diff --git a/bootstrap.yml b/bootstrap.yml index c4b08ff..5481a88 100644 --- a/bootstrap.yml +++ b/bootstrap.yml @@ -17,15 +17,14 @@ #### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! #### - -# Update software repositories here -# Change the following to work with multiple distros - - name: bootstrap.yml hosts: all tasks: + +#### System Software + - name: Update repositories become: true ansible.builtin.apt: @@ -43,6 +42,9 @@ - python3-venv - python3-virtualenv + +#### Configure sudo + - name: Create system group hpf-sudo for normal sudo users become: true ansible.builtin.group: @@ -79,6 +81,9 @@ backup: true validate: /usr/sbin/visudo -csf %s + +#### Configure sshd + ## New - name: Make sure /etc/ssh/sshd_config.d exists become: true @@ -102,6 +107,9 @@ validate: /usr/sbin/sshd -t -f %s notify: Restart sshd + +#### Configure /etc/skel + - name: Make sure /etc/skel/.profile.d exists become: true ansible.builtin.file: @@ -131,6 +139,19 @@ mode: u=rw,go= backup: true + +#### User: root + + - name: Set root's authorized_keys + become: true + ansible.posix.authorized_key: + user: root + state: present + key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}" + + +#### User: hpf-ans + - name: Create the hpf-ans group become: true ansible.builtin.group: @@ -152,6 +173,16 @@ create_home: true shell: /usr/bin/bash + - name: Set hpf-ans's authorized_keys + become: true + ansible.posix.authorized_key: + user: hpf-ans + state: present + key: "{{ lookup('file', item) }}" + loop: + - files/ssh-keys/hpf-ans.pub + - files/ssh-keys/heath.pub + - name: Make sure pip is up to date become: true become_user: hpf-ans @@ -189,48 +220,9 @@ mode: u=rwx,go= backup: true - - name: Make sure log directory exists - become: true - ansible.builtin.file: - path: /var/log/ansible-pull.sh - state: directory - owner: hpf-ans - group: root - mode: u=rwx,go= - - name: Remove packages installed as dependencies that are no longer required and purge their configuration files - become: true - ansible.builtin.apt: - autoremove: yes - purge: true +#### User: first - - name: Remove old downloaded packages - become: true - ansible.builtin.apt: - clean: yes - changed_when: false - -## New - - name: Set root's authorized_keys - become: true - ansible.posix.authorized_key: - user: root - state: present - key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}" - -## New - - name: Set hpf-ans's authorized_keys - become: true - ansible.posix.authorized_key: - user: hpf-ans - state: present - key: "{{ lookup('file', item) }}" - loop: - - files/ssh-keys/hpf-ans.pub - - files/ssh-keys/heath.pub - - -## New - name: Set first's authorized_keys become: true ansible.posix.authorized_key: @@ -241,7 +233,9 @@ - files/ssh-keys/first.pub - files/ssh-keys/heath.pub -## New + +#### User: heath + - name: Set heath's authorized_keys become: true ansible.posix.authorized_key: @@ -249,6 +243,18 @@ state: present key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}" + +#### Schedule ansible-pull.sh + + - name: Make sure log directory exists + become: true + ansible.builtin.file: + path: /var/log/ansible-pull.sh + state: directory + owner: hpf-ans + group: root + mode: u=rwx,go= + # - name: Create ansible-pull.sh crontab entry # become: true # ansible.builtin.cron: @@ -257,6 +263,24 @@ # job: $HOME/bin/ansible-pull.sh # backup: true + +#### Clean System Software + + - name: Remove packages installed as dependencies that are no longer required and purge their configuration files + become: true + ansible.builtin.apt: + autoremove: yes + purge: true + + - name: Remove old downloaded packages + become: true + ansible.builtin.apt: + autoclean: yes +# changed_when: false + + +#### Handlers + handlers: - name: Restart sshd diff --git a/scraps/TODO.txt b/scraps/TODO.txt index 8a5050b..b8b0dad 100644 --- a/scraps/TODO.txt +++ b/scraps/TODO.txt @@ -11,13 +11,14 @@ x hpf-ans * member of hpf-sudo x authorized_keys = first, heath * heath - * normal user + * normal user w/ special number * /usr/bin/bash * member of hpf-sudo x authorized_keys = heath +# Change the following to work with multiple distros (nothing hardcoded) * create production, development branches