cobbler
目录
cobbler简介
Cobbler是一个Linux服务器安装的服务,可以通过网络启动(PXE)的方式来快速安装、重装物理服务器和虚拟机,同时还可以管理DHCP,DNS等。
Cobbler可以使用命令行方式管理,也提供了基于Web的界面管理工具(cobbler-web),还提供了API接口,可以方便二次开发使用。
Cobbler是较早前的kickstart的升级版,优点是比较容易配置,还自带web界面比较易于管理。
Cobbler内置了一个轻量级配置管理系统,但它也支持和其它配置管理系统集成,如Puppet,暂时不支持SaltStack。
cobbler集成的服务:
PXE服务支持
DHCP服务管理
DNS服务管理(可选bind,dnsmasq)
电源管理
Kickstart服务支持
YUM仓库管理
TFTP(PXE启动时需要)
Apache(提供kickstart的安装源,并提供定制化的kickstart配置)
cobbler配置文件详解
cobbler配置文件目录在/etc/cobbler
配置文件 | 作用 |
---|---|
/etc/cobbler/settings | cobbler 主配置文件 |
/etc/cobbler/iso/ | iso模板配置文件 |
/etc/cobbler/pxe | pxe模板配置文件 |
/etc/cobbler/power | 电源配置文件 |
/etc/cobbler/user.conf | web服务授权配置文件 |
/etc/cobbler/users.digest | web访问的用户名密码配置文件 |
/etc/cobbler/dhcp.template | dhcp服务器的的配置模板 |
/etc/cobbler/dnsmasq.template | dns服务器的配置模板 |
/etc/cobbler/tftpd.template | tftp服务的配置模板 |
/etc/cobbler/modules.conf | 模块的配置文件 |
cobbler数据目录
目录 作用
/var/lib/cobbler/config/ | 用于存放distros,system,profiles等信息配置文件 |
---|---|
/var/lib/cobbler/triggers/ | 用于存放用户定义的cobbler命令 |
/var/lib/cobbler/kickstart/ | 默认存放kickstart文件 |
/var/lib/cobbler/loaders/ | 存放各种引导程序以及镜像目录 |
/var/www/cobbler/ks_mirror/ | 导入的发行版系统的所有数据 |
/var/www/cobbler/images/ | 导入发行版的kernel和initrd镜像用于远程网络启动 |
/var/www/cobbler/repo_mirror/ | yum仓库存储目录 |
cobbler日志文件
日志文件路径 | 说明 |
---|---|
/var/log/cobbler/installing | 客户端安装日志 |
/var/log/cobbler/cobbler.log | cobbler日志 |
cobbler工作原理
cobbler的作用
服务器上架后,可以手动选择需要安装的系统(如:Centos7 或 Centos 8)
服务器上架后,能够根据需求,安装配置操作系统(如:修改IP地址、主机名、选择安装包)
系统安装后,可以自定义的执行脚本,完成系统基础软件初始化(如:Zabbix安装配置、SaltStack安装配置)
可以当内部YUM源,并在系统安装时进行初始化
可以重装系统
Cobbler支持API,可以无缝融合到自建运维平台中
Cobbler支持网卡的路由配置、DNS配置、bonding
cobbler命令详解
cobbler check //核对当前设置是否有问题
cobbler list //列出所有的cobbler元素
cobbler report //列出元素的详细信息
cobbler sync //同步配置到数据目录,更改配置最好都要执行下
cobbler reposync //同步yum仓库
cobbler distro //查看导入的发行版系统信息
cobbler system //查看添加的系统信息
cobbler profile //查看配置信息
cobbler服务端部署
阿里云官网
配置源
可以在阿里云官网上面进行下载
配置yum源
[root@localhost ~]# dnf -y install wget
[root@localhost ~]# cd /etc/yum.repos.d/
[root@localhost yum.repos.d]# rm -rf *
[root@localhost yum.repos.d]# ls
[root@localhost yum.repos.d]# sed -i -e '/mirrors.cloud.aliyuncs.com/d' -e '/mirrors.aliyuncs.com/d' /etc/yum.repos.d/CentOS-Base.repo
[root@localhost yum.repos.d]# ls
CentOS-Base.repo
配置epel源
[root@localhost yum.repos.d]# yum install -y https://mirrors.aliyun.com/epel/epel-release-latest-8.noarch.rpm
[root@localhost yum.repos.d]# sed -i 's|^#baseurl=https://download.example/pub|baseurl=https://mirrors.aliyun.com|' /etc/yum.repos.d/epel*
[root@localhost yum.repos.d]# sed -i 's|^metalink|#metalink|' /etc/yum.repos.d/epel*
[root@localhost yum.repos.d]# ls
CentOS-Base.repo epel-modular.repo epel-testing-modular.repo epel-testing.repo epel.repo
安装cobbler以及相关软件
[root@localhost ~]# dnf module list | grep cobbler
//过滤系统上面是否有cobbler安装包,有的话选择安装3这个版本的
cobbler 3 default [d] Versatile Linux deployment server
cobbler 3.3 default [d] Versatile Linux deployment server
[root@localhost ~]# dnf -y module enable cobbler:3
[root@localhost ~]# dnf -y install httpd dhcp* tftp tftp-server cobbler cobbler-web pykickstart rsync rsync-daemon
启动服务并设置开机自启
[root@localhost ~]# systemctl enable --now httpd
Created symlink /etc/systemd/system/multi-user.target.wants/httpd.service → /usr/lib/systemd/system/httpd.service.
[root@localhost ~]# systemctl enable --now rsyncd
Created symlink /etc/systemd/system/multi-user.target.wants/rsyncd.service → /usr/lib/systemd/system/rsyncd.service.
[root@localhost ~]# systemctl enable --now tftp
Created symlink /etc/systemd/system/sockets.target.wants/tftp.socket → /usr/lib/systemd/system/tftp.socket.
[root@localhost ~]# systemctl enable --now cobblerd.service
Created symlink /etc/systemd/system/multi-user.target.wants/cobblerd.service → /usr/lib/systemd/system/cobblerd.service.
关闭防火墙和selinux并重启系统
[root@localhost ~]# systemctl stop firewalld.service
[root@localhost ~]# vim /etc/selinux/config
SELINUX=disabled
[root@localhost ~]# setenforce 0
[root@localhost ~]# systemctl disable --now firewalld.service
Removed /etc/systemd/system/multi-user.target.wants/firewalld.service.
Removed /etc/systemd/system/dbus-org.fedoraproject.FirewallD1.service.
[root@localhost ~]# reboot
查看重启的访问是否起来
[root@localhost ~]# systemctl status httpd
● httpd.service - The Apache HTTP Server
Loaded: loaded (/usr/lib/systemd/system/httpd.service; enabled; vendor preset: disabled)
Active: active (running) since Sun 2022-09-25 00:52:50 CST; 2min 2s ago
Docs: man:httpd.service(8)
Main PID: 954 (httpd)
Status: "Running, listening on: port 443, port 80"
Tasks: 231 (limit: 12221)
Memory: 63.4M
CGroup: /system.slice/httpd.service
├─954 /usr/sbin/httpd -DFOREGROUND
├─981 /usr/sbin/httpd -DFOREGROUND
├─982 (wsgi:cobbler_w -DFOREGROUND
├─983 /usr/sbin/httpd -DFOREGROUND
├─984 /usr/sbin/httpd -DFOREGROUND
└─985 /usr/sbin/httpd -DFOREGROUND
Sep 25 00:52:49 localhost systemd[1]: Starting The Apache HTTP Server...
Sep 25 00:52:50 localhost httpd[954]: AH00558: httpd: Could not reliably determine the server's full>
Sep 25 00:52:50 localhost systemd[1]: Started The Apache HTTP Server.
Sep 25 00:52:50 localhost httpd[954]: Server configured, listening on: port 443, port 80
[root@localhost ~]# systemctl status rsyncd
● rsyncd.service - fast remote file copy program daemon
Loaded: loaded (/usr/lib/systemd/system/rsyncd.service; enabled; vendor preset: disabled)
Active: active (running) since Sun 2022-09-25 00:52:51 CST; 2min 22s ago
Main PID: 1251 (rsync)
Tasks: 1 (limit: 12221)
Memory: 968.0K
CGroup: /system.slice/rsyncd.service
└─1251 /usr/bin/rsync --daemon --no-detach
Sep 25 00:52:51 localhost.localdomain systemd[1]: Started fast remote file copy program daemon.
Sep 25 00:52:51 localhost.localdomain rsyncd[1251]: rsyncd version 3.1.3 starting, listening on port>
[root@localhost ~]# systemctl status tftp
● tftp.service - Tftp Server
Loaded: loaded (/usr/lib/systemd/system/tftp.service; indirect; vendor preset: disabled)
Active: inactive (dead)
Docs: man:in.tftpd
[root@localhost ~]# systemctl status cobblerd.service
● cobblerd.service - Cobbler Helper Daemon
Loaded: loaded (/usr/lib/systemd/system/cobblerd.service; enabled; vendor preset: disabled)
Active: active (running) since Sun 2022-09-25 00:52:49 CST; 2min 39s ago
Process: 961 ExecStartPost=/usr/bin/touch /usr/share/cobbler/web/cobbler.wsgi (code=exited, status>
Main PID: 960 (cobblerd)
Tasks: 1 (limit: 12221)
Memory: 43.5M
CGroup: /system.slice/cobblerd.service
└─960 /usr/bin/python3 -s /usr/bin/cobblerd -F
Sep 25 00:52:49 localhost systemd[1]: Starting Cobbler Helper Daemon...
Sep 25 00:52:49 localhost systemd[1]: Started Cobbler Helper Daemon.
生成加密的密码
[root@localhost ~]# openssl passwd -1 -salt "$RANDOM" "redhat"
$1$27730$h2sYARYp9JNbQ74WwGb3l0
修改配置文件并将生成的密码写入其中然后重启cobbler服务
[root@localhost ~]# vim /etc/cobbler/settings.yaml
# (dual homed, etc), you need to read the --server-override section
# of the manpage for how that works.
server: 192.168.222.250 //修改server的IP地址为本机ip
# of the Cobbler server here so that PXE booting guests can find it
# if you do not set this correctly, this will be manifested in TFTP open timeouts.
next_server: 192.168.222.250 //修改next_server的IP地址为本机ip
# and put the output between the "" below.
default_password_crypted: "$1$27730$h2sYARYp9JNbQ74WwGb3l0" //将生成的密码写到这里
# set to true to enable Cobbler's DHCP management features.
# the choice of DHCP management engine is in /etc/cobbler/modules.conf
manage_dhcp: true 将fslae改为true
[root@localhost ~]# systemctl restart cobblerd.service
通过cobbler check 核对当前设置是否有问题,并解决问题
[root@localhost ~]# cobbler check
The following are potential configuration items that you may want to fix:
1: some network boot-loaders are missing from /var/lib/cobbler/loaders. If you only want to handle x86/x86_64 netbooting, you may ensure that you have installed a *recent* version of the syslinux package installed and can ignore this message entirely. Files in this directory, should you want to support all architectures, should include pxelinux.0, menu.c32, and yaboot.
2: reposync is not installed, install yum-utils or dnf-plugins-core
3: yumdownloader is not installed, install yum-utils or dnf-plugins-core
4: debmirror package is not installed, it will be required to manage debian deployments and repositories
5: fencing tools were not found, and are required to use the (optional) power management features. install cman or fence-agents to use them
Restart cobblerd and then run 'cobbler sync' to apply changes.
问题1:
[root@localhost ~]# cd /var/lib/cobbler/loaders/
[root@localhost loaders]# ls
[root@localhost loaders]# dnf -y install syslinux*
[root@localhost ~]# cp /usr/share/syslinux/pxelinux.0 /var/lib/cobbler/loaders/
[root@localhost ~]# cp /usr/share/syslinux/menu.c32 /var/lib/cobbler/loaders/
[root@localhost ~]# ls /var/lib/cobbler/loaders/
menu.c32 pxelinux.0
问题2,3:
[root@localhost ~]# dnf -y install yum-utils
问题4和问题5可以忽略,
因为如果使用的是debian系统才需要解决,使用的是centos8就可以不用解决
Debian系统解决办法安装fence-agents
配置DHCP模板文件,同步cobbler配置
[root@localhost ~]# vim /etc/cobbler/dhcp.template
subnet 192.168.222.0 netmask 255.255.255.0 { //子网的网段
option routers 192.168.222.2; //网关
option domain-name-servers 192.168.222.2; //dns服务器
option subnet-mask 255.255.255.0; //子网掩码
range dynamic-bootp 192.168.222.100 192.168.222.110;//分配地址范围(地址池)
default-lease-time 21600;
max-lease-time 43200;
next-server $next_server;
class "pxeclients" {
[root@localhost ~]# systemctl restart httpd cobblerd.service
[root@localhost ~]# cobbler sync
....
shell triggers finished successfully
running python triggers from /var/lib/cobbler/triggers/change/*
running python trigger cobbler.modules.scm_track
running python trigger cobbler.modules.managers.genders
running shell triggers from /var/lib/cobbler/triggers/change/*
shell triggers finished successfully
*** TASK COMPLETE ***
管理distro挂载镜像并导入镜像
[root@localhost ~]# mount /dev/cdrom /mnt
mount: /mnt: WARNING: device write-protected, mounted read-only.
[root@localhost ~]# cobbler import --path=/mnt/ --name=lvnanhai arch=x86_64
...
starting descent into /var/www/cobbler/distro_mirror/lvnanhai for lvnanhai-x86_64
processing repo at : /var/www/cobbler/distro_mirror/lvnanhai/AppStream
need to process repo/comps: /var/www/cobbler/distro_mirror/lvnanhai/AppStream
looking for /var/www/cobbler/distro_mirror/lvnanhai/AppStream/repodata/*comps*.xml
Keeping repodata as-is :/var/www/cobbler/distro_mirror/lvnanhai/AppStream/repodata
processing repo at : /var/www/cobbler/distro_mirror/lvnanhai/BaseOS
need to process repo/comps: /var/www/cobbler/distro_mirror/lvnanhai/BaseOS
looking for /var/www/cobbler/distro_mirror/lvnanhai/BaseOS/repodata/*comps*.xml
Keeping repodata as-is :/var/www/cobbler/distro_mirror/lvnanhai/BaseOS/repodata
*** TASK COMPLETE ***
//安装源的唯一标示就是根据name参数来定义,本例导入成功后,安装源的唯一标示就是:CentOS-lvnanhai-x86_64,如果重复,系统会提示导入失败
列出cobbler镜像列表
[root@localhost ~]# cobbler list
distros:
lvnanhai-x86_64
profiles:
lvnanhai-x86_64
systems:
repos:
images:
mgmtclasses:
packages:
files:
查看详细信息 查看指定的--name 接镜像名
[root@localhost ~]# cobbler distro report --name lvnanhai-x86_64
Name : lvnanhai-x86_64
Architecture : x86_64
Automatic Installation Template Metadata : {'tree': 'http://@@http_server@@/cblr/links/lvnanhai-x86_64'}
TFTP Boot Files : {}
Boot loader : grub
Breed : redhat
Comment :
Fetchable Files : {}
Initrd : /var/www/cobbler/distro_mirror/lvnanhai/images/pxeboot/initrd.img
Kernel : /var/www/cobbler/distro_mirror/lvnanhai/images/pxeboot/vmlinuz
Kernel Options : {}
Kernel Options (Post Install) : {}
Management Classes : []
OS Version : rhel8
Owners : ['admin']
Redhat Management Key :
Remote Boot Initrd : ~
Remote Boot Kernel : ~
Template Files : {}
创建kickstarts自动安装脚本
[root@localhost ~]# cobbler profile get-autoinstall --name lvnanhai-x86_64 >/var/lib/cobbler/templates/lvnanhai.ks
//此处>后面不要使用tab键,不然会卡住
[root@localhost ~]# vim /var/lib/cobbler/templates/lvnanhai.ks
# Firewall configuration
firewall --disabled //关闭防火墙
%packages
@^minimal-environment //添加最小化安装
%end
此时使用虚拟机去安装系统并不会成功 需要做如下操作
[root@localhost ~]# cd /usr/share/cobbler/bin/
[root@localhost bin]# ls
migrate-data-v2-to-v3.py migrate-settings.sh mkgrub.sh settings-migration-v1-to-v2.sh
[root@localhost bin]# bash mkgrub.sh
+ grub2-mkimage -O arm64-efi -o /var/lib/cobbler/loaders/grub/grubaa64.efi --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr efinet
grub2-mkimage: error: cannot open `/usr/lib/grub/arm64-efi/moddep.lst': No such file or directory.
+ set +x
+ grub2-mkimage -O i386-pc-pxe -o /var/lib/cobbler/loaders/grub/grub.0 --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr chain pxe biosdisk
+ set +x
+ grub2-mkimage -O powerpc-ieee1275 -o /var/lib/cobbler/loaders/grub/grub.ppc64le --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr net ofnet
grub2-mkimage: error: cannot open `/usr/lib/grub/powerpc-ieee1275/moddep.lst': No such file or directory.
+ set +x
+ grub2-mkimage -O x86_64-efi -o /var/lib/cobbler/loaders/grub/grubx64.efi --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr chain efinet
grub2-mkimage: error: cannot open `/usr/lib/grub/x86_64-efi/moddep.lst': No such file or directory.
+ set +x
+ ln -s /usr/share/syslinux/ldlinux.c32 /var/lib/cobbler/loaders/ldlinux.c32
+ set +x
[root@localhost bin]# ls /var/lib/cobbler/loaders/
grub ldlinux.c32 menu.c32 pxelinux.0
[root@localhost bin]# cobbler sync
....
running python trigger cobbler.modules.scm_track
running python trigger cobbler.modules.managers.genders
running shell triggers from /var/lib/cobbler/triggers/change/*
shell triggers finished successfully
*** TASK COMPLETE ***
[root@localhost bin]# systemctl restart httpd cobblerd.service
//重启服务
此时我们可以创建一个虚拟机来测试
手动创建
用户是root,密码是前面openssl指定redhat
自动安装,使用浏览器访问https://192.168.222.250/cobbler_web
默认登录的用户名和密码都为cobbler
不用自己选择,系统自动给你安装