Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 1 | #!/bin/bash |
| 2 | |
| 3 | # vim: ts=4 sw=4 sts=4 et tw=72 : |
| 4 | |
| 5 | # force any errors to cause the script and job to end in failure |
| 6 | set -xeu -o pipefail |
| 7 | |
| 8 | ensure_kernel_install() { |
| 9 | # Workaround for mkinitrd failing on occassion. |
| 10 | # On CentOS 7 it seems like the kernel install can fail it's mkinitrd |
| 11 | # run quietly, so we may not notice the failure. This script retries for a |
| 12 | # few times before giving up. |
| 13 | initramfs_ver=$(rpm -q kernel | tail -1 | sed "s/kernel-/initramfs-/") |
| 14 | grub_conf="/boot/grub/grub.conf" |
| 15 | # Public cloud does not use /boot/grub/grub.conf and uses grub2 instead. |
| 16 | if [ ! -e "$grub_conf" ]; then |
| 17 | echo "$grub_conf not found. Using Grub 2 conf instead." |
| 18 | grub_conf="/boot/grub2/grub.cfg" |
| 19 | fi |
| 20 | |
| 21 | for i in $(seq 3); do |
| 22 | if grep "$initramfs_ver" "$grub_conf"; then |
| 23 | break |
| 24 | fi |
| 25 | echo "Kernel initrd missing. Retrying to install kernel..." |
| 26 | yum reinstall -y kernel |
| 27 | done |
| 28 | if ! grep "$initramfs_ver" "$grub_conf"; then |
| 29 | cat /boot/grub/grub.conf |
| 30 | echo "ERROR: Failed to install kernel." |
| 31 | exit 1 |
| 32 | fi |
| 33 | } |
| 34 | |
| 35 | ensure_ubuntu_install() { |
| 36 | # Workaround for mirrors occassionally failing to install a package. |
| 37 | # On Ubuntu sometimes the mirrors fail to install a package. This wrapper |
| 38 | # checks that a package is successfully installed before moving on. |
| 39 | |
| 40 | packages=($@) |
| 41 | |
| 42 | for pkg in "${packages[@]}" |
| 43 | do |
| 44 | # Retry installing package 5 times if necessary |
| 45 | for i in {0..5} |
| 46 | do |
| 47 | if [ "$(dpkg-query -W -f='${Status}' "$pkg" 2>/dev/null | grep -c "ok installed")" -eq 0 ]; then |
| 48 | apt-cache policy "$pkg" |
| 49 | apt-get install "$pkg" |
| 50 | continue |
| 51 | else |
| 52 | echo "$pkg already installed." |
| 53 | break |
| 54 | fi |
| 55 | done |
| 56 | done |
| 57 | } |
| 58 | |
| 59 | rh_systems() { |
| 60 | # Handle the occurance where SELINUX is actually disabled |
| 61 | SELINUX=$(grep -E '^SELINUX=(disabled|permissive|enforcing)$' /etc/selinux/config) |
| 62 | MODE=$(echo "$SELINUX" | cut -f 2 -d '=') |
| 63 | case "$MODE" in |
| 64 | permissive) |
| 65 | echo "************************************" |
| 66 | echo "** SYSTEM ENTERING ENFORCING MODE **" |
| 67 | echo "************************************" |
| 68 | # make sure that the filesystem is properly labelled. |
| 69 | # it could be not fully labeled correctly if it was just switched |
| 70 | # from disabled, the autorelabel misses some things |
| 71 | # skip relabelling on /dev as it will generally throw errors |
| 72 | restorecon -R -e /dev / |
| 73 | |
| 74 | # enable enforcing mode from the very start |
| 75 | setenforce enforcing |
| 76 | |
| 77 | # configure system for enforcing mode on next boot |
| 78 | sed -i 's/SELINUX=permissive/SELINUX=enforcing/' /etc/selinux/config |
| 79 | ;; |
| 80 | disabled) |
| 81 | sed -i 's/SELINUX=disabled/SELINUX=permissive/' /etc/selinux/config |
| 82 | touch /.autorelabel |
| 83 | |
| 84 | echo "*******************************************" |
| 85 | echo "** SYSTEM REQUIRES A RESTART FOR SELINUX **" |
| 86 | echo "*******************************************" |
| 87 | ;; |
| 88 | enforcing) |
| 89 | echo "*********************************" |
| 90 | echo "** SYSTEM IS IN ENFORCING MODE **" |
| 91 | echo "*********************************" |
| 92 | ;; |
| 93 | esac |
| 94 | |
| 95 | # Allow jenkins access to alternatives command to switch java version |
| 96 | cat <<EOF >/etc/sudoers.d/89-jenkins-user-defaults |
| 97 | Defaults:jenkins !requiretty |
| 98 | jenkins ALL = NOPASSWD: /usr/sbin/alternatives |
| 99 | EOF |
| 100 | |
| 101 | echo "---> Updating operating system" |
| 102 | yum clean all |
| 103 | yum install -y deltarpm |
| 104 | yum update -y |
| 105 | |
| 106 | ensure_kernel_install |
| 107 | |
| 108 | # add in components we need or want on systems |
| 109 | echo "---> Installing base packages" |
| 110 | yum install -y @base https://dl.fedoraproject.org/pub/epel/epel-release-latest-7.noarch.rpm |
| 111 | # separate group installs from package installs since a non-existing |
| 112 | # group with dnf based systems (F21+) will fail the install if such |
| 113 | # a group does not exist |
| 114 | yum install -y unzip xz puppet git git-review perl-XML-XPath |
Zack Williams | 6156cb2 | 2020-01-22 14:04:00 -0700 | [diff] [blame] | 115 | yum install -y python-{devel,virtualenv} |
| 116 | yum install -y python3-{devel,setuptools,pip} |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 117 | |
| 118 | # All of our systems require Java (because of Jenkins) |
| 119 | # Install all versions of the OpenJDK devel but force 1.7.0 to be the |
| 120 | # default |
| 121 | |
| 122 | echo "---> Configuring OpenJDK" |
| 123 | yum install -y 'java-*-openjdk-devel' |
| 124 | |
| 125 | FACTER_OS=$(/usr/bin/facter operatingsystem) |
| 126 | FACTER_OSVER=$(/usr/bin/facter operatingsystemrelease) |
| 127 | case "$FACTER_OS" in |
| 128 | Fedora) |
| 129 | if [ "$FACTER_OSVER" -ge "21" ] |
| 130 | then |
| 131 | echo "---> not modifying java alternatives as OpenJDK 1.7.0 does not exist" |
| 132 | else |
| 133 | alternatives --set java /usr/lib/jvm/jre-1.7.0-openjdk.x86_64/bin/java |
| 134 | alternatives --set java_sdk_openjdk /usr/lib/jvm/java-1.7.0-openjdk.x86_64 |
| 135 | fi |
| 136 | ;; |
| 137 | RedHat|CentOS) |
| 138 | if [ "$(echo "$FACTER_OSVER" | cut -d'.' -f1)" -ge "7" ] |
| 139 | then |
| 140 | echo "---> not modifying java alternatives as OpenJDK 1.7.0 does not exist" |
| 141 | else |
| 142 | alternatives --set java /usr/lib/jvm/jre-1.7.0-openjdk.x86_64/bin/java |
| 143 | alternatives --set java_sdk_openjdk /usr/lib/jvm/java-1.7.0-openjdk.x86_64 |
| 144 | fi |
| 145 | ;; |
| 146 | *) |
| 147 | alternatives --set java /usr/lib/jvm/jre-1.7.0-openjdk.x86_64/bin/java |
| 148 | alternatives --set java_sdk_openjdk /usr/lib/jvm/java-1.7.0-openjdk.x86_64 |
| 149 | ;; |
| 150 | esac |
| 151 | |
| 152 | ######################## |
| 153 | # --- START LFTOOLS DEPS |
| 154 | |
| 155 | # Used by various scripts to push patches to Gerrit |
| 156 | yum install -y git-review |
| 157 | |
| 158 | # Needed to parse OpenStack commands used by opendaylight-infra stack commands |
| 159 | # to initialize Heat template based systems. |
| 160 | yum install -y jq |
| 161 | |
| 162 | # Used by lftools scripts to parse XML |
| 163 | yum install -y xmlstarlet |
| 164 | |
Zack Williams | 6156cb2 | 2020-01-22 14:04:00 -0700 | [diff] [blame] | 165 | # Install Shellcheck from archive |
| 166 | SHELLCHECK_VERSION="v0.6.0" |
| 167 | SHELLCHECK_SHA256SUM="95c7d6e8320d285a9f026b5241f48f1c02d225a1b08908660e8b84e58e9c7dce" |
Andy Bavier | d77cf71 | 2020-09-15 16:18:33 -0700 | [diff] [blame] | 168 | curl -L -o /tmp/shellcheck.tar.xz https://github.com/koalaman/shellcheck/releases/download/${SHELLCHECK_VERSION}/shellcheck-${SHELLCHECK_VERSION}.linux.x86_64.tar.xz |
Zack Williams | 6156cb2 | 2020-01-22 14:04:00 -0700 | [diff] [blame] | 169 | echo "$SHELLCHECK_SHA256SUM /tmp/shellcheck.tar.xz" | sha256sum -c - |
| 170 | pushd /tmp |
| 171 | tar -xJvf shellcheck.tar.xz |
| 172 | cp shellcheck-${SHELLCHECK_VERSION}/shellcheck /usr/local/bin/shellcheck |
| 173 | chmod a+x /usr/local/bin/shellcheck |
| 174 | popd |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 175 | |
| 176 | # --- END LFTOOLS DEPS |
| 177 | ###################### |
| 178 | |
| 179 | # install haveged to avoid low entropy rejecting ssh connections |
| 180 | yum install -y haveged |
| 181 | systemctl enable haveged.service |
| 182 | } |
| 183 | |
| 184 | ubuntu_systems() { |
| 185 | # Ignore SELinux since slamming that onto Ubuntu leads to |
| 186 | # frustration |
| 187 | |
| 188 | # Allow jenkins access to update-alternatives command to switch java version |
| 189 | cat <<EOF >/etc/sudoers.d/89-jenkins-user-defaults |
| 190 | Defaults:jenkins !requiretty |
Zack Williams | 3aa36f9 | 2019-09-20 10:58:16 -0700 | [diff] [blame] | 191 | jenkins ALL = NOPASSWD: /usr/sbin/update-alternatives, /usr/sbin/update-java-alternatives |
| 192 | |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 193 | EOF |
| 194 | |
| 195 | export DEBIAN_FRONTEND=noninteractive |
| 196 | cat <<EOF >> /etc/apt/apt.conf |
| 197 | APT { |
| 198 | Get { |
| 199 | Assume-Yes "true"; |
| 200 | allow-change-held-packages "true"; |
| 201 | allow-downgrades "true"; |
| 202 | allow-remove-essential "true"; |
| 203 | }; |
| 204 | }; |
| 205 | |
| 206 | Dpkg::Options { |
| 207 | "--force-confdef"; |
| 208 | "--force-confold"; |
| 209 | }; |
| 210 | |
| 211 | EOF |
| 212 | |
| 213 | # Add hostname to /etc/hosts to fix 'unable to resolve host' issue with sudo |
| 214 | sed -i "/127.0.0.1/s/$/ $(hostname)/" /etc/hosts |
| 215 | |
| 216 | echo "---> Updating operating system" |
| 217 | |
Zack Williams | 889b9f2 | 2019-09-20 09:23:11 -0700 | [diff] [blame] | 218 | # added 2019-09-20 as apt-add-repository and software-properties-common weren't working |
| 219 | cat <<EOF >/etc/apt/sources.list.d/packer.list |
| 220 | # created by packer |
| 221 | deb http://us.archive.ubuntu.com/ubuntu $(lsb_release -sc) main universe restricted multiverse |
| 222 | |
| 223 | EOF |
| 224 | |
Zack Williams | 6057e76 | 2019-09-20 08:59:22 -0700 | [diff] [blame] | 225 | # remove these as the fix seems to be broken now? zdw, 2019-09-20 |
| 226 | # # Change made 2018-07-09 by zdw |
| 227 | # # per discussion on #lf-releng, the upstream Ubuntu image changed to be |
| 228 | # # missing add-apt-repository, so the next command failed. |
| 229 | # apt-get update -m |
| 230 | # # added 2019-09-20, sometimes upstream repos are broken w/this package, try to determine why |
| 231 | # apt-cache madison software-properties-common |
| 232 | # apt-get install -y software-properties-common |
Zack Williams | 852578f | 2018-04-12 14:03:57 -0700 | [diff] [blame] | 233 | |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 234 | # add additional repositories |
Zack Williams | 889b9f2 | 2019-09-20 09:23:11 -0700 | [diff] [blame] | 235 | # add-apt-repository "deb http://us.archive.ubuntu.com/ubuntu $(lsb_release -sc) main universe restricted multiverse" |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 236 | |
| 237 | echo "---> Installing base packages" |
| 238 | apt-get clean |
| 239 | apt-get update -m |
Zack Williams | 889b9f2 | 2019-09-20 09:23:11 -0700 | [diff] [blame] | 240 | apt-get upgrade -m |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 241 | apt-get dist-upgrade -m |
| 242 | |
Andy Bavier | b781c4c | 2018-09-20 08:16:52 -0700 | [diff] [blame] | 243 | apt-get update -m |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 244 | ensure_ubuntu_install unzip xz-utils puppet git libxml-xpath-perl |
| 245 | |
Zack Williams | 1b00d40 | 2019-07-22 17:17:10 -0700 | [diff] [blame] | 246 | # Deprecated - updating to corretto Java distro, 2019-07-22, zdw |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 247 | # install Java 7 |
Zack Williams | 1b00d40 | 2019-07-22 17:17:10 -0700 | [diff] [blame] | 248 | # echo "---> Configuring OpenJDK" |
| 249 | # FACTER_OSVER=$(/usr/bin/facter operatingsystemrelease) |
| 250 | # case "$FACTER_OSVER" in |
| 251 | # 14.04) |
| 252 | # apt-get install openjdk-7-jdk |
| 253 | # # make jdk8 available |
| 254 | # add-apt-repository -y ppa:openjdk-r/ppa |
| 255 | # apt-get update |
| 256 | # # We need to force openjdk-8-jdk to install |
| 257 | # apt-get install openjdk-8-jdk |
| 258 | # # make sure that we still default to openjdk 7 |
| 259 | # update-alternatives --set java /usr/lib/jvm/java-7-openjdk-amd64/jre/bin/java |
| 260 | # update-alternatives --set javac /usr/lib/jvm/java-7-openjdk-amd64/bin/javac |
| 261 | # ;; |
| 262 | # 16.04) |
| 263 | # apt-get install openjdk-8-jdk |
| 264 | # ;; |
| 265 | # *) |
| 266 | # echo "---> Unknown Ubuntu version $FACTER_OSVER" |
| 267 | # exit 1 |
| 268 | # ;; |
| 269 | # esac |
| 270 | ######################## |
| 271 | |
| 272 | echo "---> Configuring Corretto JDK Distribution" |
| 273 | # instructions: https://docs.aws.amazon.com/corretto/latest/corretto-8-ug/generic-linux-install.html |
| 274 | # install prereqs |
Zack Williams | 1b00d40 | 2019-07-22 17:17:10 -0700 | [diff] [blame] | 275 | |
Zack Williams | 3fa1050 | 2020-09-29 22:03:02 -0700 | [diff] [blame^] | 276 | cat << EOF | base64 -d > /tmp/corretto-apt-key.gpg |
| 277 | LS0tLS1CRUdJTiBQR1AgUFVCTElDIEtFWSBCTE9DSy0tLS0tClZlcnNpb246IEdudVBHIH |
| 278 | YyLjAuMjIgKEdOVS9MaW51eCkKCm1RSU5CRjNwU2hrQkVBREp6Z2xlaFFERmxjMSs5VkZ1 |
| 279 | YlZQenBxOFpZdHptSmtOamYwOXNjT1V6YUtaT20zQXIKbVBoOVJ1Zms0bUI3dDFMUDRKZU |
| 280 | hBS0FTMTdnZ0NIR1Z4UkdYQUFROUxhZjhpYlg0U2lGTzNFaHl5bDNzbXVGZgpaaGV4Qm52 |
| 281 | Yzd2UmM0RVVsS3FhckNRUlVsYXJhRE9ybXE3V2JoWGR2Q2djNHUydUJMd1VqQWQzUEhRVU |
| 282 | J5QVp3CmxzRVF6cFFuZWhOb21qckUwcE82bXM5QWhtcGJYbGYveXIxNEVYdmxvNGxUZDhR |
| 283 | VWR2UytBT0NZZnJIYjlXR08KSUVzeXlEdXp1ZjJnclYvUUZwb2kwVkJoVEN5aU5ZWGxhMk |
| 284 | FmQ3JlTUdsT0NZc2p3MW5VOTNPeUFxRjNTYVRPQwpvNTJ5cnpjYjJOcGJCRHdSWE9ITndl |
| 285 | MW1kK0RiUndFZmthV3I1STkxRnFScGdFZWF3cXl4WTFtaUpSSGR1aHN6CldUZ1RNQkYvRV |
| 286 | FmbVRzcEQyWUJYL0JqTkpUcmREWFl2QUNYOHNsVlYvdkJucGkrZEVwVkVLM2hoMjFpajk5 |
| 287 | MVMKbHY4WW9Gbm9DN1hQNDRDN1dOcFZRcEdXOVpXcG5qTEN2bTNETUtXMHIzVmZiM1hEWW |
| 288 | huSEkxUTE0UHhuMGN3Zgp4MUwyUkE0ZG95V2QxVFJaQkZCZTJmMHZTa1pUMFlGYWliS2FL |
| 289 | aTZBa0RJTVUvK3UrL2Uzd1diWVhxenNTSVRqCmZmTWtwTU1OU3d4Ym04SnFuc3VkanV6ZE |
| 290 | VzWUFpQlVjRk13V3lzUURjeXU2M3VuMk9tTEtMZkt4eTE5dkNwUzEKOG1rTnk5NUp1TzRq |
| 291 | WnR1K0lpaW52U1NqbGJKbXNsdTN1SzMvY1RSc1dhQjdCUnRIZXdFN1N1Z01Pd0FSQVFBQg |
| 292 | p0RWhCYldGNmIyNGdVMlZ5ZG1salpYTWdURXhESUNoQmJXRjZiMjRnUTI5eWNtVjBkRzhn |
| 293 | Y21Wc1pXRnpaU2tnClBHTnZjbkpsZEhSdkxYUmxZVzFBWVcxaGVtOXVMbU52YlQ2SkFqRU |
| 294 | VFd0VDQUJzRkFsM3BTaGtDR3k4RkNRbG0KQVlBRkZRZ0tDUXNDSGdFQ0Y0QUFDZ2tRb1NK |
| 295 | VUtyQlBKT09KRGcvNkFxbW50YXhEV1g2cWZSKyswcXd0RDlMcAp2Z09ORnZBKzlBWVFlR3 |
| 296 | Q3T1g3OU8vU1NQeTk3S3ZuNkRZUkJkZWxTaFRBSDYwRGJYQ1VzNDJzSVJGcVJqbUhZCkhm |
| 297 | SWdPa1VKaldvSno5b1FuWSttekFLYk9vaENyUitZSXZ5Q2VnRmIwZGJvRGFxU1E0dzY4K2 |
| 298 | QxaXM3TDg0cHoKWkIyajBuclFEYkZpaFBtUitlcGZIa0xVR0d5d3VaSENkRUZmRDhuWE1P |
| 299 | SmVWYmdTemY3VmhsOFpyeWRJa1pUSQo3YUFTRzVNa0RPL0d1VnBFR1FZQW5IOWgvanpKbG |
| 300 | ZVS25kc3dDNlVGY001T2wwN3BEUGRIVkJBaTlxMVN5eERlCnVTUzFOZ0RXN09XN3pncEIr |
| 301 | NC9QclpLS2lFUC9mQkFXYTluRlNMd1RhTWRzb2FBdVFBbW1nYnFZZnkzWFhLSzcKSUJhS1 |
| 302 | NuSnBRRHZOYjB2bVhKRVkzcVgyQmZoMHAxS0NlYVFoWXdJSmk4clBRV0MyNGZpTFk5YmRD |
| 303 | SWxrYmJQUQpDU05PRXE5blVXUmc5S2JVR21kL1BXU2tUNkpoZXlxM0JaQkYxWVBZRXQ4by |
| 304 | 9sNDM3SEhkMDhsUkVxSDBzYW5hCkhiNzJHWlRpMlJVck5CQnA1QzFlOE1xbGxYRTZSS21y |
| 305 | aTJtMFRTQkhSNUM0WkxJSTlkdXlBODM5ZFlJQTRLR1UKbm1ldFpja3VSdXdIRm1kMy9ZV3 |
| 306 | RNRWZuNDdVZWR6aFZUMTZ6M092QmlwSFUxQkt6TEdjdlVGWHJVS3ZwSlFsaApkTlBVUWgr |
| 307 | d2I5MUV6SXRqa0o5Nm0rTis4MWlRZE4zeWQ4Y0UzOE5UQThiK1FjN3RtVFl4d05aeGN2MT |
| 308 | ZGeExBCnkyVmhLYzA5QThSd1NJNjl2RHM9Cj1aTlJICi0tLS0tRU5EIFBHUCBQVUJMSUMg |
| 309 | S0VZIEJMT0NLLS0tLS0K |
Zack Williams | 52b4cb6 | 2019-08-30 08:09:07 -0700 | [diff] [blame] | 310 | EOF |
| 311 | |
Zack Williams | 3fa1050 | 2020-09-29 22:03:02 -0700 | [diff] [blame^] | 312 | apt-key add /tmp/corretto-apt-key.gpg |
| 313 | add-apt-repository -y 'deb https://apt.corretto.aws stable main' |
| 314 | apt-get update |
| 315 | |
| 316 | apt-get install -y java-1.8.0-amazon-corretto-jdk java-11-amazon-corretto-jdk |
| 317 | |
Zack Williams | 1b00d40 | 2019-07-22 17:17:10 -0700 | [diff] [blame] | 318 | # Set default version to be Java8 |
Zack Williams | 52b4cb6 | 2019-08-30 08:09:07 -0700 | [diff] [blame] | 319 | update-java-alternatives --set java-1.8.0-amazon-corretto |
Zack Williams | 1b00d40 | 2019-07-22 17:17:10 -0700 | [diff] [blame] | 320 | |
| 321 | # Set default version to be Java11 |
Zack Williams | 52b4cb6 | 2019-08-30 08:09:07 -0700 | [diff] [blame] | 322 | # update-java-alternatives --set java-11-amazon-corretto |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 323 | |
| 324 | ######################## |
| 325 | # --- START LFTOOLS DEPS |
| 326 | |
| 327 | # Used by various scripts to push patches to Gerrit |
Zack Williams | 0716145 | 2020-02-11 11:04:56 -0700 | [diff] [blame] | 328 | # ensure_ubuntu_install git-review |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 329 | |
| 330 | # Needed to parse OpenStack commands used by opendaylight-infra stack commands |
| 331 | # to initialize Heat template based systems. |
| 332 | ensure_ubuntu_install jq |
| 333 | |
| 334 | # Used by lftools scripts to parse XML |
| 335 | ensure_ubuntu_install xmlstarlet |
| 336 | |
Zack Williams | ae52f5e | 2018-04-12 11:47:57 -0700 | [diff] [blame] | 337 | # Change made by zdw on 2018-04-12 |
| 338 | # hackage.haskell.org was down, talked to zxiiro on #lf-releng and he recommended |
| 339 | # pulling down the packages in a way similar to this ansible role, rather than using cabal: |
| 340 | # https://github.com/lfit/ansible-roles-shellcheck-install/blob/master/tasks/main.yml |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 341 | |
Zack Williams | 1b00d40 | 2019-07-22 17:17:10 -0700 | [diff] [blame] | 342 | SHELLCHECK_VERSION="v0.6.0" |
| 343 | SHELLCHECK_SHA256SUM="95c7d6e8320d285a9f026b5241f48f1c02d225a1b08908660e8b84e58e9c7dce" |
Andy Bavier | 5f2dd1e | 2020-09-15 16:58:02 -0700 | [diff] [blame] | 344 | curl -L -o /tmp/shellcheck.tar.xz https://github.com/koalaman/shellcheck/releases/download/${SHELLCHECK_VERSION}/shellcheck-${SHELLCHECK_VERSION}.linux.x86_64.tar.xz |
Zack Williams | ae52f5e | 2018-04-12 11:47:57 -0700 | [diff] [blame] | 345 | echo "$SHELLCHECK_SHA256SUM /tmp/shellcheck.tar.xz" | sha256sum -c - |
| 346 | pushd /tmp |
| 347 | tar -xJvf shellcheck.tar.xz |
| 348 | cp shellcheck-${SHELLCHECK_VERSION}/shellcheck /usr/local/bin/shellcheck |
| 349 | chmod a+x /usr/local/bin/shellcheck |
| 350 | popd |
Linux Foundation Administrators | 1dc9dd5 | 2018-01-26 09:09:09 -0800 | [diff] [blame] | 351 | |
| 352 | # --- END LFTOOLS DEPS |
| 353 | ###################### |
| 354 | |
| 355 | # install haveged to avoid low entropy rejecting ssh connections |
| 356 | apt-get install haveged |
| 357 | update-rc.d haveged defaults |
| 358 | |
| 359 | # disable unattended upgrades & daily updates |
| 360 | echo '---> Disabling automatic daily upgrades' |
| 361 | sed -ine 's/"1"/"0"/g' /etc/apt/apt.conf.d/10periodic |
| 362 | echo 'APT::Periodic::Unattended-Upgrade "0";' >> /etc/apt/apt.conf.d/10periodic |
| 363 | } |
| 364 | |
| 365 | all_systems() { |
| 366 | # Do any Distro specific installations here |
| 367 | echo "Checking distribution" |
| 368 | FACTER_OS=$(/usr/bin/facter operatingsystem) |
| 369 | case "$FACTER_OS" in |
| 370 | *) |
| 371 | echo "---> $FACTER_OS found" |
| 372 | echo "No extra steps for $FACTER_OS" |
| 373 | ;; |
| 374 | esac |
| 375 | } |
| 376 | |
| 377 | echo "---> Attempting to detect OS" |
| 378 | # upstream cloud images use the distro name as the initial user |
| 379 | ORIGIN=$(if [ -e /etc/redhat-release ] |
| 380 | then |
| 381 | echo redhat |
| 382 | else |
| 383 | echo ubuntu |
| 384 | fi) |
| 385 | #ORIGIN=$(logname) |
| 386 | |
| 387 | case "${ORIGIN}" in |
| 388 | fedora|centos|redhat) |
| 389 | echo "---> RH type system detected" |
| 390 | rh_systems |
| 391 | ;; |
| 392 | ubuntu) |
| 393 | echo "---> Ubuntu system detected" |
| 394 | ubuntu_systems |
| 395 | ;; |
| 396 | *) |
| 397 | # Kill the build for unhandled distributions |
| 398 | echo "---> Unknown operating system" 1>&2 |
| 399 | exit 1 |
| 400 | ;; |
| 401 | esac |
| 402 | |
| 403 | # execute steps for all systems |
| 404 | all_systems |