Foreman: Difference between revisions

From Leo's Notes
This page was last edited on 6 June 2018, at 22:43.
No edit summary
Line 4: Line 4:


== Installation ==
== Installation ==
=== Foreman Only ===
=== Foreman (with Katello) ===
Foreman can be installed on most Linux distributions as well as in Docker. This section will go over the steps needed to get Foreman running on one server. However, individual foreman components could be installed on separate machines if desired.
Foreman can be installed on most Linux distributions as well as in Docker (though, the image would need to use systemd since the puppet modules depend on it). This section will go over the steps needed to get Foreman running on a server.
 
On a clean CentOS 7 system:


To quickly get started with Foreman, get a clean install of CentOS and install the {{code|foreman-installer}}:
{{highlight|lang=terminal|code=
{{highlight|lang=terminal|code=
# yum -y install https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm && \
## Update system
yum -y install http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm && \
# yum clean all
yum -y install https://yum.theforeman.org/releases/1.15/el7/x86_64/foreman-release.rpm && \
 
yum -y install foreman-installer
## Install repos
}}
# yum -y localinstall http://fedorapeople.org/groups/katello/releases/yum/3.6/katello/el7/x86_64/katello-repos-latest.rpm
# yum -y localinstall http://yum.theforeman.org/releases/1.17/el7/x86_64/foreman-release.rpm
# yum -y localinstall https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm
# yum -y localinstall http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm


Ensure that the server has the proper hostname. For example, if this server is to be called 'foreman.lab.cpsc.ucalgary.ca', add the following to the hosts file:
## Update packages and install new ones
{{highlight|lang=text|code=
# yum -y update
192.168.154.129    foreman.lab.cpsc.ucalgary.ca foreman
# yum -y install foreman-release-scl python-django katello tfm-rubygem-foreman_dhcp_browser
}}
}}


The {{code|foreman-installer}} will bootstrap the installation process using the puppet classes that are bundled with it with the features that are desired as arguments. To get just foreman installed:
Ensure that the server's hostname resolves properly. If it does not (such as if you're doing this in a test environment), add it to the hosts file. For example:
{{highlight|lang=terminal|code=
{{highlight|lang=terminal|code=
# /usr/sbin/foreman-installer \
# cat /etc/hosts
                --foreman-servername foreman.lab.cpsc.ucalgary.ca \
## The FQDN should be first
                --foreman-serveraliases foreman \
192.168.154.129    foreman.lab.cpsc.ucalgary.ca foreman
                --foreman-db-type postgresql \
                --foreman-db-username foreman \
                --foreman-db-database foreman \
                --foreman-db-password a4jbdsftsdfrsdfhdfdfPjk7zb \
                --foreman-db-manage  true \
                --enable-foreman \
                --enable-puppet \
                --enable-foreman-plugin-salt \
                --enable-foreman-plugin-discovery \
                --enable-foreman-proxy-plugin-discovery \
 
# /usr/sbin/foreman-rake db:migrate
# /usr/sbin/foreman-rake db:seed
# /usr/sbin/foreman-rake permissions:reset
}}
}}


The initial setup will take a while. Once this step is complete, you should be able to access the Foreman web interface at https://foreman.lab.cpsc.ucalgary.ca.
The {{code|foreman-installer}} will bootstrap the installation process using the puppet modules installed in the previous step. Start the installer by running:
 
=== Katello and Foreman ===
Katello must only be installed on a clean system and should not be installed on an existing foreman installation.


{{highlight|lang=terminal|code=
{{highlight|lang=terminal|code=
# yum clean all
# yum install -y yum-utils
# yum -y update
# yum -y localinstall http://fedorapeople.org/groups/katello/releases/yum/3.6/katello/el7/x86_64/katello-repos-latest.rpm
# yum -y localinstall http://yum.theforeman.org/releases/1.17/el7/x86_64/foreman-release.rpm
# yum -y localinstall https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm
# yum -y localinstall http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm
# yum -y install foreman-release-scl python-django
# yum -y install katello
## Then install katello as you would foreman but with a scenario specified. For example:
# foreman-installer --scenario katello \
# foreman-installer --scenario katello \
   --foreman-servername foreman.lab.cpsc.ucalgary.ca \
   --foreman-servername foreman \
   --foreman-serveraliases foreman \
   --foreman-serveraliases foreman \
  --foreman-initial-organization "U of C" \
  --foreman-initial-location "CPSC" \
   --foreman-db-type postgresql \
   --foreman-db-type postgresql \
   --foreman-db-username foreman \
   --foreman-db-username foreman \
   --foreman-db-database foreman \
   --foreman-db-database foreman \
   --foreman-db-password a4jbdsftsdfrsdfhdfdfPjk7zb \
   --foreman-db-password 1GwtY31DEsQFLEVdH0oh \
   --foreman-db-manage true \
   --foreman-db-manage true \
   --enable-foreman \
   --enable-foreman \
Line 75: Line 53:
   --enable-puppet
   --enable-puppet
}}
}}
The initial setup will take a while. Once this step is complete, you should be able to access the Foreman web interface using a web browser.


=== Smart Proxy ===
=== Smart Proxy ===
The Smart Proxy can be installed using foreman-installer as well. This can be done either on the same foreman server, or on a separate server. The oauth tokens are obtained from the web interface under 'settings' (or probably from foreman-rake somehow?).
A Foreman Smart Proxy provides a RESTful interface that interacts with certain services such as DHCP or DNS. Installing only the Foreman Smart Proxy requires the installation of the {{code|foreman-proxy}} package.
 
To set up a Smart Proxy that handles DHCP and DNS on a separate server, run:
{{highlight|lang=terminal|code=
## Repositories
# yum -y localinstall http://yum.theforeman.org/releases/1.17/el7/x86_64/foreman-release.rpm
# yum -y localinstall https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm
# yum -y localinstall http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm
 
## Install packages
# yum -y install dhcp bind xinetd  krb5-workstation  foreman-proxy  tftp-server  bind-utils  yum-utils
}}
 
The smart proxy can be configured by editing files in {{code|/etc/foreman-proxy}}. Each individual service that the smart proxy should handle must be enabled in its corresponding yaml configuration file there.
 
After the configuration is done, start the proxy.
 
You can debug the proxy by running the smart proxy manually as well as changing the {{code|log_level}} value to {{code|DEBUG}} in {{code|/etc/foreman-proxy/settings.yml}}.:
{{highlight|lang=terminal|code=
{{highlight|lang=terminal|code=
# /usr/sbin/foreman-installer \
# /usr/share/foreman-proxy/bin/smart-proxy
          --enable-foreman-proxy \
          --foreman-proxy-tftp=true \
          --foreman-proxy-tftp-servername=192.168.154.129 \
          --foreman-plugin-discovery-install-images true \
          --foreman-proxy-dhcp=true \
          --foreman-proxy-dhcp-interface=ens33 \
          --foreman-proxy-dhcp-gateway=192.168.154.2 \
          --foreman-proxy-dhcp-range="192.168.154.10 192.168.154.99" \
          --foreman-proxy-dhcp-nameservers="192.168.154.129" \
          --foreman-proxy-dns=true \
          --foreman-proxy-dns-interface=ens33 \
          --foreman-proxy-dns-zone=lab.cpsc.ucalgary.ca \
          --foreman-proxy-dns-reverse=154.168.192.in-addr.arpa \
          --foreman-proxy-dns-forwarders=192.168.154.2 \
          --foreman-proxy-foreman-base-url=https://foreman.lab.cpsc.ucalgary.ca \
          --foreman-proxy-oauth-consumer-key=nR2c2fqESzhcNpGKncenchS4LHNvHP5s \
          --foreman-proxy-oauth-consumer-secret=u6KnRBtdZvRy8KEiYCeGhwVXDpjK6mhb
}}
}}



Revision as of 22:43, 6 June 2018

Foreman is a host management system for Linux systems.

Foreman in addition to Katello, Pulp, and Candlepin, provides the base system for Red Hat Satellite 6.

Installation

Foreman (with Katello)

Foreman can be installed on most Linux distributions as well as in Docker (though, the image would need to use systemd since the puppet modules depend on it). This section will go over the steps needed to get Foreman running on a server.

On a clean CentOS 7 system:

## Update system
# yum clean all

## Install repos
# yum -y localinstall http://fedorapeople.org/groups/katello/releases/yum/3.6/katello/el7/x86_64/katello-repos-latest.rpm
# yum -y localinstall http://yum.theforeman.org/releases/1.17/el7/x86_64/foreman-release.rpm
# yum -y localinstall https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm
# yum -y localinstall http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm

## Update packages and install new ones
# yum -y update
# yum -y install foreman-release-scl python-django katello tfm-rubygem-foreman_dhcp_browser

Ensure that the server's hostname resolves properly. If it does not (such as if you're doing this in a test environment), add it to the hosts file. For example:

# cat /etc/hosts
## The FQDN should be first
192.168.154.129    foreman.lab.cpsc.ucalgary.ca foreman

The foreman-installer will bootstrap the installation process using the puppet modules installed in the previous step. Start the installer by running:

# foreman-installer --scenario katello \
  --foreman-servername foreman \
  --foreman-serveraliases foreman \
  --foreman-initial-organization "U of C" \
  --foreman-initial-location "CPSC" \
  --foreman-db-type postgresql \
  --foreman-db-username foreman \
  --foreman-db-database foreman \
  --foreman-db-password 1GwtY31DEsQFLEVdH0oh \
  --foreman-db-manage true \
  --enable-foreman \
  --enable-foreman-plugin-discovery  \
  --enable-foreman-plugin-default-hostgroup  \
  --enable-foreman-plugin-templates  \
  --enable-foreman-proxy \
  --enable-foreman-proxy-plugin-pulp \
  --enable-katello \
  --enable-puppet

The initial setup will take a while. Once this step is complete, you should be able to access the Foreman web interface using a web browser.

Smart Proxy

A Foreman Smart Proxy provides a RESTful interface that interacts with certain services such as DHCP or DNS. Installing only the Foreman Smart Proxy requires the installation of the foreman-proxy package.

To set up a Smart Proxy that handles DHCP and DNS on a separate server, run:

## Repositories
# yum -y localinstall http://yum.theforeman.org/releases/1.17/el7/x86_64/foreman-release.rpm
# yum -y localinstall https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm
# yum -y localinstall http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm

## Install packages
# yum -y install dhcp bind xinetd  krb5-workstation  foreman-proxy  tftp-server  bind-utils  yum-utils

The smart proxy can be configured by editing files in /etc/foreman-proxy. Each individual service that the smart proxy should handle must be enabled in its corresponding yaml configuration file there.

After the configuration is done, start the proxy.

You can debug the proxy by running the smart proxy manually as well as changing the log_level value to DEBUG in /etc/foreman-proxy/settings.yml.:

# /usr/share/foreman-proxy/bin/smart-proxy


Plugins

Plugins can be enabled when running foreman-installer. Additional plugins can also be enabled if it is installed.

For example:

# yum install tfm-rubygem-foreman_dhcp_browser tfm-rubygem-foreman_salt


Troubleshooting

Custom Certificates

If using self-signed certificates you may get:

/Stage[main]/Foreman_proxy::Register/Foreman_smartproxy[foreman-proxy2.lab.cpsc.ucalgary.ca]: Could not evaluate: Exception SSL_connect returned=1 errno=0 state=error: certificate verify failed in get request to: https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies?search=name=%22foreman-proxy2.lab.cpsc.ucalgary.ca%22
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_resource/rest_v3.rb:89:in `rescue in request'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_resource/rest_v3.rb:71:in `request'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:6:in `proxy'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:13:in `id'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:17:in `exists?'

Fix this by adding the self-signed certificate from the foreman server to the foreman proxy system.

[root@foreman]# cp "/etc/puppetlabs/puppet/ssl/certs/ca.pem" 
[root@foreman-proxy2 anchors]#  cp ca.pem /etc/pki/ca-trust/source/anchors
[root@foreman-proxy2 anchors]# update-ca-trust extract
[root@foreman-proxy2 anchors]# wget -O - https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies
--2018-06-01 12:45:47--  https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies
Resolving foreman.lab.cpsc.ucalgary.ca (foreman.lab.cpsc.ucalgary.ca)... 192.168.154.129
Connecting to foreman.lab.cpsc.ucalgary.ca (foreman.lab.cpsc.ucalgary.ca)