Compare commits

..

14 Commits

8 changed files with 109 additions and 23 deletions
+29 -6
View File
@@ -1,5 +1,22 @@
#!/bin/sh #!/bin/sh
####
#### WARNING:
####
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
#### exact same things with the following exceptions:
####
#### * bootstrap.sh
#### - at the end it should run ansible-pull.sh against bootstrap.yml
####
#### * bootstrap.yml
#### - at the end it should configure cron to schedule ansible-pull.sh
####
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
#### ! Make sure to keep them in sync !
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
####
# #
#### VARIABLES #### VARIABLES
@@ -8,7 +25,7 @@
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible" GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
GIT_REPO="${GIT_REPO_BASE}.git" GIT_REPO="${GIT_REPO_BASE}.git"
GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/files/etc_sudoers_d_hpf" GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/files/etc_sudoers_d_hpf"
GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/files/home_hpf_ans_bin_ansible-pull.sh" GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/files/home_hpf_ans_bin_ansible_pull_sh"
ETC_sudoers_d_hpf="/etc/sudoers.d/hpf" ETC_sudoers_d_hpf="/etc/sudoers.d/hpf"
@@ -19,6 +36,8 @@ HPF_ANS_activate="${HPF_ANS_ansible_venv}/bin/activate"
HPF_ANS_bin="\${HOME}/bin" HPF_ANS_bin="\${HOME}/bin"
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh" HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
ANSIBLE_PULL_SH_LOG_DIR="/var/log/ansible-pull.sh"
# #
#### FUNCTIONS #### FUNCTIONS
@@ -102,14 +121,14 @@ system_groupadd hpf-sudo-np 701
rm "${ETC_sudoers_d_hpf}" 2>/dev/null rm "${ETC_sudoers_d_hpf}" 2>/dev/null
curl -o "$ETC_sudoers_d_hpf" "${GIT_REPO_sudoers_d_hpf}" curl -o "$ETC_sudoers_d_hpf" "${GIT_REPO_sudoers_d_hpf}"
chown root:root "${ETC_sudoers_d_hpf}" chown root:root "${ETC_sudoers_d_hpf}"
chmod u=rw,g=r,o= "${ETC_sudoers_d_hpf}" chmod u=rw,go= "${ETC_sudoers_d_hpf}"
# Create the hpf-ans user # Create the hpf-ans user
system_useradd hpf-ans 800 system_useradd hpf-ans 800
add_groups_to_user hpf-sudo-np hpf-ans add_groups_to_user hpf-sudo-np hpf-ans
# Make sure .ansible-venv exists # Make sure .ansible-venv exists
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then python3 -m venv \"${HPF_ANS_ansible_venv}\" ; fi" as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi"
# Make sure pip is up to date # Make sure pip is up to date
as_hpf_ans "pip install --upgrade pip" as_hpf_ans "pip install --upgrade pip"
@@ -119,12 +138,16 @@ as_hpf_ans "pip install --upgrade ansible"
# Make sure bin exists # Make sure bin exists
as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\"" as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\""
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod ug=rwx,o= \"${HPF_ANS_bin}\"" as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\""
# Create ~hpf-ans/bin/ansible-pull.sh # Create ~hpf-ans/bin/ansible-pull.sh
as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null" as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null"
as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\"" as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\""
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod ug=rwx,o= \"${HPF_ANS_ansible_pull_sh}\"" as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\""
# Make sure log directory exists
mkdir -p "${ANSIBLE_PULL_SH_LOG_DIR}"
chown hpf-ans:root "${ANSIBLE_PULL_SH_LOG_DIR}"; chmod ug=rwx,o= "${ANSIBLE_PULL_SH_LOG_DIR}"
# Run ansible-pull to finish up # Run ansible-pull to finish up
as_hpf_ans "bin/ansible-pull.sh" as_hpf_ans "bin/ansible-pull.sh bootstrap.yml"
+37 -2
View File
@@ -1,5 +1,23 @@
--- ---
####
#### WARNING:
####
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
#### exact same things with the following exceptions:
####
#### * bootstrap.sh
#### - at the end it should run ansible-pull.sh against bootstrap.yml
####
#### * bootstrap.yml
#### - at the end it should configure cron to schedule ansible-pull.sh
####
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
#### ! Make sure to keep them in sync !
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
####
# Update software repositories here # Update software repositories here
# Change the following to work with multiple distros # Change the following to work with multiple distros
@@ -74,10 +92,10 @@
ansible.builtin.pip: ansible.builtin.pip:
name: ansible name: ansible
virtualenv: $HOME/.ansible-venv virtualenv: $HOME/.ansible-venv
extra_args: --upgrade extra_args: "--upgrade"
become: no become: no
-name: Make sure bin directory exists - name: Make sure bin directory exists
ansible.builtin.file: ansible.builtin.file:
path: $HOME/bin path: $HOME/bin
state: directory state: directory
@@ -93,4 +111,21 @@
owner: hpf-ans owner: hpf-ans
group: hpf-ans group: hpf-ans
mode: u=rwx,go= mode: u=rwx,go=
backup: true
become: no
- name: Make sure log directory exists
ansible.builtin.file:
path: /var/log/ansible-pull.sh
state: directory
owner: hpf-ans
group: root
mode: ug=rwx,o=
# - name: Create ansible-pull.sh crontab entry
# ansible.builtin.cron:
# name: "ansible-pull"
# minute: "*/27"
# job: $HOME/bin/ansible-pull.sh
# backup: true
# become: no
-14
View File
@@ -1,14 +0,0 @@
#!/bin/bash
source ~/.ansible-venv/bin/activate
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
GIT_REPO="${GIT_REPO_BASE}.git"
ANSIBLE_PULL_LOG="/var/log/ansible-pull.log"
echo | sudo tee -a "${ANSIBLE_PULL_LOG}"
echo -n "$(basename "${0}"): " | sudo tee -a "${ANSIBLE_PULL_LOG}"
date "+%Y-%m-%d %H:%M:%S" | sudo tee -a "${ANSIBLE_PULL_LOG}"
ansible-pull --only-if-changed -U "${GIT_REPO}" 2>&1 | sudo tee -a "${ANSIBLE_PULL_LOG}"
+27
View File
@@ -0,0 +1,27 @@
#!/bin/bash
# - Fix branch to check out
. "${HOME}/.ansible-venv/bin/activate"
SCRIPT_NAME="$(basename "${0}")"
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
GIT_REPO="${GIT_REPO_BASE}.git"
LOG_DIR="/var/log/ansible-pull.sh"
LOG_FILE="${LOG_DIR}/ansible-pull.sh.log"
LOCK_FILE="/tmp/ansible-pull.sh.lock"
# - Redirect all further output to the log file
exec >>"${LOG_FILE}" 2>&1
# - Log that we've gotten this far
echo -n "$(basename "${0}"): $(date "+%Y-%m-%d %H:%M:%S")"
# - If we can't lock the lock file, don't proceed
exec 9>"${LOCK_FILE}"
if ! flock -n 9 ; then echo " - ERROR - Another copy of ${SCRIPT_NAME} is already running! Exiting..." ; exit 1 ; fi
# - Do our work
echo
ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout main "${@}"
+2
View File
@@ -0,0 +1,2 @@
ansible_pull_branch: main
ntp_server: 0.north-america.pool.ntp.org
-1
View File
@@ -1 +0,0 @@
ntp_server: 0.north-america.pool.ntp.org
@@ -0,0 +1 @@
ansible_pull_branch: development
+13
View File
@@ -0,0 +1,13 @@
---
- name: dummy
hosts: all
become: no
tasks:
- name: Display host's value of ansible_pull_branch
ansible.builtin.debug:
var: ansible_pull_branch