#!/bin/bash -x set -eE -o pipefail trap 'echo "$0:$LINENO:error: \"$BASH_COMMAND\" returned $?"' ERR # # fai's setup-storage won't do btrfs on luks, # # so we do it ourself :) #### begin configuration if ifclass VM; then d=vd else d=sd fi if ifclass TWO_DISK; then letters=(a b) elif ifclass ONE_DISK; then letters=(a) else exit fi ##### end configuration skiptask partition devs=(${letters[@]/#//dev/${d}}) crypt_devs=(${letters[@]/#//dev/mapper/crypt_dev_${d}}) # we can set this manually to force partitioning #partition=false # somewhat crude detection of whether to partition for dev in ${devs[@]}; do x=($dev[0-9]) [[ ${#x[@]} == 4 ]] || partition=true for part in ${dev}{1,2,3,4}; do [[ -e $part ]] || partition=true done # type tells us it's not totally blank for part in ${dev}{1,3}; do blkid | grep "^$part:.*TYPE=" &>/dev/null || partition=true done done partition=true # override temporarily # keyfiles generated like: # head -c 2048 /dev/urandom | od | s dd of=/q/root/luks/host-demohost luks_dir=/var/lib/fai/config/distro-install-common/luks if ifclass tp; then lukspw=$(cat $luks_dir/traci) else lukspw=$(cat $luks_dir/ian) fi if ifclass demohost; then lukspw=x fi boot_end=504 crypt=/dev/mapper/crypt_dev_${d##/dev/}a3 # 1.5 x based on https://access.redhat.com/documentation/en-US/Red_Hat_Enterprise_Linux/7/html/Installation_Guide/sect-disk-partitioning-setup-x86.html#sect-custom-partitioning-x86 swap_end=$(( $(grep ^MemTotal: /proc/meminfo| awk '{print $2}') * 3/(${#devs[@]} * 2 ) / 1000 + boot_end )) create_subvols() { cd /mnt for x in a home root; do btrfs subvolume list . | grep "$x$" >/dev/null || btrfs subvolume create $x done btrfs subvolume set-default \ $(btrfs subvolume list . | grep 'root$' | awk '{print $2}') . cd / umount /mnt } shopt -s nullglob if $partition; then mkdir -p /tmp/fai for dev in ${devs[@]}; do for x in $dev[0-9]; do wipefs -a $x; done parted -s $dev mklabel gpt # gpt ubuntu cloud image uses ~4. fai uses 1 MiB. ehh, i'll do 4. # also, using MB instead of MiB causes complains about alignment. parted -s $dev mkpart primary "ext3" 4MB ${boot_end}MiB parted -s $dev set 1 boot on parted -s $dev mkpart primary "linux-swap" ${boot_end}MiB ${swap_end}MiB parted -s -- $dev mkpart primary "" ${swap_end}MiB -0 parted -s $dev mkpart primary "" 1MiB 4MiB parted -s $dev set 4 bios_grub on # the mkfs failed randomly on a vm, so I threw a sleep in here. sleep .1 mkfs.ext4 -F ${dev}1 # 3 is device which simply holds a key for the 4's, # so we can unlock multi-device btrfs fs with 1 manually entered passphrase. # # Background: It's of course possible modify the initramfs to # put the input from a passphrase prompt into a variable and use # it to unlock multiple devices, but that would require figuring # more things out. # for luks_dev in ${dev}3; do yes YES | cryptsetup luksFormat $luks_dev $luks_dir/host-$HOSTNAME \ -c aes-cbc-essiv:sha256 -s 256 || [[ $? == 141 ]] yes "$lukspw" | \ cryptsetup luksAddKey --key-file $luks_dir/host-$HOSTNAME \ $luks_dev || [[ $? == 141 ]] # background: Keyfile and password are treated just # like 2 ways to input a passphrase, so we don't actually need to have # different contents of keyfile and passphrase, but it makes some # security sense to a really big randomly generated passphrase # as much as possible, so we have both. # # This would remove the keyfile. # yes 'test' | cryptsetup luksRemoveKey /dev/... \ # /key/file || [[ $? == 141 ]] cryptsetup luksOpen $luks_dev crypt_dev_${luks_dev##/dev/} \ --key-file $luks_dir/host-$HOSTNAME done done mkfs.btrfs -f ${crypt_devs[@]/%/3} parted ${devs[0]} set 1 boot on mount $crypt /mnt create_subvols else for dev in ${devs[@]}; do mkfs.ext4 -F ${dev}1 cryptsetup luksOpen ${dev}3 crypt_dev_${dev##/dev/}3 \ --key-file $luks_dir/host-$HOSTNAME || [[ $? == 141 ]] done sleep 1 mount -o subvolid=0 $crypt /mnt # systemd creates subvolumes we want to delete. s=($(btrfs subvolume list --sort=-path /mnt | sed -rn 's#^.*path\s*(root/\S+)\s*$#\1#p')) for subvol in ${s[@]}; do btrfs subvolume delete /mnt/$subvol; done btrfs subvolume set-default 0 /mnt btrfs subvolume delete /mnt/root create_subvols fi for dev in ${devs[@]}; do cat >>/tmp/fai/crypttab <>/tmp/fai/crypttab < /tmp/fai/fstab </tmp/fai/disk_var.sh <