README.md 4.16 KB
Newer Older
Pietsch, Martin's avatar
Pietsch, Martin committed
1 2 3 4
Description
===========

This role configures and upgrades a FreeBSD system. Furthermore, it creates a mirror and installation media for this.
5 6 7
For the creation of jail container it is possible to define special rules for devices to be seen by them. An example is:

function_packages:
8
   * name: "example.service"
9 10 11 12 13 14 15 16 17
     container: true
     container_options:
        exec.start: "/bin/sh /etc/rc"
        exec.stop: "/bin/sh /etc/rc.shutdown"
        exec.clean: yes
        mount.devfs: yes
        securelevel: "3"
        devfs_ruleset: "5"
        devfs_rules:
18
           * "add path deviceXY unhide"      
19 20 21 22
        path: /var/jails/$name

The list *devfs_rules* contains a devfs rule that enables the *deviceXY* to the container. It is also nessecary to set the container option *devfs_ruleset*.

Pietsch, Martin's avatar
Pietsch, Martin committed
23 24 25 26 27 28 29

Requirement
===========

User defined variables
----------------------

30 31 32 33
* hostname: inventory hostname, needed for creation of answer file
* network
* keymap
* locale
Pietsch, Martin's avatar
Pietsch, Martin committed
34 35 36 37

Variables
---------

38 39 40 41
* freebsd_install_home_mirror:
  * description:
    * home URL of install packages of FreeBSD
  * default: ftp://ftp.freebsd.org/pub/FreeBSD/releases
Pietsch, Martin's avatar
Pietsch, Martin committed
42

43 44 45 46 47 48 49 50 51
* freebsd_install_local_mirror:
  * description:
    * local URL of install packages of FreeBSD
  * default: ""

* freebsd_kernel_options:
  * description:
    * This option is a list of tuples (name, value) of kernel options with their value.
  * default: look at vars/main.yml
Pietsch, Martin's avatar
Pietsch, Martin committed
52 53 54 55

Connection plugins
------------------

56
 * sshjail
Pietsch, Martin's avatar
Pietsch, Martin committed
57 58 59 60

Filter plugins
--------------

61 62
 * ip_in_range
 * regex_filter_list
Pietsch, Martin's avatar
Pietsch, Martin committed
63 64 65 66

Module
------

67
 * jail
Pietsch, Martin's avatar
Pietsch, Martin committed
68

69 70 71
Roles
-----

72 73
 * package.pf
 * package.packaging.pkgng
74
 
Pietsch, Martin's avatar
Pietsch, Martin committed
75 76 77
Tools
-----

78 79
 * git
 * unarchive
Pietsch, Martin's avatar
Pietsch, Martin committed
80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98

Processes
=========

main
----

1. execute system configuration (see configure)
2. if container are used
   2.1 create container root directory
   2.2 install jail.conf, if not exists
   2.3 enable jail support
   2.4 install container functions
3. install native packages, if defined

configure
---------

1. execute basic system configuration
99
2. set persistent kernel options
Pietsch, Martin's avatar
Pietsch, Martin committed
100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116
2. set network configuration for IPv4 and IPv6
3. restart network interfaces, if necessary
4. set DNS configuration
5. configure firewall (default: pf)
6. set keymap and locale

answerfile
----------

1. generate answerfile and store it to system_answerfile_path

createcontainer
---------------

1. check jail configuration
2. create jail container, if its are not suppressed

117 118 119 120 121
configurecontainer
------------------

1. configure jail container

Pietsch, Martin's avatar
Pietsch, Martin committed
122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163
installer
---------

1. install build dependencies
2. build installer images for all given architectures and releases
   2.1 create build directory
   2.2 synchronise mfsBSD
   2.3 set rc.conf entries
   2.4 install unattended installer
   2.5 copy ansible's public ssh key
   2.6 install latest pkg-static
   2.7 get installer files
   2.8 create installer
   2.9 register installer
   2.10. cleanup installer image in build path

mirror
------

1. create mirror path, if not exists
2. download all FreeBSD release files of all given architectures and releases
3. download all package files of given architectures and releases

registercontainer
-----------------

1. if container are used and ansible_connection has the value ssh, register container with sshjail
2. if container are used and ansible_connection has the value local, register container with jail
3. set container_host variable

upgrade
-------

1. if system_upgrade_states is set
   1.1 identify corresponded host of development environment
   1.2 upgrade software of host system 
   1.3 migrate jails for corresponded host of development environment
2. if system_upgrade_states is not set
   2.1 upgrade software of host system 
   2.2 upgrade software of container
3. reboot system if necessary
4. wait for system
164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186

_jaildevfs
----------

1. load jail container configurations
2. set devfs rule in file /etc/defaults/devfs.rules
3. restart devfs

_jailcreation
-------------

1. install fstab for special jail container
2. create jail container
3. start jail container
4. register jail container in inventory
5. install software in jail container

_jailconfig
-----------

1. collect and create jail container data


187

188 189 190 191 192
License
=======

BSD

193 194 195 196 197
Contributors
============

* Martin Pietsch (martin.pietsch@tu-dresden.de)