Compare commits
2 Commits
| Author | SHA256 | Date | |
|---|---|---|---|
| 9b213b81e9 | |||
| 761137317a |
+69
-45
@@ -17,15 +17,14 @@
|
|||||||
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||||
####
|
####
|
||||||
|
|
||||||
|
|
||||||
# Update software repositories here
|
|
||||||
# Change the following to work with multiple distros
|
|
||||||
|
|
||||||
- name: bootstrap.yml
|
- name: bootstrap.yml
|
||||||
hosts: all
|
hosts: all
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
|
|
||||||
|
|
||||||
|
#### System Software
|
||||||
|
|
||||||
- name: Update repositories
|
- name: Update repositories
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.apt:
|
ansible.builtin.apt:
|
||||||
@@ -43,6 +42,9 @@
|
|||||||
- python3-venv
|
- python3-venv
|
||||||
- python3-virtualenv
|
- python3-virtualenv
|
||||||
|
|
||||||
|
|
||||||
|
#### Configure sudo
|
||||||
|
|
||||||
- name: Create system group hpf-sudo for normal sudo users
|
- name: Create system group hpf-sudo for normal sudo users
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.group:
|
ansible.builtin.group:
|
||||||
@@ -79,6 +81,9 @@
|
|||||||
backup: true
|
backup: true
|
||||||
validate: /usr/sbin/visudo -csf %s
|
validate: /usr/sbin/visudo -csf %s
|
||||||
|
|
||||||
|
|
||||||
|
#### Configure sshd
|
||||||
|
|
||||||
## New
|
## New
|
||||||
- name: Make sure /etc/ssh/sshd_config.d exists
|
- name: Make sure /etc/ssh/sshd_config.d exists
|
||||||
become: true
|
become: true
|
||||||
@@ -102,6 +107,9 @@
|
|||||||
validate: /usr/sbin/sshd -t -f %s
|
validate: /usr/sbin/sshd -t -f %s
|
||||||
notify: Restart sshd
|
notify: Restart sshd
|
||||||
|
|
||||||
|
|
||||||
|
#### Configure /etc/skel
|
||||||
|
|
||||||
- name: Make sure /etc/skel/.profile.d exists
|
- name: Make sure /etc/skel/.profile.d exists
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
@@ -131,6 +139,19 @@
|
|||||||
mode: u=rw,go=
|
mode: u=rw,go=
|
||||||
backup: true
|
backup: true
|
||||||
|
|
||||||
|
|
||||||
|
#### User: root
|
||||||
|
|
||||||
|
- name: Set root's authorized_keys
|
||||||
|
become: true
|
||||||
|
ansible.posix.authorized_key:
|
||||||
|
user: root
|
||||||
|
state: present
|
||||||
|
key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}"
|
||||||
|
|
||||||
|
|
||||||
|
#### User: hpf-ans
|
||||||
|
|
||||||
- name: Create the hpf-ans group
|
- name: Create the hpf-ans group
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.group:
|
ansible.builtin.group:
|
||||||
@@ -152,6 +173,16 @@
|
|||||||
create_home: true
|
create_home: true
|
||||||
shell: /usr/bin/bash
|
shell: /usr/bin/bash
|
||||||
|
|
||||||
|
- name: Set hpf-ans's authorized_keys
|
||||||
|
become: true
|
||||||
|
ansible.posix.authorized_key:
|
||||||
|
user: hpf-ans
|
||||||
|
state: present
|
||||||
|
key: "{{ lookup('file', item) }}"
|
||||||
|
loop:
|
||||||
|
- files/ssh-keys/hpf-ans.pub
|
||||||
|
- files/ssh-keys/heath.pub
|
||||||
|
|
||||||
- name: Make sure pip is up to date
|
- name: Make sure pip is up to date
|
||||||
become: true
|
become: true
|
||||||
become_user: hpf-ans
|
become_user: hpf-ans
|
||||||
@@ -189,48 +220,9 @@
|
|||||||
mode: u=rwx,go=
|
mode: u=rwx,go=
|
||||||
backup: true
|
backup: true
|
||||||
|
|
||||||
- name: Make sure log directory exists
|
|
||||||
become: true
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: /var/log/ansible-pull.sh
|
|
||||||
state: directory
|
|
||||||
owner: hpf-ans
|
|
||||||
group: root
|
|
||||||
mode: u=rwx,go=
|
|
||||||
|
|
||||||
- name: Remove packages installed as dependencies that are no longer required and purge their configuration files
|
#### User: first
|
||||||
become: true
|
|
||||||
ansible.builtin.apt:
|
|
||||||
autoremove: yes
|
|
||||||
purge: true
|
|
||||||
|
|
||||||
- name: Remove old downloaded packages
|
|
||||||
become: true
|
|
||||||
ansible.builtin.apt:
|
|
||||||
clean: yes
|
|
||||||
changed_when: false
|
|
||||||
|
|
||||||
## New
|
|
||||||
- name: Set root's authorized_keys
|
|
||||||
become: true
|
|
||||||
ansible.posix.authorized_key:
|
|
||||||
user: root
|
|
||||||
state: present
|
|
||||||
key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}"
|
|
||||||
|
|
||||||
## New
|
|
||||||
- name: Set hpf-ans's authorized_keys
|
|
||||||
become: true
|
|
||||||
ansible.posix.authorized_key:
|
|
||||||
user: hpf-ans
|
|
||||||
state: present
|
|
||||||
key: "{{ lookup('file', item) }}"
|
|
||||||
loop:
|
|
||||||
- files/ssh-keys/hpf-ans.pub
|
|
||||||
- files/ssh-keys/heath.pub
|
|
||||||
|
|
||||||
|
|
||||||
## New
|
|
||||||
- name: Set first's authorized_keys
|
- name: Set first's authorized_keys
|
||||||
become: true
|
become: true
|
||||||
ansible.posix.authorized_key:
|
ansible.posix.authorized_key:
|
||||||
@@ -241,7 +233,9 @@
|
|||||||
- files/ssh-keys/first.pub
|
- files/ssh-keys/first.pub
|
||||||
- files/ssh-keys/heath.pub
|
- files/ssh-keys/heath.pub
|
||||||
|
|
||||||
## New
|
|
||||||
|
#### User: heath
|
||||||
|
|
||||||
- name: Set heath's authorized_keys
|
- name: Set heath's authorized_keys
|
||||||
become: true
|
become: true
|
||||||
ansible.posix.authorized_key:
|
ansible.posix.authorized_key:
|
||||||
@@ -249,6 +243,18 @@
|
|||||||
state: present
|
state: present
|
||||||
key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}"
|
key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}"
|
||||||
|
|
||||||
|
|
||||||
|
#### Schedule ansible-pull.sh
|
||||||
|
|
||||||
|
- name: Make sure log directory exists
|
||||||
|
become: true
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /var/log/ansible-pull.sh
|
||||||
|
state: directory
|
||||||
|
owner: hpf-ans
|
||||||
|
group: root
|
||||||
|
mode: u=rwx,go=
|
||||||
|
|
||||||
# - name: Create ansible-pull.sh crontab entry
|
# - name: Create ansible-pull.sh crontab entry
|
||||||
# become: true
|
# become: true
|
||||||
# ansible.builtin.cron:
|
# ansible.builtin.cron:
|
||||||
@@ -257,6 +263,24 @@
|
|||||||
# job: $HOME/bin/ansible-pull.sh
|
# job: $HOME/bin/ansible-pull.sh
|
||||||
# backup: true
|
# backup: true
|
||||||
|
|
||||||
|
|
||||||
|
#### Clean System Software
|
||||||
|
|
||||||
|
- name: Remove packages installed as dependencies that are no longer required and purge their configuration files
|
||||||
|
become: true
|
||||||
|
ansible.builtin.apt:
|
||||||
|
autoremove: yes
|
||||||
|
purge: true
|
||||||
|
|
||||||
|
- name: Remove old downloaded packages
|
||||||
|
become: true
|
||||||
|
ansible.builtin.apt:
|
||||||
|
autoclean: yes
|
||||||
|
# changed_when: false
|
||||||
|
|
||||||
|
|
||||||
|
#### Handlers
|
||||||
|
|
||||||
handlers:
|
handlers:
|
||||||
|
|
||||||
- name: Restart sshd
|
- name: Restart sshd
|
||||||
|
|||||||
+6
-5
@@ -1,23 +1,24 @@
|
|||||||
x root
|
x root
|
||||||
* authorized_keys = heath
|
x authorized_keys = heath
|
||||||
x hpf-ans
|
x hpf-ans
|
||||||
x system user
|
x system user
|
||||||
x /usr/bin/bash
|
x /usr/bin/bash
|
||||||
x member of hpf-sudo-np
|
x member of hpf-sudo-np
|
||||||
* authorized_keys = hpf-ans
|
x authorized_keys = hpf-ans, heath
|
||||||
* first
|
* first
|
||||||
* normal user
|
* normal user
|
||||||
* /usr/bin/bash
|
* /usr/bin/bash
|
||||||
* member of hpf-sudo
|
* member of hpf-sudo
|
||||||
* authorized_keys = heath, first
|
x authorized_keys = first, heath
|
||||||
* heath
|
* heath
|
||||||
* normal user
|
* normal user w/ special number
|
||||||
* /usr/bin/bash
|
* /usr/bin/bash
|
||||||
* member of hpf-sudo
|
* member of hpf-sudo
|
||||||
* authorized_keys = heath
|
x authorized_keys = heath
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
# Change the following to work with multiple distros (nothing hardcoded)
|
||||||
|
|
||||||
|
|
||||||
* create production, development branches
|
* create production, development branches
|
||||||
|
|||||||
Reference in New Issue
Block a user