more bootstrap.sh
This commit is contained in:
+34
-21
@@ -1,7 +1,11 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
|
|
||||||
system-groupadd () {
|
#
|
||||||
sudo groupadd -r -g $2 $1
|
#### FUNCTIONS
|
||||||
|
#
|
||||||
|
|
||||||
|
system_groupadd () {
|
||||||
|
echo groupadd -r -g "$2" "$1"
|
||||||
rc=$?
|
rc=$?
|
||||||
if [ $rc -ne 0 ] ; then
|
if [ $rc -ne 0 ] ; then
|
||||||
echo "ERROR - Unable to add $1 group! ($rc)" 1>&2
|
echo "ERROR - Unable to add $1 group! ($rc)" 1>&2
|
||||||
@@ -9,9 +13,9 @@ system-groupadd () {
|
|||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
system-useradd () {
|
system_useradd () {
|
||||||
system-groupadd "${@}"
|
system_groupadd "${@}"
|
||||||
sudo useradd -r -u $2 -g $2 -s /bin/sh -m $1
|
echo useradd -r -u "$2" -g "$2" -s /bin/sh -m "$1"
|
||||||
rc=$?
|
rc=$?
|
||||||
if [ $rc -ne 0 ] ; then
|
if [ $rc -ne 0 ] ; then
|
||||||
echo "ERROR - Unable to add $1 user! ($rc)" 1>&2
|
echo "ERROR - Unable to add $1 user! ($rc)" 1>&2
|
||||||
@@ -19,25 +23,34 @@ system-useradd () {
|
|||||||
fi
|
fi
|
||||||
}
|
}
|
||||||
|
|
||||||
|
add_groups_to_user () {
|
||||||
|
echo usermod -aG "$1" "$2"
|
||||||
|
rc=$?
|
||||||
|
if [ $rc -ne 0 ] ; then
|
||||||
|
echo "ERROR - Unable to add groups ($1) to user ($2)! ($rc)" 1>&2
|
||||||
|
exit 3
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
#
|
||||||
|
#### PROCESS
|
||||||
|
#
|
||||||
|
|
||||||
|
###########?????????? VERIFY RUNNING AS ROOT
|
||||||
|
|
||||||
# Create system group hpf-sudo for normal sudo users
|
# Create system group hpf-sudo for normal sudo users
|
||||||
system-groupadd hpf-sudo 700
|
system_groupadd hpf-sudo 700
|
||||||
|
|
||||||
# Create system group hpf-sudo-np for special sudo users that don't require a password
|
# Create system group hpf-sudo-np for special sudo users that don't require a password
|
||||||
system-groupadd hpf-sudo-np 701
|
system_groupadd hpf-sudo-np 701
|
||||||
|
|
||||||
# Create the Ansible user
|
# Create the Ansible user
|
||||||
system-useradd hpf-ans 800
|
system_useradd hpf-ans 800
|
||||||
usermod -aG hpf-sudo-np hpf-ans
|
add_groups_to_user "hpf-sudo-np" hpf-ans
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
# Add hpf-ans authorized keys
|
|
||||||
# Add hpf-ans sudoers
|
|
||||||
# Add sudoers entries
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
# Create /etc/sudoers.d/hpetersenfamily
|
||||||
|
f="/etc/sudoers.d/hpf"
|
||||||
|
echo curl -o "$f" https://gitea.admin-a.hpetersenfamily.com/heath/ansible/raw/branch/main/etc_sudoers_d_hpf
|
||||||
|
echo chown root:root "$f"
|
||||||
|
echo chmod u=rw,g=r,o= "$f"
|
||||||
|
|||||||
@@ -0,0 +1,2 @@
|
|||||||
|
%hpf-sudo ALL=(ALL) ALL
|
||||||
|
%hpf-sudo-np ALL=(ALL) NOPASSWD: ALL
|
||||||
Reference in New Issue
Block a user