Foreman: Difference between revisions
No edit summary |
No edit summary |
||
| Line 62: | Line 62: | ||
}} | }} | ||
== Troubleshooting == | |||
=== Custom Certificates === | |||
If using self-signed certificates you may get: | |||
{{highlight|lang=text|code= | |||
/Stage[main]/Foreman_proxy::Register/Foreman_smartproxy[foreman-proxy2.lab.cpsc.ucalgary.ca]: Could not evaluate: Exception SSL_connect returned=1 errno=0 state=error: certificate verify failed in get request to: https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies?search=name=%22foreman-proxy2.lab.cpsc.ucalgary.ca%22 | |||
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_resource/rest_v3.rb:89:in `rescue in request' | |||
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_resource/rest_v3.rb:71:in `request' | |||
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:6:in `proxy' | |||
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:13:in `id' | |||
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:17:in `exists?' | |||
}} | |||
Fix this by adding the self-signed certificate from the foreman server to the foreman proxy system. | |||
{{highlight|lang=text|code= | |||
[root@foreman]# cp "/etc/puppetlabs/puppet/ssl/certs/ca.pem" | |||
[root@foreman-proxy2 anchors]# cp ca.pem /etc/pki/ca-trust/source/anchors | |||
[root@foreman-proxy2 anchors]# update-ca-trust extract | |||
[root@foreman-proxy2 anchors]# wget -O - https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies | |||
--2018-06-01 12:45:47-- https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies | |||
Resolving foreman.lab.cpsc.ucalgary.ca (foreman.lab.cpsc.ucalgary.ca)... 192.168.154.129 | |||
Connecting to foreman.lab.cpsc.ucalgary.ca (foreman.lab.cpsc.ucalgary.ca)|192.168.154.129|:443... connected. | |||
HTTP request sent, awaiting response... 401 Unauthorized | |||
Authorization failed. | |||
}} | |||
[[Category:Linux]] | [[Category:Linux]] | ||
Revision as of 18:50, 1 June 2018
Foreman is a host management system for Linux systems.
Installation
Foreman can be installed on most Linux distributions as well as in Docker. This section will go over the steps needed to get Foreman running on one server. However, individual foreman components could be installed on separate machines if desired.
To quickly get started with Foreman, get a clean install of CentOS and install the foreman-installer:
# yum -y install https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm && \
yum -y install http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm && \
yum -y install https://yum.theforeman.org/releases/1.15/el7/x86_64/foreman-release.rpm && \
yum -y install foreman-installer
Ensure that the server has the proper hostname. For example, if this server is to be called 'foreman.lab.cpsc.ucalgary.ca', add the following to the hosts file:
192.168.154.129 foreman.lab.cpsc.ucalgary.ca foreman
The foreman-installer will bootstrap the installation process using the puppet classes that are bundled with it with the features that are desired as arguments. To get just foreman installed:
# /usr/sbin/foreman-installer \
--foreman-servername foreman.lab.cpsc.ucalgary.ca \
--foreman-serveraliases foreman \
--foreman-db-type postgresql \
--foreman-db-username foreman \
--foreman-db-database foreman \
--foreman-db-password a4jbdsftsdfrsdfhdfdfPjk7zb \
--foreman-db-manage true \
--enable-foreman \
--enable-puppet \
--enable-foreman-plugin-salt \
--enable-foreman-plugin-discovery \
--enable-foreman-proxy-plugin-discovery \
# /usr/sbin/foreman-rake db:migrate
# /usr/sbin/foreman-rake db:seed
# /usr/sbin/foreman-rake permissions:reset
The initial setup will take a while. Once this step is complete, you should be able to access the Foreman web interface at https://foreman.lab.cpsc.ucalgary.ca.
The Smart Proxy can be installed using foreman-installer as well. This can be done either on the same foreman server, or on a separate server. The oauth tokens are obtained from the web interface under 'settings' (or probably from foreman-rake somehow?).
# /usr/sbin/foreman-installer \
--enable-foreman-proxy \
--foreman-proxy-tftp=true \
--foreman-proxy-tftp-servername=192.168.154.129 \
--foreman-plugin-discovery-install-images true \
--foreman-proxy-dhcp=true \
--foreman-proxy-dhcp-interface=ens33 \
--foreman-proxy-dhcp-gateway=192.168.154.2 \
--foreman-proxy-dhcp-range="192.168.154.10 192.168.154.99" \
--foreman-proxy-dhcp-nameservers="192.168.154.129" \
--foreman-proxy-dns=true \
--foreman-proxy-dns-interface=ens33 \
--foreman-proxy-dns-zone=lab.cpsc.ucalgary.ca \
--foreman-proxy-dns-reverse=154.168.192.in-addr.arpa \
--foreman-proxy-dns-forwarders=192.168.154.2 \
--foreman-proxy-foreman-base-url=https://foreman.lab.cpsc.ucalgary.ca \
--foreman-proxy-oauth-consumer-key=nR2c2fqESzhcNpGKncenchS4LHNvHP5s \
--foreman-proxy-oauth-consumer-secret=u6KnRBtdZvRy8KEiYCeGhwVXDpjK6mhb
Troubleshooting
Custom Certificates
If using self-signed certificates you may get:
/Stage[main]/Foreman_proxy::Register/Foreman_smartproxy[foreman-proxy2.lab.cpsc.ucalgary.ca]: Could not evaluate: Exception SSL_connect returned=1 errno=0 state=error: certificate verify failed in get request to: https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies?search=name=%22foreman-proxy2.lab.cpsc.ucalgary.ca%22
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_resource/rest_v3.rb:89:in `rescue in request'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_resource/rest_v3.rb:71:in `request'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:6:in `proxy'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:13:in `id'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:17:in `exists?'
Fix this by adding the self-signed certificate from the foreman server to the foreman proxy system.
[root@foreman]# cp "/etc/puppetlabs/puppet/ssl/certs/ca.pem"
[root@foreman-proxy2 anchors]# cp ca.pem /etc/pki/ca-trust/source/anchors
[root@foreman-proxy2 anchors]# update-ca-trust extract
[root@foreman-proxy2 anchors]# wget -O - https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies
--2018-06-01 12:45:47-- https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies
Resolving foreman.lab.cpsc.ucalgary.ca (foreman.lab.cpsc.ucalgary.ca)... 192.168.154.129
Connecting to foreman.lab.cpsc.ucalgary.ca (foreman.lab.cpsc.ucalgary.ca)