#!/bin/sh #### #### WARNING: #### #### bootstrap.sh and bootstrap.yml should be updated together. They should do the #### exact same things with the following exceptions: #### #### * bootstrap.sh #### - at the end it should run ansible-pull.sh against bootstrap.yml #### #### * bootstrap.yml #### - at the end it should configure cron to schedule ansible-pull.sh #### #### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! #### ! Make sure to keep them in sync ! #### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! #### # #### VARIABLES # GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible" GIT_REPO="${GIT_REPO_BASE}.git" GIT_REPO_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/files/etc_sudoers_d_hpf" GIT_REPO_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/files/home_hpf_ans_bin_ansible_pull_sh" ETC_sudoers_d_hpf="/etc/sudoers.d/hpf" HPF_ANS_ansible_venv="\${HOME}/.ansible-venv" HPF_ANS_activate="${HPF_ANS_ansible_venv}/bin/activate" HPF_ANS_bin="\${HOME}/bin" HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh" ANSIBLE_PULL_SH_LOG_DIR="/var/log/ansible-pull.sh" # #### FUNCTIONS # # $group_name $group_number group_exists () { grep -q "^$1:[^:]*:$2:" /etc/group } # $user_name $user_number user_exists () { grep -q "^$1:[^:]*:$2:$2:" /etc/passwd } # $group_name $group_number system_groupadd () { if group_exists "$1" "$2" ; then return 0 ; fi groupadd -r -g "$2" "$1" rc=$? if [ $rc -ne 0 ] ; then echo "ERROR - Unable to add $1 group! ($rc)" >&2 exit 1 fi } # $user_name $user_number system_useradd () { if user_exists "$1" "$2" ; then return 0 ; fi system_groupadd "${@}" useradd -r -u "$2" -g "$2" -s /bin/bash -m "$1" rc=$? if [ $rc -ne 0 ] ; then echo "ERROR - Unable to add $1 user! ($rc)" >&2 exit 2 fi } # $groups $user_name add_groups_to_user () { usermod -aG "$1" "$2" rc=$? if [ $rc -ne 0 ] ; then echo "ERROR - Unable to add groups ($1) to user ($2)! ($rc)" >&2 exit 3 fi } # $command_line as_hpf_ans () { su --login hpf-ans -c "if [ -r \"${HPF_ANS_activate}\" ] ; then source \"${HPF_ANS_activate}\" ; fi ; ${1}" } # #### PROCESS # # Make sure we're running as root if [ $(id -u) -ne 0 ] ; then echo "ERROR - Not running as root!" >&2 exit 100 fi # Install minimal necessary packages if which -s apt ; then apt update apt install bash curl python3 python3-pip python3-venv python3-virtualenv -y else echo "ERROR - Unable to determine how to install packages" >&2 exit 101 fi # Create system group hpf-sudo for normal sudo users system_groupadd hpf-sudo 700 # Create system group hpf-sudo-np for special sudo users that don't require a password system_groupadd hpf-sudo-np 701 # Create /etc/sudoers.d/hpf to allow common sudo permissions rm "${ETC_sudoers_d_hpf}" 2>/dev/null curl -o "$ETC_sudoers_d_hpf" "${GIT_REPO_sudoers_d_hpf}" chown root:root "${ETC_sudoers_d_hpf}" chmod u=rw,go= "${ETC_sudoers_d_hpf}" # Create the hpf-ans user system_useradd hpf-ans 800 add_groups_to_user hpf-sudo-np hpf-ans # Make sure .ansible-venv exists as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi" # Make sure pip is up to date as_hpf_ans "pip install --upgrade pip" # Make sure ansible is installed as_hpf_ans "pip install --upgrade ansible" # Make sure bin exists as_hpf_ans "mkdir -p \"${HPF_ANS_bin}\"" as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_bin}\"; chmod u=rwx,go= \"${HPF_ANS_bin}\"" # Create ~hpf-ans/bin/ansible-pull.sh as_hpf_ans "rm \"${HPF_ANS_ansible_pull_sh}\" 2>/dev/null" as_hpf_ans "curl -o \"${HPF_ANS_ansible_pull_sh}\" \"${GIT_REPO_ansible_pull_sh}\"" as_hpf_ans "chown hpf-ans:hpf-ans \"${HPF_ANS_ansible_pull_sh}\"; chmod u=rwx,go= \"${HPF_ANS_ansible_pull_sh}\"" # Make sure log directory exists mkdir -p "${ANSIBLE_PULL_SH_LOG_DIR}" chown hpf-ans:root "${ANSIBLE_PULL_SH_LOG_DIR}"; chmod ug=rwx,o= "${ANSIBLE_PULL_SH_LOG_DIR}" # Run ansible-pull to finish up as_hpf_ans "bin/ansible-pull.sh bootstrap.yml"