Saltstack Official Linux Formula
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

README.rst 54KB

9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
8 years ago
8 years ago
8 years ago
8 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
9 years ago
1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254
  1. ============
  2. Linux Fomula
  3. ============
  4. Linux Operating Systems:
  5. * Ubuntu
  6. * CentOS
  7. * RedHat
  8. * Fedora
  9. * Arch
  10. Sample Pillars
  11. ==============
  12. Linux System
  13. ------------
  14. Basic Linux box
  15. .. code-block:: yaml
  16. linux:
  17. system:
  18. enabled: true
  19. name: 'node1'
  20. domain: 'domain.com'
  21. cluster: 'system'
  22. environment: prod
  23. timezone: 'Europe/Prague'
  24. utc: true
  25. Linux with system users, some with password set:
  26. .. warning:: If no ``password`` variable is passed,
  27. any predifined password will be removed.
  28. .. code-block:: yaml
  29. linux:
  30. system:
  31. ...
  32. user:
  33. jdoe:
  34. name: 'jdoe'
  35. enabled: true
  36. sudo: true
  37. shell: /bin/bash
  38. full_name: 'Jonh Doe'
  39. home: '/home/jdoe'
  40. home_dir_mode: 755
  41. email: 'jonh@doe.com'
  42. jsmith:
  43. name: 'jsmith'
  44. enabled: true
  45. full_name: 'With clear password'
  46. home: '/home/jsmith'
  47. hash_password: true
  48. password: "userpassword"
  49. mark:
  50. name: 'mark'
  51. enabled: true
  52. full_name: "unchange password'
  53. home: '/home/mark'
  54. password: false
  55. elizabeth:
  56. name: 'elizabeth'
  57. enabled: true
  58. full_name: 'With hased password'
  59. home: '/home/elizabeth'
  60. password: "$6$nUI7QEz3$dFYjzQqK5cJ6HQ38KqG4gTWA9eJu3aKx6TRVDFh6BVJxJgFWg2akfAA7f1fCxcSUeOJ2arCO6EEI6XXnHXxG10"
  61. Configure sudo for users and groups under ``/etc/sudoers.d/``.
  62. This ways ``linux.system.sudo`` pillar map to actual sudo attributes:
  63. .. code-block:: jinja
  64. # simplified template:
  65. Cmds_Alias {{ alias }}={{ commands }}
  66. {{ user }} {{ hosts }}=({{ runas }}) NOPASSWD: {{ commands }}
  67. %{{ group }} {{ hosts }}=({{ runas }}) NOPASSWD: {{ commands }}
  68. # when rendered:
  69. saltuser1 ALL=(ALL) NOPASSWD: ALL
  70. .. code-block:: yaml
  71. linux:
  72. system:
  73. sudo:
  74. enabled: true
  75. aliases:
  76. host:
  77. LOCAL:
  78. - localhost
  79. PRODUCTION:
  80. - db1
  81. - db2
  82. runas:
  83. DBA:
  84. - postgres
  85. - mysql
  86. SALT:
  87. - root
  88. command:
  89. # Note: This is not 100% safe when ALL keyword is used, user still may modify configs and hide his actions.
  90. # Best practice is to specify full list of commands user is allowed to run.
  91. SUPPORT_RESTRICTED:
  92. - /bin/vi /etc/sudoers*
  93. - /bin/vim /etc/sudoers*
  94. - /bin/nano /etc/sudoers*
  95. - /bin/emacs /etc/sudoers*
  96. - /bin/su - root
  97. - /bin/su -
  98. - /bin/su
  99. - /usr/sbin/visudo
  100. SUPPORT_SHELLS:
  101. - /bin/sh
  102. - /bin/ksh
  103. - /bin/bash
  104. - /bin/rbash
  105. - /bin/dash
  106. - /bin/zsh
  107. - /bin/csh
  108. - /bin/fish
  109. - /bin/tcsh
  110. - /usr/bin/login
  111. - /usr/bin/su
  112. - /usr/su
  113. ALL_SALT_SAFE:
  114. - /usr/bin/salt state*
  115. - /usr/bin/salt service*
  116. - /usr/bin/salt pillar*
  117. - /usr/bin/salt grains*
  118. - /usr/bin/salt saltutil*
  119. - /usr/bin/salt-call state*
  120. - /usr/bin/salt-call service*
  121. - /usr/bin/salt-call pillar*
  122. - /usr/bin/salt-call grains*
  123. - /usr/bin/salt-call saltutil*
  124. SALT_TRUSTED:
  125. - /usr/bin/salt*
  126. users:
  127. # saltuser1 with default values: saltuser1 ALL=(ALL) NOPASSWD: ALL
  128. saltuser1: {}
  129. saltuser2:
  130. hosts:
  131. - LOCAL
  132. # User Alias DBA
  133. DBA:
  134. hosts:
  135. - ALL
  136. commands:
  137. - ALL_SALT_SAFE
  138. groups:
  139. db-ops:
  140. hosts:
  141. - ALL
  142. - '!PRODUCTION'
  143. runas:
  144. - DBA
  145. commands:
  146. - /bin/cat *
  147. - /bin/less *
  148. - /bin/ls *
  149. salt-ops:
  150. hosts:
  151. - 'ALL'
  152. runas:
  153. - SALT
  154. commands:
  155. - SUPPORT_SHELLS
  156. salt-ops-2nd:
  157. name: salt-ops
  158. nopasswd: false
  159. setenv: true # Enable sudo -E option
  160. runas:
  161. - DBA
  162. commands:
  163. - ALL
  164. - '!SUPPORT_SHELLS'
  165. - '!SUPPORT_RESTRICTED'
  166. Linux with package, latest version:
  167. .. code-block:: yaml
  168. linux:
  169. system:
  170. ...
  171. package:
  172. package-name:
  173. version: latest
  174. Linux with package from certail repo, version with no upgrades:
  175. .. code-block:: yaml
  176. linux:
  177. system:
  178. ...
  179. package:
  180. package-name:
  181. version: 2132.323
  182. repo: 'custom-repo'
  183. hold: true
  184. Linux with package from certail repo, version with no GPG
  185. verification:
  186. .. code-block:: yaml
  187. linux:
  188. system:
  189. ...
  190. package:
  191. package-name:
  192. version: 2132.323
  193. repo: 'custom-repo'
  194. verify: false
  195. Linux with autoupdates (automatically install security package
  196. updates):
  197. .. code-block:: yaml
  198. linux:
  199. system:
  200. ...
  201. autoupdates:
  202. enabled: true
  203. mail: root@localhost
  204. mail_only_on_error: true
  205. remove_unused_dependencies: false
  206. automatic_reboot: true
  207. automatic_reboot_time: "02:00"
  208. Managing cron tasks
  209. -------------------
  210. There are two data structures that are related to managing cron itself and
  211. cron tasks:
  212. .. code-block:: yaml
  213. linux:
  214. system:
  215. cron:
  216. and
  217. .. code-block:: yaml
  218. linux:
  219. system:
  220. job:
  221. `linux:system:cron` manages cron packages, services, and '/etc/cron.allow' file.
  222. 'deny' files are managed the only way - we're ensuring they are absent, that's
  223. a requirement from CIS 5.1.8
  224. 'cron' pillar structure is the following:
  225. .. code-block:: yaml
  226. linux:
  227. system:
  228. cron:
  229. enabled: true
  230. pkgs: [ <cron packages> ]
  231. services: [ <cron services> ]
  232. user:
  233. <username>:
  234. enabled: true
  235. To add user to '/etc/cron.allow' use 'enabled' key as shown above.
  236. '/etc/cron.deny' is not managed as CIS 5.1.8 requires it was removed.
  237. A user would be ignored if any of the following is true:
  238. * user is disabled in `linux:system:user:<username>`
  239. * user is disabled in `linux:system:cron:user:<username>`
  240. `linux:system:job` manages individual cron tasks.
  241. By default, it will use name as an identifier, unless identifier key is
  242. explicitly set or False (then it will use Salt's default behavior which is
  243. identifier same as command resulting in not being able to change it):
  244. .. code-block:: yaml
  245. linux:
  246. system:
  247. ...
  248. job:
  249. cmd1:
  250. command: '/cmd/to/run'
  251. identifier: cmd1
  252. enabled: true
  253. user: 'root'
  254. hour: 2
  255. minute: 0
  256. Managing 'at' tasks
  257. -------------------
  258. Pillar for managing `at` tasks is similar to one for `cron` tasks:
  259. .. code-block:: yaml
  260. linux:
  261. system:
  262. at:
  263. enabled: true
  264. pkgs: [ <at packages> ]
  265. services: [ <at services> ]
  266. user:
  267. <username>:
  268. enabled: true
  269. To add a user to '/etc/at.allow' use 'enabled' key as shown above.
  270. '/etc/at.deny' is not managed as CIS 5.1.8 requires it was removed.
  271. A user will be ignored if any of the following is true:
  272. * user is disabled in `linux:system:user:<username>`
  273. * user is disabled in `linux:system:at:user:<username>`
  274. Linux security limits (limit sensu user memory usage to max 1GB):
  275. .. code-block:: yaml
  276. linux:
  277. system:
  278. ...
  279. limit:
  280. sensu:
  281. enabled: true
  282. domain: sensu
  283. limits:
  284. - type: hard
  285. item: as
  286. value: 1000000
  287. Enable autologin on ``tty1`` (may work only for Ubuntu 14.04):
  288. .. code-block:: yaml
  289. linux:
  290. system:
  291. console:
  292. tty1:
  293. autologin: root
  294. # Enable serial console
  295. ttyS0:
  296. autologin: root
  297. rate: 115200
  298. term: xterm
  299. To disable set autologin to ``false``.
  300. Set ``policy-rc.d`` on Debian-based systems. Action can be any available
  301. command in ``while true`` loop and ``case`` context.
  302. Following will disallow dpkg to stop/start services for the Cassandra
  303. package automatically:
  304. .. code-block:: yaml
  305. linux:
  306. system:
  307. policyrcd:
  308. - package: cassandra
  309. action: exit 101
  310. - package: '*'
  311. action: switch
  312. Set system locales:
  313. .. code-block:: yaml
  314. linux:
  315. system:
  316. locale:
  317. en_US.UTF-8:
  318. default: true
  319. "cs_CZ.UTF-8 UTF-8":
  320. enabled: true
  321. Systemd settings:
  322. .. code-block:: yaml
  323. linux:
  324. system:
  325. ...
  326. systemd:
  327. system:
  328. Manager:
  329. DefaultLimitNOFILE: 307200
  330. DefaultLimitNPROC: 307200
  331. user:
  332. Manager:
  333. DefaultLimitCPU: 2
  334. DefaultLimitNPROC: 4
  335. Ensure presence of directory:
  336. .. code-block:: yaml
  337. linux:
  338. system:
  339. directory:
  340. /tmp/test:
  341. user: root
  342. group: root
  343. mode: 700
  344. makedirs: true
  345. Ensure presence of file by specifying its source:
  346. .. code-block:: yaml
  347. linux:
  348. system:
  349. file:
  350. /tmp/test.txt:
  351. source: http://example.com/test.txt
  352. user: root #optional
  353. group: root #optional
  354. mode: 700 #optional
  355. dir_mode: 700 #optional
  356. encoding: utf-8 #optional
  357. hash: <<hash>> or <<URI to hash>> #optional
  358. makedirs: true #optional
  359. linux:
  360. system:
  361. file:
  362. test.txt:
  363. name: /tmp/test.txt
  364. source: http://example.com/test.txt
  365. Ensure presence of file by specifying its contents:
  366. .. code-block:: yaml
  367. linux:
  368. system:
  369. file:
  370. /tmp/test.txt:
  371. contents: |
  372. line1
  373. line2
  374. linux:
  375. system:
  376. file:
  377. /tmp/test.txt:
  378. contents_pillar: linux:network:hostname
  379. linux:
  380. system:
  381. file:
  382. /tmp/test.txt:
  383. contents_grains: motd
  384. Ensure presence of file to be serialized through one of the
  385. serializer modules (see:
  386. https://docs.saltstack.com/en/latest/ref/serializers/all/index.html):
  387. .. code-block:: yaml
  388. linux:
  389. system:
  390. file:
  391. /tmp/test.json:
  392. serialize: json
  393. contents:
  394. foo: 1
  395. bar: 'bar'
  396. Kernel
  397. ~~~~~~
  398. Install always up to date LTS kernel and headers from Ubuntu Trusty:
  399. .. code-block:: yaml
  400. linux:
  401. system:
  402. kernel:
  403. type: generic
  404. lts: trusty
  405. headers: true
  406. Load kernel modules and add them to ``/etc/modules``:
  407. .. code-block:: yaml
  408. linux:
  409. system:
  410. kernel:
  411. modules:
  412. - nf_conntrack
  413. - tp_smapi
  414. - 8021q
  415. Configure or blacklist kernel modules with additional options to
  416. ``/etc/modprobe.d`` following example will add
  417. ``/etc/modprobe.d/nf_conntrack.conf`` file with line
  418. ``options nf_conntrack hashsize=262144``:
  419. 'option' can be a mapping (with 'enabled' and 'value' keys) or a scalar.
  420. Example for 'scalar' option value:
  421. .. code-block:: yaml
  422. linux:
  423. system:
  424. kernel:
  425. module:
  426. nf_conntrack:
  427. option:
  428. hashsize: 262144
  429. Example for 'mapping' option value:
  430. .. code-block:: yaml
  431. linux:
  432. system:
  433. kernel:
  434. module:
  435. nf_conntrack:
  436. option:
  437. hashsize:
  438. enabled: true
  439. value: 262144
  440. NOTE: 'enabled' key is optional and is True by default.
  441. Blacklist a module:
  442. .. code-block:: yaml
  443. linux:
  444. system:
  445. kernel:
  446. module:
  447. nf_conntrack:
  448. blacklist: true
  449. A module can have a number of aliases, wildcards are allowed.
  450. Define an alias for a module:
  451. .. code-block:: yaml
  452. linux:
  453. system:
  454. kernel:
  455. module:
  456. nf_conntrack:
  457. alias:
  458. nfct:
  459. enabled: true
  460. "nf_conn*":
  461. enabled: true
  462. NOTE: 'enabled' key is mandatory as there are no other keys exist.
  463. Execute custom command instead of 'insmod' when inserting a module:
  464. .. code-block:: yaml
  465. linux:
  466. system:
  467. kernel:
  468. module:
  469. nf_conntrack:
  470. install:
  471. enabled: true
  472. command: /bin/true
  473. NOTE: 'enabled' key is optional and is True by default.
  474. Execute custom command instead of 'rmmod' when removing a module:
  475. .. code-block:: yaml
  476. linux:
  477. system:
  478. kernel:
  479. module:
  480. nf_conntrack:
  481. remove:
  482. enabled: true
  483. command: /bin/true
  484. NOTE: 'enabled' key is optional and is True by default.
  485. Define module dependencies:
  486. .. code-block:: yaml
  487. linux:
  488. system:
  489. kernel:
  490. module:
  491. nf_conntrack:
  492. softdep:
  493. pre:
  494. 1:
  495. enabled: true
  496. value: a
  497. 2:
  498. enabled: true
  499. value: b
  500. 3:
  501. enabled: true
  502. value: c
  503. post:
  504. 1:
  505. enabled: true
  506. value: x
  507. 2:
  508. enabled: true
  509. value: y
  510. 3:
  511. enabled: true
  512. value: z
  513. NOTE: 'enabled' key is optional and is True by default.
  514. Install specific kernel version and ensure all other kernel packages are
  515. not present. Also install extra modules and headers for this kernel:
  516. .. code-block:: yaml
  517. linux:
  518. system:
  519. kernel:
  520. type: generic
  521. extra: true
  522. headers: true
  523. version: 4.2.0-22
  524. Systcl kernel parameters:
  525. .. code-block:: yaml
  526. linux:
  527. system:
  528. kernel:
  529. sysctl:
  530. net.ipv4.tcp_keepalive_intvl: 3
  531. net.ipv4.tcp_keepalive_time: 30
  532. net.ipv4.tcp_keepalive_probes: 8
  533. Configure kernel boot options:
  534. .. code-block:: yaml
  535. linux:
  536. system:
  537. kernel:
  538. boot_options:
  539. - elevator=deadline
  540. - spectre_v2=off
  541. - nopti
  542. CPU
  543. ~~~
  544. Enable cpufreq governor for every cpu:
  545. .. code-block:: yaml
  546. linux:
  547. system:
  548. cpu:
  549. governor: performance
  550. CGROUPS
  551. ~~~~~~~
  552. Setup linux cgroups:
  553. .. code-block:: yaml
  554. linux:
  555. system:
  556. cgroup:
  557. enabled: true
  558. group:
  559. ceph_group_1:
  560. controller:
  561. cpu:
  562. shares:
  563. value: 250
  564. cpuacct:
  565. usage:
  566. value: 0
  567. cpuset:
  568. cpus:
  569. value: 1,2,3
  570. memory:
  571. limit_in_bytes:
  572. value: 2G
  573. memsw.limit_in_bytes:
  574. value: 3G
  575. mapping:
  576. subjects:
  577. - '@ceph'
  578. generic_group_1:
  579. controller:
  580. cpu:
  581. shares:
  582. value: 250
  583. cpuacct:
  584. usage:
  585. value: 0
  586. mapping:
  587. subjects:
  588. - '*:firefox'
  589. - 'student:cp'
  590. Shared libraries
  591. ~~~~~~~~~~~~~~~~
  592. Set additional shared library to Linux system library path:
  593. .. code-block:: yaml
  594. linux:
  595. system:
  596. ld:
  597. library:
  598. java:
  599. - /usr/lib/jvm/jre-openjdk/lib/amd64/server
  600. - /opt/java/jre/lib/amd64/server
  601. Certificates
  602. ~~~~~~~~~~~~
  603. Add certificate authority into system trusted CA bundle:
  604. .. code-block:: yaml
  605. linux:
  606. system:
  607. ca_certificates:
  608. mycert: |
  609. -----BEGIN CERTIFICATE-----
  610. MIICPDCCAaUCEHC65B0Q2Sk0tjjKewPMur8wDQYJKoZIhvcNAQECBQAwXzELMAkG
  611. A1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMTcwNQYDVQQLEy5DbGFz
  612. cyAzIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTk2
  613. MDEyOTAwMDAwMFoXDTI4MDgwMTIzNTk1OVowXzELMAkGA1UEBhMCVVMxFzAVBgNV
  614. BAoTDlZlcmlTaWduLCBJbmMuMTcwNQYDVQQLEy5DbGFzcyAzIFB1YmxpYyBQcmlt
  615. YXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIGfMA0GCSqGSIb3DQEBAQUAA4GN
  616. ADCBiQKBgQDJXFme8huKARS0EN8EQNvjV69qRUCPhAwL0TPZ2RHP7gJYHyX3KqhE
  617. BarsAx94f56TuZoAqiN91qyFomNFx3InzPRMxnVx0jnvT0Lwdd8KkMaOIG+YD/is
  618. I19wKTakyYbnsZogy1Olhec9vn2a/iRFM9x2Fe0PonFkTGUugWhFpwIDAQABMA0G
  619. CSqGSIb3DQEBAgUAA4GBALtMEivPLCYATxQT3ab7/AoRhIzzKBxnki98tsX63/Do
  620. lbwdj2wsqFHMc9ikwFPwTtYmwHYBV4GSXiHx0bH/59AhWM1pF+NEHJwZRDmJXNyc
  621. AA9WjQKZ7aKQRUzkuxCkPfAyAw7xzvjoyVGM5mKf5p/AfbdynMk2OmufTqj/ZA1k
  622. -----END CERTIFICATE-----
  623. Sysfs
  624. ~~~~~
  625. Install sysfsutils and set sysfs attributes:
  626. .. code-block:: yaml
  627. linux:
  628. system:
  629. sysfs:
  630. scheduler:
  631. block/sda/queue/scheduler: deadline
  632. power:
  633. mode:
  634. power/state: 0660
  635. owner:
  636. power/state: "root:power"
  637. devices/system/cpu/cpu0/cpufreq/scaling_governor: powersave
  638. Optional: You can also use list that will ensure order of items.
  639. .. code-block:: yaml
  640. linux:
  641. system:
  642. sysfs:
  643. scheduler:
  644. block/sda/queue/scheduler: deadline
  645. power:
  646. - mode:
  647. power/state: 0660
  648. - owner:
  649. power/state: "root:power"
  650. - devices/system/cpu/cpu0/cpufreq/scaling_governor: powersave
  651. Sysfs definition with disabled automatic write. Attributes are saved
  652. to configuration, but are not applied during the run.
  653. Thay will be applied automatically after the reboot.
  654. .. code-block:: yaml
  655. linux:
  656. system:
  657. sysfs:
  658. enable_apply: false
  659. scheduler:
  660. block/sda/queue/scheduler: deadline
  661. .. note:: The `enable_apply` parameter defaults to `True` if not defined.
  662. Huge Pages
  663. ~~~~~~~~~~~~
  664. Huge Pages give a performance boost to applications that intensively deal
  665. with memory allocation/deallocation by decreasing memory fragmentation:
  666. .. code-block:: yaml
  667. linux:
  668. system:
  669. kernel:
  670. hugepages:
  671. small:
  672. size: 2M
  673. count: 107520
  674. mount_point: /mnt/hugepages_2MB
  675. mount: false/true # default is true (mount immediately) / false (just save in the fstab)
  676. large:
  677. default: true # default automatically mounted
  678. size: 1G
  679. count: 210
  680. mount_point: /mnt/hugepages_1GB
  681. .. note:: Not recommended to use both pagesizes concurrently.
  682. Intel SR-IOV
  683. ~~~~~~~~~~~~
  684. PCI-SIG Single Root I/O Virtualization and Sharing (SR-IOV)
  685. specification defines a standardized mechanism to virtualize
  686. PCIe devices. The mechanism can virtualize a single PCIe
  687. Ethernet controller to appear as multiple PCIe devices:
  688. .. code-block:: yaml
  689. linux:
  690. system:
  691. kernel:
  692. sriov: True
  693. unsafe_interrupts: False # Default is false. for older platforms and AMD we need to add interrupt remapping workaround
  694. rc:
  695. local: |
  696. #!/bin/sh -e
  697. # Enable 7 VF on eth1
  698. echo 7 > /sys/class/net/eth1/device/sriov_numvfs; sleep 2; ifup -a
  699. exit 0
  700. Isolate CPU options
  701. ~~~~~~~~~~~~~~~~~~~
  702. Remove the specified CPUs, as defined by the cpu_number values, from
  703. the general kernel SMP balancing and scheduler algroithms. The only
  704. way to move a process onto or off an *isolated* CPU is via the CPU
  705. affinity syscalls. ``cpu_number begins`` at ``0``, so the
  706. maximum value is ``1`` less than the number of CPUs on the system.:
  707. .. code-block:: yaml
  708. linux:
  709. system:
  710. kernel:
  711. isolcpu: 1,2,3,4,5,6,7 # isolate first cpu 0
  712. Repositories
  713. ~~~~~~~~~~~~
  714. RedHat-based Linux with additional OpenStack repo:
  715. .. code-block:: yaml
  716. linux:
  717. system:
  718. ...
  719. repo:
  720. rdo-icehouse:
  721. enabled: true
  722. source: 'http://repos.fedorapeople.org/repos/openstack/openstack-icehouse/epel-6/'
  723. pgpcheck: 0
  724. Ensure system repository to use czech Debian mirror (``default: true``)
  725. Also pin it's packages with priority ``900``:
  726. .. code-block:: yaml
  727. linux:
  728. system:
  729. repo:
  730. debian:
  731. default: true
  732. source: "deb http://ftp.cz.debian.org/debian/ jessie main contrib non-free"
  733. # Import signing key from URL if needed
  734. key_url: "http://dummy.com/public.gpg"
  735. pin:
  736. - pin: 'origin "ftp.cz.debian.org"'
  737. priority: 900
  738. package: '*'
  739. If you need to add multiple pin rules for one repo, please use new,ordered definition format
  740. ('pinning' definition will be in priotity to use):
  741. .. code-block:: yaml
  742. linux:
  743. system:
  744. repo:
  745. mcp_saltstack:
  746. source: "deb [arch=amd64] http://repo.saltstack.com/apt/ubuntu/16.04/amd64/2017.7/ xenial main"
  747. architectures: amd64
  748. clean_file: true
  749. pinning:
  750. 10:
  751. enabled: true
  752. pin: 'release o=SaltStack'
  753. priority: 50
  754. package: 'libsodium18'
  755. 20:
  756. enabled: true
  757. pin: 'release o=SaltStack'
  758. priority: 1100
  759. package: '*'
  760. .. note:: For old Ubuntu releases (<xenial)
  761. extra packages for apt transport, like ``apt-transport-https``
  762. may be required to be installed manually.
  763. (Chicken-eggs issue: we need to install packages to
  764. reach repo from where they should be installed)
  765. Otherwise, you still can try 'fortune' and install prereq.packages before
  766. any repo configuration, using list of requires in map.jinja.
  767. Disabling any prerequisite packages installation:
  768. You can simply drop any package pre-installation (before system.linux.repo
  769. will be processed) via cluster lvl:
  770. .. code-block:: yaml
  771. linux:
  772. system:
  773. pkgs: ~
  774. Package manager proxy global setup:
  775. .. code-block:: yaml
  776. linux:
  777. system:
  778. ...
  779. repo:
  780. apt-mk:
  781. source: "deb http://apt-mk.mirantis.com/ stable main salt"
  782. ...
  783. proxy:
  784. pkg:
  785. enabled: true
  786. ftp: ftp://ftp-proxy-for-apt.host.local:2121
  787. ...
  788. # NOTE: Global defaults for any other componet that configure proxy on the system.
  789. # If your environment has just one simple proxy, set it on linux:system:proxy.
  790. #
  791. # fall back system defaults if linux:system:proxy:pkg has no protocol specific entries
  792. # as for https and http
  793. ftp: ftp://proxy.host.local:2121
  794. http: http://proxy.host.local:3142
  795. https: https://proxy.host.local:3143
  796. Package manager proxy setup per repository:
  797. .. code-block:: yaml
  798. linux:
  799. system:
  800. ...
  801. repo:
  802. debian:
  803. source: "deb http://apt-mk.mirantis.com/ stable main salt"
  804. ...
  805. apt-mk:
  806. source: "deb http://apt-mk.mirantis.com/ stable main salt"
  807. # per repository proxy
  808. proxy:
  809. enabled: true
  810. http: http://maas-01:8080
  811. https: http://maas-01:8080
  812. ...
  813. proxy:
  814. # package manager fallback defaults
  815. # used if linux:system:repo:apt-mk:proxy has no protocol specific entries
  816. pkg:
  817. enabled: true
  818. ftp: ftp://proxy.host.local:2121
  819. #http: http://proxy.host.local:3142
  820. #https: https://proxy.host.local:3143
  821. ...
  822. # global system fallback system defaults
  823. ftp: ftp://proxy.host.local:2121
  824. http: http://proxy.host.local:3142
  825. https: https://proxy.host.local:3143
  826. Remove all repositories:
  827. .. code-block:: yaml
  828. linux:
  829. system:
  830. purge_repos: true
  831. Refresh repositories metada, after configuration:
  832. .. code-block:: yaml
  833. linux:
  834. system:
  835. refresh_repos_meta: true
  836. Setup custom apt config options:
  837. .. code-block:: yaml
  838. linux:
  839. system:
  840. apt:
  841. config:
  842. compression-workaround:
  843. "Acquire::CompressionTypes::Order": "gz"
  844. docker-clean:
  845. "DPkg::Post-Invoke":
  846. - "rm -f /var/cache/apt/archives/*.deb /var/cache/apt/archives/partial/*.deb /var/cache/apt/*.bin || true"
  847. "APT::Update::Post-Invoke":
  848. - "rm -f /var/cache/apt/archives/*.deb /var/cache/apt/archives/partial/*.deb /var/cache/apt/*.bin || true"
  849. RC
  850. ~~
  851. rc.local example
  852. .. code-block:: yaml
  853. linux:
  854. system:
  855. rc:
  856. local: |
  857. #!/bin/sh -e
  858. #
  859. # rc.local
  860. #
  861. # This script is executed at the end of each multiuser runlevel.
  862. # Make sure that the script will "exit 0" on success or any other
  863. # value on error.
  864. #
  865. # In order to enable or disable this script just change the execution
  866. # bits.
  867. #
  868. # By default this script does nothing.
  869. exit 0
  870. Prompt
  871. ~~~~~~
  872. Setting prompt is implemented by creating ``/etc/profile.d/prompt.sh``.
  873. Every user can have different prompt:
  874. .. code-block:: yaml
  875. linux:
  876. system:
  877. prompt:
  878. root: \\n\\[\\033[0;37m\\]\\D{%y/%m/%d %H:%M:%S} $(hostname -f)\\[\\e[0m\\]\\n\\[\\e[1;31m\\][\\u@\\h:\\w]\\[\\e[0m\\]
  879. default: \\n\\D{%y/%m/%d %H:%M:%S} $(hostname -f)\\n[\\u@\\h:\\w]
  880. On Debian systems, to set prompt system-wide, it's necessary to
  881. remove setting PS1 in ``/etc/bash.bashrc`` and ``~/.bashrc``,
  882. which comes from ``/etc/skel/.bashrc``. This formula will do
  883. this automatically, but will not touch existing user's
  884. ``~/.bashrc`` files except root.
  885. Bash
  886. ~~~~
  887. Fix bash configuration to preserve history across sessions
  888. like ZSH does by default:
  889. .. code-block:: yaml
  890. linux:
  891. system:
  892. bash:
  893. preserve_history: true
  894. Login banner message
  895. ~~~~~~~~~~~~~~~~~~~~
  896. ``/etc/issue`` is a text file which contains a message or system
  897. identification to be printed before the login prompt. It may contain
  898. various @char and \char sequences, if supported by the getty-type
  899. program employed on the system.
  900. Setting logon banner message is easy:
  901. .. code-block:: yaml
  902. liunx:
  903. system:
  904. banner:
  905. enabled: true
  906. contents: |
  907. UNAUTHORIZED ACCESS TO THIS SYSTEM IS PROHIBITED
  908. You must have explicit, authorized permission to access or configure this
  909. device. Unauthorized attempts and actions to access or use this system may
  910. result in civil and/or criminal penalties.
  911. All activities performed on this system are logged and monitored.
  912. Message of the day
  913. ~~~~~~~~~~~~~~~~~~
  914. ``pam_motd`` from package ``libpam-modules`` is used for dynamic
  915. messages of the day. Setting custom ``motd`` will clean up existing ones.
  916. Setting static ``motd`` will replace existing ``/etc/motd`` and remove
  917. scripts from ``/etc/update-motd.d``.
  918. Setting static ``motd``:
  919. .. code-block:: yaml
  920. linux:
  921. system:
  922. motd: |
  923. UNAUTHORIZED ACCESS TO THIS SYSTEM IS PROHIBITED
  924. You must have explicit, authorized permission to access or configure this
  925. device. Unauthorized attempts and actions to access or use this system may
  926. result in civil and/or criminal penalties.
  927. All activities performed on this system are logged and monitored.
  928. Setting dynamic ``motd``:
  929. .. code-block:: yaml
  930. linux:
  931. system:
  932. motd:
  933. - release: |
  934. #!/bin/sh
  935. [ -r /etc/lsb-release ] && . /etc/lsb-release
  936. if [ -z "$DISTRIB_DESCRIPTION" ] && [ -x /usr/bin/lsb_release ]; then
  937. # Fall back to using the very slow lsb_release utility
  938. DISTRIB_DESCRIPTION=$(lsb_release -s -d)
  939. fi
  940. printf "Welcome to %s (%s %s %s)\n" "$DISTRIB_DESCRIPTION" "$(uname -o)" "$(uname -r)" "$(uname -m)"
  941. - warning: |
  942. #!/bin/sh
  943. printf "This is [company name] network.\n"
  944. printf "Unauthorized access strictly prohibited.\n"
  945. Services
  946. ~~~~~~~~
  947. Stop and disable the ``linux`` service:
  948. .. code-block:: yaml
  949. linux:
  950. system:
  951. service:
  952. apt-daily.timer:
  953. status: dead
  954. Possible statuses are ``dead`` (disable service by default), ``running``
  955. (enable service by default), ``enabled``, ``disabled``:
  956. Linux with the ``atop`` service:
  957. .. code-block:: yaml
  958. linux:
  959. system:
  960. atop:
  961. enabled: true
  962. interval: 20
  963. logpath: "/var/log/atop"
  964. outfile: "/var/log/atop/daily.log"
  965. Linux with the ``mcelog`` service:
  966. .. code-block:: yaml
  967. linux:
  968. system:
  969. mcelog:
  970. enabled: true
  971. logging:
  972. syslog: true
  973. syslog_error: true
  974. RHEL / CentOS
  975. ^^^^^^^^^^^^^
  976. Currently, ``update-motd`` is not available
  977. for RHEL. So there is no native support for dynamic ``motd``.
  978. You can still set a static one, with a different pillar structure:
  979. .. code-block:: yaml
  980. linux:
  981. system:
  982. motd: |
  983. This is [company name] network.
  984. Unauthorized access strictly prohibited.
  985. Haveged
  986. ~~~~~~~
  987. If you are running headless server and are low on entropy,
  988. you may set up Haveged:
  989. .. code-block:: yaml
  990. linux:
  991. system:
  992. haveged:
  993. enabled: true
  994. Linux network
  995. -------------
  996. Linux with network manager:
  997. .. code-block:: yaml
  998. linux:
  999. network:
  1000. enabled: true
  1001. network_manager: true
  1002. Linux with default static network interfaces, default gateway
  1003. interface and DNS servers:
  1004. .. code-block:: yaml
  1005. linux:
  1006. network:
  1007. enabled: true
  1008. interface:
  1009. eth0:
  1010. enabled: true
  1011. type: eth
  1012. address: 192.168.0.102
  1013. netmask: 255.255.255.0
  1014. gateway: 192.168.0.1
  1015. name_servers:
  1016. - 8.8.8.8
  1017. - 8.8.4.4
  1018. mtu: 1500
  1019. Linux with bonded interfaces and disabled ``NetworkManager``:
  1020. .. code-block:: yaml
  1021. linux:
  1022. network:
  1023. enabled: true
  1024. interface:
  1025. eth0:
  1026. type: eth
  1027. ...
  1028. eth1:
  1029. type: eth
  1030. ...
  1031. bond0:
  1032. enabled: true
  1033. type: bond
  1034. address: 192.168.0.102
  1035. netmask: 255.255.255.0
  1036. mtu: 1500
  1037. use_in:
  1038. - interface: ${linux:interface:eth0}
  1039. - interface: ${linux:interface:eth0}
  1040. network_manager:
  1041. disable: true
  1042. Linux with VLAN ``interface_params``:
  1043. .. code-block:: yaml
  1044. linux:
  1045. network:
  1046. enabled: true
  1047. interface:
  1048. vlan69:
  1049. type: vlan
  1050. use_interfaces:
  1051. - interface: ${linux:interface:bond0}
  1052. Linux with wireless interface parameters:
  1053. .. code-block:: yaml
  1054. linux:
  1055. network:
  1056. enabled: true
  1057. gateway: 10.0.0.1
  1058. default_interface: eth0
  1059. interface:
  1060. wlan0:
  1061. type: eth
  1062. wireless:
  1063. essid: example
  1064. key: example_key
  1065. security: wpa
  1066. priority: 1
  1067. Linux networks with routes defined:
  1068. .. code-block:: yaml
  1069. linux:
  1070. network:
  1071. enabled: true
  1072. gateway: 10.0.0.1
  1073. default_interface: eth0
  1074. interface:
  1075. eth0:
  1076. type: eth
  1077. route:
  1078. default:
  1079. address: 192.168.0.123
  1080. netmask: 255.255.255.0
  1081. gateway: 192.168.0.1
  1082. Native Linux Bridges:
  1083. .. code-block:: yaml
  1084. linux:
  1085. network:
  1086. interface:
  1087. eth1:
  1088. enabled: true
  1089. type: eth
  1090. proto: manual
  1091. up_cmds:
  1092. - ip address add 0/0 dev $IFACE
  1093. - ip link set $IFACE up
  1094. down_cmds:
  1095. - ip link set $IFACE down
  1096. br-ex:
  1097. enabled: true
  1098. type: bridge
  1099. address: ${linux:network:host:public_local:address}
  1100. netmask: 255.255.255.0
  1101. use_interfaces:
  1102. - eth1
  1103. Open vSwitch Bridges:
  1104. .. code-block:: yaml
  1105. linux:
  1106. network:
  1107. bridge: openvswitch
  1108. interface:
  1109. eth1:
  1110. enabled: true
  1111. type: eth
  1112. proto: manual
  1113. up_cmds:
  1114. - ip address add 0/0 dev $IFACE
  1115. - ip link set $IFACE up
  1116. down_cmds:
  1117. - ip link set $IFACE down
  1118. br-ex:
  1119. enabled: true
  1120. type: bridge
  1121. address: ${linux:network:host:public_local:address}
  1122. netmask: 255.255.255.0
  1123. use_interfaces:
  1124. - eth1
  1125. br-prv:
  1126. enabled: true
  1127. type: ovs_bridge
  1128. mtu: 65000
  1129. br-ens7:
  1130. enabled: true
  1131. name: br-ens7
  1132. type: ovs_bridge
  1133. proto: manual
  1134. mtu: 9000
  1135. use_interfaces:
  1136. - ens7
  1137. patch-br-ens7-br-prv:
  1138. enabled: true
  1139. name: ens7-prv
  1140. ovs_type: ovs_port
  1141. type: ovs_port
  1142. bridge: br-ens7
  1143. port_type: patch
  1144. peer: prv-ens7
  1145. tag: 109 # [] to unset a tag
  1146. mtu: 65000
  1147. patch-br-prv-br-ens7:
  1148. enabled: true
  1149. name: prv-ens7
  1150. bridge: br-prv
  1151. ovs_type: ovs_port
  1152. type: ovs_port
  1153. port_type: patch
  1154. peer: ens7-prv
  1155. tag: 109
  1156. mtu: 65000
  1157. ens7:
  1158. enabled: true
  1159. name: ens7
  1160. proto: manual
  1161. ovs_port_type: OVSPort
  1162. type: ovs_port
  1163. ovs_bridge: br-ens7
  1164. bridge: br-ens7
  1165. Debian manual proto interfaces
  1166. When you are changing interface proto from static in up state
  1167. to manual, you may need to flush ip addresses. For example,
  1168. if you want to use the interface and the ip on the bridge.
  1169. This can be done by setting the ``ipflush_onchange`` to true.
  1170. .. code-block:: yaml
  1171. linux:
  1172. network:
  1173. interface:
  1174. eth1:
  1175. enabled: true
  1176. type: eth
  1177. proto: manual
  1178. mtu: 9100
  1179. ipflush_onchange: true
  1180. Debian static proto interfaces
  1181. When you are changing interface proto from dhcp in up state to
  1182. static, you may need to flush ip addresses and restart interface
  1183. to assign ip address from a managed file. For example, if you wantto
  1184. use the interface and the ip on the bridge. This can be done by
  1185. setting the ``ipflush_onchange`` with combination ``restart_on_ipflush``
  1186. param set to true.
  1187. .. code-block:: yaml
  1188. linux:
  1189. network:
  1190. interface:
  1191. eth1:
  1192. enabled: true
  1193. type: eth
  1194. proto: static
  1195. address: 10.1.0.22
  1196. netmask: 255.255.255.0
  1197. ipflush_onchange: true
  1198. restart_on_ipflush: true
  1199. Concatinating and removing interface files
  1200. Debian based distributions have ``/etc/network/interfaces.d/``
  1201. directory, where you can store configuration of network
  1202. interfaces in separate files. You can concatinate the files
  1203. to the defined destination when needed, this operation removes
  1204. the file from the ``/etc/network/interfaces.d/``. If you just need
  1205. to remove iface files, you can use the ``remove_iface_files`` key.
  1206. .. code-block:: yaml
  1207. linux:
  1208. network:
  1209. concat_iface_files:
  1210. - src: '/etc/network/interfaces.d/50-cloud-init.cfg'
  1211. dst: '/etc/network/interfaces'
  1212. remove_iface_files:
  1213. - '/etc/network/interfaces.d/90-custom.cfg'
  1214. Configure DHCP client
  1215. None of the keys is mandatory, include only those you really need.
  1216. For full list of available options under send, supersede, prepend,
  1217. append refer to dhcp-options(5).
  1218. .. code-block:: yaml
  1219. linux:
  1220. network:
  1221. dhclient:
  1222. enabled: true
  1223. backoff_cutoff: 15
  1224. initial_interval: 10
  1225. reboot: 10
  1226. retry: 60
  1227. select_timeout: 0
  1228. timeout: 120
  1229. send:
  1230. - option: host-name
  1231. declaration: "= gethostname()"
  1232. supersede:
  1233. - option: host-name
  1234. declaration: "spaceship"
  1235. - option: domain-name
  1236. declaration: "domain.home"
  1237. #- option: arp-cache-timeout
  1238. # declaration: 20
  1239. prepend:
  1240. - option: domain-name-servers
  1241. declaration:
  1242. - 8.8.8.8
  1243. - 8.8.4.4
  1244. - option: domain-search
  1245. declaration:
  1246. - example.com
  1247. - eng.example.com
  1248. #append:
  1249. #- option: domain-name-servers
  1250. # declaration: 127.0.0.1
  1251. # ip or subnet to reject dhcp offer from
  1252. reject:
  1253. - 192.33.137.209
  1254. - 10.0.2.0/24
  1255. request:
  1256. - subnet-mask
  1257. - broadcast-address
  1258. - time-offset
  1259. - routers
  1260. - domain-name
  1261. - domain-name-servers
  1262. - domain-search
  1263. - host-name
  1264. - dhcp6.name-servers
  1265. - dhcp6.domain-search
  1266. - dhcp6.fqdn
  1267. - dhcp6.sntp-servers
  1268. - netbios-name-servers
  1269. - netbios-scope
  1270. - interface-mtu
  1271. - rfc3442-classless-static-routes
  1272. - ntp-servers
  1273. require:
  1274. - subnet-mask
  1275. - domain-name-servers
  1276. # if per interface configuration required add below
  1277. interface:
  1278. ens2:
  1279. initial_interval: 11
  1280. reject:
  1281. - 192.33.137.210
  1282. ens3:
  1283. initial_interval: 12
  1284. reject:
  1285. - 192.33.137.211
  1286. Linux network systemd settings:
  1287. .. code-block:: yaml
  1288. linux:
  1289. network:
  1290. ...
  1291. systemd:
  1292. link:
  1293. 10-iface-dmz:
  1294. Match:
  1295. MACAddress: c8:5b:67:fa:1a:af
  1296. OriginalName: eth0
  1297. Link:
  1298. Name: dmz0
  1299. netdev:
  1300. 20-bridge-dmz:
  1301. match:
  1302. name: dmz0
  1303. network:
  1304. mescription: bridge
  1305. bridge: br-dmz0
  1306. network:
  1307. # works with lowercase, keys are by default capitalized
  1308. 40-dhcp:
  1309. match:
  1310. name: '*'
  1311. network:
  1312. DHCP: yes
  1313. Configure global environment variables
  1314. Use ``/etc/environment`` for static system wide variable assignment
  1315. after boot. Variable expansion is frequently not supported.
  1316. .. code-block:: yaml
  1317. linux:
  1318. system:
  1319. env:
  1320. BOB_VARIABLE: Alice
  1321. ...
  1322. BOB_PATH:
  1323. - /srv/alice/bin
  1324. - /srv/bob/bin
  1325. ...
  1326. ftp_proxy: none
  1327. http_proxy: http://global-http-proxy.host.local:8080
  1328. https_proxy: ${linux:system:proxy:https}
  1329. no_proxy:
  1330. - 192.168.0.80
  1331. - 192.168.1.80
  1332. - .domain.com
  1333. - .local
  1334. ...
  1335. # NOTE: global defaults proxy configuration.
  1336. proxy:
  1337. ftp: ftp://proxy.host.local:2121
  1338. http: http://proxy.host.local:3142
  1339. https: https://proxy.host.local:3143
  1340. noproxy:
  1341. - .domain.com
  1342. - .local
  1343. Configure the ``profile.d`` scripts
  1344. The ``profile.d`` scripts are being sourced during ``.sh`` execution
  1345. and support variable expansion in opposite to /etc/environment global
  1346. settings in ``/etc/environment``.
  1347. .. code-block:: yaml
  1348. linux:
  1349. system:
  1350. profile:
  1351. locales: |
  1352. export LANG=C
  1353. export LC_ALL=C
  1354. ...
  1355. vi_flavors.sh: |
  1356. export PAGER=view
  1357. export EDITOR=vim
  1358. alias vi=vim
  1359. shell_locales.sh: |
  1360. export LANG=en_US
  1361. export LC_ALL=en_US.UTF-8
  1362. shell_proxies.sh: |
  1363. export FTP_PROXY=ftp://127.0.3.3:2121
  1364. export NO_PROXY='.local'
  1365. Configure login.defs parameters
  1366. -------------------------------
  1367. .. code-block:: yaml
  1368. linux:
  1369. system:
  1370. login_defs:
  1371. <opt_name>:
  1372. enabled: true
  1373. value: <opt_value>
  1374. <opt_name> is a configurational option defined in 'man login.defs'.
  1375. <opt_name> is case sensitive, should be UPPERCASE only!
  1376. Linux with hosts
  1377. Parameter ``purge_hosts`` will enforce whole ``/etc/hosts file``,
  1378. removing entries that are not defined in model except defaults
  1379. for both IPv4 and IPv6 localhost and hostname as well as FQDN.
  1380. We recommend using this option to verify that ``/etc/hosts``
  1381. is always in a clean state. However it is not enabled by default
  1382. for security reasons.
  1383. .. code-block:: yaml
  1384. linux:
  1385. network:
  1386. purge_hosts: true
  1387. host:
  1388. # No need to define this one if purge_hosts is true
  1389. hostname:
  1390. address: 127.0.1.1
  1391. names:
  1392. - ${linux:network:fqdn}
  1393. - ${linux:network:hostname}
  1394. node1:
  1395. address: 192.168.10.200
  1396. names:
  1397. - node2.domain.com
  1398. - service2.domain.com
  1399. node2:
  1400. address: 192.168.10.201
  1401. names:
  1402. - node2.domain.com
  1403. - service2.domain.com
  1404. Linux with hosts collected from mine
  1405. All DNS records defined within infrastrucuture
  1406. are passed to the local hosts records or any DNS server. Only
  1407. hosts with the ``grain`` parameter set to ``true`` will be propagated
  1408. to the mine.
  1409. .. code-block:: yaml
  1410. linux:
  1411. network:
  1412. purge_hosts: true
  1413. mine_dns_records: true
  1414. host:
  1415. node1:
  1416. address: 192.168.10.200
  1417. grain: true
  1418. names:
  1419. - node2.domain.com
  1420. - service2.domain.com
  1421. Set up ``resolv.conf``, nameservers, domain and search domains:
  1422. .. code-block:: yaml
  1423. linux:
  1424. network:
  1425. resolv:
  1426. dns:
  1427. - 8.8.4.4
  1428. - 8.8.8.8
  1429. domain: my.example.com
  1430. search:
  1431. - my.example.com
  1432. - example.com
  1433. options:
  1434. - ndots: 5
  1435. - timeout: 2
  1436. - attempts: 2
  1437. Set up custom TX queue length for tap interfaces:
  1438. .. code-block:: yaml
  1439. linux:
  1440. network:
  1441. tap_custom_txqueuelen: 10000
  1442. DPDK OVS interfaces
  1443. **DPDK OVS NIC**
  1444. .. code-block:: yaml
  1445. linux:
  1446. network:
  1447. bridge: openvswitch
  1448. dpdk:
  1449. enabled: true
  1450. driver: uio/vfio
  1451. openvswitch:
  1452. pmd_cpu_mask: "0x6"
  1453. dpdk_socket_mem: "1024,1024"
  1454. dpdk_lcore_mask: "0x400"
  1455. memory_channels: 2
  1456. interface:
  1457. dpkd0:
  1458. name: ${_param:dpdk_nic}
  1459. pci: 0000:06:00.0
  1460. driver: igb_uio/vfio-pci
  1461. enabled: true
  1462. type: dpdk_ovs_port
  1463. n_rxq: 2
  1464. pmd_rxq_affinity: "0:1,1:2"
  1465. bridge: br-prv
  1466. mtu: 9000
  1467. br-prv:
  1468. enabled: true
  1469. type: dpdk_ovs_bridge
  1470. **DPDK OVS Bond**
  1471. .. code-block:: yaml
  1472. linux:
  1473. network:
  1474. bridge: openvswitch
  1475. dpdk:
  1476. enabled: true
  1477. driver: uio/vfio
  1478. openvswitch:
  1479. pmd_cpu_mask: "0x6"
  1480. dpdk_socket_mem: "1024,1024"
  1481. dpdk_lcore_mask: "0x400"
  1482. memory_channels: 2
  1483. interface:
  1484. dpdk_second_nic:
  1485. name: ${_param:primary_second_nic}
  1486. pci: 0000:06:00.0
  1487. driver: igb_uio/vfio-pci
  1488. bond: dpdkbond0
  1489. enabled: true
  1490. type: dpdk_ovs_port
  1491. n_rxq: 2
  1492. pmd_rxq_affinity: "0:1,1:2"
  1493. mtu: 9000
  1494. dpdk_first_nic:
  1495. name: ${_param:primary_first_nic}
  1496. pci: 0000:05:00.0
  1497. driver: igb_uio/vfio-pci
  1498. bond: dpdkbond0
  1499. enabled: true
  1500. type: dpdk_ovs_port
  1501. n_rxq: 2
  1502. pmd_rxq_affinity: "0:1,1:2"
  1503. mtu: 9000
  1504. dpdkbond0:
  1505. enabled: true
  1506. bridge: br-prv
  1507. type: dpdk_ovs_bond
  1508. mode: active-backup
  1509. br-prv:
  1510. enabled: true
  1511. type: dpdk_ovs_bridge
  1512. **DPDK OVS LACP Bond with vlan tag**
  1513. .. code-block:: yaml
  1514. linux:
  1515. network:
  1516. bridge: openvswitch
  1517. dpdk:
  1518. enabled: true
  1519. driver: uio
  1520. openvswitch:
  1521. pmd_cpu_mask: "0x6"
  1522. dpdk_socket_mem: "1024,1024"
  1523. dpdk_lcore_mask: "0x400"
  1524. memory_channels: "2"
  1525. interface:
  1526. eth3:
  1527. enabled: true
  1528. type: eth
  1529. proto: manual
  1530. name: ${_param:tenant_first_nic}
  1531. eth4:
  1532. enabled: true
  1533. type: eth
  1534. proto: manual
  1535. name: ${_param:tenant_second_nic}
  1536. dpdk0:
  1537. name: ${_param:tenant_first_nic}
  1538. pci: "0000:81:00.0"
  1539. driver: igb_uio
  1540. bond: bond1
  1541. enabled: true
  1542. type: dpdk_ovs_port
  1543. n_rxq: 2
  1544. dpdk1:
  1545. name: ${_param:tenant_second_nic}
  1546. pci: "0000:81:00.1"
  1547. driver: igb_uio
  1548. bond: bond1
  1549. enabled: true
  1550. type: dpdk_ovs_port
  1551. n_rxq: 2
  1552. bond1:
  1553. enabled: true
  1554. bridge: br-prv
  1555. type: dpdk_ovs_bond
  1556. mode: balance-slb
  1557. br-prv:
  1558. enabled: true
  1559. type: dpdk_ovs_bridge
  1560. tag: ${_param:tenant_vlan}
  1561. address: ${_param:tenant_address}
  1562. netmask: ${_param:tenant_network_netmask}
  1563. **DPDK OVS bridge for VXLAN**
  1564. If VXLAN is used as tenant segmentation, IP address must
  1565. be set on ``br-prv``.
  1566. .. code-block:: yaml
  1567. linux:
  1568. network:
  1569. ...
  1570. interface:
  1571. br-prv:
  1572. enabled: true
  1573. type: dpdk_ovs_bridge
  1574. address: 192.168.50.0
  1575. netmask: 255.255.255.0
  1576. tag: 101
  1577. mtu: 9000
  1578. **DPDK OVS bridge with Linux network interface**
  1579. .. code-block:: yaml
  1580. linux:
  1581. network:
  1582. ...
  1583. interface:
  1584. eth0:
  1585. type: eth
  1586. ovs_bridge: br-prv
  1587. ...
  1588. br-prv:
  1589. enabled: true
  1590. type: dpdk_ovs_bridge
  1591. ...
  1592. Linux storage
  1593. -------------
  1594. Linux with mounted Samba:
  1595. .. code-block:: yaml
  1596. linux:
  1597. storage:
  1598. enabled: true
  1599. mount:
  1600. samba1:
  1601. - enabled: true
  1602. - path: /media/myuser/public/
  1603. - device: //192.168.0.1/storage
  1604. - file_system: cifs
  1605. - options: guest,uid=myuser,iocharset=utf8,file_mode=0777,dir_mode=0777,noperm
  1606. NFS mount:
  1607. .. code-block:: yaml
  1608. linux:
  1609. storage:
  1610. enabled: true
  1611. mount:
  1612. nfs_glance:
  1613. enabled: true
  1614. path: /var/lib/glance/images
  1615. device: 172.16.10.110:/var/nfs/glance
  1616. file_system: nfs
  1617. opts: rw,sync
  1618. File swap configuration:
  1619. .. code-block:: yaml
  1620. linux:
  1621. storage:
  1622. enabled: true
  1623. swap:
  1624. file:
  1625. enabled: true
  1626. engine: file
  1627. device: /swapfile
  1628. size: 1024
  1629. Partition swap configuration:
  1630. .. code-block:: yaml
  1631. linux:
  1632. storage:
  1633. enabled: true
  1634. swap:
  1635. partition:
  1636. enabled: true
  1637. engine: partition
  1638. device: /dev/vg0/swap
  1639. LVM group ``vg1`` with one device and ``data`` volume mounted
  1640. into ``/mnt/data``.
  1641. .. code-block:: yaml
  1642. parameters:
  1643. linux:
  1644. storage:
  1645. mount:
  1646. data:
  1647. enabled: true
  1648. device: /dev/vg1/data
  1649. file_system: ext4
  1650. path: /mnt/data
  1651. lvm:
  1652. vg1:
  1653. enabled: true
  1654. devices:
  1655. - /dev/sdb
  1656. volume:
  1657. data:
  1658. size: 40G
  1659. mount: ${linux:storage:mount:data}
  1660. Create partitions on disk. Specify size in MB. It expects empty
  1661. disk without any existing partitions.
  1662. Set ``startsector=1`` if you want to start partitions from ``2048``.
  1663. .. code-block:: yaml
  1664. linux:
  1665. storage:
  1666. disk:
  1667. first_drive:
  1668. startsector: 1
  1669. name: /dev/loop1
  1670. type: gpt
  1671. partitions:
  1672. - size: 200 #size in MB
  1673. type: fat32
  1674. - size: 300 #size in MB
  1675. mkfs: True
  1676. type: xfs
  1677. /dev/vda1:
  1678. partitions:
  1679. - size: 5
  1680. type: ext2
  1681. - size: 10
  1682. type: ext4
  1683. Multipath with Fujitsu Eternus DXL:
  1684. .. code-block:: yaml
  1685. parameters:
  1686. linux:
  1687. storage:
  1688. multipath:
  1689. enabled: true
  1690. blacklist_devices:
  1691. - /dev/sda
  1692. - /dev/sdb
  1693. backends:
  1694. - fujitsu_eternus_dxl
  1695. Multipath with Hitachi VSP 1000:
  1696. .. code-block:: yaml
  1697. parameters:
  1698. linux:
  1699. storage:
  1700. multipath:
  1701. enabled: true
  1702. blacklist_devices:
  1703. - /dev/sda
  1704. - /dev/sdb
  1705. backends:
  1706. - hitachi_vsp1000
  1707. Multipath with IBM Storwize:
  1708. .. code-block:: yaml
  1709. parameters:
  1710. linux:
  1711. storage:
  1712. multipath:
  1713. enabled: true
  1714. blacklist_devices:
  1715. - /dev/sda
  1716. - /dev/sdb
  1717. backends:
  1718. - ibm_storwize
  1719. Multipath with multiple backends:
  1720. .. code-block:: yaml
  1721. parameters:
  1722. linux:
  1723. storage:
  1724. multipath:
  1725. enabled: true
  1726. blacklist_devices:
  1727. - /dev/sda
  1728. - /dev/sdb
  1729. - /dev/sdc
  1730. - /dev/sdd
  1731. backends:
  1732. - ibm_storwize
  1733. - fujitsu_eternus_dxl
  1734. - hitachi_vsp1000
  1735. PAM LDAP integration:
  1736. .. code-block:: yaml
  1737. parameters:
  1738. linux:
  1739. system:
  1740. auth:
  1741. enabled: true
  1742. mkhomedir:
  1743. enabled: true
  1744. umask: 0027
  1745. ldap:
  1746. enabled: true
  1747. binddn: cn=bind,ou=service_users,dc=example,dc=com
  1748. bindpw: secret
  1749. uri: ldap://127.0.0.1
  1750. base: ou=users,dc=example,dc=com
  1751. ldap_version: 3
  1752. pagesize: 65536
  1753. referrals: off
  1754. filter:
  1755. passwd: (&(&(objectClass=person)(uidNumber=*))(unixHomeDirectory=*))
  1756. shadow: (&(&(objectClass=person)(uidNumber=*))(unixHomeDirectory=*))
  1757. group: (&(objectClass=group)(gidNumber=*))
  1758. Disabled multipath (the default setup):
  1759. .. code-block:: yaml
  1760. parameters:
  1761. linux:
  1762. storage:
  1763. multipath:
  1764. enabled: false
  1765. Linux with local loopback device:
  1766. .. code-block:: yaml
  1767. linux:
  1768. storage:
  1769. loopback:
  1770. disk1:
  1771. file: /srv/disk1
  1772. size: 50G
  1773. External config generation
  1774. --------------------------
  1775. You are able to use config support metadata between formulas
  1776. and only generate configuration files for external use, for example, Docker, and so on.
  1777. .. code-block:: yaml
  1778. parameters:
  1779. linux:
  1780. system:
  1781. config:
  1782. pillar:
  1783. jenkins:
  1784. master:
  1785. home: /srv/volumes/jenkins
  1786. approved_scripts:
  1787. - method java.net.URL openConnection
  1788. credentials:
  1789. - type: username_password
  1790. scope: global
  1791. id: test
  1792. desc: Testing credentials
  1793. username: test
  1794. password: test
  1795. Netconsole Remote Kernel Logging
  1796. --------------------------------
  1797. Netconsole logger can be configured for the configfs-enabled kernels
  1798. (``CONFIG_NETCONSOLE_DYNAMIC`` must be enabled). The configuration
  1799. applies both in runtime (if network is already configured),
  1800. and on-boot after an interface initialization.
  1801. .. note::
  1802. * Receiver can be located only on the same L3 domain
  1803. (or you need to configure gateway MAC manually).
  1804. * The Receiver MAC is detected only on configuration time.
  1805. * Using broadcast MAC is not recommended.
  1806. .. code-block:: yaml
  1807. parameters:
  1808. linux:
  1809. system:
  1810. netconsole:
  1811. enabled: true
  1812. port: 514 (optional)
  1813. loglevel: debug (optional)
  1814. target:
  1815. 192.168.0.1:
  1816. interface: bond0
  1817. mac: "ff:ff:ff:ff:ff:ff" (optional)
  1818. Usage
  1819. =====
  1820. Set MTU of the eth0 network interface to 1400:
  1821. .. code-block:: bash
  1822. ip link set dev eth0 mtu 1400
  1823. Read more
  1824. =========
  1825. * https://www.archlinux.org/
  1826. * http://askubuntu.com/questions/175172/how-do-i-configure-proxies-in-ubuntu-server-or-minimal-cli-ubuntu
  1827. Documentation and Bugs
  1828. ======================
  1829. * http://salt-formulas.readthedocs.io/
  1830. Learn how to install and update salt-formulas.
  1831. * https://github.com/salt-formulas/salt-formula-linux/issues
  1832. In the unfortunate event that bugs are discovered, report the issue to the
  1833. appropriate issue tracker. Use the Github issue tracker for a specific salt
  1834. formula.
  1835. * https://launchpad.net/salt-formulas
  1836. For feature requests, bug reports, or blueprints affecting the entire
  1837. ecosystem, use the Launchpad salt-formulas project.
  1838. * https://launchpad.net/~salt-formulas-users
  1839. Join the salt-formulas-users team and subscribe to mailing list if required.
  1840. * https://github.com/salt-formulas/salt-formula-linux
  1841. Develop the salt-formulas projects in the master branch and then submit pull
  1842. requests against a specific formula.
  1843. * #salt-formulas @ irc.freenode.net
  1844. Use this IRC channel in case of any questions or feedback which is always
  1845. welcome.