Compare commits
12 Commits
main
...
9f1db4076f
| Author | SHA256 | Date | |
|---|---|---|---|
| 9f1db4076f | |||
| da8db08d78 | |||
| f2661aaf02 | |||
| 44766173bd | |||
| c5b8ada835 | |||
| b25e844c0a | |||
| dc490c1613 | |||
| c2dcfa2996 | |||
| 16e3a9cbe2 | |||
| 117821b738 | |||
| 0e3f78b695 | |||
| ba750bed89 |
+41
-18
@@ -1,4 +1,4 @@
|
||||
#!/bin/sh
|
||||
#!/usr/bin/env sh
|
||||
|
||||
####
|
||||
#### WARNING:
|
||||
@@ -22,16 +22,29 @@
|
||||
#### VARIABLES
|
||||
#
|
||||
|
||||
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||
GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/files/etc_sudoers_d_hpf"
|
||||
GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/files/home_hpf_ans_bin_ansible_pull_sh"
|
||||
TIMESTAMP="$(date "+%Y%m%d%H%M%S")"
|
||||
|
||||
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||
#GIT_REPO="${GIT_REPO_BASE}.git"
|
||||
GIT_REPO_BRANCH="${1:-"development"}"
|
||||
|
||||
GIT_REPO_FILES="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files"
|
||||
|
||||
GIT_REPO_sudoers_d_hpf="${GIT_REPO_FILES}/sudoers_d_hpf"
|
||||
GIT_REPO_ansible_venv_sh="${GIT_REPO_FILES}/profile_d_ansible_venv_sh"
|
||||
GIT_REPO_profile_append="${GIT_REPO_FILES}/profile_append"
|
||||
GIT_REPO_ansible_pull_sh="${GIT_REPO_FILES}/ansible_pull_sh"
|
||||
|
||||
ETC_sudoers_d_hpf="/etc/sudoers.d/hpf"
|
||||
|
||||
HPF_ANS_ansible_venv="\${HOME}/.ansible-venv"
|
||||
HPF_ANS_activate="${HPF_ANS_ansible_venv}/bin/activate"
|
||||
unset SKEL
|
||||
if [ -r /etc/default/useradd ] ; then . /etc/default/useradd ; fi
|
||||
SKEL="${SKEL:-/etc/skel}"
|
||||
SKEL_profile_d="${SKEL}/.profile.d"
|
||||
SKEL_ansible_venv_sh="${SKEL_profile_d}/ansible-venv.sh"
|
||||
SKEL_profile="${SKEL}/.profile"
|
||||
|
||||
HPF_ANS_ansible_venv_dir="\${HOME}/.ansible-venv"
|
||||
|
||||
HPF_ANS_bin="\${HOME}/bin"
|
||||
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
|
||||
@@ -88,7 +101,7 @@ add_groups_to_user () {
|
||||
|
||||
# $command_line
|
||||
as_hpf_ans () {
|
||||
su --login hpf-ans -c "if [ -r \"${HPF_ANS_activate}\" ] ; then source \"${HPF_ANS_activate}\" ; fi ; ${1}"
|
||||
su --login hpf-ans --command "${1}"
|
||||
}
|
||||
|
||||
|
||||
@@ -97,8 +110,8 @@ as_hpf_ans () {
|
||||
#
|
||||
|
||||
# Make sure we're running as root
|
||||
if [ $(id -u) -ne 0 ] ; then
|
||||
echo "ERROR - Not running as root!" >&2
|
||||
if [ "$(id -u)" -ne 0 ] ; then
|
||||
echo "ERROR - Not running as root" >&2
|
||||
exit 100
|
||||
fi
|
||||
|
||||
@@ -118,17 +131,27 @@ system_groupadd hpf-sudo 700
|
||||
system_groupadd hpf-sudo-np 701
|
||||
|
||||
# Create /etc/sudoers.d/hpf to allow common sudo permissions
|
||||
rm "${ETC_sudoers_d_hpf}" 2>/dev/null
|
||||
curl -o "$ETC_sudoers_d_hpf" "${GIT_REPO_sudoers_d_hpf}"
|
||||
chown root:root "${ETC_sudoers_d_hpf}"
|
||||
chmod u=rw,go= "${ETC_sudoers_d_hpf}"
|
||||
if [ -e "${ETC_sudoers_d_hpf}" ] ; then mv "${ETC_sudoers_d_hpf}" "${ETC_sudoers_d_hpf}.${TIMESTAMP}" ; fi
|
||||
curl -o "${ETC_sudoers_d_hpf}" "${GIT_REPO_sudoers_d_hpf}"
|
||||
chown root:root "${ETC_sudoers_d_hpf}"; chmod u=rw,go= "${ETC_sudoers_d_hpf}"
|
||||
|
||||
# Make sure .profile.d exists
|
||||
mkdir -p "${SKEL_profile_d}"
|
||||
chown root:root "${SKEL_profile_d}"; chmod u=rwx,go= "${SKEL_profile_d}"
|
||||
|
||||
# Create ansible-venv.sh
|
||||
if [ ! -r "${SKEL_ansible_venv_sh}" ] ; then
|
||||
curl -o "${SKEL_ansible_venv_sh}" "${GIT_REPO_ansible_venv_sh}"
|
||||
chown root:root "${SKEL_ansible_venv_sh}"; chmod u=rwx,go= "${SKEL_ansible_venv_sh}"
|
||||
curl "${GIT_REPO_profile_append}" >>"${SKEL_profile}"
|
||||
fi
|
||||
|
||||
# Create the hpf-ans user
|
||||
system_useradd hpf-ans 800
|
||||
add_groups_to_user hpf-sudo-np hpf-ans
|
||||
|
||||
# Make sure .ansible-venv exists
|
||||
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi"
|
||||
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv_dir}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv_dir}\" ; fi"
|
||||
|
||||
# Make sure pip is up to date
|
||||
as_hpf_ans "pip install --upgrade pip"
|
||||
@@ -140,8 +163,8 @@ as_hpf_ans "pip install --upgrade ansible"
|
||||
as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\""
|
||||
|
||||
# Create ~hpf-ans/bin/ansible-pull.sh
|
||||
as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null"
|
||||
# Create ansible-pull.sh
|
||||
as_hpf_ans "if [ -e \"${HPF_ANS_ansible_pull_sh}\" ] ; then mv \"${HPF_ANS_ansible_pull_sh}\" \"${HPF_ANS_ansible_pull_sh}.${TIMESTAMP}\" ; fi"
|
||||
as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\""
|
||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\""
|
||||
|
||||
@@ -150,4 +173,4 @@ mkdir -p "${ANSIBLE_PULL_SH_LOG_DIR}"
|
||||
chown hpf-ans:root "${ANSIBLE_PULL_SH_LOG_DIR}"; chmod ug=rwx,o= "${ANSIBLE_PULL_SH_LOG_DIR}"
|
||||
|
||||
# Run ansible-pull to finish up
|
||||
as_hpf_ans "bin/ansible-pull.sh bootstrap.yml"
|
||||
#as_hpf_ans "$HPF_ANS_ansible_pull_sh --branch ${GIT_REPO_BRANCH} bootstrap.yml"
|
||||
|
||||
+36
-5
@@ -23,12 +23,12 @@
|
||||
|
||||
- name: bootstrap
|
||||
hosts: all
|
||||
become: yes
|
||||
|
||||
tasks:
|
||||
|
||||
- name: Install bootstrap packages
|
||||
ansible.builtin.apt:
|
||||
become: yes
|
||||
state: latest
|
||||
pkg:
|
||||
- bash
|
||||
@@ -40,6 +40,7 @@
|
||||
|
||||
- name: Make sure hpf-sudo group exists
|
||||
ansible.builtin.group:
|
||||
become: yes
|
||||
name: hpf-sudo
|
||||
state: present
|
||||
system: true
|
||||
@@ -47,6 +48,7 @@
|
||||
|
||||
- name: Make sure hpf-sudo-np group exists
|
||||
ansible.builtin.group:
|
||||
become: yes
|
||||
name: hpf-sudo-np
|
||||
state: present
|
||||
system: true
|
||||
@@ -54,6 +56,7 @@
|
||||
|
||||
- name: Copy over /etc/sudoers.d/hpf
|
||||
ansible.builtin.copy:
|
||||
become: yes
|
||||
src: etc_sudoers_d_hpf
|
||||
dest: /etc/sudoers.d/hpf
|
||||
owner: root
|
||||
@@ -62,8 +65,38 @@
|
||||
backup: true
|
||||
validate: /usr/sbin/visudo -csf %s
|
||||
|
||||
|
||||
#### .profile.d should be in SKEL directory - look it up
|
||||
|
||||
- name: Make sure .profile.d directory exists
|
||||
ansible.builtin.file:
|
||||
become: true
|
||||
path: /etc/skel/.profile.d
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: u=rwx,go=
|
||||
|
||||
|
||||
#### ansible-venv.sh should be in SKEL directory - look it up
|
||||
|
||||
- name: Copy over ansible-venv.sh
|
||||
ansible.builtin.copy:
|
||||
become: true
|
||||
src: profile_d_ansible_venv_sh
|
||||
dest: /etc/skel/.profile.d/ansible-pull.sh
|
||||
owner: root
|
||||
group: root
|
||||
mode: u=rwx,go=
|
||||
backup: true
|
||||
|
||||
|
||||
#### .profile
|
||||
|
||||
|
||||
- name: Make sure hpf-ans group exists
|
||||
ansible.builtin.group:
|
||||
become: yes
|
||||
name: hpf-ans
|
||||
state: present
|
||||
system: true
|
||||
@@ -71,6 +104,7 @@
|
||||
|
||||
- name: Make sure hpf-ans user exists
|
||||
ansible.builtin.user:
|
||||
become: yes
|
||||
name: hpf-ans
|
||||
state: present
|
||||
system: true
|
||||
@@ -86,14 +120,12 @@
|
||||
name: pip
|
||||
virtualenv: $HOME/.ansible-venv
|
||||
extra_args: --upgrade
|
||||
become: no
|
||||
|
||||
- name: Install latest version of ansible in .ansible-venv
|
||||
ansible.builtin.pip:
|
||||
name: ansible
|
||||
virtualenv: $HOME/.ansible-venv
|
||||
extra_args: "--upgrade"
|
||||
become: no
|
||||
|
||||
- name: Make sure bin directory exists
|
||||
ansible.builtin.file:
|
||||
@@ -102,7 +134,6 @@
|
||||
owner: hpf-ans
|
||||
group: hpf-ans
|
||||
mode: u=rwx,go=
|
||||
become: no
|
||||
|
||||
- name: Copy over bin/ansible-pull.sh
|
||||
ansible.builtin.copy:
|
||||
@@ -112,10 +143,10 @@
|
||||
group: hpf-ans
|
||||
mode: u=rwx,go=
|
||||
backup: true
|
||||
become: no
|
||||
|
||||
- name: Make sure log directory exists
|
||||
ansible.builtin.file:
|
||||
become: yes
|
||||
path: /var/log/ansible-pull.sh
|
||||
state: directory
|
||||
owner: hpf-ans
|
||||
|
||||
@@ -1,7 +1,23 @@
|
||||
#!/bin/bash
|
||||
|
||||
# - Fix branch to check out
|
||||
# - Process command line
|
||||
GIT_REPO_BRANCH="production"
|
||||
while [ $# -gt 0 ]; do
|
||||
case "$1" in
|
||||
-h|--help)
|
||||
echo "Usage: $0 [--branch <branch name>]"
|
||||
exit 0
|
||||
;;
|
||||
--branch)
|
||||
shift 1
|
||||
if [ $# -eq 0 ] ; then echo "$0: ERROR - Branch not specified." ; exit 1 ; fi
|
||||
GIT_REPO_BRANCH="$1"
|
||||
shift 1
|
||||
;;
|
||||
esac
|
||||
done
|
||||
|
||||
# - Include ansible virtual environment
|
||||
. "${HOME}/.ansible-venv/bin/activate"
|
||||
|
||||
SCRIPT_NAME="$(basename "${0}")"
|
||||
@@ -23,5 +39,5 @@ if ! flock -n 9 ; then echo " - ERROR - Another copy of ${SCRIPT_NAME} is alread
|
||||
|
||||
# - Do our work
|
||||
echo
|
||||
ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout main "${@}"
|
||||
ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}"
|
||||
|
||||
@@ -0,0 +1,6 @@
|
||||
|
||||
if [ -d "$HOME/.profile.d" ] ; then
|
||||
for profile_script in $HOME/.profile.d/*.sh ; do
|
||||
. "${profile_script}"
|
||||
done
|
||||
fi
|
||||
@@ -0,0 +1,6 @@
|
||||
ANSIBLE_ACTIVATE="${HOME}/.ansible-venv/bin/activate"
|
||||
|
||||
if [ -r "${ANSIBLE_ACTIVATE}" ] ; then
|
||||
VIRTUAL_ENV_DISABLE_PROMPT=true
|
||||
. "${ANSIBLE_ACTIVATE}"
|
||||
fi
|
||||
+116
@@ -0,0 +1,116 @@
|
||||
|
||||
|
||||
|
||||
* create production, development branches
|
||||
* have bootstrap.sh get ansible_pull_branch variable value
|
||||
|
||||
* have bootstrap.yml use ansible.builtin.blockinfile to maintain /etc/skel/.profile
|
||||
|
||||
|
||||
|
||||
# add /home/hpf-ans/bin/ansible-pull.sh crontab
|
||||
|
||||
|
||||
|
||||
* Configure hosts
|
||||
# cat >>/etc/hosts <<!!TheEnd!!
|
||||
|
||||
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
|
||||
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
|
||||
!!TheEnd!!
|
||||
* Configure chrony
|
||||
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
|
||||
pool 0.north-america.pool.ntp.org iburst
|
||||
!!TheEnd!!
|
||||
* Configure SSH
|
||||
# cat >/etc/ssh/sshd_config.d/hpetersenfamily.conf <<!!TheEnd!!
|
||||
PasswordAuthentication no
|
||||
PermitEmptyPasswords no
|
||||
PermitRootLogin no
|
||||
!!TheEnd!!
|
||||
# cat >>/home/first/.ssh/authorized_keys <<!!TheEnd!!
|
||||
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBM5BBUOxkuSK7WlpaDvp6lrM9ajLSyh4PWD7VFzYOFN5/zfafy6Vf/oxtLE4UACw5ZGvBMQNH40bW+T9aO0lQ9g= first Heath@HPetersenFamily.com
|
||||
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBBFiio/AimTUloJdfk4TXyWO7A0Fd9SoUcqheBjEvj4TnrxpSL/EhwF2CU9jZTasm6NBo2eKcH4aMt1l2ejOtIM= heath Heath@HPetersenFamily.com
|
||||
!!TheEnd!!
|
||||
|
||||
|
||||
##########
|
||||
########## normal tasks
|
||||
##########
|
||||
|
||||
- name: Install openssh, openssh-server, openssh-sftp-server
|
||||
ansible.builtin.apt:
|
||||
pkg:
|
||||
- openssh
|
||||
- openssh-server
|
||||
- openssh-sftp-server
|
||||
|
||||
- name: Install bash, bash-completion
|
||||
ansible.builtin.apt:
|
||||
pkg:
|
||||
- bash
|
||||
- bash-completion
|
||||
|
||||
- name: Install chrony
|
||||
ansible.builtin.apt:
|
||||
pkg:
|
||||
- chrony
|
||||
|
||||
#- name: Set host name
|
||||
# ansible.builtin.hostname:
|
||||
# name: ## Fully qualified domain name ##
|
||||
# use: systemd
|
||||
|
||||
|
||||
- name: Copy a new sudoers file into place, after passing validation with visudo
|
||||
ansible.builtin.template:
|
||||
src: /mine/sudoers
|
||||
dest: /etc/sudoers
|
||||
validate: /usr/sbin/visudo -cf %s
|
||||
|
||||
- name: Update sshd configuration safely, avoid locking yourself out
|
||||
ansible.builtin.template:
|
||||
src: etc/ssh/sshd_config.j2
|
||||
dest: /etc/ssh/sshd_config
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0600'
|
||||
validate: /usr/sbin/sshd -t -f %s
|
||||
backup: yes
|
||||
|
||||
|
||||
proxmox-clients
|
||||
hw:
|
||||
pve-lxc:
|
||||
pve-oci:
|
||||
pve-kvm:
|
||||
|
||||
|
||||
users: first, heath, hpf-ans
|
||||
|
||||
~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
|
||||
~heath/.ssh/authorized_keys
|
||||
~first/.ssh/authorized_keys
|
||||
~heath/.gitconfig
|
||||
|
||||
|
||||
|
||||
|
||||
fail2ban
|
||||
uptime kuma
|
||||
|
||||
==============================================================
|
||||
==============================================================
|
||||
==============================================================
|
||||
|
||||
logrotate /var/log/ansible-pull.log
|
||||
cron job for ansible-pull
|
||||
|
||||
|
||||
use tags to do things like allow selecting software updates, software cleanup, etc.
|
||||
ansible_os_family variable
|
||||
ansible galaxy
|
||||
|
||||
have upgrade pip and ansible in ~hpf-ans/.ansible-venv
|
||||
hashicorp vault
|
||||
have ansible-pull.sh make sure only one copy is running
|
||||
Reference in New Issue
Block a user