Add bigboy alma kickstart
This commit is contained in:
parent
855d82c954
commit
6362b3b7ac
1 changed files with 420 additions and 0 deletions
420
alma10-minimal-bigboy.ks
Normal file
420
alma10-minimal-bigboy.ks
Normal file
|
|
@ -0,0 +1,420 @@
|
|||
#version=DEVEL
|
||||
# AlmaLinux 10.2 Unattended Installation Kickstart — BigBoy Sovereign AI Server
|
||||
#
|
||||
# This kickstart automates Phase 1 (Base OS Installation & Foundation)
|
||||
# Designed for 5-drive architecture: 1× NVMe (OS) + 4× SATA (data)
|
||||
#
|
||||
# Usage:
|
||||
# USB method: Insert USB, boot, type: inst.ks=file:///ks.cfg
|
||||
# HTTP method: Boot, type: inst.ks=http://<workbench_ip>:8000/alma10-minimal-bigboy.ks
|
||||
#
|
||||
# Reference: /home/john/projects/bigboy-alma/alma-phase1-install-workflow.md
|
||||
#
|
||||
# Checksum (validate before use):
|
||||
# sha256sum alma10-minimal-bigboy.ks
|
||||
# (Note: Update after final edits)
|
||||
#
|
||||
# ============================================================================
|
||||
|
||||
# ============================================================================
|
||||
# INSTALLATION MODE & FIRST BOOT
|
||||
# ============================================================================
|
||||
|
||||
# Use text mode installer (no GUI needed for headless server)
|
||||
text
|
||||
|
||||
# Do not run Setup Agent on first boot (we handle via Ansible Phase 2)
|
||||
firstboot --disable
|
||||
|
||||
# ============================================================================
|
||||
# LOCALIZATION & SYSTEM CONFIGURATION
|
||||
# ============================================================================
|
||||
|
||||
# Keyboard layout: US (standard for IT infrastructure)
|
||||
keyboard --xlayouts='us'
|
||||
|
||||
# System language: English (UTF-8 for international support)
|
||||
lang en_US.UTF-8
|
||||
|
||||
# System timezone: Europe/Rome UTC (CE headquarters timezone)
|
||||
# Logs will use this timezone for consistency across deployment
|
||||
timezone Europe/Rome --utc
|
||||
|
||||
# ============================================================================
|
||||
# NETWORK CONFIGURATION
|
||||
# ============================================================================
|
||||
|
||||
# Network: DHCP on primary interface (enp4s0)
|
||||
# Will typically receive 192.168.0.240 on Fritzy bench LAN
|
||||
# Phase 2 (Ansible) may configure static IP or DHCP reservation
|
||||
network --bootproto=dhcp --device=link --activate --hostname=bigboy --ipv6=off
|
||||
|
||||
# ============================================================================
|
||||
# SECURITY & AUTHENTICATION
|
||||
# ============================================================================
|
||||
|
||||
# Root password: LOCK (no password login allowed)
|
||||
# SSH key-based auth will be set up in Phase 2 (Ansible)
|
||||
# This prevents accidental password-based access
|
||||
rootpw --lock
|
||||
|
||||
# SELinux: Disabled for initial deployment (Phase 9 enables in Permissive)
|
||||
# Allows us to monitor denials during first month without blocking services
|
||||
selinux --disabled
|
||||
|
||||
# Firewall: Disabled during installation (Phase 9 hardens with firewalld)
|
||||
firewall --disabled
|
||||
|
||||
# ============================================================================
|
||||
# REPOSITORY CONFIGURATION
|
||||
# ============================================================================
|
||||
|
||||
# Base URL: AlmaLinux 10 official repositories
|
||||
# Uses kickstart mirror for fastest package downloads during install
|
||||
url --url="https://repo.almalinux.org/almalinux/10/BaseOS/x86_64/kickstart/"
|
||||
|
||||
# AppStream repository (applications, runtimes, development tools)
|
||||
repo --name="almalinux10-appstream" --mirrorlist="https://mirrors.almalinux.org/mirrorlist/10/appstream"
|
||||
|
||||
# CodeReady Linux Builder (CRB, equivalent to AlmaLinux 8 PowerTools)
|
||||
# Contains development packages needed for Phase 4 GPU driver compilation
|
||||
repo --name="almalinux10-crb" --mirrorlist="https://mirrors.almalinux.org/mirrorlist/10/crb/"
|
||||
|
||||
# EPEL (Extra Packages for Enterprise Linux)
|
||||
# Additional packages not in standard RHEL repos
|
||||
repo --name="epel10" --mirrorlist="https://mirrors.fedoraproject.org/mirrorlist?repo=epel-10&arch=x86_64"
|
||||
|
||||
# ============================================================================
|
||||
# BOOTLOADER CONFIGURATION
|
||||
# ============================================================================
|
||||
|
||||
# Bootloader: UEFI (modern standard)
|
||||
# Boot drive: NVMe (primary OS drive)
|
||||
# Location: partition (for UEFI boot)
|
||||
bootloader --location=partition --boot-drive=nvme0n1
|
||||
|
||||
# ============================================================================
|
||||
# DISK PARTITIONING SCHEME
|
||||
# ============================================================================
|
||||
#
|
||||
# Design:
|
||||
# NVMe (500GB): EFI boot (1GB) + btrfs OS (~499GB)
|
||||
# SATA Drive 1 (RAG): Single btrfs partition (mounted by Phase 3 Ansible)
|
||||
# SATA Drive 2 (Prompt): Single btrfs partition (mounted by Phase 3 Ansible)
|
||||
# SATA Drive 3 (Backup): Single btrfs partition (mounted by Phase 3 Ansible)
|
||||
# SATA Drive 4 (AI Logs): Single btrfs partition (mounted by Phase 3 Ansible)
|
||||
#
|
||||
# Important: SATA partitions are created but NOT mounted during kickstart.
|
||||
# Phase 3 Ansible role handles subvolume creation, mounting, and fstab.
|
||||
# ============================================================================
|
||||
|
||||
# Do not erase existing partitions (safety measure)
|
||||
clearpart --none --initlabel
|
||||
|
||||
# ============================================================================
|
||||
# NVMe PARTITIONING (Primary OS drive)
|
||||
# ============================================================================
|
||||
|
||||
# Partition 1: EFI System Partition
|
||||
# Size: 1 GB (sufficient for kernel + bootloader)
|
||||
# Filesystem: vfat (EFI standard)
|
||||
# Mount: /boot/efi (handled by Anaconda)
|
||||
part /boot/efi --fstype=efi --size=1024 --ondrive=nvme0n1
|
||||
|
||||
# Partition 2: OS Root (btrfs)
|
||||
# Size: Grow to fill remaining NVMe space (~499 GB)
|
||||
# Filesystem: btrfs (enables snapshots, compression, subvolumes)
|
||||
# Mount: / (root filesystem)
|
||||
# Note: Anaconda will create default btrfs layout; Phase 3 Ansible reconfigures
|
||||
part / --fstype=btrfs --size=1 --grow --ondrive=nvme0n1
|
||||
|
||||
# ============================================================================
|
||||
# SATA DRIVE PARTITIONING (Data drives — Phase 3 handles subvolumes)
|
||||
# ============================================================================
|
||||
|
||||
# Note: Device naming in installer:
|
||||
# Physical: /dev/nvme0n1 (NVMe), /dev/sda-/dev/sdd (SATA)
|
||||
# Installer may refer to them differently; use physical names
|
||||
#
|
||||
# All SATA drives created as single btrfs partitions here.
|
||||
# Phase 3 Ansible will:
|
||||
# - Create subvolumes on each drive
|
||||
# - Mount them at /srv/rag-library, /srv/prompt-library, etc.
|
||||
# - Configure fstab with UUIDs (from HARDWARE.md)
|
||||
# - Set compression and mount options
|
||||
|
||||
# SATA Drive 1 (sda): RAG Library partition
|
||||
# Will be mounted at /srv/rag-library in Phase 3
|
||||
part /srv/rag-raw --fstype=btrfs --size=1 --grow --ondrive=sda
|
||||
|
||||
# SATA Drive 2 (sdb): Prompt Library partition
|
||||
# Will be mounted at /srv/prompt-library in Phase 3
|
||||
part /srv/prompt-raw --fstype=btrfs --size=1 --grow --ondrive=sdb
|
||||
|
||||
# SATA Drive 3 (sdc): Backup partition
|
||||
# Will be mounted at /srv/backup in Phase 3
|
||||
part /srv/backup-raw --fstype=btrfs --size=1 --grow --ondrive=sdc
|
||||
|
||||
# SATA Drive 4 (sdd): AI Logs partition
|
||||
# Will be mounted at /srv/ai-logs in Phase 3
|
||||
part /srv/ai-raw --fstype=btrfs --size=1 --grow --ondrive=sdd
|
||||
|
||||
# ============================================================================
|
||||
# PACKAGE SELECTION
|
||||
# ============================================================================
|
||||
|
||||
%packages
|
||||
|
||||
# ============================================================================
|
||||
# CORE OS PACKAGES
|
||||
# ============================================================================
|
||||
|
||||
# @core: Essential OS packages (required)
|
||||
@core
|
||||
|
||||
# Kernel and headers (required for GPU driver compilation in Phase 4)
|
||||
kernel
|
||||
kernel-devel
|
||||
kernel-headers
|
||||
|
||||
# UEFI bootloader and shim (required for secure boot compatibility)
|
||||
grub2-efi-x64
|
||||
shim-x64
|
||||
efibootmgr
|
||||
|
||||
# ============================================================================
|
||||
# BUILD ESSENTIALS (for Phase 4 NVIDIA driver installation)
|
||||
# ============================================================================
|
||||
|
||||
# GCC compiler (required by NVIDIA driver kernel module compilation)
|
||||
gcc
|
||||
|
||||
# Make build tool (required by NVIDIA driver Makefile)
|
||||
make
|
||||
|
||||
# Patch utility (sometimes needed by driver post-install scripts)
|
||||
patch
|
||||
|
||||
# Perl (sometimes used in driver installation scripts)
|
||||
perl
|
||||
|
||||
# ============================================================================
|
||||
# SYSTEM UTILITIES (minimal essential set)
|
||||
# ============================================================================
|
||||
|
||||
# Networking and file transfer
|
||||
curl
|
||||
wget
|
||||
|
||||
# Text editors (vim for configuration editing)
|
||||
vim
|
||||
|
||||
# Version control (git for CI/CD in future phases)
|
||||
git
|
||||
|
||||
# Terminal multiplexer (tmux for Ansible session management)
|
||||
tmux
|
||||
|
||||
# System monitoring (htop for real-time system observation)
|
||||
htop
|
||||
|
||||
# ============================================================================
|
||||
# SYSTEM ADMINISTRATION
|
||||
# ============================================================================
|
||||
|
||||
# OpenSSH client and server (SSH access for Ansible Phase 2+)
|
||||
openssh-clients
|
||||
openssh-server
|
||||
|
||||
# Sudo (will be configured for Ansible non-root operations, Phase 2)
|
||||
sudo
|
||||
|
||||
# ============================================================================
|
||||
# STORAGE & MONITORING UTILITIES
|
||||
# ============================================================================
|
||||
|
||||
# btrfs-progs: Tools for btrfs filesystem management (Phase 3, Phase 11)
|
||||
btrfs-progs
|
||||
|
||||
# smartmontools: SMART disk health monitoring (Phase 11 thermal testing)
|
||||
smartmontools
|
||||
|
||||
# util-linux: Standard Linux system utilities (mount, fdisk, etc.)
|
||||
util-linux
|
||||
|
||||
# ============================================================================
|
||||
# EXPLICITLY EXCLUDED PACKAGES (reduce footprint)
|
||||
# ============================================================================
|
||||
|
||||
# Localization packages (not needed; en_US already specified)
|
||||
-kde-l10n-*
|
||||
-kde-l10n-common
|
||||
|
||||
# Network Manager GUI (not needed; CLI only)
|
||||
-network-manager-applet
|
||||
-nm-connection-editor
|
||||
|
||||
%end
|
||||
|
||||
# ============================================================================
|
||||
# SERVICES CONFIGURATION
|
||||
# ============================================================================
|
||||
|
||||
# Enabled services:
|
||||
# - sshd: SSH daemon (required for Ansible Phase 2+)
|
||||
# - NetworkManager: Network management daemon (handles DHCP, interfaces)
|
||||
#
|
||||
# Disabled services:
|
||||
# - avahi-daemon: mDNS/Bonjour (not needed on server)
|
||||
services --enabled=sshd,NetworkManager --disabled=avahi-daemon
|
||||
|
||||
# ============================================================================
|
||||
# POST-INSTALLATION SCRIPT
|
||||
# ============================================================================
|
||||
#
|
||||
# This script runs after package installation, before reboot.
|
||||
# Handles kickstart-specific setup that Anaconda can't do automatically.
|
||||
#
|
||||
# Logs: Written to /root/anaconda-post.log (check if install fails)
|
||||
# ============================================================================
|
||||
|
||||
%post --log=/root/anaconda-post.log
|
||||
#!/bin/bash
|
||||
|
||||
# ============================================================================
|
||||
# LOGGING INITIALIZATION (EU Sovereignty Policy)
|
||||
# ============================================================================
|
||||
|
||||
# Create deployment log directory (used by all Ansible phases)
|
||||
# Phase 0 (CE EU AI-Cloud Sovereignty Policy) requires structured logging
|
||||
mkdir -p /srv/deployment-log
|
||||
chmod 0755 /srv/deployment-log
|
||||
|
||||
# Log kickstart completion timestamp and system info
|
||||
{
|
||||
echo "=== Kickstart Installation Completed ==="
|
||||
echo "Timestamp: $(date -Iseconds)"
|
||||
echo "Hostname: $(hostname)"
|
||||
echo "Kernel: $(uname -r)"
|
||||
echo "AlmaLinux version: $(cat /etc/almalinux-release)"
|
||||
echo ""
|
||||
echo "Installed packages:"
|
||||
rpm -qa | wc -l
|
||||
echo ""
|
||||
echo "Disk layout:"
|
||||
lsblk
|
||||
echo ""
|
||||
echo "Network configuration:"
|
||||
ip addr show enp4s0
|
||||
echo ""
|
||||
echo "Repositories:"
|
||||
dnf repolist
|
||||
} >> /srv/deployment-log/kickstart.log 2>&1
|
||||
|
||||
# ============================================================================
|
||||
# GPU DRIVER PREPARATION (Phase 4 NVIDIA driver installation)
|
||||
# ============================================================================
|
||||
|
||||
# Blacklist nouveau (open-source NVIDIA driver) before GPU driver install
|
||||
# This prevents conflicts during Phase 4 NVIDIA proprietary driver installation
|
||||
cat >> /etc/modprobe.d/blacklist-nouveau.conf << 'EOF'
|
||||
# Blacklist nouveau to allow proprietary NVIDIA driver installation (Phase 4)
|
||||
blacklist nouveau
|
||||
options nouveau modeset=0
|
||||
EOF
|
||||
|
||||
# Rebuild initramfs without nouveau module
|
||||
# This ensures nouveau won't load on next boot
|
||||
dracut --force 2>&1 >> /srv/deployment-log/kickstart.log
|
||||
|
||||
# ============================================================================
|
||||
# SSH DAEMON SETUP (Foundation for Phase 2+ Ansible)
|
||||
# ============================================================================
|
||||
|
||||
# Enable SSH daemon to start on boot
|
||||
systemctl enable sshd
|
||||
|
||||
# Start SSH immediately (allows manual access if needed before Phase 2)
|
||||
systemctl start sshd
|
||||
|
||||
# Log SSH readiness
|
||||
{
|
||||
echo "SSH daemon enabled and started"
|
||||
systemctl status sshd | head -1
|
||||
} >> /srv/deployment-log/kickstart.log 2>&1
|
||||
|
||||
# ============================================================================
|
||||
# POST-SCRIPT COMPLETION LOG
|
||||
# ============================================================================
|
||||
|
||||
{
|
||||
echo ""
|
||||
echo "=== Kickstart Post-Installation Complete ==="
|
||||
echo "Timestamp: $(date -Iseconds)"
|
||||
echo "Deployment directory: /srv/deployment-log/"
|
||||
echo "Next phase: Ansible Phase 2 (System Configuration)"
|
||||
} >> /srv/deployment-log/kickstart.log 2>&1
|
||||
|
||||
# Exit success
|
||||
exit 0
|
||||
|
||||
%end
|
||||
|
||||
# ============================================================================
|
||||
# KDUMP CONFIGURATION (disable for minimal footprint)
|
||||
# ============================================================================
|
||||
|
||||
%addon com_redhat_kdump --disable
|
||||
%end
|
||||
|
||||
# ============================================================================
|
||||
# ANACONDA PASSWORD POLICY
|
||||
# ============================================================================
|
||||
#
|
||||
# Note: Root password is locked (rootpw --locked above)
|
||||
# These policies apply only to user account creation during installation
|
||||
# ============================================================================
|
||||
|
||||
%anaconda
|
||||
# Root password policy (not applicable due to locked root)
|
||||
# pwpolicy root --minlen=6 --minquality=50 --notstrict --nochanges --notempty
|
||||
|
||||
# User account policy (lenient; Ansible Phase 2 will harden)
|
||||
pwpolicy user --minlen=6 --minquality=50 --notstrict --nochanges --emptyok
|
||||
|
||||
# LUKS encryption policy (if encrypted partitions created)
|
||||
pwpolicy luks --minlen=6 --minquality=50 --notstrict --nochanges --notempty
|
||||
%end
|
||||
|
||||
# ============================================================================
|
||||
# INSTALLATION COMPLETION
|
||||
# ============================================================================
|
||||
|
||||
# Reboot automatically after installation completes
|
||||
# --eject: Attempt to eject installation media (USB) if possible
|
||||
reboot --eject
|
||||
|
||||
# ============================================================================
|
||||
# END OF KICKSTART FILE
|
||||
# ============================================================================
|
||||
#
|
||||
# Verification checklist before use:
|
||||
# [ ] NVMe device name is correct (nvme0n1)
|
||||
# [ ] SATA device names are correct (sda, sdb, sdc, sdd)
|
||||
# [ ] Network interface (enp4s0) matches hardware
|
||||
# [ ] Hostname (bigboy) is correct
|
||||
# [ ] Timezone (Europe/Rome) is correct
|
||||
# [ ] Repositories are accessible (test with: curl <repo_url>)
|
||||
# [ ] Post-install script has no syntax errors
|
||||
#
|
||||
# Expected outcome (Phase 1):
|
||||
# - AlmaLinux 10.2 minimal installation
|
||||
# - NVMe partitioned: EFI (1GB) + btrfs root (~499GB)
|
||||
# - SATA drives partitioned: single btrfs partition each
|
||||
# - SSH daemon running and ready for Ansible
|
||||
# - /srv/deployment-log/ created and logged
|
||||
# - Nouveau blacklisted, initramfs rebuilt
|
||||
# - System reboots automatically
|
||||
#
|
||||
# Next phase: Phase 2 (System Configuration & Secondary Drive Preparation)
|
||||
# ============================================================================
|
||||
Loading…
Add table
Add a link
Reference in a new issue