#!/usr/bin/env sh #### #### WARNING: #### #### bootstrap.sh and bootstrap.yml should be updated together. They should do the #### exact same things with the following exceptions: #### #### * bootstrap.sh #### - at the end it should run ansible-pull.sh against bootstrap.yml #### #### * bootstrap.yml #### - at the end it should configure cron to schedule ansible-pull.sh #### #### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! #### ! Make sure to keep them in sync ! #### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! #### # #### VARIABLES # TIMESTAMP="$(date "+%Y%m%d%H%M%S")" GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible" GIT_REPO_BRANCH="${1:-"development"}" GIT_REPO_FILES="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files" GIT_REPO_sudoers_d_hpf="${GIT_REPO_FILES}/etc/sudoers.d/hpf" GIT_REPO_SKEL_ansible_venv_sh="${GIT_REPO_FILES}/etc/skel/.profile.d/ansible-venv.sh" GIT_REPO_SKEL_profile="${GIT_REPO_FILES}/etc/skel/.profile" GIT_REPO_ansible_pull_sh="${GIT_REPO_FILES}/home/hpf-ans/bin/ansible-pull.sh" ETC_sudoers_d="/etc/sudoers.d" ETC_sudoers_d_hpf="${ETC_sudoers_d}/hpf" unset SKEL if [ -r /etc/default/useradd ] ; then . /etc/default/useradd ; fi SKEL="${SKEL:-/etc/skel}" SKEL_profile_d="${SKEL}/.profile.d" SKEL_ansible_venv_sh="${SKEL_profile_d}/ansible-venv.sh" SKEL_profile="${SKEL}/.profile" ANSIBLE_PULL_SH_LOG_DIR="/var/log/ansible-pull.sh" # #### FUNCTIONS # # $group_name $group_number group_exists () { grep -q "^$1:[^:]*:$2:" /etc/group } # $user_name $user_number user_exists () { grep -q "^$1:[^:]*:$2:$2:" /etc/passwd } # $group_name $group_number system_groupadd () { if group_exists "$1" "$2" ; then return 0 ; fi groupadd -r -g "$2" "$1" rc=$? if [ $rc -ne 0 ] ; then echo "ERROR - Unable to add $1 group! ($rc)" >&2 exit 1 fi } # $user_name $user_number system_useradd () { if user_exists "$1" "$2" ; then return 0 ; fi system_groupadd "${@}" useradd -r -u "$2" -g "$2" -s /usr/bin/bash -m "$1" rc=$? if [ $rc -ne 0 ] ; then echo "ERROR - Unable to add $1 user! ($rc)" >&2 exit 2 fi } # $groups $user_name add_groups_to_user () { usermod -aG "$1" "$2" rc=$? if [ $rc -ne 0 ] ; then echo "ERROR - Unable to add groups ($1) to user ($2)! ($rc)" >&2 exit 3 fi } # $source_file $dest_file $dest_file_ownership $dest_file_permissions get_file() { local source_file dest_file dest_file_ownership dest_file_permissions source_file="${1}" dest_file="${2}" dest_file_ownership="${3}" dest_file_permissions="${4}" if [ -e "${dest_file}" ] ; then mv "${dest_file}" "${dest_file}.${TIMESTAMP}" ; fi if ! curl -f -o "${dest_file}" "${source_file}" ; then echo "ERROR - Unable to download \"${source_file}\"" >&2 echo " to \"${dest_file}\"." >&2 exit 4 fi if ! chown "${dest_file_ownership}" "${dest_file}" ; then echo "ERROR - Unable to change ownership of \"${dest_file}\" to \"${dest_file_ownership}\"" >&2 exit 4 fi if ! chmod "${dest_file_permissions}" "${dest_file}" ; then echo "ERROR - Unable to change permissions of \"${dest_file}\" to \"${dest_file_permissions}\"" >&2 exit 4 fi } # $directory $directory_ownership $directory_permissions create_directory() { local directory directory_ownership directory_permissions directory="${1}" directory_ownership="${2}" directory_permissions="${3}" if ! mkdir -p "${directory}" ; then echo "ERROR - Unable to create directory \"${directory}\"" >&2 exit 5 fi if ! chown "${directory_ownership}" "${directory}" ; then echo "ERROR - Unable to change ownership of \"${directory}\" to \"${directory_ownership}\"" >&2 exit 5 fi if ! chmod "${directory_permissions}" "${directory}" ; then echo "ERROR - Unable to change permissions of \"${directory}\" to \"${directory_permissions}\"" >&2 exit 5 fi } # $command_line as_hpf_ans () { su --login hpf-ans --command "${1}" } # #### PROCESS # # Make sure we're running as root if [ "$(id -u)" -ne 0 ] ; then echo "ERROR - Not running as root" >&2 exit 100 fi # Install minimal necessary packages if which -s apt ; then apt update apt install bash curl python3 python3-pip python3-venv python3-virtualenv -y else echo "ERROR - Unable to determine how to install packages" >&2 exit 101 fi # Create system group hpf-sudo for normal sudo users system_groupadd hpf-sudo 700 # Create system group hpf-sudo-np for special sudo users that don't require a password system_groupadd hpf-sudo-np 701 # Make sure /etc/sudoers.d exists create_directory "${ETC_sudoers_d}" "root:root" "u=rwx,go=" # Get /etc/sudoers.d/hpf get_file "${GIT_REPO_sudoers_d_hpf}" "${ETC_sudoers_d_hpf}" "root:root" "u=rw,go=" # Make sure /etc/skel/.profile.d exists create_directory "${SKEL_profile_d}" "root:root" "u=rwx,go=" # Get /etc/skel/.profile.d/ansible-venv.sh get_file "${GIT_REPO_SKEL_ansible_venv_sh}" "${SKEL_ansible_venv_sh}" "root:root" "u=rw,go=" # Get /etc/skel/.profile get_file "${GIT_REPO_SKEL_profile}" "${SKEL_profile}" "root:root" "u=rw,go=r" # Create the hpf-ans user system_useradd hpf-ans 800 add_groups_to_user hpf-sudo-np hpf-ans # Set HPF_ANS variables now that the user is created HPF_ANS_HOME="$(as_hpf_ans 'echo "${HOME}"')" HPF_ANS_ansible_venv="${HPF_ANS_HOME}/.ansible-venv" HPF_ANS_bin="${HPF_ANS_HOME}/bin" HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh" # Make sure /home/hpf-ans/.ansible-venv exists as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi" # Make sure pip is up to date as_hpf_ans "pip install --upgrade pip" # Make sure ansible is up to date as_hpf_ans "pip install --upgrade ansible" # Make sure /home/hpf-ans/bin exists create_directory "${HPF_ANS_bin}" "hpf-ans:hpf-ans" "u=rwx,go=" # Get /home/hpf-ans/bin/ansible-pull.sh get_file "${GIT_REPO_ansible_pull_sh}" "${HPF_ANS_ansible_pull_sh}" "hpf-ans:hpf-ans" "u=rwx,go=" # Make sure log directory exists create_directory "${ANSIBLE_PULL_SH_LOG_DIR}" "hpf-ans:root" "u=rwx,go=" # Run ansible-pull to finish up #as_hpf_ans "$HPF_ANS_ansible_pull_sh --branch ${GIT_REPO_BRANCH} bootstrap.yml"