Global InfraGlobal Infra Cloud

How-To: Linux

Common Linux operations on Global Infra: firewall, disks, sudo, yum, patching

Edit

Add Sudo Rules

Sudo rules are managed through IPA. Contact the SRE-A team to configure sudo access for your users on specific hosts.

Add a Firewall Rule

Firewall rules are managed through Puppet hiera configuration. See the Compute service documentation for details on managing iptables/firewalld rules.

Add a Disk

Additional disks can be provisioned through the Compute service and attached to your VMs via Terraform.

Add a Yum Repository

1. Create the repository and token

Use the automation stack to create your repository and token via Artifactory. The token will be available in Vault.

2. Add the token to hiera

Add the key to your hiera project’s private.eyaml:

password::yum_my_example_user_ro: >
  ENC[PKCS7,AAAA....

3. Declare the repository

Add yum_hh_repos at the correct level of your hiera hierarchy:

yum_hh_repos:
  'local-mynamespace-rpm-myrepo-release':
    desc: 'my repository description'
    baseurl: "https://artifactory.global.ingenico.com/artifactory/local-mynamespace-rpm-myrepo-release"
    username: yum_my_example_user_ro
    password: "%{lookup('password::yum_my_example_user_ro')}"
    enabled: 1
    gpgcheck: 1
    priority: 30
    gpgkey: 'RPM-GPG-KEY-myexisting-key'

If the GPG key is not already present, include the key content:

yum_hh_repos:
  'local-mynamespace-rpm-myrepo-release':
    desc: 'my repository description'
    baseurl: "https://artifactory.global.ingenico.com/artifactory/local-mynamespace-rpm-myrepo-release"
    username: yum_my_example_user_ro
    password: "%{lookup('password::yum_my_example_user_ro')}"
    enabled: 1
    gpgcheck: 1
    priority: 30
    gpgkey: 'RPM-GPG-KEY-local-mynamespace-rpm-myrepo-release'
    gpgkey_content: |
      -----BEGIN PGP PUBLIC KEY BLOCK-----
      Version: GnuPG v1
      ... YOUR GPG CONTENT HERE ...
      -----END PGP PUBLIC KEY BLOCK-----

A carriage return is needed after -----END PGP PUBLIC KEY BLOCK----- with the same indentation.

Add a Record to /etc/hosts

Add the following key to your hiera config:

base::hosts::other_host:
  - "# DC1/2/3 Preprod network gateways"
  - "10.133.33.111 csgateway0101e1.core.pp.eu.ginfra.net"
  - "10.135.33.69 csgateway0101e2.core.pp.eu.ginfra.net"
  - "10.137.33.69 csgateway0101e3.core.pp.eu.ginfra.net"

Patch Your Servers

Linux server patching is managed through the system patching strategy. Contact the SRE team or refer to the patching documentation for your environment.

On this page