- A+
cobbler
cobbler简介
Cobbler是一个Linux服务器安装的服务,可以通过网络启动(PXE)的方式来快速安装、重装物理服务器和虚拟机,同时还可以管理DHCP,DNS等。
Cobbler可以使用命令行方式管理,也提供了基于Web的界面管理工具(cobbler-web),还提供了API接口,可以方便二次开发使用。
Cobbler是较早前的kickstart的升级版,优点是比较容易配置,还自带web界面比较易于管理。
Cobbler内置了一个轻量级配置管理系统,但它也支持和其它配置管理系统集成,如Puppet,暂时不支持SaltStack。
cobbler集成的服务:
PXE服务支持
DHCP服务管理
DNS服务管理(可选bind,dnsmasq)
电源管理
Kickstart服务支持
YUM仓库管理
TFTP(PXE启动时需要)
Apache(提供kickstart的安装源,并提供定制化的kickstart配置)
cobbler配置文件详解
cobbler配置文件目录在/etc/cobbler
配置文件 | 作用 |
---|---|
/etc/cobbler/settings | cobbler 主配置文件 |
/etc/cobbler/iso/ | iso模板配置文件 |
/etc/cobbler/pxe | pxe模板配置文件 |
/etc/cobbler/power | 电源配置文件 |
/etc/cobbler/user.conf | web服务授权配置文件 |
/etc/cobbler/users.digest | web访问的用户名密码配置文件 |
/etc/cobbler/dhcp.template | dhcp服务器的的配置模板 |
/etc/cobbler/dnsmasq.template | dns服务器的配置模板 |
/etc/cobbler/tftpd.template | tftp服务的配置模板 |
/etc/cobbler/modules.conf | 模块的配置文件 |
cobbler数据目录
目录 作用
/var/lib/cobbler/config/ | 用于存放distros,system,profiles等信息配置文件 |
---|---|
/var/lib/cobbler/triggers/ | 用于存放用户定义的cobbler命令 |
/var/lib/cobbler/kickstart/ | 默认存放kickstart文件 |
/var/lib/cobbler/loaders/ | 存放各种引导程序以及镜像目录 |
/var/www/cobbler/ks_mirror/ | 导入的发行版系统的所有数据 |
/var/www/cobbler/images/ | 导入发行版的kernel和initrd镜像用于远程网络启动 |
/var/www/cobbler/repo_mirror/ | yum仓库存储目录 |
cobbler日志文件
日志文件路径 | 说明 |
---|---|
/var/log/cobbler/installing | 客户端安装日志 |
/var/log/cobbler/cobbler.log | cobbler日志 |
cobbler工作原理
cobbler的作用
服务器上架后,可以手动选择需要安装的系统(如:Centos7 或 Centos 8)
服务器上架后,能够根据需求,安装配置操作系统(如:修改IP地址、主机名、选择安装包)
系统安装后,可以自定义的执行脚本,完成系统基础软件初始化(如:Zabbix安装配置、SaltStack安装配置)
可以当内部YUM源,并在系统安装时进行初始化
可以重装系统
Cobbler支持API,可以无缝融合到自建运维平台中
Cobbler支持网卡的路由配置、DNS配置、bonding
cobbler命令详解
cobbler check //核对当前设置是否有问题
cobbler list //列出所有的cobbler元素
cobbler report //列出元素的详细信息
cobbler sync //同步配置到数据目录,更改配置最好都要执行下
cobbler reposync //同步yum仓库
cobbler distro //查看导入的发行版系统信息
cobbler system //查看添加的系统信息
cobbler profile //查看配置信息
cobbler服务端部署
阿里云官网
配置源
可以在阿里云官网上面进行下载
配置yum源 [root@localhost ~]# dnf -y install wget [root@localhost ~]# cd /etc/yum.repos.d/ [root@localhost yum.repos.d]# rm -rf * [root@localhost yum.repos.d]# ls [root@localhost yum.repos.d]# sed -i -e '/mirrors.cloud.aliyuncs.com/d' -e '/mirrors.aliyuncs.com/d' /etc/yum.repos.d/CentOS-Base.repo [root@localhost yum.repos.d]# ls CentOS-Base.repo 配置epel源 [root@localhost yum.repos.d]# yum install -y https://mirrors.aliyun.com/epel/epel-release-latest-8.noarch.rpm [root@localhost yum.repos.d]# sed -i 's|^#baseurl=https://download.example/pub|baseurl=https://mirrors.aliyun.com|' /etc/yum.repos.d/epel* [root@localhost yum.repos.d]# sed -i 's|^metalink|#metalink|' /etc/yum.repos.d/epel* [root@localhost yum.repos.d]# ls CentOS-Base.repo epel-modular.repo epel-testing-modular.repo epel-testing.repo epel.repo
安装cobbler以及相关软件
[root@localhost ~]# dnf module list | grep cobbler //过滤系统上面是否有cobbler安装包,有的话选择安装3这个版本的 cobbler 3 default [d] Versatile Linux deployment server cobbler 3.3 default [d] Versatile Linux deployment server [root@localhost ~]# dnf -y module enable cobbler:3 [root@localhost ~]# dnf -y install httpd dhcp* tftp tftp-server cobbler cobbler-web pykickstart rsync rsync-daemon
启动服务并设置开机自启
[root@localhost ~]# systemctl enable --now httpd Created symlink /etc/systemd/system/multi-user.target.wants/httpd.service → /usr/lib/systemd/system/httpd.service. [root@localhost ~]# systemctl enable --now rsyncd Created symlink /etc/systemd/system/multi-user.target.wants/rsyncd.service → /usr/lib/systemd/system/rsyncd.service. [root@localhost ~]# systemctl enable --now tftp Created symlink /etc/systemd/system/sockets.target.wants/tftp.socket → /usr/lib/systemd/system/tftp.socket. [root@localhost ~]# systemctl enable --now cobblerd.service Created symlink /etc/systemd/system/multi-user.target.wants/cobblerd.service → /usr/lib/systemd/system/cobblerd.service.
关闭防火墙和selinux并重启系统
[root@localhost ~]# systemctl stop firewalld.service [root@localhost ~]# vim /etc/selinux/config SELINUX=disabled [root@localhost ~]# setenforce 0 [root@localhost ~]# systemctl disable --now firewalld.service Removed /etc/systemd/system/multi-user.target.wants/firewalld.service. Removed /etc/systemd/system/dbus-org.fedoraproject.FirewallD1.service. [root@localhost ~]# reboot
查看重启的访问是否起来
[root@localhost ~]# systemctl status httpd ● httpd.service - The Apache HTTP Server Loaded: loaded (/usr/lib/systemd/system/httpd.service; enabled; vendor preset: disabled) Active: active (running) since Sun 2022-09-25 00:52:50 CST; 2min 2s ago Docs: man:httpd.service(8) Main PID: 954 (httpd) Status: "Running, listening on: port 443, port 80" Tasks: 231 (limit: 12221) Memory: 63.4M CGroup: /system.slice/httpd.service ├─954 /usr/sbin/httpd -DFOREGROUND ├─981 /usr/sbin/httpd -DFOREGROUND ├─982 (wsgi:cobbler_w -DFOREGROUND ├─983 /usr/sbin/httpd -DFOREGROUND ├─984 /usr/sbin/httpd -DFOREGROUND └─985 /usr/sbin/httpd -DFOREGROUND Sep 25 00:52:49 localhost systemd[1]: Starting The Apache HTTP Server... Sep 25 00:52:50 localhost httpd[954]: AH00558: httpd: Could not reliably determine the server's full> Sep 25 00:52:50 localhost systemd[1]: Started The Apache HTTP Server. Sep 25 00:52:50 localhost httpd[954]: Server configured, listening on: port 443, port 80 [root@localhost ~]# systemctl status rsyncd ● rsyncd.service - fast remote file copy program daemon Loaded: loaded (/usr/lib/systemd/system/rsyncd.service; enabled; vendor preset: disabled) Active: active (running) since Sun 2022-09-25 00:52:51 CST; 2min 22s ago Main PID: 1251 (rsync) Tasks: 1 (limit: 12221) Memory: 968.0K CGroup: /system.slice/rsyncd.service └─1251 /usr/bin/rsync --daemon --no-detach Sep 25 00:52:51 localhost.localdomain systemd[1]: Started fast remote file copy program daemon. Sep 25 00:52:51 localhost.localdomain rsyncd[1251]: rsyncd version 3.1.3 starting, listening on port> [root@localhost ~]# systemctl status tftp ● tftp.service - Tftp Server Loaded: loaded (/usr/lib/systemd/system/tftp.service; indirect; vendor preset: disabled) Active: inactive (dead) Docs: man:in.tftpd [root@localhost ~]# systemctl status cobblerd.service ● cobblerd.service - Cobbler Helper Daemon Loaded: loaded (/usr/lib/systemd/system/cobblerd.service; enabled; vendor preset: disabled) Active: active (running) since Sun 2022-09-25 00:52:49 CST; 2min 39s ago Process: 961 ExecStartPost=/usr/bin/touch /usr/share/cobbler/web/cobbler.wsgi (code=exited, status> Main PID: 960 (cobblerd) Tasks: 1 (limit: 12221) Memory: 43.5M CGroup: /system.slice/cobblerd.service └─960 /usr/bin/python3 -s /usr/bin/cobblerd -F Sep 25 00:52:49 localhost systemd[1]: Starting Cobbler Helper Daemon... Sep 25 00:52:49 localhost systemd[1]: Started Cobbler Helper Daemon.
生成加密的密码
[root@localhost ~]# openssl passwd -1 -salt "$RANDOM" "redhat" $1$27730$h2sYARYp9JNbQ74WwGb3l0
修改配置文件并将生成的密码写入其中然后重启cobbler服务
[root@localhost ~]# vim /etc/cobbler/settings.yaml # (dual homed, etc), you need to read the --server-override section # of the manpage for how that works. server: 192.168.222.250 //修改server的IP地址为本机ip # of the Cobbler server here so that PXE booting guests can find it # if you do not set this correctly, this will be manifested in TFTP open timeouts. next_server: 192.168.222.250 //修改next_server的IP地址为本机ip # and put the output between the "" below. default_password_crypted: "$1$27730$h2sYARYp9JNbQ74WwGb3l0" //将生成的密码写到这里 # set to true to enable Cobbler's DHCP management features. # the choice of DHCP management engine is in /etc/cobbler/modules.conf manage_dhcp: true 将fslae改为true [root@localhost ~]# systemctl restart cobblerd.service
通过cobbler check 核对当前设置是否有问题,并解决问题
[root@localhost ~]# cobbler check The following are potential configuration items that you may want to fix: 1: some network boot-loaders are missing from /var/lib/cobbler/loaders. If you only want to handle x86/x86_64 netbooting, you may ensure that you have installed a *recent* version of the syslinux package installed and can ignore this message entirely. Files in this directory, should you want to support all architectures, should include pxelinux.0, menu.c32, and yaboot. 2: reposync is not installed, install yum-utils or dnf-plugins-core 3: yumdownloader is not installed, install yum-utils or dnf-plugins-core 4: debmirror package is not installed, it will be required to manage debian deployments and repositories 5: fencing tools were not found, and are required to use the (optional) power management features. install cman or fence-agents to use them Restart cobblerd and then run 'cobbler sync' to apply changes. 问题1: [root@localhost ~]# cd /var/lib/cobbler/loaders/ [root@localhost loaders]# ls [root@localhost loaders]# dnf -y install syslinux* [root@localhost ~]# cp /usr/share/syslinux/pxelinux.0 /var/lib/cobbler/loaders/ [root@localhost ~]# cp /usr/share/syslinux/menu.c32 /var/lib/cobbler/loaders/ [root@localhost ~]# ls /var/lib/cobbler/loaders/ menu.c32 pxelinux.0 问题2,3: [root@localhost ~]# dnf -y install yum-utils 问题4和问题5可以忽略, 因为如果使用的是debian系统才需要解决,使用的是centos8就可以不用解决 Debian系统解决办法安装fence-agents
配置DHCP模板文件,同步cobbler配置
[root@localhost ~]# vim /etc/cobbler/dhcp.template subnet 192.168.222.0 netmask 255.255.255.0 { //子网的网段 option routers 192.168.222.2; //网关 option domain-name-servers 192.168.222.2; //dns服务器 option subnet-mask 255.255.255.0; //子网掩码 range dynamic-bootp 192.168.222.100 192.168.222.110;//分配地址范围(地址池) default-lease-time 21600; max-lease-time 43200; next-server $next_server; class "pxeclients" { [root@localhost ~]# systemctl restart httpd cobblerd.service [root@localhost ~]# cobbler sync .... shell triggers finished successfully running python triggers from /var/lib/cobbler/triggers/change/* running python trigger cobbler.modules.scm_track running python trigger cobbler.modules.managers.genders running shell triggers from /var/lib/cobbler/triggers/change/* shell triggers finished successfully *** TASK COMPLETE ***
管理distro挂载镜像并导入镜像
[root@localhost ~]# mount /dev/cdrom /mnt mount: /mnt: WARNING: device write-protected, mounted read-only. [root@localhost ~]# cobbler import --path=/mnt/ --name=lvnanhai arch=x86_64 ... starting descent into /var/www/cobbler/distro_mirror/lvnanhai for lvnanhai-x86_64 processing repo at : /var/www/cobbler/distro_mirror/lvnanhai/AppStream need to process repo/comps: /var/www/cobbler/distro_mirror/lvnanhai/AppStream looking for /var/www/cobbler/distro_mirror/lvnanhai/AppStream/repodata/*comps*.xml Keeping repodata as-is :/var/www/cobbler/distro_mirror/lvnanhai/AppStream/repodata processing repo at : /var/www/cobbler/distro_mirror/lvnanhai/BaseOS need to process repo/comps: /var/www/cobbler/distro_mirror/lvnanhai/BaseOS looking for /var/www/cobbler/distro_mirror/lvnanhai/BaseOS/repodata/*comps*.xml Keeping repodata as-is :/var/www/cobbler/distro_mirror/lvnanhai/BaseOS/repodata *** TASK COMPLETE *** //安装源的唯一标示就是根据name参数来定义,本例导入成功后,安装源的唯一标示就是:CentOS-lvnanhai-x86_64,如果重复,系统会提示导入失败
列出cobbler镜像列表
[root@localhost ~]# cobbler list distros: lvnanhai-x86_64 profiles: lvnanhai-x86_64 systems: repos: images: mgmtclasses: packages: files:
查看详细信息 查看指定的--name 接镜像名
[root@localhost ~]# cobbler distro report --name lvnanhai-x86_64 Name : lvnanhai-x86_64 Architecture : x86_64 Automatic Installation Template Metadata : {'tree': 'http://@@http_server@@/cblr/links/lvnanhai-x86_64'} TFTP Boot Files : {} Boot loader : grub Breed : redhat Comment : Fetchable Files : {} Initrd : /var/www/cobbler/distro_mirror/lvnanhai/images/pxeboot/initrd.img Kernel : /var/www/cobbler/distro_mirror/lvnanhai/images/pxeboot/vmlinuz Kernel Options : {} Kernel Options (Post Install) : {} Management Classes : [] OS Version : rhel8 Owners : ['admin'] Redhat Management Key : Remote Boot Initrd : ~ Remote Boot Kernel : ~ Template Files : {}
创建kickstarts自动安装脚本
[root@localhost ~]# cobbler profile get-autoinstall --name lvnanhai-x86_64 >/var/lib/cobbler/templates/lvnanhai.ks //此处>后面不要使用tab键,不然会卡住 [root@localhost ~]# vim /var/lib/cobbler/templates/lvnanhai.ks # Firewall configuration firewall --disabled //关闭防火墙 %packages @^minimal-environment //添加最小化安装 %end
此时使用虚拟机去安装系统并不会成功 需要做如下操作
[root@localhost ~]# cd /usr/share/cobbler/bin/ [root@localhost bin]# ls migrate-data-v2-to-v3.py migrate-settings.sh mkgrub.sh settings-migration-v1-to-v2.sh [root@localhost bin]# bash mkgrub.sh + grub2-mkimage -O arm64-efi -o /var/lib/cobbler/loaders/grub/grubaa64.efi --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr efinet grub2-mkimage: error: cannot open `/usr/lib/grub/arm64-efi/moddep.lst': No such file or directory. + set +x + grub2-mkimage -O i386-pc-pxe -o /var/lib/cobbler/loaders/grub/grub.0 --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr chain pxe biosdisk + set +x + grub2-mkimage -O powerpc-ieee1275 -o /var/lib/cobbler/loaders/grub/grub.ppc64le --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr net ofnet grub2-mkimage: error: cannot open `/usr/lib/grub/powerpc-ieee1275/moddep.lst': No such file or directory. + set +x + grub2-mkimage -O x86_64-efi -o /var/lib/cobbler/loaders/grub/grubx64.efi --prefix= all_video boot cat configfile echo true font gfxmenu gfxterm gzio halt iso9660 jpeg minicmd normal part_apple part_msdos part_gpt password_pbkdf2 png reboot search search_fs_uuid search_fs_file search_label sleep test video fat loadenv linux btrfs ext2 xfs jfs reiserfs tftp http luks gcry_rijndael gcry_sha1 gcry_sha256 mdraid09 mdraid1x lvm serial regexp tr chain efinet grub2-mkimage: error: cannot open `/usr/lib/grub/x86_64-efi/moddep.lst': No such file or directory. + set +x + ln -s /usr/share/syslinux/ldlinux.c32 /var/lib/cobbler/loaders/ldlinux.c32 + set +x [root@localhost bin]# ls /var/lib/cobbler/loaders/ grub ldlinux.c32 menu.c32 pxelinux.0 [root@localhost bin]# cobbler sync .... running python trigger cobbler.modules.scm_track running python trigger cobbler.modules.managers.genders running shell triggers from /var/lib/cobbler/triggers/change/* shell triggers finished successfully *** TASK COMPLETE *** [root@localhost bin]# systemctl restart httpd cobblerd.service //重启服务
此时我们可以创建一个虚拟机来测试
手动创建
用户是root,密码是前面openssl指定redhat
自动安装,使用浏览器访问https://192.168.222.250/cobbler_web
默认登录的用户名和密码都为cobbler
不用自己选择,系统自动给你安装