From 438c4d2100749310f91c021e2ccce66f5e9ef55f82115d2769fbee2227e83507 Mon Sep 17 00:00:00 2001 From: Heath Petersen Date: Fri, 24 Jul 2026 13:07:37 -0500 Subject: [PATCH] clean up bootstrap.sh --- bootstrap.sh | 90 ++++++++++++++++++++++++++++++++++++---------------- 1 file changed, 62 insertions(+), 28 deletions(-) diff --git a/bootstrap.sh b/bootstrap.sh index c5a1af8..008fd55 100644 --- a/bootstrap.sh +++ b/bootstrap.sh @@ -25,7 +25,6 @@ TIMESTAMP="$(date "+%Y%m%d%H%M%S")" GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible" -#GIT_REPO="${GIT_REPO_BASE}.git" GIT_REPO_BRANCH="${1:-"development"}" GIT_REPO_FILES="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files" @@ -35,7 +34,8 @@ GIT_REPO_ansible_venv_sh="${GIT_REPO_FILES}/profile_d_ansible_venv_sh" GIT_REPO_profile_append="${GIT_REPO_FILES}/profile_append" GIT_REPO_ansible_pull_sh="${GIT_REPO_FILES}/ansible_pull_sh" -ETC_sudoers_d_hpf="/etc/sudoers.d/hpf" +ETC_sudoers_d="/etc/sudoers.d" +ETC_sudoers_d_hpf="${ETC_sudoers_d}/hpf" unset SKEL if [ -r /etc/default/useradd ] ; then . /etc/default/useradd ; fi @@ -44,11 +44,6 @@ SKEL_profile_d="${SKEL}/.profile.d" SKEL_ansible_venv_sh="${SKEL_profile_d}/ansible-venv.sh" SKEL_profile="${SKEL}/.profile" -HPF_ANS_ansible_venv_dir="\${HOME}/.ansible-venv" - -HPF_ANS_bin="\${HOME}/bin" -HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh" - ANSIBLE_PULL_SH_LOG_DIR="/var/log/ansible-pull.sh" @@ -99,6 +94,34 @@ add_groups_to_user () { fi } +# $source_file $dest_file $dest_file_ownership $dest_file_permissions +get_file() { + local source_file dest_file dest_file_ownership dest_file_permissions + + source_file="${1}" + dest_file="${2}" + dest_file_ownership="${3}" + dest_file_permissions="${4}" + + if [ -e "${dest_file}" ] ; then mv "${dest_file}" "${dest_file}.${TIMESTAMP}" ; fi + curl -o "${dest_file}" "${source_file}" + chown "${dest_file_ownership}" "${dest_file}" + chmod "${dest_file_permissions}" "${dest_file}" +} + +# $directory $directory_ownership $directory_permissions +create_directory() { + local directory directory_ownership directory_permissions + + directory="${1}" + directory_ownership ="${2}" + directory_permissions="${3}" + + mkdir -p "${directory}" + chown "${directory_ownership}" "${directory}" + chmod "${directory_permissions}" "${directory}" +} + # $command_line as_hpf_ans () { su --login hpf-ans --command "${1}" @@ -130,28 +153,43 @@ system_groupadd hpf-sudo 700 # Create system group hpf-sudo-np for special sudo users that don't require a password system_groupadd hpf-sudo-np 701 -# Create /etc/sudoers.d/hpf to allow common sudo permissions -if [ -e "${ETC_sudoers_d_hpf}" ] ; then mv "${ETC_sudoers_d_hpf}" "${ETC_sudoers_d_hpf}.${TIMESTAMP}" ; fi -curl -o "${ETC_sudoers_d_hpf}" "${GIT_REPO_sudoers_d_hpf}" -chown root:root "${ETC_sudoers_d_hpf}"; chmod u=rw,go= "${ETC_sudoers_d_hpf}" +# Make sure /etc/sudoers.d exists +create_directory "${ETC_sudoers_d}" "root:root" "u=rwx,go=" -# Make sure .profile.d exists -mkdir -p "${SKEL_profile_d}" -chown root:root "${SKEL_profile_d}"; chmod u=rwx,go= "${SKEL_profile_d}" +# Get /etc/sudoers.d/hpf +get_file "${GIT_REPO_sudoers_d_hpf}" "${ETC_sudoers_d_hpf}" "root:root" "u=rw,go=" -# Create ansible-venv.sh -if [ ! -r "${SKEL_ansible_venv_sh}" ] ; then - curl -o "${SKEL_ansible_venv_sh}" "${GIT_REPO_ansible_venv_sh}" - chown root:root "${SKEL_ansible_venv_sh}"; chmod u=rwx,go= "${SKEL_ansible_venv_sh}" - curl "${GIT_REPO_profile_append}" >>"${SKEL_profile}" -fi +# Make sure /etc/skel/.profile.d exists +create_directory "${SKEL_profile_d}" "root:root" "u=rwx,go=" + +# Get /etc/skel/.profile.d/ansible-venv.sh +get_file "${GIT_REPO_ansible_venv_sh}" "${SKEL_ansible_venv_sh}" "root:root" "u=rwx,go=" + +# Get /etc/skel/.profile +get_file "${GIT_REPO_profile_append}" "${SKEL_profile}" "root:root" "u=rw,go=r" # Create the hpf-ans user system_useradd hpf-ans 800 add_groups_to_user hpf-sudo-np hpf-ans +# Determine HPF_ANS variables now that the user is created +HPF_ANS_HOME="$(as_hpf_ans 'echo "${HOME}"')" +HPF_ANS_ansible_venv="${HPF_ANS_HOME}/.ansible-venv" +HPF_ANS_bin="${HPF_ANS_HOME}/bin" +HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh" + + + +echo "HPF_ANS_HOME=\"${HPF_ANS_HOME}\"" +echo "HPF_ANS_ansible_venv=\"${HPF_ANS_ansible_venv}\"" +echo "HPF_ANS_bin=\"${HPF_ANS_bin}\"" +echo "HPF_ANS_ansible_pull_sh=\"${HPF_ANS_ansible_pull_sh}\"" +exit 200 + + + # Make sure .ansible-venv exists -as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv_dir}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv_dir}\" ; fi" +as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi" # Make sure pip is up to date as_hpf_ans "pip install --upgrade pip" @@ -160,17 +198,13 @@ as_hpf_ans "pip install --upgrade pip" as_hpf_ans "pip install --upgrade ansible" # Make sure bin exists -as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\"" -as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\"" +create_directory "${HPF_ANS_bin}" "hpf-ans:hpf-ans" "u=rwx,go=" # Create ansible-pull.sh -as_hpf_ans "if [ -e \"${HPF_ANS_ansible_pull_sh}\" ] ; then mv \"${HPF_ANS_ansible_pull_sh}\" \"${HPF_ANS_ansible_pull_sh}.${TIMESTAMP}\" ; fi" -as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\"" -as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\"" +get_file "${GIT_REPO_ansible_pull_sh}" "${HPF_ANS_ansible_pull_sh}" "hpf-ans:hpf-ans" "u=rwx,go=" # Make sure log directory exists -mkdir -p "${ANSIBLE_PULL_SH_LOG_DIR}" -chown hpf-ans:root "${ANSIBLE_PULL_SH_LOG_DIR}"; chmod ug=rwx,o= "${ANSIBLE_PULL_SH_LOG_DIR}" +create_directory "${ANSIBLE_PULL_SH_LOG_DIR}" "hpf-ans:root" "u=rwx,go=" # Run ansible-pull to finish up #as_hpf_ans "$HPF_ANS_ansible_pull_sh --branch ${GIT_REPO_BRANCH} bootstrap.yml"