Compare commits
19 Commits
0502c4f766
...
main
| Author | SHA256 | Date | |
|---|---|---|---|
| cccc72cd6f | |||
| 3067b21276 | |||
| 19f79cd518 | |||
| 6a5089eb01 | |||
| 08b7af2bef | |||
| 4431f86464 | |||
| 01c537343c | |||
| c421d990aa | |||
| 0d943ef1cd | |||
| 1db51f6057 | |||
| 7db15a06b5 | |||
| 2f0f64871f | |||
| 3cf63e3966 | |||
| accb444ad6 | |||
| d46ebceabe | |||
| c778125cb1 | |||
| 0177a6df37 | |||
| 3a6818e9d1 | |||
| fe974643ae |
+31
-8
@@ -1,5 +1,22 @@
|
||||
#!/bin/sh
|
||||
|
||||
####
|
||||
#### WARNING:
|
||||
####
|
||||
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
|
||||
#### exact same things with the following exceptions:
|
||||
####
|
||||
#### * bootstrap.sh
|
||||
#### - at the end it should run ansible-pull.sh against bootstrap.yml
|
||||
####
|
||||
#### * bootstrap.yml
|
||||
#### - at the end it should configure cron to schedule ansible-pull.sh
|
||||
####
|
||||
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||
#### ! Make sure to keep them in sync !
|
||||
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||
####
|
||||
|
||||
|
||||
#
|
||||
#### VARIABLES
|
||||
@@ -7,8 +24,8 @@
|
||||
|
||||
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||
GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/etc_sudoers_d_hpf"
|
||||
GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/home_hpf_ans_bin_ansible-pull.sh"
|
||||
GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/files/etc_sudoers_d_hpf"
|
||||
GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/files/home_hpf_ans_bin_ansible_pull_sh"
|
||||
|
||||
|
||||
ETC_sudoers_d_hpf="/etc/sudoers.d/hpf"
|
||||
@@ -19,6 +36,8 @@ HPF_ANS_activate="${HPF_ANS_ansible_venv}/bin/activate"
|
||||
HPF_ANS_bin="\${HOME}/bin"
|
||||
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
|
||||
|
||||
ANSIBLE_PULL_SH_LOG_DIR="/var/log/ansible-pull.sh"
|
||||
|
||||
|
||||
#
|
||||
#### FUNCTIONS
|
||||
@@ -86,7 +105,7 @@ fi
|
||||
# Install minimal necessary packages
|
||||
if which -s apt ; then
|
||||
apt update
|
||||
apt install bash curl python3 python3-pip python3-venv -y
|
||||
apt install bash curl python3 python3-pip python3-venv python3-virtualenv -y
|
||||
else
|
||||
echo "ERROR - Unable to determine how to install packages" >&2
|
||||
exit 101
|
||||
@@ -102,14 +121,14 @@ system_groupadd hpf-sudo-np 701
|
||||
rm "${ETC_sudoers_d_hpf}" 2>/dev/null
|
||||
curl -o "$ETC_sudoers_d_hpf" "${GIT_REPO_sudoers_d_hpf}"
|
||||
chown root:root "${ETC_sudoers_d_hpf}"
|
||||
chmod u=rw,g=r,o= "${ETC_sudoers_d_hpf}"
|
||||
chmod u=rw,go= "${ETC_sudoers_d_hpf}"
|
||||
|
||||
# Create the hpf-ans user
|
||||
system_useradd hpf-ans 800
|
||||
add_groups_to_user hpf-sudo-np hpf-ans
|
||||
|
||||
# Make sure .ansible-venv exists
|
||||
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then python3 -m venv \"${HPF_ANS_ansible_venv}\" ; fi"
|
||||
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi"
|
||||
|
||||
# Make sure pip is up to date
|
||||
as_hpf_ans "pip install --upgrade pip"
|
||||
@@ -119,12 +138,16 @@ as_hpf_ans "pip install --upgrade ansible"
|
||||
|
||||
# Make sure bin exists
|
||||
as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod ug=rwx,o= \"${HPF_ANS_bin}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\""
|
||||
|
||||
# Create ~hpf-ans/bin/ansible-pull.sh
|
||||
as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null"
|
||||
as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod ug=rwx,o= \"${HPF_ANS_ansible_pull_sh}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\""
|
||||
|
||||
# Make sure log directory exists
|
||||
mkdir -p "${ANSIBLE_PULL_SH_LOG_DIR}"
|
||||
chown hpf-ans:root "${ANSIBLE_PULL_SH_LOG_DIR}"; chmod ug=rwx,o= "${ANSIBLE_PULL_SH_LOG_DIR}"
|
||||
|
||||
# Run ansible-pull to finish up
|
||||
as_hpf_ans "bin/ansible-pull.sh"
|
||||
as_hpf_ans "bin/ansible-pull.sh bootstrap.yml"
|
||||
|
||||
+131
@@ -0,0 +1,131 @@
|
||||
---
|
||||
|
||||
####
|
||||
#### WARNING:
|
||||
####
|
||||
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
|
||||
#### exact same things with the following exceptions:
|
||||
####
|
||||
#### * bootstrap.sh
|
||||
#### - at the end it should run ansible-pull.sh against bootstrap.yml
|
||||
####
|
||||
#### * bootstrap.yml
|
||||
#### - at the end it should configure cron to schedule ansible-pull.sh
|
||||
####
|
||||
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||
#### ! Make sure to keep them in sync !
|
||||
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||
####
|
||||
|
||||
|
||||
# Update software repositories here
|
||||
# Change the following to work with multiple distros
|
||||
|
||||
- name: bootstrap
|
||||
hosts: all
|
||||
become: yes
|
||||
|
||||
tasks:
|
||||
|
||||
- name: Install bootstrap packages
|
||||
ansible.builtin.apt:
|
||||
state: latest
|
||||
pkg:
|
||||
- bash
|
||||
- curl
|
||||
- python3
|
||||
- python3-pip
|
||||
- python3-venv
|
||||
- python3-virtualenv
|
||||
|
||||
- name: Make sure hpf-sudo group exists
|
||||
ansible.builtin.group:
|
||||
name: hpf-sudo
|
||||
state: present
|
||||
system: true
|
||||
gid: 700
|
||||
|
||||
- name: Make sure hpf-sudo-np group exists
|
||||
ansible.builtin.group:
|
||||
name: hpf-sudo-np
|
||||
state: present
|
||||
system: true
|
||||
gid: 701
|
||||
|
||||
- name: Copy over /etc/sudoers.d/hpf
|
||||
ansible.builtin.copy:
|
||||
src: etc_sudoers_d_hpf
|
||||
dest: /etc/sudoers.d/hpf
|
||||
owner: root
|
||||
group: root
|
||||
mode: u=rw,go=
|
||||
backup: true
|
||||
validate: /usr/sbin/visudo -csf %s
|
||||
|
||||
- name: Make sure hpf-ans group exists
|
||||
ansible.builtin.group:
|
||||
name: hpf-ans
|
||||
state: present
|
||||
system: true
|
||||
gid: 800
|
||||
|
||||
- name: Make sure hpf-ans user exists
|
||||
ansible.builtin.user:
|
||||
name: hpf-ans
|
||||
state: present
|
||||
system: true
|
||||
uid: 800
|
||||
group: hpf-ans
|
||||
groups: hpf-sudo-np
|
||||
append: yes
|
||||
create_home: true
|
||||
shell: /bin/bash
|
||||
|
||||
- name: Install latest version of pip in .ansible-venv
|
||||
ansible.builtin.pip:
|
||||
name: pip
|
||||
virtualenv: $HOME/.ansible-venv
|
||||
extra_args: --upgrade
|
||||
become: no
|
||||
|
||||
- name: Install latest version of ansible in .ansible-venv
|
||||
ansible.builtin.pip:
|
||||
name: ansible
|
||||
virtualenv: $HOME/.ansible-venv
|
||||
extra_args: "--upgrade"
|
||||
become: no
|
||||
|
||||
- name: Make sure bin directory exists
|
||||
ansible.builtin.file:
|
||||
path: $HOME/bin
|
||||
state: directory
|
||||
owner: hpf-ans
|
||||
group: hpf-ans
|
||||
mode: u=rwx,go=
|
||||
become: no
|
||||
|
||||
- name: Copy over bin/ansible-pull.sh
|
||||
ansible.builtin.copy:
|
||||
src: home_hpf_ans_bin_ansible_pull_sh
|
||||
dest: $HOME/bin/ansible-pull.sh
|
||||
owner: hpf-ans
|
||||
group: hpf-ans
|
||||
mode: u=rwx,go=
|
||||
backup: true
|
||||
become: no
|
||||
|
||||
- name: Make sure log directory exists
|
||||
ansible.builtin.file:
|
||||
path: /var/log/ansible-pull.sh
|
||||
state: directory
|
||||
owner: hpf-ans
|
||||
group: root
|
||||
mode: ug=rwx,o=
|
||||
|
||||
# - name: Create ansible-pull.sh crontab entry
|
||||
# ansible.builtin.cron:
|
||||
# name: "ansible-pull"
|
||||
# minute: "*/27"
|
||||
# job: $HOME/bin/ansible-pull.sh
|
||||
# backup: true
|
||||
# become: no
|
||||
@@ -0,0 +1,27 @@
|
||||
#!/bin/bash
|
||||
|
||||
# - Fix branch to check out
|
||||
|
||||
. "${HOME}/.ansible-venv/bin/activate"
|
||||
|
||||
SCRIPT_NAME="$(basename "${0}")"
|
||||
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||
LOG_DIR="/var/log/ansible-pull.sh"
|
||||
LOG_FILE="${LOG_DIR}/ansible-pull.sh.log"
|
||||
LOCK_FILE="/tmp/ansible-pull.sh.lock"
|
||||
|
||||
# - Redirect all further output to the log file
|
||||
exec >>"${LOG_FILE}" 2>&1
|
||||
|
||||
# - Log that we've gotten this far
|
||||
echo -n "$(basename "${0}"): $(date "+%Y-%m-%d %H:%M:%S")"
|
||||
|
||||
# - If we can't lock the lock file, don't proceed
|
||||
exec 9>"${LOCK_FILE}"
|
||||
if ! flock -n 9 ; then echo " - ERROR - Another copy of ${SCRIPT_NAME} is already running! Exiting..." ; exit 1 ; fi
|
||||
|
||||
# - Do our work
|
||||
echo
|
||||
ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout main "${@}"
|
||||
|
||||
@@ -1,14 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
source ~/.ansible-venv/bin/activate
|
||||
|
||||
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||
|
||||
ANSIBLE_PULL_LOG="/var/log/ansible-pull.log"
|
||||
|
||||
echo | sudo tee -a "${ANSIBLE_PULL_LOG}"
|
||||
echo -n "$(basename "${0}"): " | sudo tee -a "${ANSIBLE_PULL_LOG}"
|
||||
date "+%Y-%m-%d %H:%M:%S" | sudo tee -a "${ANSIBLE_PULL_LOG}"
|
||||
ansible-pull --only-if-changed -U "${GIT_REPO}" 2>&1 | sudo tee -a "${ANSIBLE_PULL_LOG}"
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
ansible_pull_branch: main
|
||||
ntp_server: 0.north-america.pool.ntp.org
|
||||
@@ -1 +0,0 @@
|
||||
ntp_server: 0.north-america.pool.ntp.org
|
||||
|
||||
@@ -0,0 +1 @@
|
||||
ansible_pull_branch: development
|
||||
@@ -0,0 +1,13 @@
|
||||
---
|
||||
|
||||
- name: dummy
|
||||
hosts: all
|
||||
become: no
|
||||
|
||||
tasks:
|
||||
|
||||
|
||||
|
||||
- name: Display host's value of ansible_pull_branch
|
||||
ansible.builtin.debug:
|
||||
var: ansible_pull_branch
|
||||
Symlink
+1
@@ -0,0 +1 @@
|
||||
/home/heath/Development/ansible/files
|
||||
Reference in New Issue
Block a user