2016年5月18日 星期三

DC/OS on CentOS

Update system packages 

$ sudo yum udate -y && sudo yum upgrade -y
Please check your kernel version
$ uname -r
3.10.0-327.10.1.el7.x86_64
Docker requirements
  • Docker 1.7 or greater must be installed on all bootstrap and cluster nodes.
Docker recommendations
  • Docker 1.9 or greater is recommended for stability reasons.
  • Do not use Docker devicemapper storage driver in loop-lvm mode.
  • Prefer OverlayFS or devicemapper in direct-lvm mode when choosing a production storage driver.
  • Manage Docker on CentOS with systemd.
  • Run Docker commands as the root user (with sudo) or as a user in the docker user group.
Setting Overlay script for CentOS7
#!/bin/bash
 
#####
# Basic tool
#####
 
yum -y install curl git tig tree vim wget
yum -y groupinstall "Development Tools"
 
#####
# Docker Repo
#####
 
DOCKER_REPO="/etc/yum.repos.d/docker.repo"
 
if [ -f ${DOCKER_REPO} ]; then
    echo -e "\033[0;33;40mDocker Repo exist\033[0m"
    echo -e "\033[0;36;40mInstall Docker Engine\033[0m"
    yum install -y docker-engine
    echo -e "\033[0;32;40mdone\033[0m"
else
    echo -e "\033[0;36;40mSetting Docker Repo\033[0m"
    tee ${DOCKER_REPO} <<- -e="" -y="" 2="" baseurl="https://yum.dockerproject.org/repo/main/centos/7/" docker-engine="" docker="" dockerrepo="" echo="" enable="" enabled="1" engine="" eof="" fi="" gpgcheck="1" gpgkey="https://yum.dockerproject.org/gpg" grep="" install="" lsmod="" m="" mdone="" minstall="" module="" name="Docker" overlay="" repository="" sleep="" yum="">> /dev/null
check_overlay=$?
 
if [ ${check_overlay} = 0 ]; then
    echo -e "\033[0;33;40mAlready Enabled overlay module\033[0m"
else
    echo -e "\033[0;36;40mEnable overlay module\033[0m"
    modprobe overlay
    echo -e "\033[0;32;40mdone\033[0m"
fi
 
sleep 2
#####
# Setting Disk and mount
####
 
HDD_DEVICE="`cat /var/log/messages | grep 'unknown partition table' | awk '{print $6}' | cut -d: -f1 | head -n 1`"
OVERLAY_DIR="/var/lib/docker/overlay"
 
if [ -b /dev/${HDD_DEVICE}1 ]; then
    echo -e "\033[0;33;40m${HDD_DEVICE}1 exist\033[0m"
else
    echo -e "\033[0;36;40mFormate Disk\033[0m"
    echo "n
p
1
 
 
w
"|fdisk /dev/${HDD_DEVICE}; mkfs.ext4 /dev/${HDD_DEVICE}1
    echo -e "\033[0;32;40mdone\033[0m"
fi
 
sleep 2
 
if [ -d ${OVERLAY_DIR} ]; then
    echo -e "\033[0;33;40m${OVERLAY_DIR} exist\033[0m"
else
    echo -e "\033[0;36;40mCreating ${OVERLAY_DIR} directoy\033[0m"
    mkdir -p ${OVERLAY_DIR}
    echo -e "\033[0;32;40mdone\033[0m"
fi
 
sleep 2
 
cat /etc/fstab | grep 'overlay' >> /dev/null
check_uuid=$?
HDD_UUID_1="`blkid  /dev/${HDD_DEVICE}1 | awk '{print $2}' | sed 's/\"//g'`"
 
if [ ${check_uuid} = 0 ]; then
    echo -e "\033[0;33;40mfstab OK\033[0m"
else
    echo -e "\033[0;36;40mSetting fstab\033[0m"
    echo -n "${HDD_UUID_1}    ${OVERLAY_DIR}  ext4 defaults 0 2" >> /etc/fstab
    mount -a
    echo -e "\033[0;32;40mdone\033[0m"
fi
 
sleep 2
#####
# Setting Docker Engine
####
 
DOCKER_SERVICE="/usr/lib/systemd/system/docker.service"
 
grep '\-\-storage-driver=overlay' ${DOCKER_SERVICE} >> /dev/null
check_storage_driver=$?
 
if [ ${check_storage_driver} = 0 -a -f ${DOCKER_SERVICE} ]; then
  echo -e "\033[0;33;40mDocker Storage nothing to do\033[0m"
else
  echo -e "\033[0;36;40mSetting docker storage\033[0m"
  sed 12d -i ${DOCKER_SERVICE}
  sed "11 aExecStart=/usr/bin/docker daemon --storage-driver=overlay -H fd://" -i ${DOCKER_SERVICE} >> /dev/null
  echo -e "\033[0;32;40mdone\033[0m"
fi
 
#####
# Enable Docker
#####
 
systemctl daemon-reload
systemctl start docker
On CentOS 7, firewalld must be stopped and disabled.
$ sudo systemctl stop firewalld && sudo systemctl disable firewalld
Data compression (advanced installer),to install these utilities on CentOS7 and RHEL7:
$ sudo yum install -y tar xz unzip curl ipset
Cluster permissions (advanced installer)
On each of your cluster nodes, use the following command to:
  • Disable SELinux or set it to permissive mode.
  • Add nogroup to each of your Mesos masters and agents.
  • Disable IPV6.
$ sudo sed -i s/SELINUX=enforcing/SELINUX=permissive/g /etc/selinux/config &&
  sudo groupadd nogroup &&
  sudo sysctl -w net.ipv6.conf.all.disable_ipv6=1 &&
  sudo sysctl -w net.ipv6.conf.default.disable_ipv6=1 &&
  sudo reboot
  • Download the DC/OS installer
curl -O https://downloads.dcos.io/dcos/EarlyAccess/dcos_generate_config.sh
  • Create a directory named genconf on your bootstrap each node.
sudo mkdir -p genconf && cd genconf
  • Create a ip-detect script
#!/usr/bin/env bash
set -o nounset -o errexit
export PATH=/usr/sbin:/usr/bin:$PATH
echo $(ip addr show eth0 | grep -Eo '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}' | head -1)
  • Create config.yaml. for exammple
---
agent_list:
- 
- 
- 
bootstrap_url: file:///opt/dcos_install_tmp
cluster_name: DCOS
exhibitor_storage_backend: static
ip_detect_filename: /genconf/ip-detect
master_discovery: static
master_list:
- 
- 
- 
process_timeout: 10000
resolvers:
- 8.8.8.8
ssh_port: 22
ssh_user: 
  • Copy your private SSH key to genconf/ssh_key
$ cp  genconf/ssh_key && chmod 0600 genconf/ssh_key
Now you genconf will be like this and copy to each node
genconf/
├── config.yaml
├── ip-detect
└── ssh_key
$ scp -rp genconf username@:
Check help
$ sudo bash dcos_generate_config.sh --help
Running mesosphere/dcos-genconf docker with BUILD_DIR set to /home/centos/genconf
usage:
Install DC/OS
 
dcos_installer [-h] [-f LOG_FILE] [--hash-password HASH_PASSWORD] [-v]
[--web | --genconf | --preflight | --deploy | --postflight | --uninstall | --validate-config | --test]
 
Environment Settings:
 
  PORT                  Set the :port to run the web UI
  CHANNEL_NAME          ADVANCED - Set build channel name
  BOOTSTRAP_ID          ADVANCED - Set bootstrap ID for build
 
optional arguments:
  -h, --help            show this help message and exit
  -v, --verbose         Verbose log output (DEBUG).
  --offline             Do not install preflight prerequisites on CentOS7,
                        RHEL7 in web mode
  --web                 Run the web interface.
  --genconf             Execute the configuration generation (genconf).
  --preflight           Execute the preflight checks on a series of nodes.
  --install-prereqs     Install preflight prerequisites. Works only on CentOS7
                        and RHEL7.
  --deploy              Execute a deploy.
  --postflight          Execute postflight checks on a series of nodes.
  --uninstall           Execute uninstall on target hosts.
  --validate-config     Validate the configuration in config.yaml
  --test                Performs tests on the dcos_installer application
  • Run this command for each master and node.
sudo bash dcos_generate_config.sh --install-prereqs
  • Run docker nginx for download install dcos_install.sh on master, and other node just download dcos_install.sh
sudo bash dcos_generate_config.sh
sudo docker run -d -p :80 -v $PWD/genconf/serve:/usr/share/nginx/html:ro nginx
Create /tmp/dcos directory and download dcos_install.sh
mkdir -p /tmp/dcos && cd /tmp/dcos
curl -O http://:/dcos_install.sh
sudo bash dcos_install.sh 
role must be master or slave
Now You can check
ZooKeeper http://IP:8181/exhibitor/v1/ui/index.html
Mesos http://IP:5050
DC/OShttp://IP

2015年11月25日 星期三

Docker install on Ubuntu


OS: Ubuntu 14.04(LTS)

Add GPG Key

sudo apt-key adv — keyserver hkp://p80.pool.sks-keyservers.net:80 — recv-keys 58118E89F3A912897C070ADBF76221572C52609D

Create Docker Repo

echo “deb https://apt.dockerproject.org/repo ubuntu-trusty main” > /etc/apt/sources.list.d/docker.list

Update the apt package index

apt-get update

Purge the old repo if it exists

apt-get purge lxc-docker
Actuaully, you can skip this step, if your system is new installed, lxc-docker this package isn’t exist.

Verify that apt is pulling from the right repository

apt-cache policy docker-engine

Install Docker

apt-get install docker-engine && sudo shutdown -r now
Now you can play docker now…enjoy it~!!

Reference

2015年1月5日 星期一

pear could not extract the package.xml


sudo pear -d preferred_state=alpha install Net_Gearman-0.2.3
downloading Net_Gearman-0.2.3.tgz ...
Starting to download Net_Gearman-0.2.3.tgz (17,572 bytes)
......done: 17,572 bytes
could not extract the package.xml file from "/build/buildd/php5-5.3.10/pear-build-download/Net_Gearman-0.2.3.tgz"
Download of "pear/Net_Gearman" succeeded, but it is not a valid package archive
Error: cannot download "pear/Net_Gearman"
Download failed
install failed
這裝不起來是因為目前的php-pear的版本跟php本身的版本不同,所以才會導致裝不起來
php-pear的版本
dpkg --list | grep php-pear
ii  php-pear                         5.3.10-1ubuntu3.15                    PEAR - PHP Extension and Application Repository
php的版本
php -v
PHP 5.5.20-1+deb.sury.org~precise+1 (cli) (built: Dec 21 2014 19:54:33)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies
with Zend OPcache v7.0.4-dev, Copyright (c) 1999-2014, by Zend Technologies  
這問題其實我本來也一直找不到為什麼,後來突發起想,想說來upgrade一下,可能搞不好就好了,結果被我誤打誤撞弄出來,其實細心一點看error訊息,就很容易找到問題了。
could not extract the package.xml file from "/build/buildd/php5-5.3.10/pear-build-download/Net_Gearman-0.2.3.tgz"
解法:
apt-get update
apt-get upgrade
sudo pear -d preferred_state=alpha install Net_Gearman-0.2.3

2014年11月24日 星期一

SALTSTACK 實用指令

salt-key -L                                 #列出目前有哪些minion的key

salt '*' state.highstate                    #正常執行

salt '*' state.highstate -v test=True       #模擬運行

salt '*' grains.ls                          #列出可用的grains

salt '*' grains.items                       #列出所有grains的名字及內容

salt -C 'G@os:Ubuntu' test.ping             #可以用正則來找出符合條件的

salt '*' saltutil.syn_all or saltutil.grains 這二個指令都是把自定義的grains丟到minion上
在minion的路徑是/var/cache/salt/minion/extmods/grains
參考文獻



Ubuntu 14.04 install Saltstack

環境介紹:(在VirtualBox上實作)
準備二台Ubuntu 14.04
一台叫saltmaster, 一台叫minion
saltmasterminion
eth0 10.0.2.5 (DHPC取得IP)eth0 10.0.2.6 (DHCP取得IP)
Step 1. Add Repository
sudo apt-get update
sudo apt-get upgrade
sudo apt-get install python-software-properties
sudo apt-get install add-apt-repository ppa:saltstack/salt
sudo apt-get update
sudo apt-get install salt-master        #在slatmaster上執行就好
sudo apt-get install minion             #在minion上執行就好
Step 2. Configuration
在/etc/salt/下,有一個主要設定檔,master,預設listen 4505 & 4506port
file_roots:
  base:
    - /srv/salt
interface: 10.0.2.13
這個是master主要的設定,預設interface就會抓你目前的IP,file_roots是指定你sls檔所要開始的位置,我還是比照官方的設定,一樣寫在/srv/salt下,然後在saltstack,第一個sls檔,叫top.sls,所有開始的設定,都是必須要從這個檔案開始讀取。
下面是saltmaster的目錄結構
/etc/salt# tree
.
├── master                            #主要設定檔
├── master.d
└── pki                               #放key的資料夾
    └── master
        ├── master.pem
        ├── master.pub
        ├── minions                   #放minion public key的資料夾
        │   └── salt
        ├── minions_pre               #當key還沒被master所認可時,key會被放這目錄下
        └── minions_rejected          #當key被master所拒絕時,key會被放到這目錄下

6 directories, 4 files
如果想要使用自動簽署public key from minion,就可以在/etc/salt/master加入auto_accept這個參數,預設是關閉的
auto_accept=yes

2014年11月23日 星期日

gpart 分割磁區

切 /dev/ada1 為例子
STEP 1. 先用gpart show查看目前的硬碟資訊
gpart show
STEP 2. 建立GPT Partition於ada1
gpart create -s GPT ada1
STEP 3. 查看gpart 狀態
gpart show

=>          63  976561551  ada0  MBR  (466G)
               63  976559157    1  freebsd  [active]  (466G)
  976559220       2394       - free -  (1.2M)
=>           0  976559157  ada0s1  BSD  (466G)
                0   50331648      2  freebsd-swap  (24G)
   50331648   33554432      1  freebsd-ufs  (16G)
   83886080   67108864      4  freebsd-ufs  (32G)
  150994944   67108864      5  freebsd-ufs  (32G)
  218103808   67108864      6  freebsd-ufs  (32G)
  285212672   67108864      7  freebsd-ufs  (32G)
  352321536  624237621      8  freebsd-ufs  (298G)
=>        34  4882808253  ada1  GPT  (2.3T)
             34  4882808253       - free -  (2.3T)
STEP 4. 於ada1上增加type為freebsd-ufs的partition
gpart add -b 34 -s 4882808253 -t freebsd-ufs ada1

其中,-b -s -t 是絕對必要參數 
 -b:start
 -s:size
 -t:fs_type
STEP 5.再執行gpart show可以看到該生出來的已經生出來
=>          63  976561551  da0  MBR  (466G)
               63  976559157    1  freebsd  [active]  (466G)
  976559220       2394       - free -  (1.2M)
=>           0  976559157  ada0s1  BSD  (466G)
                0   50331648      2  freebsd-swap  (24G)
   50331648   33554432      1  freebsd-ufs  (16G)
   83886080   67108864      4  freebsd-ufs  (32G)
  150994944   67108864      5  freebsd-ufs  (32G)
  218103808   67108864      6  freebsd-ufs  (32G)
  285212672   67108864      7  freebsd-ufs  (32G)
  352321536  624237621      8  freebsd-ufs  (298G)
=>        34  4882808253  ada1  GPT  (2.3T)
             34  4882808253    1  freebsd-ufs  (2.3T)
=>        34  4882808253  ufsid/4cecc4f9c9eaaa33  GPT  (2.3T)
             34  4882808253                       1  freebsd-ufs  (2.3T)
STEP 6.執行newfs
newfs -O2 -U /dev/ada1p1
Step 7.執行mount測試
mount /dev/ada1p1 /mnt

L2TP Over IPSec


環境介紹:(在VirtualBox上實作)
準備二台Ubuntu 12.04.4
一台叫Right, 一台叫Left
RightLeft
eth0 10.0.2.5 (DHPC取得IP)eth0 10.0.2.6 (DHCP取得IP)
eth1 192.168.1.10 (Static IP)eth1 192.168.2.10 (Static IP)
先安裝基本套件及所需的Repo
apt-get update
apt-get install -y python-software-properties
add-apt-repository ppa:xelerance/xl2tpd
add-apt-repository ppa:openswan/ppa
apt-get update
安裝L2TP套件
apt-get install xl2tpd
編輯設定檔 /etc/xl2tpd/xl2tpd.conf,這是主要要設定檔
[global]
ipsec saref = no

[lns default]                                   #Server端
ip range = 192.168.2.50-192.168.2.100           #要給Client端連進來的IP Scope
local ip = 192.168.2.1                          #給一個內網IP,並且不要跟現在內網有的IP重覆即可
require chap = yes                              #是否使用CHAP認証
require authentication = yes                     
ppp debug = yes                                 #log會在/var/log/syslog
pppoptfile =/etc/ppp/options.xl2tpd             #pppoe的設定檔案位置
length bit = yes

[lac daniel]                                    #Client端撥給對面的Server所用的名稱"daniel"
lns = 10.0.2.5                                  #自已的對外IP
ppp debug = yes
pppoptfile = /etc/ppp/options.l2tpd.client  
length bit = yes
設定DNS及安全認証方式,/etc/ppp/options.xl2tpd
require-chap
ms-dns 8.8.8.8
lcp-echo-interval 10
lcp-echo-failure 3
auth
refuse-mschap-v2
refuse-mschap
asyncmap 0
auth
lock
hide-password
local
#debug
name l2tpd
proxyarp
mtu 1404
mru 1404
設定L2TP Client端的設定檔,/etc/ppp/options.l2tpd.client
ipcp-accept-local
ipcp-accept-remote
refuse-eap
require-mschap-v2
noccp
noauth
idle 1800
mtu 1410
mru 1410
defaultroute
replacedefaultroute                         #可不加
usepeerdns
debug
lock
connect-delay 5000
name steven                                 #撥接時的帳號
password novell                             #撥接時的密碼
新增Client端連線進來的帳號及密碼,/etc/ppp/chap-secrets,即為ppp服務
  • Client 指的使用者名稱
  • Server 指的是撥入Server的IP
  • IP addresses 指的是撥入後進來拿到IP的範圍,若先前有在xl2tpd.conf裡設定好ip range,此處就可以用*號表示
# Secrets for authentication using CHAP
# client        server  secret                  IP addresses
daniel          *        novell                 *
重開L2tp
/etc/init.d/xl2tpd restart
連結L2TP Server,即連接到指定的lac
這個撥打過去,會跟Server端的/etc/ppp/chap/secrets做驗証,如果正確就連結。
echo 'c steven' > /var/run/xl2tpd/l2tp-control
安裝OPENSWAN套件
apt-get install openswan
IPSec主要設定檔,/etc/ipsec.conf
二台的IPSec的主要設定檔要長的一樣
version 2.0
config setup
    dumpdir=/var/run/pluto/
    nat_traversal=yes
    virtual_private=%v4:10.0.0.0/8,%v4:192.168.0.0/16,%v4:172.16.0.0/12,%v4:25.0.0.0/8,%v6:fd00::/8,%v6:fe80::/10
    oe=off
    protostack=netkey                   #default是auto,要改成netkey


conn net-net                            
    authby=secret
    left=10.0.2.5                       #設對方的對外IP
    leftsubnet=192.168.1.0/24           #設對方的內部網段
    leftnexthop=%defaultroute           #採預設路由的方式
    right=10.0.2.4                      #設自已的對外IP
    rightsubnet=192.168.2.0/24          #設自已的內部網段
    rightnexthop=%defaultroute          #採預設路由
    auto=start
編輯/etc/ipsec.secrets
我採用的是sample roadwarrior,如果要用其他的寫法,請參考man ipsec.secrets
# sample roadwarrior
%any gateway.corp.com: PSK "shared secret with many roadwarriors"
%any 10.0.2.1 : PSK "novell"
編輯/etc/sysctl.conf,啟用IPv4轉發
net.ipv4.ip_forward=1
net.ipv4.conf.default.rp_filter = 0
編輯完後,執行以下指令,使其生效
sysctl -p
防火牆
請依據實際上要開的port來做設定
iptables --table nat --append POSTROUTING --jump MASQUERADE
腳本設定
#!/bin/bash
for each in /proc/sys/net/ipv4/conf/*
do
    echo 0 > $each/accept_redirects
    echo 0 > $each/send_redirects
done
驗証IPSec
ipsec verify
若出現以下訊息,是說明並沒有將ICMP給關閉,請執行上面的腳本設定或是將其放至/etc/rc.local裡,開機時,自動啟用。
 NETKEY: Testing XFRM related proc values
         ICMP default/send_redirects                [NOT DISABLED]

  Disable /proc/sys/net/ipv4/conf/*/send_redirects or NETKEY will cause act on or cause sending of bogus ICMP redirects!

         ICMP default/accept_redirects              [NOT DISABLED]

  Disable /proc/sys/net/ipv4/conf/*/accept_redirects or NETKEY will cause act on or cause sending of bogus ICMP redirects!
再次執行
ipsec verify
連結IPSec
ipsec auto --up net-net