Centos 安装Puppet

环境说明:

OS:CentOS 5.4 i386
puppetmaster    192.168.0.12    hostname: puppetmaster.info.com
client        192.168.0.64    hostname: client1.info.com

原理图:

1)         客户端通过facter收集客户端信息并发送至服务端
2)         连接服务端并请求catalog日志
3)         请求节点(node)的信息
4)         从服务器端接收节点(node)的实例
5)         编译代码(包括语法检查等工作)
6)         查询是否有exported 虚拟资源
7)         如有,则从数据库接收虚拟资源
8)         接收完整的catalog日志
9)         存储catalog日志到数据库
10)       客户端接收完整的catalog日志

一、 时间同步,并写入crontab

  1. 15 1 * * * /usr/sbin/ntpdate pool.ntp.org; hwclock -w >/dev/null 2>&1

二、 修改主机名,并写入/etc/hosts文件

Puppet 要求所有机器有完整的域名(FQDN),如果没有 DNS 服务器提供域名的话,可以在两台机器上设置主机名
(注意建议先设置主机名再安装 Puppet,因安装 Puppet 时会把主机名写入证书,客户端和服务端通信需要这个证书)

  1. 192.168.0.12 puppetmaster.info.com
  2. 192.168.0.64 client1.info.com

三、 安装ruby

  1. [[email protected] ~]# yum install ruby ruby-libs ruby-rdoc -y
  2. [[email protected] ~]# ruby --version
  3. ruby 1.8.5 (2006-08-25) [i386-linux]

我安装的是1.8.5 ,不要安装1.8.7 puppet 还不支持,( 我没试过,如果出现不支持的情况,注意一下这里。)

四、 安装facter

安装puppet之前必须先安装facter
facter是一个系统盘点工具,收集主的一些资料,比如CPU,主机IP等,它收集到值发送给puppet服务器端,服务器端就可以根据不同的条件来对不同的节点机器生成不同的puppet配置文件

puppet资源下载点 http://downloads.puppetlabs.com/

  1. [[email protected] src]# wget http://downloads.puppetlabs.com/facter/facter-1.6.8.tar.gz
  2. [[email protected] src]# tar xzvf facter-1.6.8.tar.gz
  3. [[email protected] src]# cd facter-1.6.8
  4. [[email protected] facter-1.6.8]# ruby install.rb

五、 安装puppet

  1. [[email protected] src]# wget http://downloads.puppetlabs.com/puppet/puppet-2.7.14.tar.gz
  2. [[email protected] src]# tar xzvf puppet-2.7.14.tar.gz
  3. [[email protected] src]# cd puppet-2.7.14
  4. [[email protected] puppet-2.7.14]# ruby install.rb

六、 复制配置文件

  1. [[email protected] puppet-2.7.14]# cp conf/redhat/fileserver.conf /etc/puppet/
  2. [[email protected] puppet-2.7.14]# cp conf/redhat/puppet.conf /etc/puppet/
  3. [[email protected] puppet-2.7.14]# cp conf/redhat/server.init /etc/init.d/puppetmaster

七、 设置puppetmaster 服务开机启动

  1. [[email protected] puppet-2.7.14]# ls -l /etc/init.d/puppetmaster
  2. -rwxr-xr-x 1 root root 3936 Sep 3 12:13 /etc/init.d/puppetmaster
  3. [[email protected] puppet-2.7.14]#
  4. [[email protected] puppet-2.7.14]# chkconfig --add puppetmaster
  5. [[email protected] puppet-2.7.14]# chkconfig --level 35 puppetmaster on

八、 创建puppet帐号

  1. [[email protected] puppet-2.7.14]# puppetmasterd --mkusers

1)确认是否生成清单文件夹

  1. [[email protected] puppet-2.7.14]# ls -l /etc/puppet/
  2. total 16
  3. -rw-r--r-- 1 root root 2552 Sep 3 12:11 auth.conf
  4. -rwxr-xr-x 1 root root 381 Sep 3 12:13 fileserver.conf
  5. drwxr-xr-x 2 root root 4096 Sep 3 12:17 manifests
  6. -rwxr-xr-x 1 root root 853 Sep 3 12:13 puppet.conf

2)确认系统生成puppet用户

  1. [[email protected] puppet-2.7.14]# id puppet
  2. uid=1002(puppet) gid=1002(puppet) groups=1002(puppet)
  3. [[email protected] puppet]# cat /etc/passwd |grep puppet
  4. puppet:x:1002:1002::/home/puppet:/bin/bash

3)保证/var/lib/puppet/rrd目录存在且属主是puppet

  1. [[email protected] puppet]# ls -l /var/lib/puppet/
  2. total 36
  3. drwxr-x--- 2 puppet puppet 4096 Sep 3 12:17 bucket
  4. drwxr-xr-x 2 root root 4096 Sep 3 12:17 facts
  5. drwxr-xr-x 2 root root 4096 Sep 3 12:17 lib
  6. drwxr-x--- 2 puppet puppet 4096 Sep 3 12:17 reports
  7. drwxr-x--- 2 puppet puppet 4096 Sep 3 12:17 rrd
  8. drwxr-x--- 2 puppet puppet 4096 Sep 3 12:17 server_data
  9. drwxrwx--x 8 puppet root 4096 Sep 3 12:26 ssl
  10. drwxr-xr-t 2 root root 4096 Sep 3 12:17 state
  11. drwxr-x--- 2 puppet puppet 4096 Sep 3 12:17 yaml

4)查看端口

  1. [[email protected] puppet]# netstat -Tanlp | grep 8140
  2. tcp 0 0 0.0.0.0:8140 0.0.0.0:* LISTEN 4556/ruby

5)打开防火墙的8140端口
#vi /etc/sysconfig/iptables

增加:

-A INPUT -m state --state NEW -m tcp -p tcp --dport 8140 -j ACCEPT

保存后重启防火墙:

#service iptables restart

客户端:

安装facter,puppet 同puppetmaster 一样。但复制的文件如下

  1. [[email protected] puppet-2.7.14]# cp conf/redhat/client.init /etc/init.d/puppet
  2. cp conf/redhat/puppet.conf /etc/puppet/
  3. [[email protected] puppet-2.7.14]# chkconfig --level 35 puppet on

创建puppet用户:

  1. [[email protected] puppet-2.7.14]# puppetd --mkusers
  2. Could not prepare for execution: Got 1 failure(s) while initializing: change from absent to present failed: Could not create user puppet: Executionof ‘/usr/sbin/useradd -g puppet -M puppet‘ returned 3: useradd: invalid numeric argument ‘puppet‘
  3. [[email protected] puppet-2.7.14]# groupadd puppet;useradd -g puppet -M puppet
  4. [[email protected] puppet-2.7.14]# service puppet start
  5. Starting puppet: [ OK ]

修改puppet.conf,设置10秒钟同步一次服务:

#vi /etc/puppet/puppet.conf
[agent]
server = puppetmaster.info.com
listen = true
report = true
runinterval = 10

重启服务器:

#service puppet restart

测试解析与puppetmaster端口是否畅通

点击(此处)折叠或打开

  1. [[email protected] puppet-2.7.14]# telnet puppetmaster.info.com 8140
  2. Trying 192.168.0.12...
  3. Connected to puppetmaster.info.com (192.168.0.12).
  4. Escape character is ‘^]‘.
  5. [[email protected] puppet-2.7.14]# puppetd --test --server puppetmaster.info.com
  6. warning: peer certificate won‘t be verified in this SSL session
  7. info: Caching certificate for ca
  8. warning: peer certificate won‘t be verified in this SSL session
  9. warning: peer certificate won‘t be verified in this SSL session
  10. info: Creating a new SSL certificate request for client1.info.com
  11. info: Certificate Request fingerprint (md5): 07:C9:D4:43:3C:3E:D6:D1:0A:B1:8B:71:DB:6B:9D:FE
  12. warning: peer certificate won‘t be verified in this SSL session
  13. warning: peer certificate won‘t be verified in this SSL session
  14. warning: peer certificate won‘t be verified in this SSL session
  15. Exiting; no certificate found and waitforcert is disabled

# puppetd --test --server puppetmaster.info.com命令是指puppetd 从 puppetmaster.info.com去读取
puppet配置文件. 第一次连接,双方会进行ssl证书的验证,这是一个新的客户端,在服务器端那里还没有被认证,因此需要在服务器端进行证书认证

以下这步批准证书是在服务端操作

查看当前待批准证书列表

点击(此处)折叠或打开

  1. [[email protected] ~]# puppetca -l
  2. client1.info.com (07:C9:D4:43:3C:3E:D6:D1:0A:B1:8B:71:DB:6B:9D:FE)

批准当前证书

点击(此处)折叠或打开

  1. [[email protected] ~]# puppetca -s client1.info.com
  2. notice: Signed certificate request for client1.info.com
  3. notice: Removing file Puppet::SSL::CertificateRequest client1.info.com at ‘/var/lib/puppet/ssl/ca/requests/client1.info.com.pem‘

查看验证签名,注意前面的+号,说明已经签名

点击(此处)折叠或打开

  1. [[email protected] ~]# puppetca -a --list
  2. + client1.info.com (03:BE:50:AE:72:1A:39:79:17:F4:E5:74:FD:CC:BC:8C)
  3. + puppetmaster.info.com (97:34:BF:26:A6:0E:E9:9C:DB:76:D3:53:D0:56:60:83) (alt names: DNS:puppet, DNS:puppet.info.com, DNS:puppetmaster.info.com)

如果要批准全部证书

点击(此处)折叠或打开

  1. puppetca -s -a
  2. 也可以在puppetmaster端的puppet.conf加入这行:
  3. autosign = true
  4. 服务端就自动签证书

回到客户端操作,从服务端取回已批准的证书

点击(此处)折叠或打开

  1. [[email protected] puppet-2.7.14]# puppetd --test --server puppetmaster.info.com
  2. warning: peer certificate won‘t be verified in this SSL session
  3. info: Caching certificate for client1.info.com
  4. info: Caching certificate_revocation_list for ca
  5. info: Caching catalog for client1.info.com
  6. info: Applying configuration version ‘1378188531

验证证书是否正确

点击(此处)折叠或打开

  1. 服务端:
  2. [[email protected] ~]# md5sum /var/lib/puppet/ssl/ca/signed/client1.info.com.pem
  3. 27a295f39a6b4a6c7ceb74c9c3a5084c /var/lib/puppet/ssl/ca/signed/client1.info.com.pem
  4. 客户端:
  5. [[email protected] puppet-2.7.14]# md5sum /etc/puppet/ssl/certs/client1.info.com.pem
  6. 27a295f39a6b4a6c7ceb74c9c3a5084c /etc/puppet/ssl/certs/client1.info.com.pem
  7. 出现修改主机名问题引起无法认证,需要重新申请证书,操作以下两个步骤:
  8. 服务端:
  9. [[email protected] ~]# rm /var/lib/puppet/ssl/ca/signed/client1.info.com.pem -rf
  10. 客户端:
  11. [[email protected] puppet-2.7.14]# rm /etc/puppet/ssl/certs/ -rf

功能测试

服务端:
建立pp文件测试
puppet的第一个执行的代码是在/etc/puppet/manifest/site.pp ,因此这个文件必须存在,而且其他的代码也要通过代码来调用.

点击(此处)折叠或打开

  1. [[email protected] ~]# vim /etc/puppet/manifests/site.pp
  2. node default {
  3. file {"/tmp/viong.txt":
  4. content=>"good,test pass!\nHello World!\n";}
  5. }

上面的代码对默认连入的puppet客户端执行一个操作,在/tmp目录生成一个viong.txt文件,内容是good,test pass! 回车换行Hello World!回车换行.

初次创建pp文件,需要重启puppetmaster

点击(此处)折叠或打开

  1. [[email protected] ~]# service puppetmaster restart
  2. Stopping puppetmaster: [ OK ]
  3. Starting puppetmaster: [ OK ]

客户端:

点击(此处)折叠或打开

  1. [[email protected] puppet-2.7.14]# puppetd --test --server puppetmaster.info.com
  2. info: Caching catalog for client1.info.com
  3. info: Applying configuration version ‘1378190404‘
  4. notice: /Stage[main]//Node[default]/File[/tmp/viong.txt]/ensure: defined content as ‘{md5}4750aa5be82dae5db286a5859700dd51‘
  5. notice: Finished catalog run in 0.03 seconds
  6. 如果报错
  7. [[email protected] puppet-2.7.14]# puppetd --test --server puppetmaster.info.com
  8. err: Could not retrieve catalog from remote server: Error 400 on SERVER: Could not parse for environment production: Syntax error at end of file; expected ‘}‘ at /etc/puppet/manifests/site.pp:4 on node client1.info.com
  9. warning: Not using cache on failed catalog
  10. err: Could not retrieve catalog; skipping run
  11. 可能是/etc/puppet/manifests/site.pp 这个文件书写格式有问题。

在客户端查看:

点击(此处)折叠或打开

  1. [[email protected] puppet-2.7.14]# ls -l /tmp/viong.txt
  2. -rw-r--r-- 1 root root 29 Sep 3 14:50 /tmp/viong.txt
  3. [[email protected] puppet-2.7.14]# cat /tmp/viong.txt
  4. good,test pass!
    Hello World!
时间: 2024-10-17 01:00:21

Centos 安装Puppet的相关文章

CentOS 6.4安装Puppet

CentOS安装Puppet 环境介绍:centos6.4x64 採用CentOS-6.4-x86_64-minimal.iso最小化安装 puppet版本号3.6.2.ruby1.8.7,facter1.7.1 Puppet 要求全部机器有完整的域名(FQDN),假设没有 DNS server提供域名的话.能够在两台机器上设置主机名(注意要先设置主机名再安装 Puppet,由于安装 Puppet 时会把主机名写入证书,client和服务端通信须要这个证书): # vi /etc/hosts 1

在CentOS 6.4上安装Puppet配置管理工具

在CentOS 6.4上安装Puppet配置管理工具 linux, puppetAdd comments 五052013 上篇说了下在ubuntu12.04上安装puppet,安装的版本为puppet2.7.11版本,今天尝试了下在CentOS6.4系统上安装puppet 3.1.1版本,本文参考chenshake的文章 ? 1 2 3 4 OS:centso 6.4 X64 Puppet 3.1.1 Puppet master: master.canghai.com Puppet client

自动化运维之centos 7上安装puppet,附工作原理图

环境说明: 192.168.154.137 master.localdomain #Puppet Server 192.168.154.138 agent1.localdomain #Puppet Agent 这里的机器名称不要有下划线等特殊符合,否则后面会报"the scheme puppet does not accept registry part"这样的错误信息. centos的官方软件库里面不包含puppet包,但是在epel项目里面有包含puppet包.epel 是一个对r

Puppet整合Foreman(二):安装puppet

一.设置主机名 [[email protected] ~]# vi /etc/sysconfig/network   HOSTNAME=puppet.ewin.com [[email protected] ~]#echo "10.99.1.30 puppet.ewp.com" >> /etc/hosts 二.安装Puppet 1.安装 [[email protected] ~]# rpm -ivh http://yum.puppetlabs.com/puppetlabs-r

源码安装 puppet 3.8.5

环境:CentOS 6.5 x86_64 安装依赖环境: ruby 1.8:yum安装 ruby gem:yum安装 openssl:yum安装 gcc 编译环境:yum安装 # yum install ruby gcc glibc rubygems openssl* 2. 安装好后可以安装 hiera.facter.puppet了. 下载源码包. puppet官方源码包下载地址: https://downloads.puppetlabs.com/ hiera版本:1.3.4 facter版本:

在CentOS6.1上安装puppet最新版本puppet-3.6.2版本问题

前述: 最近发现了一个问题,在CentOS6.4上安装puppet,直接安装一个puppet官方源即可,然后直接使用yum安装puppet. 但是现在在CentOS6.1上安装puppet-3.6.2,发现很多puppet所需要的依赖包的版本太高,而CentOS6.1提供的软件版本太低,无法满足puppet的安装,在安装puppet时会提示很多依赖包,需要安装,而这个安装无法通过yum安装,需要自己下载rpm包安装,特别麻烦. 后来想过安装低版本的puppet,比如安装3.2.4的,但是也可以,

centos_6.5 64位 安装puppet

我们先准备三台centos 6.5 x86_64机器,做好安装前的工作. OS: Centos 6.5 x86_64 Puppet master: master.com (192.168.37.72) Puppet clients: client1.com (192.168.37.83) Puppet clients: client2.com (192.168.37.82) 一.先做好安装的准备工作: 在master和client均关闭selinux,iptables: 停止iptables [

Puppet部署:安装puppet server、client

Puppet部署:安装puppet server.client puppet与其他手工操作工具有一个最大的区别就是 puppet的配置具有稳定性,因此你可以多次执行puppet,一旦你更新了你的配置文件,puppet就会根据配置文件来更改你的机器配置,通常每30分钟检查一次. AD:2014WOT全球软件技术峰会北京站 课程视频发布 puppet与其他手工操作工具有一个最大的区别就是 puppet的配置具有稳定性,因此你可以多次执行puppet, 一旦你更新了你的配置文件,puppet就会根据配

CentOS 安装redis 2.8.7

波折了好几下才装上 1.下载 wget http://download.redis.io/releases/redis-2.8.7.tar.gz 下载后的文件在当前目录里 redis-2.8.7.tar.gz 2.编译安装 tar xf redis-2.8.7.tar.gz cd redis-2.8.7 make make install 如果没有安装gcc的话会提示gcc not found 于是就需要安装一下gcc: yum -y install gcc 因为刚开始把yum的源换成163的了