Compare commits

..

29 Commits

Author SHA256 Message Date
heath cccc72cd6f clean up ansible-pull logging and lock against concurrent runs 2026-07-12 15:30:07 -05:00
heath 3067b21276 clean up 2026-07-12 13:53:17 -05:00
heath 19f79cd518 use virtualenv command instead of module 2026-07-12 12:38:57 -05:00
heath 6a5089eb01 update boothstrap comments 2026-07-12 10:03:08 -05:00
heath 08b7af2bef just in case 2026-07-11 20:00:45 -05:00
heath 4431f86464 back up ansible-pull.sh if updated 2026-07-11 18:43:15 -05:00
heath 01c537343c change bootstrap.sh file permissions 2026-07-11 18:25:01 -05:00
heath c421d990aa have bootstrap.sh pull and play bootstrap.yml 2026-07-11 18:16:08 -05:00
heath 0d943ef1cd allow arguments to ansible-pull.sh 2026-07-11 18:11:25 -05:00
heath 1db51f6057 back up ansible-pull.sh if changed 2026-07-11 17:59:06 -05:00
heath 7db15a06b5 Add warning comments to bootstrap.sh and bootstrap.yml 2026-07-11 13:19:27 -05:00
heath 2f0f64871f fix source name for ansible-pull.sh 2026-07-11 13:10:15 -05:00
heath 3cf63e3966 fix 2026-07-11 13:05:53 -05:00
heath accb444ad6 don't run copy of ansible-pull.sh as root 2026-07-11 12:57:17 -05:00
heath d46ebceabe bin/ansible-pull.sh 2026-07-11 12:55:46 -05:00
heath c778125cb1 x 2026-07-11 12:41:00 -05:00
heath 0177a6df37 working on bootstrap.yml 2026-07-11 11:31:14 -05:00
heath 3a6818e9d1 have bootstrap.sh install python3-virtualenv 2026-07-11 11:29:20 -05:00
heath fe974643ae moved bootstrap files into files directory 2026-07-11 10:43:22 -05:00
heath 0502c4f766 my first playbooks! 2026-07-10 17:06:23 -05:00
heath 18b5cbf644 correct error in ansible.cfg 2026-07-10 17:05:33 -05:00
heath 97b9bc97dd have bootstrap upgrade ansible if already installed 2026-07-10 15:33:39 -05:00
heath 723ac0a24d scraps 2026-07-10 15:32:33 -05:00
heath c5bd013060 created inventory/group_vars/heath.yml 2026-07-10 15:26:01 -05:00
heath 993692447b Initial ansible.cfg and inventory files 2026-07-10 15:11:34 -05:00
heath fd4b1e0fea housekeeping 2026-07-10 11:56:59 -05:00
heath d711e39fb8 remove unused variable 2026-07-10 11:53:09 -05:00
heath 46f4ce36da clean house 2026-07-10 11:48:27 -05:00
heath 8be5322957 rename GIT_REPO variables 2026-07-10 11:07:31 -05:00
17 changed files with 334 additions and 48 deletions
+21
View File
@@ -0,0 +1,21 @@
[defaults]
inventory = ./inventory
remote_user = hpf-ans
host_key_checking = False
timeout = 30
stdout_callback = default
callback_result_format = yaml
#[privilege_escalation]
#become = True
#become_method = sudo
#become_user = root
#become_ask_pass = False
[ssh_connection]
pipelining = True
+59 -34
View File
@@ -1,5 +1,22 @@
#!/bin/sh #!/bin/sh
####
#### WARNING:
####
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
#### exact same things with the following exceptions:
####
#### * bootstrap.sh
#### - at the end it should run ansible-pull.sh against bootstrap.yml
####
#### * bootstrap.yml
#### - at the end it should configure cron to schedule ansible-pull.sh
####
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
#### ! Make sure to keep them in sync !
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
####
# #
#### VARIABLES #### VARIABLES
@@ -7,13 +24,19 @@
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible" GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
GIT_REPO="${GIT_REPO_BASE}.git" GIT_REPO="${GIT_REPO_BASE}.git"
GIT_REPO_ETC_SUDOERS_D_HPF="${GIT_REPO_BASE}/raw/branch/main/etc_sudoers_d_hpf" GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/files/etc_sudoers_d_hpf"
GIT_REPO_HOME_HPF_ANS_BIN_ANSIBLE_PULL_SH="${GIT_REPO_BASE}/raw/branch/main/home_hpf_ans_bin_ansible-pull.sh" GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/files/home_hpf_ans_bin_ansible_pull_sh"
VENV_DIRECTORY="\${HOME}/.ansible-venv"
VENV_ACTIVATE="${VENV_DIRECTORY}/bin/activate"
ANSIBLE_PULL_LOG="/var/log/ansible-pull.log" ETC_sudoers_d_hpf="/etc/sudoers.d/hpf"
HPF_ANS_ansible_venv="\${HOME}/.ansible-venv"
HPF_ANS_activate="${HPF_ANS_ansible_venv}/bin/activate"
HPF_ANS_bin="\${HOME}/bin"
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
ANSIBLE_PULL_SH_LOG_DIR="/var/log/ansible-pull.sh"
# #
@@ -36,7 +59,7 @@ system_groupadd () {
groupadd -r -g "$2" "$1" groupadd -r -g "$2" "$1"
rc=$? rc=$?
if [ $rc -ne 0 ] ; then if [ $rc -ne 0 ] ; then
echo "ERROR - Unable to add $1 group! ($rc)" 1>&2 echo "ERROR - Unable to add $1 group! ($rc)" >&2
exit 1 exit 1
fi fi
} }
@@ -48,7 +71,7 @@ system_useradd () {
useradd -r -u "$2" -g "$2" -s /bin/bash -m "$1" useradd -r -u "$2" -g "$2" -s /bin/bash -m "$1"
rc=$? rc=$?
if [ $rc -ne 0 ] ; then if [ $rc -ne 0 ] ; then
echo "ERROR - Unable to add $1 user! ($rc)" 1>&2 echo "ERROR - Unable to add $1 user! ($rc)" >&2
exit 2 exit 2
fi fi
} }
@@ -58,14 +81,14 @@ add_groups_to_user () {
usermod -aG "$1" "$2" usermod -aG "$1" "$2"
rc=$? rc=$?
if [ $rc -ne 0 ] ; then if [ $rc -ne 0 ] ; then
echo "ERROR - Unable to add groups ($1) to user ($2)! ($rc)" 1>&2 echo "ERROR - Unable to add groups ($1) to user ($2)! ($rc)" >&2
exit 3 exit 3
fi fi
} }
# $command_line # $command_line
as_hpf_ans () { as_hpf_ans () {
su --login hpf-ans -c "if [ -r \"${VENV_ACTIVATE}\" ] ; then source \"${VENV_ACTIVATE}\" ; fi ; ${1}" su --login hpf-ans -c "if [ -r \"${HPF_ANS_activate}\" ] ; then source \"${HPF_ANS_activate}\" ; fi ; ${1}"
} }
@@ -75,16 +98,16 @@ as_hpf_ans () {
# Make sure we're running as root # Make sure we're running as root
if [ $(id -u) -ne 0 ] ; then if [ $(id -u) -ne 0 ] ; then
echo "ERROR - Not running as root!" 1>&2 echo "ERROR - Not running as root!" >&2
exit 100 exit 100
fi fi
# Install minimal necessary packages # Install minimal necessary packages
if which -s apt ; then if which -s apt ; then
apt update apt update
apt install bash curl python3 python3-pip python3-venv -y apt install bash curl python3 python3-pip python3-venv python3-virtualenv -y
else else
echo "ERROR - Unable to determine how to install packages" 1>&2 echo "ERROR - Unable to determine how to install packages" >&2
exit 101 exit 101
fi fi
@@ -94,35 +117,37 @@ system_groupadd hpf-sudo 700
# Create system group hpf-sudo-np for special sudo users that don't require a password # Create system group hpf-sudo-np for special sudo users that don't require a password
system_groupadd hpf-sudo-np 701 system_groupadd hpf-sudo-np 701
# Create the Ansible user # Create /etc/sudoers.d/hpf to allow common sudo permissions
rm "${ETC_sudoers_d_hpf}" 2>/dev/null
curl -o "$ETC_sudoers_d_hpf" "${GIT_REPO_sudoers_d_hpf}"
chown root:root "${ETC_sudoers_d_hpf}"
chmod u=rw,go= "${ETC_sudoers_d_hpf}"
# Create the hpf-ans user
system_useradd hpf-ans 800 system_useradd hpf-ans 800
add_groups_to_user "hpf-sudo-np" hpf-ans add_groups_to_user hpf-sudo-np hpf-ans
# Create /etc/sudoers.d/hpf # Make sure .ansible-venv exists
f="/etc/sudoers.d/hpf" as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi"
rm "${f}" 2>/dev/null
curl -o "$f" "${GIT_REPO_ETC_SUDOERS_D_HPF}"
chown root:root "$f"
chmod u=rw,g=r,o= "$f"
# Make sure the hpf-ans ansible venv exists # Make sure pip is up to date
as_hpf_ans "if [ ! -d \"${VENV_DIRECTORY}\" ] ; then python3 -m venv \"${VENV_DIRECTORY}\" ; fi"
# Make sure pip is up to date in .ansible-venv
as_hpf_ans "pip install --upgrade pip" as_hpf_ans "pip install --upgrade pip"
# Make sure ansible is installed in .ansible-venv # Make sure ansible is installed
as_hpf_ans "pip install ansible" as_hpf_ans "pip install --upgrade ansible"
# Create ~hpf-ans/bin directory # Make sure bin exists
d="\${HOME}/bin" as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\""
as_hpf_ans "mkdir -p \"${d}\"; chown hpf-ans:hpf-ans \"${d}\"; chmod ug=rwx,o= \"${d}\"" as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\""
# Create ~hpf-ans/bin/ansible-pull.sh # Create ~hpf-ans/bin/ansible-pull.sh
f="\${HOME}/bin/ansible-pull.sh" as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null"
as_hpf_ans "rm \"${f}\" 2>/dev/null" as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\""
as_hpf_ans "curl -o \"${f}\" \"${GIT_REPO_HOME_HPF_ANS_BIN_ANSIBLE_PULL_SH}\"" as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\""
as_hpf_ans "chown hpf-ans:hpf-ans \"${f}\"; chmod ug=rwx,o= \"${f}\""
# Make sure log directory exists
mkdir -p "${ANSIBLE_PULL_SH_LOG_DIR}"
chown hpf-ans:root "${ANSIBLE_PULL_SH_LOG_DIR}"; chmod ug=rwx,o= "${ANSIBLE_PULL_SH_LOG_DIR}"
# Run ansible-pull to finish up # Run ansible-pull to finish up
as_hpf_ans "bin/ansible-pull.sh" as_hpf_ans "bin/ansible-pull.sh bootstrap.yml"
+131
View File
@@ -0,0 +1,131 @@
---
####
#### WARNING:
####
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
#### exact same things with the following exceptions:
####
#### * bootstrap.sh
#### - at the end it should run ansible-pull.sh against bootstrap.yml
####
#### * bootstrap.yml
#### - at the end it should configure cron to schedule ansible-pull.sh
####
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
#### ! Make sure to keep them in sync !
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
####
# Update software repositories here
# Change the following to work with multiple distros
- name: bootstrap
hosts: all
become: yes
tasks:
- name: Install bootstrap packages
ansible.builtin.apt:
state: latest
pkg:
- bash
- curl
- python3
- python3-pip
- python3-venv
- python3-virtualenv
- name: Make sure hpf-sudo group exists
ansible.builtin.group:
name: hpf-sudo
state: present
system: true
gid: 700
- name: Make sure hpf-sudo-np group exists
ansible.builtin.group:
name: hpf-sudo-np
state: present
system: true
gid: 701
- name: Copy over /etc/sudoers.d/hpf
ansible.builtin.copy:
src: etc_sudoers_d_hpf
dest: /etc/sudoers.d/hpf
owner: root
group: root
mode: u=rw,go=
backup: true
validate: /usr/sbin/visudo -csf %s
- name: Make sure hpf-ans group exists
ansible.builtin.group:
name: hpf-ans
state: present
system: true
gid: 800
- name: Make sure hpf-ans user exists
ansible.builtin.user:
name: hpf-ans
state: present
system: true
uid: 800
group: hpf-ans
groups: hpf-sudo-np
append: yes
create_home: true
shell: /bin/bash
- name: Install latest version of pip in .ansible-venv
ansible.builtin.pip:
name: pip
virtualenv: $HOME/.ansible-venv
extra_args: --upgrade
become: no
- name: Install latest version of ansible in .ansible-venv
ansible.builtin.pip:
name: ansible
virtualenv: $HOME/.ansible-venv
extra_args: "--upgrade"
become: no
- name: Make sure bin directory exists
ansible.builtin.file:
path: $HOME/bin
state: directory
owner: hpf-ans
group: hpf-ans
mode: u=rwx,go=
become: no
- name: Copy over bin/ansible-pull.sh
ansible.builtin.copy:
src: home_hpf_ans_bin_ansible_pull_sh
dest: $HOME/bin/ansible-pull.sh
owner: hpf-ans
group: hpf-ans
mode: u=rwx,go=
backup: true
become: no
- name: Make sure log directory exists
ansible.builtin.file:
path: /var/log/ansible-pull.sh
state: directory
owner: hpf-ans
group: root
mode: ug=rwx,o=
# - name: Create ansible-pull.sh crontab entry
# ansible.builtin.cron:
# name: "ansible-pull"
# minute: "*/27"
# job: $HOME/bin/ansible-pull.sh
# backup: true
# become: no
+27
View File
@@ -0,0 +1,27 @@
#!/bin/bash
# - Fix branch to check out
. "${HOME}/.ansible-venv/bin/activate"
SCRIPT_NAME="$(basename "${0}")"
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
GIT_REPO="${GIT_REPO_BASE}.git"
LOG_DIR="/var/log/ansible-pull.sh"
LOG_FILE="${LOG_DIR}/ansible-pull.sh.log"
LOCK_FILE="/tmp/ansible-pull.sh.lock"
# - Redirect all further output to the log file
exec >>"${LOG_FILE}" 2>&1
# - Log that we've gotten this far
echo -n "$(basename "${0}"): $(date "+%Y-%m-%d %H:%M:%S")"
# - If we can't lock the lock file, don't proceed
exec 9>"${LOCK_FILE}"
if ! flock -n 9 ; then echo " - ERROR - Another copy of ${SCRIPT_NAME} is already running! Exiting..." ; exit 1 ; fi
# - Do our work
echo
ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout main "${@}"
-14
View File
@@ -1,14 +0,0 @@
#!/bin/bash
source ~/.ansible-venv/bin/activate
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
GIT_REPO="${GIT_REPO_BASE}.git"
ANSIBLE_PULL_LOG="/var/log/ansible-pull.log"
echo | sudo tee -a "${ANSIBLE_PULL_LOG}"
echo -n "$(basename "${0}"): " | sudo tee -a "${ANSIBLE_PULL_LOG}"
date "+%Y-%m-%d %H:%M:%S" | sudo tee -a "${ANSIBLE_PULL_LOG}"
ansible-pull --only-if-changed -U "${GIT_REPO}" 2>&1 | sudo tee -a "${ANSIBLE_PULL_LOG}"
+2
View File
@@ -0,0 +1,2 @@
ansible_pull_branch: main
ntp_server: 0.north-america.pool.ntp.org
View File
+23
View File
@@ -0,0 +1,23 @@
---
heath:
children:
mobile:
children:
laptops:
hosts:
iris.heath.hpetersenfamily.com:
vars:
cellphones:
hosts:
vars:
fixed:
children:
clusters:
children:
pve:
children:
pve_heath_hpetersenfamily_com:
hosts:
pve01.heath.hpetersenfamily.com:
pve02.heath.hpetersenfamily.com:
@@ -0,0 +1 @@
ansible_pull_branch: development
+12
View File
@@ -0,0 +1,12 @@
---
mobile:
children:
laptops:
hosts:
vars:
fixed:
children:
admins:
hosts:
admin-a.hpetersenfamily.com:
vars:
+13
View File
@@ -0,0 +1,13 @@
---
- name: dummy
hosts: all
become: no
tasks:
- name: Display host's value of ansible_pull_branch
ansible.builtin.debug:
var: ansible_pull_branch
+5
View File
@@ -0,0 +1,5 @@
$ ansible-playbook --limit iris.heath.hpetersenfamily.com --list-hosts scraps/update_software.yml
$ ansible-playbook --limit iris.heath.hpetersenfamily.com --syntax-check scraps/update_software.yml
$ ansible-inventory --list
+19
View File
@@ -0,0 +1,19 @@
---
# CHANGEME - handle multiple software packaging systems (apt, yum, dnf, rpm, etc.)
- name: Update software
hosts: all
become: yes
post_tasks:
- name: Remove packages installed as dependencies that are no longer required and purge their configuration files
ansible.builtin.apt:
autoremove: yes
purge: true
- name: Remove old downloaded packages
ansible.builtin.apt:
clean: yes
+3
View File
@@ -0,0 +1,3 @@
#!/usr/bin/bash
ansible-inventory --host "${1}"
+1
View File
@@ -0,0 +1 @@
/home/heath/Development/ansible/files
+17
View File
@@ -0,0 +1,17 @@
---
# CHANGEME - handle multiple software packaging systems (apt, yum, dnf, rpm, etc.)
- name: Update software
hosts: all
become: yes
pre_tasks:
- name: Update package repositories
ansible.builtin.apt:
update_cache: yes
- name: Upgrade all packages
ansible.builtin.apt:
upgrade: full