + exit 1 + fi +} + +host=$1 + +# assuming ipv4, or else we might need to deal with multiple addresses +# in an ipv4 + ipv6 network. +my_ip=$(ip -4 route get 8.8.8.8 | sed -nr 's,^.*src\s+(\S+).*,\1,p') +if [[ ! $my_ip || $my_ip =~ [[:space:]] ]]; then + echo "$0: error: failed to get \$my_ip, got: $my_ip" + exit 1 +fi + +if [[ $host == default ]]; then + ip='*' +elif [[ $host == [0-9]*.[0-9]*.[0-9]*.[0-9]* ]]; then + ip=$host/32 +else + type -t host &>/dev/null || apt-get -y install dnsutils + ip=$(host $host | sed -rn 's/^\S+ has address //p;T;q')/32 + if [[ ! $ip || $ip =~ [[:space:]] ]]; then + echo "$0: error: failed to get \$my_ip, got: $my_ip" + exit 1 + fi + +fi + +if modprobe nfsd &>/dev/null; then + std_arg="-u nfs://faiserver/srv/fai/config" + # nfsv4 wont do rw with overlayfs yet + # https://lists.uni-koeln.de/pipermail/linux-fai/2017-March/011641.html + root_arg="$my_ip:/srv/fai/nfsroot:vers=3" + # fai-setup without -e sets the ip to the local_ip/local_network, eg 192.168.1.3/24 + # I restrict it to one ip as simple but imperfect access control. + # we may chattr +i /etc/exports if we dun want it modified + # for example, if we made these exports more widely available + # while doing multiple installs or a recovery. + if [[ -w /etc/exports ]]; then + sed -ri --follow-symlinks '\%^/srv/fai/%d' /etc/exports + cat >>/etc/exports < + Deny from all + Allow from $ip + +EOF +fi rm -f /srv/tftp/fai/pxelinux.cfg/* if [[ ! $1 ]]; then exit 0 fi -host=$1 -ip=$(getent hosts $host | awk '{print $1}') -std_arg="-u nfs://faiserver/srv/fai/config" -e fai-chboot -Iv $std_arg default # set it to default to get a val out of it next -kernel=$(fai-chboot -L '^default$' | awk '{print $3}') # man page doesn't explain this, but this deletes & thus disables # all chboot systems. -type -t host &>/dev/null || apt-get -y install dnsutils -gateway_ip=$(route -n | sed -rn 's/^0\.0\.0\.0\s+(\S+).*/\1/p') -my_ip=$(host faiserver $gateway_ip | sed -rn 's/^\S+ has address //p') -k_args=$(fai-chboot -L '^default$' | \ - sed -r "s/^(\S+\s+){3}(.*root=)(.*)/\2$my_ip:\3/") -rm -f /srv/tftp/fai/pxelinux.cfg/* -e fai-chboot -k "$k_args" -v -f verbose,sshd,createvt,reboot $std_arg $kernel "$host" - -# fai-setup without -e sets the ip to the local_ip/local_network, eg 192.168.1.3/24 -# I restrict it to one ip as simple but imperfect access control. -sed -ri --follow-symlinks '\%^/srv/fai/%d' /etc/exports -cat >>/etc/exports <