preparing to schedule ansible-pull.sh
This commit is contained in:
+25
-26
@@ -1,22 +1,4 @@
|
|||||||
---
|
---
|
||||||
|
|
||||||
####
|
|
||||||
#### WARNING:
|
|
||||||
####
|
|
||||||
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
|
|
||||||
#### exact same things with the following exceptions:
|
|
||||||
####
|
|
||||||
#### * bootstrap.sh
|
|
||||||
#### - at the end it should run ansible-pull.sh against bootstrap.yml
|
|
||||||
####
|
|
||||||
#### * bootstrap.yml
|
|
||||||
#### - at the end it should configure cron to schedule ansible-pull.sh
|
|
||||||
####
|
|
||||||
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
|
||||||
#### ! Make sure to keep them in sync !
|
|
||||||
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
|
||||||
####
|
|
||||||
|
|
||||||
- name: Bootstrap playbook
|
- name: Bootstrap playbook
|
||||||
hosts: all
|
hosts: all
|
||||||
|
|
||||||
@@ -41,6 +23,7 @@
|
|||||||
- python3-pip
|
- python3-pip
|
||||||
- python3-venv
|
- python3-venv
|
||||||
- python3-virtualenv
|
- python3-virtualenv
|
||||||
|
- logrotate
|
||||||
|
|
||||||
|
|
||||||
#### Configure sudo
|
#### Configure sudo
|
||||||
@@ -276,7 +259,7 @@
|
|||||||
key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}"
|
key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}"
|
||||||
|
|
||||||
|
|
||||||
#### Schedule ansible-pull.sh
|
#### ansible-pull.sh
|
||||||
|
|
||||||
- name: Make sure log directory exists
|
- name: Make sure log directory exists
|
||||||
become: true
|
become: true
|
||||||
@@ -287,13 +270,29 @@
|
|||||||
group: root
|
group: root
|
||||||
mode: u=rwx,go=
|
mode: u=rwx,go=
|
||||||
|
|
||||||
# - name: Create ansible-pull.sh crontab entry
|
# - name: Create ansible-pull.sh crontab entry
|
||||||
# become: true
|
# become: true
|
||||||
# ansible.builtin.cron:
|
# become_user: hpf-ans
|
||||||
# name: "ansible-pull"
|
# ansible.builtin.cron:
|
||||||
# minute: "*/27"
|
# name: "ansible-pull"
|
||||||
# job: $HOME/bin/ansible-pull.sh
|
# minute: "*/27"
|
||||||
# backup: true
|
# job: $HOME/bin/ansible-pull.sh
|
||||||
|
# backup: true
|
||||||
|
|
||||||
|
- name: Rotate ansible-pull.sh.log
|
||||||
|
become: true
|
||||||
|
community.general.logrotate:
|
||||||
|
name: ansible-pull.sh
|
||||||
|
paths:
|
||||||
|
- /var/log/ansible-pull.sh/*.log
|
||||||
|
rotation_period: daily
|
||||||
|
rotate_count: 32
|
||||||
|
compress: true
|
||||||
|
compress_options: "-9"
|
||||||
|
delay_compress: true
|
||||||
|
missing_ok: true
|
||||||
|
not_if_empty: true
|
||||||
|
backup: true
|
||||||
|
|
||||||
|
|
||||||
#### Clean System Software
|
#### Clean System Software
|
||||||
|
|||||||
@@ -1,4 +1,4 @@
|
|||||||
#!/bin/bash
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
# - Process command line
|
# - Process command line
|
||||||
GIT_REPO_BRANCH="production"
|
GIT_REPO_BRANCH="production"
|
||||||
@@ -14,10 +14,18 @@ while [ $# -gt 0 ]; do
|
|||||||
GIT_REPO_BRANCH="$1"
|
GIT_REPO_BRANCH="$1"
|
||||||
shift 1
|
shift 1
|
||||||
;;
|
;;
|
||||||
|
--)
|
||||||
|
shift 1
|
||||||
|
break
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
echo "$0: ERROR - Invalid argument." ; exit 2
|
||||||
|
;;
|
||||||
esac
|
esac
|
||||||
done
|
done
|
||||||
|
|
||||||
# - Include ansible virtual environment
|
# - Include ansible virtual environment (in case not already done - we don't know how we're being run)
|
||||||
|
VIRTUAL_ENV_DISABLE_PROMPT=true
|
||||||
. "${HOME}/.ansible-venv/bin/activate"
|
. "${HOME}/.ansible-venv/bin/activate"
|
||||||
|
|
||||||
SCRIPT_NAME="$(basename "${0}")"
|
SCRIPT_NAME="$(basename "${0}")"
|
||||||
@@ -27,17 +35,17 @@ LOG_DIR="/var/log/ansible-pull.sh"
|
|||||||
LOG_FILE="${LOG_DIR}/ansible-pull.sh.log"
|
LOG_FILE="${LOG_DIR}/ansible-pull.sh.log"
|
||||||
LOCK_FILE="/tmp/ansible-pull.sh.lock"
|
LOCK_FILE="/tmp/ansible-pull.sh.lock"
|
||||||
|
|
||||||
# - Redirect all further output to the log file
|
#???????????????????????????????? change the following to lock the log file?
|
||||||
|
|
||||||
|
# - If we can't lock the lock file, don't proceed
|
||||||
|
if ! exec 9>"${LOCK_FILE}" ; then echo "ERROR - Unable to open the lock file (${LOCK_FILE})! Exiting..." ; exit 10 ; fi
|
||||||
|
if ! flock -n 9 ; then echo "ERROR - Another copy of ${SCRIPT_NAME} is already running! Exiting..." ; exit 11 ; fi
|
||||||
|
|
||||||
|
# - Append all further STDOUT and STDERR to the log file
|
||||||
exec >>"${LOG_FILE}" 2>&1
|
exec >>"${LOG_FILE}" 2>&1
|
||||||
|
|
||||||
# - Log that we've gotten this far
|
# - Log that we've gotten this far
|
||||||
echo -n "$(basename "${0}"): $(date "+%Y-%m-%d %H:%M:%S")"
|
echo "$(basename "${0}"): $(date "+%Y-%m-%d %H:%M:%S")"
|
||||||
|
|
||||||
# - If we can't lock the lock file, don't proceed
|
|
||||||
exec 9>"${LOCK_FILE}"
|
|
||||||
if ! flock -n 9 ; then echo " - ERROR - Another copy of ${SCRIPT_NAME} is already running! Exiting..." ; exit 1 ; fi
|
|
||||||
|
|
||||||
# - Do our work
|
# - Do our work
|
||||||
echo
|
|
||||||
ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}"
|
ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}"
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user