preparing to schedule ansible-pull.sh

This commit is contained in:
2026-07-26 12:03:03 -05:00
parent e1592fca85
commit 8b50cacb1b
2 changed files with 44 additions and 37 deletions
+25 -26
View File
@@ -1,22 +1,4 @@
--- ---
####
#### WARNING:
####
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
#### exact same things with the following exceptions:
####
#### * bootstrap.sh
#### - at the end it should run ansible-pull.sh against bootstrap.yml
####
#### * bootstrap.yml
#### - at the end it should configure cron to schedule ansible-pull.sh
####
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
#### ! Make sure to keep them in sync !
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
####
- name: Bootstrap playbook - name: Bootstrap playbook
hosts: all hosts: all
@@ -41,6 +23,7 @@
- python3-pip - python3-pip
- python3-venv - python3-venv
- python3-virtualenv - python3-virtualenv
- logrotate
#### Configure sudo #### Configure sudo
@@ -276,7 +259,7 @@
key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}" key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}"
#### Schedule ansible-pull.sh #### ansible-pull.sh
- name: Make sure log directory exists - name: Make sure log directory exists
become: true become: true
@@ -287,13 +270,29 @@
group: root group: root
mode: u=rwx,go= mode: u=rwx,go=
# - name: Create ansible-pull.sh crontab entry # - name: Create ansible-pull.sh crontab entry
# become: true # become: true
# ansible.builtin.cron: # become_user: hpf-ans
# name: "ansible-pull" # ansible.builtin.cron:
# minute: "*/27" # name: "ansible-pull"
# job: $HOME/bin/ansible-pull.sh # minute: "*/27"
# backup: true # job: $HOME/bin/ansible-pull.sh
# backup: true
- name: Rotate ansible-pull.sh.log
become: true
community.general.logrotate:
name: ansible-pull.sh
paths:
- /var/log/ansible-pull.sh/*.log
rotation_period: daily
rotate_count: 32
compress: true
compress_options: "-9"
delay_compress: true
missing_ok: true
not_if_empty: true
backup: true
#### Clean System Software #### Clean System Software
+18 -10
View File
@@ -1,4 +1,4 @@
#!/bin/bash #!/usr/bin/env bash
# - Process command line # - Process command line
GIT_REPO_BRANCH="production" GIT_REPO_BRANCH="production"
@@ -14,10 +14,18 @@ while [ $# -gt 0 ]; do
GIT_REPO_BRANCH="$1" GIT_REPO_BRANCH="$1"
shift 1 shift 1
;; ;;
--)
shift 1
break
;;
*)
echo "$0: ERROR - Invalid argument." ; exit 2
;;
esac esac
done done
# - Include ansible virtual environment # - Include ansible virtual environment (in case not already done - we don't know how we're being run)
VIRTUAL_ENV_DISABLE_PROMPT=true
. "${HOME}/.ansible-venv/bin/activate" . "${HOME}/.ansible-venv/bin/activate"
SCRIPT_NAME="$(basename "${0}")" SCRIPT_NAME="$(basename "${0}")"
@@ -27,17 +35,17 @@ LOG_DIR="/var/log/ansible-pull.sh"
LOG_FILE="${LOG_DIR}/ansible-pull.sh.log" LOG_FILE="${LOG_DIR}/ansible-pull.sh.log"
LOCK_FILE="/tmp/ansible-pull.sh.lock" LOCK_FILE="/tmp/ansible-pull.sh.lock"
# - Redirect all further output to the log file #???????????????????????????????? change the following to lock the log file?
# - If we can't lock the lock file, don't proceed
if ! exec 9>"${LOCK_FILE}" ; then echo "ERROR - Unable to open the lock file (${LOCK_FILE})! Exiting..." ; exit 10 ; fi
if ! flock -n 9 ; then echo "ERROR - Another copy of ${SCRIPT_NAME} is already running! Exiting..." ; exit 11 ; fi
# - Append all further STDOUT and STDERR to the log file
exec >>"${LOG_FILE}" 2>&1 exec >>"${LOG_FILE}" 2>&1
# - Log that we've gotten this far # - Log that we've gotten this far
echo -n "$(basename "${0}"): $(date "+%Y-%m-%d %H:%M:%S")" echo "$(basename "${0}"): $(date "+%Y-%m-%d %H:%M:%S")"
# - If we can't lock the lock file, don't proceed
exec 9>"${LOCK_FILE}"
if ! flock -n 9 ; then echo " - ERROR - Another copy of ${SCRIPT_NAME} is already running! Exiting..." ; exit 1 ; fi
# - Do our work # - Do our work
echo
ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}" ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}"