diff --git a/bootstrap.sh b/bootstrap.sh index 96ec1f5..1cfc70a 100644 --- a/bootstrap.sh +++ b/bootstrap.sh @@ -76,7 +76,7 @@ system_groupadd () { system_useradd () { if user_exists "$1" "$2" ; then return 0 ; fi system_groupadd "${@}" - useradd -r -u "$2" -g "$2" -s /bin/bash -m "$1" + useradd -r -u "$2" -g "$2" -s /usr/bin/bash -m "$1" rc=$? if [ $rc -ne 0 ] ; then echo "ERROR - Unable to add $1 user! ($rc)" >&2 @@ -182,7 +182,7 @@ get_file "${GIT_REPO_sudoers_d_hpf}" "${ETC_sudoers_d_hpf}" "root:root" "u=rw,go create_directory "${SKEL_profile_d}" "root:root" "u=rwx,go=" # Get /etc/skel/.profile.d/ansible-venv.sh -get_file "${GIT_REPO_SKEL_ansible_venv_sh}" "${SKEL_ansible_venv_sh}" "root:root" "u=rwx,go=" +get_file "${GIT_REPO_SKEL_ansible_venv_sh}" "${SKEL_ansible_venv_sh}" "root:root" "u=rw,go=" # Get /etc/skel/.profile get_file "${GIT_REPO_SKEL_profile}" "${SKEL_profile}" "root:root" "u=rw,go=r" @@ -203,7 +203,7 @@ as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_AN # Make sure pip is up to date as_hpf_ans "pip install --upgrade pip" -# Make sure ansible is installed +# Make sure ansible is up to date as_hpf_ans "pip install --upgrade ansible" # Make sure /home/hpf-ans/bin exists diff --git a/bootstrap.yml b/bootstrap.yml index 1bab937..827d8a3 100644 --- a/bootstrap.yml +++ b/bootstrap.yml @@ -21,11 +21,16 @@ # Update software repositories here # Change the following to work with multiple distros -- name: bootstrap +- name: bootstrap.yml hosts: all tasks: + - name: Update repositories + ansible.builtin.apt: + become: yes + update_cache: yes + - name: Install bootstrap packages ansible.builtin.apt: become: yes @@ -38,7 +43,7 @@ - python3-venv - python3-virtualenv - - name: Make sure hpf-sudo group exists + - name: Create system group hpf-sudo for normal sudo users ansible.builtin.group: become: yes name: hpf-sudo @@ -46,7 +51,7 @@ system: true gid: 700 - - name: Make sure hpf-sudo-np group exists + - name: Create system group hpf-sudo-np for special sudo users that don't require a password ansible.builtin.group: become: yes name: hpf-sudo-np @@ -54,10 +59,19 @@ system: true gid: 701 - - name: Copy over /etc/sudoers.d/hpf + - name: Make sure /etc/sudoers.d exists + ansible.builtin.file: + become: yes + path: /etc/sudoers.d + state: directory + owner: root + group: root + mode: u=rwx,go= + + - name: Get /etc/sudoers.d/hpf ansible.builtin.copy: become: yes - src: etc_sudoers_d_hpf + src: etc/sudoers.d/hpf dest: /etc/sudoers.d/hpf owner: root group: root @@ -65,36 +79,36 @@ backup: true validate: /usr/sbin/visudo -csf %s - -#### .profile.d should be in SKEL directory - look it up - - - name: Make sure .profile.d directory exists + - name: Make sure /etc/skel/.profile.d exists ansible.builtin.file: - become: true + become: yes path: /etc/skel/.profile.d state: directory owner: root group: root mode: u=rwx,go= - -#### ansible-venv.sh should be in SKEL directory - look it up - - - name: Copy over ansible-venv.sh + - name: Get /etc/skel/.profile.d/ansible-venv.sh ansible.builtin.copy: - become: true - src: profile_d_ansible_venv_sh - dest: /etc/skel/.profile.d/ansible-pull.sh + become: yes + src: etc/skel/.profile.d/ansible-venv.sh + dest: /etc/skel/.profile.d/ansible-venv.sh owner: root group: root - mode: u=rwx,go= + mode: u=rw,go= backup: true + - name: Get /etc/skel/.profile + ansible.builtin.copy: + become: yes + src: etc/skel/.profile + dest: /etc/skel/.profile + owner: root + group: root + mode: u=rw,go= + backup: true -#### .profile - - - - name: Make sure hpf-ans group exists + - name: Create the hpf-ans group ansible.builtin.group: become: yes name: hpf-ans @@ -102,7 +116,7 @@ system: true gid: 800 - - name: Make sure hpf-ans user exists + - name: Create the hpf-ans user ansible.builtin.user: become: yes name: hpf-ans @@ -113,21 +127,21 @@ groups: hpf-sudo-np append: yes create_home: true - shell: /bin/bash + shell: /usr/bin/bash - - name: Install latest version of pip in .ansible-venv + - name: Make sure pip is up to date ansible.builtin.pip: name: pip virtualenv: $HOME/.ansible-venv extra_args: --upgrade - - name: Install latest version of ansible in .ansible-venv + - name: Make sure ansible is up to date ansible.builtin.pip: name: ansible virtualenv: $HOME/.ansible-venv - extra_args: "--upgrade" + extra_args: --upgrade - - name: Make sure bin directory exists + - name: Make sure /home/hpf-ans/bin exists ansible.builtin.file: path: $HOME/bin state: directory @@ -135,9 +149,9 @@ group: hpf-ans mode: u=rwx,go= - - name: Copy over bin/ansible-pull.sh + - name: Get /home/hpf-ans/bin/ansible-pull.sh ansible.builtin.copy: - src: home_hpf_ans_bin_ansible_pull_sh + src: home/hpf_ans/bin/ansible-pull.sh dest: $HOME/bin/ansible-pull.sh owner: hpf-ans group: hpf-ans