From 8b50cacb1ba17d9111abeb79b569a89795aa26b34eee5835e1a736cbc310f0c5 Mon Sep 17 00:00:00 2001 From: Heath Petersen Date: Sun, 26 Jul 2026 12:03:03 -0500 Subject: [PATCH] preparing to schedule ansible-pull.sh --- bootstrap.yml | 51 +++++++++++++------------- files/home/hpf-ans/bin/ansible-pull.sh | 30 +++++++++------ 2 files changed, 44 insertions(+), 37 deletions(-) diff --git a/bootstrap.yml b/bootstrap.yml index 0cbf345..ddfb019 100644 --- a/bootstrap.yml +++ b/bootstrap.yml @@ -1,22 +1,4 @@ --- - -#### -#### WARNING: -#### -#### bootstrap.sh and bootstrap.yml should be updated together. They should do the -#### exact same things with the following exceptions: -#### -#### * bootstrap.sh -#### - at the end it should run ansible-pull.sh against bootstrap.yml -#### -#### * bootstrap.yml -#### - at the end it should configure cron to schedule ansible-pull.sh -#### -#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! -#### ! Make sure to keep them in sync ! -#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! -#### - - name: Bootstrap playbook hosts: all @@ -41,6 +23,7 @@ - python3-pip - python3-venv - python3-virtualenv + - logrotate #### Configure sudo @@ -276,7 +259,7 @@ key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}" -#### Schedule ansible-pull.sh +#### ansible-pull.sh - name: Make sure log directory exists become: true @@ -287,13 +270,29 @@ group: root mode: u=rwx,go= -# - name: Create ansible-pull.sh crontab entry -# become: true -# ansible.builtin.cron: -# name: "ansible-pull" -# minute: "*/27" -# job: $HOME/bin/ansible-pull.sh -# backup: true +# - name: Create ansible-pull.sh crontab entry +# become: true +# become_user: hpf-ans +# ansible.builtin.cron: +# name: "ansible-pull" +# minute: "*/27" +# job: $HOME/bin/ansible-pull.sh +# backup: true + + - name: Rotate ansible-pull.sh.log + become: true + community.general.logrotate: + name: ansible-pull.sh + paths: + - /var/log/ansible-pull.sh/*.log + rotation_period: daily + rotate_count: 32 + compress: true + compress_options: "-9" + delay_compress: true + missing_ok: true + not_if_empty: true + backup: true #### Clean System Software diff --git a/files/home/hpf-ans/bin/ansible-pull.sh b/files/home/hpf-ans/bin/ansible-pull.sh index 4c3aa36..b56874e 100644 --- a/files/home/hpf-ans/bin/ansible-pull.sh +++ b/files/home/hpf-ans/bin/ansible-pull.sh @@ -1,4 +1,4 @@ -#!/bin/bash +#!/usr/bin/env bash # - Process command line GIT_REPO_BRANCH="production" @@ -14,10 +14,18 @@ while [ $# -gt 0 ]; do GIT_REPO_BRANCH="$1" shift 1 ;; + --) + shift 1 + break + ;; + *) + echo "$0: ERROR - Invalid argument." ; exit 2 + ;; esac done -# - Include ansible virtual environment +# - Include ansible virtual environment (in case not already done - we don't know how we're being run) +VIRTUAL_ENV_DISABLE_PROMPT=true . "${HOME}/.ansible-venv/bin/activate" SCRIPT_NAME="$(basename "${0}")" @@ -27,17 +35,17 @@ LOG_DIR="/var/log/ansible-pull.sh" LOG_FILE="${LOG_DIR}/ansible-pull.sh.log" LOCK_FILE="/tmp/ansible-pull.sh.lock" -# - Redirect all further output to the log file +#???????????????????????????????? change the following to lock the log file? + +# - If we can't lock the lock file, don't proceed +if ! exec 9>"${LOCK_FILE}" ; then echo "ERROR - Unable to open the lock file (${LOCK_FILE})! Exiting..." ; exit 10 ; fi +if ! flock -n 9 ; then echo "ERROR - Another copy of ${SCRIPT_NAME} is already running! Exiting..." ; exit 11 ; fi + +# - Append all further STDOUT and STDERR to the log file exec >>"${LOG_FILE}" 2>&1 # - Log that we've gotten this far -echo -n "$(basename "${0}"): $(date "+%Y-%m-%d %H:%M:%S")" - -# - If we can't lock the lock file, don't proceed -exec 9>"${LOCK_FILE}" -if ! flock -n 9 ; then echo " - ERROR - Another copy of ${SCRIPT_NAME} is already running! Exiting..." ; exit 1 ; fi +echo "$(basename "${0}"): $(date "+%Y-%m-%d %H:%M:%S")" # - Do our work -echo -ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}" - +ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}" \ No newline at end of file