


* create production, development branches
* have bootstrap.sh get ansible_pull_branch variable value

* have bootstrap.yml use ansible.builtin.blockinfile to maintain /etc/skel/.profile



# add /home/hpf-ans/bin/ansible-pull.sh crontab



  * Configure hosts
    # cat >>/etc/hosts <<!!TheEnd!!
    
      127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
      ::1       name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
      !!TheEnd!!
  * Configure chrony
    # cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
      pool 0.north-america.pool.ntp.org iburst
      !!TheEnd!!
  * Configure SSH
    # cat >/etc/ssh/sshd_config.d/hpetersenfamily.conf <<!!TheEnd!!
      PasswordAuthentication no
      PermitEmptyPasswords no
      PermitRootLogin no
      !!TheEnd!!
    # cat >>/home/first/.ssh/authorized_keys <<!!TheEnd!!
      ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBM5BBUOxkuSK7WlpaDvp6lrM9ajLSyh4PWD7VFzYOFN5/zfafy6Vf/oxtLE4UACw5ZGvBMQNH40bW+T9aO0lQ9g= first Heath@HPetersenFamily.com
      ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBBFiio/AimTUloJdfk4TXyWO7A0Fd9SoUcqheBjEvj4TnrxpSL/EhwF2CU9jZTasm6NBo2eKcH4aMt1l2ejOtIM= heath Heath@HPetersenFamily.com
      !!TheEnd!!


##########
########## normal tasks
##########
  
- name: Install openssh, openssh-server, openssh-sftp-server
  ansible.builtin.apt:
    pkg:
    - openssh
    - openssh-server
    - openssh-sftp-server
    
- name: Install bash, bash-completion
  ansible.builtin.apt:
    pkg:
    - bash
    - bash-completion
    
- name: Install chrony
  ansible.builtin.apt:
    pkg:
    - chrony
  
#- name: Set host name
#  ansible.builtin.hostname:
#    name: ## Fully qualified domain name ##
#    use: systemd
  
  
- name: Copy a new sudoers file into place, after passing validation with visudo
  ansible.builtin.template:
    src: /mine/sudoers
    dest: /etc/sudoers
    validate: /usr/sbin/visudo -cf %s

- name: Update sshd configuration safely, avoid locking yourself out
  ansible.builtin.template:
    src: etc/ssh/sshd_config.j2
    dest: /etc/ssh/sshd_config
    owner: root
    group: root
    mode: '0600'
    validate: /usr/sbin/sshd -t -f %s
    backup: yes


proxmox-clients
hw:
  pve-lxc:
  pve-oci:
  pve-kvm:


users: first, heath, hpf-ans

~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
~heath/.ssh/authorized_keys
~first/.ssh/authorized_keys
~heath/.gitconfig




fail2ban
uptime kuma

==============================================================
==============================================================
==============================================================

logrotate /var/log/ansible-pull.log
cron job for ansible-pull


use tags to do things like allow selecting software updates, software cleanup, etc.
ansible_os_family variable
ansible galaxy

have upgrade pip and ansible in ~hpf-ans/.ansible-venv
hashicorp vault
have ansible-pull.sh make sure only one copy is running