Class: Pero::Docker

Inherits:
Object
  • Object
show all
Defined in:
lib/pero/docker.rb

Instance Attribute Summary collapse

Instance Method Summary collapse

Constructor Details

#initialize(version, image_name, environment, volumes) ⇒ Docker

Returns a new instance of Docker.



9
10
11
12
13
14
# File 'lib/pero/docker.rb', line 9

def initialize(version, image_name, environment, volumes)
  @server_version = version
  @image_name = image_name
  @environment = environment
  @volumes = volumes
end

Instance Attribute Details

#image_nameObject (readonly)

Returns the value of attribute image_name.



7
8
9
# File 'lib/pero/docker.rb', line 7

def image_name
  @image_name
end

#server_versionObject (readonly)

Returns the value of attribute server_version.



7
8
9
# File 'lib/pero/docker.rb', line 7

def server_version
  @server_version
end

#volumesObject (readonly)

Returns the value of attribute volumes.



7
8
9
# File 'lib/pero/docker.rb', line 7

def volumes
  @volumes
end

Instance Method Details

#alerady_run?Boolean

Returns:

  • (Boolean)


49
50
51
52
# File 'lib/pero/docker.rb', line 49

def alerady_run?
  c = find
  c && c.info['State'] == 'running' && c
end

#buildObject



16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
# File 'lib/pero/docker.rb', line 16

def build
  Pero.log.info 'start build container'
  ::Docker.options[:read_timeout] = 300
  begin
    image = if image_name
              ::Docker::Image.create('fromImage' => image_name)
            else
              ::Docker::Image.build(
                docker_file,
                {
                  'platform' => ENV['DOCKER_DEFAULT_PLATFORM'] || 'linux/amd64'
                }
              )
            end
  rescue StandardError => e
    Pero.log.debug docker_file
    Pero.log.error "failed build container #{e.inspect}"
    raise e
  end
  Pero.log.info 'success build container'
  image
end

#conf_dirObject



123
124
125
126
127
128
129
130
131
132
133
# File 'lib/pero/docker.rb', line 123

def conf_dir
  if Gem::Version.new('4.0.0') > Gem::Version.new(server_version)
    '/etc/puppet'
  elsif Gem::Version.new('5.0.0') > Gem::Version.new(server_version) && Gem::Version.new('4.0.0') <= Gem::Version.new(server_version)
    '/etc/puppetlabs/puppet/'
  elsif Gem::Version.new('6.0.0') > Gem::Version.new(server_version) && Gem::Version.new('5.0.0') <= Gem::Version.new(server_version)
    '/etc/puppetlabs/puppet/'
  else
    '/etc/puppetlabs/puppet/'
  end
end

#container_nameObject



39
40
41
# File 'lib/pero/docker.rb', line 39

def container_name
  "pero-#{Digest::MD5.hexdigest(Dir.pwd)[0..5]}-#{@environment}"
end

#create_caObject



176
177
178
179
180
181
182
183
184
# File 'lib/pero/docker.rb', line 176

def create_ca
  if Gem::Version.new('5.0.0') > Gem::Version.new(server_version)
    'puppet cert generate `hostname` --dns_alt_names localhost,127.0.0.1'
  elsif Gem::Version.new('6.0.0') > Gem::Version.new(server_version)
    'puppet cert generate `hostname` --dns_alt_names localhost,127.0.0.1'
  else
    'puppetserver ca setup --ca-name `hostname` --subject-alt-names DNS:localhost'
  end
end

#docker_fileObject



135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
# File 'lib/pero/docker.rb', line 135

def docker_file
  release_package, package_name = if Gem::Version.new('4.0.0') > Gem::Version.new(server_version)
                                    ["puppetlabs-release-el-#{el}.noarch.rpm", 'puppet-server']
                                  elsif Gem::Version.new('5.0.0') > Gem::Version.new(server_version) && Gem::Version.new('4.0.0') <= Gem::Version.new(server_version)
                                    ["puppetlabs-release-pc1-el-#{el}.noarch.rpm", 'puppetserver']
                                  elsif Gem::Version.new('6.0.0') > Gem::Version.new(server_version) && Gem::Version.new('5.0.0') <= Gem::Version.new(server_version)
                                    ["puppet5-release-el-#{el}.noarch.rpm", 'puppetserver']
                                  elsif Gem::Version.new('7.0.0') > Gem::Version.new(server_version) && Gem::Version.new('6.0.0') <= Gem::Version.new(server_version)
                                    ["puppet6-release-el-#{el}.noarch.rpm", 'puppetserver']
                                  else
                                    ["puppet7-release-el-#{el}.noarch.rpm", 'puppetserver']
                                  end

  vault_repo = if el == 6
                 <<~EOS
                   RUN sed -i "s|#baseurl=|baseurl=|g" /etc/yum.repos.d/CentOS-Base.repo \
                     && sed -i "s|mirrorlist=|#mirrorlist=|g" /etc/yum.repos.d/CentOS-Base.repo \
                     && sed -i "s|http://mirror\.centos\.org/|http://vault\.centos\.org/|g" /etc/yum.repos.d/CentOS-Base.repo
                 EOS
               else
                 ''
               end

  legacy_signing = if Gem::Version.new('3.0.0') > Gem::Version.new(server_version)
                     "RUN echo 'LegacySigningMDs md5' >> /etc/pki/tls/legacy-settings"
                   else
                     ''
                   end

  <<~EOS
    FROM #{from_image}
    #{vault_repo}
    #{legacy_signing}
    RUN curl -L -k -O https://yum.puppetlabs.com/#{release_package}  && \
    rpm -ivh #{release_package}
    RUN yum install -y #{package_name}-#{server_version}
    ENV PATH $PATH:/opt/puppetlabs/bin
    RUN echo -e "#{puppet_config.split(/\n/).join('\\n')}" > #{conf_dir}/puppet.conf
  EOS
end

#elObject



201
202
203
204
205
206
207
# File 'lib/pero/docker.rb', line 201

def el
  if Gem::Version.new('3.5.1') > Gem::Version.new(server_version)
    6
  else
    7
  end
end

#findObject



43
44
45
46
47
# File 'lib/pero/docker.rb', line 43

def find
  ::Docker::Container.all(all: true).find do |c|
    c.info['Names'].first == "/#{container_name}"
  end
end

#from_imageObject



209
210
211
# File 'lib/pero/docker.rb', line 209

def from_image
  "centos:#{el}"
end

#puppet_configObject



107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
# File 'lib/pero/docker.rb', line 107

def puppet_config
  <<~EOS
    [master]
    vardir = /var/puppet
    certname = puppet
    dns_alt_names = puppet,localhost
    autosign = true
    environment_timeout = unlimited
    codedir = /etc/puppetlabs/code

    [main]
    server = puppet
    #{@environment && @environment != '' ? "environment = #{@environment}" : nil}
  EOS
end

#runObject



54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
# File 'lib/pero/docker.rb', line 54

def run
  ::Docker::Container.all(all: true).each do |c|
    c.delete(force: true) if c.info['Names'].first == "/#{container_name}"
  end

  vols = volumes || []
  vols << "#{Dir.pwd}:/etc/puppetlabs/code/environments/#{@environment}"
  vols << "#{Dir.pwd}/keys:/etc/puppetlabs/puppet/eyaml/"

  container = ::Docker::Container.create({
                                           'name' => container_name,
                                           'Hostname' => 'puppet',
                                           'Image' => build.id,
                                           'ExposedPorts' => { '8140/tcp' => {} },
                                           'HostConfig' => {
                                             'Binds' => vols,
                                             'PortBindings' => {
                                               '8140/tcp' => [{ 'HostPort' => '0' }]
                                             }
                                           },
                                           'platform' => ENV['DOCKER_DEFAULT_PLATFORM'] || 'linux/amd64',
                                           'Cmd' => ['bash', '-c', "rm -rf #{conf_dir}/ssl/* && #{create_ca} && #{run_cmd}"]
                                         })

  Pero.log.info 'start puppet master container'
  container.start

  container = find
  raise "can't start container" unless container

  begin
    Retryable.retryable(tries: 20, sleep: 5) do
      https = Net::HTTP.new('localhost', container.info['Ports'].first['PublicPort'])
      https.use_ssl = true
      https.verify_mode = OpenSSL::SSL::VERIFY_NONE
      Pero.log.debug 'start server health check'
      https.start do
        response = https.get('/')
        Pero.log.debug "puppet http response #{response}"
      end
    rescue StandardError => e
      Pero.log.debug e.inspect
      raise e
    end
  rescue StandardError
    Pero.log.error "can't start container.please check [ docker logs #{container.info['id']} ]"
    container = find
    container.kill if container && container.info['State'] != 'exited'
    raise "can't start puppet server"
  end
  container
end

#run_cmdObject



186
187
188
189
190
191
192
193
194
195
196
197
198
199
# File 'lib/pero/docker.rb', line 186

def run_cmd
  if Gem::Version.new('3.0.0') > Gem::Version.new(server_version)
    # /var/puppet/run is created for the first time by running `puppet master`,
    # but `puppet master` will fail because the permissions are wrong.
    # So, let the `puppet master` fail once, fix the permission of /var/puppet/run, and execute `puppet master` again.
    'puppet master --no-daemonize --verbose || (chown puppet: /var/puppet/run && puppet master --no-daemonize --verbose)'
  elsif Gem::Version.new('5.0.0') > Gem::Version.new(server_version)
    'puppet master --no-daemonize --verbose'
  elsif Gem::Version.new('6.0.0') > Gem::Version.new(server_version)
    'puppetserver foreground'
  else
    'puppetserver foreground'
  end
end