VMS:KitsNet Standard: Difference between revisions

Peter A. Smode (talk | contribs)
Created page with "<bs:pageaccess groups="kitsnet_adm"></bs:pageaccess> ==.ssh== <code>mkdir .ssh</code> then use sftp to pull in contents from another system. ==sudoers== Activate '''wheel'''..."
 
Peter A. Smode (talk | contribs)
No edit summary
Line 1: Line 1:
<bs:pageaccess groups="kitsnet_adm"></bs:pageaccess>
==Prep for XXXVMS==
==.ssh==
<code>mkdir .ssh</code> then use sftp to pull in contents from another system.


==sudoers==
* Start InfoServer software with <code>@SYS$STARTUP:ESS$STARTUP DISK TAPE</code>
Activate '''wheel''' with no password
* Bind to and mount XXXVMS volume<syntaxhighlight lang="shell-session">
 
$ MCR ESS$LADCP BIND /SYS XXXVMS
==grub==
%LADCP-I-BIND, service bound to logical unit DAD$XXXVMS (_DAD1:)
<code># vi /etc/default/grub</code>
$ MOUNT /SYSTEM DAD$XXXVMS XXXVMS
<syntaxhighlight>
%MOUNT-I-WRITELOCK, volume is write locked
GRUB_TERMINAL_INPUT="console serial"
%MOUNT-I-MOUNTED, XXXVMS mounted on _DAD1:
GRUB_TERMINAL_OUTPUT="console serial"
GRUB_CMDLINE_LINUX="crashkernel=auto resume=/dev/mapper/V0uv029-swap rd.lvm.lv=V0uv029/root rd.lvm.lv=V0uv029/swap console=ttyS0"
GRUB_SERIAL_COMMAND="serial --unit=0 --speed=115200 --word=8 --parity=no --stop=1"
</syntaxhighlight>
For RHEL 9, the GRUB_CMDLIN_LINUX needs to end with <code>console=tty0 console=ttyS0,115200</code>
 
<code># grub2-mkconfig -o /boot/grub2/grub.cfg</code>
 
But for Rocky 9.3 and later, an extra qualifier is needed:
 
<code># grub2-mkconfig -o /boot/grub2/grub.cfg --update-bls-cmdline</code>
==dnf and files in /etc/yum.repos.d==
<syntaxhighlight lang="shell-session">
# yum install wget
#
# #for CentOS
# mv CentOS-Linux-AppStream.repo CentOS-Linux-AppStream.repo-ORIG
# echo > CentOS-Linux-AppStream.repo
# mv CentOS-Linux-BaseOS.repo CentOS-Linux-BaseOS.repo-ORIG
# echo > CentOS-Linux-BaseOS.repo
# wget http://wort/KitsNet/KitsNet-v8.repo
#
# #for Rocky v8
# mv Rocky-AppStream.repo Rocky-AppStream.repo-ORIG
# echo > Rocky-AppStream.repo
# mv Rocky-BaseOS.repo Rocky-BaseOS.repo-ORIG
# echo > Rocky-BaseOS.repo
# wget http://wort/KitsNet/KitsNet-Rv8.repo
#
# #for Rocky v9
# wget http://wort/KitsNet/KitsNet-Rv9.repo
# mv rocky.repo rocky.repo-ORIG
# cp rocky.repo-ORIG rocky.repo
# #manually edit rocky.repo to comment out [baseos] and [appstream] stanzas
#
# dnf clean all
# dnf list
</syntaxhighlight>
 
==Packages, packages, packages...==
<syntaxhighlight lang="shell-session">
# dnf install -y epel-release
# dnf config-manager --set-enabled powertools #(prior to Rocky Linux 9.0)
# dnf config-manager --enable crb #(Rocky Linux 9.0 onward)
# dnf install -y yum-utils net-tools lsof rsync vnstat screen sysstat ncdu vim bind-utils python3 vim dnf-automatic glances
</syntaxhighlight>''The first KitsNet build with Rocky Linux v8.4 generated a system without rsyslog installed nor syslog started. As a result, most logs from <code>/var/log</code> were missing. <code>dnf install rsyslog</code> installed the missing packages and enabled and started the service.''
 
==Fix glances==
As per [https://github.com/giampaolo/psutil/issues/1354 disk_io_counters() fails on Linux kernel 4.19], there is a bug in the '''psutil''' python module that causes it to fail on reporting Disk I/O counters in newer kernels. This in turn causes the glances utility to fail to report Disk I/O counters. The fix is to patch the <code>_pslinux.py</code> file in the psutil module.<syntaxhighlight lang="shell-session">
# ls -al /usr/lib64/python3.6/site-packages/psutil/_pslinux.py
-rw-r--r--. 1 root root 74870 Jul  3 09:56 /usr/lib64/python3.6/site-packages/psutil/_pslinux.py
# grep "fields_len == 14" /usr/lib64/python3.6/site-packages/psutil/_pslinux.py
        elif fields_len == 14:
# sed -i  's#fields_len == 14:#fields_len == 14 or fields_len == 18:#g'  /usr/lib64/python3.6/site-packages/psutil/_pslinux.py
# grep "fields_len == 14" /usr/lib64/python3.6/site-packages/psutil/_pslinux.py
        elif fields_len == 14 or fields_len == 18:
</syntaxhighlight>
</syntaxhighlight>
 
* Decide devices for Cluster Common directory strucucture and local utilities. Use these as areguments to XXXVMS_PREP.COM. Default for each is SYS$SYSDEVICE<syntaxhighlight lang="shell-session">
 
$ @DAD$XXXVMS:[LOCAL_UTIL.XXXVMS]XXXVMS_PREP SYS$SYSDEVICE: SYS$SYSDEVICE:
==python==
%CREATE-I-CREATED, _VX2$DUA0:[XXXVMS_CLUCOM] created
<code># alternatives --set python /usr/bin/python3 #Prior to Rocky Linux 9 only</code>  
%CREATE-I-CREATED, _VX2$DUA0:[XXXVMS_CLUCOM.LOGFILES.VX2] created
 
%CREATE-I-CREATED, _VX2$DUA0:[XXXVMS_CLUCOM.SYSMGR] created
==chrony/ntp configuration==
%CREATE-I-CREATED, _VX2$DUA0:[XXXVMS_CLUCOM.SYSEXE] created
See https://www.golinuxcloud.com/configure-chrony-ntp-server-client-force-sync/ for more information.  
%CREATE-I-CREATED, _VX2$DUA0:[XXXVMS_CLUCOM.SYSLIB] created
 
%CREATE-I-CREATED, _VX2$DUA0:[LOCAL_UTIL] created
Edit <code>/etc/chrony.conf</code> to bypass <code>pool</code>, enable <code>log</code> and <code>allow 192.168.0.0/16</code> statements
%CREATE-I-CREATED, _VX2$DUA0:[LOCAL_UTIL.MISC] created
 
%CREATE-I-CREATED, _VX2$DUA0:[LOCAL_UTIL.SYS_MISC] created
As of 10/3/2023, radix has defined CNAMEs for time, time1 and time2, pointing to wort, courvoisier and radix respectively. Probably should be using these in the server statements, unless DHCP is actually passing the NTP servers properly. server statement should have the iburst parameter as well to make initial sync more timely.<syntaxhighlight lang="shell-session">
%CREATE-I-CREATED, _VX2$DUA0:[LOCAL_UTIL.XXXVMS] created
# systemctl restart chronyd
# systemctl status chronyd
# timedatectl
# chronyc tracking
# chronyc activity
</syntaxhighlight>
</syntaxhighlight>


==logwatch==
SYLOGICALS.COM
<syntaxhighlight lang="shell-session">
# dnf install -y logwatch
# vi /etc/logwatch/conf/logwatch.conf
</syntaxhighlight>Add line: <code> Format = html</code>
 
==rsyslog==
Add to the end of <code>/etc/rsyslog.conf</code> the line: <code>*.* @192.168.15.80:514</code> and restart the rsyslog service.
 
==postfix==
Update <code>/etc/aliases</code> with '''reroot@lan.kitsnet.us''' then<syntaxhighlight lang="shell-session">
# dnf install -y postfix
# newaliases
# systemctl enable postfix --now
# systemctl status postfix
</syntaxhighlight>
 
==Zabbix client==
<syntaxhighlight lang="shell-session">
# firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="192.168.15.64/32" port protocol="tcp" port="10050" accept'
# firewall-cmd --permanent --add-rich-rule='rule family="ipv6" port port="10050" protocol="tcp" accept'
# firewall-cmd --reload
# dnf install -y https://repo.zabbix.com/zabbix/5.0/rhel/8/x86_64/zabbix-release-5.0-1.el8.noarch.rpm
# #(for Rocky 9 use https://repo.zabbix.com/zabbix/5.0/rhel/9/x86_64/zabbix-release-5.0-3.el9.noarch.rpm)
# #(for CentOS 7 use https://repo.zabbix.com/zabbix/5.0/rhel/7/x86_64/zabbix-release-5.0-1.el7.noarch.rpm)
# dnf clean all
# dnf install -y zabbix-agent2
# vi /etc/zabbix/zabbix_agent2.conf
</syntaxhighlight>Change the two lines with server IP address and Hostname directove:<syntaxhighlight lang="shell-session">
Server=192.168.15.0/24,zoco.lan.kitsnet.us,2603:7000:9800:4742::e04,fd06:8328:ea57::e04
ServerActive=zabbix.lan.kitsnet.us
#Hostname=Zabbix server
</syntaxhighlight>save and then:<syntaxhighlight lang="shell-session">
# systemctl enable zabbix-agent2 --now
</syntaxhighlight>
 
==Automatic updates==
The configuration file is <code>/etc/dnf/automatic.conf</code> Set <code>apply_updates = yes</code> <syntaxhighlight lang="shell-session">
# sudo systemctl enable --now dnf-automatic.timer
# systemctl list-timers *dnf-*
</syntaxhighlight>
 
==Backup==
===Install Veeam and scripts===
<syntaxhighlight lang="shell-session">
# #do either
# dnf install -y http://wort/KitsNet/Veeam/veeam-release-el8-1.0.8-1.x86_64.rpm  && dnf check-update -y
# #or
# dnf install -y http://wort/KitsNet/Veeam/veeam-release-el9-1.0.8-1.x86_64.rpm  && dnf check-update -y
# dnf install -y veeam nfs-utils KNveeam
</syntaxhighlight>Clean install with Rocky 9 was weird last time (3/17/2023). The wrong version of blksnap installed. To get it right, I had to explicitly reference blksnap at the head of the dnf install list that included veeam.
 
===Prep NFS export on  \\bkup===
<syntaxhighlight lang="shell-session">
# mkdir /backups/Linux/newhost
# vi /etc/exports
</syntaxhighlight>Add line: <code>/backups/Linux/''newhost''        ''newhost''(rw,sync,no_root_squash,no_all_squash)          192.168.15.''##''(rw,sync,no_root_squash,no_all_squash)</code><syntaxhighlight lang="shell-session">
# exportfs -ra
</syntaxhighlight>
 
===Configure Veeam Backup Job===
*Jobname <code><''Newhost''>-all</code>
*Destination: Shared folder to NFS path <code>bkup/ backups/Linux/<''newhost''></code>
*Advanced, Scripts, Post-job <code>/usr/local/sbin/veeam_backup_status-email</code>
*For Active Directory Domain Controllers, specify a the Pre-job script as <code>/usr/local/sbin/backup_samba-ad-dc</code>
*A reboot is necessary before running the first backup on el9 based systems in order to load the necessary modules to support snapshots
 
==Housekeeping==
 
===Install miscellaneous KitsNet tools===
<syntaxhighlight lang="shell-session">
# dnf install -y KNsysmisc
</syntaxhighlight>


===Schedule check for current kernel version===
* Copy SYLOGICALS.COM from DAD$XXXVMS:[SYSMGR] to SYS$COMMON:[SYSMGR]. Tailor if necessary and execute.
Add the following entry to the root crontab<syntaxhighlight lang="text">
0 0 * * * sleep $(( RANDOM \% 14400)); /usr/local/sbin/KernelCurrent -r
</syntaxhighlight>This form will reboot the system if the kernel is found to be out of date.

Revision as of 21:15, 11 April 2025

1 Prep for XXXVMS[edit | edit source]

  • Start InfoServer software with @SYS$STARTUP:ESS$STARTUP DISK TAPE
  • Bind to and mount XXXVMS volume
    $ MCR ESS$LADCP BIND /SYS XXXVMS
    %LADCP-I-BIND, service bound to logical unit DAD$XXXVMS (_DAD1:)
    $ MOUNT /SYSTEM DAD$XXXVMS XXXVMS
    %MOUNT-I-WRITELOCK, volume is write locked
    %MOUNT-I-MOUNTED, XXXVMS mounted on _DAD1:
    
  • Decide devices for Cluster Common directory strucucture and local utilities. Use these as areguments to XXXVMS_PREP.COM. Default for each is SYS$SYSDEVICE
    $ @DAD$XXXVMS:[LOCAL_UTIL.XXXVMS]XXXVMS_PREP SYS$SYSDEVICE: SYS$SYSDEVICE:
    %CREATE-I-CREATED, _VX2$DUA0:[XXXVMS_CLUCOM] created
    %CREATE-I-CREATED, _VX2$DUA0:[XXXVMS_CLUCOM.LOGFILES.VX2] created
    %CREATE-I-CREATED, _VX2$DUA0:[XXXVMS_CLUCOM.SYSMGR] created
    %CREATE-I-CREATED, _VX2$DUA0:[XXXVMS_CLUCOM.SYSEXE] created
    %CREATE-I-CREATED, _VX2$DUA0:[XXXVMS_CLUCOM.SYSLIB] created
    %CREATE-I-CREATED, _VX2$DUA0:[LOCAL_UTIL] created
    %CREATE-I-CREATED, _VX2$DUA0:[LOCAL_UTIL.MISC] created
    %CREATE-I-CREATED, _VX2$DUA0:[LOCAL_UTIL.SYS_MISC] created
    %CREATE-I-CREATED, _VX2$DUA0:[LOCAL_UTIL.XXXVMS] created
    

SYLOGICALS.COM

  • Copy SYLOGICALS.COM from DAD$XXXVMS:[SYSMGR] to SYS$COMMON:[SYSMGR]. Tailor if necessary and execute.