From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael Tremer To: development@lists.ipfire.org Subject: [PATCH 1/3] cloud: Execute user-data scripts at the end of initialization Date: Thu, 19 May 2022 09:40:25 +0000 Message-ID: <20220519094027.200441-1-michael.tremer@ipfire.org> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============6400892526971708496==" List-Id: --===============6400892526971708496== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable This is useful when the user-data needs to reboot an instance. Previously, some initialization did not happen which is now being done first before the user-data script is being executed. This gives users more flexibility about what they are doing in those scripts. Signed-off-by: Michael Tremer --- src/initscripts/helper/aws-setup | 35 +++++++++++------------ src/initscripts/helper/azure-setup | 35 +++++++++++------------ src/initscripts/helper/exoscale-setup | 35 +++++++++++------------ src/initscripts/helper/gcp-setup | 35 +++++++++++------------ src/initscripts/helper/oci-setup | 41 +++++++++++++-------------- 5 files changed, 83 insertions(+), 98 deletions(-) diff --git a/src/initscripts/helper/aws-setup b/src/initscripts/helper/aws-se= tup index a40d4beeb..f14f4eb57 100644 --- a/src/initscripts/helper/aws-setup +++ b/src/initscripts/helper/aws-setup @@ -118,25 +118,6 @@ import_aws_configuration() { fi done =20 - # Download the user-data script only on the first boot - if [ ! -e "/var/ipfire/main/firstsetup_ok" ]; then - # Download user-data - local user_data=3D"$(get user-data)" - - # Save user-data script to be executed later - if [ "${user_data:0:2}" =3D "#!" ]; then - echo "${user_data}" > /tmp/aws-user-data.script - chmod 700 /tmp/aws-user-data.script - - # Run the user-data script - local now=3D"$(date -u +"%s")" - /tmp/aws-user-data.script &>/var/log/user-data.log.${now} - - # Delete the script right away - rm /tmp/aws-user-data.script - fi - fi - # Import network configuration # After this, no network connectivity will be available from this script du= e to the # renaming of the network interfaces for which they have to be shut down @@ -259,6 +240,22 @@ import_aws_configuration() { echo "2,ACCEPT,INPUTFW,ON,std_net_src,ALL,ipfire,RED1,,TCP,,,ON,,,TGT_POR= T,444,,,,,,,,,,,00:00,00:00,,AUTO,,dnat,,,,,second" ) >> /var/ipfire/firewall/input =20 + # Download user-data + local user_data=3D"$(get user-data)" + + # Save user-data script to be executed later + if [ "${user_data:0:2}" =3D "#!" ]; then + echo "${user_data}" > /tmp/aws-user-data.script + chmod 700 /tmp/aws-user-data.script + + # Run the user-data script + local now=3D"$(date -u +"%s")" + /tmp/aws-user-data.script &>/var/log/user-data.log.${now} + + # Delete the script right away + rm /tmp/aws-user-data.script + fi + # This script has now completed the first steps of setup touch /var/ipfire/main/firstsetup_ok fi diff --git a/src/initscripts/helper/azure-setup b/src/initscripts/helper/azur= e-setup index 1eff57799..7a4422a35 100644 --- a/src/initscripts/helper/azure-setup +++ b/src/initscripts/helper/azure-setup @@ -141,25 +141,6 @@ import_azure_configuration() { fi done =20 - # Download the user-data script only on the first boot - if [ ! -e "/var/ipfire/main/firstsetup_ok" ]; then - # Download user-data - local user_data=3D"$(get customData)" - - # Save user-data script to be executed later - if [ "${user_data:0:2}" =3D "#!" ]; then - echo "${user_data}" > /tmp/azure-user-data.script - chmod 700 /tmp/azure-user-data.script - - # Run the user-data script - local now=3D"$(date -u +"%s")" - /tmp/azure-user-data.script &>/var/log/user-data.log.${now} - - # Delete the script right away - rm /tmp/azure-user-data.script - fi - fi - # Import network configuration # After this, no network connectivity will be available from this script du= e to the # renaming of the network interfaces for which they have to be shut down @@ -279,6 +260,22 @@ import_azure_configuration() { echo "2,ACCEPT,INPUTFW,ON,std_net_src,ALL,ipfire,RED1,,TCP,,,ON,,,TGT_POR= T,444,,,,,,,,,,,00:00,00:00,,AUTO,,dnat,,,,,second" ) >> /var/ipfire/firewall/input =20 + # Download user-data + local user_data=3D"$(get customData)" + + # Save user-data script to be executed later + if [ "${user_data:0:2}" =3D "#!" ]; then + echo "${user_data}" > /tmp/azure-user-data.script + chmod 700 /tmp/azure-user-data.script + + # Run the user-data script + local now=3D"$(date -u +"%s")" + /tmp/azure-user-data.script &>/var/log/user-data.log.${now} + + # Delete the script right away + rm /tmp/azure-user-data.script + fi + # This script has now completed the first steps of setup touch /var/ipfire/main/firstsetup_ok fi diff --git a/src/initscripts/helper/exoscale-setup b/src/initscripts/helper/e= xoscale-setup index e9295cc9c..02fdda2a3 100644 --- a/src/initscripts/helper/exoscale-setup +++ b/src/initscripts/helper/exoscale-setup @@ -83,25 +83,6 @@ import_exoscale_configuration() { chown setup.nobody "/home/setup/.ssh/authorized_keys" fi =20 - # Download the user-data script only on the first boot - if [ ! -e "/var/ipfire/main/firstsetup_ok" ]; then - # Download user-data - local user_data=3D"$(get user-data)" - - # Save user-data script to be executed later - if [ "${user_data:0:2}" =3D "#!" ]; then - echo "${user_data}" > /tmp/user-data.script - chmod 700 /tmp/user-data.script - - # Run the user-data script - local now=3D"$(date -u +"%s")" - /tmp/user-data.script &>/var/log/user-data.log.${now} - - # Delete the script right away - rm /tmp/user-data.script - fi - fi - # Import any previous settings for the local interfaces eval $(/usr/local/bin/readhash <(grep -E "^(GREEN|ORANGE)_.*=3D" /var/ipfi= re/ethernet/settings 2>/dev/null)) =20 @@ -208,6 +189,22 @@ import_exoscale_configuration() { echo "2,ACCEPT,INPUTFW,ON,std_net_src,ALL,ipfire,RED1,,TCP,,,ON,,,TGT_POR= T,444,,,,,,,,,,,00:00,00:00,,AUTO,,dnat,,,,,second" ) >> /var/ipfire/firewall/input =20 + # Download user-data + local user_data=3D"$(get user-data)" + + # Save user-data script to be executed later + if [ "${user_data:0:2}" =3D "#!" ]; then + echo "${user_data}" > /tmp/user-data.script + chmod 700 /tmp/user-data.script + + # Run the user-data script + local now=3D"$(date -u +"%s")" + /tmp/user-data.script &>/var/log/user-data.log.${now} + + # Delete the script right away + rm /tmp/user-data.script + fi + # This script has now completed the first steps of setup touch /var/ipfire/main/firstsetup_ok fi diff --git a/src/initscripts/helper/gcp-setup b/src/initscripts/helper/gcp-se= tup index 935194931..4f5148c3e 100644 --- a/src/initscripts/helper/gcp-setup +++ b/src/initscripts/helper/gcp-setup @@ -118,25 +118,6 @@ import_gcp_configuration() { fi done <<<"$(get instance/attributes/ssh-keys)" =20 - # Download the user-data script only on the first boot - if [ ! -e "/var/ipfire/main/firstsetup_ok" ]; then - # Download a startup script - local script=3D"$(get instance/attributes/startup-script)" - - # Execute the script - if [ "${script:0:2}" =3D "#!" ]; then - echo "${script}" > /tmp/gcp-startup.script - chmod 700 /tmp/gcp-startup.script - - # Run the script - local now=3D"$(date -u +"%s")" - /tmp/gcp-startup.script &>/var/log/startup-script.log.${now} - - # Delete the script right away - rm /tmp/gcp-startup.script - fi - fi - # Import network configuration # After this, no network connectivity will be available from this script du= e to the # renaming of the network interfaces for which they have to be shut down @@ -249,6 +230,22 @@ import_gcp_configuration() { echo "2,ACCEPT,INPUTFW,ON,std_net_src,ALL,ipfire,RED1,,TCP,,,ON,,,TGT_POR= T,444,,,,,,,,,,,00:00,00:00,,AUTO,,dnat,,,,,second" ) >> /var/ipfire/firewall/input =20 + # Download a startup script + local script=3D"$(get instance/attributes/startup-script)" + + # Execute the script + if [ "${script:0:2}" =3D "#!" ]; then + echo "${script}" > /tmp/gcp-startup.script + chmod 700 /tmp/gcp-startup.script + + # Run the script + local now=3D"$(date -u +"%s")" + /tmp/gcp-startup.script &>/var/log/startup-script.log.${now} + + # Delete the script right away + rm /tmp/gcp-startup.script + fi + # This script has now completed the first steps of setup touch /var/ipfire/main/firstsetup_ok fi diff --git a/src/initscripts/helper/oci-setup b/src/initscripts/helper/oci-se= tup index 782fde5a2..312014b74 100644 --- a/src/initscripts/helper/oci-setup +++ b/src/initscripts/helper/oci-setup @@ -147,28 +147,6 @@ import_oci_configuration() { fi done <<<"$(get instance/metadata/ssh_authorized_keys)" =20 - # Download the user-data script only on the first boot - if [ ! -e "/var/ipfire/main/firstsetup_ok" ]; then - # Download a startup script - local script=3D"$(get instance/metadata/user_data)" - - # Try to decode this - script=3D"$(try_base64_decode "${script}")" - - # Execute the script - if [ "${script:0:2}" =3D "#!" ]; then - echo "${script}" > /tmp/user-data.script - chmod 700 /tmp/user-data.script - - # Run the script - local now=3D"$(date -u +"%s")" - /tmp/user-data.script &>/var/log/user-data.log.${now} - - # Delete the script right away - rm /tmp/user-data.script - fi - fi - # Import network configuration # After this, no network connectivity will be available from this script du= e to the # renaming of the network interfaces for which they have to be shut down @@ -285,6 +263,25 @@ import_oci_configuration() { echo "2,ACCEPT,INPUTFW,ON,std_net_src,ALL,ipfire,RED1,,TCP,,,ON,,,TGT_POR= T,444,,,,,,,,,,,00:00,00:00,,AUTO,,dnat,,,,,second" ) >> /var/ipfire/firewall/input =20 + # Download a startup script + local script=3D"$(get instance/metadata/user_data)" + + # Try to decode this + script=3D"$(try_base64_decode "${script}")" + + # Execute the script + if [ "${script:0:2}" =3D "#!" ]; then + echo "${script}" > /tmp/user-data.script + chmod 700 /tmp/user-data.script + + # Run the script + local now=3D"$(date -u +"%s")" + /tmp/user-data.script &>/var/log/user-data.log.${now} + + # Delete the script right away + rm /tmp/user-data.script + fi + # This script has now completed the first steps of setup touch /var/ipfire/main/firstsetup_ok fi --=20 2.30.2 --===============6400892526971708496==--