Compare commits
54 Commits
main
..
90de36e0b2
| Author | SHA256 | Date | |
|---|---|---|---|
| 90de36e0b2 | |||
| bfe44f6b17 | |||
| 331b2ba504 | |||
| 26142f24b0 | |||
| 97b4169bdc | |||
| b8792fc523 | |||
| 1a0d1e5d0b | |||
| 8b50cacb1b | |||
| e1592fca85 | |||
| 456ee502ee | |||
| 4fe4ca317a | |||
| 4f86f4c114 | |||
| bcd45cff9e | |||
| 0e820b49f9 | |||
| 9b213b81e9 | |||
| 761137317a | |||
| 43ded2bdca | |||
| bb65f915a7 | |||
| 94fc56674f | |||
| 9518826ea4 | |||
| e34628f838 | |||
| c3d3c59611 | |||
| 9c63ca61a0 | |||
| 839a136393 | |||
| fa41c94b49 | |||
| 347962126e | |||
| 4154b5297a | |||
| 0429125819 | |||
| 28e9fbd9b9 | |||
| dfc6aa5cb3 | |||
| 86b8a2e06d | |||
| 2bf8241293 | |||
| 303608172f | |||
| 31eac61575 | |||
| db6669f9a9 | |||
| effd8336cd | |||
| 246737d212 | |||
| aff550d586 | |||
| 716ac04c4f | |||
| 438c4d2100 | |||
| 36369f1ad6 | |||
| f4f2b96d1a | |||
| 9f1db4076f | |||
| da8db08d78 | |||
| f2661aaf02 | |||
| 44766173bd | |||
| c5b8ada835 | |||
| b25e844c0a | |||
| dc490c1613 | |||
| c2dcfa2996 | |||
| 16e3a9cbe2 | |||
| 117821b738 | |||
| 0e3f78b695 | |||
| ba750bed89 |
@@ -0,0 +1,219 @@
|
|||||||
|
#!/usr/bin/env sh
|
||||||
|
|
||||||
|
####
|
||||||
|
#### WARNING:
|
||||||
|
####
|
||||||
|
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
|
||||||
|
#### exact same things with the following exceptions:
|
||||||
|
####
|
||||||
|
#### * bootstrap.sh
|
||||||
|
#### - at the end it should run ansible-pull.sh against bootstrap.yml
|
||||||
|
####
|
||||||
|
#### * bootstrap.yml
|
||||||
|
#### - at the end it should configure cron to schedule ansible-pull.sh
|
||||||
|
####
|
||||||
|
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||||
|
#### ! Make sure to keep them in sync !
|
||||||
|
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
||||||
|
####
|
||||||
|
|
||||||
|
|
||||||
|
#
|
||||||
|
#### VARIABLES
|
||||||
|
#
|
||||||
|
|
||||||
|
TIMESTAMP="$(date "+%Y%m%d%H%M%S")"
|
||||||
|
|
||||||
|
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||||
|
GIT_REPO_BRANCH="${1:-"development"}"
|
||||||
|
|
||||||
|
GIT_REPO_FILES="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files"
|
||||||
|
|
||||||
|
GIT_REPO_sudoers_d_hpf="${GIT_REPO_FILES}/etc/sudoers.d/hpf"
|
||||||
|
GIT_REPO_SKEL_ansible_venv_sh="${GIT_REPO_FILES}/etc/skel/.profile.d/ansible-venv.sh"
|
||||||
|
GIT_REPO_SKEL_profile="${GIT_REPO_FILES}/etc/skel/.profile"
|
||||||
|
GIT_REPO_ansible_pull_sh="${GIT_REPO_FILES}/home/hpf-ans/bin/ansible-pull.sh"
|
||||||
|
|
||||||
|
ETC_sudoers_d="/etc/sudoers.d"
|
||||||
|
ETC_sudoers_d_hpf="${ETC_sudoers_d}/hpf"
|
||||||
|
|
||||||
|
unset SKEL
|
||||||
|
if [ -r /etc/default/useradd ] ; then . /etc/default/useradd ; fi
|
||||||
|
SKEL="${SKEL:-/etc/skel}"
|
||||||
|
SKEL_profile_d="${SKEL}/.profile.d"
|
||||||
|
SKEL_ansible_venv_sh="${SKEL_profile_d}/ansible-venv.sh"
|
||||||
|
SKEL_profile="${SKEL}/.profile"
|
||||||
|
|
||||||
|
ANSIBLE_PULL_SH_LOG_DIR="/var/log/ansible-pull.sh"
|
||||||
|
|
||||||
|
|
||||||
|
#
|
||||||
|
#### FUNCTIONS
|
||||||
|
#
|
||||||
|
|
||||||
|
# $group_name $group_number
|
||||||
|
group_exists () {
|
||||||
|
grep -q "^$1:[^:]*:$2:" /etc/group
|
||||||
|
}
|
||||||
|
|
||||||
|
# $user_name $user_number
|
||||||
|
user_exists () {
|
||||||
|
grep -q "^$1:[^:]*:$2:$2:" /etc/passwd
|
||||||
|
}
|
||||||
|
|
||||||
|
# $group_name $group_number
|
||||||
|
system_groupadd () {
|
||||||
|
if group_exists "$1" "$2" ; then return 0 ; fi
|
||||||
|
groupadd -r -g "$2" "$1"
|
||||||
|
rc=$?
|
||||||
|
if [ $rc -ne 0 ] ; then
|
||||||
|
echo "ERROR - Unable to add $1 group! ($rc)" >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# $user_name $user_number
|
||||||
|
system_useradd () {
|
||||||
|
if user_exists "$1" "$2" ; then return 0 ; fi
|
||||||
|
system_groupadd "${@}"
|
||||||
|
useradd -r -u "$2" -g "$2" -s /usr/bin/bash -m "$1"
|
||||||
|
rc=$?
|
||||||
|
if [ $rc -ne 0 ] ; then
|
||||||
|
echo "ERROR - Unable to add $1 user! ($rc)" >&2
|
||||||
|
exit 2
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# $groups $user_name
|
||||||
|
add_groups_to_user () {
|
||||||
|
usermod -aG "$1" "$2"
|
||||||
|
rc=$?
|
||||||
|
if [ $rc -ne 0 ] ; then
|
||||||
|
echo "ERROR - Unable to add groups ($1) to user ($2)! ($rc)" >&2
|
||||||
|
exit 3
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# $source_file $dest_file $dest_file_ownership $dest_file_permissions
|
||||||
|
get_file() {
|
||||||
|
local source_file dest_file dest_file_ownership dest_file_permissions
|
||||||
|
|
||||||
|
source_file="${1}"
|
||||||
|
dest_file="${2}"
|
||||||
|
dest_file_ownership="${3}"
|
||||||
|
dest_file_permissions="${4}"
|
||||||
|
|
||||||
|
if [ -e "${dest_file}" ] ; then mv "${dest_file}" "${dest_file}.${TIMESTAMP}" ; fi
|
||||||
|
if ! curl -f -o "${dest_file}" "${source_file}" ; then
|
||||||
|
echo "ERROR - Unable to download \"${source_file}\"" >&2
|
||||||
|
echo " to \"${dest_file}\"." >&2
|
||||||
|
exit 4
|
||||||
|
fi
|
||||||
|
if ! chown "${dest_file_ownership}" "${dest_file}" ; then
|
||||||
|
echo "ERROR - Unable to change ownership of \"${dest_file}\" to \"${dest_file_ownership}\"" >&2
|
||||||
|
exit 4
|
||||||
|
fi
|
||||||
|
if ! chmod "${dest_file_permissions}" "${dest_file}" ; then
|
||||||
|
echo "ERROR - Unable to change permissions of \"${dest_file}\" to \"${dest_file_permissions}\"" >&2
|
||||||
|
exit 4
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# $directory $directory_ownership $directory_permissions
|
||||||
|
create_directory() {
|
||||||
|
local directory directory_ownership directory_permissions
|
||||||
|
|
||||||
|
directory="${1}"
|
||||||
|
directory_ownership="${2}"
|
||||||
|
directory_permissions="${3}"
|
||||||
|
|
||||||
|
if ! mkdir -p "${directory}" ; then
|
||||||
|
echo "ERROR - Unable to create directory \"${directory}\"" >&2
|
||||||
|
exit 5
|
||||||
|
fi
|
||||||
|
if ! chown "${directory_ownership}" "${directory}" ; then
|
||||||
|
echo "ERROR - Unable to change ownership of \"${directory}\" to \"${directory_ownership}\"" >&2
|
||||||
|
exit 5
|
||||||
|
fi
|
||||||
|
if ! chmod "${directory_permissions}" "${directory}" ; then
|
||||||
|
echo "ERROR - Unable to change permissions of \"${directory}\" to \"${directory_permissions}\"" >&2
|
||||||
|
exit 5
|
||||||
|
fi
|
||||||
|
}
|
||||||
|
|
||||||
|
# $command_line
|
||||||
|
as_hpf_ans () {
|
||||||
|
su --login hpf-ans --command "${1}"
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
#
|
||||||
|
#### PROCESS
|
||||||
|
#
|
||||||
|
|
||||||
|
# Make sure we're running as root
|
||||||
|
if [ "$(id -u)" -ne 0 ] ; then
|
||||||
|
echo "ERROR - Not running as root" >&2
|
||||||
|
exit 100
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Install minimal necessary packages
|
||||||
|
if which -s apt ; then
|
||||||
|
apt update
|
||||||
|
apt install bash curl python3 python3-pip python3-venv python3-virtualenv -y
|
||||||
|
else
|
||||||
|
echo "ERROR - Unable to determine how to install packages" >&2
|
||||||
|
exit 101
|
||||||
|
fi
|
||||||
|
|
||||||
|
# Create system group hpf-sudo for normal sudo users
|
||||||
|
system_groupadd hpf-sudo 700
|
||||||
|
|
||||||
|
# Create system group hpf-sudo-np for special sudo users that don't require a password
|
||||||
|
system_groupadd hpf-sudo-np 701
|
||||||
|
|
||||||
|
# Make sure /etc/sudoers.d exists
|
||||||
|
create_directory "${ETC_sudoers_d}" "root:root" "u=rwx,go="
|
||||||
|
|
||||||
|
# Get /etc/sudoers.d/hpf
|
||||||
|
get_file "${GIT_REPO_sudoers_d_hpf}" "${ETC_sudoers_d_hpf}" "root:root" "u=rw,go="
|
||||||
|
|
||||||
|
# Make sure /etc/skel/.profile.d exists
|
||||||
|
create_directory "${SKEL_profile_d}" "root:root" "u=rwx,go="
|
||||||
|
|
||||||
|
# Get /etc/skel/.profile.d/ansible-venv.sh
|
||||||
|
get_file "${GIT_REPO_SKEL_ansible_venv_sh}" "${SKEL_ansible_venv_sh}" "root:root" "u=rw,go="
|
||||||
|
|
||||||
|
# Get /etc/skel/.profile
|
||||||
|
get_file "${GIT_REPO_SKEL_profile}" "${SKEL_profile}" "root:root" "u=rw,go="
|
||||||
|
|
||||||
|
# Create the hpf-ans user
|
||||||
|
system_useradd hpf-ans 800
|
||||||
|
add_groups_to_user hpf-sudo-np hpf-ans
|
||||||
|
|
||||||
|
# Set HPF_ANS variables now that the user is created
|
||||||
|
HPF_ANS_HOME="$(as_hpf_ans 'echo "${HOME}"')"
|
||||||
|
HPF_ANS_ansible_venv="${HPF_ANS_HOME}/.ansible-venv"
|
||||||
|
HPF_ANS_bin="${HPF_ANS_HOME}/bin"
|
||||||
|
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
|
||||||
|
|
||||||
|
# Make sure /home/hpf-ans/.ansible-venv exists
|
||||||
|
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi"
|
||||||
|
|
||||||
|
# Make sure pip is up to date
|
||||||
|
as_hpf_ans "pip install --upgrade pip"
|
||||||
|
|
||||||
|
# Make sure ansible is up to date
|
||||||
|
as_hpf_ans "pip install --upgrade ansible"
|
||||||
|
|
||||||
|
# Make sure /home/hpf-ans/bin exists
|
||||||
|
create_directory "${HPF_ANS_bin}" "hpf-ans:hpf-ans" "u=rwx,go="
|
||||||
|
|
||||||
|
# Get /home/hpf-ans/bin/ansible-pull.sh
|
||||||
|
get_file "${GIT_REPO_ansible_pull_sh}" "${HPF_ANS_ansible_pull_sh}" "hpf-ans:hpf-ans" "u=rwx,go="
|
||||||
|
|
||||||
|
# Make sure log directory exists
|
||||||
|
create_directory "${ANSIBLE_PULL_SH_LOG_DIR}" "hpf-ans:root" "u=rwx,go="
|
||||||
|
|
||||||
|
# Run ansible-pull to finish up
|
||||||
|
#as_hpf_ans "$HPF_ANS_ansible_pull_sh --branch ${GIT_REPO_BRANCH} bootstrap.yml"
|
||||||
@@ -10,6 +10,8 @@ timeout = 30
|
|||||||
stdout_callback = default
|
stdout_callback = default
|
||||||
callback_result_format = yaml
|
callback_result_format = yaml
|
||||||
|
|
||||||
|
interpreter_python = auto_silent
|
||||||
|
|
||||||
#[privilege_escalation]
|
#[privilege_escalation]
|
||||||
#become = True
|
#become = True
|
||||||
#become_method = sudo
|
#become_method = sudo
|
||||||
|
|||||||
-153
@@ -1,153 +0,0 @@
|
|||||||
#!/bin/sh
|
|
||||||
|
|
||||||
####
|
|
||||||
#### WARNING:
|
|
||||||
####
|
|
||||||
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
|
|
||||||
#### exact same things with the following exceptions:
|
|
||||||
####
|
|
||||||
#### * bootstrap.sh
|
|
||||||
#### - at the end it should run ansible-pull.sh against bootstrap.yml
|
|
||||||
####
|
|
||||||
#### * bootstrap.yml
|
|
||||||
#### - at the end it should configure cron to schedule ansible-pull.sh
|
|
||||||
####
|
|
||||||
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
|
||||||
#### ! Make sure to keep them in sync !
|
|
||||||
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
|
||||||
####
|
|
||||||
|
|
||||||
|
|
||||||
#
|
|
||||||
#### VARIABLES
|
|
||||||
#
|
|
||||||
|
|
||||||
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
|
||||||
GIT_REPO="${GIT_REPO_BASE}.git"
|
|
||||||
GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/files/etc_sudoers_d_hpf"
|
|
||||||
GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/files/home_hpf_ans_bin_ansible_pull_sh"
|
|
||||||
|
|
||||||
|
|
||||||
ETC_sudoers_d_hpf="/etc/sudoers.d/hpf"
|
|
||||||
|
|
||||||
HPF_ANS_ansible_venv="\${HOME}/.ansible-venv"
|
|
||||||
HPF_ANS_activate="${HPF_ANS_ansible_venv}/bin/activate"
|
|
||||||
|
|
||||||
HPF_ANS_bin="\${HOME}/bin"
|
|
||||||
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
|
|
||||||
|
|
||||||
ANSIBLE_PULL_SH_LOG_DIR="/var/log/ansible-pull.sh"
|
|
||||||
|
|
||||||
|
|
||||||
#
|
|
||||||
#### FUNCTIONS
|
|
||||||
#
|
|
||||||
|
|
||||||
# $group_name $group_number
|
|
||||||
group_exists () {
|
|
||||||
grep -q "^$1:[^:]*:$2:" /etc/group
|
|
||||||
}
|
|
||||||
|
|
||||||
# $user_name $user_number
|
|
||||||
user_exists () {
|
|
||||||
grep -q "^$1:[^:]*:$2:$2:" /etc/passwd
|
|
||||||
}
|
|
||||||
|
|
||||||
# $group_name $group_number
|
|
||||||
system_groupadd () {
|
|
||||||
if group_exists "$1" "$2" ; then return 0 ; fi
|
|
||||||
groupadd -r -g "$2" "$1"
|
|
||||||
rc=$?
|
|
||||||
if [ $rc -ne 0 ] ; then
|
|
||||||
echo "ERROR - Unable to add $1 group! ($rc)" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
# $user_name $user_number
|
|
||||||
system_useradd () {
|
|
||||||
if user_exists "$1" "$2" ; then return 0 ; fi
|
|
||||||
system_groupadd "${@}"
|
|
||||||
useradd -r -u "$2" -g "$2" -s /bin/bash -m "$1"
|
|
||||||
rc=$?
|
|
||||||
if [ $rc -ne 0 ] ; then
|
|
||||||
echo "ERROR - Unable to add $1 user! ($rc)" >&2
|
|
||||||
exit 2
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
# $groups $user_name
|
|
||||||
add_groups_to_user () {
|
|
||||||
usermod -aG "$1" "$2"
|
|
||||||
rc=$?
|
|
||||||
if [ $rc -ne 0 ] ; then
|
|
||||||
echo "ERROR - Unable to add groups ($1) to user ($2)! ($rc)" >&2
|
|
||||||
exit 3
|
|
||||||
fi
|
|
||||||
}
|
|
||||||
|
|
||||||
# $command_line
|
|
||||||
as_hpf_ans () {
|
|
||||||
su --login hpf-ans -c "if [ -r \"${HPF_ANS_activate}\" ] ; then source \"${HPF_ANS_activate}\" ; fi ; ${1}"
|
|
||||||
}
|
|
||||||
|
|
||||||
|
|
||||||
#
|
|
||||||
#### PROCESS
|
|
||||||
#
|
|
||||||
|
|
||||||
# Make sure we're running as root
|
|
||||||
if [ $(id -u) -ne 0 ] ; then
|
|
||||||
echo "ERROR - Not running as root!" >&2
|
|
||||||
exit 100
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Install minimal necessary packages
|
|
||||||
if which -s apt ; then
|
|
||||||
apt update
|
|
||||||
apt install bash curl python3 python3-pip python3-venv python3-virtualenv -y
|
|
||||||
else
|
|
||||||
echo "ERROR - Unable to determine how to install packages" >&2
|
|
||||||
exit 101
|
|
||||||
fi
|
|
||||||
|
|
||||||
# Create system group hpf-sudo for normal sudo users
|
|
||||||
system_groupadd hpf-sudo 700
|
|
||||||
|
|
||||||
# Create system group hpf-sudo-np for special sudo users that don't require a password
|
|
||||||
system_groupadd hpf-sudo-np 701
|
|
||||||
|
|
||||||
# Create /etc/sudoers.d/hpf to allow common sudo permissions
|
|
||||||
rm "${ETC_sudoers_d_hpf}" 2>/dev/null
|
|
||||||
curl -o "$ETC_sudoers_d_hpf" "${GIT_REPO_sudoers_d_hpf}"
|
|
||||||
chown root:root "${ETC_sudoers_d_hpf}"
|
|
||||||
chmod u=rw,go= "${ETC_sudoers_d_hpf}"
|
|
||||||
|
|
||||||
# Create the hpf-ans user
|
|
||||||
system_useradd hpf-ans 800
|
|
||||||
add_groups_to_user hpf-sudo-np hpf-ans
|
|
||||||
|
|
||||||
# Make sure .ansible-venv exists
|
|
||||||
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi"
|
|
||||||
|
|
||||||
# Make sure pip is up to date
|
|
||||||
as_hpf_ans "pip install --upgrade pip"
|
|
||||||
|
|
||||||
# Make sure ansible is installed
|
|
||||||
as_hpf_ans "pip install --upgrade ansible"
|
|
||||||
|
|
||||||
# Make sure bin exists
|
|
||||||
as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\""
|
|
||||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\""
|
|
||||||
|
|
||||||
# Create ~hpf-ans/bin/ansible-pull.sh
|
|
||||||
as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null"
|
|
||||||
as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\""
|
|
||||||
as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\""
|
|
||||||
|
|
||||||
# Make sure log directory exists
|
|
||||||
mkdir -p "${ANSIBLE_PULL_SH_LOG_DIR}"
|
|
||||||
chown hpf-ans:root "${ANSIBLE_PULL_SH_LOG_DIR}"; chmod ug=rwx,o= "${ANSIBLE_PULL_SH_LOG_DIR}"
|
|
||||||
|
|
||||||
# Run ansible-pull to finish up
|
|
||||||
as_hpf_ans "bin/ansible-pull.sh bootstrap.yml"
|
|
||||||
+307
-115
@@ -1,131 +1,323 @@
|
|||||||
---
|
---
|
||||||
|
- name: Bootstrap playbook
|
||||||
####
|
|
||||||
#### WARNING:
|
|
||||||
####
|
|
||||||
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
|
|
||||||
#### exact same things with the following exceptions:
|
|
||||||
####
|
|
||||||
#### * bootstrap.sh
|
|
||||||
#### - at the end it should run ansible-pull.sh against bootstrap.yml
|
|
||||||
####
|
|
||||||
#### * bootstrap.yml
|
|
||||||
#### - at the end it should configure cron to schedule ansible-pull.sh
|
|
||||||
####
|
|
||||||
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
|
||||||
#### ! Make sure to keep them in sync !
|
|
||||||
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
|
||||||
####
|
|
||||||
|
|
||||||
|
|
||||||
# Update software repositories here
|
|
||||||
# Change the following to work with multiple distros
|
|
||||||
|
|
||||||
- name: bootstrap
|
|
||||||
hosts: all
|
hosts: all
|
||||||
become: yes
|
|
||||||
|
|
||||||
tasks:
|
tasks:
|
||||||
|
|
||||||
- name: Install bootstrap packages
|
|
||||||
ansible.builtin.apt:
|
|
||||||
state: latest
|
|
||||||
pkg:
|
|
||||||
- bash
|
|
||||||
- curl
|
|
||||||
- python3
|
|
||||||
- python3-pip
|
|
||||||
- python3-venv
|
|
||||||
- python3-virtualenv
|
|
||||||
|
|
||||||
- name: Make sure hpf-sudo group exists
|
#### System Software
|
||||||
ansible.builtin.group:
|
|
||||||
name: hpf-sudo
|
|
||||||
state: present
|
|
||||||
system: true
|
|
||||||
gid: 700
|
|
||||||
|
|
||||||
- name: Make sure hpf-sudo-np group exists
|
- name: Update repositories
|
||||||
ansible.builtin.group:
|
become: true
|
||||||
name: hpf-sudo-np
|
ansible.builtin.apt:
|
||||||
state: present
|
update_cache: true
|
||||||
system: true
|
|
||||||
gid: 701
|
|
||||||
|
|
||||||
- name: Copy over /etc/sudoers.d/hpf
|
- name: Install bootstrap packages
|
||||||
ansible.builtin.copy:
|
become: true
|
||||||
src: etc_sudoers_d_hpf
|
ansible.builtin.apt:
|
||||||
dest: /etc/sudoers.d/hpf
|
state: present
|
||||||
owner: root
|
pkg:
|
||||||
group: root
|
- bash
|
||||||
mode: u=rw,go=
|
- curl
|
||||||
backup: true
|
- python3
|
||||||
validate: /usr/sbin/visudo -csf %s
|
- python3-pip
|
||||||
|
- python3-venv
|
||||||
|
- python3-virtualenv
|
||||||
|
- logrotate
|
||||||
|
|
||||||
- name: Make sure hpf-ans group exists
|
|
||||||
ansible.builtin.group:
|
|
||||||
name: hpf-ans
|
|
||||||
state: present
|
|
||||||
system: true
|
|
||||||
gid: 800
|
|
||||||
|
|
||||||
- name: Make sure hpf-ans user exists
|
#### Configure sudo
|
||||||
ansible.builtin.user:
|
|
||||||
name: hpf-ans
|
|
||||||
state: present
|
|
||||||
system: true
|
|
||||||
uid: 800
|
|
||||||
group: hpf-ans
|
|
||||||
groups: hpf-sudo-np
|
|
||||||
append: yes
|
|
||||||
create_home: true
|
|
||||||
shell: /bin/bash
|
|
||||||
|
|
||||||
- name: Install latest version of pip in .ansible-venv
|
- name: Create system group hpf-sudo for normal sudo users
|
||||||
ansible.builtin.pip:
|
become: true
|
||||||
name: pip
|
ansible.builtin.group:
|
||||||
virtualenv: $HOME/.ansible-venv
|
name: hpf-sudo
|
||||||
extra_args: --upgrade
|
state: present
|
||||||
become: no
|
system: true
|
||||||
|
gid: 700
|
||||||
|
|
||||||
- name: Install latest version of ansible in .ansible-venv
|
- name: Create system group hpf-sudo-np for special sudo users that don't require a password
|
||||||
ansible.builtin.pip:
|
become: true
|
||||||
name: ansible
|
ansible.builtin.group:
|
||||||
virtualenv: $HOME/.ansible-venv
|
name: hpf-sudo-np
|
||||||
extra_args: "--upgrade"
|
state: present
|
||||||
become: no
|
system: true
|
||||||
|
gid: 701
|
||||||
|
|
||||||
- name: Make sure bin directory exists
|
- name: Make sure /etc/sudoers.d exists
|
||||||
ansible.builtin.file:
|
become: true
|
||||||
path: $HOME/bin
|
ansible.builtin.file:
|
||||||
state: directory
|
path: /etc/sudoers.d
|
||||||
owner: hpf-ans
|
state: directory
|
||||||
group: hpf-ans
|
owner: root
|
||||||
mode: u=rwx,go=
|
group: root
|
||||||
become: no
|
mode: u=rwx,go=
|
||||||
|
|
||||||
- name: Copy over bin/ansible-pull.sh
|
- name: Get /etc/sudoers.d/hpf
|
||||||
ansible.builtin.copy:
|
become: true
|
||||||
src: home_hpf_ans_bin_ansible_pull_sh
|
ansible.builtin.copy:
|
||||||
dest: $HOME/bin/ansible-pull.sh
|
src: etc/sudoers.d/hpf
|
||||||
owner: hpf-ans
|
dest: /etc/sudoers.d/hpf
|
||||||
group: hpf-ans
|
owner: root
|
||||||
mode: u=rwx,go=
|
group: root
|
||||||
backup: true
|
mode: u=rw,go=
|
||||||
become: no
|
backup: true
|
||||||
|
validate: /usr/sbin/visudo -csf %s
|
||||||
|
|
||||||
- name: Make sure log directory exists
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: /var/log/ansible-pull.sh
|
|
||||||
state: directory
|
|
||||||
owner: hpf-ans
|
|
||||||
group: root
|
|
||||||
mode: ug=rwx,o=
|
|
||||||
|
|
||||||
# - name: Create ansible-pull.sh crontab entry
|
#### Configure sshd
|
||||||
# ansible.builtin.cron:
|
|
||||||
# name: "ansible-pull"
|
- name: Make sure /etc/ssh/sshd_config.d exists
|
||||||
# minute: "*/27"
|
become: true
|
||||||
# job: $HOME/bin/ansible-pull.sh
|
ansible.builtin.file:
|
||||||
# backup: true
|
path: /etc/ssh/sshd_config.d
|
||||||
# become: no
|
state: directory
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: u=rwx,go=rx
|
||||||
|
|
||||||
|
- name: Get /etc/ssh/sshd_config.d/hpf.conf
|
||||||
|
become: true
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: etc/ssh/sshd_config.d/hpf.conf
|
||||||
|
dest: /etc/ssh/sshd_config.d/hpf.conf
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: u=rwx,go=rx
|
||||||
|
backup: true
|
||||||
|
validate: /usr/sbin/sshd -t -f %s
|
||||||
|
notify: Restart sshd
|
||||||
|
|
||||||
|
|
||||||
|
#### Configure /etc/skel
|
||||||
|
|
||||||
|
- name: Make sure /etc/skel/.profile.d exists
|
||||||
|
become: true
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /etc/skel/.profile.d
|
||||||
|
state: directory
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: u=rwx,go=
|
||||||
|
|
||||||
|
- name: Get /etc/skel/.profile.d/ansible-venv.sh
|
||||||
|
become: true
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: etc/skel/.profile.d/ansible-venv.sh
|
||||||
|
dest: /etc/skel/.profile.d/ansible-venv.sh
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: u=rw,go=
|
||||||
|
backup: true
|
||||||
|
|
||||||
|
- name: Get /etc/skel/.profile
|
||||||
|
become: true
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: etc/skel/.profile
|
||||||
|
dest: /etc/skel/.profile
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: u=rw,go=
|
||||||
|
backup: true
|
||||||
|
|
||||||
|
|
||||||
|
#### User: root
|
||||||
|
|
||||||
|
- name: Set root's authorized_keys
|
||||||
|
become: true
|
||||||
|
ansible.posix.authorized_key:
|
||||||
|
user: root
|
||||||
|
state: present
|
||||||
|
key: "{{ lookup('file', item) }}"
|
||||||
|
loop:
|
||||||
|
- files/ssh-keys/heath.pub
|
||||||
|
|
||||||
|
|
||||||
|
#### User: first
|
||||||
|
|
||||||
|
- name: Create the first user
|
||||||
|
become: true
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: first
|
||||||
|
comment: First User
|
||||||
|
state: present
|
||||||
|
system: false
|
||||||
|
groups: hpf-sudo-np
|
||||||
|
append: true
|
||||||
|
create_home: true
|
||||||
|
shell: /usr/bin/bash
|
||||||
|
|
||||||
|
- name: Set first's authorized_keys
|
||||||
|
become: true
|
||||||
|
ansible.posix.authorized_key:
|
||||||
|
user: first
|
||||||
|
state: present
|
||||||
|
key: "{{ lookup('file', item) }}"
|
||||||
|
loop:
|
||||||
|
- files/ssh-keys/first.pub
|
||||||
|
- files/ssh-keys/heath.pub
|
||||||
|
|
||||||
|
|
||||||
|
#### User: hpf-ans
|
||||||
|
|
||||||
|
- name: Create the hpf-ans group
|
||||||
|
become: true
|
||||||
|
ansible.builtin.group:
|
||||||
|
name: hpf-ans
|
||||||
|
state: present
|
||||||
|
system: true
|
||||||
|
gid: 800
|
||||||
|
|
||||||
|
- name: Create the hpf-ans user
|
||||||
|
become: true
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: hpf-ans
|
||||||
|
state: present
|
||||||
|
system: true
|
||||||
|
uid: 800
|
||||||
|
group: hpf-ans
|
||||||
|
groups: hpf-sudo-np
|
||||||
|
append: true
|
||||||
|
create_home: true
|
||||||
|
shell: /usr/bin/bash
|
||||||
|
|
||||||
|
- name: Set hpf-ans's authorized_keys
|
||||||
|
become: true
|
||||||
|
ansible.posix.authorized_key:
|
||||||
|
user: hpf-ans
|
||||||
|
state: present
|
||||||
|
key: "{{ lookup('file', item) }}"
|
||||||
|
loop:
|
||||||
|
- files/ssh-keys/heath.pub
|
||||||
|
|
||||||
|
- name: Make sure pip is up to date
|
||||||
|
become: true
|
||||||
|
become_user: hpf-ans
|
||||||
|
ansible.builtin.pip:
|
||||||
|
name: pip
|
||||||
|
virtualenv: $HOME/.ansible-venv
|
||||||
|
extra_args: --upgrade
|
||||||
|
|
||||||
|
- name: Make sure ansible is up to date
|
||||||
|
become: true
|
||||||
|
become_user: hpf-ans
|
||||||
|
ansible.builtin.pip:
|
||||||
|
name: ansible
|
||||||
|
virtualenv: $HOME/.ansible-venv
|
||||||
|
extra_args: --upgrade
|
||||||
|
|
||||||
|
|
||||||
|
#### User: heath
|
||||||
|
|
||||||
|
- name: Create the heath group
|
||||||
|
become: true
|
||||||
|
ansible.builtin.group:
|
||||||
|
name: heath
|
||||||
|
state: present
|
||||||
|
system: false
|
||||||
|
gid: 60001
|
||||||
|
|
||||||
|
- name: Create the heath user
|
||||||
|
become: true
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: heath
|
||||||
|
comment: Heath Petersen
|
||||||
|
state: present
|
||||||
|
system: false
|
||||||
|
uid: 60001
|
||||||
|
group: heath
|
||||||
|
groups: hpf-sudo
|
||||||
|
append: true
|
||||||
|
create_home: true
|
||||||
|
shell: /usr/bin/bash
|
||||||
|
|
||||||
|
- name: Set heath's authorized_keys
|
||||||
|
become: true
|
||||||
|
ansible.posix.authorized_key:
|
||||||
|
user: heath
|
||||||
|
state: present
|
||||||
|
key: "{{ lookup('file', item) }}"
|
||||||
|
loop:
|
||||||
|
- files/ssh-keys/heath.pub
|
||||||
|
|
||||||
|
|
||||||
|
#### ansible-pull.sh
|
||||||
|
|
||||||
|
- name: Make sure /home/hpf-ans/bin exists
|
||||||
|
become: true
|
||||||
|
become_user: hpf-ans
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: $HOME/bin
|
||||||
|
state: directory
|
||||||
|
owner: hpf-ans
|
||||||
|
group: hpf-ans
|
||||||
|
mode: u=rwx,go=
|
||||||
|
|
||||||
|
- name: Get /home/hpf-ans/bin/ansible-pull.sh
|
||||||
|
become: true
|
||||||
|
become_user: hpf-ans
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: home/hpf-ans/bin/ansible-pull.sh
|
||||||
|
dest: $HOME/bin/ansible-pull.sh
|
||||||
|
owner: hpf-ans
|
||||||
|
group: hpf-ans
|
||||||
|
mode: u=rwx,go=
|
||||||
|
backup: true
|
||||||
|
|
||||||
|
- name: Make sure log directory exists
|
||||||
|
become: true
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: /var/log/ansible-pull.sh
|
||||||
|
state: directory
|
||||||
|
owner: hpf-ans
|
||||||
|
group: root
|
||||||
|
mode: u=rwx,go=
|
||||||
|
|
||||||
|
# - name: Create ansible-pull.sh crontab entry
|
||||||
|
# become: true
|
||||||
|
# become_user: hpf-ans
|
||||||
|
# ansible.builtin.cron:
|
||||||
|
# name: "ansible-pull"
|
||||||
|
# minute: "*/27"
|
||||||
|
# job: $HOME/bin/ansible-pull.sh
|
||||||
|
# backup: true
|
||||||
|
|
||||||
|
- name: Rotate ansible-pull.sh.log
|
||||||
|
become: true
|
||||||
|
community.general.logrotate:
|
||||||
|
name: ansible-pull.sh
|
||||||
|
paths:
|
||||||
|
- /var/log/ansible-pull.sh/*.log
|
||||||
|
rotation_period: daily
|
||||||
|
rotate_count: 32
|
||||||
|
compress: true
|
||||||
|
compress_options: "-9"
|
||||||
|
delay_compress: true
|
||||||
|
missing_ok: true
|
||||||
|
not_if_empty: true
|
||||||
|
backup: true
|
||||||
|
|
||||||
|
|
||||||
|
#### Clean System Software
|
||||||
|
|
||||||
|
- name: Remove packages installed as dependencies that are no longer required and purge their configuration files
|
||||||
|
become: true
|
||||||
|
ansible.builtin.apt:
|
||||||
|
autoremove: true
|
||||||
|
purge: true
|
||||||
|
|
||||||
|
- name: Remove old downloaded packages
|
||||||
|
become: true
|
||||||
|
ansible.builtin.apt:
|
||||||
|
autoclean: true
|
||||||
|
|
||||||
|
|
||||||
|
#### Handlers
|
||||||
|
|
||||||
|
handlers:
|
||||||
|
|
||||||
|
- name: Restart sshd
|
||||||
|
become: true
|
||||||
|
ansible.builtin.service:
|
||||||
|
name: sshd
|
||||||
|
state: restarted
|
||||||
|
|||||||
@@ -0,0 +1,34 @@
|
|||||||
|
# ~/.profile: executed by the command interpreter for login shells.
|
||||||
|
# This file is not read by bash(1), if ~/.bash_profile or ~/.bash_login
|
||||||
|
# exists.
|
||||||
|
# see /usr/share/doc/bash/examples/startup-files for examples.
|
||||||
|
# the files are located in the bash-doc package.
|
||||||
|
|
||||||
|
# the default umask is set in /etc/profile; for setting the umask
|
||||||
|
# for ssh logins, install and configure the libpam-umask package.
|
||||||
|
#umask 022
|
||||||
|
|
||||||
|
# if running bash
|
||||||
|
if [ -n "$BASH_VERSION" ]; then
|
||||||
|
# include .bashrc if it exists
|
||||||
|
if [ -f "$HOME/.bashrc" ]; then
|
||||||
|
. "$HOME/.bashrc"
|
||||||
|
fi
|
||||||
|
fi
|
||||||
|
|
||||||
|
# set PATH so it includes user's private bin if it exists
|
||||||
|
if [ -d "$HOME/bin" ] ; then
|
||||||
|
PATH="$HOME/bin:$PATH"
|
||||||
|
fi
|
||||||
|
|
||||||
|
# set PATH so it includes user's private bin if it exists
|
||||||
|
if [ -d "$HOME/.local/bin" ] ; then
|
||||||
|
PATH="$HOME/.local/bin:$PATH"
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [ -d "$HOME/.profile.d" ] ; then
|
||||||
|
for profile_script in $HOME/.profile.d/*.sh ; do
|
||||||
|
. "${profile_script}"
|
||||||
|
done
|
||||||
|
fi
|
||||||
|
|
||||||
@@ -0,0 +1,6 @@
|
|||||||
|
ANSIBLE_ACTIVATE="${HOME}/.ansible-venv/bin/activate"
|
||||||
|
|
||||||
|
if [ -r "${ANSIBLE_ACTIVATE}" ] ; then
|
||||||
|
VIRTUAL_ENV_DISABLE_PROMPT=true
|
||||||
|
. "${ANSIBLE_ACTIVATE}"
|
||||||
|
fi
|
||||||
@@ -0,0 +1,3 @@
|
|||||||
|
PermitRootLogin prohibit-password # Some software such as Proxmox requires key based root login
|
||||||
|
PasswordAuthentication no
|
||||||
|
PermitEmptyPasswords no
|
||||||
@@ -0,0 +1,63 @@
|
|||||||
|
#!/usr/bin/env bash
|
||||||
|
|
||||||
|
SCRIPT_NAME="$(basename "${0}")"
|
||||||
|
GIT_REPO_BRANCH="production"
|
||||||
|
OIC_FLAG="--only-if-changed"
|
||||||
|
|
||||||
|
# - Process command line
|
||||||
|
while [ $# -gt 0 ]; do
|
||||||
|
case "$1" in
|
||||||
|
-h|--help)
|
||||||
|
echo "Usage: $0 [--branch <branch name>]"
|
||||||
|
exit 0
|
||||||
|
;;
|
||||||
|
-b|--branch)
|
||||||
|
shift 1
|
||||||
|
if [ $# -eq 0 ] ; then echo "${SCRIPT_NAME}: ERROR - Branch not specified." ; exit 1 ; fi
|
||||||
|
GIT_REPO_BRANCH="$1"
|
||||||
|
shift 1
|
||||||
|
;;
|
||||||
|
-f|--force)
|
||||||
|
shift 1
|
||||||
|
OIC_FLAG=""
|
||||||
|
;;
|
||||||
|
--)
|
||||||
|
shift 1
|
||||||
|
break
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
echo "${SCRIPT_NAME}: ERROR - Invalid argument '${1}'." ; exit 2
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
done
|
||||||
|
|
||||||
|
VENV_ACTIVATE_SCRIPT="${HOME}/.ansible-venv/bin/activate"
|
||||||
|
LOCK_FILE="/var/run/lock/ansible-pull.sh.lock"
|
||||||
|
LOG_DIR="/var/log/ansible-pull.sh"
|
||||||
|
LOG_FILE="${LOG_DIR}/ansible-pull.sh.log"
|
||||||
|
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
||||||
|
GIT_REPO="${GIT_REPO_BASE}.git"
|
||||||
|
|
||||||
|
# - Include ansible virtual environment (in case not already done - we don't know how we're being run)
|
||||||
|
VIRTUAL_ENV_DISABLE_PROMPT=true
|
||||||
|
. "${VENV_ACTIVATE_SCRIPT}"
|
||||||
|
|
||||||
|
# - If we can't get a lock, don't proceed
|
||||||
|
if ! exec 9>"${LOCK_FILE}" ; then
|
||||||
|
echo "${SCRIPT_NAME}: ERROR - Unable to open the lock file (${LOCK_FILE})! Exiting..." >&2
|
||||||
|
exit 10
|
||||||
|
fi
|
||||||
|
if ! flock -n 9 ; then
|
||||||
|
echo "${SCRIPT_NAME}: ERROR - Another copy is already running! Exiting..." >&2
|
||||||
|
exit 11
|
||||||
|
fi
|
||||||
|
|
||||||
|
# - Append all further STDOUT and STDERR to the log file
|
||||||
|
exec >>"${LOG_FILE}" 2>&1
|
||||||
|
|
||||||
|
# - Log that we've gotten this far
|
||||||
|
echo
|
||||||
|
echo "${SCRIPT_NAME}: $(date "+%Y-%m-%d %H:%M:%S") ----------------------------------------"
|
||||||
|
|
||||||
|
# - Do our work
|
||||||
|
ansible-pull ${OIC_FLAG} --url "${GIT_REPO}" --checkout "${GIT_REPO_BRANCH}" "${@}"
|
||||||
@@ -0,0 +1,35 @@
|
|||||||
|
#!/usr/bin/env sh
|
||||||
|
|
||||||
|
if [ -z "${1:-}" ] ; then
|
||||||
|
echo "ERROR - ansible OS family unspecified." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
ANSIBLE_OS_FAMILY="${1}"
|
||||||
|
shift
|
||||||
|
|
||||||
|
useradd_D() {
|
||||||
|
|
||||||
|
case "${ANSIBLE_OS_FAMILY}" in
|
||||||
|
Debian)
|
||||||
|
/usr/sbin/useradd -D
|
||||||
|
;;
|
||||||
|
RedHat)
|
||||||
|
/usr/sbin/useradd -D
|
||||||
|
;;
|
||||||
|
*)
|
||||||
|
echo "ERROR - Unknown ansible OS FAMILY \"${ANSIBLE_OS_FAMILY}\"." >&2
|
||||||
|
exit 99
|
||||||
|
;;
|
||||||
|
esac
|
||||||
|
}
|
||||||
|
|
||||||
|
user_vars() {
|
||||||
|
useradd_D | sed 's/.*=/hpf_fact_\L&/'
|
||||||
|
}
|
||||||
|
|
||||||
|
#echo '{"hpf":'
|
||||||
|
#(user_vars; ) | jo
|
||||||
|
#echo '}'
|
||||||
|
|
||||||
|
user_vars
|
||||||
@@ -1,27 +0,0 @@
|
|||||||
#!/bin/bash
|
|
||||||
|
|
||||||
# - Fix branch to check out
|
|
||||||
|
|
||||||
. "${HOME}/.ansible-venv/bin/activate"
|
|
||||||
|
|
||||||
SCRIPT_NAME="$(basename "${0}")"
|
|
||||||
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
|
||||||
GIT_REPO="${GIT_REPO_BASE}.git"
|
|
||||||
LOG_DIR="/var/log/ansible-pull.sh"
|
|
||||||
LOG_FILE="${LOG_DIR}/ansible-pull.sh.log"
|
|
||||||
LOCK_FILE="/tmp/ansible-pull.sh.lock"
|
|
||||||
|
|
||||||
# - Redirect all further output to the log file
|
|
||||||
exec >>"${LOG_FILE}" 2>&1
|
|
||||||
|
|
||||||
# - Log that we've gotten this far
|
|
||||||
echo -n "$(basename "${0}"): $(date "+%Y-%m-%d %H:%M:%S")"
|
|
||||||
|
|
||||||
# - If we can't lock the lock file, don't proceed
|
|
||||||
exec 9>"${LOCK_FILE}"
|
|
||||||
if ! flock -n 9 ; then echo " - ERROR - Another copy of ${SCRIPT_NAME} is already running! Exiting..." ; exit 1 ; fi
|
|
||||||
|
|
||||||
# - Do our work
|
|
||||||
echo
|
|
||||||
ansible-pull --only-if-changed --url "${GIT_REPO}" --checkout main "${@}"
|
|
||||||
|
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBM5BBUOxkuSK7WlpaDvp6lrM9ajLSyh4PWD7VFzYOFN5/zfafy6Vf/oxtLE4UACw5ZGvBMQNH40bW+T9aO0lQ9g= first Heath@HPetersenFamily.com
|
||||||
@@ -0,0 +1 @@
|
|||||||
|
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBBFiio/AimTUloJdfk4TXyWO7A0Fd9SoUcqheBjEvj4TnrxpSL/EhwF2CU9jZTasm6NBo2eKcH4aMt1l2ejOtIM= Heath@HPetersenFamily.com
|
||||||
@@ -0,0 +1,89 @@
|
|||||||
|
|
||||||
|
heath
|
||||||
|
authorized_keys:
|
||||||
|
- heath@hpetersenfamily.com
|
||||||
|
password:
|
||||||
|
status: VALID
|
||||||
|
value: COMMON STRONG FOR ALL HOSTS
|
||||||
|
private_keys:
|
||||||
|
- FOR WORKSTATIONS: heath@hpetersenfamily.com # Can this even be done securely through Ansible?
|
||||||
|
first
|
||||||
|
authorized_keys:
|
||||||
|
- first@hpetersenfamily.com
|
||||||
|
- heath@hpetersenfamily.com
|
||||||
|
password:
|
||||||
|
status: VALID
|
||||||
|
value: UNIQUE LONG FOR EACH HOST
|
||||||
|
private_keys:
|
||||||
|
root
|
||||||
|
authorized_keys:
|
||||||
|
- heath@hpetersenfamily.com
|
||||||
|
password:
|
||||||
|
status: LOCKED
|
||||||
|
private_keys:
|
||||||
|
hpf-ans:
|
||||||
|
authorized_keys:
|
||||||
|
- heath@hpetersenfamily.com
|
||||||
|
password:
|
||||||
|
status: LOCKED
|
||||||
|
private_keys:
|
||||||
|
|
||||||
|
|
||||||
|
# Change to work with multiple distros (nothing hardcoded)
|
||||||
|
|
||||||
|
* create production, development branches
|
||||||
|
* cron job for ansible-pull
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
* Configure hosts
|
||||||
|
# cat >>/etc/hosts <<-!!TheEnd!!
|
||||||
|
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
|
||||||
|
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
|
||||||
|
!!TheEnd!!
|
||||||
|
|
||||||
|
|
||||||
|
##########
|
||||||
|
########## normal tasks
|
||||||
|
##########
|
||||||
|
|
||||||
|
- name: Install openssh, openssh-server, openssh-sftp-server
|
||||||
|
ansible.builtin.apt:
|
||||||
|
pkg:
|
||||||
|
- openssh
|
||||||
|
- openssh-server
|
||||||
|
- openssh-sftp-server
|
||||||
|
|
||||||
|
- name: Install bash, bash-completion
|
||||||
|
ansible.builtin.apt:
|
||||||
|
pkg:
|
||||||
|
- bash
|
||||||
|
- bash-completion
|
||||||
|
|
||||||
|
- name: Install chrony
|
||||||
|
ansible.builtin.apt:
|
||||||
|
pkg:
|
||||||
|
- chrony
|
||||||
|
|
||||||
|
#- name: Set host name
|
||||||
|
# ansible.builtin.hostname:
|
||||||
|
# name: ## Fully qualified domain name ##
|
||||||
|
# use: systemd
|
||||||
|
|
||||||
|
* Configure chrony
|
||||||
|
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
|
||||||
|
pool 0.north-america.pool.ntp.org iburst
|
||||||
|
!!TheEnd!!
|
||||||
|
|
||||||
|
|
||||||
|
~heath/.gitconfig
|
||||||
|
|
||||||
|
fail2ban
|
||||||
|
uptime kuma
|
||||||
|
|
||||||
|
==============================================================
|
||||||
|
==============================================================
|
||||||
|
==============================================================
|
||||||
|
|
||||||
|
use tags to do things like allow selecting software updates, software cleanup, etc.
|
||||||
|
|
||||||
@@ -0,0 +1,28 @@
|
|||||||
|
---
|
||||||
|
- name: Create user
|
||||||
|
hosts: all
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
|
||||||
|
- name: Create the second user
|
||||||
|
become: true
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: second
|
||||||
|
comment: second User
|
||||||
|
state: present
|
||||||
|
system: false
|
||||||
|
groups: hpf-sudo-np
|
||||||
|
append: true
|
||||||
|
create_home: true
|
||||||
|
shell: /usr/bin/bash
|
||||||
|
uid: 60002
|
||||||
|
|
||||||
|
- name: Set second's authorized_keys
|
||||||
|
become: true
|
||||||
|
ansible.posix.authorized_key:
|
||||||
|
user: second
|
||||||
|
state: present
|
||||||
|
key: "{{ lookup('file', item) }}"
|
||||||
|
loop:
|
||||||
|
- files/ssh-keys/second.pub
|
||||||
|
- files/ssh-keys/heath.pub
|
||||||
@@ -0,0 +1,34 @@
|
|||||||
|
---
|
||||||
|
|
||||||
|
- name: test-get_hpf_facts.yml
|
||||||
|
hosts: all
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
|
||||||
|
- name: Copy over get_hpf_facts.sh
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: hpf-ans/bin/get_hpf_facts.sh
|
||||||
|
dest: bin/get_hpf_facts.sh
|
||||||
|
owner: hpf-ans
|
||||||
|
group: hpf-ans
|
||||||
|
mode: u=rwx,go=gx
|
||||||
|
backup: true
|
||||||
|
|
||||||
|
- name: Run get_hpf_facts.sh
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: bin/get_hpf_facts.sh {{ ansible_facts["os_family"] }}
|
||||||
|
register: hpf_facts
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Convert k=v stdout into facts
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
"{{ item.split('=', 1)[0] }}": "{{ item.split('=', 1)[1] }}"
|
||||||
|
loop: "{{ hpf_facts.stdout.splitlines() }}"
|
||||||
|
|
||||||
|
- name: Print all variables
|
||||||
|
ansible.builtin.debug:
|
||||||
|
var: hostvars[inventory_hostname]
|
||||||
|
|
||||||
|
- name: Print skel
|
||||||
|
ansible.builtin.debug:
|
||||||
|
var: hpf_fact_skel
|
||||||
@@ -0,0 +1,70 @@
|
|||||||
|
---
|
||||||
|
|
||||||
|
- name: test-get_useradd_settings.sh
|
||||||
|
hosts: all
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
|
||||||
|
- name: Copy over bin/get_useradd_settings.sh
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: hpf-ans/bin/get_useradd_settings.sh
|
||||||
|
dest: bin/get_useradd_settings.sh
|
||||||
|
owner: hpf-ans
|
||||||
|
group: hpf-ans
|
||||||
|
mode: u=rwx,go=gx
|
||||||
|
backup: true
|
||||||
|
|
||||||
|
- name: Run get_useradd_settings.sh
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: bin/get_useradd_settings.sh {{ ansible_facts["os_family"] }}
|
||||||
|
register: useradd_settings
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Convert k=v stdout into variables
|
||||||
|
ansible.builtin.set_fact:
|
||||||
|
# great_heath:
|
||||||
|
# - "{{ item.split('=', 1)[0] }}": "{{ item.split('=', 1)[1] }}"
|
||||||
|
"HPF_{{ item.split('=', 1)[0] }}": "{{ item.split('=', 1)[1] }}"
|
||||||
|
# "{{ item.split('=', 1)[0] | trim }}": "{{ item.split('=', 1)[1] | trim }}"
|
||||||
|
loop: "{{ useradd_settings.stdout.splitlines() }}"
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
# - name: Convert key-value strings into variables
|
||||||
|
# vars:
|
||||||
|
# my_var: "SKEL= SKEL2=/etc/skel\nHEATH=great"
|
||||||
|
# ansible.builtin.set_fact: "{{ my_var }}"
|
||||||
|
|
||||||
|
# ansible.builtin.set_fact: "{{ useradd_settings.stdout }}"
|
||||||
|
|
||||||
|
# ansible.builtin.set_fact: "SKEL= SKEL2=/etc/skel\nHEATH=great"
|
||||||
|
|
||||||
|
# ansible.builtin.set_fact: "{{ useradd_settings.stdout | from_yaml }}"
|
||||||
|
|
||||||
|
# ansible.builtin.set_fact: "{{ useradd_settings.stdout }}"
|
||||||
|
|
||||||
|
# ansible.builtin.set_fact: "SKEL2=/etc/skel\nHEATH=great"
|
||||||
|
|
||||||
|
# - name: Convert key-value strings into variables
|
||||||
|
# ansible.builtin.set_fact:
|
||||||
|
# kv_vars: "{{ useradd_settings.stdout }}"
|
||||||
|
|
||||||
|
# - name: Print ansible variables
|
||||||
|
# ansible.builtin.debug:
|
||||||
|
# var: vars
|
||||||
|
|
||||||
|
# - name: Print SKEL
|
||||||
|
# ansible.builtin.debug:
|
||||||
|
# var: SKEL
|
||||||
|
# - name: Print heath.SKEL
|
||||||
|
# ansible.builtin.debug:
|
||||||
|
# var: heath.SKEL
|
||||||
|
# - name: Print SKEL2
|
||||||
|
# ansible.builtin.debug:
|
||||||
|
# var: SKEL2
|
||||||
|
# - name: Print HEATH
|
||||||
|
# ansible.builtin.debug:
|
||||||
|
# var: HEATH
|
||||||
|
- name: Print all variables
|
||||||
|
ansible.builtin.debug:
|
||||||
|
var: vars
|
||||||
Reference in New Issue
Block a user