| [1858] | 1 | # install Squeeze |
|---|
| 2 | # Configure each drive with a 1G partition and a rest-of-the-space partition, as RAID |
|---|
| 3 | # Create a RAID1 for the 1G partitions |
|---|
| 4 | # Create a RAID1 for each pair of rest-of-the-space partitions |
|---|
| 5 | # Create an ext3 /boot on the 1G RAID1 |
|---|
| 6 | # Create an LVM volume group named after the machine's short hostname |
|---|
| 7 | # Create an LV called "swap" that is the same size as the machine's physical RAM |
|---|
| 8 | # Create an LV called "root" that is 50G ext4 |
|---|
| 9 | |
|---|
| 10 | # ??? F11 will suggest ext4, DON'T USE IT. |
|---|
| [1241] | 11 | # - New filesystem, so it's scary |
|---|
| 12 | # - The hosts can't mount it |
|---|
| 13 | # - Grub can't cope with it |
|---|
| 14 | |
|---|
| [1858] | 15 | # install useful utility packages |
|---|
| 16 | aptitude install htop ipmitool emacs23-nox vim memtest86 memtest86+ ntp ntpdate git |
|---|
| 17 | git config --global color.ui auto |
|---|
| 18 | |
|---|
| [1241] | 19 | # install Xen |
|---|
| [1858] | 20 | aptitude install xen-linux-system |
|---|
| [1859] | 21 | |
|---|
| [1241] | 22 | # download Debathena archive key, verify |
|---|
| [1859] | 23 | (aptitude install debian-keyring && |
|---|
| 24 | cd /tmp && |
|---|
| 25 | wget http://debathena.mit.edu/apt/debathena-archive.asc && |
|---|
| 26 | kcr_fingerprint=$(gpg --keyring /usr/share/keyrings/debian-keyring.gpg --no-default-keyring --list-keys --with-colons kcr@debian.org | grep ^pub | cut -f 5 -d :) && |
|---|
| 27 | gpg --primary-keyring /tmp/debathena.gpg --no-default-keyring --import debathena-archive.asc && |
|---|
| 28 | gpg --primary-keyring /tmp/debathena.gpg --no-default-keyring --refresh-keys && |
|---|
| 29 | gpg --primary-keyring /tmp/debathena.gpg --no-default-keyring --keyring /usr/share/keyrings/debian-keyring.gpg --list-sigs --with-colons debathena@mit.edu | grep ^sig | cut -d: -f5 | grep -q $kcr_fingerprint && |
|---|
| 30 | gpg --primary-keyring /tmp/debathena.gpg --no-default-keyring --export debathena@mit.edu | apt-key adv --import) |
|---|
| 31 | |
|---|
| [1858] | 32 | # add Debathena repos to etc/apt/sources.list.d |
|---|
| 33 | cat <<EOF > /etc/apt/sources.list.d/debathena.list |
|---|
| 34 | deb http://debathena.mit.edu/apt squeeze debathena debathena-config debathena-system openafs |
|---|
| 35 | deb-src http://debathena.mit.edu/apt squeeze debathena debathena-config debathena-system openafs |
|---|
| 36 | EOF |
|---|
| 37 | |
|---|
| 38 | # install host keytab |
|---|
| 39 | # install Debathena software (hit enter to take the defaults at the |
|---|
| 40 | # configuration prompts) |
|---|
| 41 | aptitude update |
|---|
| 42 | aptitude install debathena-clients debathena-ssh-server-config |
|---|
| [1241] | 43 | # compare packages with another server |
|---|
| [1858] | 44 | dpkg -l |
|---|
| [1241] | 45 | # reconfigure so that we can get an MTA, although we don't |
|---|
| [1858] | 46 | # want the hosts to accept mail (mail sent by smarthost; no local mail) |
|---|
| [1241] | 47 | # outgoing.mit.edu |
|---|
| [1858] | 48 | dpkg-reconfigure exim4-config |
|---|
| [1241] | 49 | # answer questions properly |
|---|
| 50 | # change root alias in /etc/aliases to be the same as scripts server |
|---|
| 51 | # reload it |
|---|
| 52 | newaliases |
|---|
| [1858] | 53 | # clone the xen config (/etc/xen) |
|---|
| 54 | git clone -b squeeze ssh://scripts@scripts.mit.edu/mit/scripts/git/xen.git /etc/xen |
|---|
| [1241] | 55 | # copy conserver config (we need to version this) |
|---|
| [1693] | 56 | # setup conserver |
|---|
| 57 | cat /etc/conserver/console.cf # add the correct entires here |
|---|
| 58 | visudo # add conservr to sudoers list with: |
|---|
| 59 | conservr ALL=(ALL) NOPASSWD: /usr/sbin/xm console * |
|---|