# Install using kickstart and %post rsync

**URL:** <https://forums.rockylinux.org/t/install-using-kickstart-and-post-rsync/13146>\
**Category:** Rocky Linux Help & Support\
**Tags:** rocky-linux-9\
**Created:** [March 8, 2024, 7:22am UTC](https://forums.rockylinux.org/t/install-using-kickstart-and-post-rsync/13146 "2024-03-08T07:22:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Faqterson](https://avatars.discourse-cdn.com/v4/letter/f/898d66/32.png) [@Faqterson](https://forums.rockylinux.org/u/Faqterson)\
**Post date:** [March 8, 2024, 7:22am UTC](https://forums.rockylinux.org/t/install-using-kickstart-and-post-rsync/13146/1 "2024-03-08T07:22:17Z")

</div>

I am trying to sync a couple files on install using kickstart script

```auto
%post
export RSYNC_PASSWORD="password"
/usr/bin/rsync -rltgo rsync://rsync@myrsyncdeamon.local/important-files/ /important-files/
%end

```

Is their any way to secure the password in the kickstart file to have it encrypted.

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [March 8, 2024, 9:47am UTC](https://forums.rockylinux.org/t/install-using-kickstart-and-post-rsync/13146/2 "2024-03-08T09:47:07Z")

</div>

I don’t know answer to that question.

* * *

I do use a slightly different approach:

1. Kickstart deploys a ssh public key for the root user
2. After install I do run Ansible playbook on my “control host” that completes the config. (Ansible gets into the target system via ssh.)

That obviously requires that there is a control host (for example, the myrsyncdeamon.local) that can run Ansible. In your case, if that rsync is all you do, you could run the rsync in the myrsyncdeamon.local to push (rather than pull) if target had your key in authorized\_keys? As downside, one has to do it separately, unlike the %post.

---

<div class="post-metadata">

**Author:** ![Faqterson](https://avatars.discourse-cdn.com/v4/letter/f/898d66/32.png) [@Faqterson](https://forums.rockylinux.org/u/Faqterson)\
**Post date:** [March 8, 2024, 10:15am UTC](https://forums.rockylinux.org/t/install-using-kickstart-and-post-rsync/13146/3 "2024-03-08T10:15:13Z")

</div>

Can you provide an example of how the kickstart will deploy an SSH public key?  
I am sure this could work as well, if host controller can access the new install or new install can access the host controller with minimal interference from a user, the better.

_I don’t want to baby sit VM’s while they install._

I do have a host controller that is running as a rsync deamon. I have been looking into Puppet but it looks to be over kill for what we are trying to accomplish.

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [March 8, 2024, 10:46am UTC](https://forums.rockylinux.org/t/install-using-kickstart-and-post-rsync/13146/4 "2024-03-08T10:46:56Z")

</div>

I seem to have at end of kickstart file:

```auto
sshkey --username=root "ssh-ed25519 AA..mw jlehtone@moon"

```

The `sshkey` should be described in kickstart documentation.

* * *

I got into Ansible because it was used by someone to set up (and maintain) HPC clusters, and it is available in the distro (package `ansible-core`). IMHO, the main benefit of Ansible and Puppet is not that initial install is automated, but that one can update/maintain config of existing systems and one has logical copy of config of each system – a backup that is trivial to “restore”.

---

<div class="post-metadata">

**Author:** ![Faqterson](https://avatars.discourse-cdn.com/v4/letter/f/898d66/32.png) [@Faqterson](https://forums.rockylinux.org/u/Faqterson)\
**Post date:** [March 11, 2024, 6:18am UTC](https://forums.rockylinux.org/t/install-using-kickstart-and-post-rsync/13146/5 "2024-03-11T06:18:13Z")

</div>

Looking at the documentation this could work but it works in the opposite way, this gives the controller access to the host server were currently we give the host access to the controller.

_Reason: customers with on site servers and the impossible task to get ssh access, it’s easier to get_ _access out from a clients network than into their networks_

* * *

My biggest issue is security related to the kickstart file. If anyone gets access to kickstart file, they can get access to the files.  
Using `sshkey` won’t allow access to the controller which fixed the security issue.

* * *

I am also doing all of this to update/maintain config of our servers. Exp: A simple change to httpd.conf can be synced to all the servers. I currently I am use cron and a bash script to pull the changes from a rsync deamon server.  
Puppet, Ansible and rsyncd to me, all do exactly the same thing just an a different way.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/rockylinux/original/1X/91b7219eec10e30013422e4df76c1d898711a5d5.svg) [@system](https://forums.rockylinux.org/u/system)\
**Post date:** [May 10, 2024, 6:18am UTC](https://forums.rockylinux.org/t/install-using-kickstart-and-post-rsync/13146/6 "2024-05-10T06:18:35Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
