Showing posts with label CentOS. Show all posts
Showing posts with label CentOS. Show all posts

Tuesday, 11 April 2023

Install Terraform on CentOS Stream 9 Server


Install Terraform from the Terraform Repository


sudo dnf install dnf-utils


sudo yum-config-manager --add-repo https://rpm.releases.hashicorp.com/RHEL/hashicorp.repo

Adding repo from: https://rpm.releases.hashicorp.com/RHEL/hashicorp.repo


sudo dnf repolist

repo id              repo name

appstream            CentOS Stream 9 - AppStream

baseos               CentOS Stream 9 - BaseOS

extras-common        CentOS Stream 9 - Extras packages

hashicorp            Hashicorp Stable - x86_64


sudo dnf install terraform -y


sudo dnf --showduplicate list terraform


terraform version

Terraform v1.4.4

on linux_amd64


Ref:- install-terraform-on-centos-stream-9-server


Wednesday, 15 February 2023

Build RPM From Scratch in RHEL 9


cat /etc/redhat-release

CentOS Stream release 9


RPM:- Package Manager and the package format used by many Linux distributions such as Fedora, RedHat, and CentOS to manage and distribute software in binary form.


rpmbuild directory is known as the root directory for the rpm build environment

tree rpmbuild

rpmbuild

├── BUILD

├── RPMS

├── SOURCES

├── SPECS

└── SRPMS


BUILD        - directory, where the source code of the program want to package, is built

RPMS         - where the rpm packages generated

SOURCES   - have compressed source code of the software inthe form of a tarball or a zip file.

SPECS   - have a .spec file with instructions to build the package

SRPMS   - same as RPMS, but for source RPMS. these special packages contain the original source code of the application.


the spec file is where all instructions and information needed to build an rpm package are defined.


 Build RPM: Example to build an RPM Create a local yum repo.

#as root

yum repolist

yum install -y rpmdevtools rpm-build

mv /etc/yum.repos.d/centos.repo /tmp

yum repolist

ls -l /etc/yum.repos.d/


#su to user account (recommended)

rpmdev-setuptree

ls -l rpmbuild

tree rpmbuild

rpmbuild

├── BUILD

├── RPMS

├── SOURCES

├── SPECS

└── SRPMS


5 directories, 0 files


cd rpmbuild/SOURCES/

ls

mkdir -p localrepo-1/etc/yum.repos.d/

ls

localrepo-1


Mount RHEL 9 ISO File or DVD

sudo mkdir /var/repo

sudo mount -o loop rhel-baseos-9.0-x86_64-dvd.iso /var/repo/

sudo mount /dev/sr0 /var/repo/

vim localrepo-1/etc/yum.repos.d/RHEL9local.repo

[Local-BaseOS]

name=Red Hat Enterprise Linux 9 - BaseOS

metadata_expire=-1

gpgcheck=1

enabled=1

baseurl=file:///var/repo/BaseOS/

gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release


[Local-AppStream]

name=Red Hat Enterprise Linux 9 - AppStream

metadata_expire=-1

gpgcheck=1

enabled=1

baseurl=file:///var/repo/AppStream/

gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-redhat-release


 tar -cvzf localrepo-1.tar.gz localrepo-1/

localrepo-1/

localrepo-1/etc/

localrepo-1/etc/yum.repos.d/

localrepo-1/etc/yum.repos.d/RHEL9local.repo


cd ../SPECS/

ls

#create spec file

rpmdev-newspec localrepo.spec

localrepo.spec created; type minimal, rpm version >= 4.16.


 vim localrepo.spec

Name:           localrepo

Version:        1

Release:        0

Summary:        Local Repo For RHEL 9


Group:          System Environment/Base

License:        GPL

URL:            https://www.linuxmissive.com/

Source0:        localrepo-1.tar.gz

BuildArch:      noarch

BuildRoot:      %{_tmppath}/%{name}-buildroot


%description

Create a local yum repo file in /etc/yum.repos.d/ directory.


%prep

%setup -q


%install

mkdir -p "$RPM_BUILD_ROOT"

cp -R * "$RPM_BUILD_ROOT"


%clean

rm -rf $RPM_BUILD_ROOT


%files

%defattr(-,root,root,-)

/etc/yum.repos.d/RHEL9local.repo


%changelog

* Wed Feb 15 2023 Jojan Paul <jpmolekunnel@gmail.com>

-


cd 

#build now

rpmbuild -v -bb rpmbuild/SPECS/localrepo.spec

rpm -qpl rpmbuild/RPMS/noarch/localrepo-1-0.noarch.rpm 

/etc/yum.repos.d/RHEL9local.repo


#install rpm as root

su -

 rpm -ivh /home/devops/rpmbuild/RPMS/noarch/localrepo-1-0.noarch.rpm


rpm -qa | grep localrepo

localrepo-1-0.noarch


 cd /etc/yum.repos.d/

 ls

centos-addons.repo  RHEL9local.repo


#check yum repo working after installing rpm package

yum repolist

repo id                      repo name

Local-AppStream              Red Hat Enterprise Linux 9 - AppStream

Local-BaseOS                 Red Hat Enterprise Linux 9 - BaseOS

extras-common                CentOS Stream 9 - Extras packages


#test

yum install httpd


Sunday, 25 December 2022

Add Swap Space on CentOS 9 Stream


To Add 1GB Swap Space 


#create swap file

 sudo dd if=/dev/zero of=/swapfile bs=1024 count=1048576

1048576+0 records in

1048576+0 records out

1073741824 bytes (1.1 GB, 1.0 GiB) copied, 19.8022 s, 54.2 MB/s


#set permission

sudo chmod 600 /swapfile


#set up swap area file

sudo mkswap /swapfile

Setting up swapspace version 1, size = 1024 MiB (1073737728 bytes)

no label, UUID=53c7c8d2-ed2d-4f61-b263-79a4dcd94304


#activate swap

 sudo swapon /swapfile


sudo swapon --show

NAME      TYPE       SIZE USED PRIO

/dev/dm-1 partition  2.1G   4M   -2

/swapfile file      1024M   0B   -3


sudo free -h

               total        used        free      shared  buff/cache   available

Mem:           1.7Gi       898Mi        69Mi        12Mi       970Mi       852Mi

Swap:          3.1Gi       4.0Mi       3.1Gi


#make permenant entry

sudo vim /etc/fstab

/swapfile swap swap defaults 0 0



Monday, 7 September 2015

Chef Installation and configure on CentOS



Install chef-server
iptables -F
rpm -ivh chef-server-11.1.7-1.el6.x86_64

Configure Chef Server

chef-server-ctl reconfigure

Running handlers:
Running handlers complete
Chef Client finished, 415/479 resources updated in 220.548599949 seconds
Chef Server Reconfigured!

Confirm Chef server is running by,

chef-server-ctl status
run: bookshelf: (pid 1084) 60730s; run: log: (pid 1083) 60730s
run: chef-expander: (pid 1080) 60730s; run: log: (pid 1079) 60730s
run: chef-server-webui: (pid 1070) 60730s; run: log: (pid 1068) 60730s
run: chef-solr: (pid 1076) 60730s; run: log: (pid 1073) 60730s
run: erchef: (pid 1085) 60730s; run: log: (pid 1082) 60730s
down: nginx: 0s, normally up, want up; run: log: (pid 1078) 60730s
run: postgresql: (pid 1091) 60730s; run: log: (pid 1072) 60730s
run: rabbitmq: (pid 1075) 60730s; run: log: (pid 1071) 60730s


Optionally, run the Opscode Pedant test suite. This will verify that everything is working.
chef-server-ctl test

Configure Chef Workstation

check Chef client pkg is already installed or not

rpmquery chef
package chef is not installed

rpm -ivh chef-11.18.12-1.el6.x86_64

rpmquery chef
chef-11.18.12-1.el6.x86_64

chef-client
To Secure communication with Chef server,

copy files from chef server path /etc/chef-server to chef workstation
scp -r admin.pem chef-validator.pem chef-webui.pem root@10.98.33.204:/root/.chef
admin.pem
chef-validator.pem
chef-webui.pem

mkdir .chef @ home and mv all 3 files inside dir

knife configure -i
Overwrite /root/.chef/knife.rb? (Y/N)Y
Please enter the chef server URL: [https://testchefwork.example.com:443] https://testchefserver.example.com:443
Please enter a name for the new user: [root]
Please enter the existing admin name: [admin] admin
Please enter the location of the existing admin's private key: [/etc/chef-server/admin.pem] /root/.chef/admin.pem
Please enter the validation clientname: [chef-validator]
Please enter the location of the validation key: [/etc/chef-server/chef-validator.pem] /root/.chef/chef-validator.pem
Please enter the path to a chef repository (or leave blank):
Creating initial API user...
Please enter a password for the new user:
Created user[root]
Configuration file written to /root/.chef/knife.rb

knife ssl fetch

knife ssl check

Connecting to host testchefserver.example.com:443
ERROR: The SSL certificate of testchefserver.example.com could not be verified
Certificate issuer data: /C=US/ST=WA/L=Seattle/O=YouCorp/OU=Operations/CN=testchefserver.example.com/emailAddress=you@example.com

Configuration Info:

OpenSSL Configuration:
* Version: OpenSSL 1.0.1m 19 Mar 2015
* Certificate file: /opt/chef/embedded/ssl/cert.pem
* Certificate directory: /opt/chef/embedded/ssl/certs
Chef SSL Configuration:
* ssl_ca_path: nil
* ssl_ca_file: nil
* trusted_certs_dir: "/root/.chef/trusted_certs"

TO FIX THIS ERROR:

If the server you are connecting to uses a self-signed certificate, you must
configure chef to trust that server's certificate.

By default, the certificate is stored in the following location on the host
where your chef-server runs:

  /var/opt/chef-server/nginx/ca/SERVER_HOSTNAME.crt

Copy that file to you trusted_certs_dir (currently: /root/.chef/trusted_certs)
using SSH/SCP or some other secure method, then re-run this command to confirm
that the server's certificate is now trusted.

knife ssl check
Connecting to host testchefserver.example.com:443
Successfully verified certificates from `testchefserver.example.com'

knife client list

chef-validator
chef-webui
 knife user list
admin
jojan
root

Node configuration

iptables -L

 rpm -ivh chef-11.18.12-1.el6.x86_64.rpm

warning: chef-11.18.12-1.el6.x86_64.rpm: Header V4 DSA/SHA1 Signature, key ID 83ef826a: NOKEY
Preparing...                ########################################### [100%]
   1:chef                   ########################################### [100%]
Thank you for installing Chef!

copy chef-validator.pem from chef server path /etc/chef-server to /etc/chef in Node server

knife ssl fetch -s https://testchefserver.example.com

WARNING: No knife configuration file found
WARNING: Certificates from testchefserver.example.com will be fetched and placed in your trusted_cert
directory ().

Knife has no means to verify these are the correct certificates. You should
verify the authenticity of these certificates after downloading.

ERROR: TypeError: can't convert nil into String

 knife ssl check
Connecting to host testchefserver.example.com:443
Successfully verified certificates from `testchefserver.example.com'
[root@testchefnode .chef]# knife ssl fetch -s https://testchefserver.example.com
WARNING: Certificates from testchefserver.example.com will be fetched and placed in your trusted_cert
directory (/root/.chef/trusted_certs).

Knife has no means to verify these are the correct certificates. You should
verify the authenticity of these certificates after downloading.

Adding certificate for testchefserver.example.com in /root/.chef/trusted_certs/testchefserver_example_com.crt

knife ssl check -s https://testchefserver.example.com

Connecting to host testchefserver.example.com:443
Successfully verified certificates from `testchefserver.example.com'

cat /etc/chef/client.rb
log_level :info
log_location STDOUT
chef_server_url "https://testchefserver.example.com:443"
trusted_certs_dir "/root/.chef/trusted_certs"

chef-client -S https://testchefserver.example.com -K /etc/chef/chef-validator.pem

creating a recipe on workstation and upload to server

knife cookbook create motd
** Creating cookbook motd
** Creating README for cookbook: motd
** Creating CHANGELOG for cookbook: motd
** Creating metadata for cookbook: motd

cd /var/chef/cookbooks/motd

ls -l
attributes
CHANGELOG.md
definitions
files
libraries
metadata.rb
providers
README.md
recipes
resources
templates

cd recipes/
vi default.rb

file '/etc/motd' do
        content 'Welcome to chef'
end

Before uploading to server make sure there is no syntax error

knife cookbook test motd
checking motd
Running syntax check on motd
Validating ruby files
Validating templates
Validating ruby files
Validating templates

upload to server,

knife cookbook upload motd
Uploading motd         [0.1.0]
Uploaded 1 cookbook.

to chk from server

knife cookbook list
motd   0.1.0

to chek from dashboard,
https://testchefserver.example.com/cookbooks

Add cookbook to a node,

go to https://testchefserver.example.com/nodes and edit
drag and drop Available Recipes moted to Run List,

chef-client
[2015-09-07T11:17:30+05:30] INFO: Forking chef instance to converge...
[2015-09-07T11:17:30+05:30] WARN:
........................................
- update content in file /etc/motd from e3b0c4 to cad802
    --- /etc/motd       2010-01-12 18:58:22.000000000 +0530
    +++ /tmp/.motd20150907-26207-mb0jjs 2015-09-07 11:17:32.622947241 +0530
    @@ -1 +1,2 @@
    +Welcome to chef
    - restore selinux security context
[2015-09-07T11:17:32+05:30] INFO: Chef Run complete in 0.661581977 seconds

Running handlers:
[2015-09-07T11:17:32+05:30] INFO: Running report handlers
Running handlers complete
[2015-09-07T11:17:32+05:30] INFO: Report handlers complete
Chef Client finished, 1/1 resources updated in 2.350334219 seconds

now cat it in node server,

cat /etc/motd
Welcome to chef

Ref:- https://www.youtube.com/watch?v=egvEPsVMfK0

Wednesday, 2 September 2015

Disable FirewallD and use iptables in RHEL 7 and CentOS 7


If you want to use iptables on CentOS 7 and RHEL 7 instead of firewallD Please follow,

systemctl mask firewalld

systemctl stop firewalld

yum -y install iptables-services

systemctl enable iptables

Ref: http://www.tejasbarot.com/2014/08/02/rhel-7-centos-7-disable-firewalld-and-use-iptables/#axzz3keP3fIkw


Thursday, 14 June 2012

Install Nagios on CentOS/Fedora

* Nagios and the plugins will be installed underneath /usr/local/nagios
* Nagios will be configured to monitor a few aspects of your local system (CPU load, disk usage, etc.)
* The Nagios web interface will be accessible at http://localhost/nagios/

Prerequisites

Make sure that the following packages are installed

    * Apache
    * PHP
    * GCC compiler
    * GD development libraries

yum install httpd php

yum install gcc glibc glibc-common

yum install gd gd-devel

Create a new nagios user account and give it a password

/usr/sbin/useradd -m nagios

passwd nagios

Create a new nagcmd group for allowing external commands to be submitted through the web interface. Add both the nagios user and the apache user to the group.

/usr/sbin/groupadd nagcmd

/usr/sbin/usermod -a -G nagcmd nagios

/usr/sbin/usermod -a -G nagcmd apache

Download Nagios and the Plugins

http://www.nagios.org/download/

Compile and Install Nagios

Extract the Nagios source code tarball.
tar xzf nagios-3.2.3.tar.gz

cd nagios-3.2.3

Run the Nagios configure script, passing the name of the group created earlier
./configure --with-command-group=nagcmd

Compile the Nagios source code.

make all

Install binaries, init script, sample config files and set permissions on the external command directory.

make install

make install-init

make install-config

make install-commandmode

Customize Configuration

vi /usr/local/nagios/etc/objects/contacts.cfg

Configure the Web Interface

Install the Nagios web config file in the Apache conf.d directory.

make install-webconf


Create a nagiosadmin account for logging into the Nagios web interface. Remember the password you assign to this account – you’ll need it later.

htpasswd -c /usr/local/nagios/etc/htpasswd.users nagiosadmin


Restart Apache to make the new settings take effect.

service httpd restart

Compile and Install the Nagios Plugins

Extract the Nagios plugins source code tarball.

cd ~/downloads

tar xzf nagios-plugins-1.X.tar.gz

cd nagios-plugins-1.X.

Compile and install the plugins.

./configure --with-nagios-user=nagios --with-nagios-group=nagios

make

make install

Start Nagios

Add Nagios to the list of system services and have it automatically start when the system boots.

chkconfig --add nagios

chkconfig nagios on

Verify the sample Nagios configuration files.

/usr/local/nagios/bin/nagios -v /usr/local/nagios/etc/nagios.cfg

If there are no errors, start Nagios.

service nagios start

Modify SELinux Settings

See if SELinux is in Enforcing mode.

getenforce

Put SELinux into Permissive mode.

setenforce 0

To make this change permanent, you’ll have to modify the settings in /etc/selinux/config and reboot.

Login to the Web Interface

Access the Nagios web interface at the URL below, prompted for the username (nagiosadmin) and password you specified earlier.

http://localhost/nagios/







Reference:- http://cuongk6t.wordpress.com/2011/06/07/how-to-install-nagios-on-centos-6-or-fedora/



Friday, 11 May 2012

CentOS LAMP Install via YUM

CentOS Apache Install

yum install httpd

/etc/init.d/httpd start

chkconfig httpd on


CentOS MySQL Server Install

yum install mysql-server mysql

/etc/init.d/mysqld start

chkconfig mysqld on


CentOS PHP & php-mysql Install

To install PHP and php-mysql (php-mysql is required so that PHP can talk to MySQL)

yum install php php-mysql


FYI here is the full CentOS LAMP command (this will install Apache, MySQL & PHP)

yum install httpd php php-mysql mysql mysql-server