Showing posts with label Automation. Show all posts
Showing posts with label Automation. Show all posts

Monday, June 23, 2025

Ansible Modules

June 23, 2025 0

 

inlinefile module:

Adding /Modify or delete a line inside of file.
Main parameter:
path - full path of the file
line - text
insertbefore / insertafter - EOF/regular expression
validate - Validation of command
state - Present/absent
mode/owner/group - permission
setype/seuser/selevel - SElinux setup
Ping Module:
It is validated the host reachability of remote host.
ansible.builtin.ping is a module name.
Reboot Module:
We can reboot a remote host through reboot module.
Main parameter of this reboot module as below:
reboot_timeout - 600
msg - text of reboot notification
reboot_command - define a reboot command depends up on OS
pre_reboot_delay - 0
Post_reboot_delay - 0
test_command - 'whoami'
boot_time_command - "cat /proc/sys/kernel/boot_id"

Copy Module:
Copy a file from one location to other location.
Main Parameters:
dest - Remote file path
src - local file path
fail_on_missing - yes / no
validate_checksum - yes /no
flat - yes/no
Service Module:
We can enable and disable the system services through this module.
ansible.builtin.service_facts
Main parameters:
name : Service name
state :  started, stopped, restarted, reloaded
enabled: yes/no
arguments/args : extra args
Package installation module:
Main parameters:
name - Name of the package
state - present/installed/absent/removed/latest
Create a file:
Main parameter:
path - file path
state - absent/directory/hard/link/touch
Module for a file permission change:
Main parameters:
Path - file path
owner - user
group - group
mode - rwx mode
state - file state [absent/directory/hard/link/touch]
setype/seuser/selevel - SElinux
Module for Download a file through Internet
Main parameters:
url - download URL
dest - destionation path
force - no/yes
checksum - checksum:URL
force_basic_auth/url_username/url_password/use_gssapi - HTTP basic auth/GSSAPI kerberos
headers - custom HTTP headers
http_agent - ansible-http-get
owner/group/mode - permission
setype/seuser/selevel - SElinux

Example:
---
 - name: Download an ansible package
   hosts: all
   become: false
   gather_facts: false
   vars: 
     myurl: "https://releases.ansible.com/ansible/ansible-2.9.25.tar.gz"
mycrc: "sha256:https://releases.ansible.com/ansible/ansible-2.9.25.tar.gz"
mydest: "/home/test/ansible-2.9.25.tar.gz"
   tasks:
     - name: downloading an ansible file
   ansible.builtin.get_url:
     url: "{{ myurl }}" 
desk: "{{ mydest }}"
checksum: "{{ mycrc }}"
mode: '0644'
owner: devops
group: wheel
Module for backing up the file
Main Parameters:
src - source path
dest - destionation path
archive - mirrors the rsync archive flag, enables recursive, links, perms, times, owner, group, flags 
rsync_opts - no/yes

Changed the line inside of file:
---
- name: search demo
  hosts: all
  vars:
    myfile: "/etc/ssh/sshd_config"
    myline: 'PasswordAuthentication no'
  become: true
  tasks:
    - name: string found
      ansible.builtin.lineinfile:
        name: "{{ myfile }]"
        line: "{{ myline }}"
        state: present
      check_mode: true
      register: conf
      failed_when:(conf is changed) or (conf is failed)

Wednesday, April 23, 2025

Terraform [HCL] Language - Write a terraform code

April 23, 2025 0

 

Hashi Corp Language:


Expressions:
  * Expression work with values in the configuration
  * They can be simple values as text or number
  * We can be use as complex such as data, loops and conditions
   Example:
 list(tuple) - ["us-east1", "us-east-2"]
 map - { name = "user1", department = "devops"}
 bool - true or false
 
versoin = "-> 4.16"
-> will consider minior. It will allow a minor version upto .99 but it will not change a major number in our case is "4".

"*" operation:
It will allow the number in the loop and avoid overloading a variable into memory.
Example:
output "ebs_block_device" {
  description = "block device volume IDs"
  value = aws_instance.splat_lab_labs.ebs_block_device[*}.volume_id
}
Functions:
  * Function is one or more insructions that perfrom a specific task.
  * Terraform functions are used to add functionality or transform and combine values.
  Example:
 resource "aws_iam_user" "web_user" {
   name ="user-${count.index}"
   count = 5
   tags = {
     time_created = timestamp()
department = "OPS"
   }
}
Example2:
resource "aws_iam_user" "functional_user" {
  name = "functional-user"
  tags = {
    department = "OPS"
time_created = timestamp()
time2= formatdate("MM DD YYYY hh:mm ZZZ", timestamp()}
  }
}

Meta Arguments:
count - It allow to set multiple resources within a block.
Example:
resource "aws_instance" "count_test" {
  count = 2
  ami = "ami-0c7c4e3c6b4941f0f"
  instance_type = "t2.micro"
  tags = {
    Name ="Count-Test-${count.index}"
  }
}
for-each meta arugment:
A for loop is using for iterating/executing over the sequence within the block.
Example:
Creating four users while creating an AWS instance.

resource "aws_iam_user" "Accounts" {
  for_each =toset{("Shiva", "Dev", "John", "Abdul")}
  name = each.key
  }
}
Local Values:
  * Local value assigns a name to an expression that can be reused easily.
  * Use case such as various list [ports, username] & reference to other values.
Example:
resource "aws_iam_user" "accounts" {
  for_each=local.accounts
  name = each.key
}
we will define a local function within the block.
locals {
  accounts = toset {("James", "Don")}
}

Dynamic block:
The codes will be reusable within resource block. It will speed up the code execution time.

Version Constraints:
  * Version constraints are configurable strings that manage the version of software to be used with Terraform includes providers and TF version as well.
  * TF version is followed by semantic versioning (Major:Minor:Patch)

= constraint - It will allow the exact version only
!= constraint - Excludes exact version number
< > - Grater than, less than a version number
>= <= - Grater than or equal to or less than or equal to that version
~> - ONlythe rightmost number increments [minor or patch number]

Stored the state file in the remote object through TF code.
terraform {
  required_providers {
    aws = {
  source = "hasicorp/aws"
  version = "5.01"
}
  }
  required_version = " <= 1.4.6"
}

module "s3_bucket" {
  source= "terraform-aws-modules/s3-bucket/aws"
  version "3.14.0"
  bucket =""
  acl = "private"
  force_destroy = true
  
  control_object_ownership = true
  object_ownership = "ObjectWriter"
  
  versioning = {
    enabled =true
  }
|

TF state file saves in bucket and set as provide inside of backet. 

Life cycle management:
create_before_destroy : It will create instead of destroying at first
prevent_destroy : It will prevent from destroying of instance
ignore_changes : It will implement of any changes.
replace_triggered_by : It will overwrite the changes

Saturday, April 12, 2025

Use case study of CloudFormation and Terraform

April 12, 2025 0

 

Scope: CloudFormation is very powerful because it is developed and supported directly by AWS, but Terraform has a great community that always works at a fast pace to ensure new resources, and features are implemented for providers quickly.
Type: CloudFormation is a managed service by AWS, but Terraform has a CLI tool that can run from your workstation, a server, or a CI/CD system (such as Jenkins, GitHub Actions, etc.) or Terraform Cloud (a SaaS automation solution from HashiCorp).
License and support: CloudFormation is a native AWS service, and AWS Support plans cover it as well. Terraform is an enterprise product and an open source project. HashiCorp offers 24/7 support, but at the same time, the huge Terraform community and provider developers are always helpful.
Syntax/language: CloudFormation supports both JSON and YAML formats. Terraform uses HashiCorp Configuration Language (HCL), which is human-readable as well as machine-friendly.
Architecture: CloudFormation is an AWS-managed service to which you send/upload your templates for provisioning; on the other hand, Terraform is a decentralized system with which you can provision infrastructure from any workstation or server.
Modularization: In CloudFormation, nested stacks and cross-stack references can be used to achieve modularization, while Terraform is capable of creating reusable and reproducible modules.
User experience/ease of use: In contrast to CloudFormation, which is limited to AWS services, Terraform spans multiple cloud service providers such as AWS, Azure, and Google Cloud Platform, among others. This flexibility allows Terraform to provide a unified approach to managing cloud infrastructure across multiple providers, making it a popular choice for organizations that use more than one cloud provider.
Life cycle and state management: CloudFormation stores the state and manages it with the use of stacks. Terraform stores the state on disk in JSON format and allows you to use a remote state system, such as an AWS S3 bucket, that gives you the capability of tracking versions.
Import from existing infrastructure: It is possible to import resources into CloudFormation, but only a few resources are supported. It is possible to import all resources into Terraform state, but it does not generate configuration in the process; you need to handle that. But there are third-party tools that can generate configuration, too.
Verification steps: CloudFormation uses change sets to verify the required changes. Terraform has a powerful plan for identifying changes and allows you to verify your changes to existing infrastructure before applying them.
Rolling updates and rollbacks: CloudFormation automatically rolls back to the last working state. Terraform has no feature for rolling updates or rollbacks, but you can build a rollback system using a CI/CD system.
Multi-cloud management: CloudFormation is AWS-only, but Terraform supports multiple cloud providers and many more services.
Compliance integration: CloudFormation is built by AWS, so compliance is already assured, but for Terraform, you need to implement third-party tools yourself to achieve compliance.
Deployment type: CloudFormation has a built-in CI/CD system that takes care of everything concerning deployment and rollbacks. Terraform can be deployed from any system, but you need to build your CI/CD workflow or adopt a service that can fill the gaps.
Drift detection: Both tools have drift detection by default.
Cost: Using AWS CloudFormation does not incur any additional charges beyond the cost of the AWS resources that are created, such as Amazon EC2 instances or Elastic Load Balancing load balancers. In contrast, Terraform is an open source project that can be used free of charge. However, to obtain enterprise-level features such as CI/CD automation and state management, you may need to consider using additional services and systems provided by HashiCorp or third-party service providers. These additional services may come with their own costs.

Terraform - Part 2

April 12, 2025 0

 

Terraform Workflow:
Terraform workflows consist of five fundamental steps:


Write - Create  a module of your code
Init - Initialize your code with download of required plugins of provider.
Plan - Review and predict the changes and determine whether to accept this changes.
Apply - Implement the changes in the real environment.
Destroy - Destroying the infra structure which we created.




We can validated the file format through terraform fmt command.

[root@thiru project]# terraform fmt main.tf
╷
│ Error: Invalid multi-line string
│
│   on main.tf line 15:
│   15: resource "aws_instance" "Web_server {
│   16:   ami =
│
│ Quoted strings may not be split over multiple lines. To produce a multi-line string, either use the \n escape to represent a newline character or use the
│ "heredoc" multi-line template syntax.
╵

╷[root@thiru project]# terraform fmt main.tf
[root@thiru project]#














Friday, April 4, 2025

Ansible - Ansible Tower

April 04, 2025 0

 

Ansible Tower:
Ansible Tower is a web based platform that makes working with Ansible easier in large-scale environments, Ansible tower has renamed as Ansible automation platform in the latest version.
Ansible Automation platform has classified as below:
  • Event Driven Ansible controller - It triggers playbooks on specific events or react on specific events.
  • Ansible Automation Hub - It integrated platform to manage Ansible Content Collections.
  • Ansible Light Speed AI [Required separate subscription]

* Installation is controlled by inventory file.  Inventory files define the hosts and containers created and variables on it.
Managing machines with Tower
Managed machines with Tower is similar things from managing machines with Ansible from the command line.
Identify the managing machine from Tower
* setup the /etc/hosts to resolve the DNS of managed machines.
We need to ensure that below setups are in places in the managed machines.
* Ensure sshd is running and accept the incoming connection from the firewall
* Need a user account with Sudo privileges
* Need to enable the password less connection between Tower and managed servers.
Ansible Tower components:
* Organization - It is a collection of managed devices
* Users - Administrative users that can be granted access to specific tasks
* Inventories - Managed servers. It can be created statically or dynamically.
* Credentials - Credentials that are used to log into managed machines (like AWS or cloud credentials)
* Project - It is a collection of playbooks obtained from a certain location (ex. GIT)
* Template - The job definition with all of its parameters. It must be launched or scheduled.
Setup the project in AWX:
We need to follow up below steps to create our first project under AWX.
1) Create a organization
2) Create a inventory 
3) Configure a credentials
4) Setup the project
5) Define a Job Template
6) Run the Job 
Created a Inventory:
Login into AWX console and navigate into Inventories under Resources.


Create a Host file under Inventory:


Create a credentials:
Navigate into Credentials under resources from AWX GUI.

Click on create Credential and define a username and password which is used to maintain a resources and Templates.
Create a Project:
Navigate into Project under resources.
Define a project name and select the AWX environment and GIT repo.

Create a work flow Template for more than 1 job.


.
Submit a job and monitor it. We can able to schedule a job for particular time as well.





Thursday, August 13, 2015

Install the Perl module

August 13, 2015 0
Unable to install a perl module and through below error:

Looking for CPAN mirrors near you (please be patient)
Can't locate Time/HiRes.pm in @INC (@INC contains: /usr/local/lib64/perl5 /usr/local/share/perl5 /usr/lib64/perl5/vendor_perl /usr/share/perl5/vendor_perl /usr/lib64/perl5 /usr/share/perl5 /OBD/OBRT) at /usr/share/perl5/Net/Ping.pm line 313.

Needs to install perl-Time-HiRes.x86_64 4:1.9725-3.el7 package to fix this issue

[root@localhost OBRT]# yum install perl-Time-HiRes
Loaded plugins: product-id, subscription-manager
This system is not registered to Red Hat Subscription Management. You can use subscription-manager to register.
Resolving Dependencies
--> Running transaction check
---> Package perl-Time-HiRes.x86_64 4:1.9725-3.el7 will be installed
--> Finished Dependency Resolution

Dependencies Resolved

==============================================================================================================================
 Package                          Arch                    Version                            Repository                  Size
==============================================================================================================================
Installing:
 perl-Time-HiRes                  x86_64                  4:1.9725-3.el7                     rhel7_dvd                   45 k

Transaction Summary
==============================================================================================================================
Install  1 Package

Total download size: 45 k
Installed size: 92 k
Is this ok [y/d/N]: yes
Downloading packages:
Running transaction check
Running transaction test
Transaction test succeeded
Running transaction
  Installing : 4:perl-Time-HiRes-1.9725-3.el7.x86_64                                                                      1/1
  Verifying  : 4:perl-Time-HiRes-1.9725-3.el7.x86_64                                                                      1/1

Installed:
  perl-Time-HiRes.x86_64 4:1.9725-3.el7

Complete!

2) Install the DBI module 

[root@localhost OBRT]# cpan install DBI



Monday, August 10, 2015

Restart the puppet server

August 10, 2015 0


[root@localhost bin]# ./puppetserver  foreground

^Z
[1]+  Stopped                 ./puppetserver foreground
[root@localhost bin]# bg
[1]+ ./puppetserver foreground &
[root@localhost bin]# service pe-puppet start
Redirecting to /bin/systemctl start  pe-puppet.service
[root@localhost bin]# 2015-08-11 01:28:30,699 INFO  [o.e.j.u.log] Logging initialized @25047ms
2015-08-11 01:28:33,683 INFO  [p.t.s.w.jetty9-service] Initializing web server(s).
2015-08-11 01:28:33,903 INFO  [p.s.j.jruby-puppet-service] Initializing the JRuby service
2015-08-11 01:28:33,905 WARN  [p.s.j.jruby-puppet-core] No configuration value found for jruby-puppet max-active-instances; using default value of 1.  Please consider setting this value explicitly in the jruby-puppet section of your Puppet Server config files.

[root@localhost bin]# /bin/systemctl start  pe-puppet.service
[root@localhost bin]#
[root@localhost bin]# ps -ef | grep 2015-08-11 01:28:56,757 INFO  [puppet-server] Puppet Puppet settings initialized; run mode: master
2015-08-11 01:28:59,855 INFO  [p.s.j.jruby-puppet-agents] Finished creating JRubyPuppet instance 1 of 1
2015-08-11 01:28:59,992 INFO  [p.s.c.puppet-server-config-core] Not overriding webserver settings with values from core Puppet
2015-08-11 01:28:59,998 INFO  [p.p.certificate-authority] CA already initialized for SSL
2015-08-11 01:28:59,999 INFO  [p.s.c.certificate-authority-service] CA Service adding a ring handler
2015-08-11 01:29:00,017 WARN  [o.e.j.s.h.ContextHandler] Empty contextPath
2015-08-11 01:29:00,084 INFO  [p.p.certificate-authority] Master already initialized for SSL
2015-08-11 01:29:00,090 INFO  [p.e.s.m.master-service] Master Service adding a ring handler
2015-08-11 01:29:00,090 WARN  [o.e.j.s.h.ContextHandler] Empty contextPath
2015-08-11 01:29:00,096 INFO  [p.s.p.puppet-admin-service] Starting Puppet Admin web app
2015-08-11 01:29:00,106 INFO  [p.t.s.w.jetty9-service] Starting web server(s).
2015-08-11 01:29:00,573 INFO  [p.t.s.w.jetty9-core] Starting web server.
2015-08-11 01:29:00,579 INFO  [o.e.j.s.Server] jetty-9.2.z-SNAPSHOT
2015-08-11 01:29:01,404 INFO  [o.e.j.s.h.ContextHandler] Started o.e.j.s.ServletContextHandler@754424ce{/packages,file:/opt/puppet/packages/public/,AVAILABLE}
2015-08-11 01:29:01,406 INFO  [o.e.j.s.h.ContextHandler] Started o.e.j.s.h.ContextHandler@4af56eab{/,null,AVAILABLE}
2015-08-11 01:29:01,408 INFO  [o.e.j.s.h.ContextHandler] Started o.e.j.s.h.ContextHandler@3734c2ff{/,null,AVAILABLE}
2015-08-11 01:29:01,410 INFO  [o.e.j.s.h.ContextHandler] Started o.e.j.s.h.ContextHandler@6cbc6861{/puppet-admin-api,null,AVAILABLE}

Usage: grep [OPTION]... PATTERN [FILE]...
Try 'grep --help' for more information.
[root@localhost bin]# 2015-08-11 01:29:02,016 INFO  [o.e.j.s.ServerConnector] Started ServerConnector@5bf1fe70{SSL-HTTP/1.1}{0.0.0.0:8140}
2015-08-11 01:29:02,017 INFO  [o.e.j.s.Server] Started @56392ms
2015-08-11 01:29:02,110 INFO  [p.e.s.m.master-service] Puppet Server has successfully started and is now ready to handle requests

[root@localhost bin]#








how to restart the puppet?

August 10, 2015 0



[root@localhost opt]# service pe-puppet restart
Redirecting to /bin/systemctl restart  pe-puppet.service

[root@localhost opt]#
[root@localhost opt]# /bin/systemctl restart  pe-puppet.service
[root@localhost opt]#

Friday, August 7, 2015

how to open 3000 port for puppet on RHEL 7?

August 07, 2015 0
1) add rule for 3000 ports through firewall-cmd command

[root@localhost puppet-enterprise-3.8.0-el-7-x86_64]# firewall-cmd --zone=public --add-port=3000/tcp --permanent
success
[root@localhost puppet-enterprise-3.8.0-el-7-x86_64]#

2) Reload the firewall rules

[root@localhost puppet-enterprise-3.8.0-el-7-x86_64]# firewall-cmd --reload
success
[root@localhost puppet-enterprise-3.8.0-el-7-x86_64]#

3) verify the port status

[root@localhost puppet-enterprise-3.8.0-el-7-x86_64]# iptables-save | grep -i 3000
-A IN_public_allow -p tcp -m tcp --dport 3000 -m conntrack --ctstate NEW -j ACCEPT
[root@localhost puppet-enterprise-3.8.0-el-7-x86_64]#


Thursday, August 6, 2015

Puppet Installation

August 06, 2015 0


Step 1) Download the puppet installer
Step2) unzip and untar it
Step3) Run the puppet installer
root@test puppet-enterprise-3.8.0-el-7-x86_64]# ./puppet-enterprise-installer
==============================================================================================================================

Puppet Enterprise v3.8.0 installer

Puppet Enterprise documentation can be found at http://docs.puppetlabs.com/pe/3.8/

------------------------------------------------------------------------------------------------------------------------------

STEP 1: GUIDED INSTALLATION

Before you begin, choose an installation method. We've provided a few paths to choose from.

- Perform a guided installation using the web-based interface. Think of this as an installation interview in which we ask
you exactly how you want to install PE. In order to use the web-based installer, you must be able to access this machine
on port 3000 and provide the SSH credentials of a user with root access. This method will login to servers on your behalf,
install Puppet Enterprise and get you up and running fairly quickly.

- Use the web-based interface to create an answer file so that you can log in to the servers yourself and perform the
installation locally. If you choose not to use the web-based interface, you can write your own answer file, or use the
answer file(s) provided in the PE installation tarball. Refer to Answer File Installation
(http://docs.puppetlabs.com/pe/3.8/install_automated.html), which provides an overview on installing PE with an answer
file.

?? Install packages and perform a guided install? [Y/n] y

Installing setup packages.

Please go to https://test:3000 in your browser to continue installation. Be sure to use https:// and that port 3000 is
Reachable through the firewall.
Step4) Enable the firewall to allow 3000 port
Step 5) create the Puppet master