clean house
This commit is contained in:
+29
-25
@@ -7,11 +7,17 @@
|
||||
|
||||
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||
GIT_REPO_etc_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/etc_sudoers_d_hpf"
|
||||
GIT_REPO_home_hpf_ans_bin_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/home_hpf_ans_bin_ansible-pull.sh"
|
||||
GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/etc_sudoers_d_hpf"
|
||||
GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/home_hpf_ans_bin_ansible-pull.sh"
|
||||
|
||||
VENV_DIRECTORY="\${HOME}/.ansible-venv"
|
||||
VENV_ACTIVATE="${VENV_DIRECTORY}/bin/activate"
|
||||
|
||||
ETC_sudoers_d_hpf="/etc/sudoers.d/hpf"
|
||||
|
||||
HPF_ANS_ansible_venv="\${HOME}/.ansible-venv"
|
||||
HPF_ANS_activate="${HPF_ANS_ansible_venv}/bin/activate"
|
||||
|
||||
HPF_ANS_bin="\${HOME}/bin"
|
||||
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
|
||||
|
||||
ANSIBLE_PULL_LOG="/var/log/ansible-pull.log"
|
||||
|
||||
@@ -65,7 +71,7 @@ add_groups_to_user () {
|
||||
|
||||
# $command_line
|
||||
as_hpf_ans () {
|
||||
su --login hpf-ans -c "if [ -r \"${VENV_ACTIVATE}\" ] ; then source \"${VENV_ACTIVATE}\" ; fi ; ${1}"
|
||||
su --login hpf-ans -c "if [ -r \"${HPF_ANS_activate}\" ] ; then source \"${HPF_ANS_activate}\" ; fi ; ${1}"
|
||||
}
|
||||
|
||||
|
||||
@@ -94,35 +100,33 @@ system_groupadd hpf-sudo 700
|
||||
# Create system group hpf-sudo-np for special sudo users that don't require a password
|
||||
system_groupadd hpf-sudo-np 701
|
||||
|
||||
# Create the Ansible user
|
||||
# Create /etc/sudoers.d/hpf to allow common sudo permissions
|
||||
rm "${ETC_sudoers_d_hpf}" 2>/dev/null
|
||||
curl -o "$ETC_sudoers_d_hpf" "${GIT_REPO_sudoers_d_hpf}"
|
||||
chown root:root "${ETC_sudoers_d_hpf}"
|
||||
chmod u=rw,g=r,o= "${ETC_sudoers_d_hpf}"
|
||||
|
||||
# Create the hpf-ans user
|
||||
system_useradd hpf-ans 800
|
||||
add_groups_to_user "hpf-sudo-np" hpf-ans
|
||||
add_groups_to_user hpf-sudo-np hpf-ans
|
||||
|
||||
# Create /etc/sudoers.d/hpf
|
||||
f="/etc/sudoers.d/hpf"
|
||||
rm "${f}" 2>/dev/null
|
||||
curl -o "$f" "${GIT_REPO_etc_sudoers_d_hpf}"
|
||||
chown root:root "$f"
|
||||
chmod u=rw,g=r,o= "$f"
|
||||
# Make sure .ansible-venv exists
|
||||
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then python3 -m venv \"${HPF_ANS_ansible_venv}\" ; fi"
|
||||
|
||||
# Make sure the hpf-ans ansible venv exists
|
||||
as_hpf_ans "if [ ! -d \"${VENV_DIRECTORY}\" ] ; then python3 -m venv \"${VENV_DIRECTORY}\" ; fi"
|
||||
|
||||
# Make sure pip is up to date in .ansible-venv
|
||||
# Make sure pip is up to date
|
||||
as_hpf_ans "pip install --upgrade pip"
|
||||
|
||||
# Make sure ansible is installed in .ansible-venv
|
||||
# Make sure ansible is installed
|
||||
as_hpf_ans "pip install ansible"
|
||||
|
||||
# Create ~hpf-ans/bin directory
|
||||
d="\${HOME}/bin"
|
||||
as_hpf_ans "mkdir -p \"${d}\"; chown hpf-ans:hpf-ans \"${d}\"; chmod ug=rwx,o= \"${d}\""
|
||||
# Make sure bin exists
|
||||
as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod ug=rwx,o= \"${HPF_ANS_bin}\""
|
||||
|
||||
# Create ~hpf-ans/bin/ansible-pull.sh
|
||||
f="\${HOME}/bin/ansible-pull.sh"
|
||||
as_hpf_ans "rm \"${f}\" 2>/dev/null"
|
||||
as_hpf_ans "curl -o \"${f}\" \"${GIT_REPO_home_hpf_ans_bin_ansible_pull_sh}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${f}\"; chmod ug=rwx,o= \"${f}\""
|
||||
as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null"
|
||||
as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod ug=rwx,o= \"${HPF_ANS_ansible_pull_sh}\""
|
||||
|
||||
# Run ansible-pull to finish up
|
||||
as_hpf_ans "bin/ansible-pull.sh"
|
||||
|
||||
Reference in New Issue
Block a user