infra/image/system-services: Enhance checks, also fix reverse zone

Checks for IPv4 addresses have been added and reverse zone handling
for fixipaip.sh

The services are logging StandardOutput and StandardError to journal
now.
This commit is contained in:
Thomas Woerner
2024-08-02 17:00:12 +02:00
parent 7dbe6edbf0
commit e05fbce04c
4 changed files with 115 additions and 17 deletions

View File

@@ -5,6 +5,8 @@ After=multi-user.target
[Service] [Service]
Type=oneshot Type=oneshot
ExecStart=/root/fixipaip.sh ExecStart=/root/fixipaip.sh
StandardOutput=journal
StandardError=journal
[Install] [Install]
WantedBy=default.target WantedBy=default.target

View File

@@ -1,26 +1,82 @@
#!/bin/bash -eu #!/bin/bash -eu
function valid_fqdn()
{
local name="${1}"
[[ "${name}" =~ [[:space:]] ]] && return 1
[[ "${name}" =~ \. ]] || return 1
[[ "${name}" =~ \.\. ]] && return 1
for i in ${name//./ }; do
[[ "${i}" =~ ^[a-z0-9_/]+$ ]] || return 1
done
[[ "${name}" == "localhost.localdomain" ]] && return 1
return 0
}
function valid_ipv4()
{
local ip="${1}"
local rematch="^([0-9]{1,3}\.){3}[0-9]{1,3}$"
[[ "${ip}" =~ ${rematch} ]] || return 1
for i in ${ip//./ }; do
[[ ${i} -le 255 ]] || return 1
done
return 0
}
HOSTNAME=$(hostname) HOSTNAME=$(hostname)
IP=$(hostname -I | cut -d " " -f 1) IP=$(hostname -I | cut -d " " -f 1)
export KRB5CCNAME=ansible_freeipa_cache
if [ -z "${HOSTNAME}" ]; then if [ -z "${HOSTNAME}" ] || ! valid_fqdn "${HOSTNAME}" ; then
echo "ERROR: Failed to retrieve hostname." echo "ERROR: Got invalid hostname: '${HOSTNAME}'"
exit 1 exit 1
fi fi
if [ -z "${IP}" ]; then if [ -z "${IP}" ] || ! valid_ipv4 "${IP}" ; then
echo "ERROR: Failed to retrieve IP address." echo "ERROR: Got invalid IPv4 address: '${IP}'"
exit 1
fi
PTR=$(echo "${IP}" | awk -F"." '{print $4}')
if [ -z "${PTR}" ] || [ -n "${PTR//[0-9]}" ]; then
echo "ERROR: Failed to get PTR from IPv4 address: '${PTR}'"
exit 1 exit 1
fi fi
if ! echo "SomeADMINpassword" | kinit -c ansible_freeipa_cache admin echo "Fix IPA IP:"
echo " HOSTNAME: '${HOSTNAME}'"
echo " IP: '${IP}'"
echo " PTR: '${PTR}'"
if ! echo "SomeADMINpassword" | kinit -c "${KRB5CCNAME}"
then then
echo "ERROR: Failed to obtain Kerberos ticket" echo "ERROR: Failed to obtain Kerberos ticket"
exit 1 exit 1
fi fi
KRB5CCNAME=ansible_freeipa_cache \
ipa dnsrecord-mod test.local "${HOSTNAME%%.*}" --a-rec="$IP" ZONES=$(ipa dnszone-find --name-from-ip="${HOSTNAME}." --raw --pkey-only \
KRB5CCNAME=ansible_freeipa_cache \ | grep "idnsname:" | awk -F": " '{print $2}')
ipa dnsrecord-mod test.local ipa-ca --a-rec="$IP" for zone in ${ZONES}; do
kdestroy -c ansible_freeipa_cache -A echo
if [[ "${zone}" == *".in-addr.arpa."* ]]; then
echo "Fixing reverse zone ${zone}:"
OLD_PTR=$(ipa dnsrecord-find "${zone}" --ptr-rec="${HOSTNAME}." \
--raw | grep "idnsname:" | awk -F": " '{print $2}')
if [ -z "${OLD_PTR}" ] || [ -n "${OLD_PTR//[0-9]}" ]; then
echo "ERROR: Failed to get old PTR from '${zone}': '${OLD_PTR}'"
else
ipa dnsrecord-mod "${zone}" "${OLD_PTR}" --ptr-rec="${HOSTNAME}." \
--rename="${PTR}"
fi
else
echo "Fixing forward zone ${zone}:"
ipa dnsrecord-mod test.local "${HOSTNAME%%.*}" --a-rec="$IP"
ipa dnsrecord-mod test.local ipa-ca --a-rec="$IP"
fi
done
kdestroy -c "${KRB5CCNAME}" -A
exit 0 exit 0

View File

@@ -7,6 +7,8 @@ Before=ipa.service
[Service] [Service]
Type=oneshot Type=oneshot
ExecStart=/root/fixnet.sh ExecStart=/root/fixnet.sh
StandardOutput=journal
StandardError=journal
[Install] [Install]
WantedBy=ipa.service WantedBy=ipa.service

View File

@@ -1,24 +1,62 @@
#!/bin/bash -eu #!/bin/bash -eu
function valid_fqdn()
{
local name="${1}"
[[ "${name}" =~ [[:space:]] ]] && return 1
[[ "${name}" =~ \. ]] || return 1
[[ "${name}" =~ \.\. ]] && return 1
for i in ${name//./ }; do
[[ "${i}" =~ ^[a-z0-9_/]+$ ]] || return 1
done
[[ "${name}" == "localhost.localdomain" ]] && return 1
return 0
}
function valid_ipv4()
{
local ip="${1}"
local rematch="^([0-9]{1,3}\.){3}[0-9]{1,3}$"
[[ "${ip}" =~ ${rematch} ]] || return 1
for i in ${ip//./ }; do
[[ ${i} -le 255 ]] || return 1
done
return 0
}
HOSTNAME=$(hostname) HOSTNAME=$(hostname)
IP=$(hostname -I | cut -d " " -f 1) IP=$(hostname -I | cut -d " " -f 1)
if [ -z "${HOSTNAME}" ]; then if [ -z "${HOSTNAME}" ] || ! valid_fqdn "${HOSTNAME}" ; then
echo "ERROR: Failed to retrieve hostname." echo "ERROR: Failed to retrieve hostname."
exit 1 exit 1
fi fi
if [ -z "${IP}" ]; then if [ -z "${IP}" ] || ! valid_ipv4 "${IP}" ; then
echo "ERROR: Failed to retrieve IP address." echo "ERROR: Got invalid IPv4 address: '${IP}'"
exit 1 exit 1
fi fi
# shellcheck disable=SC2143 echo "Fix NET:"
if [ -n "$(grep -P "[[:space:]]${HOSTNAME}" /etc/hosts)" ]; then echo " HOSTNAME: '${HOSTNAME}'"
sed -ie "s/.*${HOSTNAME}/${IP}\t${HOSTNAME}/" /etc/hosts echo " IP: '${IP}'"
echo
if grep -qE "^[^(#\s*)][0-9\.]+\s$HOSTNAME(\s|$)" /etc/hosts
then
sed -i.bak -e "s/.*${HOSTNAME}/${IP}\t${HOSTNAME}/" /etc/hosts
else else
echo -e "$IP\t${HOSTNAME}" >> /etc/hosts echo -e "$IP\t${HOSTNAME} ${HOSTNAME%%.*}" >> /etc/hosts
fi fi
echo "nameserver 127.0.0.1" > /etc/resolv.conf echo "nameserver 127.0.0.1" > /etc/resolv.conf
echo "/etc/hosts:"
cat "/etc/hosts"
echo
echo "/etc/resolv.conf:"
cat "/etc/resolv.conf"
exit 0 exit 0