Foreman: Difference between revisions
No edit summary |
|||
| Line 29: | Line 29: | ||
## The FQDN should be first | ## The FQDN should be first | ||
192.168.154.129 foreman.lab.cpsc.ucalgary.ca foreman | 192.168.154.129 foreman.lab.cpsc.ucalgary.ca foreman | ||
}} | |||
{{Warning | |||
|1=Make sure hostnames are correct | |||
|2=Verify that {{code|hostname}} returns the hostname with no domain and {{code|hostname -f}} returns the full FQDN. | |||
If this isn't the case and you continue with the installation, foreman will glitch out with issues such as: | |||
* Not being able to add the domain to foreman, with it saying it already exists | |||
* Adding a new host will cause the domain to be appended to the hostname twice | |||
}} | }} | ||
| Line 34: | Line 43: | ||
{{highlight|lang=terminal|code= | {{highlight|lang=terminal|code= | ||
foreman-installer --scenario katello \ | |||
--foreman-servername foreman \ | --foreman-servername foreman \ | ||
--foreman-serveraliases foreman \ | --foreman-serveraliases foreman \ | ||
| Line 48: | Line 57: | ||
--enable-foreman-plugin-default-hostgroup \ | --enable-foreman-plugin-default-hostgroup \ | ||
--enable-foreman-plugin-templates \ | --enable-foreman-plugin-templates \ | ||
--enable-foreman-plugin-hooks \ | |||
--enable-foreman-proxy \ | --enable-foreman-proxy \ | ||
--enable-foreman-proxy-plugin-pulp \ | --enable-foreman-proxy-plugin-pulp \ | ||
--enable-katello \ | --enable-katello \ | ||
--enable-puppet | --enable-puppet | ||
}} | |||
This stage takes a while. Make a note of the user credentials after installation succeeds. | |||
Allow certain ports through the firewall. | |||
{{Todo | |||
|1=Configure the firewall properly | |||
|2=Add the proper commands to configure the firewall appropriately. | |||
}} | |||
{{highlight|lang=terminal|code= | |||
# systemctl disable firewalld | |||
# systemctl stop firewalld | |||
}} | |||
You may also want to disable SELinux as it might cause issues with Foreman from working properly. | |||
{{Todo | |||
|1=Verify that this is actually accurate | |||
|2=I think foreman should work with SELinux. Issues I had might be related to the firewall. | |||
}} | |||
{{highlight|lang=terminal|code= | |||
# setenforce 0 | |||
# vi /etc/selinux/config | |||
}} | }} | ||
Revision as of 16:39, 8 June 2018
Foreman is a host management system for Linux systems.
Foreman in addition to Katello, Pulp, and Candlepin, provides the base system for Red Hat Satellite 6.
Installation
Foreman (with Katello)
Foreman can be installed on most Linux distributions as well as in Docker (though, the image would need to use systemd since the puppet modules depend on it). This section will go over the steps needed to get Foreman running on a server.
On a clean CentOS 7 system:
## Update system
# yum clean all
## Install repos
# yum -y localinstall http://fedorapeople.org/groups/katello/releases/yum/3.6/katello/el7/x86_64/katello-repos-latest.rpm
# yum -y localinstall http://yum.theforeman.org/releases/1.17/el7/x86_64/foreman-release.rpm
# yum -y localinstall https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm
# yum -y localinstall http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm
## Update packages and install new ones
# yum -y update
# yum -y install foreman-release-scl python-django katello tfm-rubygem-foreman_dhcp_browser
Ensure that the server's hostname resolves properly. If it does not (such as if you're doing this in a test environment), add it to the hosts file. For example:
# cat /etc/hosts
## The FQDN should be first
192.168.154.129 foreman.lab.cpsc.ucalgary.ca foreman
Make sure hostnames are correct
Verify thathostname returns the hostname with no domain and hostname -f returns the full FQDN.
If this isn't the case and you continue with the installation, foreman will glitch out with issues such as:
- Not being able to add the domain to foreman, with it saying it already exists
- Adding a new host will cause the domain to be appended to the hostname twice
The foreman-installer will bootstrap the installation process using the puppet modules installed in the previous step. Start the installer by running:
foreman-installer --scenario katello \
--foreman-servername foreman \
--foreman-serveraliases foreman \
--foreman-initial-organization "U of C" \
--foreman-initial-location "CPSC" \
--foreman-db-type postgresql \
--foreman-db-username foreman \
--foreman-db-database foreman \
--foreman-db-password 1GwtY31DEsQFLEVdH0oh \
--foreman-db-manage true \
--enable-foreman \
--enable-foreman-plugin-discovery \
--enable-foreman-plugin-default-hostgroup \
--enable-foreman-plugin-templates \
--enable-foreman-plugin-hooks \
--enable-foreman-proxy \
--enable-foreman-proxy-plugin-pulp \
--enable-katello \
--enable-puppet
This stage takes a while. Make a note of the user credentials after installation succeeds.
Allow certain ports through the firewall.
TODO: Configure the firewall properly
Add the proper commands to configure the firewall appropriately.# systemctl disable firewalld
# systemctl stop firewalld
You may also want to disable SELinux as it might cause issues with Foreman from working properly.
TODO: Verify that this is actually accurate
I think foreman should work with SELinux. Issues I had might be related to the firewall.# setenforce 0
# vi /etc/selinux/config
The initial setup will take a while. Once this step is complete, you should be able to access the Foreman web interface using a web browser.
Smart Proxy
A Foreman Smart Proxy provides a RESTful interface that interacts with certain services such as DHCP or DNS. Installing only the Foreman Smart Proxy requires the installation of the foreman-proxy package.
To set up a Smart Proxy that handles DHCP and DNS on a separate server, run:
## Repositories
# yum -y localinstall http://yum.theforeman.org/releases/1.17/el7/x86_64/foreman-release.rpm
# yum -y localinstall https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm
# yum -y localinstall http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm
## Install packages
# yum -y install dhcp bind xinetd krb5-workstation foreman-proxy tftp-server bind-utils yum-utils
The smart proxy can be configured by editing files in /etc/foreman-proxy. Each individual service that the smart proxy should handle must be enabled in its corresponding yaml configuration file there.
After the configuration is done, start the proxy.
You can debug the proxy by running the smart proxy manually as well as changing the log_level value to DEBUG in /etc/foreman-proxy/settings.yml.:
# /usr/share/foreman-proxy/bin/smart-proxy
Plugins
Plugins can be enabled when running foreman-installer. Additional plugins can also be enabled if it is installed.
For example:
# yum install tfm-rubygem-foreman_dhcp_browser tfm-rubygem-foreman_salt
Troubleshooting
Custom Certificates
If using self-signed certificates you may get:
/Stage[main]/Foreman_proxy::Register/Foreman_smartproxy[foreman-proxy2.lab.cpsc.ucalgary.ca]: Could not evaluate: Exception SSL_connect returned=1 errno=0 state=error: certificate verify failed in get request to: https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies?search=name=%22foreman-proxy2.lab.cpsc.ucalgary.ca%22
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_resource/rest_v3.rb:89:in `rescue in request'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_resource/rest_v3.rb:71:in `request'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:6:in `proxy'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:13:in `id'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:17:in `exists?'
Fix this by adding the self-signed certificate from the foreman server to the foreman proxy system.
[root@foreman]# cp "/etc/puppetlabs/puppet/ssl/certs/ca.pem"
[root@foreman-proxy2 anchors]# cp ca.pem /etc/pki/ca-trust/source/anchors
[root@foreman-proxy2 anchors]# update-ca-trust extract
[root@foreman-proxy2 anchors]# wget -O - https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies
--2018-06-01 12:45:47-- https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies
Resolving foreman.lab.cpsc.ucalgary.ca (foreman.lab.cpsc.ucalgary.ca)... 192.168.154.129
Connecting to foreman.lab.cpsc.ucalgary.ca (foreman.lab.cpsc.ucalgary.ca)