在Linux上安裝Chef工作站

來源:互聯網
上載者:User

在Linux上安裝Chef工作站
導讀Chef是一個IT基礎設施自動化軟體,它可以管理你組織中所有的伺服器和網路裝置。當我們想與Chef伺服器、任何物理節點(伺服器、網路裝置等)的基礎設施進行互動時,我們需要一個Chef工作站。本教程解釋如何安裝和配置Linux伺服器上Chef工作站。

下載 ChefDK

ChefDK是Chef Development Kit的縮寫,它幾乎用於所有的平台,包括基於Debian發行版、Ubuntu、RedHat、CentOS、Mac OS X和Windows。當前ChefDK的穩定版本是0.11.2,對於基於RHEL的系統,它可用於版本 6 和 7(如: CentOS 6 和 CentOS 7),RPM版本只有64位版本。

使用以下命令下載ChefDK
在CentOS 7上

cd ~wget https://packages.chef.io/stable/el/7/chefdk-0.11.2-1.el7.x86_64.rpm

在CentOS 6上

cd ~wget https://packages.chef.io/stable/el/6/chefdk-0.11.2-1.el6.x86_64.rpm
安裝 ChefDK

使用RPM安裝剛剛下載的ChefDK

# rpm -ivh chefdk-0.11.2-1.el7.x86_64.rpm Preparing...                          ################################# [100%]Updating / installing...   1:chefdk-0.11.2-1.el7              ################################# [100%]Thank you for installing Chef Development Kit!

ChefDK預設安裝到/opt/chefdk目錄下,如下所示

# ls -l /opt/chefdk/drwxr-xr-x. 2 root root  4096 Mar  3 13:50 bindrwxr-xr-x. 7 root root    62 Mar  3 13:50 embedded-rw-r--r--. 1 root root 13249 Feb 22 14:26 version-manifest.json-rw-r--r--. 1 root root  8233 Feb 22 14:26 version-manifest.txt
驗證ChefDK的安裝

執行chef verify,驗證所有來自ChefDK的不同組件,確保他們都工作正常,沒有任何問題

# chef verifyRunning verification for component 'berkshelf'Running verification for component 'test-kitchen'Running verification for component 'tk-policyfile-provisioner'Running verification for component 'chef-client'Running verification for component 'chef-dk'Running verification for component 'chef-provisioning'Running verification for component 'chefspec'Running verification for component 'generated-cookbooks-pass-chefspec'Running verification for component 'rubocop'Running verification for component 'fauxhai'Running verification for component 'knife-spork'Running verification for component 'kitchen-vagrant'Running verification for component 'package installation'Running verification for component 'openssl'Running verification for component 'inspec'.......---------------------------------------------Verification of component 'test-kitchen' succeeded.Verification of component 'chef-dk' succeeded.Verification of component 'chefspec' succeeded.Verification of component 'rubocop' succeeded.Verification of component 'knife-spork' succeeded.Verification of component 'openssl' succeeded.Verification of component 'berkshelf' succeeded.Verification of component 'chef-client' succeeded.Verification of component 'fauxhai' succeeded.Verification of component 'inspec' succeeded.Verification of component 'tk-policyfile-provisioner' succeeded.Verification of component 'kitchen-vagrant' succeeded.Verification of component 'chef-provisioning' succeeded.Verification of component 'package installation' succeeded.Verification of component 'generated-cookbooks-pass-chefspec' succeeded.

下面是chef verify失敗的案例。注意:Ruby在Chef中是必須的,它被嵌入在了ChefDK中。

# chef verify../opt/chefdk/embedded/lib/ruby/gems/2.1.0/gems/mixlib-shellout-2.2.6/lib/mixlib/shellout.rb:289:in `invalid!': Expected process to exit with [0], but received '1' (Mixlib::ShellOut::ShellCommandFailed)---- Begin output of /usr/bin/ohai -v ----STDOUT: STDERR: /opt/chefdk/embedded/lib/ruby/site_ruby/2.1.0/rubygems/dependency.rb:319:in `to_specs': Could not find 'chef-config' (= 12.8.0) - did find: [chef-config-12.7.2] (Gem::LoadError)

以上錯誤資訊顯示:“Could not find ‘chef-config’ (= 12.8.0) – did find: [chef-config-12.7.2] (Gem::LoadError)”,在安裝的ChefDK中chef-config的版本是12.7.2的舊版本,在手動安裝chef-confg 12.8.0版本後再執行chef verify,顯示驗證成功。

驗證ChefDK版本

執行 chef -version命令,顯示ChefDK的版本號碼以及所有附帶組件

# chef --versionChef Development Kit Version: 0.11.2chef-client version: 12.7.2berks version: 4.2.0kitchen version: 1.5.0
設定Chef 環境變數

設定Chef相關的環境變數,如:GEM_ROOT GEM_HOME GEM_PATH。

export GEM_ROOT="/opt/chefdk/embedded/lib/ruby/gems/2.1.0"export GEM_HOME="/root/.chefdk/gem/ruby/2.1.0"export GEM_PATH="/root/.chefdk/gem/ruby/2.1.0:/opt/chefdk/embedded/lib/ruby/gems/2.1.0"

此外,如果你的系統上已經安裝了ruby,你需要更新與ruby相關的PATH變數,如下所示

export PATH="/opt/chefdk/bin:/root/.chefdk/gem/ruby/2.1.0/bin:/opt/chefdk/embedded/bin:/opt/chefdk/bin:/root/.chefdk/gem/ruby/2.1.0/bin:/opt/chefdk/embedded/bin:/opt/chefdk/bin:/root/.chefdk/gem/ruby/2.1.0/bin:/opt/chefdk/embedded/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/root/bin"

顯示所有Chef設定的環境變數。

chef shell-init bash

想要快速設定這些環境變數,可以將其添加到bash_profile檔案中,如下所示。

echo 'eval "$(chef shell-init bash)"' >> ~/.bash_profile
訪問Chef的Firewalld規則

為了訪問Chef伺服器上的Chef Manage GUI,添加以下firewalld規則,開放Chef伺服器上的相應連接埠。

firewall-cmd --direct  --add-rule ipv4 \filter INPUT_direct 0 -i eth0 -p tcp \ --dport 443 -j ACCEPTfirewall-cmd --direct  --add-rule ipv4 \filter INPUT_direct 0 -i eth0 -p tcp \ --dport 80 -j ACCEPTfirewall-cmd --direct  --add-rule ipv4 \filter INPUT_direct 0 -i eth0 -p tcp \ --dport 9683 -j ACCEPTfirewall-cmd --reload
從Chef Manage GUI下載Starter Kit

登入到Chef Manage GUI,單擊“Administration”選項,從列表中選擇“organization”。此例中,“organization”為“example”,選中organization之後,點擊左側菜單中的“Starter Kit”。

按下“Download(下載)”按鈕之後,會跳出一個警告資訊,按下“Proceed”,它會將chef-starter.zip檔案下載到本地機器。

解壓縮 Starter Kit

將chef-starter.zip檔案傳輸到Chef工作站並解壓到root的home目錄下

# cd ~# unzip chef-starter.zip Archive:  chef-starter.zip   creating: chef-repo/cookbooks/   creating: chef-repo/cookbooks/starter/   creating: chef-repo/cookbooks/starter/templates/   creating: chef-repo/cookbooks/starter/templates/default/  inflating: chef-repo/cookbooks/starter/templates/default/sample.erb     creating: chef-repo/cookbooks/starter/files/   creating: chef-repo/cookbooks/starter/files/default/  inflating: chef-repo/cookbooks/starter/files/default/sample.txt     creating: chef-repo/cookbooks/starter/recipes/  inflating: chef-repo/cookbooks/starter/recipes/default.rb     creating: chef-repo/cookbooks/starter/attributes/  inflating: chef-repo/cookbooks/starter/attributes/default.rb    inflating: chef-repo/cookbooks/starter/metadata.rb    inflating: chef-repo/cookbooks/chefignore    inflating: chef-repo/README.md       inflating: chef-repo/.gitignore       creating: chef-repo/.chef/   creating: chef-repo/roles/  inflating: chef-repo/.chef/knife.rb    inflating: chef-repo/roles/starter.rb    inflating: chef-repo/.chef/ramesh.pem    inflating: chef-repo/.chef/example-validator.pem

如果你手動建立了chef-repo檔案夾,那你就需要手動建立上述的子目錄,複製knife.rb檔案、organization-validator.pem檔案(如:example-validator.pem)、username.pem檔案(如:ramesh.pem)到上面顯示的目錄中。

Chef伺服器的SSL認證

在這個階段如果執行knife client list會得到以下錯誤資訊

# cd ~/chef-repo# knife client listERROR: SSL Validation failure connecting to host: centos.example.com - SSL_connect returned=1 errno=0 state=error: certificate verify failedERROR: Could not establish a secure connection to the server.Use `knife ssl check` to troubleshoot your SSL configuration.If your Chef Server uses a self-signed certificate, you can use`knife ssl fetch` to make knife trust the server's certificates.Original Exception: OpenSSL::SSL::SSLError: SSL Error connecting to https://centos.example.com/organizations/example/clients - SSL_connect returned=1 errno=0 state=error: certificate verify failed

認證驗證失敗,因為我們沒有從Chef伺服器下載SSL認證,此時可以執行以下“knife ssl fetch”。

# cd ~/chef-repo# knife ssl fetchWARNING: Certificates from centos.example.com will be fetched and placed in your trusted_certdirectory (/root/chef-repo/.chef/trusted_certs).Knife has no means to verify these are the correct certificates. You shouldverify the authenticity of these certificates after downloading.

認證將會下載到以下truster_certs目錄中

# ls -l /root/chef-repo/.chef/trusted_certs-rw-r--r--. 1 root root 1379 Mar 20 20:17 centos_example_com.crt# cat /root/chef-repo/.chef/trusted_certs/centos_example_com.crt -----BEGIN CERTIFICATE-----MIIDzDCCArSgAwIBAgIBADANBgkqhkiG9w0BAQsFADBRMQswCQYDVQQGEwJVUzEQMA4GA1UECgwHWW91Q29ycDETMBEGA1UECwwKT3BlcmF0aW9uczEbMBkGA1UEAwwSZXJhdGlvbnMxGzAZBgNVBAMMEmNlbnRvcy5leGFtcGxlLmNvbTCCASIwDQYJKoZI....WLyr2ORLMcck/OGsubabO/koMNTqhl2JJPECNiDJh06MeZ/2+BOwGZSpXDbw+vFENJAsLfsTzihGWZ58einMFA==-----END CERTIFICATE-----
Chef工作站的最終確認

如果Chef工作站工作正常,當你執行“knife client list”時,它會顯示所有串連工作站的用戶端。由於我們剛剛安裝它,因此只能看到剛剛我們建立的組織(organization)

# cd ~/chef-repo# knife client listexample-validator

如果你現有的Chef工作站機器上已經有5個伺服器串連到它了,你會看到以下資訊

# knife client listexample-validatornode1node2node3node4node5

原文來自:http://www.thegeekstuff.com/作者:Ramesh Natarajan


譯者:燁子

轉載地址:http://www.linuxprobe.com/chef-workstation-install-linux.html


聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.