too much
This commit is contained in:
@@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
HPetersenFamily.com Ansible Configuration
|
HPetersenFamily.com Ansible Configuration
|
||||||
|
|
||||||
|
* set /etc/hostname to host.fqdn
|
||||||
* curl -s https://gitea.admin-a.hpetersenfamily.com/heath/ansible/raw/branch/main/bootstrap.sh | sudo /bin/bash
|
* curl -s https://gitea.admin-a.hpetersenfamily.com/heath/ansible/raw/branch/main/bootstrap.sh | sudo /bin/bash
|
||||||
|
|
||||||
* ansible-pull will look for host.fqdn.yml, host.yml, then local.yml
|
* ansible-pull will look for host.fqdn.yml, host.yml, then local.yml
|
||||||
|
|||||||
+50
-20
@@ -1,5 +1,23 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
|
|
||||||
|
|
||||||
|
#
|
||||||
|
#### VARIABLES
|
||||||
|
#
|
||||||
|
|
||||||
|
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||||
|
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||||
|
GIT_REPO_ETC_SUDOERS_D_HPF="${GIT_REPO_BASE}/raw/branch/main/etc_sudoers_d_hpf"
|
||||||
|
GIT_REPO_HOME_HPF_ANS_BIN_ANSIBLE_PULL_SH="${GIT_REPO_BASE}/raw/branch/main/home_hpf_ans_bin_ansible-pull.sh"
|
||||||
|
|
||||||
|
HPF_ANS_BIN_DIR=~hpf
|
||||||
|
|
||||||
|
VENV_DIRECTORY=~hpf-ans/.ansible-venv
|
||||||
|
VENV_ACTIVATE="${VENV_DIRECTORY}/bin/activate"
|
||||||
|
|
||||||
|
ANSIBLE_PULL_LOG="/var/log/ansible-pull.log"
|
||||||
|
|
||||||
|
|
||||||
#
|
#
|
||||||
#### FUNCTIONS
|
#### FUNCTIONS
|
||||||
#
|
#
|
||||||
@@ -47,6 +65,11 @@ add_groups_to_user () {
|
|||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
# $command_line
|
||||||
|
as_hpf_ans () {
|
||||||
|
su --login hpf-ans -c "if [ -r \"${VENV_ACTIVATE}\" ] ; then source \"${VENV_ACTIVATE}\" ; fi ; ${1}"
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
#
|
#
|
||||||
#### PROCESS
|
#### PROCESS
|
||||||
@@ -58,6 +81,15 @@ if [ $(id -u) -ne 0 ] ; then
|
|||||||
exit 100
|
exit 100
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# Install minimal necessary packages
|
||||||
|
if which -s apt ; then
|
||||||
|
apt update
|
||||||
|
apt install bash curl python3 python3-pip python3-venv -y
|
||||||
|
else
|
||||||
|
echo "ERROR - Unable to determine how to install packages" 1>&2
|
||||||
|
exit 101
|
||||||
|
fi
|
||||||
|
|
||||||
# Create system group hpf-sudo for normal sudo users
|
# Create system group hpf-sudo for normal sudo users
|
||||||
system_groupadd hpf-sudo 700
|
system_groupadd hpf-sudo 700
|
||||||
|
|
||||||
@@ -71,35 +103,33 @@ add_groups_to_user "hpf-sudo-np" hpf-ans
|
|||||||
# Create /etc/sudoers.d/hpf
|
# Create /etc/sudoers.d/hpf
|
||||||
f="/etc/sudoers.d/hpf"
|
f="/etc/sudoers.d/hpf"
|
||||||
if [ ! -f "$f" ] ; then
|
if [ ! -f "$f" ] ; then
|
||||||
curl -s -o "$f" \
|
curl -o "$f" "${GIT_REPO_ETC_SUDOERS_D_HPF}"
|
||||||
"https://gitea.admin-a.hpetersenfamily.com/heath/ansible/raw/branch/main/etc_sudoers_d_hpf"
|
|
||||||
chown root:root "$f"
|
chown root:root "$f"
|
||||||
chmod u=rw,g=r,o= "$f"
|
chmod u=rw,g=r,o= "$f"
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# Make sure python3 pip and venv are installed
|
|
||||||
if which -s apt ; then
|
|
||||||
apt update
|
|
||||||
apt install python3-pip python3-venv -y
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Make sure the hpf-ans ansible venv exists
|
# Make sure the hpf-ans ansible venv exists
|
||||||
venv_dir=~hpf-ans/.ansible-venv
|
as_hpf_ans "if [ ! -d \"${VENV_DIRECTORY}\" ] ; then python3 -m venv \"${VENV_DIRECTORY}\" ; fi"
|
||||||
venv_script="$venv_dir/bin/activate"
|
|
||||||
if [ ! -f "$venv_script" ] ; then
|
|
||||||
su --login hpf-ans -c \
|
|
||||||
"python3 -m venv \"$venv_dir\""
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Make sure pip is up to date in .ansible-venv
|
# Make sure pip is up to date in .ansible-venv
|
||||||
su --login hpf-ans -c \
|
as_hpf_ans "pip install --upgrade pip"
|
||||||
"source \"$venv_script\"; pip install --upgrade pip"
|
|
||||||
|
|
||||||
# Make sure ansible is installed in .ansible-venv
|
# Make sure ansible is installed in .ansible-venv
|
||||||
if ! su --login hpf-ans -c "source \"$venv_script\"; which -s ansible" ; then
|
as_hpf_ans "pip install ansible"
|
||||||
su --login hpf-ans -c \
|
|
||||||
"source \"$venv_script\"; pip install ansible"
|
# Create ~hpf-ans/bin directory
|
||||||
|
d=~hpf-ans/bin
|
||||||
|
if [ ! -d "${d}" ] ; then
|
||||||
|
as_hpf_ans "mkdir -p \"${d}\""
|
||||||
|
as_hpf_ans "chown hpf-ans:hpf-ans \"${d}\"; chmod ug=rwx,o= \"${d}\""
|
||||||
fi
|
fi
|
||||||
|
|
||||||
#### ansible-pull --only-if-changed -U https://gitea.admin-a.hpetersenfamily.com/heath/ansible.git 2>&1 | sudo tee -a /var/log/ansible-pull.log
|
# Create ~hpf-ans/bin/ansible-pull.sh
|
||||||
|
f=~hpf-ans/bin/ansible-pull.sh
|
||||||
|
if [ ! -f "${f}" ] ; then
|
||||||
|
as_hpf_ans "curl -o \"${f}\" \"${GIT_REPO_HOME_HPF_ANS_BIN_ANSIBLE_PULL_SH}\""
|
||||||
|
as_hpf_ans "chown hpf-ans:hpf-ans \"${f}\"; chmod ug=rwx,o= \"${f}\""
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Run ansible-pull to finish up
|
||||||
|
#as_hpf_ans "ansible-pull --only-if-changed -U \"${GIT_REPO}\" 2>&1 | sudo tee -a \"${ANSIBLE_PULL_LOG}\""
|
||||||
|
|||||||
@@ -0,0 +1,14 @@
|
|||||||
|
#!/bin/bash
|
||||||
|
|
||||||
|
source ~/.ansible-venv/bin/activate
|
||||||
|
|
||||||
|
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||||
|
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||||
|
|
||||||
|
ANSIBLE_PULL_LOG="/var/log/ansible-pull.log"
|
||||||
|
|
||||||
|
echo | sudo tee -a "${ANSIBLE_PULL_LOG}"
|
||||||
|
echo -n "${0}: " | sudo tee -a "${ANSIBLE_PULL_LOG}"
|
||||||
|
date "+%Y-%m-%d %H:%M:%S" | sudo tee -a "${ANSIBLE_PULL_LOG}"
|
||||||
|
ansible-pull --only-if-changed -U "${GIT_REPO}" 2>&1 | sudo tee -a "${ANSIBLE_PULL_LOG}"
|
||||||
|
|
||||||
Reference in New Issue
Block a user