--- #### #### WARNING: #### #### bootstrap.sh and bootstrap.yml should be updated together. They should do the #### exact same things with the following exceptions: #### #### * bootstrap.sh #### - at the end it should run ansible-pull.sh against bootstrap.yml #### #### * bootstrap.yml #### - at the end it should configure cron to schedule ansible-pull.sh #### #### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! #### ! Make sure to keep them in sync ! #### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! #### # Update software repositories here # Change the following to work with multiple distros - name: bootstrap hosts: all tasks: - name: Install bootstrap packages ansible.builtin.apt: become: yes state: latest pkg: - bash - curl - python3 - python3-pip - python3-venv - python3-virtualenv - name: Make sure hpf-sudo group exists ansible.builtin.group: become: yes name: hpf-sudo state: present system: true gid: 700 - name: Make sure hpf-sudo-np group exists ansible.builtin.group: become: yes name: hpf-sudo-np state: present system: true gid: 701 - name: Copy over /etc/sudoers.d/hpf ansible.builtin.copy: become: yes src: etc_sudoers_d_hpf dest: /etc/sudoers.d/hpf owner: root group: root mode: u=rw,go= backup: true validate: /usr/sbin/visudo -csf %s #### .profile.d should be in SKEL directory - look it up - name: Make sure .profile.d directory exists ansible.builtin.file: become: true path: /etc/skel/.profile.d state: directory owner: root group: root mode: u=rwx,go= #### ansible-venv.sh should be in SKEL directory - look it up - name: Copy over ansible-venv.sh ansible.builtin.copy: become: true src: profile_d_ansible_venv_sh dest: /etc/skel/.profile.d/ansible-pull.sh owner: root group: root mode: u=rwx,go= backup: true #### .profile - name: Make sure hpf-ans group exists ansible.builtin.group: become: yes name: hpf-ans state: present system: true gid: 800 - name: Make sure hpf-ans user exists ansible.builtin.user: become: yes name: hpf-ans state: present system: true uid: 800 group: hpf-ans groups: hpf-sudo-np append: yes create_home: true shell: /bin/bash - name: Install latest version of pip in .ansible-venv ansible.builtin.pip: name: pip virtualenv: $HOME/.ansible-venv extra_args: --upgrade - name: Install latest version of ansible in .ansible-venv ansible.builtin.pip: name: ansible virtualenv: $HOME/.ansible-venv extra_args: "--upgrade" - name: Make sure bin directory exists ansible.builtin.file: path: $HOME/bin state: directory owner: hpf-ans group: hpf-ans mode: u=rwx,go= - name: Copy over bin/ansible-pull.sh ansible.builtin.copy: src: home_hpf_ans_bin_ansible_pull_sh dest: $HOME/bin/ansible-pull.sh owner: hpf-ans group: hpf-ans mode: u=rwx,go= backup: true - name: Make sure log directory exists ansible.builtin.file: become: yes path: /var/log/ansible-pull.sh state: directory owner: hpf-ans group: root mode: ug=rwx,o= # - name: Create ansible-pull.sh crontab entry # ansible.builtin.cron: # name: "ansible-pull" # minute: "*/27" # job: $HOME/bin/ansible-pull.sh # backup: true # become: no