1902e5bd1SLuigi RizzoIMPORTANT NOTE:
2902e5bd1SLuigi Rizzo
3902e5bd1SLuigi RizzoAs of Feb. 11, 2002 (and indeed, for quite some time before that),
4902e5bd1SLuigi Rizzothe /etc/rc.diskless{1,2} scripts support a slightly different
5902e5bd1SLuigi Rizzodiskless boot process than the one documented in the rest of
6902e5bd1SLuigi Rizzothis file (which is 3 years old).
7902e5bd1SLuigi Rizzo
8902e5bd1SLuigi RizzoI am not deleting the information below because it contains some
9902e5bd1SLuigi Rizzouseful background information on diskless operation, but for the
10902e5bd1SLuigi Rizzoactual details you should look at /etc/rc.diskless1, /etc/rc.diskless2,
11902e5bd1SLuigi Rizzoand the /usr/share/examples/diskless/clone_root script which can
12902e5bd1SLuigi Rizzobe useful to set up clients and server for diskless boot.
13902e5bd1SLuigi Rizzo
14902e5bd1SLuigi Rizzo--- $FreeBSD$ ---
15902e5bd1SLuigi Rizzo------------------------------------------------------------------------
163606882cSMatthew Dillon
173606882cSMatthew Dillon		      TEMPLATING machine configurations
183606882cSMatthew Dillon
193606882cSMatthew Dillon			    Matthew Dillon
203606882cSMatthew Dillon			    [email protected]
213606882cSMatthew Dillon
223606882cSMatthew Dillon    This document describes a general mechanism by which you can template
233606882cSMatthew Dillon    / and /usr.  That is, to keep a 'master template' of / and /usr on a
243606882cSMatthew Dillon    separate machine which is then used to update the rest of your machines.
253606882cSMatthew Dillon
263606882cSMatthew Dillon    Generally speaking, you can't simply mirror /.  You might be able to
273606882cSMatthew Dillon    get away with mirroring /usr.  There are two main problems involved with
283606882cSMatthew Dillon    templating:
293606882cSMatthew Dillon
303606882cSMatthew Dillon    (1) Avoiding overwriting run-time generated files
313606882cSMatthew Dillon
323606882cSMatthew Dillon	By default, the system maintains a number of files in the root
333606882cSMatthew Dillon	partition.  For example, sendmail will dbm /etc/aliases into
343606882cSMatthew Dillon	/etc/aliases.db.  vipw or chpass or other password related routines
353606882cSMatthew Dillon	will regenerate the password dbm's /etc/spwd.db, /etc/pwd.db, and
363606882cSMatthew Dillon	passwd.  /etc/namedb/s might contain generated secondaries.  And
373606882cSMatthew Dillon	so forth.
383606882cSMatthew Dillon
393606882cSMatthew Dillon	The templating mechanism must avoid copying over such files.
403606882cSMatthew Dillon
413606882cSMatthew Dillon    (2) Customizing machines.
423606882cSMatthew Dillon
433606882cSMatthew Dillon	Customizing machines is actually considerably simpler.  You create
443606882cSMatthew Dillon	a configuration hierarchy and convert the configuration files that
453606882cSMatthew Dillon	have to be customized into softlinks that run through a special
463606882cSMatthew Dillon	softlink in the configuration directory.  This will work for every
473606882cSMatthew Dillon	configuration file except possibly /etc/master.passwd
483606882cSMatthew Dillon
493606882cSMatthew Dillon	For example, /etc/resolv.conf would be turned into a softlink to
503606882cSMatthew Dillon	/conf/ME/resolv.conf, and /conf/ME itself would be a softlink to
513606882cSMatthew Dillon	/conf/<HOSTNAME>.  The actual resolv.conf configuration file
523606882cSMatthew Dillon	would reside in /conf/<HOSTNAME>.
533606882cSMatthew Dillon
543606882cSMatthew Dillon	If you have a lot of hosts, some configuration files may be commonly
553606882cSMatthew Dillon	classified.  For example, all your shell machines might have the
563606882cSMatthew Dillon	same /etc/resolv.conf.  The solution is to make
573606882cSMatthew Dillon	/conf/<HOSTNAME>/resolv.conf a softlink to a common directory, say
583606882cSMatthew Dillon	/conf/HT.SHELL/resolv.conf.  It may sound a little messy, but this
593606882cSMatthew Dillon	sort of categorization actually makes the sysadmins job much, much
603606882cSMatthew Dillon	easier.
613606882cSMatthew Dillon
623606882cSMatthew Dillon	The /conf/ directory hierarchy is stored on the template and
633606882cSMatthew Dillon	distributed to all the machines along with the rest of the root
643606882cSMatthew Dillon	partition.
653606882cSMatthew Dillon
663606882cSMatthew Dillon	This type of customization is taken from my direct experience
673606882cSMatthew Dillon	instituting such a system at BEST.  At the time, BEST had over 45
683606882cSMatthew Dillon	machines managed from a single template.
693606882cSMatthew Dillon
703606882cSMatthew Dillon		RUN-TIME GENERATED OR MODIFIED FILES IN / or /USR
713606882cSMatthew Dillon
723606882cSMatthew Dillon	/etc/aliases.db
733606882cSMatthew Dillon	/etc/master.passwd
743606882cSMatthew Dillon	/etc/spwd.db
753606882cSMatthew Dillon	/etc/pwd.db
763606882cSMatthew Dillon	/etc/passwd
773606882cSMatthew Dillon	/etc/namedb/s
783606882cSMatthew Dillon	/root/.history
793606882cSMatthew Dillon	/root/.ssh/identity
803606882cSMatthew Dillon	/root/.ssh/identity.pub
813606882cSMatthew Dillon	/root/.ssh/random_seed
823606882cSMatthew Dillon	/root/.ssh/known_hosts
833606882cSMatthew Dillon	/conf/ME
843606882cSMatthew Dillon	/kernel*	( note 2 )
853606882cSMatthew Dillon	/dev	( note 3 )
863606882cSMatthew Dillon	/var	( note 4 )
873606882cSMatthew Dillon	/home	( note 4 )
883606882cSMatthew Dillon	/lost+found
893606882cSMatthew Dillon
903606882cSMatthew Dillon	/usr/lost+found
913606882cSMatthew Dillon	/usr/home	( note 4 )
923606882cSMatthew Dillon	/usr/crash	( note 5 )
933606882cSMatthew Dillon	/usr/obj	( note 5 )
943606882cSMatthew Dillon	/usr/ports	( note 5 )
953606882cSMatthew Dillon	/usr/src	( note 5 )
963606882cSMatthew Dillon	/usr/local/crack ( note 5 )
97*2394cc22SEitan Adler	/usr/local/lib/X11/xdm/xdm-errors ( note 6 )
98*2394cc22SEitan Adler	/usr/local/lib/X11/xdm/xdm-pid 	  ( note 6 )
993606882cSMatthew Dillon	/usr/local/etc/ssh_host_key	  ( note 6 )
1003606882cSMatthew Dillon	/usr/local/etc/ssh_host_key.pub	  ( note 6 )
1013606882cSMatthew Dillon	/usr/local/etc/ssh_random_seed	  ( note 6 )
1023606882cSMatthew Dillon
1033606882cSMatthew Dillon	/conf/ME	( note 7 )
1043606882cSMatthew Dillon
1053606882cSMatthew Dillon	note 2:	You typically want to update kernels manually and *NOT*
1063606882cSMatthew Dillon		template them as a safety measure.  This also allows you to run
1073606882cSMatthew Dillon		different kernels on different machines or.
1083606882cSMatthew Dillon
1093606882cSMatthew Dillon	note 3: /dev must be updated manually.  Some devices, such as tty's and
1103606882cSMatthew Dillon		pty's, use the access and/or modify time and/or user/group
1113606882cSMatthew Dillon		operationally and regenerating the devices on the fly would be
1123606882cSMatthew Dillon		bad.
1133606882cSMatthew Dillon
1143606882cSMatthew Dillon	note 4:	/var and /home are usually separately mounted partitions and
1153606882cSMatthew Dillon		thus would not fall under the template, but as a safety measure
1163606882cSMatthew Dillon		the template copier refuse to copy directories named 'home'.
1173606882cSMatthew Dillon
1183606882cSMatthew Dillon	note 5: These are directories that are as often created directly on
1193606882cSMatthew Dillon		/usr as they are separately-mounted partitions.  You typically
1203606882cSMatthew Dillon		do not want to template such directories.
1213606882cSMatthew Dillon
1223606882cSMatthew Dillon	note 6: Note that you can solve the problem of xdm and sshd creating
123*2394cc22SEitan Adler		files in /usr.  With xdm, edit /usr/local/lib/xdm/xdm-config
1243606882cSMatthew Dillon		and change the errorLogFile and pidFile config lines.
1253606882cSMatthew Dillon
1263606882cSMatthew Dillon		With sshd, add 'HostKey' and 'RandomSeed' directives to specify
1273606882cSMatthew Dillon		/var/db for the location of the host key and run-time sshd
1283606882cSMatthew Dillon		random seed:
1293606882cSMatthew Dillon
1303606882cSMatthew Dillon		HostKey /var/db/ssh_host_key
1313606882cSMatthew Dillon		RandomSeed /var/db/ssh_random_seed
1323606882cSMatthew Dillon
1333606882cSMatthew Dillon	note 7: In this example, /conf/ME is the machine customizer and must
1343606882cSMatthew Dillon		be pointed to the /conf/<full-host-name>/ directory, which is
1353606882cSMatthew Dillon		different for each machine.  Thus, the /conf/ME softlink
1363606882cSMatthew Dillon		should never be overwritten by the templating copy.
1373606882cSMatthew Dillon
1383606882cSMatthew Dillon
1395665fe6bSUlrich Spörlein		TYPICAL CUSTOMIZED CONFIGURATION SOFTLINKS
1403606882cSMatthew Dillon
1413606882cSMatthew Dillon    The following files typically need to be turned into softlinks
1423606882cSMatthew Dillon    to /conf/ME/<filename>:
1433606882cSMatthew Dillon
1443606882cSMatthew Dillon	/etc/ccd.conf		-> /conf/ME/ccd.conf
1453606882cSMatthew Dillon	/etc/ipfw.conf		...
1463606882cSMatthew Dillon	/etc/fstab
1473606882cSMatthew Dillon	/etc/motd
1483606882cSMatthew Dillon	/etc/resolv.conf
1493606882cSMatthew Dillon	/etc/aliases
1503606882cSMatthew Dillon	/etc/sendmail.cw
1513606882cSMatthew Dillon	/etc/organization
1523606882cSMatthew Dillon	/etc/named.conf
1533606882cSMatthew Dillon	/etc/rc.conf.local
1543606882cSMatthew Dillon	/etc/printcap
1553606882cSMatthew Dillon	/etc/inetd.conf
1563606882cSMatthew Dillon	/etc/login.conf
1573606882cSMatthew Dillon	/etc/gettytab
1583606882cSMatthew Dillon	/etc/ntp.conf
1593606882cSMatthew Dillon	/etc/exports
1603606882cSMatthew Dillon	/root/.k5login		-> /conf/ME/root/.k5login
1613606882cSMatthew Dillon
1623606882cSMatthew Dillon    And, of course, /conf/ME is usually a softlink to the appropriate
1633606882cSMatthew Dillon    /conf/<full-host-name>/.  Depending on your system configuration,
1643606882cSMatthew Dillon    there may be other files not listed above that you have to worry about.
1653606882cSMatthew Dillon
166321bc15bSMatthew Dillon    In many cases, /conf/ME/filename is itself a softlink to
167321bc15bSMatthew Dillon    "../HT.xxxx/filename", where HT.xxxx is something like HT.STD ... this
168321bc15bSMatthew Dillon    added complexity actually makes it easier to manage multiple
169321bc15bSMatthew Dillon    classifications of machines.
170321bc15bSMatthew Dillon
1713606882cSMatthew Dillon				DELETION OF FILES
1723606882cSMatthew Dillon
1733606882cSMatthew Dillon    Any file found on the template destination that does not exist in the
1743606882cSMatthew Dillon    source and is not listed as an exception by the source should be deleted.
1753606882cSMatthew Dillon    However, deletion can be dangerous and cpdup will ask for confirmation
1763606882cSMatthew Dillon    by default.  Once you know you aren't going to blow things up, you can
1773606882cSMatthew Dillon    turn this feature off and update your systems automatically from cron.
1783606882cSMatthew Dillon
1793606882cSMatthew Dillon    By formalizing the delete operation, you can be 100% sure that it is
1803606882cSMatthew Dillon    possible to recreate / and /usr on any machine with only the original
1813606882cSMatthew Dillon    template and a backup of the ( relatively few ) explicitly-excepted
1823606882cSMatthew Dillon    files.  The most common mistake a sysop makes is to make a change to a
1833606882cSMatthew Dillon    file in / or /usr on a target machine instead of the template machine.
1843606882cSMatthew Dillon    If the target machine is updated once a night from cron, the sysop
1853606882cSMatthew Dillon    quickly learns not to do this ( because his changes get overwritten
186202c735fSSimon L. B. Nielsen    overnight ).  With a manual update, these sorts of mistakes can propagate
1873606882cSMatthew Dillon    for weeks or months before they are caught.
1883606882cSMatthew Dillon
1893606882cSMatthew Dillon			    TEMPLATE COPYING AND SAFETY
1903606882cSMatthew Dillon			       THE CPDUP PROGRAM
1913606882cSMatthew Dillon
1923606882cSMatthew Dillon    The 'cpdup' program is a program which efficiently duplicates a directory
1933606882cSMatthew Dillon    tree.  The program copies source to destination, duplicating devices,
1943606882cSMatthew Dillon    softlinks, hardlinks, files, modification times, uid, gid, flags, perms,
1953606882cSMatthew Dillon    and so forth.  The program incorporates several major features:
1963606882cSMatthew Dillon
197202c735fSSimon L. B. Nielsen	*   The program refuses, absolutely, to cross partition boundaries.
1983606882cSMatthew Dillon	    i.e. if you were copying the template /usr from an NFS mount to
1993606882cSMatthew Dillon	    your /usr, and you had a mount point called /usr/home, the
2003606882cSMatthew Dillon	    template copying program would *NOT* descend into /usr/home on
2013606882cSMatthew Dillon	    the destination.
2023606882cSMatthew Dillon
2033606882cSMatthew Dillon	    This is a safety.
2043606882cSMatthew Dillon
2053606882cSMatthew Dillon	*   The program accesses a file called .cpignore in each directory
206202c735fSSimon L. B. Nielsen	    it descends into on the source to obtain a list of exceptions
2073606882cSMatthew Dillon	    for that directory -- that is, files not to copy or mess with.
2083606882cSMatthew Dillon
2093606882cSMatthew Dillon	    This is a templating function.
2103606882cSMatthew Dillon
2113606882cSMatthew Dillon	*   The program refuses to delete a directory on the destination
2123606882cSMatthew Dillon	    being replaced by a softlink or file on the source.
2133606882cSMatthew Dillon
2143606882cSMatthew Dillon	    This is a safety mechanism
2153606882cSMatthew Dillon
216c52721b9SMike Pritchard	*   The program is capable of maintaining MD5 check cache files and
2173606882cSMatthew Dillon	    doing an MD5 check between source and destination during the
2183606882cSMatthew Dillon	    scan.
2193606882cSMatthew Dillon
2203606882cSMatthew Dillon	*   The program is capable of deleting files/directories on the
2213606882cSMatthew Dillon	    destination that do not exist on the source, but asks for
2223606882cSMatthew Dillon	    confirmation by default.
2233606882cSMatthew Dillon
2243606882cSMatthew Dillon	    This is a templating and a safety mechanism.
2253606882cSMatthew Dillon
2263606882cSMatthew Dillon	*   The program uses a copy-to-tmp-and-rename methodology allowing
2273606882cSMatthew Dillon	    it to be used to update live filesystems.
2283606882cSMatthew Dillon
2293606882cSMatthew Dillon	    This is a templating mechanism.
2303606882cSMatthew Dillon
2313606882cSMatthew Dillon	*   The program, by default, tries to determine if a copy is required
2323606882cSMatthew Dillon	    by checking modify times, file size, perms, and other stat
2333606882cSMatthew Dillon	    elements.  If the elements match, it does not bother to copy
2343606882cSMatthew Dillon	    ( unless an MD5 check is being made, in which case it must read
2353606882cSMatthew Dillon	    the destination file ).
2363606882cSMatthew Dillon
2373606882cSMatthew Dillon    You typically run cpdup on the target machine.  The target machine
2383606882cSMatthew Dillon    temporarily mounts the template machine's / and /usr via NFS, read-only,
2393606882cSMatthew Dillon    and runs cpdup to update / and /usr.  If you use this methodology note
2403606882cSMatthew Dillon    that THERE ARE SECURITY CONSIDERATIONS!  See 'SECURITY CONSIDERATIONS WITH
2413606882cSMatthew Dillon    NFS' below.
2423606882cSMatthew Dillon
2433606882cSMatthew Dillon    Whatever script you use that does the NFS mounts should ensure that the
2443606882cSMatthew Dillon    mount succeeded before continuing with the cpdup.
2453606882cSMatthew Dillon
2463606882cSMatthew Dillon    You should create .cpignore files in the appropriate directories on the
2473606882cSMatthew Dillon    template machine's / and /usr partitions so as not to overwrite active
2483606882cSMatthew Dillon    files on the target.  The most critical .cpignore files should be
2493606882cSMatthew Dillon    protected with 'chflags schg .cpignore'.  Specifically, the ones in /
2503606882cSMatthew Dillon    and /etc, but possibly others as well.  For example, the .cpignore
2513606882cSMatthew Dillon    hierarchy for protect /root is:
2523606882cSMatthew Dillon
2533606882cSMatthew Dillon	# /root/.cpignore contains
2543606882cSMatthew Dillon	.history
2553606882cSMatthew Dillon
2563606882cSMatthew Dillon	# /root/.ssh/.cpignore contains
2573606882cSMatthew Dillon	random_seed
2583606882cSMatthew Dillon	known_hosts
2593606882cSMatthew Dillon	authorized_keys
2603606882cSMatthew Dillon	identity
2613606882cSMatthew Dillon	identity.pub
2623606882cSMatthew Dillon
2633606882cSMatthew Dillon    WHEN INITIALLY CONVERTING A TARGET MACHINE TO USE TEMPLATING, ALWAYS
2645665fe6bSUlrich Spörlein    MAKE A FULL BACKUP OF THE TARGET MACHINE FIRST!  You may accidentally
2655665fe6bSUlrich Spörlein    delete files on the target during the conversion due to forgetting to
2665665fe6bSUlrich Spörlein    enter items into appropriate .cpignore files on the source.
2673606882cSMatthew Dillon
2683606882cSMatthew Dillon	SECURITY CONSIDERATIONS WITH NFS ROOT EXPORT FROM TEMPLATE MACHINE
2693606882cSMatthew Dillon	SECURITY CONSIDERATIONS WITH NFS USR EXPORT FROM TEMPLATE MACHINE
2703606882cSMatthew Dillon
2713606882cSMatthew Dillon    There are some serious security considerations that must be taken into
2723606882cSMatthew Dillon    account when exporting / and /usr on the template machine.
2733606882cSMatthew Dillon
2743606882cSMatthew Dillon	* only export read-only
2753606882cSMatthew Dillon
2763606882cSMatthew Dillon	* the password file ( aka vipw ) may not contain any crypted passwords
2773606882cSMatthew Dillon	  at all.  You MUST use ssh or kerberos to access the template machine.
2783606882cSMatthew Dillon
2793606882cSMatthew Dillon	  You can get away with giving only root a crypted password, but only
2803606882cSMatthew Dillon	  if you disallow network root logins and only allow direct root
2813606882cSMatthew Dillon	  logins on the  console.
2823606882cSMatthew Dillon
2833606882cSMatthew Dillon	* The machine's private ssh_host_key usually resides in /usr/local/etc.
2843606882cSMatthew Dillon	  You must move this key to /var/db.  You can softlink link so no
2853606882cSMatthew Dillon	  modification of sshd_config is required.
2863606882cSMatthew Dillon
2873606882cSMatthew Dillon	* The machine's private ~root/.ssh/identity file is also exposed by
2883606882cSMatthew Dillon	  the NFS export, you should move this file to /var/db as well and
2893606882cSMatthew Dillon	  put a softlink in ~root/.ssh.
2903606882cSMatthew Dillon
2913606882cSMatthew Dillon	* DON'T EXPORT /var !  Either that, or don't put the private keys
2923606882cSMatthew Dillon	  in /var/db ... put them somewhere else.
2933606882cSMatthew Dillon
2943606882cSMatthew Dillon	* You may want to redirect the location of the random_seed file, which
2953606882cSMatthew Dillon	  can be done by editing ~root/.ssh/sshd_config and
2963606882cSMatthew Dillon	  /usr/local/etc/sshd_config so it is not exposed either.
2973606882cSMatthew Dillon
2983606882cSMatthew Dillon					-Matt
2993606882cSMatthew Dillon					Matthew Dillon
3003606882cSMatthew Dillon					[email protected]
3013606882cSMatthew Dillon
302