Showing posts with label Centos. Show all posts
Showing posts with label Centos. Show all posts

Wednesday, 2 July 2014

Libvirt/qemu/kvm as non-root user

Prerequisites:

A server with KVM

I'm going to use the qemu user that is created when you install KVM but you could use any user you like.

First, your user should belong to the kvm group:

grep kvm /etc/group kvm:x:36:qemu

Create a libvirtd group and add your user to it

groupadd libvirt
usermod -a -G libvirt qemu


Create a new policykit config to allow access to libvirtd using your user account via ssh

vi /etc/polkit-1/localauthority/50-local.d/50-libvirt-remote-access.pkla

Add the following content:

[Remote libvirt SSH access]
Identity=unix-group:libvirt
Identity=unix-user:qemu
Action=org.libvirt.unix.manage
ResultAny=yes
ResultInactive=yes
ResultActive=yes


Restart libvirt

service libvirtd restart

Thursday, 19 September 2013

Disable DNSMASQ on KVM host

I have a fleet of servers with bridged, static IP's running as KVM guests. These servers do not require DHCP yet KVM by default starts up dnsmasq regardless.

Normally this is not an issue but I just so happened to need dnsmasq for DNS on one of the KVM hosts and it would refuse to start due to it being already invoked by libvirt.

You can't just disable the libvirt dnsmasq because it seems required for any virtual network that is active. You can however disable the unused virtual network which has the same effect.

# virsh net-destroy default
# virsh net-autostart --disable default



Then you can configure dnsmasq by editing /etc/dnsmasq.conf and it should work normally.

Thursday, 30 August 2012

Install scp, rsync and other tools on CentOS

When you do a "minimal" install of CentOS it doesn't install things like rsync and scp by default.

To install them do;

yum install openssh-clients rsync

Wednesday, 29 August 2012

Unmount stale NFS mounts

If you have a stale NFS mount hanging on your system it can cause various programs and utilities to fail. A typical symptom is a hang when using the 'df' command.

In such cases you cant do umount /path/to/stale/nfs because it will say "the device is busy" or words to that effect

To fix this you can unmount it with the 'lazy' option;

umount -l /path/to/stale/nfs

If you don't expect that mount point to ever be available again (for example the nfs server was decommissioned) then make sure you adjust /etc/fstab accordingly.

Thursday, 21 June 2012

HOWTO: Subversion 1.7.x on Centos 6

Howto: Subversion 1.7.x on Centos 6

Prerequisites:
* Minimal CentOS 6 installation
* SELinux & Firewall disabled

First, I'm going to start off with a bit of a mini-rant.

As usual, installing stuff on RHEL/CentOS is much harder than it is on Debian based systems. For one, the repositories are far more limited and what packages there are  are hopelessly outdated. Of course I understand that the RHEL philosophy is to freeze packages for a particular major version (6 in this case) and only provide security and bug fixes to these packages because this makes sense when running servers in a business environment, which is, of course, their target market.

This is a good thing.

However sometimes you want a newer version of something for whatever reason. Debian manages this by having a backports repository which can be optionally enabled to allow easy access to newer packages from the Debian testing branch. From what I can tell RHEL/CentOS do not have an equivalent option. Of course there are third party repositories that provide access to newer packages (to a degree), but coverage is sporadic at best.

In this case we will be required to resort to manually downloading third party RPM packages from WANDisco because they are not provided via any repository I could find. Apparently you are meant to fill out some sort of webform where you have to provide them with your personal details and "request" the packages along with an installer script that will allegedly install all the dependancies.

Feel free to go and fill out that form, however, I wasn't willing to go that route, it evoked too many memories of when I used to be a Windows user, where everything comes with strings attached.

The good news is that the RPMs are available without having to request them by going directly to here. The bad news is that these packages are for RHEL/CentOS 5 and I have been unable to find the equivalent packages for CentOS 6. This crucial difference will cause us to briefly flirt with the dreaded dependancy hell later on.

So, the first step is to obtain the following packages (64 bit links to my site below);

subversion-1.7.5-1.x86_64.rpm
mod_dav_svn-1.7.5-1.x86_64.rpm
neon-0.25.5-10.el5_4.1.x86_64.rpm

Note: If you don't want to trust my linked packages (and why should you?) or you require 32 bit versions then the first two are available from the WANDisco website mentioned above, the third I found at rpm.pbone.net.

OK, with the three files in hand, we probably should ensure our system is up to date before we proceed.

yum update

Subversion requires Apache web server, let's install it now;

yum install httpd

You probably want Apache to start automatically after a reboot;

chkconfig httpd on

We should also start it now;

service httpd start

These dependencies are required for SVN 1.7.x and thankfully they are all available in the standard CentOS repository;

yum install openssl098e compat-db43 compat-expat1 compat-openldap

Tip: In cases like this you can use something like "yum whatprovides ./libldap-2.3.so.0" to find where your dependencies live

Here's where we hit a minor snag. If we try and install the subversion rpm at this point it will complain that it depends on neon-0.25 but the CentOS6 repository provides v0.29.

Another rant: This is another bugbear I have with the yum/rpm system. It seems to be much more finicky than Debian and backwards compatibility is often non-existent. In this case the WANDisco RPM has been built to explicitly require neon 0.25 even though I am pretty sure that v 0.29 is fully backwards compatible and would work. It's a stupid situation and one that I honestly can't remember finding in Debian/Ubuntu over nearly 10 years of using that distro. Maybe that is because you are not forced to rely on dodgy third party compiled packages on a regular basis I suppose.

Anyway, luckily for us neon does not have any onerous dependency requirements of it's own so we can go ahead and install the older version manually without falling into dependency hell, which is a bit of luck.

rpm -i neon-0.25.5-10.el5_4.1.x86_64.rpm

With neon v0.25 installed, we can go ahead and install subversion and mod_dav_svn;

rpm -i subversion-1.7.5-1.x86_64.rpm
rpm -i mod_dav_svn-1.7.5-1.x86_64.rpm


Note: If you see something like this;

warning: mod_dav_svn-1.7.5-1.x86_64.rpm: Header V4 DSA/SHA1 Signature, key ID 3bbf077a: NOKEY

you can ignore it, unless you want to obtain and configure the appropriate validation keys for these files which is outside the scope of this document.

We can confirm that subversion is now installed;

# rpm -qa | grep subversion
subversion-1.7.5-1.x86_64


OK, all is good, right? Well, yes and no. Everything is OK right now but if you try and do a yum update, it will fail like this;

--> Finished Dependency Resolution
Error: Package: subversion-1.7.5-1.x86_64 (installed)
           Requires: libneon.so.25()(64bit)
           Removing: neon-0.25.5-10.el5_4.1.x86_64 (installed)
               libneon.so.25()(64bit)
           Updated By: neon-0.29.3-1.2.el6.x86_64 (base)
               Not found
You could try using --skip-broken to work around the problem
You could try running: rpm -Va --nofiles --nodigest


Aaargh!

To workaround this, we can exclude neon from being updated;

vi /etc/yum.conf

Add this line somewhere in the file;

exclude=neon*

Now our yum update won't try and upgrade neon and therefore complain about dependency problems;

# yum update
Loaded plugins: fastestmirror
Loading mirror speeds from cached hostfile
 * base: ftp.swin.edu.au
 * extras: ftp.swin.edu.au
 * updates: ftp.swin.edu.au
base                                                                                                 
extras    updates                                                                                              Setting up Update Process
No Packages marked for Update


And that's it, go grab yourself a beverage for a job well done!

Tuesday, 22 May 2012

CentOS 6 Bridged Networking

If you are intending to run KVM under Centos, you will most likely want to use bridged networking.

I am starting with a standard CentOS 6 "minimal" install but the same process applies to RHEL and CentOS all versions.



First, install the bridge utils package;

yum install bridge-utils


Create/edit these two files, substituting the ipaddress and other details as applicable;

# cat /etc/sysconfig/network-scripts/ifcfg-eth0
DEVICE="eth0"
NM_CONTROLLED="no"
ONBOOT=yes
HWADDR=FF:FF:FF:FF:FF:FF   # Use the actual hardware address for your NIC
TYPE=Ethernet
BRIDGE=br0

# cat /etc/sysconfig/network-scripts/ifcfg-br0
DEVICE="br0"
TYPE=Bridge
BOOTPROTO=static
ONBOOT=yes
IPADDR=10.0.0.1
PREFIX=24
GATEWAY=10.0.0.254     # You can put this in /etc/sysconfig/network if you prefer
DNS1=10.0.0.2
DOMAIN=example.net
DEFROUTE=yes
IPV4_FAILURE_FATAL=yes
IPV6INIT=no
NAME="System br0"


Restart your server and you should now have a bridge adapter called "br0";

# ifconfig br0
br0    Link encap:Ethernet  HWaddr FF:FF:FF:FF:FF:FF 
          inet addr:10.0.0.1  Bcast:10.255.255.255  Mask:255.255.255.0
          inet6 addr: fe80::21a:64ff:fe78:3f44/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:9092 errors:0 dropped:0 overruns:0 frame:0
          TX packets:4424 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:0
          RX bytes:9175506 (8.7 MiB)  TX bytes:369549 (360.8 KiB)


Confirm the bridge;

#brctl show
bridge name          bridge id           STP enabled    interfaces
br0                  8000.001a64783f44   no             eth0
virbr0               8000.525400badaa9   yes            virbr0-nic