Files
ansible/bootstrap.yml

132 lines
3.0 KiB
YAML

---
####
#### WARNING:
####
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
#### exact same things with the following exceptions:
####
#### * bootstrap.sh
#### - at the end it should run ansible-pull.sh against bootstrap.yml
####
#### * bootstrap.yml
#### - at the end it should configure cron to schedule ansible-pull.sh
####
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
#### ! Make sure to keep them in sync !
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
####
# Update software repositories here
# Change the following to work with multiple distros
- name: bootstrap
hosts: all
become: yes
tasks:
- name: Install bootstrap packages
ansible.builtin.apt:
state: latest
pkg:
- bash
- curl
- python3
- python3-pip
- python3-venv
- python3-virtualenv
- name: Make sure hpf-sudo group exists
ansible.builtin.group:
name: hpf-sudo
state: present
system: true
gid: 700
- name: Make sure hpf-sudo-np group exists
ansible.builtin.group:
name: hpf-sudo-np
state: present
system: true
gid: 701
- name: Copy over /etc/sudoers.d/hpf
ansible.builtin.copy:
src: etc_sudoers_d_hpf
dest: /etc/sudoers.d/hpf
owner: root
group: root
mode: u=rw,go=
backup: true
validate: /usr/sbin/visudo -csf %s
- name: Make sure hpf-ans group exists
ansible.builtin.group:
name: hpf-ans
state: present
system: true
gid: 800
- name: Make sure hpf-ans user exists
ansible.builtin.user:
name: hpf-ans
state: present
system: true
uid: 800
group: hpf-ans
groups: hpf-sudo-np
append: yes
create_home: true
shell: /bin/bash
- name: Install latest version of pip in .ansible-venv
ansible.builtin.pip:
name: pip
virtualenv: $HOME/.ansible-venv
extra_args: --upgrade
become: no
- name: Install latest version of ansible in .ansible-venv
ansible.builtin.pip:
name: ansible
virtualenv: $HOME/.ansible-venv
extra_args: "--upgrade"
become: no
- name: Make sure bin directory exists
ansible.builtin.file:
path: $HOME/bin
state: directory
owner: hpf-ans
group: hpf-ans
mode: u=rwx,go=
become: no
- name: Copy over bin/ansible-pull.sh
ansible.builtin.copy:
src: home_hpf_ans_bin_ansible_pull_sh
dest: $HOME/bin/ansible-pull.sh
owner: hpf-ans
group: hpf-ans
mode: u=rwx,go=
backup: true
become: no
- name: Make sure log directory exists
ansible.builtin.file:
path: /var/log/ansible-pull.sh
state: directory
owner: hpf-ans
group: root
mode: ug=rwx,o=
# - name: Create ansible-pull.sh crontab entry
# ansible.builtin.cron:
# name: "ansible-pull"
# minute: "*/27"
# job: $HOME/bin/ansible-pull.sh
# backup: true
# become: no