mirror of
				https://github.com/apache/cloudstack.git
				synced 2025-10-26 08:42:29 +01:00 
			
		
		
		
	* Support for live patching systemVMs and deprecating systemVM.iso. Includes: - fix systemVM template version - Include agent.zip, cloud-scripts.tgz to the commons package - Support for live-patching systemVMs - CPVM, SSVM, Routers - Fix Unit test - Remove systemvm.iso dependency * The following commit: - refactors logic added to support SystemVM deployment on KVM - Adds support to copy specific files (required for patching) to the hosts on Xenserver - Modifies vmops method - createFileInDomr to take cleanup param - Adds configuratble sleep param to CitrixResourceBase::connect() used to verify if telnet to specifc port is possible (if sleep is 0, then default to _sleep = 10000ms) - Adds Command/Answer for patch systemVMs on XenServer/Xcp * - Support to patch SystemVMs - VMWare - Remove attaching systemvm.iso to systemVMs - Modify / Refactor VMware start command to copy patch related files to the systemvms - cleanup * Commit comprises of: - remove docker from systemvm template - use containerd as container runtime - update create-k8s-binaries script to use ctr for all docker operations - Update userdata sent to the k8s nodes - update cksnode script, run during patching of the cks/k8s nodes * Add ssh to k8s nodes details in the Access tab on the UI * test * Refactor ca/cert patching logic * Commit comprises of the following changes: - Use restart network/VPC API to patch routers - use livePatch API support patching of only cpvm/ssvm - add timeout to the keystore setup/import script * remove all references of systemvm.iso * Fix keystore-cert-import invocation + refactor cert timeout in CP/SS VMs * fix script timeout * Refactor cert patching for systemVMs + update keystore-cert-import script + patch-sysvms script + remove patchSysvmCommand from networkelementcommand * remove commented code + change core user to cloud for cks nodes * Update ownership of ssh directory * NEED TO DISCUSS - add on the fly template conversion as an ExecStartPre action (systemd) * Add UI changes + move changes from patch file to runcmd * test: validate performance for template modification during seeding * create vms folder in cloudstack-commons directory - debian rules * remove logic for on the fly template convert + update k8s test * fix syntax issue - causing issue with shared network tests * Code cleanup * refactor patching logic - certs * move logic of fixing rootdiskcontroller from upgrade to kubernetes service * add livepatch option to restart network & vpc * smooth upgrade of cks clusters * Support for live patching systemVMs and deprecating systemVM.iso. Includes: - fix systemVM template version - Include agent.zip, cloud-scripts.tgz to the commons package - Support for live-patching systemVMs - CPVM, SSVM, Routers - Fix Unit test - Remove systemvm.iso dependency * The following commit: - refactors logic added to support SystemVM deployment on KVM - Adds support to copy specific files (required for patching) to the hosts on Xenserver - Modifies vmops method - createFileInDomr to take cleanup param - Adds configuratble sleep param to CitrixResourceBase::connect() used to verify if telnet to specifc port is possible (if sleep is 0, then default to _sleep = 10000ms) - Adds Command/Answer for patch systemVMs on XenServer/Xcp * - Support to patch SystemVMs - VMWare - Remove attaching systemvm.iso to systemVMs - Modify / Refactor VMware start command to copy patch related files to the systemvms - cleanup * Commit comprises of: - remove docker from systemvm template - use containerd as container runtime - update create-k8s-binaries script to use ctr for all docker operations - Update userdata sent to the k8s nodes - update cksnode script, run during patching of the cks/k8s nodes * Add ssh to k8s nodes details in the Access tab on the UI * test * Refactor ca/cert patching logic * Commit comprises of the following changes: - Use restart network/VPC API to patch routers - use livePatch API support patching of only cpvm/ssvm - add timeout to the keystore setup/import script * remove all references of systemvm.iso * Fix keystore-cert-import invocation + refactor cert timeout in CP/SS VMs * fix script timeout * Refactor cert patching for systemVMs + update keystore-cert-import script + patch-sysvms script + remove patchSysvmCommand from networkelementcommand * remove commented code + change core user to cloud for cks nodes * Update ownership of ssh directory * NEED TO DISCUSS - add on the fly template conversion as an ExecStartPre action (systemd) * Add UI changes + move changes from patch file to runcmd * test: validate performance for template modification during seeding * create vms folder in cloudstack-commons directory - debian rules * remove logic for on the fly template convert + update k8s test * fix syntax issue - causing issue with shared network tests * Code cleanup * add cgroup config for containerd * add systemd config for kubelet * add additional info during image registry config * address comments * add temp links of download.cloudstack.org * address part of the comments * address comments * update containerd config - as version has upgraded to 1.5 from 1.4.12 in 4.17.0 * address comments - simplify * fix vue3 related icon changes * allow network commands when router template version is lower but is patched * add internal LB to the list of routers to be patched on network restart with live patch * add unit tests for API param validations and new helper utilities - file scp & checksum validations * perform patching only for non-user i.e., system VMs * add test to validate params * remove unused import * add column to domain_router to display software version and support networkrestart with livePatch from router view * Requires upgrade column to consider package (cloud-scripts) checksum to identify if true/false * use router software version instead of checksum * show N/A if no software version reported i.e., in upgraded envs * fix deb failure * update pom to official links of systemVM template
		
			
				
	
	
		
			131 lines
		
	
	
		
			3.6 KiB
		
	
	
	
		
			Bash
		
	
	
		
			Executable File
		
	
	
	
	
			
		
		
	
	
			131 lines
		
	
	
		
			3.6 KiB
		
	
	
	
		
			Bash
		
	
	
		
			Executable File
		
	
	
	
	
| #!/bin/bash
 | |
| # Licensed to the Apache Software Foundation (ASF) under one
 | |
| # or more contributor license agreements.  See the NOTICE file
 | |
| # distributed with this work for additional information
 | |
| # regarding copyright ownership.  The ASF licenses this file
 | |
| # to you under the Apache License, Version 2.0 (the
 | |
| # "License"); you may not use this file except in compliance
 | |
| # with the License.  You may obtain a copy of the License at
 | |
| #
 | |
| #   http://www.apache.org/licenses/LICENSE-2.0
 | |
| #
 | |
| # Unless required by applicable law or agreed to in writing,
 | |
| # software distributed under the License is distributed on an
 | |
| # "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
 | |
| # KIND, either express or implied.  See the License for the
 | |
| # specific language governing permissions and limitations
 | |
| # under the License.
 | |
| set -x
 | |
| PATH="/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin"
 | |
| 
 | |
| # Clear boot up flag, it would be created by rc.local after boot up done
 | |
| mkdir -p /var/cache/cloud
 | |
| rm -f /var/cache/cloud/boot_up_done
 | |
| 
 | |
| [ -x /sbin/ifup ] || exit 0
 | |
| 
 | |
| . /lib/lsb/init-functions
 | |
| 
 | |
| log_it() {
 | |
|   echo "$(date) $@" >> /var/log/cloud.log
 | |
|   log_action_msg "$@"
 | |
| }
 | |
| 
 | |
| validate_checksums() {
 | |
|   local oldmd5=
 | |
|   [ -f ${1} ] && oldmd5=$(cat ${1})
 | |
|   local newmd5=
 | |
|   [ -f ${2} ] && newmd5=$(md5sum ${2} | awk '{print $1}')
 | |
|   log_it "Scripts checksum detected: oldmd5=$oldmd5 newmd5=$newmd5" >> /dev/null 2>&1
 | |
|   echo "oldmd5='${oldmd5}'; newmd5='${newmd5}'"
 | |
| }
 | |
| 
 | |
| patch() {
 | |
|   local PATCH_MOUNT=/tmp
 | |
|   local PATCH_SCRIPTS=cloud-scripts.tgz
 | |
|   local oldpatchfile=/usr/share/cloud/$PATCH_SCRIPTS
 | |
|   local patchfile=$PATCH_MOUNT/$PATCH_SCRIPTS
 | |
|   local privkey=$PATCH_MOUNT/authorized_keys
 | |
|   local md5file=/var/cache/cloud/cloud-scripts-signature
 | |
|   mkdir -p $PATCH_MOUNT
 | |
| 
 | |
|   if [ -f /var/cache/cloud/authorized_keys ]; then
 | |
|     privkey=/var/cache/cloud/authorized_keys
 | |
|   fi
 | |
| 
 | |
|   eval $(validate_checksums $md5file $oldpatchfile)
 | |
|   if [ "$oldmd5" == "$newmd5" ] && [ -d /usr/local/cloud/systemvm ] && [ "$(ls -A /usr/local/cloud/systemvm)" ]; then
 | |
|     log_it "Checksum matches, no need to patch"
 | |
|     return 0
 | |
|   fi
 | |
| 
 | |
|   CMDLINE=/var/cache/cloud/cmdline
 | |
|   export TYPE=$(grep -Po 'type=\K[a-zA-Z]*' $CMDLINE)
 | |
|   retry=60
 | |
|   local patched=false
 | |
|   if [ "$TYPE" != "cksnode" ]; then
 | |
|     while [ $retry -gt 0 ]
 | |
|     do
 | |
|       if [ -f $patchfile ]; then
 | |
|         eval $(validate_checksums $md5file $patchfile)
 | |
|         if [ "$oldmd5" != "$newmd5" ] && [ -f ${patchfile} ] && [ "$newmd5" != "" ]
 | |
|         then
 | |
|           tar xzf $patchfile -C /
 | |
|           echo ${newmd5} > ${md5file}
 | |
|           log_it "Patched scripts using $patchfile"
 | |
|           touch /var/cache/cloud/patch.required
 | |
|         fi
 | |
| 
 | |
|         if [ -f $privkey ]; then
 | |
|           cp -f $privkey /root/.ssh/
 | |
|           chmod go-rwx /root/.ssh/authorized_keys
 | |
|         fi
 | |
|         patched=true
 | |
|         break
 | |
|       fi
 | |
| 
 | |
|       sleep 2
 | |
|       retry=$(($retry-1))
 | |
|       log_it "Could not find patch file, retrying"
 | |
|     done
 | |
| 
 | |
|     if [ $retry -eq 0 ] && [ "$patched" == "false" ]; then
 | |
|       return 2
 | |
|     fi
 | |
|     return 0
 | |
|   fi
 | |
| }
 | |
| 
 | |
| cleanup() {
 | |
|   rm -rf /tmp/agent.zip
 | |
|   mv /tmp/cloud-scripts.tgz /usr/share/cloud/cloud-scripts.tgz
 | |
| }
 | |
| 
 | |
| start() {
 | |
|   log_it "Executing cloud-early-config"
 | |
| 
 | |
|   # Clear /tmp for file lock
 | |
|   rm -f /tmp/*.lock
 | |
|   rm -f /tmp/rrouter_bumped
 | |
|   rm -f /root/.rnd
 | |
|   echo "" > /root/.ssh/known_hosts
 | |
| 
 | |
|   if which growpart > /dev/null; then
 | |
|     ROOT_MOUNT_POINT=$(df -h / | tail -n 1  | cut -d' ' -f1)
 | |
|     ROOT_DISK=$(echo $ROOT_MOUNT_POINT | sed 's/[0-9]*$//g')
 | |
|     growpart $ROOT_DISK 2
 | |
|     growpart $ROOT_DISK 6
 | |
|     resize2fs $ROOT_MOUNT_POINT
 | |
|   fi
 | |
| 
 | |
|   patch
 | |
|   sync
 | |
|   /opt/cloud/bin/setup/bootstrap.sh
 | |
|   cleanup
 | |
| 
 | |
|   log_it "Finished setting up systemvm"
 | |
|   exit 0
 | |
| }
 | |
| 
 | |
| start
 |