-
Smithx10
zlogin -C doesn't work with KVM?
-
bahamat
Eh...it depends?
-
Smithx10
udnerstood
-
bahamat
The guest needs to have the console explicitly configured
-
Smithx10
Someone left a team and no one has access to a bunch of their VMs, is there a way to do a startup script assuming they have the smartos tools / cloud-init running in the instnace?
-
bahamat
I'm pretty sure (though, now on reflection not 100%) that we do have zlogin -C wired up to the serial port so that if the guest also sets it up it would work.
-
bahamat
Well, there's a couple of things.
-
bahamat
There's some stuff for overwriting ssh keys, but I'm not sure that works with the cloud-init stuff anymore.
-
Smithx10
What was the way to overwrite ssh keys without cloud-init
-
bahamat
You could write a special metadata key that would signal our start up script to replace the authorized_keys file
-
bahamat
I'm trying to find the code for it
-
Smithx10
Thanks
-
bahamat
-
Smithx10
so set overwrite_root_akeys to "OVERWRITE" yea?
-
bahamat
Yeah
-
bahamat
But I don't think we ship that on modern images.
-
bahamat
I can't find it anywhere on any of my bhyve systems
-
bahamat
We actually probably should, because it's a nice failsafe to have.
-
bahamat
The other option is to get on the vnc console and interrupt grub, which is always a pain in the ass.
-
Smithx10
yea
-
Smithx10
the idea of smartlogin was cool
-
Smithx10
but with VM i can see the pain
-
bahamat
Smithx10: With newer OpenSSH you can have AuthorizedKeysCommand, and have that mget the keys
-
bahamat
But you have to set that up yourself.
-
bahamat
I've considered several ways of putting that into images, but there's no clear way to do it "right" that won't be broken by the distro when upgrading the package.
-
bahamat
Oh, actually, even newer ones have `Include /etc/ssh/sshd_config.d` by default.
-
Smithx10
Yeah, we <3 AuthorizedKeysCommand but the issue is the BUs are kinda on their own for this
-
Smithx10
until we can be authorized to govern their instances
-
Smithx10
exactly, we use it for all our stuff in our accounts for ops
-
Smithx10
but.... its that line between them having freedom vs having to work with us
-
Smithx10
maybe I should have had images always populate from mdata on bounce
-
Smithx10
Not sure if you saw things like "Boundary" or WarpGate
-
Smithx10
-
Smithx10
-
Smithx10
seems pretty cool
-
bahamat
Yeah, I've seen them, but like how much should we customize images for customers? I'm in favor of very little
-
Smithx10
same