#6392 Installers refactoring tracker
Closed: fixed Opened by mbasti.

All related installers refactoring tickets should be blockers of this ticket.


Related ticket: #6393

Related ticket: #6413

master:

  • eac6f52957c361c219ad6048b515ddb62da31154 Remove redundant dsinstance restart
  • 83e72d704630b9cc5a1f713dfee30601950eb5e9 Move ds.replica_populate to an update plugin
  • 7279ef1d0f28dae9f3203362ca9e2245e56e111f Moved update of DNA plugin among update plugins
  • 2fdc2d0cb7fa98992fe6c2070cb5dc34c500ac09 CertDB: add API for non-destructive initialization from PKCS#12 bundle
  • b1283c1e56976a3019c81c3be88fa821431ac6a6 initialize empty /etc/http/alias during server/replica install
  • 8a7e79a7a6fad8dc87c8f148cb5098434f988ea3 replica install: use one remote CA host name everywhere
  • 0e232b5f526168af6bb0b52244f79dfacb43a9b7 replica install: use one remote KRA host name everywhere
  • dc38d53de1eff71570ec5ef55db6de2c6f9b5bbd install: merge all CA install code paths into one
  • 0933e080aa9635bba12efc53d904d524b309027f install: merge all KRA install code paths into one
  • f98faec47847022879b8bceb63839fcfd6e45402 ipa-client-install: move client install to module
  • 5c16608a0d5d4abe98319a077917f5424b72d031 client: remove unneded return configure_krb5_conf
  • 49f201e2b2523c83fa2b20fe91c91733e2ee947f client: remove unneded return from configure_ipa_conf
  • cc6efb97985bb93e3cdb2a6c2943d45e1132e122 client: install function: return constant not hardcoded number
  • c30b45ab157f611312c0cd0f4f7c3a12d7a02c11 client: remove extra return from hardcode_ldap_server
  • 1c9267803c6f41cc7d7485024f8864fbd62c9128 client: import IPAChangeConf directly instead the module
  • 31a9ef4f8b8e2d6bb11f68ce34a7575ced9816aa IPAChangeConf: use constant for empty line
  • 2dedfe5d33062fc7121bf36be12d7b423b62120a server install: do not restart httpd during CA install
  • cf1c4e84e74ea15fe5cf7219872cf131bd53281e client: Making the configure functions more readable
  • bddd4fac462c07458297d1cea5272bde97fb3707 Replaced EMPTY_LINE constant with a function call
  • 822e1bc82af3a6c1556546c4fbe96eeafad45762 replica install: merge RA cert import into CA install
  • 89bb5ed1ebc0b5952a1d5eae34e0f39c5ba540d7 replica install: merge KRA agent cert export into KRA install
  • 8e36e030910a4a6ec5ddb37cc19824f37b25ab51 certs: do not re-create NSS database when requesting service cert
  • 3d5161d7e943fc6d4d092d18fc980fd40d21a59f Separate function to purge IPA host principals from keytab
  • a6ec37255441294285fac58c9bf08129db110fac do partial host enrollment in domain level 0 replica install
  • 19912796edf5d6427920ff67c33e6288223e0466 fix incorrect invocation of ipa-getkeytab during DL0 host enrollment
  • 33537f555636db935dd809b62498e2415d765e8e client: make statestore and fstore consistent with server
  • 2c226ebc27e2a4e2677549003c4c70a777794296 client: move checks to client.install_check
  • 3f690a0a3a7e039183eca1578a3cb13f2c0632ef client: extract checks from install to install_check
  • fcea3b3fb88ede0e9414f83ac2372e000e728587 client: extract checks from uninstall to uninstall_check
  • 83fe6b626fd2fb7f43ddf3568aaffca1ce569079 client: move custom env variable into client module
  • 1f65c07524c8cf80996de9f6250a4e19c3a043c9 client: Remove useless except in ipa-client-install
  • 8cbbb5359155446be22a5efb1e2372e527d2d745 client: fix script execution
  • bbad08900bbe8f76e59b159cd2af800f5c089ca1 client: move clean CCACHE to module
  • b3786730e50080fa4dadeffa86388592c10b3a62 client: move install cleanup from ipa-client-install to module
  • c38ce49e8d280e52c61f722b0e5ad7aa9f53cc1a client: move install part to else branch
  • 5249eb817efbb5708d097173a8d5f1e322fb201e client: use exceptions instead of return states
  • 847b6eddab00973740413b4c46f86940cb73d25a client: use correct code for failed uninstall
  • 0914a3aeb778986dea4020ddf8ca550ebef02bad replicainstall: Unify default.conf file creation
  • 990e1acb1a667b90619e7799bb96e2cd81e97e61 Fix to ipachangeconf docstrings
  • b068d3336ad65748881d0dc74505f41dac9f0f13 Added file permissions option to IPAChangeConf.newConf()
  • a3c9def4e982bcc90e9ece0900993ace53777906 Import just IPAChangeConf instead of the whole module
  • 8cb315af627d712dd21396164cfa2b5d03ccb466 replica install: fix DS restart failure during replica promotion
  • 87c3c1abecdfb8b5eb227239eeacfbee386a7ed7 install: use ldaps for pkispawn in ipa-ca-install
  • bde1d82ebe32be339c30c85048fd18e1ce99867d Move httpd restart to DNS installation
  • ba4df6449aaa0843ab43a1a2b3cb1df8bb022c24 Move the pki-tomcat restart to cainstance creation
  • 1fc128b05fd13a3f400346cc6d2e7fb5f66875ac Properly bootstrap replica promotion api
  • 500327b7754e032738ab88ae19fad287f2d8cdab First step of merging replica installation of both DLs
  • 2de43e7aca7d4d4873ad3e5053ad75311e81dc68 Split install_http_certs() into two functions
  • e40d6a2a53a931b4d2be3e45c84da99950e60a84 Use host keytab to connect to remote server on DL0
  • 0b68899779e4500d231e974f11e428f8a3577538 Remove redundant CA cert file existance check
  • 928a4aa6f281df55e0f655d5cbf5a327794507b6 Use os.path.join instead of concatenation
  • 606cac1c9e85633f54b1cc1c9fc1351e6d1a545f Use updated CA certs in replica installation
  • 835923750bff4f26d9b90df9870a961d16728488 Take advantage of the ca/kra code cleanup in replica installation
  • bc2e3386e7fa30211a46c0c2284d901cc2509147 replicainstall: move common checks to common_check()
  • 37578cfc2bbec99d75b19c94c337c406bf6a6ef7 Use same means of checking replication agreements on both DLs
  • 1e6366bc9f10de66de84b9506341f021fb3650d9 Offer more general way to check domain level in replicainstall
  • 15f282cf2c4a5315aa3e259bd923718685d88245 service installers: clean up the inheritance
  • 81bf72dc350b9c7daab669aaa796e96aee6ecbb8 Make service user name a class member of Service
  • 32599987fdc998e104846e8a176f70399cca2af2 Turn Kerberos-related properties to Service class members
  • 4286f3885b173da9ceeb2d13d66f90336b9ef094 Service: common method for service keytab requests
  • 6181844c0ce62b8d7d35554032346396b20ad3c0 use DM credentials to retrieve service keytab only in DLO
  • 3129b874a2c222ff207f1302e5d85ae12df2eac9 dsinstance: use keytab retrieval method from parent class
  • 4e97a0171a862e20089863e4bf0ec88d0ba98a53 installers: restart DS after KDC is configured
  • 73fc15556d28706b0b9a10480fee8d56b2be9ab7 domain-level agnostic keytab retrieval in httpinstance
  • 7cd3b1bfa76c846b7ffec18e380b71a6617d97ec installutils: remove 'install_service_keytab' function
  • 8c742b1539591b49474fe8ec871e1b523e9898bd Fix CA replica install on DL1
  • a641e279ff76e09f59c4d5fef1dc1f9355dbacf7 install: improve CLI positional argument handling
  • be0c1afa74cdf9a6e7640cd4110519e61250ae93 install: simplify CLI option parsing
  • 9fd1981ae8abf720f5234b6049c9beabbb1f2211 install: introduce updated knob constructor
  • a929ac333833a5cbf503d1fcbdee150658d933a4 install: use standard Python classes to declare knob types
  • 043c262ce48a0d667e914c315e21e6e1b3862202 install: declare knob CLI names using the argparse convention
  • 269ca6c4547fc017bb3a88e994ca770047122b3e install: make knob base declaration explicit
  • 08a446a6bc516936497c1e0f278a699148f6330c install: fix subclassing of knob groups
  • a8fdb8de8248fe24f382e44b05293405b0b309ac install: introduce installer class hierarchy
  • 225fae841882832668c0842479ab11c89dfcd1a5 install: migrate server installers to the new class hierarchy
  • 714699a81fa377e6033cbc7564f0f0fd10cd9f1a install: allow specifying verbosity and console log format in CLI
  • 09423acb6574a3773d7783f9ddec022bed3539c8 install: migrate client install to the new class hierarchy

There seems to be a regression: ipa-replica-install tries to install
a CA if there is a CA in the topology, even if --setup-ca is not provided.

Seems to have occurred in 822e1bc82af3a6c1556546c4fbe96eeafad45762, where
instances of if config.setup_ca: were replaced with if ca_enabled:.

Fraser can you provide steps to reproduce? I haven't been able to reproduce it:

My steps:

[master ~]# ipa-server-install  # with CA
[replica ~]# ipa-client-install --server <server> --domain <domain>
[replica ~]# ipa-replica-install
[replica ~]# ipactl status
Directory Service: RUNNING
krb5kdc Service: RUNNING
kadmin Service: RUNNING
ipa_memcached Service: RUNNING
httpd Service: RUNNING
ipa-custodia Service: RUNNING
ntpd Service: RUNNING
ipa-otpd Service: RUNNING
ipa: INFO: The ipactl command was successful

There is a regression related to ipa-replica-install. The RA agent certificate is not tracked any more, while it used to be on all replicas in ca-full installation (whether the replica was running a CA or not).

getcert list -n ipaCert

does not output anything.

It seems that commit 822e1bc82af3a6c1556546c4fbe96eeafad45762 is responsible for this issue.

There is a regression with ipa-server-install --external-ca:

[...]
  [48/48]: configuring directory to start on boot
Done configuring directory server (dirsrv).
ipa.ipapython.install.cli.install_tool(CompatServerMasterInstall): ERROR    'dm_password'
ipa.ipapython.install.cli.install_tool(CompatServerMasterInstall): ERROR    The ipa-server-install command failed. See /var/log/ipaserver-install.log for more information

The exception is:

  File "/usr/lib/python2.7/site-packages/ipaserver/install/server/install.py", line 774, in install
    write_cache(cache_vars)
  File "/usr/lib/python2.7/site-packages/ipaserver/install/server/install.py", line 148, in write_cache
    options['dm_password'], top_dir)
2016-11-14T17:40:02Z DEBUG The ipa-server-install command failed, exception: KeyError: 'dm_password'
2016-11-14T17:40:02Z ERROR 'dm_password'
2016-11-14T17:40:02Z ERROR The ipa-server-install command failed. See /var/log/ipaserver-install.log for more information

mbasti: I can't repro either. Maybe I had some local changes that broke it... ¯_(ツ)_/¯

regression fix:
master:

  • 6ca96b3db03d4f3c5dbf465ca3d36bd563771c47 Fix the naming of ipa-dnskeysyncd service principal

master:

  • 55b14abcb561422cf48755dae6b0638656535fe5 remove Knob function

master:

  • 4221266562778806f02748fee2dfbd814261f2b4 replica install: track the RA agent certificate again

master:

  • 4fff09978eab520d130d87c0112b5caac907e651 server install: fix external CA install

KRA agent PEM file is no longer present after ipa-server-install in /etc/httpd/alias/ caused by 822e1bc.

Has a PR:
github#356

master:

  • 998c87af2b7b2c704d34dd27fe99bda495a59e23 server install: fix KRA agent PEM file not being created

KRA agent PEM file is no longer present after ipa-replica-install in /etc/httpd/alias/

master:

  • 26630db9d0fb1d9c8a02840b71b3fb3e8bdf3e0d client install: correctly report all failure

master:

  • 9ac068ad04a2323192f9447986a3d1c5431f1e50 Don't prepend option names with additional '--'

Metadata Update from @mbasti:
- Issue assigned to someone
- Issue set to the milestone: FreeIPA 4.5

master:

  • 00f49dd7bbf277757902c94990d33758fec56b23 server install: remove duplicate -w option
  • 5efa55c88d73d9f5db77df4be9fedf03f9b323d1 install: add missing space in realm_name description
  • 94f362d7b0b6c838752eb2f6674149e96d3ae95b server install: remove duplicate knob definitions
  • 1cfe06c79eb0b98a0f4bd663165156596b59e85f client install: split off SSSD options into a separate class
  • 774d8d0a5dc0ac175ab0cecc76001632c2a79744 install CLI: remove magic option groups
  • 2fc9feddd02bb17c3a9eb7efde83277fcf93252c install: re-introduce option groups

Metadata Update from @mbasti:
- Issue close_status updated to: None

Metadata Update from @jcholast:
- Issue close_status updated to: fixed
- Issue status updated to: Closed (was: Open)

Metadata