more bootstrap.sh

This commit is contained in:
2026-07-03 15:12:18 -05:00
parent 6aa85d22e9
commit 33766dbf66
2 changed files with 38 additions and 23 deletions
+36 -23
View File
@@ -1,43 +1,56 @@
#!/bin/sh #!/bin/sh
system-groupadd () { #
sudo groupadd -r -g $2 $1 #### FUNCTIONS
rc = $? #
system_groupadd () {
echo groupadd -r -g "$2" "$1"
rc=$?
if [ $rc -ne 0 ] ; then if [ $rc -ne 0 ] ; then
echo "ERROR - Unable to add $1 group! ($rc)" 1>&2 echo "ERROR - Unable to add $1 group! ($rc)" 1>&2
exit 1 exit 1
fi fi
} }
system-useradd () { system_useradd () {
system-groupadd "${@}" system_groupadd "${@}"
sudo useradd -r -u $2 -g $2 -s /bin/sh -m $1 echo useradd -r -u "$2" -g "$2" -s /bin/sh -m "$1"
rc = $? rc=$?
if [ $rc -ne 0 ] ; then if [ $rc -ne 0 ] ; then
echo "ERROR - Unable to add $1 user! ($rc)" 1>&2 echo "ERROR - Unable to add $1 user! ($rc)" 1>&2
exit 2 exit 2
fi fi
} }
add_groups_to_user () {
echo usermod -aG "$1" "$2"
rc=$?
if [ $rc -ne 0 ] ; then
echo "ERROR - Unable to add groups ($1) to user ($2)! ($rc)" 1>&2
exit 3
fi
}
#
#### PROCESS
#
###########?????????? VERIFY RUNNING AS ROOT
# Create system group hpf-sudo for normal sudo users # Create system group hpf-sudo for normal sudo users
system-groupadd hpf-sudo 700 system_groupadd hpf-sudo 700
# Create system group hpf-sudo-np for special sudo users that don't require a password # Create system group hpf-sudo-np for special sudo users that don't require a password
system-groupadd hpf-sudo-np 701 system_groupadd hpf-sudo-np 701
# Create the Ansible user # Create the Ansible user
system-useradd hpf-ans 800 system_useradd hpf-ans 800
usermod -aG hpf-sudo-np hpf-ans add_groups_to_user "hpf-sudo-np" hpf-ans
# Add hpf-ans authorized keys
# Add hpf-ans sudoers
# Add sudoers entries
# Create /etc/sudoers.d/hpetersenfamily
f="/etc/sudoers.d/hpf"
echo curl -o "$f" https://gitea.admin-a.hpetersenfamily.com/heath/ansible/raw/branch/main/etc_sudoers_d_hpf
echo chown root:root "$f"
echo chmod u=rw,g=r,o= "$f"
+2
View File
@@ -0,0 +1,2 @@
%hpf-sudo ALL=(ALL) ALL
%hpf-sudo-np ALL=(ALL) NOPASSWD: ALL