source: fedkit/prep_gateway.pl @ 968b84b

Last change on this file since 968b84b was 2c16731, checked in by Ted Faber <faber@…>, 11 years ago

Ping hosts on tap establishment

  • Property mode set to 100644
File size: 3.7 KB
RevLine 
[2edec46]1#!/usr/bin/perl
2
3use strict;
4
5use gateway_lib;
6
7use Getopt::Long;
[f8fa72b]8use File::Copy;
9use IO::File;
[2edec46]10
11my $ssh_pubkey;
12my $tunnelip;
13my $peer;
[8d4e4fb]14my $use_file;
[4e9719b]15my $fed_dir = "/usr/local/federation/";
[8d4e4fb]16my %opts = (
17    'ssh_pubkey=s' => \$ssh_pubkey,
[2edec46]18    'tunnelip' => \$tunnelip,
19    'peer=s' => \$peer,
[8d4e4fb]20    'use_file' => \$use_file,
[2edec46]21);
22
[8d4e4fb]23exit(20) unless GetOptions(%opts);
24
[f8fa72b]25if ($use_file) {
26    gateway_lib::read_config(gateway_lib::config_filename(), \%opts)
27}
28
29my $uname = `uname`;
30chomp $uname;
[8d4e4fb]31
[4e9719b]32# on portals make sure client.conf is in the override position (in fed_dir).
33my $client_conf = gateway_lib::client_conf_filename();
34
35copy($client_conf, "$fed_dir/etc/client.conf") 
36    unless $client_conf =~ /^$fed_dir/;
37
[f8fa72b]38if ($uname =~ /Linux/) {
[1d91791f]39    # Restart sshd with tunnel params
40    gateway_lib::set_sshd_params( 
41        { 'GatewayPorts' => 'yes', 'PermitTunnel' => 'yes' } );
[5e71d34]42    if ( -x "/etc/init.d/sshd") {
43        system("/etc/init.d/sshd restart");
44    }
45    elsif (-x "/etc/init.d/ssh") {
46        # XXX should look for service
47        system("/etc/init.d/ssh restart");
48    }
49    else {
50        print "Cannot figure out how to restart sshd\n";
51    }
[f8fa72b]52    gateway_lib::import_key($ssh_pubkey,'/root/.ssh/authorized_keys')
53        if $ssh_pubkey;
[8f654de]54    # Make sure the tap interface is available
55    system('modprobe tun');
[64e774d]56    # Install bridging software if not present
[09f292b]57    if ( -x '/usr/bin/yum' ) {
58        system('/usr/bin/yum -y install bridge-utils');
59    }
60    elsif (-x '/usr/bin/apt-get') {
[76c43e4]61        system('/usr/bin/apt-get -y update');
[09f292b]62        system('/usr/bin/apt-get -y install bridge-utils');
63    }
64    else {
65        print "Cannot install bridge utils, hope they're here.\n"
66    }
[f8fa72b]67}
68elsif ($uname =~ /FreeBSD/ ){
69    gateway_lib::set_sshd_params( 
70        { 'GatewayPorts' => 'yes', 'PermitTunnel' => 'yes' } );
71    system("/etc/rc.d/sshd restart");
[2edec46]72
[f8fa72b]73    gateway_lib::import_key($ssh_pubkey,'/root/.ssh/authorized_keys')
74        if $ssh_pubkey;
[2edec46]75
[f8fa72b]76    # Need these to make the Ethernet tap and bridge work.
77    system("kldload /boot/kernel/bridgestp.ko") 
78        if -r "/boot/kernel/bridgestp.ko"; 
79    system("kldload /boot/kernel/if_bridge.ko");
80    system("kldload /boot/kernel/if_tap.ko");
81}
[2edec46]82
83if ( $tunnelip ) {
84    my ($interface, $ip, $netmask, $mac, $router) = 
85        gateway_lib::deter_tunnelip();
86
[2b35261]87    gateway_lib::configure_outgoing_iface($interface, $ip, $netmask);
[2edec46]88    # Add the route to a peer.  Wait up to an hour for the peer's IP address to
89    # appear in the DNS.
[7e55a14]90    foreach my $p (split(/\s*,\s*/, $peer)) {
[2c16731]91        if ($p && $router ) {
92            gateway_lib::add_route($p, $router, 1, 60 *60);
93            # grease the skids
94            gateway_lib::ping_peer($p);
95        }
[b745876]96    }
[2edec46]97}
[64e774d]98my $coord_fn = "$fed_dir/etc/prep_done";
99my $coord_file = new IO::File(">$coord_fn") || die "Cannot open $coord_fn";
100
101print $coord_file `date`;
102$coord_file->close();
[2edec46]103
104exit(0);
[2b35261]105
106=pod
107
108=head1 NAME
109
110B<prep_tunnel.pl> - Prepare a tunnel node for use as either a service or connectivity gateway.
111
112=head1 OPTIONS
113
114=over 8
115
116=item B<peer=>I<hostname>
117
118The other gateway providing forwarding.
119
120=item B<ssh_pubkey=>I<keyfile>
121
122A public to install as authorized.
123
124=item B<tunnelip>
125
126True if the testbed uses the DETER tunnelip extension to provide external
127connectivity information
128
[8d4e4fb]129=item B<use_file>
130
131If given read additional parameters from the file in
[c6d6c43]132/proj/I<project>/exp/I<experiment>/tmp/I<hostname>.gw/conf where those are the
[8d4e4fb]133current testbed project and experiment and the hostname is before the first
134dot.  The file is option: value.
135
136
[2b35261]137=back
138
139=head1 SYNOPSIS
140
141B<prep_gateway.pl> laods the necessary kernel modules for low-level bridging
142configures the local sshd to allow it, restarts that sshd, and installs the
143given key in root's authorized keys.
144
145If the gateway supports DETER gateway, it setablishes outside connectivity and
146adds a host rout to the given peer.
147
148=head1 AUTHORS
149
150Ted Faber <faber@isi.edu>
151
152=cut
Note: See TracBrowser for help on using the repository browser.