Browse Source

Merge "Fix error message when OTP is missing, add logging"

tags/1.2.0
Zuul 1 week ago
parent
commit
0bcb4ec41b
3 changed files with 9 additions and 1 deletions
  1. 1
    1
      files/cloud-config-novajoin.json
  2. 5
    0
      files/cloud-config-novajoin.yaml
  3. 3
    0
      novajoin/ipa.py

+ 1
- 1
files/cloud-config-novajoin.json View File

@@ -1 +1 @@
1
-{"cloud-init": "#cloud-config\npackages:\n - python-simplejson\n - ipa-client\n - ipa-admintools\n - openldap-clients\n - hostname\nwrite_files:\n - content: |\n     #!/bin/sh\n     \n     function get_metadata_config_drive {\n         if [ -f /run/cloud-init/status.json ]; then\n             # Get metadata from config drive\n             data=`cat /run/cloud-init/status.json`\n             config_drive=`echo $data | python -c 'import json,re,sys;obj=json.load(sys.stdin);ds=obj.get(\"v1\", {}).get(\"datasource\"); print(re.findall(r\"source=(.*)]\", ds)[0])'`\n             if [[ -b $config_drive ]]; then\n                 temp_dir=`mktemp -d`\n                 mount $config_drive $temp_dir\n                 if [ -f $temp_dir/openstack/latest/vendor_data2.json ]; then\n                     data=`cat $temp_dir/openstack/latest/vendor_data2.json`\n                     umount $config_drive\n                     rmdir $temp_dir\n                 else\n                     umount $config_drive\n                     rmdir $temp_dir\n                 fi\n             else \n                 echo \"Unable to retrieve metadata from config drive.\"\n                 return 1\n             fi\n         else\n             echo \"Unable to retrieve metadata from config drive.\"\n             return 1\n         fi\n     \n         return 0\n     }\n     \n     function get_metadata_network {\n         # Get metadata over the network\n         data=$(timeout 300 /bin/bash -c 'data=\"\"; while [ -z \"$data\" ]; do sleep $[ ( $RANDOM % 10 )  + 1 ]s; data=`curl -s http://169.254.169.254/openstack/2016-10-06/vendor_data2.json 2>/dev/null`; done; echo $data')\n     \n         if [[ $? != 0 ]] ; then\n             echo \"Unable to retrieve metadata from metadata service.\"\n             return 1\n         fi\n     }\n     \n     function get_fqdn {\n         # Get the instance hostname out of the metadata\n         fqdn=`echo $data | python -c 'import json,sys;obj=json.load(sys.stdin);print(obj.get(\"join\", {}).get(\"hostname\", \"\"))'`\n         if [ -z \"$fqdn\"]; then\n             echo \"Unable to determine hostname\"\n             return 1\n         fi\n         return 0\n     }\n     \n     if ! get_metadata_config_drive || ! get_fqdn; then\n        if ! get_metadata_network || ! get_fqdn; then\n            echo \"FATAL: No metadata available or could not read the hostname from the metadata\"\n            exit 1\n        fi\n     fi\n     \n     realm=`echo $data | python -c 'import json,sys;obj=json.load(sys.stdin);print(obj.get(\"join\", {}).get(\"krb_realm\", \"\"))'`\n     otp=`echo $data | python -c 'import json,sys;obj=json.load(sys.stdin);print(obj.get(\"join\", {}).get(\"ipaotp\", \"\"))'`\n     \n     # run ipa-client-install\n     OPTS=\"-U -w $otp --hostname $fqdn --mkhomedir\"\n     if [ -n \"$realm\" ]; then\n         OPTS=\"$OPTS --realm=$realm\"\n     fi\n     ipa-client-install $OPTS\n   path: /root/setup-ipa-client.sh\n   permissions: '0700'\n   owner: root:root\nruncmd:\n- sh -x /root/setup-ipa-client.sh > /var/log/setup-ipa-client.log 2>&1"}
1
+{"cloud-init": "#cloud-config\npackages:\n - python-simplejson\n - ipa-client\n - ipa-admintools\n - openldap-clients\n - hostname\nwrite_files:\n - content: |\n     #!/bin/sh\n     \n     function get_metadata_config_drive {\n         if [ -f /run/cloud-init/status.json ]; then\n             # Get metadata from config drive\n             data=`cat /run/cloud-init/status.json`\n             config_drive=`echo $data | python -c 'import json,re,sys;obj=json.load(sys.stdin);ds=obj.get(\"v1\", {}).get(\"datasource\"); print(re.findall(r\"source=(.*)]\", ds)[0])'`\n             if [[ -b $config_drive ]]; then\n                 temp_dir=`mktemp -d`\n                 mount $config_drive $temp_dir\n                 if [ -f $temp_dir/openstack/latest/vendor_data2.json ]; then\n                     data=`cat $temp_dir/openstack/latest/vendor_data2.json`\n                     umount $config_drive\n                     rmdir $temp_dir\n                 else\n                     umount $config_drive\n                     rmdir $temp_dir\n                 fi\n             else \n                 echo \"Unable to retrieve metadata from config drive.\"\n                 return 1\n             fi\n         else\n             echo \"Unable to retrieve metadata from config drive.\"\n             return 1\n         fi\n     \n         return 0\n     }\n     \n     function get_metadata_network {\n         # Get metadata over the network\n         data=$(timeout 300 /bin/bash -c 'data=\"\"; while [ -z \"$data\" ]; do sleep $[ ( $RANDOM % 10 )  + 1 ]s; data=`curl -s http://169.254.169.254/openstack/2016-10-06/vendor_data2.json 2>/dev/null`; done; echo $data')\n     \n         if [[ $? != 0 ]] ; then\n             echo \"Unable to retrieve metadata from metadata service.\"\n             return 1\n         fi\n     }\n     \n     function get_fqdn {\n         # Get the instance hostname out of the metadata\n         fqdn=`echo $data | python -c 'import json,sys;obj=json.load(sys.stdin);print(obj.get(\"join\", {}).get(\"hostname\", \"\"))'`\n         if [ -z \"$fqdn\"]; then\n             echo \"Unable to determine hostname\"\n             return 1\n         fi\n         return 0\n     }\n     \n     if ! get_metadata_config_drive || ! get_fqdn; then\n        if ! get_metadata_network || ! get_fqdn; then\n            echo \"FATAL: No metadata available or could not read the hostname from the metadata\"\n            exit 1\n        fi\n     fi\n     \n     realm=`echo $data | python -c 'import json,sys;obj=json.load(sys.stdin);print(obj.get(\"join\", {}).get(\"krb_realm\", \"\"))'`\n     otp=`echo $data | python -c 'import json,sys;obj=json.load(sys.stdin);print(obj.get(\"join\", {}).get(\"ipaotp\", \"\"))'`\n     \n     if [ -z \"$otp\" ]; then\n         echo \"FATAL: Could not read OTP from the metadata. This means that a host with the same name was already enrolled in IPA.\"\n         exit 1\n     fi\n     \n     # run ipa-client-install\n     OPTS=\"-U -w $otp --hostname $fqdn --mkhomedir\"\n     if [ -n \"$realm\" ]; then\n         OPTS=\"$OPTS --realm=$realm\"\n     fi\n     ipa-client-install $OPTS\n   path: /root/setup-ipa-client.sh\n   permissions: '0700'\n   owner: root:root\nruncmd:\n- sh -x /root/setup-ipa-client.sh > /var/log/setup-ipa-client.log 2>&1"}

+ 5
- 0
files/cloud-config-novajoin.yaml View File

@@ -67,6 +67,11 @@ write_files:
67 67
      realm=`echo $data | python -c 'import json,sys;obj=json.load(sys.stdin);print(obj.get("join", {}).get("krb_realm", ""))'`
68 68
      otp=`echo $data | python -c 'import json,sys;obj=json.load(sys.stdin);print(obj.get("join", {}).get("ipaotp", ""))'`
69 69
      
70
+     if [ -z "$otp" ]; then
71
+         echo "FATAL: Could not read OTP from the metadata. This means that a host with the same name was already enrolled in IPA."
72
+         exit 1
73
+     fi
74
+     
70 75
      # run ipa-client-install
71 76
      OPTS="-U -w $otp --hostname $fqdn --mkhomedir"
72 77
      if [ -n "$realm" ]; then

+ 3
- 0
novajoin/ipa.py View File

@@ -338,6 +338,9 @@ class IPAClient(IPANovaJoinBase):
338 338
             # Updating the OTP on an enrolled-host is not allowed
339 339
             # in IPA and really a no-op.
340 340
             # We don't know the OTP of the host, so we cannot update the cache.
341
+            LOG.info('OTP is unknown for host %s. This is because validation '
342
+                     'failed during host_mod operation, which means the host '
343
+                     'with the same name was already enrolled.', hostname)
341 344
             return False
342 345
 
343 346
         return self.host_cache.get(hostname, False)

Loading…
Cancel
Save