sync bootstrap.yml and bootstrap.sh
This commit is contained in:
+3
-3
@@ -76,7 +76,7 @@ system_groupadd () {
|
|||||||
system_useradd () {
|
system_useradd () {
|
||||||
if user_exists "$1" "$2" ; then return 0 ; fi
|
if user_exists "$1" "$2" ; then return 0 ; fi
|
||||||
system_groupadd "${@}"
|
system_groupadd "${@}"
|
||||||
useradd -r -u "$2" -g "$2" -s /bin/bash -m "$1"
|
useradd -r -u "$2" -g "$2" -s /usr/bin/bash -m "$1"
|
||||||
rc=$?
|
rc=$?
|
||||||
if [ $rc -ne 0 ] ; then
|
if [ $rc -ne 0 ] ; then
|
||||||
echo "ERROR - Unable to add $1 user! ($rc)" >&2
|
echo "ERROR - Unable to add $1 user! ($rc)" >&2
|
||||||
@@ -182,7 +182,7 @@ get_file "${GIT_REPO_sudoers_d_hpf}" "${ETC_sudoers_d_hpf}" "root:root" "u=rw,go
|
|||||||
create_directory "${SKEL_profile_d}" "root:root" "u=rwx,go="
|
create_directory "${SKEL_profile_d}" "root:root" "u=rwx,go="
|
||||||
|
|
||||||
# Get /etc/skel/.profile.d/ansible-venv.sh
|
# Get /etc/skel/.profile.d/ansible-venv.sh
|
||||||
get_file "${GIT_REPO_SKEL_ansible_venv_sh}" "${SKEL_ansible_venv_sh}" "root:root" "u=rwx,go="
|
get_file "${GIT_REPO_SKEL_ansible_venv_sh}" "${SKEL_ansible_venv_sh}" "root:root" "u=rw,go="
|
||||||
|
|
||||||
# Get /etc/skel/.profile
|
# Get /etc/skel/.profile
|
||||||
get_file "${GIT_REPO_SKEL_profile}" "${SKEL_profile}" "root:root" "u=rw,go=r"
|
get_file "${GIT_REPO_SKEL_profile}" "${SKEL_profile}" "root:root" "u=rw,go=r"
|
||||||
@@ -203,7 +203,7 @@ as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_AN
|
|||||||
# Make sure pip is up to date
|
# Make sure pip is up to date
|
||||||
as_hpf_ans "pip install --upgrade pip"
|
as_hpf_ans "pip install --upgrade pip"
|
||||||
|
|
||||||
# Make sure ansible is installed
|
# Make sure ansible is up to date
|
||||||
as_hpf_ans "pip install --upgrade ansible"
|
as_hpf_ans "pip install --upgrade ansible"
|
||||||
|
|
||||||
# Make sure /home/hpf-ans/bin exists
|
# Make sure /home/hpf-ans/bin exists
|
||||||
|
|||||||
+44
-30
@@ -21,11 +21,16 @@
|
|||||||
# Update software repositories here
|
# Update software repositories here
|
||||||
# Change the following to work with multiple distros
|
# Change the following to work with multiple distros
|
||||||
|
|
||||||
- name: bootstrap
|
- name: bootstrap.yml
|
||||||
hosts: all
|
hosts: all
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
|
|
||||||
|
- name: Update repositories
|
||||||
|
ansible.builtin.apt:
|
||||||
|
become: yes
|
||||||
|
update_cache: yes
|
||||||
|
|
||||||
- name: Install bootstrap packages
|
- name: Install bootstrap packages
|
||||||
ansible.builtin.apt:
|
ansible.builtin.apt:
|
||||||
become: yes
|
become: yes
|
||||||
@@ -38,7 +43,7 @@
|
|||||||
- python3-venv
|
- python3-venv
|
||||||
- python3-virtualenv
|
- python3-virtualenv
|
||||||
|
|
||||||
- name: Make sure hpf-sudo group exists
|
- name: Create system group hpf-sudo for normal sudo users
|
||||||
ansible.builtin.group:
|
ansible.builtin.group:
|
||||||
become: yes
|
become: yes
|
||||||
name: hpf-sudo
|
name: hpf-sudo
|
||||||
@@ -46,7 +51,7 @@
|
|||||||
system: true
|
system: true
|
||||||
gid: 700
|
gid: 700
|
||||||
|
|
||||||
- name: Make sure hpf-sudo-np group exists
|
- name: Create system group hpf-sudo-np for special sudo users that don't require a password
|
||||||
ansible.builtin.group:
|
ansible.builtin.group:
|
||||||
become: yes
|
become: yes
|
||||||
name: hpf-sudo-np
|
name: hpf-sudo-np
|
||||||
@@ -54,10 +59,19 @@
|
|||||||
system: true
|
system: true
|
||||||
gid: 701
|
gid: 701
|
||||||
|
|
||||||
- name: Copy over /etc/sudoers.d/hpf
|
- name: Make sure /etc/sudoers.d exists
|
||||||
|
ansible.builtin.file:
|
||||||
|
become: yes
|
||||||
|
path: /etc/sudoers.d
|
||||||
|
state: directory
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: u=rwx,go=
|
||||||
|
|
||||||
|
- name: Get /etc/sudoers.d/hpf
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
become: yes
|
become: yes
|
||||||
src: etc_sudoers_d_hpf
|
src: etc/sudoers.d/hpf
|
||||||
dest: /etc/sudoers.d/hpf
|
dest: /etc/sudoers.d/hpf
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
@@ -65,36 +79,36 @@
|
|||||||
backup: true
|
backup: true
|
||||||
validate: /usr/sbin/visudo -csf %s
|
validate: /usr/sbin/visudo -csf %s
|
||||||
|
|
||||||
|
- name: Make sure /etc/skel/.profile.d exists
|
||||||
#### .profile.d should be in SKEL directory - look it up
|
|
||||||
|
|
||||||
- name: Make sure .profile.d directory exists
|
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
become: true
|
become: yes
|
||||||
path: /etc/skel/.profile.d
|
path: /etc/skel/.profile.d
|
||||||
state: directory
|
state: directory
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: u=rwx,go=
|
mode: u=rwx,go=
|
||||||
|
|
||||||
|
- name: Get /etc/skel/.profile.d/ansible-venv.sh
|
||||||
#### ansible-venv.sh should be in SKEL directory - look it up
|
|
||||||
|
|
||||||
- name: Copy over ansible-venv.sh
|
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
become: true
|
become: yes
|
||||||
src: profile_d_ansible_venv_sh
|
src: etc/skel/.profile.d/ansible-venv.sh
|
||||||
dest: /etc/skel/.profile.d/ansible-pull.sh
|
dest: /etc/skel/.profile.d/ansible-venv.sh
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: u=rwx,go=
|
mode: u=rw,go=
|
||||||
backup: true
|
backup: true
|
||||||
|
|
||||||
|
- name: Get /etc/skel/.profile
|
||||||
|
ansible.builtin.copy:
|
||||||
|
become: yes
|
||||||
|
src: etc/skel/.profile
|
||||||
|
dest: /etc/skel/.profile
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: u=rw,go=
|
||||||
|
backup: true
|
||||||
|
|
||||||
#### .profile
|
- name: Create the hpf-ans group
|
||||||
|
|
||||||
|
|
||||||
- name: Make sure hpf-ans group exists
|
|
||||||
ansible.builtin.group:
|
ansible.builtin.group:
|
||||||
become: yes
|
become: yes
|
||||||
name: hpf-ans
|
name: hpf-ans
|
||||||
@@ -102,7 +116,7 @@
|
|||||||
system: true
|
system: true
|
||||||
gid: 800
|
gid: 800
|
||||||
|
|
||||||
- name: Make sure hpf-ans user exists
|
- name: Create the hpf-ans user
|
||||||
ansible.builtin.user:
|
ansible.builtin.user:
|
||||||
become: yes
|
become: yes
|
||||||
name: hpf-ans
|
name: hpf-ans
|
||||||
@@ -113,21 +127,21 @@
|
|||||||
groups: hpf-sudo-np
|
groups: hpf-sudo-np
|
||||||
append: yes
|
append: yes
|
||||||
create_home: true
|
create_home: true
|
||||||
shell: /bin/bash
|
shell: /usr/bin/bash
|
||||||
|
|
||||||
- name: Install latest version of pip in .ansible-venv
|
- name: Make sure pip is up to date
|
||||||
ansible.builtin.pip:
|
ansible.builtin.pip:
|
||||||
name: pip
|
name: pip
|
||||||
virtualenv: $HOME/.ansible-venv
|
virtualenv: $HOME/.ansible-venv
|
||||||
extra_args: --upgrade
|
extra_args: --upgrade
|
||||||
|
|
||||||
- name: Install latest version of ansible in .ansible-venv
|
- name: Make sure ansible is up to date
|
||||||
ansible.builtin.pip:
|
ansible.builtin.pip:
|
||||||
name: ansible
|
name: ansible
|
||||||
virtualenv: $HOME/.ansible-venv
|
virtualenv: $HOME/.ansible-venv
|
||||||
extra_args: "--upgrade"
|
extra_args: --upgrade
|
||||||
|
|
||||||
- name: Make sure bin directory exists
|
- name: Make sure /home/hpf-ans/bin exists
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
path: $HOME/bin
|
path: $HOME/bin
|
||||||
state: directory
|
state: directory
|
||||||
@@ -135,9 +149,9 @@
|
|||||||
group: hpf-ans
|
group: hpf-ans
|
||||||
mode: u=rwx,go=
|
mode: u=rwx,go=
|
||||||
|
|
||||||
- name: Copy over bin/ansible-pull.sh
|
- name: Get /home/hpf-ans/bin/ansible-pull.sh
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
src: home_hpf_ans_bin_ansible_pull_sh
|
src: home/hpf_ans/bin/ansible-pull.sh
|
||||||
dest: $HOME/bin/ansible-pull.sh
|
dest: $HOME/bin/ansible-pull.sh
|
||||||
owner: hpf-ans
|
owner: hpf-ans
|
||||||
group: hpf-ans
|
group: hpf-ans
|
||||||
|
|||||||
Reference in New Issue
Block a user