Compare commits

...

7 Commits

Author SHA256 Message Date
heath 8d40ddc636 create local.yml and configure chrony with it 2026-08-30 15:50:18 -05:00
heath 5706fc9854 x 2026-08-22 10:59:19 -05:00
heath 5e0d333c7b aargh... 2026-08-21 18:56:36 -05:00
heath 76d0fe843a allow output to STDOUT via cmdline 2026-08-21 18:32:18 -05:00
heath 8c9a79c07a clean up 2026-08-21 17:23:09 -05:00
heath f0dbaef0e4 correct copying directories 2026-08-21 17:03:41 -05:00
heath 01e471ec0f change to copy sudoers.d at the directory instead of file level 2026-08-21 16:45:22 -05:00
8 changed files with 63 additions and 121 deletions
+1 -1
View File
@@ -1,4 +1,4 @@
# ---> Ansible # ---> Ansible
*.retry *.retry
EXAMPLES EXAMPLES
roles
+1
View File
@@ -1,6 +1,7 @@
[defaults] [defaults]
inventory = ./inventory inventory = ./inventory
roles_path = ./roles
remote_user = hpf-ans remote_user = hpf-ans
host_key_checking = False host_key_checking = False
+10 -106
View File
@@ -43,54 +43,25 @@
system: true system: true
gid: 701 gid: 701
- name: Make sure /etc/sudoers.d exists - name: Get /etc/sudoers.d
become: true
ansible.builtin.file:
path: /etc/sudoers.d
state: directory
owner: root
group: root
mode: u=rwx,go=
- name: Get /etc/sudoers.d/hpf
become: true become: true
ansible.builtin.copy: ansible.builtin.copy:
src: etc/sudoers.d/hpf src: etc/sudoers.d
dest: /etc/sudoers.d/hpf dest: /etc/
owner: root owner: root
group: root group: root
mode: u=rw,go= directory_mode: u=rwx,go=
mode: u=rw,g=r,o=
backup: true backup: true
validate: /usr/sbin/visudo -csf %s validate: /usr/sbin/visudo -csf %s
#### Configure sshd #### Configure sshd
# - name: Make sure /etc/ssh/sshd_config.d exists
# become: true
# ansible.builtin.file:
# path: /etc/ssh/sshd_config.d
# state: directory
# owner: root
# group: root
# mode: u=rwx,go=rx
#
# - name: Get /etc/ssh/sshd_config.d/hpf.conf
# become: true
# ansible.builtin.copy:
# src: etc/ssh/sshd_config.d/hpf.conf
# dest: /etc/ssh/sshd_config.d/hpf.conf
# owner: root
# group: root
# mode: u=rwx,go=rx
# backup: true
# validate: /usr/sbin/sshd -t -f %s
# notify: Restart sshd
- name: Get /etc/ssh/sshd_config.d - name: Get /etc/ssh/sshd_config.d
become: true become: true
ansible.builtin.copy: ansible.builtin.copy:
src: etc/ssh/sshd_config.d/ src: etc/ssh/sshd_config.d
dest: /etc/ssh/ dest: /etc/ssh/
owner: root owner: root
group: root group: root
@@ -100,60 +71,13 @@
validate: /usr/sbin/sshd -t -f %s validate: /usr/sbin/sshd -t -f %s
notify: Restart sshd notify: Restart sshd
#### Configure /etc/skel #### Configure /etc/skel
# - name: Make sure /etc/skel/.profile.d exists
# become: true
# ansible.builtin.file:
# path: /etc/skel/.profile.d
# state: directory
# owner: root
# group: root
# mode: u=rwx,go=
# - name: Get /etc/skel/.profile.d/ansible-venv.sh
# become: true
# ansible.builtin.copy:
# src: etc/skel/.profile.d/ansible-venv.sh
# dest: /etc/skel/.profile.d/ansible-venv.sh
# owner: root
# group: root
# mode: u=rw,go=
# backup: true
# - name: Get /etc/skel/.profile
# become: true
# ansible.builtin.copy:
# src: etc/skel/.profile
# dest: /etc/skel/.profile
# owner: root
# group: root
# mode: u=rw,go=
# backup: true
# - name: Make sure /etc/skel/.bashrc.d exists
# become: true
# ansible.builtin.file:
# path: /etc/skel/.bashrc.d
# state: directory
# owner: root
# group: root
# mode: u=rwx,go=
# - name: Get /etc/skel/.bashrc
# become: true
# ansible.builtin.copy:
# src: etc/skel/.bashrc
# dest: /etc/skel/.bashrc
# owner: root
# group: root
# mode: u=rw,go=
# backup: true
- name: Get /etc/skel - name: Get /etc/skel
become: true become: true
ansible.builtin.copy: ansible.builtin.copy:
src: etc/skel/ src: etc/skel
dest: /etc/ dest: /etc/
owner: root owner: root
group: root group: root
@@ -161,6 +85,7 @@
mode: u=rw,go= mode: u=rw,go=
backup: true backup: true
#### User: root #### User: root
- name: Set root's authorized_keys - name: Set root's authorized_keys
@@ -232,7 +157,7 @@
become: true become: true
become_user: hpf-ans become_user: hpf-ans
ansible.builtin.copy: ansible.builtin.copy:
src: home/hpf-ans/bin/ src: home/hpf-ans/bin
dest: $HOME/ dest: $HOME/
owner: hpf-ans owner: hpf-ans
group: hpf-ans group: hpf-ans
@@ -303,27 +228,6 @@
#### ansible-pull.sh #### ansible-pull.sh
# - name: Make sure /home/hpf-ans/bin exists
# become: true
# become_user: hpf-ans
# ansible.builtin.file:
# path: $HOME/bin
# state: directory
# owner: hpf-ans
# group: hpf-ans
# mode: u=rwx,go=
# - name: Get /home/hpf-ans/bin/ansible-pull.sh
# become: true
# become_user: hpf-ans
# ansible.builtin.copy:
# src: home/hpf-ans/bin/ansible-pull.sh
# dest: $HOME/bin/ansible-pull.sh
# owner: hpf-ans
# group: hpf-ans
# mode: u=rwx,go=
# backup: true
- name: Make sure log directory exists - name: Make sure log directory exists
become: true become: true
ansible.builtin.file: ansible.builtin.file:
+18 -9
View File
@@ -8,14 +8,20 @@ SCRIPT_NAME="$(basename "${0}")"
GIT_REPO_BRANCH="${GIT_REPO_BRANCH:-production}" GIT_REPO_BRANCH="${GIT_REPO_BRANCH:-production}"
OIC_FLAG="--only-if-changed" OIC_FLAG="--only-if-changed"
VERBOSE_FLAG="--verbose" VERBOSE_FLAG="--verbose"
DEBUG_FLAG="false"
# - Process command line # - Process command line
while [ $# -gt 0 ]; do while [ $# -gt 0 ]; do
case "$1" in case "$1" in
-h|--help) -h|--help)
echo "Usage: $0 [--branch <branch name>]" echo "Usage: $0 [--branch <branch name>] [--force] [--quiet] [-- <ansible-pull args>]"
exit 0 exit 0
;; ;;
-d|--debug)
VERBOSE_FLAG="-vvv"
DEBUG_FLAG="true"
shift 1
;;
-b|--branch) -b|--branch)
shift 1 shift 1
if [ $# -eq 0 ] ; then echo "${SCRIPT_NAME}: ERROR - Branch not specified." ; exit 1 ; fi if [ $# -eq 0 ] ; then echo "${SCRIPT_NAME}: ERROR - Branch not specified." ; exit 1 ; fi
@@ -23,12 +29,12 @@ while [ $# -gt 0 ]; do
shift 1 shift 1
;; ;;
-f|--force) -f|--force)
shift 1
OIC_FLAG="" OIC_FLAG=""
shift 1
;; ;;
-q|--quiet) -q|--quiet)
shift 1
VERBOSE_FLAG="" VERBOSE_FLAG=""
shift 1
;; ;;
--) --)
shift 1 shift 1
@@ -48,25 +54,28 @@ GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
GIT_REPO="${GIT_REPO_BASE}.git" GIT_REPO="${GIT_REPO_BASE}.git"
# - Include ansible virtual environment (in case not already done - we don't know how we're being run) # - Include ansible virtual environment (in case not already done - we don't know how we're being run)
VIRTUAL_ENV_DISABLE_PROMPT=true
. "${VENV_ACTIVATE_SCRIPT}" . "${VENV_ACTIVATE_SCRIPT}"
# - If we can't get a lock, don't proceed # - If we can't get a lock, don't proceed
if ! exec 9>"${LOCK_FILE}" ; then if ! exec 9>"${LOCK_FILE}" ; then
echo "${SCRIPT_NAME}: ERROR - Unable to open the lock file (${LOCK_FILE})! Exiting..." >&2 echo "${SCRIPT_NAME}: ERROR - Unable to open the lock file (${LOCK_FILE})! Exiting..." >&2
exit 10 exit 10
fi fi
if ! flock -n 9 ; then if ! flock -n 9 ; then
echo "${SCRIPT_NAME}: ERROR - Another copy is already running! Exiting..." >&2 echo "${SCRIPT_NAME}: ERROR - Another copy is already running! Exiting..." >&2
exit 11 exit 11
fi fi
# - Append all further STDOUT and STDERR to the log file # - If debugging requested or running from a terminal . . .
exec >>"${LOG_FILE}" 2>&1 if [ "${DEBUG_FLAG}" = "true" ] || test -t 0 ; then
exec > >(tee -a "${LOG_FILE}") 2>&1 # - send STDOUT and STDERR to both STDOUT and the log file
else
exec >>"${LOG_FILE}" 2>&1 # - send STDOUT and STDERR to the log file only
fi
# - Log that we've gotten this far # - Log that we've gotten this far
echo echo
echo "${SCRIPT_NAME}: $(date "+%Y-%m-%d %H:%M:%S") ----------------------------------------" echo "${SCRIPT_NAME}: ------------------------------- $(date "+%Y-%m-%d %H:%M:%S") -------------------------------"
# - Do our work # - Do our work
ansible-pull ${OIC_FLAG} ${VERBOSE_FLAG} --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}" ansible-pull ${OIC_FLAG} ${VERBOSE_FLAG} --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}"
+18
View File
@@ -0,0 +1,18 @@
---
- name: Configure time synchronization
hosts: all
become: true
vars:
timesync_ntp_provider: chrony
timesync_ntp_servers:
- hostname: 0.north-america.pool.ntp.org
iburst: true
- hostname: 1.north-america.pool.ntp.org
iburst: true
- hostname: 2.north-america.pool.ntp.org
iburst: true
timesync_chrony_custom_settings:
- "logdir /var/log/chrony"
- "log measurements statistics tracking"
roles:
- linux-system-roles.timesync
+4
View File
@@ -0,0 +1,4 @@
---
roles:
- name: linux-system-roles.timesync
version: 1.14.1
-5
View File
@@ -6,11 +6,6 @@ Manually on each system:
iris.heath.hpetersenfamily.com admin-a.hpetersenfamily.com core.mary.hpetersenfamily.com iris.heath.hpetersenfamily.com admin-a.hpetersenfamily.com core.mary.hpetersenfamily.com
* ansible-pull.sh
* debug flag to print to stdout
* bootstrap.yml
* change to copy files/home/hpf-ans/bin with all it's contents
heath heath
authorized_keys: authorized_keys:
+11
View File
@@ -0,0 +1,11 @@
#!/usr/bin/env bash
send_some_output() {
echo "hello"
echo "here"
echo "goodbye"
}
exec > >(tee -a ./x.out) 2>&1
send_some_output >&2