============ Linux Fomula ============ Linux Operating Systems: * Ubuntu * CentOS * RedHat * Fedora * Arch Sample Pillars ============== Linux System ------------ Basic Linux box .. code-block:: yaml linux: system: enabled: true name: 'node1' domain: 'domain.com' cluster: 'system' environment: prod timezone: 'Europe/Prague' utc: true Linux with system users, some with password set: .. warning:: If no ``password`` variable is passed, any predifined password will be removed. .. code-block:: yaml linux: system: ... user: jdoe: name: 'jdoe' enabled: true sudo: true shell: /bin/bash full_name: 'Jonh Doe' home: '/home/jdoe' home_dir_mode: 755 email: 'jonh@doe.com' jsmith: name: 'jsmith' enabled: true full_name: 'With clear password' home: '/home/jsmith' hash_password: true password: "userpassword" mark: name: 'mark' enabled: true full_name: "unchange password' home: '/home/mark' password: false elizabeth: name: 'elizabeth' enabled: true full_name: 'With hased password' home: '/home/elizabeth' password: "$6$nUI7QEz3$dFYjzQqK5cJ6HQ38KqG4gTWA9eJu3aKx6TRVDFh6BVJxJgFWg2akfAA7f1fCxcSUeOJ2arCO6EEI6XXnHXxG10" Configure sudo for users and groups under ``/etc/sudoers.d/``. This ways ``linux.system.sudo`` pillar map to actual sudo attributes: .. code-block:: jinja # simplified template: Cmds_Alias {{ alias }}={{ commands }} {{ user }} {{ hosts }}=({{ runas }}) NOPASSWD: {{ commands }} %{{ group }} {{ hosts }}=({{ runas }}) NOPASSWD: {{ commands }} # when rendered: saltuser1 ALL=(ALL) NOPASSWD: ALL .. code-block:: yaml linux: system: sudo: enabled: true aliases: host: LOCAL: - localhost PRODUCTION: - db1 - db2 runas: DBA: - postgres - mysql SALT: - root command: # Note: This is not 100% safe when ALL keyword is used, user still may modify configs and hide his actions. # Best practice is to specify full list of commands user is allowed to run. SUPPORT_RESTRICTED: - /bin/vi /etc/sudoers* - /bin/vim /etc/sudoers* - /bin/nano /etc/sudoers* - /bin/emacs /etc/sudoers* - /bin/su - root - /bin/su - - /bin/su - /usr/sbin/visudo SUPPORT_SHELLS: - /bin/sh - /bin/ksh - /bin/bash - /bin/rbash - /bin/dash - /bin/zsh - /bin/csh - /bin/fish - /bin/tcsh - /usr/bin/login - /usr/bin/su - /usr/su ALL_SALT_SAFE: - /usr/bin/salt state* - /usr/bin/salt service* - /usr/bin/salt pillar* - /usr/bin/salt grains* - /usr/bin/salt saltutil* - /usr/bin/salt-call state* - /usr/bin/salt-call service* - /usr/bin/salt-call pillar* - /usr/bin/salt-call grains* - /usr/bin/salt-call saltutil* SALT_TRUSTED: - /usr/bin/salt* users: # saltuser1 with default values: saltuser1 ALL=(ALL) NOPASSWD: ALL saltuser1: {} saltuser2: hosts: - LOCAL # User Alias DBA DBA: hosts: - ALL commands: - ALL_SALT_SAFE groups: db-ops: hosts: - ALL - '!PRODUCTION' runas: - DBA commands: - /bin/cat * - /bin/less * - /bin/ls * salt-ops: hosts: - 'ALL' runas: - SALT commands: - SUPPORT_SHELLS salt-ops-2nd: name: salt-ops nopasswd: false setenv: true # Enable sudo -E option runas: - DBA commands: - ALL - '!SUPPORT_SHELLS' - '!SUPPORT_RESTRICTED' Linux with package, latest version: .. code-block:: yaml linux: system: ... package: package-name: version: latest Linux with package from certail repo, version with no upgrades: .. code-block:: yaml linux: system: ... package: package-name: version: 2132.323 repo: 'custom-repo' hold: true Linux with package from certail repo, version with no GPG verification: .. code-block:: yaml linux: system: ... package: package-name: version: 2132.323 repo: 'custom-repo' verify: false Linux with autoupdates (automatically install security package updates): .. code-block:: yaml linux: system: ... autoupdates: enabled: true mail: root@localhost mail_only_on_error: true remove_unused_dependencies: false automatic_reboot: true automatic_reboot_time: "02:00" Linux with cron jobs By default, it will use name as an identifier, unless identifier key is explicitly set or False (then it will use Salt's default behavior which is identifier same as command resulting in not being able to change it): .. code-block:: yaml linux: system: ... job: cmd1: command: '/cmd/to/run' identifier: cmd1 enabled: true user: 'root' hour: 2 minute: 0 Linux security limits (limit sensu user memory usage to max 1GB): .. code-block:: yaml linux: system: ... limit: sensu: enabled: true domain: sensu limits: - type: hard item: as value: 1000000 Enable autologin on ``tty1`` (may work only for Ubuntu 14.04): .. code-block:: yaml linux: system: console: tty1: autologin: root # Enable serial console ttyS0: autologin: root rate: 115200 term: xterm To disable set autologin to ``false``. Set ``policy-rc.d`` on Debian-based systems. Action can be any available command in ``while true`` loop and ``case`` context. Following will disallow dpkg to stop/start services for the Cassandra package automatically: .. code-block:: yaml linux: system: policyrcd: - package: cassandra action: exit 101 - package: '*' action: switch Set system locales: .. code-block:: yaml linux: system: locale: en_US.UTF-8: default: true "cs_CZ.UTF-8 UTF-8": enabled: true Systemd settings: .. code-block:: yaml linux: system: ... systemd: system: Manager: DefaultLimitNOFILE: 307200 DefaultLimitNPROC: 307200 user: Manager: DefaultLimitCPU: 2 DefaultLimitNPROC: 4 Ensure presence of directory: .. code-block:: yaml linux: system: directory: /tmp/test: user: root group: root mode: 700 makedirs: true Ensure presence of file by specifying its source: .. code-block:: yaml linux: system: file: /tmp/test.txt: source: http://example.com/test.txt user: root #optional group: root #optional mode: 700 #optional dir_mode: 700 #optional encoding: utf-8 #optional hash: <> or <> #optional makedirs: true #optional linux: system: file: test.txt: name: /tmp/test.txt source: http://example.com/test.txt Ensure presence of file by specifying its contents: .. code-block:: yaml linux: system: file: /tmp/test.txt: contents: | line1 line2 linux: system: file: /tmp/test.txt: contents_pillar: linux:network:hostname linux: system: file: /tmp/test.txt: contents_grains: motd Ensure presence of file to be serialized through one of the serializer modules (see: https://docs.saltstack.com/en/latest/ref/serializers/all/index.html): .. code-block:: yaml linux: system: file: /tmp/test.json: serialize: json contents: foo: 1 bar: 'bar' Kernel ~~~~~~ Install always up to date LTS kernel and headers from Ubuntu Trusty: .. code-block:: yaml linux: system: kernel: type: generic lts: trusty headers: true Load kernel modules and add them to ``/etc/modules``: .. code-block:: yaml linux: system: kernel: modules: - nf_conntrack - tp_smapi - 8021q Configure or blacklist kernel modules with additional options to ``/etc/modprobe.d`` following example will add ``/etc/modprobe.d/nf_conntrack.conf`` file with line ``options nf_conntrack hashsize=262144``: 'option' can be a mapping (with 'enabled' and 'value' keys) or a scalar. Example for 'scalar' option value: .. code-block:: yaml linux: system: kernel: module: nf_conntrack: option: hashsize: 262144 Example for 'mapping' option value: .. code-block:: yaml linux: system: kernel: module: nf_conntrack: option: hashsize: enabled: true value: 262144 NOTE: 'enabled' key is optional and is True by default. Blacklist a module: .. code-block:: yaml linux: system: kernel: module: nf_conntrack: blacklist: true A module can have a number of aliases, wildcards are allowed. Define an alias for a module: .. code-block:: yaml linux: system: kernel: module: nf_conntrack: alias: nfct: enabled: true "nf_conn*": enabled: true NOTE: 'enabled' key is mandatory as there are no other keys exist. Execute custom command instead of 'insmod' when inserting a module: .. code-block:: yaml linux: system: kernel: module: nf_conntrack: install: enabled: true command: /bin/true NOTE: 'enabled' key is optional and is True by default. Execute custom command instead of 'rmmod' when removing a module: .. code-block:: yaml linux: system: kernel: module: nf_conntrack: remove: enabled: true command: /bin/true NOTE: 'enabled' key is optional and is True by default. Define module dependencies: .. code-block:: yaml linux: system: kernel: module: nf_conntrack: softdep: pre: 1: enabled: true value: a 2: enabled: true value: b 3: enabled: true value: c post: 1: enabled: true value: x 2: enabled: true value: y 3: enabled: true value: z NOTE: 'enabled' key is optional and is True by default. Install specific kernel version and ensure all other kernel packages are not present. Also install extra modules and headers for this kernel: .. code-block:: yaml linux: system: kernel: type: generic extra: true headers: true version: 4.2.0-22 Systcl kernel parameters: .. code-block:: yaml linux: system: kernel: sysctl: net.ipv4.tcp_keepalive_intvl: 3 net.ipv4.tcp_keepalive_time: 30 net.ipv4.tcp_keepalive_probes: 8 Configure kernel boot options: .. code-block:: yaml linux: system: kernel: boot_options: - elevator=deadline - spectre_v2=off - nopti CPU ~~~ Enable cpufreq governor for every cpu: .. code-block:: yaml linux: system: cpu: governor: performance CGROUPS ~~~~~~~ Setup linux cgroups: .. code-block:: yaml linux: system: cgroup: enabled: true group: ceph_group_1: controller: cpu: shares: value: 250 cpuacct: usage: value: 0 cpuset: cpus: value: 1,2,3 memory: limit_in_bytes: value: 2G memsw.limit_in_bytes: value: 3G mapping: subjects: - '@ceph' generic_group_1: controller: cpu: shares: value: 250 cpuacct: usage: value: 0 mapping: subjects: - '*:firefox' - 'student:cp' Shared libraries ~~~~~~~~~~~~~~~~ Set additional shared library to Linux system library path: .. code-block:: yaml linux: system: ld: library: java: - /usr/lib/jvm/jre-openjdk/lib/amd64/server - /opt/java/jre/lib/amd64/server Certificates ~~~~~~~~~~~~ Add certificate authority into system trusted CA bundle: .. code-block:: yaml linux: system: ca_certificates: mycert: | -----BEGIN CERTIFICATE----- MIICPDCCAaUCEHC65B0Q2Sk0tjjKewPMur8wDQYJKoZIhvcNAQECBQAwXzELMAkG A1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMTcwNQYDVQQLEy5DbGFz cyAzIFB1YmxpYyBQcmltYXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MB4XDTk2 MDEyOTAwMDAwMFoXDTI4MDgwMTIzNTk1OVowXzELMAkGA1UEBhMCVVMxFzAVBgNV BAoTDlZlcmlTaWduLCBJbmMuMTcwNQYDVQQLEy5DbGFzcyAzIFB1YmxpYyBQcmlt YXJ5IENlcnRpZmljYXRpb24gQXV0aG9yaXR5MIGfMA0GCSqGSIb3DQEBAQUAA4GN ADCBiQKBgQDJXFme8huKARS0EN8EQNvjV69qRUCPhAwL0TPZ2RHP7gJYHyX3KqhE BarsAx94f56TuZoAqiN91qyFomNFx3InzPRMxnVx0jnvT0Lwdd8KkMaOIG+YD/is I19wKTakyYbnsZogy1Olhec9vn2a/iRFM9x2Fe0PonFkTGUugWhFpwIDAQABMA0G CSqGSIb3DQEBAgUAA4GBALtMEivPLCYATxQT3ab7/AoRhIzzKBxnki98tsX63/Do lbwdj2wsqFHMc9ikwFPwTtYmwHYBV4GSXiHx0bH/59AhWM1pF+NEHJwZRDmJXNyc AA9WjQKZ7aKQRUzkuxCkPfAyAw7xzvjoyVGM5mKf5p/AfbdynMk2OmufTqj/ZA1k -----END CERTIFICATE----- Sysfs ~~~~~ Install sysfsutils and set sysfs attributes: .. code-block:: yaml linux: system: sysfs: scheduler: block/sda/queue/scheduler: deadline power: mode: power/state: 0660 owner: power/state: "root:power" devices/system/cpu/cpu0/cpufreq/scaling_governor: powersave Optional: You can also use list that will ensure order of items. .. code-block:: yaml linux: system: sysfs: scheduler: block/sda/queue/scheduler: deadline power: - mode: power/state: 0660 - owner: power/state: "root:power" - devices/system/cpu/cpu0/cpufreq/scaling_governor: powersave Huge Pages ~~~~~~~~~~~~ Huge Pages give a performance boost to applications that intensively deal with memory allocation/deallocation by decreasing memory fragmentation: .. code-block:: yaml linux: system: kernel: hugepages: small: size: 2M count: 107520 mount_point: /mnt/hugepages_2MB mount: false/true # default is true (mount immediately) / false (just save in the fstab) large: default: true # default automatically mounted size: 1G count: 210 mount_point: /mnt/hugepages_1GB .. note:: Not recommended to use both pagesizes concurrently. Intel SR-IOV ~~~~~~~~~~~~ PCI-SIG Single Root I/O Virtualization and Sharing (SR-IOV) specification defines a standardized mechanism to virtualize PCIe devices. The mechanism can virtualize a single PCIe Ethernet controller to appear as multiple PCIe devices: .. code-block:: yaml linux: system: kernel: sriov: True unsafe_interrupts: False # Default is false. for older platforms and AMD we need to add interrupt remapping workaround rc: local: | #!/bin/sh -e # Enable 7 VF on eth1 echo 7 > /sys/class/net/eth1/device/sriov_numvfs; sleep 2; ifup -a exit 0 Isolate CPU options ~~~~~~~~~~~~~~~~~~~ Remove the specified CPUs, as defined by the cpu_number values, from the general kernel SMP balancing and scheduler algroithms. The only way to move a process onto or off an *isolated* CPU is via the CPU affinity syscalls. ``cpu_number begins`` at ``0``, so the maximum value is ``1`` less than the number of CPUs on the system.: .. code-block:: yaml linux: system: kernel: isolcpu: 1,2,3,4,5,6,7 # isolate first cpu 0 Repositories ~~~~~~~~~~~~ RedHat-based Linux with additional OpenStack repo: .. code-block:: yaml linux: system: ... repo: rdo-icehouse: enabled: true source: 'http://repos.fedorapeople.org/repos/openstack/openstack-icehouse/epel-6/' pgpcheck: 0 Ensure system repository to use czech Debian mirror (``default: true``) Also pin it's packages with priority ``900``: .. code-block:: yaml linux: system: repo: debian: default: true source: "deb http://ftp.cz.debian.org/debian/ jessie main contrib non-free" # Import signing key from URL if needed key_url: "http://dummy.com/public.gpg" pin: - pin: 'origin "ftp.cz.debian.org"' priority: 900 package: '*' .. note:: For old Ubuntu releases (