Return-Path: X-Original-To: apmail-brooklyn-dev-archive@minotaur.apache.org Delivered-To: apmail-brooklyn-dev-archive@minotaur.apache.org Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by minotaur.apache.org (Postfix) with SMTP id D978011476 for ; Wed, 10 Sep 2014 21:27:58 +0000 (UTC) Received: (qmail 26170 invoked by uid 500); 10 Sep 2014 21:27:58 -0000 Delivered-To: apmail-brooklyn-dev-archive@brooklyn.apache.org Received: (qmail 26133 invoked by uid 500); 10 Sep 2014 21:27:58 -0000 Mailing-List: contact dev-help@brooklyn.incubator.apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: dev@brooklyn.incubator.apache.org Delivered-To: mailing list dev@brooklyn.incubator.apache.org Received: (qmail 26122 invoked by uid 99); 10 Sep 2014 21:27:58 -0000 Received: from athena.apache.org (HELO athena.apache.org) (140.211.11.136) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 10 Sep 2014 21:27:58 +0000 X-ASF-Spam-Status: No, hits=-2001.7 required=5.0 tests=ALL_TRUSTED,RP_MATCHES_RCVD X-Spam-Check-By: apache.org Received: from [140.211.11.3] (HELO mail.apache.org) (140.211.11.3) by apache.org (qpsmtpd/0.29) with SMTP; Wed, 10 Sep 2014 21:27:56 +0000 Received: (qmail 25965 invoked by uid 99); 10 Sep 2014 21:27:36 -0000 Received: from tyr.zones.apache.org (HELO tyr.zones.apache.org) (140.211.11.114) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 10 Sep 2014 21:27:36 +0000 Received: by tyr.zones.apache.org (Postfix, from userid 65534) id 2748E888717; Wed, 10 Sep 2014 21:27:36 +0000 (UTC) From: andreaturli To: dev@brooklyn.incubator.apache.org Reply-To: dev@brooklyn.incubator.apache.org References: In-Reply-To: Subject: [GitHub] incubator-brooklyn pull request: BROOKLYN-55 install script for br... Content-Type: text/plain Message-Id: <20140910212736.2748E888717@tyr.zones.apache.org> Date: Wed, 10 Sep 2014 21:27:36 +0000 (UTC) X-Virus-Checked: Checked by ClamAV on apache.org Github user andreaturli commented on a diff in the pull request: https://github.com/apache/incubator-brooklyn/pull/157#discussion_r17390267 --- Diff: brooklyn-install.sh --- @@ -0,0 +1,272 @@ +#!/bin/bash +# +# Licensed to the Apache Software Foundation (ASF) under one or more +# contributor license agreements. See the NOTICE file distributed with +# this work for additional information regarding copyright ownership. +# The ASF licenses this file to You under the Apache License, Version 2.0 +# (the "License"); you may not use this file except in compliance with +# the License. You may obtain a copy of the License at +# +# http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software +# distributed under the License is distributed on an "AS IS" BASIS, +# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +# See the License for the specific language governing permissions and +# limitations under the License. +# +# +# Brooklyn Install Script +# +# Usage: +# brooklyn-install.sh [-h] [-q] [-r] [-e] [-s] [-u user] [-k key] [-p port] hostname +# +#set -x # DEBUG + +function help() { + cat <> ${LOG} + if [ "$1" == "-n" ]; then + shift + fi + if [ "$*" != "..." ]; then + echo "Log: $*" | sed -e "s/\.\.\.//" >> ${LOG} + fi +} + +function fail() { + log "...failed!" + error "$*" +} + +function error() { + echo "Error: $*" | tee -a "${LOG}" + usage +} + +function usage() { + echo "Usage: $(basename ${0}) [-h] [-q] [-r] [-e] [-s] [-u user] [-k key] [-p port] hostname" + exit 1 +} + +QUIET=false +LOG="brooklyn-install.log" +BROOKLYN_VERSION="0.7.0-M1" +SSH=ssh + +while getopts ":hesu:k:q:p:r" o; do + case "${o}" in + h) help + ;; + e) INSTALL_EXAMPLES=true + ;; + s) SETUP_USER=true + ;; + u) BROOKLYN_USER="${OPTARG}" + ;; + k) PRIVATE_KEY_FILE="${OPTARG}" + ;; + r) SETUP_RANDOM=true + ;; + q) QUIET=true + ;; + p) PORT="${OPTARG}" + ;; + *) usage "Invalid option: $*" + ;; + esac +done +shift $((OPTIND-1)) + +if [ $# -ne 1 ]; then + error "Must specify remote hostname as last argument" +fi + +HOST="$1" +USER="${BROOKLYN_USER:-brooklyn}" +PRIVATE_KEY_FILE="${PRIVATE_KEY_FILE:-${HOME}/.ssh/id_rsa}" +SSH_PORT=${PORT:-22} + +SSH_OPTS="-o StrictHostKeyChecking=no -p ${SSH_PORT}" +if [ -f "${PRIVATE_KEY_FILE}" ]; then + SSH_OPTS="${SSH_OPTS} -i ${PRIVATE_KEY_FILE}" +else + error "SSH private key '${PRIVATE_KEY_FILE}' not found" +fi +SSH_PUBLIC_KEY_DATA=$(ssh-keygen -y -f ${PRIVATE_KEY_FILE}) + +echo "Installing Brooklyn ${BROOKLYN_VERSION} on ${HOST}:${SSH_PORT} as user: '${USER}'" + +# Pre-requisites for this script +log "Configuring '${HOST}:${PORT}'... " + +# Install packages +log -n "Installing packages for curl, sed, tar, wget on '${HOST}:${SSH_PORT}'..." +ssh ${SSH_OPTS} root@${HOST} "yum check-update || apt-get update" >> ${LOG} 2>&1 +for package in "curl" "sed" "tar" "wget"; do + ssh ${SSH_OPTS} root@${HOST} "which ${package} || { yum check-update && yum -y --nogpgcheck -q install ${package} || apt-get update && apt-get -y --allow-unauthenticated install ${package}; }" >> ${LOG} 2>&1 +done +log " done!" + +# Install Java 7 +log -n "Installing java 7 on '${HOST}:${SSH_PORT}'... " +if [ "${INSTALL_EXAMPLES}" ]; then + check="javac" +else + check="java" + JAVA_HOME="/usr" +fi +ssh ${SSH_OPTS} root@${HOST} "which ${check} || { yum -y -q install java-1.7.0-openjdk || apt-get update && apt-get -y install openjdk-7-jre-headless; }" >> ${LOG} 2>&1 +for java in "jre" "jdk" "java-1.7.0-openjdk" "java-1.7.0-openjdk-amd64"; do + if ssh ${SSH_OPTS} root@${HOST} "test -d /usr/lib/jvm/${java}"; then + JAVA_HOME="/usr/lib/jvm/${java}/" && echo "Java: ${JAVA_HOME}" >> ${LOG} + fi +done +ssh ${SSH_OPTS} root@${HOST} "test -x ${JAVA_HOME}/bin/${check}" >> ${LOG} 2>&1 || fail "Java is not installed" +log "done!" + +# Increase linux kernel entropy for faster ssh connections +if [ "${SETUP_RANDOM}" ]; then + log -n "Installing rng-tool to increase entropy on '${HOST}:${SSH_PORT}'... " + ssh ${SSH_OPTS} root@${HOST} "which rng-tools || { yum -y -q install rng-tools || apt-get -y install rng-tools; }" >> ${LOG} 2>&1 + if ssh ${SSH_OPTS} root@${HOST} "test -f /etc/default/rng-tools"; then + echo "HRNGDEVICE=/dev/urandom" | ssh ${SSH_OPTS} root@${HOST} "cat >> /etc/default/rng-tools" + ssh ${SSH_OPTS} root@${HOST} "/etc/init.d/rng-tools start" >> ${LOG} 2>&1 + else + echo "EXTRAOPTIONS=\"-r /dev/urandom\"" | ssh ${SSH_OPTS} root@${HOST} "cat >> /etc/sysconfig/rngd" + ssh ${SSH_OPTS} root@${HOST} "/etc/init.d/rngd start" >> ${LOG} 2>&1 + fi + log "done!" +fi + +# Create Brooklyn user if required +if ! ssh ${SSH_OPTS} root@${HOST} "id ${USER} > /dev/null 2>&1"; then + if [ -z "${SETUP_USER}" ]; then + error "User '${USER}' does not exist on ${HOST}" + fi + log -n "Creating user '${USER}'..." + ssh ${SSH_OPTS} root@${HOST} "useradd ${USER} -s /bin/bash -d /home/${USER} -m" >> ${LOG} 2>&1 + ssh ${SSH_OPTS} root@${HOST} "id ${USER}" >> ${LOG} 2>&1 || fail "User was not created" + log "done!" +fi + +# Setup Brooklyn user +if [ "${SETUP_USER}" ]; then + log -n "Setting up user '${USER}'... " + ssh ${SSH_OPTS} root@${HOST} "echo '${USER} ALL = (ALL) NOPASSWD: ALL' >> /etc/sudoers" + ssh ${SSH_OPTS} root@${HOST} "sed -i.brooklyn.bak 's/.*requiretty.*/#brooklyn-removed-require-tty/' /etc/sudoers" + ssh ${SSH_OPTS} root@${HOST} "mkdir -p /home/${USER}/.ssh" + ssh ${SSH_OPTS} root@${HOST} "chmod 700 /home/${USER}/.ssh" + ssh ${SSH_OPTS} root@${HOST} "echo ${SSH_PUBLIC_KEY_DATA} >> /home/${USER}/.ssh/authorized_keys" + ssh ${SSH_OPTS} root@${HOST} "chown -R ${USER}.${USER} /home/${USER}/.ssh" + ssh ${SSH_OPTS} ${USER}@${HOST} "ssh-keygen -q -t rsa -N \"\" -f .ssh/id_rsa" + ssh ${SSH_OPTS} ${USER}@${HOST} "ssh-keygen -y -f .ssh/id_rsa >> .ssh/authorized_keys" + log "done!" +fi + +# Setup Brooklyn +log -n "Downloading Brooklyn... " +ssh ${SSH_OPTS} ${USER}@${HOST} "curl -s -o brooklyn-${BROOKLYN_VERSION}.tar.gz http://search.maven.org/remotecontent?filepath=io/brooklyn/brooklyn-dist/${BROOKLYN_VERSION}/brooklyn-dist-${BROOKLYN_VERSION}-dist.tar.gz" --- End diff -- the script installs `curl` and `tar` during install dependencies step, it shouldn't fail because of them --- If your project is set up for it, you can reply to this email and have your reply appear on GitHub as well. If your project does not have this feature enabled and wishes so, or if the feature is enabled but not working, please contact infrastructure at infrastructure@apache.org or file a JIRA ticket with INFRA. ---