Tuesday, March 15, 2016

A sample knife.rb file with exception for ssl mode

current_dir = File.dirname(__FILE__)
log_level                :info
log_location             STDOUT
node_name                'rajagopalan'
client_key               '/root/chef-repo/.chef/rajagopalan.pem'
validation_client_name   'hexaware'
validation_key           '/root/chef-repo/.chef/hexaware-validator.pem'
chef_server_url          'https://api.chef.io/organizations/ORG_NAME'
cache_type               'BasicFile'
cache_options( :path => "#{ENV['HOME']}/.chef/checksums" )
cookbook_path            ['#{current_dir}/../cookbooks']


Vi  ~/.gemrc

Add this line to bypass ssl check
:ssl_verify_mode: 0

Add this line to knife.rb to exclude ssl check while executing knife ec2 server create

Excon.defaults[:ssl_verify_peer] = false

Sunday, February 14, 2016

Fix - ERROR: Server returned error 500 for https://127.0.0.1/users/ - Chef

If the following error is faced in chef-server, version 12, then do the following to fix the issue.


ERROR: Server returned error 500 for https://127.0.0.1/users

open the file /opt/opscode/embedded/cookbooks/private-chef/templates/default/oc_erchef.config.erb in vi editor and go to line 220.

Replace the following line :

{s3_url, "<%= node['private_chef']['nginx']['x_forwarded_proto'] %>://<%= @helper.vip_for_uri('bookshelf') %>"},

with

{s3_url, "https://private-chef.opscode.piab:4000"},

and then run chef-server-ctl reconfigure.

Reason and Solution:

nginx will listen on port 4000 for HTTPS connections and not the default port of 443.

During cookbook uploads, the opscode-erchef service talks to bookshelf via the s3_url in its configuration file (/var/opt/opscode/opscode-erchef/etc/app.config). This configuration file is rendered via a template(opscode-omnibus/files/private-chef-cookbooks/private-chef/templates/default/oc_erchef.config.erb), a portion of which looks like:

{s3_url, "<%= node['private_chef']['nginx']['x_forwarded_proto'] %>://<%= @helper.vip_for_uri('bookshelf') %>"},
Thus, the rendered configuration file will have an s3_url like:

{s3_url, "https://private-chef.opscode.piab"},
Given this configuration, erchef will attempt to contact erchef on port 443, the default HTTPS port. Unfortunately, nothing is listening on 443, the request to bookshelf fails and erchef returns a 500 to the user.

An astute user may attempt to set bookshelf['vip'] in private-chef.rb to something like:

bookshelf['vip'] = 'private-chef.opscode.piab:4000'

Reference : https://github.com/chef/chef-server/issues/50

Wednesday, January 20, 2016

Failed to connect to 127.0.0.1:27017, reason: errno:111 Connection refused

run mongod process with the dbpath parameter

mongod --dbpath /home/mongo/data/db

create the path if it does not exits.

Sunday, January 17, 2016

Jenkins scp plugin - can't connect to server issue, Jenkins scp repositories - can't connect to server, SEVERE: Algorithm negotiation fail

The issue can be resolve, by opening the /etc/ssh/sshd_config file and add the following line:

KexAlgorithms diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1

save and then restart ssh server: service ssh restart.

The problem is fixed.

Wednesday, December 23, 2015

Using proxy for apt-get

When your server is behind a proxy, you can do the following steps to run apt-get through a proxy:

open the file /etc/apt/apt.conf, if not create it and add the lines
Acquire::http::proxy "http://xxx\username:password@proxy.web.local:/3128";

save and exit. Now everything will go fine.

Thursday, September 17, 2015

PostgreSQL PITR


PostgreSQL allows you to restore the database to a specific point in time by using
one of the three options:
recovery_target_name,recovery_target_time,recovery_target_xid,pause_at_recovery_target
Go to master node and do the following steps
Edit postgresql.conf and add\edit  the following lines as given below
listen_addresses = '*'
port = 5432
max_connections = 100
wal_level = hot_standby
archive_mode = on
archive_command = 'cp %p /usr/local/pgsql/archive/%f'
logging_collector = on
log_directory = 'pg_log'
log_filename = 'postgresql-%Y-%m-%d_%H%M%S.log'

For demo purpose we install two instance in the same host on two different ports.
Install the second instance on the port 5433

Open the pg_hba.conf in master and add these lines at the bottom

host    all     all     0.0.0.0/0       trust
host    replication     all     0.0.0.0/0       trust
host    replication     postgres        0.0.0.0/0       trust

Start the postgresql on port 5432 and create a test database and connect to it
create database test_pitr;
\c test_pitr
 create table test(col1 int, col2 char(10));
insert into test select generate_series(1,100),'test';

Go to data directory of secondary node and clear it,
 cd /usr/local/pgsql2/data
 rm -rf *

Connect  to secondary node at 5433 and execute pg_basebackup, which will take care of pg_start_backup('label'); and pg_stop_backup();
pg_basebackup -D /usr/local/pgsql2/data/ --write-recovery-conf --xlog-method=fetch --verbose -h localhost

This command will copy data folder from master with recovery.conf

You will get output something like  this
transaction log start point: 4/8D000028 on timeline 1
transaction log end point: 4/8E000050
pg_basebackup: base backup completee

Connect to master node on 5432 and execute the command to create restore point. The point till which the wal log will be replayed
 select pg_create_restore_point('patch_2015_09_17_2');
Now create some more records
insert into test select generate_series(101,1000),'test';

After this the data directory from master will be copied over to secondary. Open the postgresql.conf and edit as given below
hot_standby = on
And leave the rest as same
Open recovery.conf and edit it as below
standby_mode = 'on'
primary_conninfo = 'user=postgres host=localhost port=5432'
pause_at_recovery_target = true
recovery_target_name = patch_2015_09_17_02

Start the server on 5433
If we check the log file, these are the important sections:
entering standby mode..
recovery stopping at restore point "patch_of_2014_07_02", time
2014-07-02 12:08:57.507946+05:30
recovery has paused
Execute pg_xlog_replay_resume() to continue

Connect to psql on the secondary node and check the record
\c test_pitr
 select * from test order by col1 desc limit 2;

Try to create a table and you may find this error,
ERROR: cannot execute CREATE TABLE in a read-only transaction
The database is still in read-only mode.
Execute the following command
 SELECT pg_xlog_replay_resume();

It's done

Tuesday, June 16, 2015

Modules got blocked in powershell v1.0

The best way to unblock in v1.0 is to remove the module from powershell location
eg: C:\windows\system32\windowspowershell\v1.0\modules\pswindowsupdate

and extract the downloaded module again into the same location.