ããã«ã¡ã¯ãHabrïŒ
ã¯ãªã¹ãã¹ã®å°ãåã«ãITéšéã§Spacewalkãç 究ããããšã決å®ãããŸãããããã¯ãäžå
åãããæ§æ管çãã·ã¹ãã æŽæ°ãããã³ãµãŒããŒããŒã¯å
šäœã®äŸ¿å©ãªãµããŒãã®ããã®ãSatelliteã®ç¡æã¢ããã°ã§ããRed Hatã·ã¹ãã ã§ãã
å
¬åŒWebãµã€ãã§å
¥æã§ããããã¥ã¡ã³ãã§ã¯ãããŸããŸãªçš®é¡ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ã®è¿œå ã³ã¡ã³ããäžè¶³ããŠãããããã¿ã¹ã¯ã¯æåã«ãã¹ããµãŒããŒã«ã次ã«è£œåã«æ®µéçã«å°å
¥ããããã«è£œåã調æ»ããããšã§ããã
Spacewalkãå°å
¥ããäž»ãªã¢ã€ãã¢ã¯ãå¶åŸ¡ã®éäžåãšåçŽåã ãã§ãªããå
äŸããã§ã«çºçããŠããããã誰ãæ°ãããããžã§ã¯ãã®ãµãŒããŒã®æŽæ°ãéã³å¿ã®ãããã³ã§åçããªãããã«ããããšã§ããã
2é±éã®ä»äºã®åŸãç§ãåãåã£ããã¹ãŠã®ç¥èã¯Confluenceã®å
éšã¢ããã°ã«å
¥åãããäŒæ¥ã®äŒã¿ã§Habrã«é¢ããèšäºãæžãããã«ãªããŸããã
å§ããåã«ãSpacewalkãæäœããããã®å®å
šãªããã¥ã¢ã«ã®ãµããããªãããã«ã圱é¿ãåãããã®ãšåããªãã£ããã®ãç°¡åã«åŒ·èª¿ããããšæããŸãã
+ãµãŒããŒ/ã¯ã©ã€ã¢ã³ãã®ã€ã³ã¹ããŒã«ãšæ§æ
+ GUIã§ã®ã·ã¹ãã ã»ããã¢ãã
+ã€ã³ã¹ããŒã«/ããã±ãŒãžã®æŽæ°ã®ãã©ãã«ã·ã¥ãŒãã£ã³ã°ãæ§æã®æäœ
+æ£èª€è¡šïŒéèŠãªæŽæ°ãè匱æ§ãªã©ã«é¢ããæ
å ±ã®åéïŒ
-ãããã·ïŒHAã®æåŠåŸã«æ¶æ»
ããå¿
èŠããããŸãïŒ
-ã³ãã©ãŒ/ããã¯ã¹ã¿ãŒã
-OpenSCAP
ã·ã¹ãã èŠä»¶
ã€ã³ãã©ã¹ãã©ã¯ãã£å
šäœãVMWareäžã§å®è¡ããããšããäºå®ã«ãããäœæ¥ã¯CentOS 7ãå®è¡ããVMäžã§å®è¡ãããŸãããéçºè
ããã®æšå¥šã·ã¹ãã èŠä»¶ã¯æ¬¡ã®ãšããã§ãã
- 4GB RAM
- / var / satellite /çšã®6GBã®ç©ºã容é
- DBçšã«12GB
ç§ã䜿çšããïŒ
- 6GB RAM
- 4 CPUïŒç§ïŒ
- 40GB HDD
ãŸããSELinuxãç¡å¹ã«ãã䜿çšããªãå Žåã¯firewalldãç¡å¹ã«ããããšããå§ãããŸãã ãŸãã¯ãhttpãµãŒãã¹ãäŸå€ã«è¿œå ããŸãã
泚ïŒèšäºã®æåŸã«ãã¯ã©ã€ã¢ã³ããšãµãŒããŒã®äž¡æ¹ã®éšåãããã³bashã¹ã¯ãªããã®Ansibleã®ãã¬ã€ããã¯ããããŸãã 圌ãã®å©ããåããŠãã€ã³ãã©ã¹ãã©ã¯ãã£å
šäœãæ°åã§å±éã§ããŸãã
èšçœ®
ã€ã³ã¹ããŒã«èªäœã¯å
¬åŒããã¥ã¡ã³ããšããã€ãã®ãµã€ãã®äž¡æ¹ã§èª¬æãããŠããŸãããèšäºã®æŽåæ§ã®ããã«ãããã§ãã®ç¹ã«ã€ããŠèšåããŸãã
Spacewalkã¯ãPostgreSQLãšOracle RDBMSã®2ã€ã®DBMSã§åäœããŸãã ç§ã¯æåã®çµéšããããä»ãã䜿çšããŸãã
2ã€ã®ã€ã³ã¹ããŒã«ãªãã·ã§ã³ããããŸããã¹ããŒã¹ãŠã©ãŒã¯ã®èªåã€ã³ã¹ããŒã©ãŒïŒã©ã¡ããåããµãŒããŒã«èªèº«ãšããŒã¿ããŒã¹ãã€ã³ã¹ããŒã«ããã³æ§æããŸãïŒãšãDBãšã¢ããªã±ãŒã·ã§ã³ãç°ãªããµãŒããŒã«é
眮ã§ããæåã€ã³ã¹ããŒã«ã®äž¡æ¹ã§ãã äž¡æ¹ã®ãªãã·ã§ã³ãæ€èšããåå¥ã®ã€ã³ã¹ããŒã«ããå§ããŸãã
PostgreSQL
yum install -y postgresql-server
PGã®PL / Tclã¢ãžã¥ãŒã«ãæ¥ç¶ããããšãå¿
èŠã§ãã
yum install -y postgresql-pltcl postgresql-setup initdb systemctl start postgresql
ããŒã¿ããŒã¹ãšãŠãŒã¶ãŒãäœæããã¢ãžã¥ãŒã«ãæ¥ç¶ããŸãã
su - postgres -c 'PGPASSWORD=verystrong; createdb spcwlkdb ; createlang plpgsql spcwlkdb ; createlang pltclu spcwlkdb ; yes $PGPASSWORD | createuser -P -sDR spcwlkuser'
æ¥ç¶ã®åé¡ãåé¿ããã«ã¯ã
/var/lib/pgsql/data/pg_hba.confãå€æŽããŠããã¹ãŠã®è¡ã®åã«æ¬¡ã®è¡ãè¿œå ããå¿
èŠããããŸãã
local spcwlkdb spcwlkuser md5 host spcwlkdb spcwlkuser 127.0.0.1/8 md5 local spcwlkdb postgres ident
ãã¹ãŠãåèµ·åããŸãã
systemctl restart postgresql
ã¢ããªã±ãŒã·ã§ã³ãšããŒã¿ããŒã¹ãç°ãªããµãŒããŒã«ã€ã³ã¹ããŒã«ããå Žåã¯ã
postgresql-contribããã±ãŒãžãããŒã¿ããŒã¹ãµãŒããŒã«ã€ã³ã¹ããŒã«ãããŠããããšã確èªããŠãã ããã
å®å®éæ³³
ãªããžããªãæ¥ç¶ããŸãïŒ
rpm -Uvh https://copr-be.cloud.fedoraproject.org/results/@spacewalkproject/spacewalk-2.8/epel-7-x86_64/00736372-spacewalk-repo/spacewalk-repo-2.8-11.el7.centos.noarch.rpm
ãŸããepelãæ¥ç¶ããŸãã
rpm -Uvh https://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm
JavaïŒ
(cd /etc/yum.repos.d && curl -O https://copr.fedorainfracloud.org/coprs/g/spacewalkproject/java-packages/repo/epel-7/group_spacewalkproject-java-packages-epel-7.repo)
Spacewalk-postgresã®ã€ã³ã¹ããŒã©ãŒãçŽæ¥ïŒ
yum -y install spacewalk-setup-postgresql
ããŒã¿ããŒã¹ã«æ¥ç¶ããŸãã
spacewalk-setup-postgresql create --db spcwlkdb --user spcwlkuser --password verystrong
å¥ã®ããŒã¿ããŒã¹/ã¢ããªã±ãŒã·ã§ã³ã¡ãœããã䜿çšããŠããå Žåã¯ã
-standaloneãã©ã°ãè¿œå ããããŒã¿ããŒã¹ãµãŒããŒã®IPã¢ãã¬ã¹ãæå®ããå¿
èŠããããŸããããŒã5432ãéãããšãå¿ããªãã§ãã ããã
泚ïŒã·ã¹ãã å
šäœã®çç£æ§ãé«ããããã«ãããŒããŠã§ã¢ã«å¿ããŠããŒã¿ããŒã¹ã調æŽããããšããå§ãããŸãã次ã«ãSpacewalkèªäœãã€ã³ã¹ããŒã«ããã€ã³ã¹ããŒã«ãå®è¡ããŸãã
yum -y install spacewalk-postgresql spacewalk-setup --external-postgresql
次ã«ãSSL蚌ææžãšããŒã¿ããŒã¹ã®äž¡æ¹ã«ã€ããŠãããã€ã質åããããŸãã ãã¹ãŠã®å€ãæåã§å
¥åãããã
-answer-fileãã©ã°ã䜿çšããŠãå°æ¥ã®ã€ã³ã¹ããŒã«ãèªååããããã«åçã®ãããã¡ã€ã«ãžã®ãã¹ãæå®ã§ããŸãã
admin-email = root@localhost ssl-set-cnames = spcwlkserver ssl-set-org = Unicorn ssl-set-org-unit = EOH ssl-set-city = Prague ssl-set-state = HMP ssl-set-country = CZ ssl-password = verystrong ssl-set-email = root@localhost ssl-config-sslvhost = Y db-backend=postgresql db-name=spcwlkdb db-user=spcwlkuser db-password=verystrong db-host=localhost db-port=5432 enable-tftp=Y
ã¢ããªã±ãŒã·ã§ã³ãçŽæ¥å¶åŸ¡ããã«ã¯ã以äžã䜿çšãã䟡å€ããããŸãã
/usr/sbin/spacewalk-service [stop|start|restart]
ã¢ããªã±ãŒã·ã§ã³ã«å¯äžãããã¹ãŠã®ãµãŒãããŒãã£ãµãŒãã¹ã衚瀺ããã«ã¯ïŒ
spacewalk-service status
ãªãã·ã§ã³2ãèªåã€ã³ã¹ããŒã«
ãªããžããªãæ¥ç¶ãããã次ãèšå®ããŠå®è¡ããŸãã
yum -y install spacewalk-setup-postgresql yum -y install spacewalk-postgresql spacewalk-setup
ç¹°ãè¿ããŸãããããŒã¿ããŒã¹ãšSSLã«é¢ãã質åããããŸã
ã--answer-fileããŒãšãåçã®ãããã¡ã€ã«ãžã®ãã¹ã䜿çšããŸãã
ããŒã¹ããã³åãã£ã³ãã«ããªããžããª
ã¯ã©ã€ã¢ã³ãã¹ããŒã·ã§ã³ã管çããããã«ãSpacewalkã¯ãããããã£ãã«ã®ã·ã¹ãã ã䜿çšããŸããããã¯ã¡ã€ã³ïŒåïŒãŸãã¯åïŒåïŒã®ããããã§ãå¿
èŠãªãªããžããªã¯åãã£ãã«ã«æ¥ç¶ãããããŒã¯ã¯ã©ã€ã¢ã³ããšãã¢ã«ãªããŸããµãŒããŒã
ãã®çµæããªããžããªã¯ãã£ãã«ãšåæããããã£ãã«ã¯ã¯ã©ã€ã¢ã³ããšæ¥ç¶ãããSpacewalkã¯äžè¬çãªæ¹æ³ã§åäœããŸãã ãã£ã³ãã«ã«çµã³ä»ããããšãã§ãããšã©ãŒã¿ãèšåãã䟡å€ããããæŽæ°ãšããã±ãŒãžå¶åŸ¡ãç°¡çŽ åããŸãã
ãã¹ãŠã®ã¯ã©ã€ã¢ã³ãã¯ãåããã£ãã«ã§ããç°ãªããã£ãã«ãŸãã¯ãªããžããªã§ããããŸããŸãªåºæºã«åŸã£ãŠã°ã«ãŒãåããããšãã§ããŸããäžåºŠã«å€æ°ã®ã¯ã©ã€ã¢ã³ããšé£æºããããšãã§ãã100以äžã®ãµãŒããŒã§æŽæ°ãè¡ãããšãã§ããŸãã
ãã¹ãŠã®ã€ã³ã¹ããŒã«æžã¿ããã±ãŒãžã®ãªã¹ããå©çšå¯èœã§ããããªããžããªã®åæåŸãã€ã³ã¹ããŒã«ãå¯èœã§ãã äžéšã®ãã€ã³ãã¯çŽæçã§ãããåã¢ã€ãã ãè¡ããšã«æ€èšããŠãæå³ããããŸããã
Spacewalkã®ãã¹ãŠã®ã¢ã¯ã·ã§ã³ã¯ã¹ã±ãžã¥ãŒã«ïŒã¹ã±ãžã¥ãŒã«ïŒã§å®è¡ãããŸããã»ãšãã©ãã¹ãŠã®ã¢ã¯ã·ã§ã³ã¯ãæãéœåã®è¯ãæéã«èšå®ã§ããŸãã
ã€ã³ã¹ããŒã«åŸããµãŒããŒã®ã¢ãã¬ã¹ã«ç§»åããã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠããã«èšå®ãå®è¡ã§ããŸãã
ãã¹ã¯ãŒãã管çè
åãçµç¹åïŒã¯ã©ã€ã¢ã³ãã管çããæ¹æ³ã®1ã€ã§ããããŸãïŒãå
¥åããã¹ã¿ãŒãããã«ã«ç§»åããŸãã
ä»ã®ãšãããå©çšå¯èœãªãªãã·ã§ã³ãèªåã§èª¿ã¹ããããã£ã³ãã«ã®äœæã«é²ãããšãã§ããŸãã
ãã£ãã«-ãœãããŠã§ã¢ãã£ãã«ã®ç®¡ç-ãã£ãã«ã®äœæïŒCentOS_7_x86_64ãªã©ããã®ãã£ãã«ã«ãã€ã³ããããOSã®ã¿ã€ããšã¿ã€ãã«åŸã£ãŠãã£ãã«åãèšå®ããããšããå§ãããŸãããã§ãã¯ãšããŠsha256ãå®å
šã«éžæã§ããŸããChannellSummaryãã£ãŒã«ãã¯ãã£ãã«ã®ç°¡åãªèª¬æçšã§ãã ãŸãããªãã·ã§ã³ã§è¿œå æ
å ±ãæäŸã§ããŸãã
次ã«ãåãã£ãã«ãäœæããŠãã¡ã€ã³ãã£ãã«ã«ãã€ã³ãããŸãã ã¡ã€ã³ãã£ã³ãã«ãäœæããã®ãšåãæ¹æ³ã§ã芪ãã£ã³ãã«ãã£ãŒã«ãã§ã®ã¿ã以åã«äœæããããã£ã³ãã«ã瀺ããŸãã
ãªããžããªãã¡ã€ã³ããã³ãµããã£ãã«ã«ãã€ã³ãããŸãã
ãã£ã³ãã«-ãªããžããªã®ç®¡çã¡ã€ã³ãã£ãã«ã«ã€ããŠã¯ãããŒã¹ãªãœãŒã¹ã䜿çšãããµããã£ãã«ã«ã€ããŠã¯æŽæ°ã䜿çšããŸãã
ãªããžããªãäœæãããããããããã£ãã«ã«æ¥ç¶ããå¿
èŠããããŸãã
ãã£ã³ãã«-ãœãããŠã§ã¢ãã£ã³ãã«ã®ç®¡ç ãã¡ã€ã³ãã£ã³ãã«ãéãããªããžããªã»ã¯ã·ã§ã³ãéããŸãã
äœæããããã¹ãŠã®ãªããžããªããããå¿
èŠãªãªããžããªãéžæããŠããŒã¯ãã[ãªãœãŒã¹ã®æŽæ°]ãã¯ãªãã¯ããŸãã
次ã«ãåæãµãããŒãéããŸãã
ãªããžããªãšãã£ãã«ãåæã§ããå Žæã§ãåæã®ã¹ã±ãžã¥ãŒã«ãæ§æããŸãã
泚ïŒéã³å¿ã®ãããã³ã®å Žåãã¯ã©ã€ã¢ã³ãã·ã¹ãã ããæšæºãªããžããªãåé€ããå¿
èŠããããŸãããã¯ã©ã€ã¢ã³ãã®ã€ã³ã¹ããŒã«ãã¯ã©ã€ã¢ã³ããšãµãŒããŒã®ãã¢ãªã³ã°ãããŒç®¡çãæ§æãã£ãã«ã®ã»ããã¢ãã
åè¿°ããããã«ãSpacewalkã¯Red Hat Networkã®ããŒã·ã¹ãã ã䜿çšããŸããããã¯ããã¢ãªã³ã°ãšç®¡çã«äœ¿çšãããŸãã
ããŒãäœæããã«ã¯ã[
ã·ã¹ãã ]-[ã¢ã¯ãã£ããŒã·ã§ã³ããŒ]-[ããŒã®äœæ]ã«ç§»åããŸããããã§ã¯ãã¹ãŠãéåžžã«ç°¡åã§ããèªåã§ããŒãèšå®ã§ãããã®åœ¢åŒã¯åžžã«
1-XXXXXXã§ãããåããŒã¯ãã£ãã«ã«ã¢ã¿ãããããŠããããšãèšåãã䟡å€ããããŸãã Universal Defaultãã©ã°ã¯ãæ°ããã·ã¹ãã ã«ããŒãã©ã¡ãŒã¿ãŒã匷å¶çã«éžæãããŸãã
ã¯ã©ã€ã¢ã³ãã®ã€ã³ã¹ããŒã«ã¯ã©ã€ã¢ã³ããªããžããªãæ¥ç¶ããå¿
èŠãªããã±ãŒãžãã€ã³ã¹ããŒã«ããŸãã
rpm -Uvh https://copr-be.cloud.fedoraproject.org/results/@spacewalkproject/spacewalk-2.8-client/epel-7-x86_64/00742644-spacewalk-repo/spacewalk-client-repo-2.8-11.el7.centos.noarch.rpm yum -y install rhn-client-tools rhn-check rhn-setup rhnsd m2crypto yum-rhn-plugin rhncfg-actions deltarpm
泚ïŒrhncfg-actionsãšdeltarpmã¯ãæ§æãšãªã¢ãŒãã³ã³ãããŒã«ãæ£ããæ©èœããããã«å¿
èŠã§ããSpacewalkã¯rhn_checkã䜿çšããŠã4æéããšã«å®è¡ãããã¯ã©ã€ã¢ã³ããµãŒããŒãåæããŸãã ãã®å€ã¯æ倧60åãŸã§ççž®ã§ããŸãããç§ã«ãšã£ãŠæé©ãªãªãã·ã§ã³ã¯ãããŸããã§ããããã®ãããSpacewalkã«ä»å±ããosadã䜿çšããããrhn_checkã«cronjobãè¿œå ãããªã©ã1åããšã«ã·ã¹ãã ããã¹ãããŠãããå¿
èŠã«å¿ããŠå€ãå€æŽã§ããŸãã
crontab -e * * * * * /usr/sbin/rhn_check
ãŸãã/ usr / bin / rhn-actions-control --enable-allãCronã«è¿œå ããããšãäžå¿
èŠã§ã¯ãªããæ§æã®å±éã«äœ¿çšãããå Žåã«ãã£ãŠã¯éããªãããšããããŸãã
ããŒç®¡çã«æ»ããäœæããããŒIDãã³ããŒããŠå®è¡ããŸãã
rhnreg_ks --serverUrl=http://your-server-ip/XMLRPC --activationkey=1-YOURKEY --force
IPãšããŒã®å€ãèªåã®ãã®ã«å€æŽããããšãå¿ããªãã§ãã ããã ç¹°ãè¿ããŸããããã®ãã©ã°ã䜿çšããã«åé¡ã«æ°ã¥ããããã
-forceãã©ã°ã䜿çšããããšããå§ãããŸãã
ã·ã¹ãã ã«æ»ããŸã
-ãã¹ãŠ ãã·ã¹ãã ã«æ³šç®ããŸãã ãããéããŠãäœãã©ã®ããã«æ¢çŽ¢ããããšãã§ããŸãããä»ã®ãšããã¯ãã·ã¹ãã 管çããã䟿å©ã«ããã°ã«ãŒããäœæããããšã匷ããå§ãããŸãã
Systems-System Goups-Create Group ãååãšèª¬æãå
¥åããä¿åããæ°ããäœæããã°ã«ãŒããéãã
Systemsã»ã¯ã·ã§ã³ã«ç§»åããŠ
ã·ã¹ãã ãã°ã«ãŒãã«è¿œå ããŸãã
ã·ã¹ãã ããã£ã³ãã«ã«ãµãã¹ã¯ã©ã€ãããŸã
ãSystems-Your system-Software folder-Software Channelsãµããã©ã«ããŒïŒãã£ã³ãã«ãéžæããŠã確èªãã¯ãªãã¯ããŸãã 楜ãã¿ã®ããã«ãããã±ãŒãž
Software-Packages-Installãã€ã³ã¹ããŒã«ããŠã¿ãŠãã ããã
èšå®ãã£ã³ãã«ã¯ã©ã€ã¢ã³ããµãŒããŒ/ããŒã«ã«ãã·ã³éã®æ§æãããã³ãªã¢ãŒãã³ã³ãããŒã«ã管çããã«ã¯ãæ§æãã£ãã«ãèšå®ããã·ã¹ãã ãããã«ãªã³ã¯ãã䟡å€ããããŸãã
æ§æ-æ§æãã£ãã«-æ§æãã£ãã«ã®äœæ ãååã説æã®èšå®ãä¿åã«é²ã¿ã
æ§æ-æ§æãã£ãã«ã®ç®¡ç-ãã£ãã«ã®ãµãã¹ã¯ã©ã€ããè¡ããæ§æãã£ãã«ã«ãœãããŠã§ã¢ãã£ãã«ãšã·ã¹ãã ã«çœ²åããŸãã
ããã§ããµãŒããŒãšããŒã«ã«ãã·ã³ã®äž¡æ¹ããæ§æãå±éããããŒãã£ã·ã§ã³ãäœæã§ããŸãã
èšå®-ãã¡ã€ã«ã®è¿œå -ãã¡ã€ã«ã®äœæ/ãã¡ã€ã«ã®ã¢ããããŒãïŒãŸããbashã¹ã¯ãªããã®åœ¢åŒã§ãªã¢ãŒãã³ãã³ããéä¿¡ã§ããŸãã
ãã¹ãŠã®ã¢ã¯ã·ã§ã³ã¯ã¹ã±ãžã¥ãŒã«ãééããããšãæãåºããŠãã ããããã®ã·ã¹ãã ã«é©çšããããã¹ãŠã®ã¢ã¯ã·ã§ã³ã®ãªã¹ãã¯ãã€ãã³ãã»ã¯ã·ã§ã³ã«ãããŸãã
æ£èª€è¡šSpacewalkã®æãéèŠãªæ©èœã®1ã€ã¯ãšã©ãŒã¿ãµããŒãã§ããããã¯ããã£ãã«ã«ç°¡åã«ãã€ã³ãããæè¿ã®æŽæ°ã®éèŠåºŠãç£èŠã§ããããã«ããŸãã ããã¯ãã¹ã¯ãªããã«å ããŠããµãŒããŒäžã§çŽæ¥æ§æãããŸããPearlã«å¿
èŠãªããã±ãŒãžãããŠã³ããŒãããå¿
èŠããããŸãã
yum -y install perl-Frontier-RPC perl-Text-Unidecode wget https://raw.githubusercontent.com/stevemeier/cefs/master/errata-import.pl chmod +x errata-import.pl
次ã«ãã¡ã€ã³ã®æŽæ°ããã³ã³ã¬ã¯ã·ã§ã³ã¹ã¯ãªããã®ãšã©ãã¿ãäœæããŸããããã¯
/ etc / rhn /ã«ä¿åãããŸã
ã
ãšã¯ã¹ããŒãã§ãæåã«æå®ããSpacewalk管çè
ã®ååãšãã¹ã¯ãŒããæå®ããŸãã
ã¹ã¯ãªãããå®è¡å¯èœã«ããŠãCronã«è¿œå ããŸãããã
chmod +x spcwlk_errata.sh crontab -e 0 2 * * 7 /usr/bin/sh /etc/rhn/spcwlk_errata.sh
ä»ããå®è¡ããŠãã°ã©ãã£ãã¯ã€ã³ã¿ãŒãã§ã€ã¹ã®å€æŽã確èªããŸãããã å®è¡ã«ã¯æéãããããŸãã
ãŸãšã
ç§ãå人çã«èŠéããéèŠãªç¹ã¯ããããã·ãã»ããã¢ããããŠã€ã³ã¹ããŒã«ããããšãããã³ã·ã¹ãã å
šäœãHAãšããŠäžããããšã§ãã ããŒã¹ã¡ãŒã«ãŒãä»ããŠã¢ããªã±ãŒã·ã§ã³ãæ§æããããŒã¿ããŒã¹ã§åæããããšãèããŠããŸããã ãã®çµæãã¯ã©ã€ã¢ã³ãã¹ããŒã·ã§ã³ã®ãµãŒããŒçŸ€ãããã»ã©å€§ãããªãããšãèæ
®ããŠããã®ã¢ã€ãã¢ãæŸæ£ããããšã決å®ãããŸããã ãã ããã·ã¹ãã ãä»åŸ6ãæã§éåžžã«æçšã§ããããšãå€æããå Žåã¯ãå
ã®ãµãŒããŒãæ¡åŒµããå¿
èŠããããŸãã
èªåå
ãµãŒããŒïŒãµãŒããŒå±éçšã®Bashã¹ã¯ãªããïŒfirewalldãç¡å¹ã«ããïŒïŒ ãšã©ãŒã¿ãã€ã³ã¹ããŒã«ããããã®Bashã¹ã¯ãªããïŒæåã«Spacewalk管çè
ã®ååãšãã¹ã¯ãŒããèšå®ïŒïŒ ãµãŒããŒå±éã®ããã®Ansibleãã¬ã€ããã¯ïŒå¿çãã¡ã€ã«ã®è¿œå ãå¿ããªãã§ãã ããïŒïŒ - hosts: spcwlk-server tasks: - name: Install Spacewalk repo yum: name: https://copr-be.cloud.fedoraproject.org/results/@spacewalkproject/spacewalk-2.8/epel-7-x86_64/00736372-spacewalk-repo/spacewalk-repo-2.8-11.el7.centos.noarch.rpm state: present - name: Install epel repo yum: name: https://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm state: present - name: Install PostgreSQL packages yum: name: - spacewalk-setup-postgresql - spacewalk-postgresql - wget - perl-Frontier-RPC - perl-Text-Unidecode - perl-XML-Simple - name: Creates directory for Spacewalk answer file file: path: /usr/share/spcwlk-tmp/ state: directory mode: 0755 - name: Deploy answer file copy: src: /etc/ansible/spcwlk_answer dest: /usr/share/spcwlk-tmp/spcwlk_answer - name: Spacewalk Server Deploy shell: spacewalk-setup --answer-file=/usr/share/spcwlk-tmp/spcwlk_answer - name: Stop firewalld systemd: name: firewalld state: stopped enabled: no
顧客ïŒã¯ã©ã€ã¢ã³ãå±éçšã®Bashã¹ã¯ãªããïŒIPãšããŒãå¿ããªãã§ãã ããïŒïŒ ã¯ã©ã€ã¢ã³ãå±éã®ããã®Anisbleãã¬ã€ããã¯ïŒ - hosts: spcwlk-clients tasks: - name: Install spacewalk repo yum: name: https://copr-be.cloud.fedoraproject.org/results/@spacewalkproject/spacewalk-2.8-client/epel-7-x86_64/00742644-spacewalk-repo/spacewalk-client-repo-2.8-11.el7.centos.noarch.rpm state: present - name: Install client packages yum: name: - rhn-client-tools - rhn-check - rhn-setup - rhnsd - m2crypto - yum-rhn-plugin - rhncfg-actions - deltarpm - wget - name: Create cronjob for rhn_check cron: name: "rhn_check" minute: "*" hour: "*" day: "*" month: "*" weekday: "*" job: "/usr/sbin/rhn_check" - name: Enable controls for config and remote control deployment shell: /usr/bin/rhn-actions-control --enable-all - name: Get certificate from server to client get_url: url: http://YourServerIPAddress/pub/RHN-ORG-TRUSTED-SSL-CERT dest: /usr/share/rhn/ - name: Register client to server rhn_register: state: present server_url: http://YourServerIPAddress/XMLRPC activationkey: "{{ activation_key }}"
èšäºãèªãã§ãããŠããããšãã é 匵ã£ãŠ