管ç察象ãµãŒããŒã®æ°ãæ°åããŸãã¯æ°çŸã«éãããšããã®ãããªããªãŒããèªåçã«æ§æããã³ç®¡çãããœãªã¥ãŒã·ã§ã³ãæ¢ãå¿ èŠããããŸãã ããããPuppetãå©ãã«ãªãå Žæã§ãã ãªããããããªã®ãïŒ Puppetã¯ã¯ãã¹ãã©ãããã©ãŒã ã§ãããè±ããªã³ãã¥ããã£ãæã¡ãå€ãã®æ¢è£œã®ã¢ãžã¥ãŒã«ïŒ4800+ïŒãããããšã³ã¿ãŒãã©ã€ãºããŒãžã§ã³ããããŸãã ãããã®å©ç¹ã¯ãã¹ãŠããã®è£œåã®åšåãçããã®ã§ã¯ãããŸããã ããããã³ã³ãœãŒã«ãããã®ãããªãçµåãã管çããããšã¯ããã»ã©ç°¡åã§ã¯ãããŸããã ãããã£ãŠãPuppetã®äŸ¿å©ãªå¶åŸ¡ãšæ§æã®ããã«ãForemanãéçºãããŸããã 次ã«ãSSHéµç®¡çã¿ã¹ã¯ã®äŸã䜿çšããŠããã®ãã³ãã«ãã€ã³ã¹ããŒã«ããã³æ§æããŸãã
èŠä»¶ïŒ
- puppet-masterã®çŽç²ãªãµãŒããŒã
- puppet-masterãµãŒããŒäžã®ã³ãã³ãã¯rootãšããŠå®è¡ãããŸã;
- puppet-agentãµãŒããŒäžã®ã³ãã³ãã¯sudoãä»ããŠå®è¡ãããŸãã
䜿çšãããœãããŠã§ã¢ïŒ
- OS Ubuntu 14.04.5 LTS;
- Puppet 3.8.7;
- ãã©ã¢ãã³1.11.4ã
ç®çïŒ
- ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ç®¡çãèªååãã䟿å©ãªæ¹æ³ãå ¥æãã
- SSHããŒã管çãã䟿å©ãªæ¹æ³ãå ¥æããŠãã ããã
ã泚æ
ãã¹ãŠã®ã¹ã¯ãªãŒã³ã·ã§ãããšèšå®ã®äžéšã¯ãã¿ãã¬ã«ãã£ãŠé ãããŠããŸãã ã³ãã³ããå®è¡ãããå Žæãããããç解ããããã«ãåã³ãã³ãã®åã«ãµãŒããŒã¿ã€ãïŒãã¹ã¿ãŒãŸãã¯ãšãŒãžã§ã³ãïŒãè¿œå ããŸããã
1. Puppetãã¹ã¿ãŒãžã®Foreman + Puppetã®ã€ã³ã¹ããŒã«
Foreman / Puppetã€ã³ã¹ããŒã©ãŒãªããžããªãè¿œå ããŠãã·ã¹ãã ã«ã€ã³ã¹ããŒã«ããŸãã
master ~ $ apt-get -y install ca-certificates master ~ $ cd ~ && wget https://apt.puppetlabs.com/puppetlabs-release-trusty.deb master ~ $ dpkg -i puppetlabs-release-trusty.deb master ~ $ sh -c 'echo "deb http://deb.theforeman.org/ trusty 1.11" > /etc/apt/sources.list.d/foreman.list' master ~ $ sh -c 'echo "deb http://deb.theforeman.org/ plugins 1.11" >> /etc/apt/sources.list.d/foreman.list' master ~ $ cd ~ && wget -q http://deb.theforeman.org/pubkey.gpg -O- | apt-key add - master ~ $ apt-get update && apt-get -y install foreman-installer
ã€ã³ã¹ããŒã©ãŒãå®è¡ããŸãã
master ~ $ foreman-installer
çµæã¯æ¬¡ã®ããã«ãªããŸãã
Foremanã®ã€ã³ã¹ããŒã«çµæ
puppetã<Domain.com>ã®ãããªãªã³ã¯ãšãã¹ã¯ãŒãã䜿çšãããã°ã€ã³ã¯ãåŸã§äŸ¿å©ã«ãªããŸãã
Foremanã§ã®ãã¡ã€ã«å€æŽã®éãã衚瀺ããããã®æ§æãæ§æããŸãããã
master ~ $ nano /etc/puppet/puppet.conf > show_diff = true
åã®ã¹ãããã§æšå¥šããããªã³ã¯ããã©ãŠã¶ãŒã§éããŸã ïŒ puppetã<Domain.com>
ãããŠããŠãŒã¶ãŒåïŒ adminãšãã€ã³ã¹ããŒã«åŸã«ã³ã³ãœãŒã«ã«è¡šç€ºããããã¹ã¯ãŒããå ¥åããŸãã
ãã°ã€ã³ãã©ãŒã ã®ã¹ã¯ãªãŒã³ã·ã§ãã
èªèšŒã«æåãããšãForemanãã€ã³ã¹ããŒã«ãããæ£åžžã«åäœããŸãã 次ã®ç« ã«é²ãããšãã§ããŸãã
2. Foremanã®ã»ããã¢ãã
ããã©ã«ãã§ã¯ãForemanã¯Puppetã«ãã£ãŠçæãããSSL蚌ææžã䜿çšãããã©ãŠã¶ãŒã¯ãããåãå ¥ããŸããã å®å šã§ãªãæ¥ç¶èŠåãæ¶ããããã«ãã«ãŒã蚌ææžïŒ
/var/lib/puppet/ssl/certs/ca.pem
ïŒããã©ãŠã¶ãŒã«è¿œå ã§ããŸãïŒChromiumã®å Žåã¯ãããã«è¿œå ïŒèšå®/ SSL /èªèšŒå±ïŒã
æåã«ãã°ã€ã³ãããšã ããã·ã¥ããŒãããŒãžã衚瀺ããããããã¯ãŒã¯äžã®ãã¹ãŠã®ããŒãã®äžè¬çãªçµ±èšã衚瀺ãããŸãã ãã¹ããè¿œå ãããšããæçšãªçµ±èšæ å ±ããããŸãã
ããã«ã®ã¹ã¯ãªãŒã³ã·ã§ãã
ãã以éã®ãã°ã€ã³ã§ã¯ããã¹ããªã¹ãããŒãžã«ãªãã€ã¬ã¯ããããŸãã
2.1ã ãã¹ã¯ãŒããå€æŽãã
ãŸãããŠãŒã¶ãŒã®ãã¹ã¯ãŒããå€æŽããå¿ èŠããããŸãã
ãã¹ã¯ãŒããå€æŽãã
ããã©ã«ãã®ãã¹ã¯ãŒãã¯ãã§ã«è€éã§ãããç¬èªã®ãã¹ã¯ãŒããäœæããããšããå§ãããŸãã
2.2ã äŸãšããŠNTPã䜿çšããŠã¢ãžã¥ãŒã«ãè¿œå ãã
æå»ã¯ãããããã¹ã¿ãŒãµãŒããŒã§æ£ç¢ºã«èšå®ããå¿ èŠããããŸãã ãããè¡ãã«ã¯ãNTPã䜿çšããŸãã æå»ãæ£ãããªãå Žåããããããã¹ã¿ãŒã¯èª€ã£ãŠé ãéå»ãŸãã¯æªæ¥ãããšãŒãžã§ã³ã蚌ææžãçºè¡ããå¯èœæ§ããããä»ã®ããŒãã¯å»æ¢ããããšèŠãªããŸãã
Foremanãä»ããŠPuppetã¢ãžã¥ãŒã«ã管çã§ããããã«ããããã«ãéçºè ãPuppet-Labsã§ã¯ãªããPuppetã³ãã¥ããã£ã®éçºè ã§ããã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããå¿ èŠãããå ŽåããããŸãã ããã¯ãForemanãPuppetã«Restful API HTTPãªã¯ãšã¹ãã䜿çšããŠãããããã¹ãŠã®ã¢ãžã¥ãŒã«ããã®APIã䜿çšããŠç®¡çãå®çŸ©ããŠããããã§ã¯ãªããšããäºå®ã«åºã¥ããŠããŸãã
puppetãã¹ã¿ãŒã«saz / ntpã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããŸãã
master ~ $ puppet module install saz/ntp
ã泚æ
saz / ntpã¢ãžã¥ãŒã«ã¯ãForemanããŒãžã§ã³1.11ã§ããŸãæ©èœããŸã ã Foremanã®ä»ã®ããŒãžã§ã³ã§ã¯ããµã€ãforge.puppetlabs.comã®ã¢ãžã¥ãŒã«ã䜿çšããŠntpãæ€çŽ¢ã§ããŸã ã
以äžã衚瀺ãããã¯ãã§ãã
saz / ntpã®ã€ã³ã¹ããŒã«çµæ
ããã§ãã¢ãžã¥ãŒã«ã¯puppet-masterå°çšã«ã€ã³ã¹ããŒã«ãããŸããã 次ã«ãWebã€ã³ã¿ãŒãã§ãŒã¹ã«å ¥ããForemanã«è¿œå ããå¿ èŠããããŸãã [ èšå® ] â [ ã¯ã©ã¹ ]ã¡ãã¥ãŒã«ç§»åãã[ puppetããã€ã³ããŒã ]ãã¯ãªãã¯ããŸãã
æ§æâã¯ã©ã¹
ãã®çµæã䜿çšå¯èœãªã¯ã©ã¹ã®ãªã¹ãã衚瀺ãããå¿ èŠãªã¯ã©ã¹ãéžæããŠ[ æŽæ° ]ãã¯ãªãã¯ããŸã ã
æŽæ°ãã
æãè¿ã ntpãµãŒããŒã䜿çšããã«ã¯ã www.pool.ntp.orgã«ã¢ã¯ã»ã¹ããŠãã ãã ã å³åŽã®ãããã¯ã§ãå¿ èŠãªããŒã«ïŒã¢ããªã«ãã¢ãžã¢ãªã©ïŒãéžæããã¯ãªããããŒãå ã®ãµãŒããŒã®ãªã¹ããéžæããŸãã
次ã«ãååãã¯ãªãã¯ããŠã ntpã¯ã©ã¹ã®èšå®ã«ç§»åããŸãã [ ã¹ããŒãã¯ã©ã¹ãã©ã¡ãŒã¿ãŒ ]ã¿ãã«ç§»åããå·ŠåŽã®ãªã¹ãã§ãµãŒããŒãªã¹ãã¿ããæ¢ããŸãã
ãµãŒããŒãªã¹ã
åã®å€ã®äŸã«åŸã£ãŠã ããã©ã«ãå€ã«ãªãŒããŒã©ã€ãé ç®ãããŒã¯ããäžèšã®ã¹ããããããµãŒããŒãè¿œå ããŸãã ãã®å€ãè¿œå ããŸããïŒ
["0.asia.pool.ntp.org","1.asia.pool.ntp.org","2.asia.pool.ntp.org","3.asia.pool.ntp.org"]
ããŒãžã®äžéšã«ãã[ éä¿¡ ]ãã¯ãªãã¯ããŠãã¯ã©ã¹ãã©ã¡ãŒã¿ãŒããªãŒããŒã©ã€ãããŸãã
2.3ã ã¢ã«ãŠã³ããšsshã¢ãžã¥ãŒã«ã®è¿œå
äŸãšããŠåã®ã¢ãžã¥ãŒã«ã䜿çšããŠã accountsã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããŸãã
master ~ $ puppet module install camptocamp-accounts
ã€ã³ã¹ããŒã«ãæåããå Žåã次ã衚瀺ãããŸãã
ã¢ã«ãŠã³ãã®ã€ã³ã¹ããŒã«çµæ
sshã¢ãžã¥ãŒã«ãã€ã³ã¹ããŒã«ããŸã ã
master ~ $ puppet module install saz/ssh
ãã®åŸã Foremanã«ç§»åããŠæ°ããã¯ã©ã¹ãã€ã³ããŒãããŸãã åŸã§ããã¹ãã°ã«ãŒããäœæããåŸã ã¢ã«ãŠã³ããšsshã¯ã©ã¹ãæ§æããŸã ã
2.4ã mysqlããã³apacheã¢ãžã¥ãŒã«ã®è¿œå
ããŒã¿ããŒã¹ããã³Webã°ã«ãŒãã®åŸç¶ã®ååã説æããã«ã¯ã apacheããã³mysqlã¢ãžã¥ãŒã«ãè¿œå ããŸãã åã®äŸã®åŸã«ã¢ãžã¥ãŒã«ãè¿œå ããŸãã 次ã®ã³ãã³ãã§ããŠã³ããŒãã§ããŸãïŒ
master ~ $ puppet module install puppetlabs-apache master ~ $ puppet module install puppetlabs-mysql
3.ãã¹ãã®è¿œå
ãã¹ããPuppetã«è¿œå ããã«ã¯ããã®ãã¹ãã«puppetãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããå¿ èŠããããŸãã puppetãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããã«ã¯ã puppet-labsãªããžããªãããŠã³ããŒãããŠã€ã³ã¹ããŒã«ããŸãã
agent ~ $ cd ~ && wget https://apt.puppetlabs.com/puppetlabs-release-trusty.deb agent ~ $ sudo dpkg -i puppetlabs-release-trusty.deb agent ~ $ sudo apt-get update
次ã«ãpuppetãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããŸãã
agent ~ $ sudo apt-get -y install puppet
PuppetããšãŒãžã§ã³ããšããŠå®è¡ããã«ã¯ãPuppetãã¹ã¿ãŒãŸãŒã³èšå®ãã³ã¡ã³ãåããå¿ èŠããããŸãã ãŸãããšãŒãžã§ã³ãã®æ§æãè¿œå ããŸããããã«ããããããããã¹ã¿ãŒã®ã¢ãã¬ã¹ãèšå®ãããŸãã 以äžã«ãæ§æãã¡ã€ã«
/etc/puppet/puppet.conf
ã®åœ¢åŒã瀺ããŸãã
puppet.conf
[main] logdir=/var/log/puppet vardir=/var/lib/puppet ssldir=/var/lib/puppet/ssl rundir=/var/run/puppet factpath=$vardir/lib/facter #templatedir=$confdir/templates #[master] # These are needed when the puppetmaster is run by passenger # and can safely be removed if webrick is used. #ssl_client_header = SSL_CLIENT_S_DN #ssl_client_verify_header = SSL_CLIENT_VERIFY [agent] server = puppet.domain.com # puppet.domain.com - hostname IP- master-
OSã®åèµ·ååŸã«ãããããšãŒãžã§ã³ããèµ·åããã«ã¯ã STARTå€æ°ã®å€ãnoããyesã«å€æŽããŸãã ãŸããpuppetãšãŒãžã§ã³ããå®è¡ããŸãã
agent ~ $ sudo sed -is/START=no/START=yes/g /etc/default/puppet agent ~ $ sudo service puppet start
å°èŠæš¡ãªã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã¯ãpuppetãšãŒãžã§ã³ããããŒã¢ã³ãšããŠå®è¡ã§ããŸãã CRONãå®è¡ããæ¹æ³ããããŸãïŒ docs.puppet.com/puppet/3.6/services_agent_unix.html#running-puppet-agent-as-a-cron-job
ã泚æ
puppetãšãŒãžã§ã³ãã¯ã ãµãŒããŒãã©ã¡ãŒã¿ãæ瀺çã«æå®ãããŠããªãéãïŒpuppet.confãã¡ã€ã«ã§ïŒãããã©ã«ãã§ãã®ãŸãŒã³ã§puppetãã¹ã¿ãŒãã¡ã€ã³ãæ€çŽ¢ããŸãã äŸïŒ server.domain.comã¯puppet.domain.comãµãŒããŒãæ€çŽ¢ããŸãã ãããã£ãŠããŸã æ瀺ã«åŸã£ãŠããã°ããã¹ãŠãããŸãããã¯ãã§ãã
ãã®åŸã ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãã©ã¢ãã³âã¹ããŒããããã·â蚌ææžã«ç§»åããŸãã
ã€ã³ãã©ã¹ãã©ã¯ãã£âã¹ããŒããããã·â蚌ææž
ãããããšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããã°ããã®ãã¹ãã衚瀺ãããŸãã ãã£ã«ã¿ãŒïŒå·ŠäžïŒã䜿çšããŠã眲åãããŠããªã蚌ææžã®ã¿ã衚瀺ã§ããŸãã 眲åããã«ã¯ã[眲å]ãã¿ã³ãã¯ãªãã¯ããå¿ èŠããããŸãã
蚌ææžâ眲å
æ°å以å ã«ã ãµãŒããŒ<Domain.com>ãµãŒããŒïŒãšãŒãžã§ã³ããã€ã³ã¹ããŒã«ããã°ããã®ãµãŒããŒïŒã[ ãã¹ã]â[ãã¹ãŠã®ãã¹ã]ãªã¹ãã«è¡šç€ºãããŸã ã
4.ãã¹ãã°ã«ãŒãã®è¿œå
ã¡ãã¥ãŒé ç®[ èšå® ] â[ãã¹ãã°ã«ãŒã ]ã«ç§»åããŸã ã [ æ°ãããã¹ãã°ã«ãŒã]ãã¯ãªãã¯ããŸãã [ ãã¹ãã°ã«ãŒã ]ã¿ãã¯æ¬¡ã®ããã«ãªããŸãã
èšå®âãã¹ãã°ã«ãŒã
ã«ãŒãã°ã«ãŒããã«ãŒãã°ã«ãŒãã«ãªããŸãã 圌女ã¯ä»ã®ãã¹ãŠã®ã°ã«ãŒãã®èŠªã«ãªããŸãã 圌女ã¯ãã¹ãŠã«å®å šã«ã¢ã¯ã»ã¹ã§ããŸãã ãããŠãã¡ã€ã³ã¯ã©ã¹ãå«ãŸããŸãã
次ã«ã Puppet Classesã¿ãã«ç§»åãã +ãã¯ãªãã¯ããŠå¿ èŠãªã¯ã©ã¹ãè¿œå ããŸãã
ããããã¯ã©ã¹
Submitãã¯ãªãã¯ããŸãã
åãååã«åŸã£ãŠãããã«2ã€ã®ã°ã«ãŒããè¿œå ããŸãã ã¯ã©ã¹accounts ã ntp ãããã³sshãç¶æ¿ãããããããå床远å ããå¿ èŠããªããããããã§ã¯ã«ãŒãã°ã«ãŒããParentãšããŠéžæããŸãã ããŒã¿ããŒã¹ã°ã«ãŒãã«ã¯mysql ::ãµãŒããŒã¯ã©ã¹ã®ã¿ã Webã°ã«ãŒãã«ã¯apacheã¯ã©ã¹ã®ã¿ãè¿œå ããŸã ã
ããŒã¿ããŒã¹ã°ã«ãŒãã®è¿œå
ãã¹ãŠã®ã°ã«ãŒãã®ãªã¹ã
5.ã°ã«ãŒããžã®ããŒãã®è¿œå
ã°ã«ãŒãã«ããŒããå«ããã«ã¯ããã®èšå®ã«ç§»åããå¿ èŠããããŸãã
ãã¹ãèšå®
ãã®åŸãæåã®ã¿ãã§ãäžã®ã¹ã¯ãªãŒã³ã·ã§ããã®ããã«ã°ã«ãŒããè¿œå ããŸãã
ã°ã«ãŒãããã¹ãã«è¿œå ãã
ãã®åŸã[ éä¿¡ ]ãã¯ãªãã¯ãããšãæ°å以å ã«mysqlããã¹ãã«è¡šç€ºãããŸãã åæ§ã«ãä»ã®2ã€ã®ãµãŒããŒãWebã°ã«ãŒãã«å²ãåœãŠãããšãã§ããŸãã
ã°ã«ãŒããå²ãåœãŠããããã¹ãã®ãªã¹ã
æ§æå šäœããããããšãŒãžã§ã³ãã«çæéã§èªåçã«æ¡åŒµãããŸãã
åŸ ã¡ãããªãå Žåã¯ãã¯ã©ã€ã¢ã³ãã§
puppet agent --test
ãå®è¡ããæ§æãã©ã®ããã«äœæããããã
puppet agent --test
ã§ç¢ºèªã§ããŸãã
6.ã¢ã«ãŠã³ãã¢ãžã¥ãŒã«ã䜿çšããŠæš©éãèšå®ãã
å®éã«ãæåã«ç€ºããåè·¯ãããäžåºŠèŠãŠãããã«åºã¥ããŠããžãã¯ãäœæã§ããŸãã
ã¡ãã¥ãŒé ç®æ§æâã¯ã©ã¹ã«ç§»åããŸãã ã¢ã«ãŠã³ããã¯ãªãã¯ããŠã¢ãžã¥ãŒã«èšå®ã«ç§»åããŸãã ãã¹ãŠã®èšå®ã®ãã¡ãã¿ãaccounts ã sshã㌠ã usersãå¿ èŠã§ã ã
ã泚æ
[ã¢ã«ãŠã³ã]ã¿ã-ããã·ã¥ããµãŒããŒãŠãŒã¶ãŒâ[ sshã㌠]ã¿ãã®å ¬éããŒåããå«ãŸããŸãã SSHããŒã¿ã -ããã·ã¥ãããŒåâã¿ã€ããšå€ããå«ãŸããŸãã [ ãŠãŒã¶ãŒ ]ã¿ã-æ¢åã®ãã©ã¡ãŒã¿ãŒãäœæãŸãã¯æå®ããå¿ èŠããããŠãŒã¶ãŒãå«ãŸããŸãã
æåŸã®ãŠãŒã¶ãŒã¿ããéããã¹ã¯ãªãŒã³ã·ã§ããã®ããã«èšå®ããŸãã
ãŠãŒã¶ãŒ
ãã®èšå®ã¯ããŠãŒã¶ãŒã®ããŒã ãã£ã¬ã¯ããªãæ§æããŸãã ããã§ã¯ã MergeãªãŒããŒã©ã€ããšMergeããã©ã«ããã©ã¡ãŒã¿ãŒã䜿çšããŸãã ãããã«ãããæçµãã¹ãã®æ§æãçµã¿åãããããšãã§ããŸãã
次ã®ããã«sshããŒã¿ããåããŸãã
sshããŒ
[ ããã©ã«ãå€]ãã£ãŒã«ãã«ã[ ã¢ã«ãŠã³ã ]ã¿ãã§äœ¿çšãããã¢ã«ãŠã³ãã®ãã¹ãŠã®å ¬éããŒãå ¥åããŸãã ãããã¯ã1ã€ãŸãã¯å¥ã®ãµãŒããŒã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã®å ¬éããŒã§ãã ã¿ã€ãããã³ãããªãã¯ãã©ã¡ãŒã¿ã®åã«2ã€ã®ã¹ããŒã¹ã®ã€ã³ãã³ããå¿ èŠã§ãã
1ã€ã®å ¬ééµãã©ã®ããã«èŠãããã®äŸïŒæ®ãã¯ä»¥äžã«æ¬¡ã ã«è¿œå ãããŸãïŒïŒ
admin: type: ssh-rsa public: AAAAB3NzaC1yc2EAAAADAQABAAABAQDXibuyi2MFzERps7mD2J38mhd4phXQlOEZrmui9rDdcYD0XeEnvdRTZPcsMOw6DRT1ERpzbcFehj+G29YxoiXZ541gVjVvsATAqojN3zEkMz5b0AgBNcKDFi9h/qwlK9YDv2trKEcRHQ4kBN332Z6oqdBFerUMys5dvc3RVlE+x2kVmYNmGIlma5twC9w/wRNoD+nUK+3bk+I+Og40f//uFAKFeY4DMoCrdOsHJrPak5nD9vL6a2m/Fe3jfgmpBCcnV3LS2mr+PdRYbtju7nzfu8WT0ugMAUi+dDMRFh3DmfCzXbOi2TPi+mP//L/A19thXffd/QzW7wmAgxlj+km1
次ã®ããã«ãäžéšã®ã¿ãã¢ã«ãŠã³ãã«å ¥åããŸãã
ã¢ã«ãŠã³ã
ãã®ãã©ã¡ãŒã¿ãŒãã次ã®ããã«ãªããŸãïŒ rootã¯rootã¢ã«ãŠã³ãããã©ãã§ãã¢ã¯ã»ã¹ã§ããŸãïŒ rootã¢ã«ãŠã³ãã¯sshããŒã¿ãã®èŠçŽ ã§ãïŒã dbadminã¢ã«ãŠã³ãã¯ããŒã¿ããŒã¹ã°ã«ãŒãããã®ãµãŒããŒã®ã¿ã«rootã¢ã¯ã»ã¹ãæã¡ã adminãŠãŒã¶ãŒã¯webã°ã«ãŒãã®ã¿ãæã¡ã adminã¢ã«ãŠã³ãã¯æ¥ç¶ã§ããŸã管çãŠãŒã¶ãŒã®ã¿ã
[ ãŠãŒã¶ãŒ ]ã¿ãã§ã 管çãŠãŒã¶ãŒãwww-dataã°ã«ãŒãã«è¿œå ããŸãã
ãŠãŒã¶ãŒ
6.1 sshã¯ã©ã¹ã®æ§æ
ã¢ã«ãŠã³ãã¯ã©ã¹ã§ã¯ãsshããŒã¢ã¯ã»ã¹ãæ§æããŸããã ãããã£ãŠãããå®å šãªã»ãã¥ãªãã£ãå®çŸããã«ã¯ããã¹ã¯ãŒãã¢ã¯ã»ã¹ãçŠæ¢ããå¿ èŠããããŸãã ããã¯ã sshã¯ã©ã¹ã䜿çšããŠè¡ãããŸã ã ãã®èšå®ã«ç§»åãã[ ã¹ããŒãã¯ã©ã¹ãã©ã¡ãŒã¿ãŒ ]ã¿ããéããŸãã 次ã«ã ã¯ã©ã€ã¢ã³ããªãã·ã§ã³ã¯æ¬¡ã®ãã©ãŒã ã«ã€ãªãããŸã ã
ã¯ã©ã€ã¢ã³ããªãã·ã§ã³
ãµãŒããŒãªãã·ã§ã³ã¿ãã¯æ¬¡ã®ãšããã§ãã
ãµãŒããŒãªãã·ã§ã³
次ã®ããã«ã storeconfigs enabledã¿ããåããŸãã
æå¹ãªstoreconfigs
Storeconfigsã¯é¡§å®¢ã«é¢ãããã¹ãŠã®ãã¡ã¯ããä¿åãããããããŒã¿ããŒã¹ã«ã¯ãšãªãå®è¡ããŠãç¹å®ã®æ¡ä»¶ãæºãããã¹ãã®ãªã¹ããååŸã§ããŸãã ã»ãã¥ãªãã£ã匷åããããã«ãç¡å¹ã«ããŸããã
7.çµæ
ãã®ã¬ã€ããå®äºãããšãPuppet管çã®äžã«è¿œå ãããã€ã³ãã©ã¹ãã©ã¯ãã£ãè¿ éã«æ§æå¯èœã«ãªããã¹ã±ãŒã©ãã«ã«ãªããŸãã ãããŠãäž»ãªç®æš-å ¬ésshããŒã®ç®¡çã¯å¯èœãªéã䟿å©ã«ãªããŸãã
ã«ãŒã/ Webã°ã«ãŒãå ã®ãã·ã³ã®1ã€ã«ãã管çãŠãŒã¶ãŒããŒã®ãªã¹ãã®ã¹ã¯ãªãŒã³ã·ã§ããïŒ
SSHããŒãªã¹ã
ssh keysãã©ã¡ãŒã¿ãŒã®ã¢ã«ãŠã³ãã¯ã©ã¹ãèšå®ãããšãã«ã MergeãªãŒããŒã©ã€ããšMerge defaultãå«ããããšãæãåºããŠãã ããã ããã¯ãç¹å®ã®ãããã¯ãŒã¯ããŒãã®æåŸã«sshããŒãæã€æ§é åãã¡ã€ã«ã1ã€åéãããããã«å¿ èŠã§ãã
è¿œå ãããããŒã䜿çšããŠãŠãŒã¶ãŒã admin ããšããŠæ¬åœã«ãã°ã€ã³ã§ãããã©ããã確èªããŸãããã
SSHæ¥ç¶ã確èªãã
ãã¹ããæåããå Žåãã€ã³ãã©ã¹ãã©ã¯ãã£ã®æºåãæŽããåŸã ã«ä»ã®ãµãŒããŒãpuppet-masterã«æ¥ç¶ããPuppetãä»ããŠä»ã®ãµãŒãã¹ãæ§æã§ããŸãã
䜿çšãªãœãŒã¹ïŒ Puppet ããã¥ã¡ã³ããForemanããã¥ã¡ã³ã ã