Compare commits
15 Commits
| Author | SHA256 | Date | |
|---|---|---|---|
| 8d40ddc636 | |||
| 5706fc9854 | |||
| 5e0d333c7b | |||
| 76d0fe843a | |||
| 8c9a79c07a | |||
| f0dbaef0e4 | |||
| 01e471ec0f | |||
| 6cdfecfd8d | |||
| 4665903b01 | |||
| a935e484d9 | |||
| 2fa109335f | |||
| f9ee2fcc05 | |||
| 316e6018fc | |||
| ed627fbd19 | |||
| 7859a609eb |
+1
-1
@@ -1,4 +1,4 @@
|
|||||||
# ---> Ansible
|
# ---> Ansible
|
||||||
*.retry
|
*.retry
|
||||||
EXAMPLES
|
EXAMPLES
|
||||||
|
roles
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
[defaults]
|
[defaults]
|
||||||
|
|
||||||
inventory = ./inventory
|
inventory = ./inventory
|
||||||
|
roles_path = ./roles
|
||||||
|
|
||||||
remote_user = hpf-ans
|
remote_user = hpf-ans
|
||||||
host_key_checking = False
|
host_key_checking = False
|
||||||
|
|||||||
+35
-71
@@ -18,7 +18,6 @@
|
|||||||
state: present
|
state: present
|
||||||
pkg:
|
pkg:
|
||||||
- bash
|
- bash
|
||||||
- curl
|
|
||||||
- python3
|
- python3
|
||||||
- python3-pip
|
- python3-pip
|
||||||
- python3-venv
|
- python3-venv
|
||||||
@@ -44,46 +43,30 @@
|
|||||||
system: true
|
system: true
|
||||||
gid: 701
|
gid: 701
|
||||||
|
|
||||||
- name: Make sure /etc/sudoers.d exists
|
- name: Get /etc/sudoers.d
|
||||||
become: true
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: /etc/sudoers.d
|
|
||||||
state: directory
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: u=rwx,go=
|
|
||||||
|
|
||||||
- name: Get /etc/sudoers.d/hpf
|
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
src: etc/sudoers.d/hpf
|
src: etc/sudoers.d
|
||||||
dest: /etc/sudoers.d/hpf
|
dest: /etc/
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: u=rw,go=
|
directory_mode: u=rwx,go=
|
||||||
|
mode: u=rw,g=r,o=
|
||||||
backup: true
|
backup: true
|
||||||
validate: /usr/sbin/visudo -csf %s
|
validate: /usr/sbin/visudo -csf %s
|
||||||
|
|
||||||
|
|
||||||
#### Configure sshd
|
#### Configure sshd
|
||||||
|
|
||||||
- name: Make sure /etc/ssh/sshd_config.d exists
|
- name: Get /etc/ssh/sshd_config.d
|
||||||
become: true
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: /etc/ssh/sshd_config.d
|
|
||||||
state: directory
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: u=rwx,go=rx
|
|
||||||
|
|
||||||
- name: Get /etc/ssh/sshd_config.d/hpf.conf
|
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
src: etc/ssh/sshd_config.d/hpf.conf
|
src: etc/ssh/sshd_config.d
|
||||||
dest: /etc/ssh/sshd_config.d/hpf.conf
|
dest: /etc/ssh/
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: u=rwx,go=rx
|
directory_mode: u=rwx,go=rx
|
||||||
|
mode: u=rw,go=r
|
||||||
backup: true
|
backup: true
|
||||||
validate: /usr/sbin/sshd -t -f %s
|
validate: /usr/sbin/sshd -t -f %s
|
||||||
notify: Restart sshd
|
notify: Restart sshd
|
||||||
@@ -91,32 +74,14 @@
|
|||||||
|
|
||||||
#### Configure /etc/skel
|
#### Configure /etc/skel
|
||||||
|
|
||||||
- name: Make sure /etc/skel/.profile.d exists
|
- name: Get /etc/skel
|
||||||
become: true
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: /etc/skel/.profile.d
|
|
||||||
state: directory
|
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: u=rwx,go=
|
|
||||||
|
|
||||||
- name: Get /etc/skel/.profile.d/ansible-venv.sh
|
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
src: etc/skel/.profile.d/ansible-venv.sh
|
src: etc/skel
|
||||||
dest: /etc/skel/.profile.d/ansible-venv.sh
|
dest: /etc/
|
||||||
owner: root
|
|
||||||
group: root
|
|
||||||
mode: u=rw,go=
|
|
||||||
backup: true
|
|
||||||
|
|
||||||
- name: Get /etc/skel/.profile
|
|
||||||
become: true
|
|
||||||
ansible.builtin.copy:
|
|
||||||
src: etc/skel/.profile
|
|
||||||
dest: /etc/skel/.profile
|
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
|
directory_mode: u=rwx,go=rx
|
||||||
mode: u=rw,go=
|
mode: u=rw,go=
|
||||||
backup: true
|
backup: true
|
||||||
|
|
||||||
@@ -132,6 +97,12 @@
|
|||||||
loop:
|
loop:
|
||||||
- files/ssh-keys/heath.pub
|
- files/ssh-keys/heath.pub
|
||||||
|
|
||||||
|
- name: Lock the root user's password
|
||||||
|
become: true
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: root
|
||||||
|
password_lock: true
|
||||||
|
|
||||||
|
|
||||||
#### User: first
|
#### User: first
|
||||||
|
|
||||||
@@ -180,6 +151,19 @@
|
|||||||
append: true
|
append: true
|
||||||
create_home: true
|
create_home: true
|
||||||
shell: /usr/bin/bash
|
shell: /usr/bin/bash
|
||||||
|
password_lock: true
|
||||||
|
|
||||||
|
- name: Get /home/hpf-ans/bin
|
||||||
|
become: true
|
||||||
|
become_user: hpf-ans
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: home/hpf-ans/bin
|
||||||
|
dest: $HOME/
|
||||||
|
owner: hpf-ans
|
||||||
|
group: hpf-ans
|
||||||
|
directory_mode: u=rwx,go=
|
||||||
|
mode: u=rwx,go=
|
||||||
|
backup: true
|
||||||
|
|
||||||
- name: Set hpf-ans's authorized_keys
|
- name: Set hpf-ans's authorized_keys
|
||||||
become: true
|
become: true
|
||||||
@@ -230,6 +214,7 @@
|
|||||||
append: true
|
append: true
|
||||||
create_home: true
|
create_home: true
|
||||||
shell: /usr/bin/bash
|
shell: /usr/bin/bash
|
||||||
|
password: '$y$j9T$.NJVASBkVLnvqgznpcpdx1$7poH23pou7VHti3IfvDzwECdLtTcMercYNCeevgV.xC'
|
||||||
|
|
||||||
- name: Set heath's authorized_keys
|
- name: Set heath's authorized_keys
|
||||||
become: true
|
become: true
|
||||||
@@ -243,27 +228,6 @@
|
|||||||
|
|
||||||
#### ansible-pull.sh
|
#### ansible-pull.sh
|
||||||
|
|
||||||
- name: Make sure /home/hpf-ans/bin exists
|
|
||||||
become: true
|
|
||||||
become_user: hpf-ans
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: $HOME/bin
|
|
||||||
state: directory
|
|
||||||
owner: hpf-ans
|
|
||||||
group: hpf-ans
|
|
||||||
mode: u=rwx,go=
|
|
||||||
|
|
||||||
- name: Get /home/hpf-ans/bin/ansible-pull.sh
|
|
||||||
become: true
|
|
||||||
become_user: hpf-ans
|
|
||||||
ansible.builtin.copy:
|
|
||||||
src: home/hpf-ans/bin/ansible-pull.sh
|
|
||||||
dest: $HOME/bin/ansible-pull.sh
|
|
||||||
owner: hpf-ans
|
|
||||||
group: hpf-ans
|
|
||||||
mode: u=rwx,go=
|
|
||||||
backup: true
|
|
||||||
|
|
||||||
- name: Make sure log directory exists
|
- name: Make sure log directory exists
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
@@ -271,7 +235,7 @@
|
|||||||
state: directory
|
state: directory
|
||||||
owner: hpf-ans
|
owner: hpf-ans
|
||||||
group: root
|
group: root
|
||||||
mode: u=rwx,go=
|
mode: u=rwx,g=r,o=
|
||||||
|
|
||||||
# - name: Create ansible-pull.sh crontab entry
|
# - name: Create ansible-pull.sh crontab entry
|
||||||
# become: true
|
# become: true
|
||||||
|
|||||||
@@ -0,0 +1,119 @@
|
|||||||
|
# ~/.bashrc: executed by bash(1) for non-login shells.
|
||||||
|
# see /usr/share/doc/bash/examples/startup-files (in the package bash-doc)
|
||||||
|
# for examples
|
||||||
|
|
||||||
|
# If not running interactively, don't do anything
|
||||||
|
case $- in
|
||||||
|
*i*) ;;
|
||||||
|
*) return;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
# don't put duplicate lines or lines starting with space in the history.
|
||||||
|
# See bash(1) for more options
|
||||||
|
HISTCONTROL=ignoreboth
|
||||||
|
|
||||||
|
# append to the history file, don't overwrite it
|
||||||
|
shopt -s histappend
|
||||||
|
|
||||||
|
# for setting history length see HISTSIZE and HISTFILESIZE in bash(1)
|
||||||
|
HISTSIZE=1000
|
||||||
|
HISTFILESIZE=2000
|
||||||
|
|
||||||
|
# check the window size after each command and, if necessary,
|
||||||
|
# update the values of LINES and COLUMNS.
|
||||||
|
shopt -s checkwinsize
|
||||||
|
|
||||||
|
# If set, the pattern "**" used in a pathname expansion context will
|
||||||
|
# match all files and zero or more directories and subdirectories.
|
||||||
|
#shopt -s globstar
|
||||||
|
|
||||||
|
# make less more friendly for non-text input files, see lesspipe(1)
|
||||||
|
#[ -x /usr/bin/lesspipe ] && eval "$(SHELL=/bin/sh lesspipe)"
|
||||||
|
|
||||||
|
# set variable identifying the chroot you work in (used in the prompt below)
|
||||||
|
if [ -z "${debian_chroot:-}" ] && [ -r /etc/debian_chroot ]; then
|
||||||
|
debian_chroot=$(cat /etc/debian_chroot)
|
||||||
|
fi
|
||||||
|
|
||||||
|
# set a fancy prompt (non-color, unless we know we "want" color)
|
||||||
|
case "$TERM" in
|
||||||
|
xterm-color|*-256color) color_prompt=yes;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
# uncomment for a colored prompt, if the terminal has the capability; turned
|
||||||
|
# off by default to not distract the user: the focus in a terminal window
|
||||||
|
# should be on the output of commands, not on the prompt
|
||||||
|
#force_color_prompt=yes
|
||||||
|
|
||||||
|
if [ -n "$force_color_prompt" ]; then
|
||||||
|
if [ -x /usr/bin/tput ] && tput setaf 1 >&/dev/null; then
|
||||||
|
# We have color support; assume it's compliant with Ecma-48
|
||||||
|
# (ISO/IEC-6429). (Lack of such support is extremely rare, and such
|
||||||
|
# a case would tend to support setf rather than setaf.)
|
||||||
|
color_prompt=yes
|
||||||
|
else
|
||||||
|
color_prompt=
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ "$color_prompt" = yes ]; then
|
||||||
|
PS1='${debian_chroot:+($debian_chroot)}\[\033[01;32m\]\u@\h\[\033[00m\]:\[\033[01;34m\]\w\[\033[00m\]\$ '
|
||||||
|
else
|
||||||
|
PS1='${debian_chroot:+($debian_chroot)}\u@\h:\w\$ '
|
||||||
|
fi
|
||||||
|
unset color_prompt force_color_prompt
|
||||||
|
|
||||||
|
# If this is an xterm set the title to user@host:dir
|
||||||
|
case "$TERM" in
|
||||||
|
xterm*|rxvt*)
|
||||||
|
PS1="\[\e]0;${debian_chroot:+($debian_chroot)}\u@\h: \w\a\]$PS1"
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
# enable color support of ls and also add handy aliases
|
||||||
|
if [ -x /usr/bin/dircolors ]; then
|
||||||
|
test -r ~/.dircolors && eval "$(dircolors -b ~/.dircolors)" || eval "$(dircolors -b)"
|
||||||
|
alias ls='ls --color=auto'
|
||||||
|
#alias dir='dir --color=auto'
|
||||||
|
#alias vdir='vdir --color=auto'
|
||||||
|
|
||||||
|
#alias grep='grep --color=auto'
|
||||||
|
#alias fgrep='fgrep --color=auto'
|
||||||
|
#alias egrep='egrep --color=auto'
|
||||||
|
fi
|
||||||
|
|
||||||
|
# colored GCC warnings and errors
|
||||||
|
#export GCC_COLORS='error=01;31:warning=01;35:note=01;36:caret=01;32:locus=01:quote=01'
|
||||||
|
|
||||||
|
# some more ls aliases
|
||||||
|
#alias ll='ls -l'
|
||||||
|
#alias la='ls -A'
|
||||||
|
#alias l='ls -CF'
|
||||||
|
|
||||||
|
# Alias definitions.
|
||||||
|
# You may want to put all your additions into a separate file like
|
||||||
|
# ~/.bash_aliases, instead of adding them here directly.
|
||||||
|
# See /usr/share/doc/bash-doc/examples in the bash-doc package.
|
||||||
|
|
||||||
|
if [ -f ~/.bash_aliases ]; then
|
||||||
|
. ~/.bash_aliases
|
||||||
|
fi
|
||||||
|
|
||||||
|
# enable programmable completion features (you don't need to enable
|
||||||
|
# this, if it's already enabled in /etc/bash.bashrc and /etc/profile
|
||||||
|
# sources /etc/bash.bashrc).
|
||||||
|
if ! shopt -oq posix; then
|
||||||
|
if [ -f /usr/share/bash-completion/bash_completion ]; then
|
||||||
|
. /usr/share/bash-completion/bash_completion
|
||||||
|
elif [ -f /etc/bash_completion ]; then
|
||||||
|
. /etc/bash_completion
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ -d "$HOME/.bashrc.d" ] ; then
|
||||||
|
for bashrc_script in $HOME/.bashrc.d/*.sh ; do
|
||||||
|
. "${bashrc_script}"
|
||||||
|
done
|
||||||
|
fi
|
||||||
@@ -31,4 +31,3 @@ if [ -d "$HOME/.profile.d" ] ; then
|
|||||||
. "${profile_script}"
|
. "${profile_script}"
|
||||||
done
|
done
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
|||||||
@@ -1,16 +1,27 @@
|
|||||||
#!/usr/bin/env bash
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
if [ -r /etc/ansible-pull.sh.conf ] ; then
|
||||||
|
. /etc/ansible-pull.sh.conf
|
||||||
|
fi
|
||||||
|
|
||||||
SCRIPT_NAME="$(basename "${0}")"
|
SCRIPT_NAME="$(basename "${0}")"
|
||||||
GIT_REPO_BRANCH="production"
|
GIT_REPO_BRANCH="${GIT_REPO_BRANCH:-production}"
|
||||||
OIC_FLAG="--only-if-changed"
|
OIC_FLAG="--only-if-changed"
|
||||||
|
VERBOSE_FLAG="--verbose"
|
||||||
|
DEBUG_FLAG="false"
|
||||||
|
|
||||||
# - Process command line
|
# - Process command line
|
||||||
while [ $# -gt 0 ]; do
|
while [ $# -gt 0 ]; do
|
||||||
case "$1" in
|
case "$1" in
|
||||||
-h|--help)
|
-h|--help)
|
||||||
echo "Usage: $0 [--branch <branch name>]"
|
echo "Usage: $0 [--branch <branch name>] [--force] [--quiet] [-- <ansible-pull args>]"
|
||||||
exit 0
|
exit 0
|
||||||
;;
|
;;
|
||||||
|
-d|--debug)
|
||||||
|
VERBOSE_FLAG="-vvv"
|
||||||
|
DEBUG_FLAG="true"
|
||||||
|
shift 1
|
||||||
|
;;
|
||||||
-b|--branch)
|
-b|--branch)
|
||||||
shift 1
|
shift 1
|
||||||
if [ $# -eq 0 ] ; then echo "${SCRIPT_NAME}: ERROR - Branch not specified." ; exit 1 ; fi
|
if [ $# -eq 0 ] ; then echo "${SCRIPT_NAME}: ERROR - Branch not specified." ; exit 1 ; fi
|
||||||
@@ -18,8 +29,12 @@ while [ $# -gt 0 ]; do
|
|||||||
shift 1
|
shift 1
|
||||||
;;
|
;;
|
||||||
-f|--force)
|
-f|--force)
|
||||||
shift 1
|
|
||||||
OIC_FLAG=""
|
OIC_FLAG=""
|
||||||
|
shift 1
|
||||||
|
;;
|
||||||
|
-q|--quiet)
|
||||||
|
VERBOSE_FLAG=""
|
||||||
|
shift 1
|
||||||
;;
|
;;
|
||||||
--)
|
--)
|
||||||
shift 1
|
shift 1
|
||||||
@@ -39,25 +54,28 @@ GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
|||||||
GIT_REPO="${GIT_REPO_BASE}.git"
|
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||||
|
|
||||||
# - Include ansible virtual environment (in case not already done - we don't know how we're being run)
|
# - Include ansible virtual environment (in case not already done - we don't know how we're being run)
|
||||||
VIRTUAL_ENV_DISABLE_PROMPT=true
|
|
||||||
. "${VENV_ACTIVATE_SCRIPT}"
|
. "${VENV_ACTIVATE_SCRIPT}"
|
||||||
|
|
||||||
# - If we can't get a lock, don't proceed
|
# - If we can't get a lock, don't proceed
|
||||||
if ! exec 9>"${LOCK_FILE}" ; then
|
if ! exec 9>"${LOCK_FILE}" ; then
|
||||||
echo "${SCRIPT_NAME}: ERROR - Unable to open the lock file (${LOCK_FILE})! Exiting..." >&2
|
echo "${SCRIPT_NAME}: ERROR - Unable to open the lock file (${LOCK_FILE})! Exiting..." >&2
|
||||||
exit 10
|
exit 10
|
||||||
fi
|
fi
|
||||||
if ! flock -n 9 ; then
|
if ! flock -n 9 ; then
|
||||||
echo "${SCRIPT_NAME}: ERROR - Another copy is already running! Exiting..." >&2
|
echo "${SCRIPT_NAME}: ERROR - Another copy is already running! Exiting..." >&2
|
||||||
exit 11
|
exit 11
|
||||||
fi
|
fi
|
||||||
|
|
||||||
# - Append all further STDOUT and STDERR to the log file
|
# - If debugging requested or running from a terminal . . .
|
||||||
exec >>"${LOG_FILE}" 2>&1
|
if [ "${DEBUG_FLAG}" = "true" ] || test -t 0 ; then
|
||||||
|
exec > >(tee -a "${LOG_FILE}") 2>&1 # - send STDOUT and STDERR to both STDOUT and the log file
|
||||||
|
else
|
||||||
|
exec >>"${LOG_FILE}" 2>&1 # - send STDOUT and STDERR to the log file only
|
||||||
|
fi
|
||||||
|
|
||||||
# - Log that we've gotten this far
|
# - Log that we've gotten this far
|
||||||
echo
|
echo
|
||||||
echo "${SCRIPT_NAME}: $(date "+%Y-%m-%d %H:%M:%S") ----------------------------------------"
|
echo "${SCRIPT_NAME}: ------------------------------- $(date "+%Y-%m-%d %H:%M:%S") -------------------------------"
|
||||||
|
|
||||||
# - Do our work
|
# - Do our work
|
||||||
ansible-pull ${OIC_FLAG} --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}"
|
ansible-pull ${OIC_FLAG} ${VERBOSE_FLAG} --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}"
|
||||||
@@ -8,6 +8,11 @@ fi
|
|||||||
ANSIBLE_OS_FAMILY="${1}"
|
ANSIBLE_OS_FAMILY="${1}"
|
||||||
shift
|
shift
|
||||||
|
|
||||||
|
if [ "${#}" -ne 0 ] ; then
|
||||||
|
echo "ERROR - unknown command line parameter specified." >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
|
||||||
useradd_D() {
|
useradd_D() {
|
||||||
|
|
||||||
case "${ANSIBLE_OS_FAMILY}" in
|
case "${ANSIBLE_OS_FAMILY}" in
|
||||||
@@ -25,11 +30,10 @@ useradd_D() {
|
|||||||
}
|
}
|
||||||
|
|
||||||
user_vars() {
|
user_vars() {
|
||||||
useradd_D | sed 's/.*=/hpf_fact_\L&/'
|
useradd_D | sed 's/.*=/\L&/'
|
||||||
}
|
}
|
||||||
|
|
||||||
#echo '{"hpf":'
|
(
|
||||||
#(user_vars; ) | jo
|
user_vars
|
||||||
#echo '}'
|
) | jo
|
||||||
|
|
||||||
user_vars
|
|
||||||
|
|||||||
@@ -0,0 +1,18 @@
|
|||||||
|
---
|
||||||
|
- name: Configure time synchronization
|
||||||
|
hosts: all
|
||||||
|
become: true
|
||||||
|
vars:
|
||||||
|
timesync_ntp_provider: chrony
|
||||||
|
timesync_ntp_servers:
|
||||||
|
- hostname: 0.north-america.pool.ntp.org
|
||||||
|
iburst: true
|
||||||
|
- hostname: 1.north-america.pool.ntp.org
|
||||||
|
iburst: true
|
||||||
|
- hostname: 2.north-america.pool.ntp.org
|
||||||
|
iburst: true
|
||||||
|
timesync_chrony_custom_settings:
|
||||||
|
- "logdir /var/log/chrony"
|
||||||
|
- "log measurements statistics tracking"
|
||||||
|
roles:
|
||||||
|
- linux-system-roles.timesync
|
||||||
@@ -0,0 +1,4 @@
|
|||||||
|
---
|
||||||
|
roles:
|
||||||
|
- name: linux-system-roles.timesync
|
||||||
|
version: 1.14.1
|
||||||
+9
-11
@@ -1,3 +1,11 @@
|
|||||||
|
Manually on each system:
|
||||||
|
* set hostname to fqdn
|
||||||
|
* set ansible branch if not production
|
||||||
|
* run bootstrap.yml
|
||||||
|
* update first password
|
||||||
|
|
||||||
|
iris.heath.hpetersenfamily.com admin-a.hpetersenfamily.com core.mary.hpetersenfamily.com
|
||||||
|
|
||||||
|
|
||||||
heath
|
heath
|
||||||
authorized_keys:
|
authorized_keys:
|
||||||
@@ -5,8 +13,6 @@ heath
|
|||||||
password:
|
password:
|
||||||
status: VALID
|
status: VALID
|
||||||
value: COMMON STRONG FOR ALL HOSTS
|
value: COMMON STRONG FOR ALL HOSTS
|
||||||
private_keys:
|
|
||||||
- FOR WORKSTATIONS: heath@hpetersenfamily.com # Can this even be done securely through Ansible?
|
|
||||||
first
|
first
|
||||||
authorized_keys:
|
authorized_keys:
|
||||||
- first@hpetersenfamily.com
|
- first@hpetersenfamily.com
|
||||||
@@ -14,19 +20,16 @@ first
|
|||||||
password:
|
password:
|
||||||
status: VALID
|
status: VALID
|
||||||
value: UNIQUE LONG FOR EACH HOST
|
value: UNIQUE LONG FOR EACH HOST
|
||||||
private_keys:
|
|
||||||
root
|
root
|
||||||
authorized_keys:
|
authorized_keys:
|
||||||
- heath@hpetersenfamily.com
|
- heath@hpetersenfamily.com
|
||||||
password:
|
password:
|
||||||
status: LOCKED
|
status: LOCKED
|
||||||
private_keys:
|
|
||||||
hpf-ans:
|
hpf-ans:
|
||||||
authorized_keys:
|
authorized_keys:
|
||||||
- heath@hpetersenfamily.com
|
- heath@hpetersenfamily.com
|
||||||
password:
|
password:
|
||||||
status: LOCKED
|
status: LOCKED
|
||||||
private_keys:
|
|
||||||
|
|
||||||
|
|
||||||
# Change to work with multiple distros (nothing hardcoded)
|
# Change to work with multiple distros (nothing hardcoded)
|
||||||
@@ -64,12 +67,7 @@ hpf-ans:
|
|||||||
ansible.builtin.apt:
|
ansible.builtin.apt:
|
||||||
pkg:
|
pkg:
|
||||||
- chrony
|
- chrony
|
||||||
|
|
||||||
#- name: Set host name
|
|
||||||
# ansible.builtin.hostname:
|
|
||||||
# name: ## Fully qualified domain name ##
|
|
||||||
# use: systemd
|
|
||||||
|
|
||||||
* Configure chrony
|
* Configure chrony
|
||||||
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
|
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
|
||||||
pool 0.north-america.pool.ntp.org iburst
|
pool 0.north-america.pool.ntp.org iburst
|
||||||
|
|||||||
@@ -0,0 +1,257 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
#
|
||||||
|
# Serialize bash variables to JSON output
|
||||||
|
#
|
||||||
|
# # Created
|
||||||
|
# Author: Dave Eddy <ysap@daveeddy.com>
|
||||||
|
# Date: July 09, 2026
|
||||||
|
# License: MIT
|
||||||
|
#
|
||||||
|
# # Contributors
|
||||||
|
# - Dave Eddy <ysap@daveeddy.com>
|
||||||
|
|
||||||
|
_jv-usage() {
|
||||||
|
local usage
|
||||||
|
read -r -d '' usage <<-EOF
|
||||||
|
Usage: jsonvar [-aev] [[name], ...]
|
||||||
|
|
||||||
|
Serialize bash variables to JSON output
|
||||||
|
|
||||||
|
Options
|
||||||
|
-a show all variables
|
||||||
|
-e show only exported variables
|
||||||
|
-v show only the values of the variables
|
||||||
|
-h show this message and exit
|
||||||
|
EOF
|
||||||
|
echo "$usage"
|
||||||
|
}
|
||||||
|
|
||||||
|
_jv-json-encode-string() {
|
||||||
|
local s=$1
|
||||||
|
|
||||||
|
local LC_ALL=C
|
||||||
|
local -A table=()
|
||||||
|
|
||||||
|
# we can start at 1 because bash variables can't have nul bytes in them
|
||||||
|
local hex byte esc i
|
||||||
|
for ((i = 1; i < 0x20; i++)); do
|
||||||
|
printf -v hex '%02x' "$i"
|
||||||
|
|
||||||
|
printf -v byte '%b' "\\x$hex"
|
||||||
|
printf -v esc '\\u%04x' "$i"
|
||||||
|
table[$byte]=$esc
|
||||||
|
done
|
||||||
|
|
||||||
|
table[$'\b']='\b'
|
||||||
|
table[$'\t']='\t'
|
||||||
|
table[$'\n']='\n'
|
||||||
|
table[$'\f']='\f'
|
||||||
|
table[$'\r']='\r'
|
||||||
|
|
||||||
|
table['\']='\\'
|
||||||
|
table['"']='\"'
|
||||||
|
|
||||||
|
# serialize the string
|
||||||
|
local out=''
|
||||||
|
local len=${#s}
|
||||||
|
local c
|
||||||
|
for ((i = 0; i < len; i++)); do
|
||||||
|
c=${s:i:1}
|
||||||
|
esc=${table[$c]}
|
||||||
|
|
||||||
|
if [[ -n $esc ]]; then
|
||||||
|
# lookup table matched for this byte
|
||||||
|
out+=$esc
|
||||||
|
else
|
||||||
|
# no lookup table match, byte falls through
|
||||||
|
out+=$c
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
|
||||||
|
printf '"%s"' "$out"
|
||||||
|
}
|
||||||
|
|
||||||
|
_jv-encode-variable() {
|
||||||
|
local _jv_name=$1
|
||||||
|
local -n _jv_ref=$_jv_name
|
||||||
|
local _jv_attrs=${_jv_ref@a}
|
||||||
|
|
||||||
|
case "$_jv_attrs" in
|
||||||
|
*a*) # process indexed array
|
||||||
|
echo -n '['
|
||||||
|
local _jv_value _jv_i=0
|
||||||
|
for _jv_value in "${_jv_ref[@]}"; do
|
||||||
|
((_jv_i++))
|
||||||
|
|
||||||
|
# check member type
|
||||||
|
if [[ $_jv_attrs == *i* ]]; then
|
||||||
|
printf '%d' "$_jv_value"
|
||||||
|
else
|
||||||
|
_jv-json-encode-string "$_jv_value"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if ((_jv_i < ${#_jv_ref[@]})); then
|
||||||
|
echo -n ', '
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
echo -n ']'
|
||||||
|
;;
|
||||||
|
*A*) # process associative array
|
||||||
|
echo -n '{'
|
||||||
|
local _jv_key _jv_value _jv_i=0
|
||||||
|
for _jv_key in "${!_jv_ref[@]}"; do
|
||||||
|
((_jv_i++))
|
||||||
|
|
||||||
|
_jv_value=${_jv_ref[$_jv_key]}
|
||||||
|
|
||||||
|
_jv-json-encode-string "$_jv_key"
|
||||||
|
echo -n ': '
|
||||||
|
|
||||||
|
if [[ $_jv_attrs == *i* ]]; then
|
||||||
|
printf '%d' "$_jv_value"
|
||||||
|
else
|
||||||
|
_jv-json-encode-string "$_jv_value"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if ((_jv_i < ${#_jv_ref[@]})); then
|
||||||
|
echo -n ', '
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
echo -n '}'
|
||||||
|
;;
|
||||||
|
*i*) # process integer
|
||||||
|
echo -n "$_jv_ref"
|
||||||
|
;;
|
||||||
|
*) # anything else, it's probably a string lol
|
||||||
|
_jv-json-encode-string "$_jv_ref"
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
jsonvar() {
|
||||||
|
local _jv_all='false'
|
||||||
|
local _jv_exported='false'
|
||||||
|
local _jv_value='false'
|
||||||
|
|
||||||
|
# get arguments from user
|
||||||
|
local OPTIND OPTARG _jv_opt
|
||||||
|
while getopts 'aevh' _jv_opt; do
|
||||||
|
case "$_jv_opt" in
|
||||||
|
a) _jv_all='true';;
|
||||||
|
e) _jv_exported='true';;
|
||||||
|
v) _jv_value='true';;
|
||||||
|
h) _jv-usage; return 0;;
|
||||||
|
*) _jv-usage >&2; return 2;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
shift "$((OPTIND - 1))"
|
||||||
|
|
||||||
|
local _jv_key
|
||||||
|
|
||||||
|
# figure out what variables to look at
|
||||||
|
local -a _jv_variables
|
||||||
|
if $_jv_all; then
|
||||||
|
readarray -t _jv_variables < <(compgen -v)
|
||||||
|
elif $_jv_exported; then
|
||||||
|
readarray -t _jv_variables < <(compgen -e)
|
||||||
|
else
|
||||||
|
_jv_variables=("$@")
|
||||||
|
|
||||||
|
# ensure the user gave us *something*
|
||||||
|
if (( ${#_jv_variables[@]} == 0 )); then
|
||||||
|
echo 'variable name or flag required' >&2
|
||||||
|
_jv-usage >&2
|
||||||
|
return 2
|
||||||
|
fi
|
||||||
|
|
||||||
|
# check variables given
|
||||||
|
local _jv_error='false'
|
||||||
|
for _jv_key in "${_jv_variables[@]}"; do
|
||||||
|
# warn the user if they gave us an internal name
|
||||||
|
if [[ $_jv_key == _jv_* ]]; then
|
||||||
|
echo "[error] invalid internal variable '$_jv_key'" >&2
|
||||||
|
_jv_error='true'
|
||||||
|
fi
|
||||||
|
|
||||||
|
# check to make sure the variable is defined
|
||||||
|
if ! declare -p "$_jv_key" &>/dev/null; then
|
||||||
|
echo "[error] variable '$_jv_key' not defined" >&2
|
||||||
|
_jv_error='true'
|
||||||
|
fi
|
||||||
|
done
|
||||||
|
|
||||||
|
if $_jv_error; then
|
||||||
|
return 1
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
# loop the variables first to filter out hidden / internal var names
|
||||||
|
local _jv_i
|
||||||
|
local _jv_len=${#_jv_variables[@]}
|
||||||
|
for ((_jv_i = 0; _jv_i < _jv_len; _jv_i++)); do
|
||||||
|
_jv_key=${_jv_variables[_jv_i]}
|
||||||
|
|
||||||
|
# filter out internal variables by name
|
||||||
|
if [[ $_jv_key == _jv_* ]]; then
|
||||||
|
unset '_jv_variables[_jv_i]'
|
||||||
|
continue
|
||||||
|
fi
|
||||||
|
|
||||||
|
# variable name was good, do nothing
|
||||||
|
done
|
||||||
|
|
||||||
|
# loop the remaining variables and format them
|
||||||
|
$_jv_value || echo '{'
|
||||||
|
_jv_i=0
|
||||||
|
for _jv_key in "${_jv_variables[@]}"; do
|
||||||
|
((_jv_i++))
|
||||||
|
|
||||||
|
if ! $_jv_value; then
|
||||||
|
# indent
|
||||||
|
echo -n ' '
|
||||||
|
|
||||||
|
# print the key
|
||||||
|
_jv-json-encode-string "$_jv_key"
|
||||||
|
echo -n ': '
|
||||||
|
fi
|
||||||
|
|
||||||
|
# print the value
|
||||||
|
_jv-encode-variable "$_jv_key"
|
||||||
|
|
||||||
|
# optionally print the comma
|
||||||
|
if ! $_jv_value && ((_jv_i < ${#_jv_variables[@]})); then
|
||||||
|
echo -n ','
|
||||||
|
fi
|
||||||
|
echo
|
||||||
|
done
|
||||||
|
$_jv_value || echo '}'
|
||||||
|
}
|
||||||
|
|
||||||
|
_jv-complete() {
|
||||||
|
COMPREPLY=(
|
||||||
|
# add all variables
|
||||||
|
$(compgen -v -- "${COMP_WORDS[COMP_CWORD]}")
|
||||||
|
|
||||||
|
# add the individual flags
|
||||||
|
$(compgen -W '-a -e -v -h' -- "${COMP_WORDS[COMP_CWORD]}")
|
||||||
|
)
|
||||||
|
}
|
||||||
|
|
||||||
|
if ( return 0 &>/dev/null ); then
|
||||||
|
# we are being sourced
|
||||||
|
complete -F _jv-complete jsonvar
|
||||||
|
else
|
||||||
|
# we are being executed directly
|
||||||
|
declare -a test_indexed=(a b c)
|
||||||
|
declare -a test_sparse=(a b c [67]=d)
|
||||||
|
declare -A test_assoc=([a]=1 [b]=2 [c]=3)
|
||||||
|
declare -i test_int=67
|
||||||
|
declare -- test_string='hello world'
|
||||||
|
|
||||||
|
declare -ai test_indexed_ints=(0 1 2 0xff foo bar baz)
|
||||||
|
declare -Ai test_assoc_ints=([foo]=0 [bar]=1 [baz]=0xff [bat]=foo)
|
||||||
|
|
||||||
|
jsonvar "$@"
|
||||||
|
fi
|
||||||
Executable
+11
@@ -0,0 +1,11 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
send_some_output() {
|
||||||
|
echo "hello"
|
||||||
|
echo "here"
|
||||||
|
echo "goodbye"
|
||||||
|
}
|
||||||
|
|
||||||
|
exec > >(tee -a ./x.out) 2>&1
|
||||||
|
|
||||||
|
send_some_output >&2
|
||||||
@@ -1,34 +1,29 @@
|
|||||||
---
|
---
|
||||||
|
|
||||||
- name: test-get_hpf_facts.yml
|
- name: test-get-hpf-facts.yml
|
||||||
hosts: all
|
hosts: all
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
|
|
||||||
- name: Copy over get_hpf_facts.sh
|
- name: Copy over get-hpf-facts.sh
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
src: hpf-ans/bin/get_hpf_facts.sh
|
src: home/hpf-ans/bin/get-hpf-facts.sh
|
||||||
dest: bin/get_hpf_facts.sh
|
dest: bin/get-hpf-facts.sh
|
||||||
owner: hpf-ans
|
owner: hpf-ans
|
||||||
group: hpf-ans
|
group: hpf-ans
|
||||||
mode: u=rwx,go=gx
|
mode: u=rwx,go=gx
|
||||||
backup: true
|
backup: true
|
||||||
|
|
||||||
- name: Run get_hpf_facts.sh
|
- name: Run get-hpf-facts.sh
|
||||||
ansible.builtin.command:
|
ansible.builtin.command:
|
||||||
cmd: bin/get_hpf_facts.sh {{ ansible_facts["os_family"] }}
|
cmd: bin/get-hpf-facts.sh {{ ansible_facts["os_family"] }}
|
||||||
register: hpf_facts
|
register: registered_hpf_facts
|
||||||
changed_when: false
|
changed_when: false
|
||||||
|
|
||||||
- name: Convert k=v stdout into facts
|
- name: Convert k=v stdout into facts
|
||||||
ansible.builtin.set_fact:
|
ansible.builtin.set_fact:
|
||||||
"{{ item.split('=', 1)[0] }}": "{{ item.split('=', 1)[1] }}"
|
hpf_facts: "{{ registered_hpf_facts.stdout | from_json }}"
|
||||||
loop: "{{ hpf_facts.stdout.splitlines() }}"
|
|
||||||
|
|
||||||
- name: Print all variables
|
|
||||||
ansible.builtin.debug:
|
|
||||||
var: hostvars[inventory_hostname]
|
|
||||||
|
|
||||||
- name: Print skel
|
- name: Print skel
|
||||||
ansible.builtin.debug:
|
ansible.builtin.debug:
|
||||||
var: hpf_fact_skel
|
var: hpf_facts.skel
|
||||||
|
|||||||
Reference in New Issue
Block a user