diff --git a/README.md b/README.md index 1d9eea3..d945a68 100644 --- a/README.md +++ b/README.md @@ -2,6 +2,7 @@ HPetersenFamily.com Ansible Configuration +* set /etc/hostname to host.fqdn * curl -s https://gitea.admin-a.hpetersenfamily.com/heath/ansible/raw/branch/main/bootstrap.sh | sudo /bin/bash * ansible-pull will look for host.fqdn.yml, host.yml, then local.yml diff --git a/bootstrap.sh b/bootstrap.sh index 8cf8d91..1b3bdf4 100644 --- a/bootstrap.sh +++ b/bootstrap.sh @@ -1,5 +1,23 @@ #!/bin/sh + +# +#### VARIABLES +# + +GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible" +GIT_REPO="${GIT_REPO_BASE}.git" +GIT_REPO_ETC_SUDOERS_D_HPF="${GIT_REPO_BASE}/raw/branch/main/etc_sudoers_d_hpf" +GIT_REPO_HOME_HPF_ANS_BIN_ANSIBLE_PULL_SH="${GIT_REPO_BASE}/raw/branch/main/home_hpf_ans_bin_ansible-pull.sh" + +HPF_ANS_BIN_DIR=~hpf + +VENV_DIRECTORY=~hpf-ans/.ansible-venv +VENV_ACTIVATE="${VENV_DIRECTORY}/bin/activate" + +ANSIBLE_PULL_LOG="/var/log/ansible-pull.log" + + # #### FUNCTIONS # @@ -47,6 +65,11 @@ add_groups_to_user () { fi } +# $command_line +as_hpf_ans () { + su --login hpf-ans -c "if [ -r \"${VENV_ACTIVATE}\" ] ; then source \"${VENV_ACTIVATE}\" ; fi ; ${1}" +} + # #### PROCESS @@ -58,6 +81,15 @@ if [ $(id -u) -ne 0 ] ; then exit 100 fi +# Install minimal necessary packages +if which -s apt ; then + apt update + apt install bash curl python3 python3-pip python3-venv -y +else + echo "ERROR - Unable to determine how to install packages" 1>&2 + exit 101 +fi + # Create system group hpf-sudo for normal sudo users system_groupadd hpf-sudo 700 @@ -71,35 +103,33 @@ add_groups_to_user "hpf-sudo-np" hpf-ans # Create /etc/sudoers.d/hpf f="/etc/sudoers.d/hpf" if [ ! -f "$f" ] ; then - curl -s -o "$f" \ - "https://gitea.admin-a.hpetersenfamily.com/heath/ansible/raw/branch/main/etc_sudoers_d_hpf" + curl -o "$f" "${GIT_REPO_ETC_SUDOERS_D_HPF}" chown root:root "$f" chmod u=rw,g=r,o= "$f" fi -# Make sure python3 pip and venv are installed -if which -s apt ; then - apt update - apt install python3-pip python3-venv -y -fi - # Make sure the hpf-ans ansible venv exists -venv_dir=~hpf-ans/.ansible-venv -venv_script="$venv_dir/bin/activate" -if [ ! -f "$venv_script" ] ; then - su --login hpf-ans -c \ - "python3 -m venv \"$venv_dir\"" -fi +as_hpf_ans "if [ ! -d \"${VENV_DIRECTORY}\" ] ; then python3 -m venv \"${VENV_DIRECTORY}\" ; fi" # Make sure pip is up to date in .ansible-venv -su --login hpf-ans -c \ - "source \"$venv_script\"; pip install --upgrade pip" +as_hpf_ans "pip install --upgrade pip" # Make sure ansible is installed in .ansible-venv -if ! su --login hpf-ans -c "source \"$venv_script\"; which -s ansible" ; then - su --login hpf-ans -c \ - "source \"$venv_script\"; pip install ansible" +as_hpf_ans "pip install ansible" + +# Create ~hpf-ans/bin directory +d=~hpf-ans/bin +if [ ! -d "${d}" ] ; then + as_hpf_ans "mkdir -p \"${d}\"" + as_hpf_ans "chown hpf-ans:hpf-ans \"${d}\"; chmod ug=rwx,o= \"${d}\"" fi -#### ansible-pull --only-if-changed -U https://gitea.admin-a.hpetersenfamily.com/heath/ansible.git 2>&1 | sudo tee -a /var/log/ansible-pull.log +# Create ~hpf-ans/bin/ansible-pull.sh +f=~hpf-ans/bin/ansible-pull.sh +if [ ! -f "${f}" ] ; then + as_hpf_ans "curl -o \"${f}\" \"${GIT_REPO_HOME_HPF_ANS_BIN_ANSIBLE_PULL_SH}\"" + as_hpf_ans "chown hpf-ans:hpf-ans \"${f}\"; chmod ug=rwx,o= \"${f}\"" +fi +# Run ansible-pull to finish up +#as_hpf_ans "ansible-pull --only-if-changed -U \"${GIT_REPO}\" 2>&1 | sudo tee -a \"${ANSIBLE_PULL_LOG}\"" diff --git a/home_hpf_ans_bin_ansible-pull.sh b/home_hpf_ans_bin_ansible-pull.sh new file mode 100644 index 0000000..b2d2d17 --- /dev/null +++ b/home_hpf_ans_bin_ansible-pull.sh @@ -0,0 +1,14 @@ +#!/bin/bash + +source ~/.ansible-venv/bin/activate + +GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible" +GIT_REPO="${GIT_REPO_BASE}.git" + +ANSIBLE_PULL_LOG="/var/log/ansible-pull.log" + +echo | sudo tee -a "${ANSIBLE_PULL_LOG}" +echo -n "${0}: " | sudo tee -a "${ANSIBLE_PULL_LOG}" +date "+%Y-%m-%d %H:%M:%S" | sudo tee -a "${ANSIBLE_PULL_LOG}" +ansible-pull --only-if-changed -U "${GIT_REPO}" 2>&1 | sudo tee -a "${ANSIBLE_PULL_LOG}" +