clean up bootstrap.sh
This commit is contained in:
+62
-28
@@ -25,7 +25,6 @@
|
||||
TIMESTAMP="$(date "+%Y%m%d%H%M%S")"
|
||||
|
||||
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||
#GIT_REPO="${GIT_REPO_BASE}.git"
|
||||
GIT_REPO_BRANCH="${1:-"development"}"
|
||||
|
||||
GIT_REPO_FILES="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files"
|
||||
@@ -35,7 +34,8 @@ GIT_REPO_ansible_venv_sh="${GIT_REPO_FILES}/profile_d_ansible_venv_sh"
|
||||
GIT_REPO_profile_append="${GIT_REPO_FILES}/profile_append"
|
||||
GIT_REPO_ansible_pull_sh="${GIT_REPO_FILES}/ansible_pull_sh"
|
||||
|
||||
ETC_sudoers_d_hpf="/etc/sudoers.d/hpf"
|
||||
ETC_sudoers_d="/etc/sudoers.d"
|
||||
ETC_sudoers_d_hpf="${ETC_sudoers_d}/hpf"
|
||||
|
||||
unset SKEL
|
||||
if [ -r /etc/default/useradd ] ; then . /etc/default/useradd ; fi
|
||||
@@ -44,11 +44,6 @@ SKEL_profile_d="${SKEL}/.profile.d"
|
||||
SKEL_ansible_venv_sh="${SKEL_profile_d}/ansible-venv.sh"
|
||||
SKEL_profile="${SKEL}/.profile"
|
||||
|
||||
HPF_ANS_ansible_venv_dir="\${HOME}/.ansible-venv"
|
||||
|
||||
HPF_ANS_bin="\${HOME}/bin"
|
||||
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
|
||||
|
||||
ANSIBLE_PULL_SH_LOG_DIR="/var/log/ansible-pull.sh"
|
||||
|
||||
|
||||
@@ -99,6 +94,34 @@ add_groups_to_user () {
|
||||
fi
|
||||
}
|
||||
|
||||
# $source_file $dest_file $dest_file_ownership $dest_file_permissions
|
||||
get_file() {
|
||||
local source_file dest_file dest_file_ownership dest_file_permissions
|
||||
|
||||
source_file="${1}"
|
||||
dest_file="${2}"
|
||||
dest_file_ownership="${3}"
|
||||
dest_file_permissions="${4}"
|
||||
|
||||
if [ -e "${dest_file}" ] ; then mv "${dest_file}" "${dest_file}.${TIMESTAMP}" ; fi
|
||||
curl -o "${dest_file}" "${source_file}"
|
||||
chown "${dest_file_ownership}" "${dest_file}"
|
||||
chmod "${dest_file_permissions}" "${dest_file}"
|
||||
}
|
||||
|
||||
# $directory $directory_ownership $directory_permissions
|
||||
create_directory() {
|
||||
local directory directory_ownership directory_permissions
|
||||
|
||||
directory="${1}"
|
||||
directory_ownership ="${2}"
|
||||
directory_permissions="${3}"
|
||||
|
||||
mkdir -p "${directory}"
|
||||
chown "${directory_ownership}" "${directory}"
|
||||
chmod "${directory_permissions}" "${directory}"
|
||||
}
|
||||
|
||||
# $command_line
|
||||
as_hpf_ans () {
|
||||
su --login hpf-ans --command "${1}"
|
||||
@@ -130,28 +153,43 @@ system_groupadd hpf-sudo 700
|
||||
# Create system group hpf-sudo-np for special sudo users that don't require a password
|
||||
system_groupadd hpf-sudo-np 701
|
||||
|
||||
# Create /etc/sudoers.d/hpf to allow common sudo permissions
|
||||
if [ -e "${ETC_sudoers_d_hpf}" ] ; then mv "${ETC_sudoers_d_hpf}" "${ETC_sudoers_d_hpf}.${TIMESTAMP}" ; fi
|
||||
curl -o "${ETC_sudoers_d_hpf}" "${GIT_REPO_sudoers_d_hpf}"
|
||||
chown root:root "${ETC_sudoers_d_hpf}"; chmod u=rw,go= "${ETC_sudoers_d_hpf}"
|
||||
# Make sure /etc/sudoers.d exists
|
||||
create_directory "${ETC_sudoers_d}" "root:root" "u=rwx,go="
|
||||
|
||||
# Make sure .profile.d exists
|
||||
mkdir -p "${SKEL_profile_d}"
|
||||
chown root:root "${SKEL_profile_d}"; chmod u=rwx,go= "${SKEL_profile_d}"
|
||||
# Get /etc/sudoers.d/hpf
|
||||
get_file "${GIT_REPO_sudoers_d_hpf}" "${ETC_sudoers_d_hpf}" "root:root" "u=rw,go="
|
||||
|
||||
# Create ansible-venv.sh
|
||||
if [ ! -r "${SKEL_ansible_venv_sh}" ] ; then
|
||||
curl -o "${SKEL_ansible_venv_sh}" "${GIT_REPO_ansible_venv_sh}"
|
||||
chown root:root "${SKEL_ansible_venv_sh}"; chmod u=rwx,go= "${SKEL_ansible_venv_sh}"
|
||||
curl "${GIT_REPO_profile_append}" >>"${SKEL_profile}"
|
||||
fi
|
||||
# Make sure /etc/skel/.profile.d exists
|
||||
create_directory "${SKEL_profile_d}" "root:root" "u=rwx,go="
|
||||
|
||||
# Get /etc/skel/.profile.d/ansible-venv.sh
|
||||
get_file "${GIT_REPO_ansible_venv_sh}" "${SKEL_ansible_venv_sh}" "root:root" "u=rwx,go="
|
||||
|
||||
# Get /etc/skel/.profile
|
||||
get_file "${GIT_REPO_profile_append}" "${SKEL_profile}" "root:root" "u=rw,go=r"
|
||||
|
||||
# Create the hpf-ans user
|
||||
system_useradd hpf-ans 800
|
||||
add_groups_to_user hpf-sudo-np hpf-ans
|
||||
|
||||
# Determine HPF_ANS variables now that the user is created
|
||||
HPF_ANS_HOME="$(as_hpf_ans 'echo "${HOME}"')"
|
||||
HPF_ANS_ansible_venv="${HPF_ANS_HOME}/.ansible-venv"
|
||||
HPF_ANS_bin="${HPF_ANS_HOME}/bin"
|
||||
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
|
||||
|
||||
|
||||
|
||||
echo "HPF_ANS_HOME=\"${HPF_ANS_HOME}\""
|
||||
echo "HPF_ANS_ansible_venv=\"${HPF_ANS_ansible_venv}\""
|
||||
echo "HPF_ANS_bin=\"${HPF_ANS_bin}\""
|
||||
echo "HPF_ANS_ansible_pull_sh=\"${HPF_ANS_ansible_pull_sh}\""
|
||||
exit 200
|
||||
|
||||
|
||||
|
||||
# Make sure .ansible-venv exists
|
||||
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv_dir}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv_dir}\" ; fi"
|
||||
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi"
|
||||
|
||||
# Make sure pip is up to date
|
||||
as_hpf_ans "pip install --upgrade pip"
|
||||
@@ -160,17 +198,13 @@ as_hpf_ans "pip install --upgrade pip"
|
||||
as_hpf_ans "pip install --upgrade ansible"
|
||||
|
||||
# Make sure bin exists
|
||||
as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\""
|
||||
create_directory "${HPF_ANS_bin}" "hpf-ans:hpf-ans" "u=rwx,go="
|
||||
|
||||
# Create ansible-pull.sh
|
||||
as_hpf_ans "if [ -e \"${HPF_ANS_ansible_pull_sh}\" ] ; then mv \"${HPF_ANS_ansible_pull_sh}\" \"${HPF_ANS_ansible_pull_sh}.${TIMESTAMP}\" ; fi"
|
||||
as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\""
|
||||
get_file "${GIT_REPO_ansible_pull_sh}" "${HPF_ANS_ansible_pull_sh}" "hpf-ans:hpf-ans" "u=rwx,go="
|
||||
|
||||
# Make sure log directory exists
|
||||
mkdir -p "${ANSIBLE_PULL_SH_LOG_DIR}"
|
||||
chown hpf-ans:root "${ANSIBLE_PULL_SH_LOG_DIR}"; chmod ug=rwx,o= "${ANSIBLE_PULL_SH_LOG_DIR}"
|
||||
create_directory "${ANSIBLE_PULL_SH_LOG_DIR}" "hpf-ans:root" "u=rwx,go="
|
||||
|
||||
# Run ansible-pull to finish up
|
||||
#as_hpf_ans "$HPF_ANS_ansible_pull_sh --branch ${GIT_REPO_BRANCH} bootstrap.yml"
|
||||
|
||||
Reference in New Issue
Block a user