Compare commits
2 Commits
| Author | SHA256 | Date | |
|---|---|---|---|
| c2dcfa2996 | |||
| 16e3a9cbe2 |
+30
-7
@@ -25,11 +25,23 @@
|
|||||||
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||||
GIT_REPO="${GIT_REPO_BASE}.git"
|
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||||
GIT_REPO_BRANCH="${1:-"production"}"
|
GIT_REPO_BRANCH="${1:-"production"}"
|
||||||
GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files/etc_sudoers_d_hpf"
|
|
||||||
GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files/home_hpf_ans_bin_ansible_pull_sh"
|
GIT_REPO_FILES="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files"
|
||||||
|
|
||||||
|
GIT_REPO_sudoers_d_hpf="${GIT_REPO_FILES}/sudoers_d_hpf"
|
||||||
|
GIT_REPO_profile_d_ansible_venv_sh="${GIT_REPO_FILES}/profile_d_ansible_venv_sh"
|
||||||
|
GIT_REPO_profile_append="${GIT_REPO_FILES}/profile_append"
|
||||||
|
GIT_REPO_ansible_pull_sh="${GIT_REPO_FILES}/ansible_pull_sh"
|
||||||
|
|
||||||
ETC_sudoers_d_hpf="/etc/sudoers.d/hpf"
|
ETC_sudoers_d_hpf="/etc/sudoers.d/hpf"
|
||||||
|
|
||||||
|
unset SKEL
|
||||||
|
if [ -r /etc/default/useradd ] ; then . /etc/default/useradd ; fi
|
||||||
|
SKEL="${SKEL:-/etc/skel}"
|
||||||
|
SKEL_profile_d="${SKEL}/.profile.d"
|
||||||
|
SKEL_ansible_venv_sh="${SKEL_profile_d}/ansible-venv.sh"
|
||||||
|
SKEL_profile="${SKEL}/.profile"
|
||||||
|
|
||||||
HPF_ANS_ansible_venv="\${HOME}/.ansible-venv"
|
HPF_ANS_ansible_venv="\${HOME}/.ansible-venv"
|
||||||
HPF_ANS_activate="${HPF_ANS_ansible_venv}/bin/activate"
|
HPF_ANS_activate="${HPF_ANS_ansible_venv}/bin/activate"
|
||||||
|
|
||||||
@@ -88,7 +100,8 @@ add_groups_to_user () {
|
|||||||
|
|
||||||
# $command_line
|
# $command_line
|
||||||
as_hpf_ans () {
|
as_hpf_ans () {
|
||||||
su --login hpf-ans --command "if [ -r \"${HPF_ANS_activate}\" ] ; then source \"${HPF_ANS_activate}\" ; fi ; ${1}"
|
#su --login hpf-ans --command "if [ -r \"${HPF_ANS_activate}\" ] ; then source \"${HPF_ANS_activate}\" ; fi ; ${1}"
|
||||||
|
su --login hpf-ans --command "${1}"
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
@@ -119,10 +132,20 @@ system_groupadd hpf-sudo-np 701
|
|||||||
|
|
||||||
# Create /etc/sudoers.d/hpf to allow common sudo permissions
|
# Create /etc/sudoers.d/hpf to allow common sudo permissions
|
||||||
rm "${ETC_sudoers_d_hpf}" 2>/dev/null
|
rm "${ETC_sudoers_d_hpf}" 2>/dev/null
|
||||||
curl -o "$ETC_sudoers_d_hpf" "${GIT_REPO_sudoers_d_hpf}"
|
curl -o "${ETC_sudoers_d_hpf}" "${GIT_REPO_sudoers_d_hpf}"
|
||||||
chown root:root "${ETC_sudoers_d_hpf}"
|
chown root:root "${ETC_sudoers_d_hpf}"; chmod u=rw,go= "${ETC_sudoers_d_hpf}"
|
||||||
chmod u=rw,go= "${ETC_sudoers_d_hpf}"
|
|
||||||
|
|
||||||
|
# Make sure .profile.d exists
|
||||||
|
mkdir -p "${SKEL_profile_d}\""
|
||||||
|
as_hpf_ans "chown root:root \"${SKEL_profile_d}\"; chmod u=rwx,go= \"${SKEL_profile_d}\""
|
||||||
|
|
||||||
|
# Create ansible-venv.sh
|
||||||
|
if [ ! -r "${SKEL_ansible_venv_sh}" ] ; then
|
||||||
|
curl -o "${SKEL_ansible_venv_sh}" "${GIT_REPO_ansible_venv_sh}"
|
||||||
|
chown root:root "${SKEL_ansible_venv_sh}"; chmod u=rwx,go= "${SKEL_ansible_venv_sh}"
|
||||||
|
curl "${GIT_REPO_profile_append}" >>"${SKEL_profile}"
|
||||||
|
fi
|
||||||
|
exit 255
|
||||||
# Create the hpf-ans user
|
# Create the hpf-ans user
|
||||||
system_useradd hpf-ans 800
|
system_useradd hpf-ans 800
|
||||||
add_groups_to_user hpf-sudo-np hpf-ans
|
add_groups_to_user hpf-sudo-np hpf-ans
|
||||||
@@ -140,7 +163,7 @@ as_hpf_ans "pip install --upgrade ansible"
|
|||||||
as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\""
|
as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\""
|
||||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\""
|
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\""
|
||||||
|
|
||||||
# Create ~hpf-ans/bin/ansible-pull.sh
|
# Create ansible-pull.sh
|
||||||
as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null"
|
as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null"
|
||||||
as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\""
|
as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\""
|
||||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\""
|
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\""
|
||||||
|
|||||||
@@ -0,0 +1,6 @@
|
|||||||
|
ANSIBLE_ACTIVATE="${HOME}/.ansible-venv/bin/activate"
|
||||||
|
|
||||||
|
if [ -r "${ANSIBLE_ACTIVATE}" ] ; then
|
||||||
|
VIRTUAL_ENV_DISABLE_PROMPT=true
|
||||||
|
. "${ANSIBLE_ACTIVATE}"
|
||||||
|
fi
|
||||||
+124
@@ -0,0 +1,124 @@
|
|||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
* create bootstrap, production, development branches
|
||||||
|
* have bootstrap.sh get ansible_pull_branch variable value
|
||||||
|
|
||||||
|
* have the following appended to .profile
|
||||||
|
if [ -d "$HOME/.profile.d" ] ; then
|
||||||
|
for profile_script in $HOME/.profile.d/*.sh ; do
|
||||||
|
. "${profile_script}"
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
* create ~/.profile.d
|
||||||
|
* create ~/.profile.d/ansible-venv.sh
|
||||||
|
ansible.builtin.blockinfile
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
# add /home/hpf-ans/bin/ansible-pull.sh crontab
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
* Configure hosts
|
||||||
|
# cat >>/etc/hosts <<!!TheEnd!!
|
||||||
|
|
||||||
|
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
|
||||||
|
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
|
||||||
|
!!TheEnd!!
|
||||||
|
* Configure chrony
|
||||||
|
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
|
||||||
|
pool 0.north-america.pool.ntp.org iburst
|
||||||
|
!!TheEnd!!
|
||||||
|
* Configure SSH
|
||||||
|
# cat >/etc/ssh/sshd_config.d/hpetersenfamily.conf <<!!TheEnd!!
|
||||||
|
PasswordAuthentication no
|
||||||
|
PermitEmptyPasswords no
|
||||||
|
PermitRootLogin no
|
||||||
|
!!TheEnd!!
|
||||||
|
# cat >>/home/first/.ssh/authorized_keys <<!!TheEnd!!
|
||||||
|
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBM5BBUOxkuSK7WlpaDvp6lrM9ajLSyh4PWD7VFzYOFN5/zfafy6Vf/oxtLE4UACw5ZGvBMQNH40bW+T9aO0lQ9g= first Heath@HPetersenFamily.com
|
||||||
|
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBBFiio/AimTUloJdfk4TXyWO7A0Fd9SoUcqheBjEvj4TnrxpSL/EhwF2CU9jZTasm6NBo2eKcH4aMt1l2ejOtIM= heath Heath@HPetersenFamily.com
|
||||||
|
!!TheEnd!!
|
||||||
|
|
||||||
|
|
||||||
|
##########
|
||||||
|
########## normal tasks
|
||||||
|
##########
|
||||||
|
|
||||||
|
- name: Install openssh, openssh-server, openssh-sftp-server
|
||||||
|
ansible.builtin.apt:
|
||||||
|
pkg:
|
||||||
|
- openssh
|
||||||
|
- openssh-server
|
||||||
|
- openssh-sftp-server
|
||||||
|
|
||||||
|
- name: Install bash, bash-completion
|
||||||
|
ansible.builtin.apt:
|
||||||
|
pkg:
|
||||||
|
- bash
|
||||||
|
- bash-completion
|
||||||
|
|
||||||
|
- name: Install chrony
|
||||||
|
ansible.builtin.apt:
|
||||||
|
pkg:
|
||||||
|
- chrony
|
||||||
|
|
||||||
|
#- name: Set host name
|
||||||
|
# ansible.builtin.hostname:
|
||||||
|
# name: ## Fully qualified domain name ##
|
||||||
|
# use: systemd
|
||||||
|
|
||||||
|
|
||||||
|
- name: Copy a new sudoers file into place, after passing validation with visudo
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: /mine/sudoers
|
||||||
|
dest: /etc/sudoers
|
||||||
|
validate: /usr/sbin/visudo -cf %s
|
||||||
|
|
||||||
|
- name: Update sshd configuration safely, avoid locking yourself out
|
||||||
|
ansible.builtin.template:
|
||||||
|
src: etc/ssh/sshd_config.j2
|
||||||
|
dest: /etc/ssh/sshd_config
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: '0600'
|
||||||
|
validate: /usr/sbin/sshd -t -f %s
|
||||||
|
backup: yes
|
||||||
|
|
||||||
|
|
||||||
|
proxmox-clients
|
||||||
|
hw:
|
||||||
|
pve-lxc:
|
||||||
|
pve-oci:
|
||||||
|
pve-kvm:
|
||||||
|
|
||||||
|
|
||||||
|
users: first, heath, hpf-ans
|
||||||
|
|
||||||
|
~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
|
||||||
|
~heath/.ssh/authorized_keys
|
||||||
|
~first/.ssh/authorized_keys
|
||||||
|
~heath/.gitconfig
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
fail2ban
|
||||||
|
uptime kuma
|
||||||
|
|
||||||
|
==============================================================
|
||||||
|
==============================================================
|
||||||
|
==============================================================
|
||||||
|
|
||||||
|
logrotate /var/log/ansible-pull.log
|
||||||
|
cron job for ansible-pull
|
||||||
|
|
||||||
|
|
||||||
|
use tags to do things like allow selecting software updates, software cleanup, etc.
|
||||||
|
ansible_os_family variable
|
||||||
|
ansible galaxy
|
||||||
|
|
||||||
|
have upgrade pip and ansible in ~hpf-ans/.ansible-venv
|
||||||
|
hashicorp vault
|
||||||
|
have ansible-pull.sh make sure only one copy is running
|
||||||
Reference in New Issue
Block a user