2014-12-16 18:41:30 +00:00
|
|
|
#cloud-config
|
|
|
|
|
2016-11-15 20:35:48 +00:00
|
|
|
hostname: {{ build_uuid | default('quay-builder', True) }}
|
|
|
|
|
2015-11-20 20:32:32 +00:00
|
|
|
users:
|
|
|
|
groups:
|
|
|
|
- sudo
|
|
|
|
- docker
|
|
|
|
|
2018-09-05 21:36:01 +00:00
|
|
|
{% if ssh_authorized_keys -%}
|
2015-01-29 23:40:17 +00:00
|
|
|
ssh_authorized_keys:
|
2018-09-05 21:36:01 +00:00
|
|
|
{% for ssh_key in ssh_authorized_keys -%}
|
|
|
|
- {{ ssh_key }}
|
|
|
|
{%- endfor %}
|
|
|
|
{%- endif %}
|
2015-01-29 23:40:17 +00:00
|
|
|
|
2014-12-16 18:41:30 +00:00
|
|
|
write_files:
|
2017-12-06 22:21:55 +00:00
|
|
|
- path: /root/disable-aws-metadata.sh
|
2018-01-05 18:26:59 +00:00
|
|
|
permission: '0755'
|
2017-12-06 22:21:55 +00:00
|
|
|
content: |
|
|
|
|
iptables -t nat -I PREROUTING -p tcp -d 169.254.169.254 --dport 80 -j DNAT --to-destination 1.1.1.1
|
|
|
|
|
2017-11-15 00:23:15 +00:00
|
|
|
- path: /etc/docker/daemon.json
|
|
|
|
permission: '0644'
|
|
|
|
content: |
|
|
|
|
{
|
|
|
|
"storage-driver": "overlay2"
|
|
|
|
}
|
|
|
|
|
2014-12-16 18:41:30 +00:00
|
|
|
- path: /root/overrides.list
|
|
|
|
permission: '0644'
|
|
|
|
content: |
|
|
|
|
REALM={{ realm }}
|
|
|
|
TOKEN={{ token }}
|
2016-07-08 17:01:02 +00:00
|
|
|
SERVER={{ websocket_scheme }}://{{ manager_hostname }}
|
2015-03-27 19:28:08 +00:00
|
|
|
{% if logentries_token -%}
|
|
|
|
LOGENTRIES_TOKEN={{ logentries_token }}
|
|
|
|
{%- endif %}
|
2014-12-16 18:41:30 +00:00
|
|
|
|
|
|
|
coreos:
|
|
|
|
update:
|
|
|
|
reboot-strategy: off
|
|
|
|
group: {{ coreos_channel }}
|
|
|
|
|
|
|
|
units:
|
2016-11-23 15:12:55 +00:00
|
|
|
- name: update-engine.service
|
|
|
|
command: stop
|
|
|
|
- name: locksmithd.service
|
|
|
|
command: stop
|
2015-03-27 20:31:35 +00:00
|
|
|
- name: systemd-journal-gatewayd.socket
|
|
|
|
command: start
|
|
|
|
enable: yes
|
|
|
|
content: |
|
|
|
|
[Unit]
|
|
|
|
Description=Journal Gateway Service Socket
|
|
|
|
[Socket]
|
|
|
|
ListenStream=/var/run/journald.sock
|
|
|
|
Service=systemd-journal-gatewayd.service
|
|
|
|
[Install]
|
|
|
|
WantedBy=sockets.target
|
2015-02-10 20:43:01 +00:00
|
|
|
{{ dockersystemd('quay-builder',
|
2018-09-05 21:36:01 +00:00
|
|
|
worker_image,
|
2015-02-10 20:43:01 +00:00
|
|
|
quay_username,
|
|
|
|
quay_password,
|
|
|
|
worker_tag,
|
|
|
|
extra_args='--net=host --privileged --env-file /root/overrides.list -v /var/run/docker.sock:/var/run/docker.sock -v /usr/share/ca-certificates:/etc/ssl/certs',
|
|
|
|
exec_stop_post=['/bin/sh -xc "/bin/sleep 120; /usr/bin/systemctl --no-block poweroff"'],
|
|
|
|
flattened=True,
|
|
|
|
restart_policy='no'
|
|
|
|
) | indent(4) }}
|
2015-03-27 19:28:08 +00:00
|
|
|
{% if logentries_token -%}
|
2016-11-14 21:28:17 +00:00
|
|
|
# https://github.com/kelseyhightower/journal-2-logentries/pull/11 so moved journal-2-logentries to coreos
|
2015-03-27 19:28:08 +00:00
|
|
|
{{ dockersystemd('builder-logs',
|
2016-11-14 21:28:17 +00:00
|
|
|
'quay.io/coreos/journal-2-logentries',
|
2015-03-27 19:28:08 +00:00
|
|
|
extra_args='--env-file /root/overrides.list -v /run/journald.sock:/run/journald.sock',
|
2015-05-20 20:34:16 +00:00
|
|
|
flattened=True,
|
2015-03-27 20:31:35 +00:00
|
|
|
after_units=['quay-builder.service']
|
2015-03-27 19:28:08 +00:00
|
|
|
) | indent(4) }}
|
|
|
|
{%- endif %}
|
2017-12-06 22:21:55 +00:00
|
|
|
- name: disable-aws-metadata.service
|
|
|
|
command: start
|
|
|
|
enable: yes
|
|
|
|
content: |
|
|
|
|
[Unit]
|
|
|
|
Description=Disable AWS metadata service
|
|
|
|
Before=network-pre.target
|
|
|
|
Wants=network-pre.target
|
|
|
|
[Service]
|
|
|
|
Type=oneshot
|
|
|
|
ExecStart=/root/disable-aws-metadata.sh
|
|
|
|
RemainAfterExit=yes
|
|
|
|
[Install]
|
|
|
|
WantedBy=multi-user.target
|
2016-06-17 20:03:40 +00:00
|
|
|
- name: machine-lifetime.service
|
|
|
|
command: start
|
|
|
|
enable: yes
|
|
|
|
content: |
|
|
|
|
[Unit]
|
|
|
|
Description=Machine Lifetime Service
|
|
|
|
[Service]
|
|
|
|
Type=oneshot
|
2018-09-05 21:36:01 +00:00
|
|
|
ExecStart=/bin/sh -xc "/bin/sleep {{ max_lifetime_s }}; /usr/bin/systemctl --no-block poweroff"
|