Compare commits
7 Commits
| Author | SHA256 | Date | |
|---|---|---|---|
| 8d40ddc636 | |||
| 5706fc9854 | |||
| 5e0d333c7b | |||
| 76d0fe843a | |||
| 8c9a79c07a | |||
| f0dbaef0e4 | |||
| 01e471ec0f |
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
# ---> Ansible
|
# ---> Ansible
|
||||||
*.retry
|
*.retry
|
||||||
EXAMPLES
|
EXAMPLES
|
||||||
|
roles
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
[defaults]
|
[defaults]
|
||||||
|
|
||||||
inventory = ./inventory
|
inventory = ./inventory
|
||||||
|
roles_path = ./roles
|
||||||
|
|
||||||
remote_user = hpf-ans
|
remote_user = hpf-ans
|
||||||
host_key_checking = False
|
host_key_checking = False
|
||||||
|
|||||||
+10
-106
@@ -43,54 +43,25 @@
|
|||||||
system: true
|
system: true
|
||||||
gid: 701
|
gid: 701
|
||||||
|
|
||||||
- name: Make sure /etc/sudoers.d exists
|
- name: Get /etc/sudoers.d
|
||||||
become: true
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: /etc/sudoers.d
|
|
||||||
state: directory
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: u=rwx,go=
|
|
||||||
|
|
||||||
- name: Get /etc/sudoers.d/hpf
|
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
src: etc/sudoers.d/hpf
|
src: etc/sudoers.d
|
||||||
dest: /etc/sudoers.d/hpf
|
dest: /etc/
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: u=rw,go=
|
directory_mode: u=rwx,go=
|
||||||
|
mode: u=rw,g=r,o=
|
||||||
backup: true
|
backup: true
|
||||||
validate: /usr/sbin/visudo -csf %s
|
validate: /usr/sbin/visudo -csf %s
|
||||||
|
|
||||||
|
|
||||||
#### Configure sshd
|
#### Configure sshd
|
||||||
|
|
||||||
# - name: Make sure /etc/ssh/sshd_config.d exists
|
|
||||||
# become: true
|
|
||||||
# ansible.builtin.file:
|
|
||||||
# path: /etc/ssh/sshd_config.d
|
|
||||||
# state: directory
|
|
||||||
# owner: root
|
|
||||||
# group: root
|
|
||||||
# mode: u=rwx,go=rx
|
|
||||||
#
|
|
||||||
# - name: Get /etc/ssh/sshd_config.d/hpf.conf
|
|
||||||
# become: true
|
|
||||||
# ansible.builtin.copy:
|
|
||||||
# src: etc/ssh/sshd_config.d/hpf.conf
|
|
||||||
# dest: /etc/ssh/sshd_config.d/hpf.conf
|
|
||||||
# owner: root
|
|
||||||
# group: root
|
|
||||||
# mode: u=rwx,go=rx
|
|
||||||
# backup: true
|
|
||||||
# validate: /usr/sbin/sshd -t -f %s
|
|
||||||
# notify: Restart sshd
|
|
||||||
|
|
||||||
- name: Get /etc/ssh/sshd_config.d
|
- name: Get /etc/ssh/sshd_config.d
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
src: etc/ssh/sshd_config.d/
|
src: etc/ssh/sshd_config.d
|
||||||
dest: /etc/ssh/
|
dest: /etc/ssh/
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
@@ -100,60 +71,13 @@
|
|||||||
validate: /usr/sbin/sshd -t -f %s
|
validate: /usr/sbin/sshd -t -f %s
|
||||||
notify: Restart sshd
|
notify: Restart sshd
|
||||||
|
|
||||||
|
|
||||||
#### Configure /etc/skel
|
#### Configure /etc/skel
|
||||||
|
|
||||||
# - name: Make sure /etc/skel/.profile.d exists
|
|
||||||
# become: true
|
|
||||||
# ansible.builtin.file:
|
|
||||||
# path: /etc/skel/.profile.d
|
|
||||||
# state: directory
|
|
||||||
# owner: root
|
|
||||||
# group: root
|
|
||||||
# mode: u=rwx,go=
|
|
||||||
|
|
||||||
# - name: Get /etc/skel/.profile.d/ansible-venv.sh
|
|
||||||
# become: true
|
|
||||||
# ansible.builtin.copy:
|
|
||||||
# src: etc/skel/.profile.d/ansible-venv.sh
|
|
||||||
# dest: /etc/skel/.profile.d/ansible-venv.sh
|
|
||||||
# owner: root
|
|
||||||
# group: root
|
|
||||||
# mode: u=rw,go=
|
|
||||||
# backup: true
|
|
||||||
|
|
||||||
# - name: Get /etc/skel/.profile
|
|
||||||
# become: true
|
|
||||||
# ansible.builtin.copy:
|
|
||||||
# src: etc/skel/.profile
|
|
||||||
# dest: /etc/skel/.profile
|
|
||||||
# owner: root
|
|
||||||
# group: root
|
|
||||||
# mode: u=rw,go=
|
|
||||||
# backup: true
|
|
||||||
|
|
||||||
# - name: Make sure /etc/skel/.bashrc.d exists
|
|
||||||
# become: true
|
|
||||||
# ansible.builtin.file:
|
|
||||||
# path: /etc/skel/.bashrc.d
|
|
||||||
# state: directory
|
|
||||||
# owner: root
|
|
||||||
# group: root
|
|
||||||
# mode: u=rwx,go=
|
|
||||||
|
|
||||||
# - name: Get /etc/skel/.bashrc
|
|
||||||
# become: true
|
|
||||||
# ansible.builtin.copy:
|
|
||||||
# src: etc/skel/.bashrc
|
|
||||||
# dest: /etc/skel/.bashrc
|
|
||||||
# owner: root
|
|
||||||
# group: root
|
|
||||||
# mode: u=rw,go=
|
|
||||||
# backup: true
|
|
||||||
|
|
||||||
- name: Get /etc/skel
|
- name: Get /etc/skel
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
src: etc/skel/
|
src: etc/skel
|
||||||
dest: /etc/
|
dest: /etc/
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
@@ -161,6 +85,7 @@
|
|||||||
mode: u=rw,go=
|
mode: u=rw,go=
|
||||||
backup: true
|
backup: true
|
||||||
|
|
||||||
|
|
||||||
#### User: root
|
#### User: root
|
||||||
|
|
||||||
- name: Set root's authorized_keys
|
- name: Set root's authorized_keys
|
||||||
@@ -232,7 +157,7 @@
|
|||||||
become: true
|
become: true
|
||||||
become_user: hpf-ans
|
become_user: hpf-ans
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
src: home/hpf-ans/bin/
|
src: home/hpf-ans/bin
|
||||||
dest: $HOME/
|
dest: $HOME/
|
||||||
owner: hpf-ans
|
owner: hpf-ans
|
||||||
group: hpf-ans
|
group: hpf-ans
|
||||||
@@ -303,27 +228,6 @@
|
|||||||
|
|
||||||
#### ansible-pull.sh
|
#### ansible-pull.sh
|
||||||
|
|
||||||
# - name: Make sure /home/hpf-ans/bin exists
|
|
||||||
# become: true
|
|
||||||
# become_user: hpf-ans
|
|
||||||
# ansible.builtin.file:
|
|
||||||
# path: $HOME/bin
|
|
||||||
# state: directory
|
|
||||||
# owner: hpf-ans
|
|
||||||
# group: hpf-ans
|
|
||||||
# mode: u=rwx,go=
|
|
||||||
|
|
||||||
# - name: Get /home/hpf-ans/bin/ansible-pull.sh
|
|
||||||
# become: true
|
|
||||||
# become_user: hpf-ans
|
|
||||||
# ansible.builtin.copy:
|
|
||||||
# src: home/hpf-ans/bin/ansible-pull.sh
|
|
||||||
# dest: $HOME/bin/ansible-pull.sh
|
|
||||||
# owner: hpf-ans
|
|
||||||
# group: hpf-ans
|
|
||||||
# mode: u=rwx,go=
|
|
||||||
# backup: true
|
|
||||||
|
|
||||||
- name: Make sure log directory exists
|
- name: Make sure log directory exists
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
|
|||||||
@@ -8,14 +8,20 @@ SCRIPT_NAME="$(basename "${0}")"
|
|||||||
GIT_REPO_BRANCH="${GIT_REPO_BRANCH:-production}"
|
GIT_REPO_BRANCH="${GIT_REPO_BRANCH:-production}"
|
||||||
OIC_FLAG="--only-if-changed"
|
OIC_FLAG="--only-if-changed"
|
||||||
VERBOSE_FLAG="--verbose"
|
VERBOSE_FLAG="--verbose"
|
||||||
|
DEBUG_FLAG="false"
|
||||||
|
|
||||||
# - Process command line
|
# - Process command line
|
||||||
while [ $# -gt 0 ]; do
|
while [ $# -gt 0 ]; do
|
||||||
case "$1" in
|
case "$1" in
|
||||||
-h|--help)
|
-h|--help)
|
||||||
echo "Usage: $0 [--branch <branch name>]"
|
echo "Usage: $0 [--branch <branch name>] [--force] [--quiet] [-- <ansible-pull args>]"
|
||||||
exit 0
|
exit 0
|
||||||
;;
|
;;
|
||||||
|
-d|--debug)
|
||||||
|
VERBOSE_FLAG="-vvv"
|
||||||
|
DEBUG_FLAG="true"
|
||||||
|
shift 1
|
||||||
|
;;
|
||||||
-b|--branch)
|
-b|--branch)
|
||||||
shift 1
|
shift 1
|
||||||
if [ $# -eq 0 ] ; then echo "${SCRIPT_NAME}: ERROR - Branch not specified." ; exit 1 ; fi
|
if [ $# -eq 0 ] ; then echo "${SCRIPT_NAME}: ERROR - Branch not specified." ; exit 1 ; fi
|
||||||
@@ -23,12 +29,12 @@ while [ $# -gt 0 ]; do
|
|||||||
shift 1
|
shift 1
|
||||||
;;
|
;;
|
||||||
-f|--force)
|
-f|--force)
|
||||||
shift 1
|
|
||||||
OIC_FLAG=""
|
OIC_FLAG=""
|
||||||
|
shift 1
|
||||||
;;
|
;;
|
||||||
-q|--quiet)
|
-q|--quiet)
|
||||||
shift 1
|
|
||||||
VERBOSE_FLAG=""
|
VERBOSE_FLAG=""
|
||||||
|
shift 1
|
||||||
;;
|
;;
|
||||||
--)
|
--)
|
||||||
shift 1
|
shift 1
|
||||||
@@ -48,7 +54,6 @@ GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
|||||||
GIT_REPO="${GIT_REPO_BASE}.git"
|
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||||
|
|
||||||
# - Include ansible virtual environment (in case not already done - we don't know how we're being run)
|
# - Include ansible virtual environment (in case not already done - we don't know how we're being run)
|
||||||
VIRTUAL_ENV_DISABLE_PROMPT=true
|
|
||||||
. "${VENV_ACTIVATE_SCRIPT}"
|
. "${VENV_ACTIVATE_SCRIPT}"
|
||||||
|
|
||||||
# - If we can't get a lock, don't proceed
|
# - If we can't get a lock, don't proceed
|
||||||
@@ -61,12 +66,16 @@ if ! flock -n 9 ; then
|
|||||||
exit 11
|
exit 11
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# - Append all further STDOUT and STDERR to the log file
|
# - If debugging requested or running from a terminal . . .
|
||||||
exec >>"${LOG_FILE}" 2>&1
|
if [ "${DEBUG_FLAG}" = "true" ] || test -t 0 ; then
|
||||||
|
exec > >(tee -a "${LOG_FILE}") 2>&1 # - send STDOUT and STDERR to both STDOUT and the log file
|
||||||
|
else
|
||||||
|
exec >>"${LOG_FILE}" 2>&1 # - send STDOUT and STDERR to the log file only
|
||||||
|
fi
|
||||||
|
|
||||||
# - Log that we've gotten this far
|
# - Log that we've gotten this far
|
||||||
echo
|
echo
|
||||||
echo "${SCRIPT_NAME}: $(date "+%Y-%m-%d %H:%M:%S") ----------------------------------------"
|
echo "${SCRIPT_NAME}: ------------------------------- $(date "+%Y-%m-%d %H:%M:%S") -------------------------------"
|
||||||
|
|
||||||
# - Do our work
|
# - Do our work
|
||||||
ansible-pull ${OIC_FLAG} ${VERBOSE_FLAG} --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}"
|
ansible-pull ${OIC_FLAG} ${VERBOSE_FLAG} --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}"
|
||||||
@@ -0,0 +1,18 @@
|
|||||||
|
---
|
||||||
|
- name: Configure time synchronization
|
||||||
|
hosts: all
|
||||||
|
become: true
|
||||||
|
vars:
|
||||||
|
timesync_ntp_provider: chrony
|
||||||
|
timesync_ntp_servers:
|
||||||
|
- hostname: 0.north-america.pool.ntp.org
|
||||||
|
iburst: true
|
||||||
|
- hostname: 1.north-america.pool.ntp.org
|
||||||
|
iburst: true
|
||||||
|
- hostname: 2.north-america.pool.ntp.org
|
||||||
|
iburst: true
|
||||||
|
timesync_chrony_custom_settings:
|
||||||
|
- "logdir /var/log/chrony"
|
||||||
|
- "log measurements statistics tracking"
|
||||||
|
roles:
|
||||||
|
- linux-system-roles.timesync
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
roles:
|
||||||
|
- name: linux-system-roles.timesync
|
||||||
|
version: 1.14.1
|
||||||
@@ -6,11 +6,6 @@ Manually on each system:
|
|||||||
|
|
||||||
iris.heath.hpetersenfamily.com admin-a.hpetersenfamily.com core.mary.hpetersenfamily.com
|
iris.heath.hpetersenfamily.com admin-a.hpetersenfamily.com core.mary.hpetersenfamily.com
|
||||||
|
|
||||||
* ansible-pull.sh
|
|
||||||
* debug flag to print to stdout
|
|
||||||
* bootstrap.yml
|
|
||||||
* change to copy files/home/hpf-ans/bin with all it's contents
|
|
||||||
|
|
||||||
|
|
||||||
heath
|
heath
|
||||||
authorized_keys:
|
authorized_keys:
|
||||||
|
|||||||
Executable
+11
@@ -0,0 +1,11 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
send_some_output() {
|
||||||
|
echo "hello"
|
||||||
|
echo "here"
|
||||||
|
echo "goodbye"
|
||||||
|
}
|
||||||
|
|
||||||
|
exec > >(tee -a ./x.out) 2>&1
|
||||||
|
|
||||||
|
send_some_output >&2
|
||||||
Reference in New Issue
Block a user