lxc-ubuntu.in revision b145c6ef5e7959016f54dadc2a92398f7ec684a4
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# template script for generating ubuntu container for LXC
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher# This script consolidates and extends the existing lxc ubuntu scripts
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# XXX todo: add -lvm option
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# Copyright � 2011 Serge Hallyn <serge.hallyn@canonical.com>
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# Copyright � 2010 Wilhelm Meier
45db68ae27147955a4be4c2c772041824c0dc00fStephen Gallagher# Author: Wilhelm Meier <wilhelm.meier@fh-kl.de>
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher# This program is free software; you can redistribute it and/or modify
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# it under the terms of the GNU General Public License version 2, as
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# published by the Free Software Foundation.
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# This program is distributed in the hope that it will be useful,
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# but WITHOUT ANY WARRANTY; without even the implied warranty of
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# GNU General Public License for more details.
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# You should have received a copy of the GNU General Public License along
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# with this program; if not, write to the Free Software Foundation, Inc.,
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher cat <<EOF > $rootfs/etc/network/interfaces
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagheriface lo inet loopback
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagheriface eth0 inet dhcp
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher # so you can 'ssh $hostname.' or 'ssh $hostname.local'
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher if [ -f $rootfs/etc/dhcp/dhclient.conf ]; then
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher sed -i "s/<hostname>/$hostname/" $rootfs/etc/dhcp/dhclient.conf
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher elif [ -f $rootfs/etc/dhcp3/dhclient.conf ]; then
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher sed -i "s/<hostname>/$hostname/" $rootfs/etc/dhcp3/dhclient.conf
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher127.0.0.1 localhost $hostname
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher sed -i "s/=\"err\"/=0/" $rootfs/etc/udev/udev.conf
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher # remove jobs for consoles 5 and 6 since we only create 4 consoles in
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher echo "root:root" | chroot $rootfs chpasswd
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher packages=dialog,apt,apt-utils,resolvconf,iproute,inetutils-ping,vim,dhcp3-client,ssh,lsb-release,gnupg
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher packages=dialog,apt,apt-utils,resolvconf,iproute,inetutils-ping,vim,dhcp3-client,ssh,lsb-release,gnupg,netbase
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher packages=dialog,apt,apt-utils,resolvconf,iproute,inetutils-ping,vim,isc-dhcp-client,isc-dhcp-common,ssh,lsb-release,gnupg,netbase
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher packages=dialog,apt,apt-utils,resolvconf,iproute,inetutils-ping,vim,isc-dhcp-client,isc-dhcp-common,ssh,lsb-release,gnupg,netbase,ubuntu-keyring
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher # check the mini ubuntu was not already downloaded
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher if [ $? -ne 0 ]; then
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher echo "Failed to create '$cache/partial-$arch' directory"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher echo "Downloading ubuntu $release minimal ..."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher debootstrap --verbose --components=main,universe --arch=$arch --include=$packages $release $cache/partial-$arch $MIRROR
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher if [ $? -ne 0 ]; then
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher echo "Failed to download the rootfs, aborting."
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher cp -a $cache/rootfs-$arch $rootfs || return 1
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher if [ $? -ne 0 ]; then
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher echo "Checking cache download in $cache/rootfs-$arch ... "
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher if [ $? -ne 0 ]; then
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher echo "Failed to download 'ubuntu $release base'"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher echo "Copy $cache/rootfs-$arch to $rootfs ... "
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher if [ $? -ne 0 ]; then
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.utsname = $name
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.rootfs = $rootfs
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagherlxc.mount = $path/fstab
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.arch = $arch
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.cap.drop = sys_module mac_override mac_admin
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.cgroup.devices.deny = a
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# /dev/null and zero
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagherlxc.cgroup.devices.allow = c 1:3 rwm
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.cgroup.devices.allow = c 1:5 rwm
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.cgroup.devices.allow = c 5:1 rwm
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.cgroup.devices.allow = c 5:0 rwm
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher#lxc.cgroup.devices.allow = c 4:0 rwm
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher#lxc.cgroup.devices.allow = c 4:1 rwm
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# /dev/{,u}random
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.cgroup.devices.allow = c 1:9 rwm
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.cgroup.devices.allow = c 1:8 rwm
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.cgroup.devices.allow = c 136:* rwm
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.cgroup.devices.allow = c 5:2 rwm
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.cgroup.devices.allow = c 254:0 rwm
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherlxc.cgroup.devices.allow = c 10:229 rwm
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagherlxc.cgroup.devices.allow = c 10:200 rwm
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherproc $rootfs/proc proc nodev,noexec,nosuid 0 0
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallaghersysfs $rootfs/sys sysfs defaults 0 0
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher if [ $? -ne 0 ]; then
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher# fake some events needed for correct startup other services
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherdescription "Container Upstart"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherstart on startup
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher rm -rf /var/run/*.pid
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher rm -rf /var/run/network/*
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher /sbin/initctl emit stopped JOB=udevtrigger --no-wait
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher /sbin/initctl emit started JOB=udev --no-wait
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# ssh - OpenBSD Secure Shell server
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher# The OpenSSH server provides secure shell access to the system.
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherdescription "OpenSSH server"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherstart on filesystem
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherstop on runlevel [!2345]
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagherrespawn limit 10 5
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# replaces SSHD_OOM_ADJUST in /etc/default/ssh
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherpre-start script
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher test -x /usr/sbin/sshd || { stop; exit 0; }
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher test -e /etc/ssh/sshd_not_to_be_run && { stop; exit 0; }
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher test -c /dev/null || { stop; exit 0; }
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher mkdir -p -m0755 /var/run/sshd
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# if you used to set SSHD_OPTS in /etc/default/ssh, you can change the
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher# 'exec' line here instead
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherexec /usr/sbin/sshd
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# console - getty
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher# This service maintains a console on tty1 from the point the system is
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# started until it is shut down again.
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherstart on stopped rc RUNLEVEL=[2345]
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherstop on runlevel [!2345]
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherexec /sbin/getty -8 38400 /dev/console
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher# /lib/init/fstab: cleared out for bare-bones lxc
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher chroot $rootfs update-locale LANG=en_US.UTF-8
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher # remove pointless services in a container
056302a92862fda16351d7192600746746f38e5dStephen Gallagher chroot $rootfs /usr/sbin/update-rc.d -f ondemand remove
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher chroot $rootfs /bin/bash -c 'cd /etc/init; for f in $(ls u*.conf); do mv $f $f.orig; done'
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher chroot $rootfs /bin/bash -c 'cd /etc/init; for f in $(ls tty[2-9].conf); do mv $f $f.orig; done'
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher chroot $rootfs /bin/bash -c 'cd /etc/init; for f in $(ls plymouth*.conf); do mv $f $f.orig; done'
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher chroot $rootfs /bin/bash -c 'cd /etc/init; for f in $(ls hwclock*.conf); do mv $f $f.orig; done'
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher chroot $rootfs /bin/bash -c 'cd /etc/init; for f in $(ls module*.conf); do mv $f $f.orig; done'
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher # if this isn't lucid, then we need to twiddle the network upstart bits :(
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher sed -i 's/^.*emission handled.*$/echo Emitting lo/' $rootfs/etc/network/if-up.d/upstart
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher # for lucid and maverick, if not trimming, then add the ubuntu-virt
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher if [ $release = "lucid" -o $release = "maverick" ]; then
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher chroot $rootfs apt-get install --force-yes -y python-software-properties
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher chroot $rootfs add-apt-repository ppa:ubuntu-virt/ppa
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher chroot $rootfs apt-get install --force-yes -y lxcguest
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher # bind-mount the user's path into the container's /home
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher echo "$h $rootfs/$h none bind 0 0" >> $path/fstab
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher # copy /etc/passwd, /etc/shadow, and /etc/group entries into container
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher if [ $? -ne 0 ]; then
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher echo 'Warning: failed to copy password entry for $user'
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher if [ ! -e $cache ]; then
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher # lock, so we won't purge while someone is creating a repository
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher if [ $? != 0 ]; then
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher rm --preserve-root --one-file-system -rf $cache && echo "Done." || exit 1
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher$1 -h|--help -p|--path=<path> --clean [-a|--arch] [-b|--bindhome <user>] [--trim] [-r|--release]
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherrelease: lucid | maverick | natty | oneiric
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallaghertrim: make a minimal (faster, but not upgrade-safe) container
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagherbindhome: bind <user>'s home into the container
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherarch: amd64 or i386: defaults to host arch
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagheroptions=$(getopt -o a:b:hp:r:xn:c -l arch:,bindhome:,help,path:,release:,trim,name:,clean -- "$@")
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher# Code taken from debootstrap
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherif [ -x /usr/bin/dpkg ] && /usr/bin/dpkg --print-architecture >/dev/null 2>&1; then
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagherelif type udpkg >/dev/null 2>&1 && udpkg --print-architecture >/dev/null 2>&1; then
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher arch=`/usr/bin/udpkg --print-architecture`
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher --) shift 1; break ;;
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherif [ $hostarch = "i386" -a $arch = "amd64" ]; then
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher echo "can't create amd64 container on i386"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher echo "'debootstrap' command is missing"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagherif [ -z "$path" ]; then
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher echo "'path' parameter is required"
52261fe16203dec6e6f69177c6d0a810b47d073fStephen Gallagher echo "This script should be run as 'root'"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher echo "failed to install ubuntu $release"
2ea6196484055397cc4bc011c5960f790431fa9dStephen Gallagher echo "failed to configure ubuntu $release for a container"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallaghercopy_configuration $path $rootfs $name $arch
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagher echo "failed write configuration file"
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagherpost_process $rootfs $release $trim_container
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagherif [ ! -z $bindhome ]; then
e59e09b5010f262228bbdeb92a79b733bf5854b3Stephen Gallagherif [ ! -z $clean ]; then