您现在的位置: 万盛学电脑网 >> 程序编程 >> 服务器教程 >> 正文

在CentOS系统下安装Puppet和Puppet Foreman的教程

作者:佚名    责任编辑:admin    更新时间:2022-06-22

   一、系统环境:

  Centos6.4 x86_64

  192.168.6.171 puppet.domain.com

  192.168.6.173 agent1.domian.com

  二、关闭selinux 和 iptables(我这里是测试环境,也可以增加puppet端口8140)

  代码如下:

  setenforce 0

  /etc/init.d/iptables stop && chkconfig iptables off

  三、更改主机名、使用host解析

  代码如下:

  [root@test ~]# cat /etc/sysconfig/network // # 192.168.6.171

  NETWORKING=yes

  NETWORKING_IPV6=no

  HOSTNAME=puppet.domain.com

  [root@test ~]# cat /etc/hosts

  192.168.6.171 puppet.domain.com

  192.168.6.173 agent1.domain.com

  [root@test ~]cat /etc/sysconfig/network // # 192.168.6.173

  NETWORKING=yes

  NETWORKING_IPV6=no

  HOSTNAME=agent1.domain.com

  [root@test ~]# cat /etc/hosts

  192.168.6.171 puppet.domain.com

  192.168.6.173 agent1.domain.com

  四、安装yum源

  1、# 下载地址 https://lug.ustc.edu.cn/wiki/mirrors/help/centos

  代码如下:

  [root@puppet yum.repos.d]# cat CentOS-Base.repo

  # CentOS-Base.repo

  #

  # The mirror system uses the connecting IP address of the client and the

  # update status of each mirror to pick mirrors that are updated to and

  # geographically close to the client. You should use this for CentOS updates

  # unless you are manually picking other mirrors.

  #

  # If the mirrorlist= does not work for you, as a fall back you can try the

  # remarked out baseurl= line instead.

  #

  #

  [base]

  name=CentOS-$releasever - Base - mirrors.ustc.edu.cn

  baseurl=http://mirrors.ustc.edu.cn/centos/$releasever/os/$basearch/

  #mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=os

  gpgcheck=1

  gpgkey=http://mirrors.ustc.edu.cn/centos/RPM-GPG-KEY-CentOS-6

  #released updates

  [updates]

  name=CentOS-$releasever - Updates - mirrors.ustc.edu.cn

  baseurl=http://mirrors.ustc.edu.cn/centos/$releasever/updates/$basearch/

  #mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=updates

  gpgcheck=1

  gpgkey=http://mirrors.ustc.edu.cn/centos/RPM-GPG-KEY-CentOS-6

  #additional packages that may be useful

  [extras]

  name=CentOS-$releasever - Extras - mirrors.ustc.edu.cn

  baseurl=http://mirrors.ustc.edu.cn/centos/$releasever/extras/$basearch/

  #mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=extras

  gpgcheck=1

  gpgkey=http://mirrors.ustc.edu.cn/centos/RPM-GPG-KEY-CentOS-6

  #additional packages that extend functionality of existing packages

  [centosplus]

  name=CentOS-$releasever - Plus - mirrors.ustc.edu.cn

  baseurl=http://mirrors.ustc.edu.cn/centos/$releasever/centosplus/$basearch/

  #mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=centosplus

  gpgcheck=1

  enabled=0

  gpgkey=http://mirrors.ustc.edu.cn/centos/RPM-GPG-KEY-CentOS-6

  #contrib - packages by Centos Users

  [contrib]

  name=CentOS-$releasever - Contrib - mirrors.ustc.edu.cn

  baseurl=http://mirrors.ustc.edu.cn/centos/$releasever/contrib/$basearch/

  #mirrorlist=http://mirrorlist.centos.org/?release=$releasever&arch=$basearch&repo=contrib

  gpgcheck=1

  enabled=0

  gpgkey=http://mirrors.ustc.edu.cn/centos/RPM-GPG-KEY-CentOS-6

  2、安装puppet官方yum源

  代码如下:

  rpm -Uvh http://yum.puppetlabs.com/el/6Server/products/x86_64/puppetlabs-release-6-6.noarch.rpm

  五、安装ruby环境(master和agent端都要操作)

  代码如下:

  yum -y install ruby ruby-libs ruby-shadow

  [root@puppet yum.repos.d]# ruby -v //# 检查ruby版本

  ruby 1.8.7 (2011-06-30 patchlevel 352) [x86_64-linux]

  master:

  代码如下:

  yum -y install puppet-server

  agent:

  代码如下:

  yum -y install puppet

  六、puppet配置文件(看到外面很多的文档又是[main] [agent] [master] 把我都绕晕了 我就直接贴我的配置文件 很简单要改的东西很少)

  1、master端的配置文件

  代码如下:

  [root@pupet ~]# cd /etc/puppet/

  [root@pupet puppet]# cat puppet.conf

  [main]

  vardir = /var/lib/puppet // # 用来存放缓存数据、配置、客户端返回的报告及文件备份

  logdir = /var/log/puppet

  rundir = /var/run/puppet

  ssldir = $vardir/ssl // # 签发认证文件目录

  [master]

  reports = foreman,console,log // # 发送报告至console,foreman,log

  certname = puppet.domain.com // # 配置主机名是puppet.domain.com

  pluginsync = true // # 开启插件同步

  environment = production // # 指定运行环境是生产

  # /etc/init.d/puppetmaster start 启动puppetmaster

  2、agent端的配置文件

  代码如下:

  [root@agent ~]# cd /etc/puppet/

  [root@agent puppet]# cat puppet.conf

  [main]

  logdir = /var/log/puppet

  rundir = /var/run/puppet

  ssldir = $vardir/ssl

  pluginsync = true

  [agent]

  classfile = $vardir/classes.txt

  localconfig = $vardir/localconfigs

  #runinterval = 300

  listen = true

  report = true

  server = puppet.domain.com // #指定server端

  # /etc/init.d/puppet start 启动puppet agent

  七、puppet验证

  1、客户端发起验证

  代码如下:

  [root@agent1 yum.repos.d]# puppet agent --test --server puppet.domain.com

  Info: Caching certificate for ca

  Info: csr_attributes file loading from /etc/puppet/csr_attributes.yaml

  Info: Creating a new SSL certificate request for agent1.domain.com

  Info: Certificate Request fingerprint (SHA256): C0:BB:24:3B:4B:59:F1:63:3D:EA:C1:EB:5B:2D:84:68:23:BA:F3:3D:0A:E6:8C:0E:38:3F:9E:F3:40:24:9A:68

  Info: Caching certificate for ca

  Exiting; no certificate found and waitforcert is disabled

  2、服务端查看

  代码如下:

  [root@puppet puppet]# puppet cert --list --all

  "agent1.domain.com" (SHA256) C0:BB:24:3B:4B:59:F1:63:3D:EA:C1:EB:5B:2D:84:68:23:BA:F3:3D:0A:E6:8C:0E:38:3F:9E:F3:40:24:9A:68

  + "puppet.domain.com" (SHA256) AF:F9:25:75:0F:3A:C5:E2:B5:71:EE:4E:65:82:7A:C1:3E:20:74:EF:57:2D:2D:1D:E5:47:1D:03:76:A5:5C:07 (alt names: "DNS:puppet", "DNS:puppet.domain.com")

  3、服务端完成验证(显示+号代表添加进来了 没有的话是带添加的主机)

  代码如下:

  [root@puppet puppet]# puppet cert sign agent1.domain.com

  Notice: Signed certificate request for agent1.domain.com

  Notice: Removing file Puppet::SSL::CertificateRequest agent1.domain.com at '/var/lib/puppet/ssl/ca/requests/agent1.domain.com.pem'

  代码如下:

  [root@puppet puppet]# puppet cert --list --all

  + "agent1.domain.com" (SHA256) 70:00:4D:89:53:2B:A4:C4:16:C4:DA:F1:63:59:5A:7A:0C:26:47:3B:74:4D:1C:29:C3:1B:BF:2E:B1:F4:89:D5

  + "puppet.domain.com" (SHA256) AF:F9:25:75:0F:3A:C5:E2:B5:71:EE:4E:65:82:7A:C1:3E:20:74:EF:57:2D:2D:1D:E5:47:1D:03:76:A5:5C:07 (alt names: "DNS:puppet", "DNS:puppet.domain.com")

  4、服务端自动验