diff --git a/bootstrap.sh b/bootstrap.sh index 2ba0b2f..190141a 100644 --- a/bootstrap.sh +++ b/bootstrap.sh @@ -1,43 +1,56 @@ #!/bin/sh -system-groupadd () { - sudo groupadd -r -g $2 $1 - rc = $? +# +#### FUNCTIONS +# + +system_groupadd () { + echo groupadd -r -g "$2" "$1" + rc=$? if [ $rc -ne 0 ] ; then echo "ERROR - Unable to add $1 group! ($rc)" 1>&2 exit 1 fi } -system-useradd () { - system-groupadd "${@}" - sudo useradd -r -u $2 -g $2 -s /bin/sh -m $1 - rc = $? +system_useradd () { + system_groupadd "${@}" + echo useradd -r -u "$2" -g "$2" -s /bin/sh -m "$1" + rc=$? if [ $rc -ne 0 ] ; then echo "ERROR - Unable to add $1 user! ($rc)" 1>&2 exit 2 fi } +add_groups_to_user () { + echo usermod -aG "$1" "$2" + rc=$? + if [ $rc -ne 0 ] ; then + echo "ERROR - Unable to add groups ($1) to user ($2)! ($rc)" 1>&2 + exit 3 + fi +} + + +# +#### PROCESS +# + +###########?????????? VERIFY RUNNING AS ROOT + # Create system group hpf-sudo for normal sudo users -system-groupadd hpf-sudo 700 +system_groupadd hpf-sudo 700 # Create system group hpf-sudo-np for special sudo users that don't require a password -system-groupadd hpf-sudo-np 701 +system_groupadd hpf-sudo-np 701 # Create the Ansible user -system-useradd hpf-ans 800 -usermod -aG hpf-sudo-np hpf-ans - - - - - -# Add hpf-ans authorized keys -# Add hpf-ans sudoers -# Add sudoers entries - - - - +system_useradd hpf-ans 800 +add_groups_to_user "hpf-sudo-np" hpf-ans +# Create /etc/sudoers.d/hpetersenfamily +f="/etc/sudoers.d/hpf" +echo curl -o "$f" https://gitea.admin-a.hpetersenfamily.com/heath/ansible/raw/branch/main/etc_sudoers_d_hpf +echo chown root:root "$f" +echo chmod u=rw,g=r,o= "$f" diff --git a/etc_sudoers_d_hpf b/etc_sudoers_d_hpf new file mode 100644 index 0000000..6e6cc1a --- /dev/null +++ b/etc_sudoers_d_hpf @@ -0,0 +1,2 @@ +%hpf-sudo ALL=(ALL) ALL +%hpf-sudo-np ALL=(ALL) NOPASSWD: ALL