kbsingh / centos / kickstarts

Forked from centos/kickstarts 5 years ago
Clone

Blame CentOS-8-x86_64-Vagrant.ks

Karanbir Singh a10660
#url --mirrorlist=http://mirrorlist.centos.org/?release=8&arch=x86_64&repo=BaseOS&infra=stock
Karanbir Singh a10660
#repo --name=AppStream --mirrorlist=http://mirrorlist.centos.org/?release=8&arch=x86_64&repo=AppStream&infra=stock
Karanbir Singh a10660
text
Karanbir Singh a10660
keyboard --vckeymap us
Karanbir Singh a10660
lang en_US
Karanbir Singh a10660
skipx
Brian Stinson d463c3
network  --bootproto=dhcp --device=link --activate --onboot=on
Karanbir Singh a10660
rootpw --plaintext vagrant
Karanbir Singh a10660
firewall --disabled
Karanbir Singh a10660
timezone --utc UTC
Karanbir Singh a10660
services --enabled=vmtoolsd
Karanbir Singh a10660
# The biosdevname and ifnames options ensure we get "eth0" as our interface
Karanbir Singh a10660
# even in environments like virtualbox that emulate a real NW card
Karanbir Singh a10660
bootloader --timeout=1 --append="no_timer_check console=tty0 console=ttyS0,115200n8 net.ifnames=0 biosdevname=0 elevator=noop"
Karanbir Singh a10660
zerombr
Karanbir Singh a10660
clearpart --all --drives=vda
Karanbir Singh a10660
part / --fstype=xfs --asprimary --size=1024 --grow --ondisk=vda
Karanbir Singh a10660
Karanbir Singh a10660
user --name=vagrant --plaintext --password=vagrant
Karanbir Singh a10660
Brian Stinson dfa83b
shutdown
Karanbir Singh a10660
Karanbir Singh a10660
%packages --instLangs=en
Karanbir Singh a10660
bash-completion
Karanbir Singh a10660
man-pages
Karanbir Singh a10660
bzip2
Karanbir Singh a10660
rsync
Karanbir Singh a10660
nfs-utils
Karanbir Singh a10660
cifs-utils
Karanbir Singh a10660
chrony
Karanbir Singh a10660
yum-utils
Karanbir Singh a10660
hyperv-daemons
Karanbir Singh a10660
open-vm-tools
Karanbir Singh a10660
# Vagrant boxes aren't normally visible, no need for Plymouth
Karanbir Singh a10660
-plymouth
Karanbir Singh a10660
# Microcode updates cannot work in a VM
Karanbir Singh a10660
-microcode_ctl
Karanbir Singh a10660
# Firmware packages are not needed in a VM
Karanbir Singh a10660
-iwl100-firmware
Karanbir Singh a10660
-iwl1000-firmware
Karanbir Singh a10660
-iwl105-firmware
Karanbir Singh a10660
-iwl135-firmware
Karanbir Singh a10660
-iwl2000-firmware
Karanbir Singh a10660
-iwl2030-firmware
Karanbir Singh a10660
-iwl3160-firmware
Karanbir Singh a10660
-iwl3945-firmware
Karanbir Singh a10660
-iwl4965-firmware
Karanbir Singh a10660
-iwl5000-firmware
Karanbir Singh a10660
-iwl5150-firmware
Karanbir Singh a10660
-iwl6000-firmware
Karanbir Singh a10660
-iwl6000g2a-firmware
Karanbir Singh a10660
-iwl6050-firmware
Karanbir Singh a10660
-iwl7260-firmware
Karanbir Singh a10660
# Don't build rescue initramfs
Karanbir Singh a10660
-dracut-config-rescue
Karanbir Singh a10660
%end
Karanbir Singh a10660
Karanbir Singh a10660
# kdump needs to reserve 160MB + 2bits/4kB RAM, and automatic allocation only
Karanbir Singh a10660
# works on systems with at least 2GB RAM (which excludes most Vagrant boxes)
Karanbir Singh a10660
# CBS doesn't support %addon yet https://bugs.centos.org/view.php?id=12169
Karanbir Singh a10660
%addon com_redhat_kdump --disable
Karanbir Singh a10660
%end
Karanbir Singh a10660
Karanbir Singh a10660
%post
Karanbir Singh a10660
# configure swap to a file
Karanbir Singh a10660
fallocate -l 2G /swapfile
Karanbir Singh a10660
chmod 600 /swapfile
Karanbir Singh a10660
mkswap /swapfile
Karanbir Singh a10660
echo "/swapfile none swap defaults 0 0" >> /etc/fstab
Karanbir Singh a10660
Karanbir Singh a10660
# sudo
Karanbir Singh a10660
echo "%vagrant ALL=(ALL) NOPASSWD: ALL" > /etc/sudoers.d/vagrant
Karanbir Singh a10660
chmod 0440 /etc/sudoers.d/vagrant
Karanbir Singh a10660
Karanbir Singh a10660
# Fix for https://github.com/CentOS/sig-cloud-instance-build/issues/38
Karanbir Singh a10660
cat > /etc/sysconfig/network-scripts/ifcfg-eth0 << EOF
Karanbir Singh a10660
DEVICE="eth0"
Karanbir Singh a10660
BOOTPROTO="dhcp"
Karanbir Singh a10660
ONBOOT="yes"
Karanbir Singh a10660
TYPE="Ethernet"
Karanbir Singh a10660
PERSISTENT_DHCLIENT="yes"
Karanbir Singh a10660
EOF
Karanbir Singh a10660
Karanbir Singh a10660
# sshd: disable password authentication and DNS checks
Karanbir Singh a10660
ex -s /etc/ssh/sshd_config <
Karanbir Singh a10660
:%substitute/^\(PasswordAuthentication\) yes$/\1 no/
Karanbir Singh a10660
:%substitute/^#\(UseDNS\) yes$/&\r\1 no/
Karanbir Singh a10660
:update
Karanbir Singh a10660
:quit
Karanbir Singh a10660
EOF
Karanbir Singh a10660
cat >>/etc/sysconfig/sshd <
Karanbir Singh a10660
Karanbir Singh a10660
# Decrease connection time by preventing reverse DNS lookups
Karanbir Singh a10660
# (see https://lists.centos.org/pipermail/centos-devel/2016-July/014981.html
Karanbir Singh a10660
#  and man sshd for more information)
Karanbir Singh a10660
OPTIONS="-u0"
Karanbir Singh a10660
EOF
Karanbir Singh a10660
Karanbir Singh a10660
# Default insecure vagrant key
Karanbir Singh a10660
mkdir -m 0700 -p /home/vagrant/.ssh
Karanbir Singh a10660
echo "ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEA6NF8iallvQVp22WDkTkyrtvp9eWW6A8YVr+kz4TjGYe7gHzIw+niNltGEFHzD8+v1I2YJ6oXevct1YeS0o9HZyN1Q9qgCgzUFtdOKLv6IedplqoPkcmF0aYet2PkEDo3MlTBckFXPITAMzF8dJSIFo9D8HfdOV0IAdx4O7PtixWKn5y2hMNG0zQPyUecp4pzC6kivAIhyfHilFR61RGL+GPXQ2MWZWFYbAGjyiYJnAmCP3NOTd0jMZEnDkbUvxhMmBYSdETk1rRgm+R4LOzFUGaHqHDLKLX+FIPKcF96hrucXzcWyLbIbEgE98OHlnVYCzRdK8jlqm8tehUc9c9WhQ== vagrant insecure public key" >> /home/vagrant/.ssh/authorized_keys
Karanbir Singh a10660
chmod 600 /home/vagrant/.ssh/authorized_keys
Karanbir Singh a10660
chown -R vagrant:vagrant /home/vagrant/.ssh
Karanbir Singh a10660
Karanbir Singh a10660
# Fix for issue #76, regular users can gain admin privileges via su
Karanbir Singh a10660
ex -s /etc/pam.d/su <<'EOF'
Karanbir Singh a10660
# allow vagrant to use su, but prevent others from becoming root or vagrant
Karanbir Singh a10660
/^account\s\+sufficient\s\+pam_succeed_if.so uid = 0 use_uid quiet$/
Karanbir Singh a10660
:append
Karanbir Singh a10660
account		[success=1 default=ignore] \\
Karanbir Singh a10660
				pam_succeed_if.so user = vagrant use_uid quiet
Karanbir Singh a10660
account		required	pam_succeed_if.so user notin root:vagrant
Karanbir Singh a10660
.
Karanbir Singh a10660
:update
Karanbir Singh a10660
:quit
Karanbir Singh a10660
EOF
Karanbir Singh a10660
Karanbir Singh a10660
# systemd should generate a new machine id during the first boot, to
Karanbir Singh a10660
# avoid having multiple Vagrant instances with the same id in the local
Karanbir Singh a10660
# network. /etc/machine-id should be empty, but it must exist to prevent
Karanbir Singh a10660
# boot errors (e.g.  systemd-journald failing to start).
Karanbir Singh a10660
:>/etc/machine-id
Karanbir Singh a10660
Karanbir Singh a10660
echo 'vag' > /etc/yum/vars/infra
Karanbir Singh a10660
Karanbir Singh a10660
# Blacklist the floppy module to avoid probing timeouts
Karanbir Singh a10660
echo blacklist floppy > /etc/modprobe.d/nofloppy.conf
Karanbir Singh a10660
chcon -u system_u -r object_r -t modules_conf_t /etc/modprobe.d/nofloppy.conf
Karanbir Singh a10660
Karanbir Singh a10660
# Customize the initramfs
Karanbir Singh a10660
pushd /etc/dracut.conf.d
Karanbir Singh a10660
# Enable VMware PVSCSI support for VMware Fusion guests.
Karanbir Singh a10660
echo 'add_drivers+=" vmw_pvscsi "' > vmware-fusion-drivers.conf
Karanbir Singh a10660
echo 'add_drivers+=" hv_netvsc hv_storvsc hv_utils hv_vmbus hid-hyperv "' > hyperv-drivers.conf
Karanbir Singh a10660
# There's no floppy controller, but probing for it generates timeouts
Karanbir Singh a10660
echo 'omit_drivers+=" floppy "' > nofloppy.conf
Karanbir Singh a10660
popd
Karanbir Singh a10660
# Fix the SELinux context of the new files
Karanbir Singh a10660
restorecon -f - <
Karanbir Singh a10660
/etc/sudoers.d/vagrant
Karanbir Singh a10660
/etc/dracut.conf.d/vmware-fusion-drivers.conf
Karanbir Singh a10660
/etc/dracut.conf.d/hyperv-drivers.conf
Karanbir Singh a10660
/etc/dracut.conf.d/nofloppy.conf
Karanbir Singh a10660
EOF
Karanbir Singh a10660
Karanbir Singh a10660
# Rerun dracut for the installed kernel (not the running kernel):
Karanbir Singh a10660
KERNEL_VERSION=$(rpm -q kernel --qf '%{version}-%{release}.%{arch}\n')
Karanbir Singh a10660
dracut -f /boot/initramfs-${KERNEL_VERSION}.img ${KERNEL_VERSION}
Karanbir Singh a10660
Karanbir Singh a10660
# Seal for deployment
Karanbir Singh a10660
rm -rf /etc/ssh/ssh_host_*
Karanbir Singh a10660
hostnamectl set-hostname localhost.localdomain
Karanbir Singh a10660
rm -rf /etc/udev/rules.d/70-*
Karanbir Singh a10660
%end