Ubuntu autoinstall 自动化部署
autoinstall 是 Ubuntu Server 安装程序 Subiquity 提供的自动化安装方案,通过 YAML 配置文件实现无人值守的服务器部署。
工作原理
autoinstall 配置可以通过以下方式提供:
- cloud-init user-data - 通过云平台的 user-data 传递
- 本地文件 - 放在安装介质或可访问的文件系统中
- HTTP 服务器 - 通过网络加载配置文件
安装程序在启动时搜索 autoinstall 配置,找到后自动执行安装,无需人工干预。
基本配置结构
#cloud-config
autoinstall:
version: 1
# 语言和键盘
locale: en_US.UTF-8
keyboard:
layout: us
# 网络配置
network:
version: 2
ethernets:
eth0:
dhcp4: true
# 软件源
apt:
primary:
- arches: [default]
uri: https://mirrors.tuna.tsinghua.edu.cn/ubuntu
# 磁盘配置
storage:
layout:
name: lvm
# 用户配置
identity:
hostname: ubuntu-server
username: ubuntu
password: "$6$rounds=4096$xyz$hashedpassword"
# SSH 配置
ssh:
install-server: true
allow-pw: false
authorized-keys:
- ssh-ed25519 AAAA... admin@workstation
# 安装后执行
late-commands:
- curtin in-target -- apt update
- curtin in-target -- apt upgrade -y完整配置示例
标准服务器安装
#cloud-config
autoinstall:
version: 1
# 交互设置(哪些步骤需要手动确认)
interactive-sections: [] # 空表示全自动
locale: en_US.UTF-8
keyboard:
layout: us
variant: ""
# 使用更新的安装程序
refresh-installer:
update: true
# 网络
network:
version: 2
ethernets:
ens33:
dhcp4: false
addresses:
- 192.168.1.100/24
routes:
- to: default
via: 192.168.1.1
nameservers:
addresses:
- 223.5.5.5
- 8.8.8.8
# 代理(留空为不使用)
proxy: ""
# APT 镜像源
apt:
primary:
- arches: [amd64]
uri: https://mirrors.tuna.tsinghua.edu.cn/ubuntu
geoip: false
# 存储配置 - 使用 LVM
storage:
layout:
name: lvm
sizing-policy: scaled
# 或指定根分区大小
# sizing-policy: all
# 系统身份
identity:
hostname: prod-web-01
username: deploy
# 使用 mkpasswd --method=sha-512 生成
password: "$6$rounds=4096$saltsalt$hashedpasswordhere"
# SSH
ssh:
install-server: true
allow-pw: false
authorized-keys:
- ssh-ed25519 AAAA... deploy@admin
# 要安装的 snap 包
snaps:
- name: docker
channel: latest/stable
classic: false
# 要安装的 deb 包
packages:
- ubuntu-server-minimal
- vim
- htop
- curl
- wget
- git
- ufw
- fail2ban
# 自动安全更新
updates: security
# 安装后执行命令
late-commands:
# 设置时区
- curtin in-target -- timedatectl set-timezone Asia/Shanghai
# 配置防火墙
- curtin in-target -- ufw allow ssh
- curtin in-target -- ufw --force enable
# 写入自定义配置文件
- |
cat <<'SYSCTL' > /target/etc/sysctl.d/99-custom.conf
net.ipv4.ip_forward = 1
net.core.somaxconn = 65535
vm.swappiness = 10
SYSCTL
# 启用服务
- curtin in-target -- systemctl enable fail2ban
# 安装完成后自动重启
shutdown: reboot自定义分区方案
#cloud-config
autoinstall:
version: 1
locale: en_US.UTF-8
storage:
config:
# 磁盘
- id: disk0
type: disk
ptable: gpt
path: /dev/sda
wipe: superblock-recursive
grub_device: false
# EFI 分区
- id: efi-part
type: partition
device: disk0
size: 512M
flag: boot
grub_device: true
# Boot 分区
- id: boot-part
type: partition
device: disk0
size: 1G
# 剩余空间给 LVM
- id: lvm-part
type: partition
device: disk0
size: -1 # 剩余全部
# EFI 文件系统
- id: efi-fs
type: format
volume: efi-part
fstype: fat32
# Boot 文件系统
- id: boot-fs
type: format
volume: boot-part
fstype: ext4
# LVM 卷组
- id: vg0
type: lvm_volgroup
name: vg0
devices:
- lvm-part
# LVM 逻辑卷 - root
- id: lv-root
type: lvm_partition
volgroup: vg0
name: lv-root
size: 20G
# LVM 逻辑卷 - var
- id: lv-var
type: lvm_partition
volgroup: vg0
name: lv-var
size: 30G
# LVM 逻辑卷 - home
- id: lv-home
type: lvm_partition
volgroup: vg0
name: lv-home
size: -1
# 格式化逻辑卷
- id: root-fs
type: format
volume: lv-root
fstype: ext4
- id: var-fs
type: format
volume: lv-var
fstype: ext4
- id: home-fs
type: format
volume: lv-home
fstype: ext4
# 挂载点
- id: mount-efi
type: mount
device: efi-fs
path: /boot/efi
- id: mount-boot
type: mount
device: boot-fs
path: /boot
- id: mount-root
type: mount
device: root-fs
path: /
- id: mount-var
type: mount
device: var-fs
path: /var
- id: mount-home
type: mount
device: home-fs
path: /home
identity:
hostname: custom-server
username: admin
password: "$6$rounds=4096$saltsalt$hash"
ssh:
install-server: true提供 autoinstall 配置
方法 1:修改 ISO
# 挂载原始 ISO
mkdir -p /mnt/iso
sudo mount -o loop ubuntu-26.04-live-server-amd64.iso /mnt/iso
# 复制内容
mkdir -p ~/custom-iso
cp -rT /mnt/iso ~/custom-iso
sudo umount /mnt/iso
# 添加 autoinstall 配置
mkdir -p ~/custom-iso/autoinstall
cp autoinstall.yaml ~/custom-iso/autoinstall/user-data
touch ~/custom-iso/autoinstall/meta-data
# 修改 GRUB 配置,添加自动安装启动项
# 在 ~/custom-iso/boot/grub/grub.cfg 中添加:
cat >> ~/custom-iso/boot/grub/grub.cfg << 'EOF'
menuentry "Autoinstall Ubuntu Server" {
set gfxpayload=keep
linux /casper/vmlinuz autoinstall ds=nocloud\;s=/cdrom/autoinstall/ ---
initrd /casper/initrd
}
EOF
# 重新生成 ISO
sudo apt install xorriso -y
xorriso -as mkisofs \
-r -V "Ubuntu 26.04 Autoinstall" \
-o ~/ubuntu-26.04-autoinstall.iso \
-J -joliet-long \
--grub2-mbr /usr/lib/grub/i386-pc/boot_hybrid.img \
-partition_offset 16 \
-append_partition 2 0xEF ~/custom-iso/boot/grub/efi.img \
-appended_part_as_gpt \
-eltorito-boot boot/grub/bios.img \
-eltorito-catalog boot/grub/boot.cat \
--no-emul-boot -boot-load-size 4 -boot-info-table --grub2-boot-info \
-eltorito-alt-boot -e '--interval:appended_partition_2:all::' --no-emul-boot \
~/custom-iso方法 2:HTTP 服务器
# 在另一台机器上启动 HTTP 服务
mkdir -p ~/autoinstall-server
cp autoinstall.yaml ~/autoinstall-server/user-data
touch ~/autoinstall-server/meta-data
cd ~/autoinstall-server
python3 -m http.server 8080
# 安装时在 GRUB 命令行添加内核参数:
# autoinstall ds=nocloud-net;s=http://192.168.1.50:8080/方法 3:PXE 网络启动
适合大规模部署,结合 TFTP + HTTP 服务器:
# 安装 PXE 相关软件
sudo apt install tftpd-hpa -y
# 将内核和 initrd 放入 TFTP 目录
sudo cp /mnt/iso/casper/vmlinuz /srv/tftp/
sudo cp /mnt/iso/casper/initrd /srv/tftp/
# PXE 配置中添加内核参数
# kernel vmlinuz
# append initrd=initrd autoinstall ds=nocloud-net;s=http://192.168.1.50:8080/ ---生成密码哈希
# 方法 1:使用 mkpasswd
sudo apt install whois -y
mkpasswd --method=sha-512
# 方法 2:使用 openssl
openssl passwd -6
# 注意:Python 3.13 已移除 crypt 模块,请改用上面的 mkpasswd 或 openssl 方法获取已安装系统的 autoinstall 配置
安装完成后可以导出当前系统的安装配置作为模板:
# 查看安装时使用的 autoinstall 配置
sudo cat /var/log/installer/autoinstall-user-data
# 这个文件包含了完整的安装配置,可以作为模板复用验证配置
# 使用 cloud-init 验证语法
cloud-init schema --config-file autoinstall.yaml
# 使用 Python 检查 YAML 格式
python3 -c "import yaml; yaml.safe_load(open('autoinstall.yaml'))"常见问题
安装卡在确认步骤
确保 interactive-sections 设置为空列表:
autoinstall:
interactive-sections: []网络配置不生效
检查网卡名称是否正确,可在安装环境中通过 ip link 确认实际网卡名。
late-commands 执行失败
- 使用
curtin in-target --前缀在目标系统中执行命令 - 直接路径操作使用
/target/前缀 - 查看日志:
/var/log/installer/curtin-install.log
Last updated on