Grant all members of NOC access to ctf.realraum.at
[noc.git] / ansible / roles / preseed / templates / preseed_ubuntu-xenial.cfg.j2
1 #########################################################################
2 #  realraum preseed file for Ubuntu xenial based VMs
3 #########################################################################
4
5 d-i debian-installer/language string en
6 d-i debian-installer/country string AT
7 d-i debian-installer/locale string en_US.UTF-8
8 d-i localechooser/preferred-locale string en_US.UTF-8
9 d-i localechooser/supported-locales multiselect de_DE.UTF-8, de_AT.UTF-8
10 d-i console-setup/ask_detect boolean false
11 d-i keyboard-configuration/xkb-keymap select us
12 d-i keyboard-configuration/layoutcode string us
13
14 d-i hw-detect/load_firmware boolean false
15
16 d-i netcfg/choose_interface select {{ install_interface | default(hostvars[hostname].network_cooked.primary.interface) }}
17 {% if 'install_dhcp' in hostvars[hostname] and hostvars[hostname].install_dhcp %}
18 d-i netcfg/disable_dhcp boolean false
19 d-i netcfg/disable_autoconfig boolean false
20 {% else %}
21 d-i netcfg/disable_dhcp boolean true
22 d-i netcfg/disable_autoconfig boolean true
23 d-i netcfg/get_ipaddress string {{ hostvars[hostname].network_cooked.primary.ip }}
24 d-i netcfg/get_netmask string {{ hostvars[hostname].network_cooked.primary.mask }}
25 d-i netcfg/get_gateway string {{ hostvars[hostname].network_cooked.primary.gateway }}
26 d-i netcfg/get_nameservers string {{ hostvars[hostname].network_cooked.nameservers | join(' ') }}
27 d-i netcfg/confirm_static boolean true
28 {% endif %}
29
30 d-i netcfg/hostname string {{ hostname }}
31 d-i netcfg/get_hostname string {{ hostname }}
32 d-i netcfg/domain string {{ hostvars[hostname].network_cooked.domain }}
33 d-i netcfg/get_domain string {{ hostvars[hostname].network_cooked.domain }}
34 d-i netcfg/wireless_wep string
35
36
37 d-i mirror/country string manual
38 d-i mirror/http/hostname string debian.ffgraz.net
39 d-i mirror/http/directory string /ubuntu
40 d-i mirror/http/proxy string
41
42
43 d-i passwd/make-user boolean false
44 d-i passwd/root-login boolean true
45 d-i passwd/root-password password this-very-very-secure-password-will-be-removed-by-latecommand
46 d-i passwd/root-password-again password this-very-very-secure-password-will-be-removed-by-latecommand
47
48
49 d-i clock-setup/utc boolean true
50 d-i time/zone string Europe/Vienna
51 d-i clock-setup/ntp boolean false
52
53
54 d-i partman/early_command string \
55     debconf-set partman-auto/disk "$(readlink -f {{ hostvars[hostname].install_cooked.disks.primary }})"; \
56     debconf-set grub-installer/bootdev "$(readlink -f {{ hostvars[hostname].install_cooked.disks.primary }})"; \
57     umount -l /media || true
58
59 d-i grub-installer/choose_bootdev string manual
60 d-i grub-installer/bootdev seen true
61
62 d-i partman-auto/method string lvm
63 d-i partman-auto/purge_lvm_from_device boolean true
64 d-i partman-auto-lvm/new_vg_name string {{ hostname }}
65 d-i partman-auto-lvm/guided_size string max
66
67 d-i partman-lvm/device_remove_lvm boolean true
68 d-i partman-md/device_remove_md boolean true
69
70 d-i partman-lvm/confirm boolean true
71 d-i partman-lvm/confirm_nooverwrite boolean true
72
73 d-i partman-auto/expert_recipe string                                    \
74       boot-root ::                                                       \
75               1000 10000 -1 ext4                                         \
76                       $defaultignore{ } $primary{ } $bootable{ }         \
77                       method{ lvm } vg_name{ {{ hostname }} }            \
78               .                                                          \
79               2048 10000 2560 ext4                                       \
80                       $lvmok{ } in_vg{ {{ hostname }} }                  \
81                       method{ format } format{ }                         \
82                       use_filesystem{ } filesystem{ ext4 }               \
83                       mountpoint{ / }                                    \
84               .                                                          \
85               1024 11000 1280 ext4                                       \
86                       $lvmok{ } in_vg{ {{ hostname }} }                  \
87                       method{ format } format{ }                         \
88                       use_filesystem{ } filesystem{ ext4 }               \
89                       mountpoint{ /var }                                 \
90               .                                                          \
91               768 10000 768 ext4                                         \
92                       $lvmok{ } in_vg{ {{ hostname }} }                  \
93                       method{ format } format{ }                         \
94                       use_filesystem{ } filesystem{ ext4 }               \
95                       mountpoint{ /var/log }                             \
96                       options/nodev{ nodev } options/noatime{ noatime }  \
97                       options/noexec{ noexec }                           \
98               .                                                          \
99               16 20000 -1 ext4                                           \
100                       $lvmok{ } in_vg{ {{ hostname }} } lv_name{ dummy } \
101               .
102
103 d-i partman-auto-lvm/no_boot boolean true
104 d-i partman-basicfilesystems/no_swap true
105 d-i partman-partitioning/confirm_write_new_label boolean true
106 d-i partman/choose_partition select finish
107 d-i partman/confirm boolean true
108 d-i partman/confirm_nooverwrite boolean true
109
110
111 d-i base-installer/install-recommends boolean false
112 d-i apt-setup/security_host string debian.ffgraz.net
113
114 tasksel tasksel/first multiselect
115 d-i pkgsel/include string openssh-server python python-apt
116 d-i pkgsel/upgrade select safe-upgrade
117 popularity-contest popularity-contest/participate boolean false
118 d-i pkgsel/update-policy select none
119 d-i base-installer/kernel/override-image string linux-generic-hwe-16.04
120
121 d-i grub-installer/only_debian boolean true
122 d-i grub-installer/with_other_os boolean false
123
124 d-i finish-install/reboot_in_progress note
125
126
127 d-i preseed/late_command string \
128     lvremove -f {{ hostname }}/dummy; \
129     in-target bash -c "apt-get update -q && apt-get full-upgrade -y -q"; \
130     in-target bash -c "passwd -d root && passwd -l root"; \
131     in-target bash -c "sed -e 's/^allow-hotplug/auto/' -i /etc/network/interfaces"; \
132 {% if preseed_force_net_ifnames_policy is defined %}
133     mkdir -p /target/etc/systemd/network; \
134     in-target bash -c "echo '[Link]' > /etc/systemd/network/90-namepolicy.link"; \
135     in-target bash -c "echo 'NamePolicy={{ preseed_force_net_ifnames_policy }}' >> /etc/systemd/network/90-namepolicy.link"; \
136     in-target bash -c "update-initramfs -u"; \
137 {% endif %}
138 {% if hostvars[hostname].ansible_port is defined %}
139     in-target bash -c "sed -e 's/^\(\s*#*\s*Port.*\)/Port {{ hostvars[hostname].ansible_port }}/' -i /etc/ssh/sshd_config"; \
140 {% endif %}
141     mkdir -p -m 0700 /target/root/.ssh; \
142     cp /authorized_keys /target/root/.ssh/