diff --git a/bootstrap.yml b/bootstrap.yml index 4dd0517..eb4099b 100644 --- a/bootstrap.yml +++ b/bootstrap.yml @@ -15,10 +15,9 @@ - name: Install bootstrap packages become: true ansible.builtin.apt: - state: present + state: latest pkg: - bash - - curl - python3 - python3-pip - python3-venv @@ -120,6 +119,25 @@ mode: u=rw,go= backup: true + - name: Make sure /etc/skel/.bashrc.d exists + become: true + ansible.builtin.file: + path: /etc/skel/.bashrc.d + state: directory + owner: root + group: root + mode: u=rwx,go= + + - name: Get /etc/skel/.bashrc + become: true + ansible.builtin.copy: + src: etc/skel/.bashrc + dest: /etc/skel/.bashrc + owner: root + group: root + mode: u=rw,go= + backup: true + #### User: root diff --git a/files/etc/skel/.bashrc b/files/etc/skel/.bashrc new file mode 100644 index 0000000..3a4dbbf --- /dev/null +++ b/files/etc/skel/.bashrc @@ -0,0 +1,119 @@ +# ~/.bashrc: executed by bash(1) for non-login shells. +# see /usr/share/doc/bash/examples/startup-files (in the package bash-doc) +# for examples + +# If not running interactively, don't do anything +case $- in + *i*) ;; + *) return;; +esac + +# don't put duplicate lines or lines starting with space in the history. +# See bash(1) for more options +HISTCONTROL=ignoreboth + +# append to the history file, don't overwrite it +shopt -s histappend + +# for setting history length see HISTSIZE and HISTFILESIZE in bash(1) +HISTSIZE=1000 +HISTFILESIZE=2000 + +# check the window size after each command and, if necessary, +# update the values of LINES and COLUMNS. +shopt -s checkwinsize + +# If set, the pattern "**" used in a pathname expansion context will +# match all files and zero or more directories and subdirectories. +#shopt -s globstar + +# make less more friendly for non-text input files, see lesspipe(1) +#[ -x /usr/bin/lesspipe ] && eval "$(SHELL=/bin/sh lesspipe)" + +# set variable identifying the chroot you work in (used in the prompt below) +if [ -z "${debian_chroot:-}" ] && [ -r /etc/debian_chroot ]; then + debian_chroot=$(cat /etc/debian_chroot) +fi + +# set a fancy prompt (non-color, unless we know we "want" color) +case "$TERM" in + xterm-color|*-256color) color_prompt=yes;; +esac + +# uncomment for a colored prompt, if the terminal has the capability; turned +# off by default to not distract the user: the focus in a terminal window +# should be on the output of commands, not on the prompt +#force_color_prompt=yes + +if [ -n "$force_color_prompt" ]; then + if [ -x /usr/bin/tput ] && tput setaf 1 >&/dev/null; then + # We have color support; assume it's compliant with Ecma-48 + # (ISO/IEC-6429). (Lack of such support is extremely rare, and such + # a case would tend to support setf rather than setaf.) + color_prompt=yes + else + color_prompt= + fi +fi + +if [ "$color_prompt" = yes ]; then + PS1='${debian_chroot:+($debian_chroot)}\[\033[01;32m\]\u@\h\[\033[00m\]:\[\033[01;34m\]\w\[\033[00m\]\$ ' +else + PS1='${debian_chroot:+($debian_chroot)}\u@\h:\w\$ ' +fi +unset color_prompt force_color_prompt + +# If this is an xterm set the title to user@host:dir +case "$TERM" in +xterm*|rxvt*) + PS1="\[\e]0;${debian_chroot:+($debian_chroot)}\u@\h: \w\a\]$PS1" + ;; +*) + ;; +esac + +# enable color support of ls and also add handy aliases +if [ -x /usr/bin/dircolors ]; then + test -r ~/.dircolors && eval "$(dircolors -b ~/.dircolors)" || eval "$(dircolors -b)" + alias ls='ls --color=auto' + #alias dir='dir --color=auto' + #alias vdir='vdir --color=auto' + + #alias grep='grep --color=auto' + #alias fgrep='fgrep --color=auto' + #alias egrep='egrep --color=auto' +fi + +# colored GCC warnings and errors +#export GCC_COLORS='error=01;31:warning=01;35:note=01;36:caret=01;32:locus=01:quote=01' + +# some more ls aliases +#alias ll='ls -l' +#alias la='ls -A' +#alias l='ls -CF' + +# Alias definitions. +# You may want to put all your additions into a separate file like +# ~/.bash_aliases, instead of adding them here directly. +# See /usr/share/doc/bash-doc/examples in the bash-doc package. + +if [ -f ~/.bash_aliases ]; then + . ~/.bash_aliases +fi + +# enable programmable completion features (you don't need to enable +# this, if it's already enabled in /etc/bash.bashrc and /etc/profile +# sources /etc/bash.bashrc). +if ! shopt -oq posix; then + if [ -f /usr/share/bash-completion/bash_completion ]; then + . /usr/share/bash-completion/bash_completion + elif [ -f /etc/bash_completion ]; then + . /etc/bash_completion + fi +fi + +if [ -d "$HOME/.bashrc.d" ] ; then + for bashrc_script in $HOME/.bashrc.d/*.sh ; do + . "${bashrc_script}" + done +fi diff --git a/files/etc/skel/.profile b/files/etc/skel/.profile index c43f0ac..c79d88f 100644 --- a/files/etc/skel/.profile +++ b/files/etc/skel/.profile @@ -31,4 +31,3 @@ if [ -d "$HOME/.profile.d" ] ; then . "${profile_script}" done fi - diff --git a/files/home/hpf-ans/bin/get-hpf-facts.sh b/files/home/hpf-ans/bin/get-hpf-facts.sh index bde2303..77e850a 100644 --- a/files/home/hpf-ans/bin/get-hpf-facts.sh +++ b/files/home/hpf-ans/bin/get-hpf-facts.sh @@ -8,6 +8,11 @@ fi ANSIBLE_OS_FAMILY="${1}" shift +if [ "${#}" -ne 0 ] ; then + echo "ERROR - unknown command line parameter specified." >&2 + exit 2 +fi + useradd_D() { case "${ANSIBLE_OS_FAMILY}" in @@ -25,11 +30,10 @@ useradd_D() { } user_vars() { - useradd_D | sed 's/.*=/hpf_fact_\L&/' + useradd_D | sed 's/.*=/\L&/' } -#echo '{"hpf":' -#(user_vars; ) | jo -#echo '}' +( + user_vars +) | jo -user_vars diff --git a/scraps/TODO.txt b/scraps/TODO.txt index 52f3ad1..f974263 100644 --- a/scraps/TODO.txt +++ b/scraps/TODO.txt @@ -1,4 +1,4 @@ - +iris.heath.hpetersenfamily.com admin-a.hpetersenfamily.com core.mary.hpetersenfamily.com heath authorized_keys: @@ -6,8 +6,6 @@ heath password: status: VALID value: COMMON STRONG FOR ALL HOSTS - private_keys: - - FOR WORKSTATIONS: heath@hpetersenfamily.com # Can this even be done securely through Ansible? first authorized_keys: - first@hpetersenfamily.com @@ -15,19 +13,16 @@ first password: status: VALID value: UNIQUE LONG FOR EACH HOST - private_keys: root authorized_keys: - heath@hpetersenfamily.com password: status: LOCKED - private_keys: hpf-ans: authorized_keys: - heath@hpetersenfamily.com password: status: LOCKED - private_keys: # Change to work with multiple distros (nothing hardcoded) diff --git a/scraps/test-get_hpf_facts.yml b/scraps/test-get_hpf_facts.yml index 6894550..6f1a7cd 100644 --- a/scraps/test-get_hpf_facts.yml +++ b/scraps/test-get_hpf_facts.yml @@ -1,34 +1,29 @@ --- -- name: test-get_hpf_facts.yml +- name: test-get-hpf-facts.yml hosts: all tasks: - - name: Copy over get_hpf_facts.sh + - name: Copy over get-hpf-facts.sh ansible.builtin.copy: - src: hpf-ans/bin/get_hpf_facts.sh - dest: bin/get_hpf_facts.sh + src: home/hpf-ans/bin/get-hpf-facts.sh + dest: bin/get-hpf-facts.sh owner: hpf-ans group: hpf-ans mode: u=rwx,go=gx backup: true - - name: Run get_hpf_facts.sh + - name: Run get-hpf-facts.sh ansible.builtin.command: - cmd: bin/get_hpf_facts.sh {{ ansible_facts["os_family"] }} - register: hpf_facts + cmd: bin/get-hpf-facts.sh {{ ansible_facts["os_family"] }} + register: registered_hpf_facts changed_when: false - name: Convert k=v stdout into facts ansible.builtin.set_fact: - "{{ item.split('=', 1)[0] }}": "{{ item.split('=', 1)[1] }}" - loop: "{{ hpf_facts.stdout.splitlines() }}" - - - name: Print all variables - ansible.builtin.debug: - var: hostvars[inventory_hostname] + hpf_facts: "{{ registered_hpf_facts.stdout | from_json }}" - name: Print skel ansible.builtin.debug: - var: hpf_fact_skel + var: hpf_facts.skel