Foreman
Foreman is a host management system for Linux systems.
Foreman in addition to Katello, Pulp, and Candlepin, provides the base system for Red Hat Satellite 6.
Installation
Foreman Only
Foreman can be installed on most Linux distributions as well as in Docker. This section will go over the steps needed to get Foreman running on one server. However, individual foreman components could be installed on separate machines if desired.
To quickly get started with Foreman, get a clean install of CentOS and install the foreman-installer:
# yum -y install https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm && \
yum -y install http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm && \
yum -y install https://yum.theforeman.org/releases/1.15/el7/x86_64/foreman-release.rpm && \
yum -y install foreman-installer
Ensure that the server has the proper hostname. For example, if this server is to be called 'foreman.lab.cpsc.ucalgary.ca', add the following to the hosts file:
192.168.154.129 foreman.lab.cpsc.ucalgary.ca foreman
The foreman-installer will bootstrap the installation process using the puppet classes that are bundled with it with the features that are desired as arguments. To get just foreman installed:
# /usr/sbin/foreman-installer \
--foreman-servername foreman.lab.cpsc.ucalgary.ca \
--foreman-serveraliases foreman \
--foreman-db-type postgresql \
--foreman-db-username foreman \
--foreman-db-database foreman \
--foreman-db-password a4jbdsftsdfrsdfhdfdfPjk7zb \
--foreman-db-manage true \
--enable-foreman \
--enable-puppet \
--enable-foreman-plugin-salt \
--enable-foreman-plugin-discovery \
--enable-foreman-proxy-plugin-discovery \
# /usr/sbin/foreman-rake db:migrate
# /usr/sbin/foreman-rake db:seed
# /usr/sbin/foreman-rake permissions:reset
The initial setup will take a while. Once this step is complete, you should be able to access the Foreman web interface at https://foreman.lab.cpsc.ucalgary.ca.
Katello and Foreman
Katello must only be installed on a clean system and should not be installed on an existing foreman installation.
# yum clean all
# yum install -y yum-utils
# yum -y localinstall http://fedorapeople.org/groups/katello/releases/yum/3.6/katello/el7/x86_64/katello-repos-latest.rpm
# yum -y localinstall http://yum.theforeman.org/releases/1.17/el7/x86_64/foreman-release.rpm
# yum -y localinstall https://yum.puppetlabs.com/puppetlabs-release-pc1-el-7.noarch.rpm
# yum -y localinstall http://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm
# yum -y install foreman-release-scl python-django
# yum -y install katello
# foreman-installer --scenario katello --help
Smart Proxy
The Smart Proxy can be installed using foreman-installer as well. This can be done either on the same foreman server, or on a separate server. The oauth tokens are obtained from the web interface under 'settings' (or probably from foreman-rake somehow?).
# /usr/sbin/foreman-installer \
--enable-foreman-proxy \
--foreman-proxy-tftp=true \
--foreman-proxy-tftp-servername=192.168.154.129 \
--foreman-plugin-discovery-install-images true \
--foreman-proxy-dhcp=true \
--foreman-proxy-dhcp-interface=ens33 \
--foreman-proxy-dhcp-gateway=192.168.154.2 \
--foreman-proxy-dhcp-range="192.168.154.10 192.168.154.99" \
--foreman-proxy-dhcp-nameservers="192.168.154.129" \
--foreman-proxy-dns=true \
--foreman-proxy-dns-interface=ens33 \
--foreman-proxy-dns-zone=lab.cpsc.ucalgary.ca \
--foreman-proxy-dns-reverse=154.168.192.in-addr.arpa \
--foreman-proxy-dns-forwarders=192.168.154.2 \
--foreman-proxy-foreman-base-url=https://foreman.lab.cpsc.ucalgary.ca \
--foreman-proxy-oauth-consumer-key=nR2c2fqESzhcNpGKncenchS4LHNvHP5s \
--foreman-proxy-oauth-consumer-secret=u6KnRBtdZvRy8KEiYCeGhwVXDpjK6mhb
Plugins
Plugins can be enabled when running foreman-installer. Additional plugins can also be enabled if it is installed.
For example:
# yum install tfm-rubygem-foreman_dhcp_browser tfm-rubygem-foreman_salt
Troubleshooting
Custom Certificates
If using self-signed certificates you may get:
/Stage[main]/Foreman_proxy::Register/Foreman_smartproxy[foreman-proxy2.lab.cpsc.ucalgary.ca]: Could not evaluate: Exception SSL_connect returned=1 errno=0 state=error: certificate verify failed in get request to: https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies?search=name=%22foreman-proxy2.lab.cpsc.ucalgary.ca%22
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_resource/rest_v3.rb:89:in `rescue in request'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_resource/rest_v3.rb:71:in `request'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:6:in `proxy'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:13:in `id'
/usr/share/foreman-installer/modules/foreman/lib/puppet/provider/foreman_smartproxy/rest_v3.rb:17:in `exists?'
Fix this by adding the self-signed certificate from the foreman server to the foreman proxy system.
[root@foreman]# cp "/etc/puppetlabs/puppet/ssl/certs/ca.pem"
[root@foreman-proxy2 anchors]# cp ca.pem /etc/pki/ca-trust/source/anchors
[root@foreman-proxy2 anchors]# update-ca-trust extract
[root@foreman-proxy2 anchors]# wget -O - https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies
--2018-06-01 12:45:47-- https://foreman.lab.cpsc.ucalgary.ca/api/v2/smart_proxies
Resolving foreman.lab.cpsc.ucalgary.ca (foreman.lab.cpsc.ucalgary.ca)... 192.168.154.129
Connecting to foreman.lab.cpsc.ucalgary.ca (foreman.lab.cpsc.ucalgary.ca)