How-To: Linux
Common Linux operations on Global Infra: firewall, disks, sudo, yum, patching
Add Sudo Rules
Sudo rules are managed through IPA. Contact the SRE-A team to configure sudo access for your users on specific hosts.
Add a Firewall Rule
Firewall rules are managed through Puppet hiera configuration. See the Compute service documentation for details on managing iptables/firewalld rules.
Add a Disk
Additional disks can be provisioned through the Compute service and attached to your VMs via Terraform.
Add a Yum Repository
1. Create the repository and token
Use the automation stack to create your repository and token via Artifactory. The token will be available in Vault.
2. Add the token to hiera
Add the key to your hiera project’s private.eyaml:
password::yum_my_example_user_ro: >
ENC[PKCS7,AAAA....3. Declare the repository
Add yum_hh_repos at the correct level of your hiera hierarchy:
yum_hh_repos:
'local-mynamespace-rpm-myrepo-release':
desc: 'my repository description'
baseurl: "https://artifactory.global.ingenico.com/artifactory/local-mynamespace-rpm-myrepo-release"
username: yum_my_example_user_ro
password: "%{lookup('password::yum_my_example_user_ro')}"
enabled: 1
gpgcheck: 1
priority: 30
gpgkey: 'RPM-GPG-KEY-myexisting-key'If the GPG key is not already present, include the key content:
yum_hh_repos:
'local-mynamespace-rpm-myrepo-release':
desc: 'my repository description'
baseurl: "https://artifactory.global.ingenico.com/artifactory/local-mynamespace-rpm-myrepo-release"
username: yum_my_example_user_ro
password: "%{lookup('password::yum_my_example_user_ro')}"
enabled: 1
gpgcheck: 1
priority: 30
gpgkey: 'RPM-GPG-KEY-local-mynamespace-rpm-myrepo-release'
gpgkey_content: |
-----BEGIN PGP PUBLIC KEY BLOCK-----
Version: GnuPG v1
... YOUR GPG CONTENT HERE ...
-----END PGP PUBLIC KEY BLOCK-----A carriage return is needed after -----END PGP PUBLIC KEY BLOCK----- with the same indentation.
Add a Record to /etc/hosts
Add the following key to your hiera config:
base::hosts::other_host:
- "# DC1/2/3 Preprod network gateways"
- "10.133.33.111 csgateway0101e1.core.pp.eu.ginfra.net"
- "10.135.33.69 csgateway0101e2.core.pp.eu.ginfra.net"
- "10.137.33.69 csgateway0101e3.core.pp.eu.ginfra.net"Patch Your Servers
Linux server patching is managed through the system patching strategy. Contact the SRE team or refer to the patching documentation for your environment.