Re: Bootstrap in chroot
"'Bas van der Vlies' via help-cfengine" <[email protected]> Wed, 22 May 2024 14:39:03 +0200
| Newsgroups | gmane.comp.sysutils.cfengine.general |
|---|---|
| Message-ID | <[email protected]> |
Markus,
I do not see that you just `skip the policy run`:
* /var/cfengine/bin/cf-agent --bootstrap="${IMAGESERVER}"
--skip-bootstrap-policy-run
Does the fail or succeed?
On 22/05/2024 13:38, Markus Rexhepi-Lindberg wrote:
> It seems that the bootstrap fails AFAIK. For instance the
> `/var/cfengine/policy_server.dat` file does not get provisioned.
>
> I first run a bootstrap as I otherwise can't start cf-execd.
>
> Starting cf-execd without running a bootstrap first.
> ```
> # cf-execd
> error: There is no readable input file at
> '/var/cfengine/inputs/promises.cf'. (stat: No such file or directory)
> error: Failsafe condition triggered. Interactive session detected,
> skipping failsafe.cf execution.
> error: Error reading CFEngine policy. Exiting...
> ```
>
> Running a boostrap and then starting cf-execd.
> ```
> # cf-agent -B <redacted>
> notice: Bootstrap mode: implicitly trusting server, use
> --trust-server=no if server trust is already established
> notice: Trusting new key: MD5=<redacted>
> R: Bootstrapping from host '<redacted>' via built-in policy
> '/var/cfengine/inputs/failsafe.cf'
> R: This autonomous node assumes the role of voluntary client
> R: Updated local policy from policy server
> R: Triggered an initial run of the policy
> R: Restarted systemd unit cfengine3
> error: Bootstrapping failed, cf-execd is not running
> # cf-execd
> #
> ```
>
> After I have done this I attempt to run the policies.
> ```
> # cf-agent -KIC
> ...
> error: No suitable server found for '/var/cfengine/scripts/'
> ...
> ```
> I get errors suggesting that there is not suitable server to be
> found/used. The policies them self seem to run fine though.
>
> If I run a bootstrap again as the last step.
> ```
> # cf-agent -B <redacted>
> notice: Bootstrap mode: implicitly trusting server, use
> --trust-server=no if server trust is already established
> R: Bootstrapping from host '<redacted>' via built-in policy
> '/var/cfengine/inputs/failsafe.cf'
> R: This autonomous node assumes the role of voluntary client
> R: Updated local policy from policy server
> R: Triggered an initial run of the policy
> notice: Bootstrap to '<redacted>' completed successfully!
> # ls -l /var/cfengine/policy_server.dat
> -rw------- 1 root root 26 May 22 13:35 /var/cfengine/policy_server.dat
> ```
> It goes through and the `/var/cfengine/policy_server.dat` file gets
> provisioned and I do not get "No suitable server ..." errors when
> running `cf-agent`.
>
> --
> Markus
> On Wednesday, May 22, 2024 at 12:50:51 PM UTC+2
> [email protected] wrote:
>
> Hi Markus,
>
> On Mon, 2024-05-20 at 02:58 -0700, Markus Rexhepi-Lindberg wrote:
> > Is it possible to bootstrap a host running in a chroot?
> >
> > I want to bootstrap a host during its provisioning stage were it
> currently runs in a chroot environment. While bootstrapping cf-agent
> complains that the cf-execd daemon is not running, which seems to be
> the case since cfengine3.service is not allowed to start in a chroot
> environment.
> >
> > ```
> > # chroot /target cf-agent -B <cfehub>
> > notice: Bootstrap mode: implicitly trusting server, use
> --trust-server=no if server trust is already established
> > notice: Trusting new key: MD5=<redacted>
> > R: Bootstrapping from host '<redacted>' via built-in policy
> '/var/cfengine/inputs/failsafe.cf <http://failsafe.cf>'
> > R: This autonomous node assumes the role of voluntary client
> > R: Updated local policy from policy server
> > R: Triggered an initial run of the policy
> > R: Restarted systemd unit cfengine3
> > error: Bootstrapping failed, cf-execd is not running
> > notice: Bootstrap mode: implicitly trusting server, use
> --trust-server=no if server trust is already established
> > ```
> >
> > I managed to workaround this by first trying to bootstrap, which
> fails, then manually start cf-execd in the chroot and finally try to
> bootstrap again which succeeds.
> >
> > ```
> > # chroot /traget cf-execd
> > # chroot /target cf-agent -B <cfehub>
> > R: Bootstrapping from host '<redacted>' via built-in policy
> '/var/cfengine/inputs/failsafe.cf <http://failsafe.cf>'
> > R: This autonomous node assumes the role of voluntary client
> > R: Updated local policy from policy server
> > R: Triggered an initial run of the policy
> > notice: Bootstrap to '<redacted>' completed successfully!
> > ```
> >
> > This works but feels like a hack. Is there another way this could
> be done?
> Did you check if the second run is necessary? AFAICT, the error
> about cf-execd
> not running is a valid one, but it doesn't mean that the rest of the
> bootstrap
> process didn't run or failed. I'd expect the host to be bootstrapped
> just fine
> just with the daemons (cf-execd, cf-serverd, cf-monitord) not
> running. So I
> think you can skip the last step, but you should start the other two
> daemons in
> the chroot as well.
>
> --
> Vratislav
>
> --
> You received this message because you are subscribed to the Google
> Groups "help-cfengine" group.
> To unsubscribe from this group and stop receiving emails from it, send
> an email to [email protected]
> <mailto:[email protected]>.
> To view this discussion on the web visit
> https://groups.google.com/d/msgid/help-cfengine/0a378e7e-d113-42f1-8674-0efdc1e5731en%40googlegroups.com <https://groups.google.com/d/msgid/help-cfengine/0a378e7e-d113-42f1-8674-0efdc1e5731en%40googlegroups.com?utm_medium=email&utm_source=footer>.
--
--
Bas van der Vlies
| High Performance Computing & Visualization | SURF| Science Park 140 |
1098 XG Amsterdam
| T +31 (0) 20 800 1300 | [email protected] | www.surf.nl |
--
You received this message because you are subscribed to the Google Groups "help-cfengine" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion on the web visit https://groups.google.com/d/msgid/help-cfengine/71f86b85-4461-44c6-ae60-02b8933f7566%40surf.nl.
smime.p7s
(application/pkcs7-signature, 4.7 KB) - not displayed