cleanup
This commit is contained in:
+30
-7
@@ -25,11 +25,23 @@
|
||||
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||
GIT_REPO_BRANCH="${1:-"production"}"
|
||||
GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files/sudoers_d_hpf"
|
||||
GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files/ansible_pull_sh"
|
||||
|
||||
GIT_REPO_FILES="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files"
|
||||
|
||||
GIT_REPO_sudoers_d_hpf="${GIT_REPO_FILES}/sudoers_d_hpf"
|
||||
GIT_REPO_profile_d_ansible_venv_sh="${GIT_REPO_FILES}/profile_d_ansible_venv_sh"
|
||||
GIT_REPO_profile_append="${GIT_REPO_FILES}/profile_append"
|
||||
GIT_REPO_ansible_pull_sh="${GIT_REPO_FILES}/ansible_pull_sh"
|
||||
|
||||
ETC_sudoers_d_hpf="/etc/sudoers.d/hpf"
|
||||
|
||||
unset SKEL
|
||||
if [ -r /etc/default/useradd ] ; then . /etc/default/useradd ; fi
|
||||
SKEL="${SKEL:-/etc/skel}"
|
||||
SKEL_profile_d="${SKEL}/.profile.d"
|
||||
SKEL_ansible_venv_sh="${SKEL_profile_d}/ansible-venv.sh"
|
||||
SKEL_profile="${SKEL}/.profile"
|
||||
|
||||
HPF_ANS_ansible_venv="\${HOME}/.ansible-venv"
|
||||
HPF_ANS_activate="${HPF_ANS_ansible_venv}/bin/activate"
|
||||
|
||||
@@ -88,7 +100,8 @@ add_groups_to_user () {
|
||||
|
||||
# $command_line
|
||||
as_hpf_ans () {
|
||||
su --login hpf-ans --command "if [ -r \"${HPF_ANS_activate}\" ] ; then source \"${HPF_ANS_activate}\" ; fi ; ${1}"
|
||||
#su --login hpf-ans --command "if [ -r \"${HPF_ANS_activate}\" ] ; then source \"${HPF_ANS_activate}\" ; fi ; ${1}"
|
||||
su --login hpf-ans --command "${1}"
|
||||
}
|
||||
|
||||
|
||||
@@ -119,10 +132,20 @@ system_groupadd hpf-sudo-np 701
|
||||
|
||||
# Create /etc/sudoers.d/hpf to allow common sudo permissions
|
||||
rm "${ETC_sudoers_d_hpf}" 2>/dev/null
|
||||
curl -o "$ETC_sudoers_d_hpf" "${GIT_REPO_sudoers_d_hpf}"
|
||||
chown root:root "${ETC_sudoers_d_hpf}"
|
||||
chmod u=rw,go= "${ETC_sudoers_d_hpf}"
|
||||
curl -o "${ETC_sudoers_d_hpf}" "${GIT_REPO_sudoers_d_hpf}"
|
||||
chown root:root "${ETC_sudoers_d_hpf}"; chmod u=rw,go= "${ETC_sudoers_d_hpf}"
|
||||
|
||||
# Make sure .profile.d exists
|
||||
mkdir -p "${SKEL_profile_d}\""
|
||||
as_hpf_ans "chown root:root \"${SKEL_profile_d}\"; chmod u=rwx,go= \"${SKEL_profile_d}\""
|
||||
|
||||
# Create ansible-venv.sh
|
||||
if [ ! -r "${SKEL_ansible_venv_sh}" ] ; then
|
||||
curl -o "${SKEL_ansible_venv_sh}" "${GIT_REPO_ansible_venv_sh}"
|
||||
chown root:root "${SKEL_ansible_venv_sh}"; chmod u=rwx,go= "${SKEL_ansible_venv_sh}"
|
||||
curl "${GIT_REPO_profile_append}" >>"${SKEL_profile}"
|
||||
fi
|
||||
exit 255
|
||||
# Create the hpf-ans user
|
||||
system_useradd hpf-ans 800
|
||||
add_groups_to_user hpf-sudo-np hpf-ans
|
||||
@@ -140,7 +163,7 @@ as_hpf_ans "pip install --upgrade ansible"
|
||||
as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\""
|
||||
|
||||
# Create ~hpf-ans/bin/ansible-pull.sh
|
||||
# Create ansible-pull.sh
|
||||
as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null"
|
||||
as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\""
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
ANSIBLE_ACTIVATE="${HOME}/.ansible-venv/bin/activate"
|
||||
|
||||
if [ -r "${ANSIBLE_ACTIVATE}" ] ; then
|
||||
VIRTUAL_ENV_DISABLE_PROMPT=true
|
||||
. "${ANSIBLE_ACTIVATE}"
|
||||
fi
|
||||
Reference in New Issue
Block a user