cobbler

  • cobbler已关闭评论
  • 158 次浏览
  • A+
所属分类:linux技术
摘要

Cobbler是一个Linux服务器安装的服务,可以通过网络启动(PXE)的方式来快速安装、重装物理服务器和虚拟机,同时还可以管理DHCP,DNS等。


cobbler


cobbler简介

Cobbler是一个Linux服务器安装的服务,可以通过网络启动(PXE)的方式来快速安装、重装物理服务器和虚拟机,同时还可以管理DHCP,DNS等。

Cobbler可以使用命令行方式管理,也提供了基于Web的界面管理工具(cobbler-web),还提供了API接口,可以方便二次开发使用。

Cobbler是较早前的kickstart的升级版,优点是比较容易配置,还自带web界面比较易于管理。

Cobbler内置了一个轻量级配置管理系统,但它也支持和其它配置管理系统集成,如Puppet,暂时不支持SaltStack。

cobbler官网

cobbler集成的服务:
PXE服务支持
DHCP服务管理
DNS服务管理(可选bind,dnsmasq)
电源管理
Kickstart服务支持
YUM仓库管理
TFTP(PXE启动时需要)
Apache(提供kickstart的安装源,并提供定制化的kickstart配置)
cobbler配置文件详解
cobbler配置文件目录在/etc/cobbler

配置文件 作用
/etc/cobbler/settings cobbler 主配置文件
/etc/cobbler/iso/ iso模板配置文件
/etc/cobbler/pxe pxe模板配置文件
/etc/cobbler/power 电源配置文件
/etc/cobbler/user.conf web服务授权配置文件
/etc/cobbler/users.digest web访问的用户名密码配置文件
/etc/cobbler/dhcp.template dhcp服务器的的配置模板
/etc/cobbler/dnsmasq.template dns服务器的配置模板
/etc/cobbler/tftpd.template tftp服务的配置模板
/etc/cobbler/modules.conf 模块的配置文件

cobbler数据目录
目录 作用

/var/lib/cobbler/config/ 用于存放distros,system,profiles等信息配置文件
/var/lib/cobbler/triggers/ 用于存放用户定义的cobbler命令
/var/lib/cobbler/kickstart/ 默认存放kickstart文件
/var/lib/cobbler/loaders/ 存放各种引导程序以及镜像目录
/var/www/cobbler/ks_mirror/ 导入的发行版系统的所有数据
/var/www/cobbler/images/ 导入发行版的kernel和initrd镜像用于远程网络启动
/var/www/cobbler/repo_mirror/ yum仓库存储目录

cobbler日志文件

日志文件路径 说明
/var/log/cobbler/installing 客户端安装日志
/var/log/cobbler/cobbler.log cobbler日志

cobbler工作原理

cobbler

cobbler的作用

服务器上架后,可以手动选择需要安装的系统(如:Centos7 或 Centos 8)
服务器上架后,能够根据需求,安装配置操作系统(如:修改IP地址、主机名、选择安装包)
系统安装后,可以自定义的执行脚本,完成系统基础软件初始化(如:Zabbix安装配置、SaltStack安装配置)
可以当内部YUM源,并在系统安装时进行初始化
可以重装系统
Cobbler支持API,可以无缝融合到自建运维平台中
Cobbler支持网卡的路由配置、DNS配置、bonding

cobbler命令详解
cobbler check //核对当前设置是否有问题
cobbler list //列出所有的cobbler元素
cobbler report //列出元素的详细信息
cobbler sync //同步配置到数据目录,更改配置最好都要执行下
cobbler reposync //同步yum仓库
cobbler distro //查看导入的发行版系统信息
cobbler system //查看添加的系统信息
cobbler profile //查看配置信息

cobbler服务端部署

阿里云官网
配置源
可以在阿里云官网上面进行下载

配置yum源 [root@localhost ~]# dnf -y install wget [root@localhost ~]# cd /etc/yum.repos.d/ [root@localhost yum.repos.d]# rm -rf * [root@localhost yum.repos.d]# ls [root@localhost yum.repos.d]# sed -i -e '/mirrors.cloud.aliyuncs.com/d' -e '/mirrors.aliyuncs.com/d' /etc/yum.repos.d/CentOS-Base.repo [root@localhost yum.repos.d]# ls CentOS-Base.repo 配置epel源 [root@localhost yum.repos.d]# yum install -y https://mirrors.aliyun.com/epel/epel-release-latest-8.noarch.rpm [root@localhost yum.repos.d]# sed -i 's|^#baseurl=https://download.example/pub|baseurl=https://mirrors.aliyun.com|' /etc/yum.repos.d/epel* [root@localhost yum.repos.d]# sed -i 's|^metalink|#metalink|' /etc/yum.repos.d/epel* [root@localhost yum.repos.d]# ls CentOS-Base.repo  epel-modular.repo  epel-testing-modular.repo  epel-testing.repo  epel.repo 

安装cobbler以及相关软件

[root@localhost ~]# dnf module list | grep cobbler //过滤系统上面是否有cobbler安装包,有的话选择安装3这个版本的 cobbler              3               default [d]                              Versatile Linux deployment server                                                                                                                                                                                                 cobbler              3.3             default [d]                              Versatile Linux deployment server                   [root@localhost ~]# dnf -y module enable cobbler:3 [root@localhost ~]# dnf -y install httpd dhcp* tftp tftp-server cobbler cobbler-web pykickstart rsync rsync-daemon 

启动服务并设置开机自启

[root@localhost ~]# systemctl enable --now httpd Created symlink /etc/systemd/system/multi-user.target.wants/httpd.service → /usr/lib/systemd/system/httpd.service. [root@localhost ~]# systemctl enable --now rsyncd Created symlink /etc/systemd/system/multi-user.target.wants/rsyncd.service → /usr/lib/systemd/system/rsyncd.service. [root@localhost ~]# systemctl enable --now tftp Created symlink /etc/systemd/system/sockets.target.wants/tftp.socket → /usr/lib/systemd/system/tftp.socket. [root@localhost ~]# systemctl enable --now cobblerd.service  Created symlink /etc/systemd/system/multi-user.target.wants/cobblerd.service → /usr/lib/systemd/system/cobblerd.service. 

关闭防火墙和selinux并重启系统

[root@localhost ~]# systemctl stop firewalld.service  [root@localhost ~]# vim /etc/selinux/config  SELINUX=disabled [root@localhost ~]# setenforce 0 [root@localhost ~]# systemctl disable --now firewalld.service  Removed /etc/systemd/system/multi-user.target.wants/firewalld.service. Removed /etc/systemd/system/dbus-org.fedoraproject.FirewallD1.service. [root@localhost ~]# reboot  

查看重启的访问是否起来

[root@localhost ~]# systemctl status httpd ● httpd.service - The Apache HTTP Server    Loaded: loaded (/usr/lib/systemd/system/httpd.service; enabled; vendor preset: disabled)    Active: active (running) since Sun 2022-09-25 00:52:50 CST; 2min 2s ago      Docs: man:httpd.service(8)  Main PID: 954 (httpd)    Status: "Running, listening on: port 443, port 80"     Tasks: 231 (limit: 12221)    Memory: 63.4M    CGroup: /system.slice/httpd.service            ├─954 /usr/sbin/httpd -DFOREGROUND            ├─981 /usr/sbin/httpd -DFOREGROUND            ├─982 (wsgi:cobbler_w -DFOREGROUND            ├─983 /usr/sbin/httpd -DFOREGROUND            ├─984 /usr/sbin/httpd -DFOREGROUND            └─985 /usr/sbin/httpd -DFOREGROUND  Sep 25 00:52:49 localhost systemd[1]: Starting The Apache HTTP Server... Sep 25 00:52:50 localhost httpd[954]: AH00558: httpd: Could not reliably determine the server's full> Sep 25 00:52:50 localhost systemd[1]: Started The Apache HTTP Server. Sep 25 00:52:50 localhost httpd[954]: Server configured, listening on: port 443, port 80 [root@localhost ~]# systemctl status rsyncd ● rsyncd.service - fast remote file copy program daemon    Loaded: loaded (/usr/lib/systemd/system/rsyncd.service; enabled; vendor preset: disabled)    Active: active (running) since Sun 2022-09-25 00:52:51 CST; 2min 22s ago  Main PID: 1251 (rsync)     Tasks: 1 (limit: 12221)    Memory: 968.0K    CGroup: /system.slice/rsyncd.service            └─1251 /usr/bin/rsync --daemon --no-detach  Sep 25 00:52:51 localhost.localdomain systemd[1]: Started fast remote file copy program daemon. Sep 25 00:52:51 localhost.localdomain rsyncd[1251]: rsyncd version 3.1.3 starting, listening on port> [root@localhost ~]# systemctl status tftp ● tftp.service - Tftp Server    Loaded: loaded (/usr/lib/systemd/system/tftp.service; indirect; vendor preset: disabled)    Active: inactive (dead)      Docs: man:in.tftpd [root@localhost ~]# systemctl status cobblerd.service  ● cobblerd.service - Cobbler Helper Daemon    Loaded: loaded (/usr/lib/systemd/system/cobblerd.service; enabled; vendor preset: disabled)    Active: active (running) since Sun 2022-09-25 00:52:49 CST; 2min 39s ago   Process: 961 ExecStartPost=/usr/bin/touch /usr/share/cobbler/web/cobbler.wsgi (code=exited, status>  Main PID: 960 (cobblerd)     Tasks: 1 (limit: 12221)    Memory: 43.5M    CGroup: /system.slice/cobblerd.service            └─960 /usr/bin/python3 -s /usr/bin/cobblerd -F  Sep 25 00:52:49 localhost systemd[1]: Starting Cobbler Helper Daemon... Sep 25 00:52:49 localhost systemd[1]: Started Cobbler Helper Daemon. 

生成加密的密码

[root@localhost ~]# openssl passwd -1 -salt "$RANDOM" "redhat" $1$27730$h2sYARYp9JNbQ74WwGb3l0 

修改配置文件并将生成的密码写入其中然后重启cobbler服务

[root@localhost ~]# vim /etc/cobbler/settings.yaml  # (dual homed, etc), you need to read the --server-override section # of the manpage for how that works. server: 192.168.222.250  //修改server的IP地址为本机ip # of the Cobbler server here so that PXE booting guests can find it # if you do not set this correctly, this will be manifested in TFTP open timeouts. next_server: 192.168.222.250 //修改next_server的IP地址为本机ip # and put the output between the "" below. default_password_crypted: "$1$27730$h2sYARYp9JNbQ74WwGb3l0"  //将生成的密码写到这里 # set to true to enable Cobbler's DHCP management features. # the choice of DHCP management engine is in /etc/cobbler/modules.conf manage_dhcp: true  将fslae改为true [root@localhost ~]# systemctl restart cobblerd.service  

通过cobbler check 核对当前设置是否有问题,并解决问题

[root@localhost ~]# cobbler check The following are potential configuration items that you may want to fix:  1: some network boot-loaders are missing from /var/lib/cobbler/loaders. If you only want to handle x86/x86_64 netbooting, you may ensure that you have installed a *recent* version of the syslinux package installed and can ignore this message entirely. Files in this directory, should you want to support all architectures, should include pxelinux.0, menu.c32, and yaboot. 2: reposync is not installed, install yum-utils or dnf-plugins-core 3: yumdownloader is not installed, install yum-utils or dnf-plugins-core 4: debmirror package is not installed, it will be required to manage debian deployments and repositories 5: fencing tools were not found, and are required to use the (optional) power management features. install cman or fence-agents to use them  Restart cobblerd and then run 'cobbler sync' to apply changes. 问题1: [root@localhost ~]# cd /var/lib/cobbler/loaders/ [root@localhost loaders]# ls [root@localhost loaders]# dnf -y install syslinux* [root@localhost ~]# cp /usr/share/syslinux/pxelinux.0 /var/lib/cobbler/loaders/ [root@localhost ~]# cp /usr/share/syslinux/menu.c32 /var/lib/cobbler/loaders/ [root@localhost ~]# ls /var/lib/cobbler/loaders/ menu.c32  pxelinux.0 问题2,3: [root@localhost ~]# dnf -y install yum-utils 问题4和问题5可以忽略, 因为如果使用的是debian系统才需要解决,使用的是centos8就可以不用解决 Debian系统解决办法安装fence-agents 

配置DHCP模板文件,同步cobbler配置

[root@localhost ~]# vim /etc/cobbler/dhcp.template subnet 192.168.222.0 netmask 255.255.255.0 { //子网的网段      option routers             192.168.222.2; //网关      option domain-name-servers 192.168.222.2;  //dns服务器      option subnet-mask         255.255.255.0; //子网掩码      range dynamic-bootp        192.168.222.100 192.168.222.110;//分配地址范围(地址池)      default-lease-time         21600;      max-lease-time             43200;      next-server                $next_server;      class "pxeclients" { [root@localhost ~]# systemctl restart httpd cobblerd.service  [root@localhost ~]# cobbler sync  .... shell triggers finished successfully running python triggers from /var/lib/cobbler/triggers/change/* running python trigger cobbler.modules.scm_track running python trigger cobbler.modules.managers.genders running shell triggers from /var/lib/cobbler/triggers/change/* shell triggers finished successfully *** TASK COMPLETE *** 

管理distro挂载镜像并导入镜像

[root@localhost ~]# mount /dev/cdrom /mnt mount: /mnt: WARNING: device write-protected, mounted read-only. [root@localhost ~]# cobbler import --path=/mnt/ --name=lvnanhai arch=x86_64 ... starting descent into /var/www/cobbler/distro_mirror/lvnanhai for lvnanhai-x86_64 processing repo at : /var/www/cobbler/distro_mirror/lvnanhai/AppStream need to process repo/comps: /var/www/cobbler/distro_mirror/lvnanhai/AppStream looking for /var/www/cobbler/distro_mirror/lvnanhai/AppStream/repodata/*comps*.xml Keeping repodata as-is :/var/www/cobbler/distro_mirror/lvnanhai/AppStream/repodata processing repo at : /var/www/cobbler/distro_mirror/lvnanhai/BaseOS need to process repo/comps: /var/www/cobbler/distro_mirror/lvnanhai/BaseOS looking for /var/www/cobbler/distro_mirror/lvnanhai/BaseOS/repodata/*comps*.xml Keeping repodata as-is :/var/www/cobbler/distro_mirror/lvnanhai/BaseOS/repodata *** TASK COMPLETE *** //安装源的唯一标示就是根据name参数来定义,本例导入成功后,安装源的唯一标示就是:CentOS-lvnanhai-x86_64,如果重复,系统会提示导入失败 

列出cobbler镜像列表

[root@localhost ~]# cobbler list  distros:    lvnanhai-x86_64  profiles:    lvnanhai-x86_64  systems:  repos:  images:  mgmtclasses:  packages:  files: 

查看详细信息 查看指定的--name 接镜像名

[root@localhost ~]# cobbler distro report --name lvnanhai-x86_64 Name                           : lvnanhai-x86_64 Architecture                   : x86_64 Automatic Installation Template Metadata : {'tree': 'http://@@http_server@@/cblr/links/lvnanhai-x86_64'} TFTP Boot Files                : {} Boot loader                    : grub Breed                          : redhat Comment                        :  Fetchable Files                : {} Initrd                         : /var/www/cobbler/distro_mirror/lvnanhai/images/pxeboot/initrd.img Kernel                         : /var/www/cobbler/distro_mirror/lvnanhai/images/pxeboot/vmlinuz Kernel Options                 : {} Kernel Options (Post Install)  : {} Management Classes             : [] OS Version                     : rhel8 Owners                         : ['admin'] Redhat Management Key          :  Remote Boot Initrd             : ~ Remote Boot Kernel             : ~ Template Files                 : {} 

创建kickstarts自动安装脚本

[root@localhost ~]#  cobbler profile get-autoinstall --name lvnanhai-x86_64 >/var/lib/cobbler/templates/lvnanhai.ks //此处>后面不要使用tab键,不然会卡住 [root@localhost ~]# vim /var/lib/cobbler/templates/lvnanhai.ks # Firewall configuration firewall --disabled //关闭防火墙 %packages @^minimal-environment  //添加最小化安装 %end 

此时使用虚拟机去安装系统并不会成功 需要做如下操作

[root@localhost ~]# cd /usr/share/cobbler/bin/ [root@localhost bin]# ls migrate-data-v2-to-v3.py  migrate-settings.sh  mkgrub.sh  settings-migration-v1-to-v2.sh [root@localhost bin]# bash mkgrub.sh  + grub2-mkimage -O arm64-efi -o /var/lib/cobbler/loaders/grub/grubaa64.efi --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr efinet grub2-mkimage: error: cannot open `/usr/lib/grub/arm64-efi/moddep.lst': No such file or directory. + set +x + grub2-mkimage -O i386-pc-pxe -o /var/lib/cobbler/loaders/grub/grub.0 --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr chain pxe biosdisk + set +x + grub2-mkimage -O powerpc-ieee1275 -o /var/lib/cobbler/loaders/grub/grub.ppc64le --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr net ofnet grub2-mkimage: error: cannot open `/usr/lib/grub/powerpc-ieee1275/moddep.lst': No such file or directory. + set +x + grub2-mkimage -O x86_64-efi -o /var/lib/cobbler/loaders/grub/grubx64.efi --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr chain efinet grub2-mkimage: error: cannot open `/usr/lib/grub/x86_64-efi/moddep.lst': No such file or directory. + set +x + ln -s /usr/share/syslinux/ldlinux.c32 /var/lib/cobbler/loaders/ldlinux.c32 + set +x [root@localhost bin]# ls /var/lib/cobbler/loaders/ grub  ldlinux.c32  menu.c32  pxelinux.0 [root@localhost bin]# cobbler sync  .... running python trigger cobbler.modules.scm_track running python trigger cobbler.modules.managers.genders running shell triggers from /var/lib/cobbler/triggers/change/* shell triggers finished successfully *** TASK COMPLETE *** [root@localhost bin]# systemctl restart httpd cobblerd.service //重启服务 

此时我们可以创建一个虚拟机来测试
手动创建
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
用户是root,密码是前面openssl指定redhat
cobbler
自动安装,使用浏览器访问https://192.168.222.250/cobbler_web
默认登录的用户名和密码都为cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
cobbler
不用自己选择,系统自动给你安装
cobbler