181 lines
4.1 KiB
YAML
181 lines
4.1 KiB
YAML
---
|
|
|
|
####
|
|
#### WARNING:
|
|
####
|
|
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
|
|
#### exact same things with the following exceptions:
|
|
####
|
|
#### * bootstrap.sh
|
|
#### - at the end it should run ansible-pull.sh against bootstrap.yml
|
|
####
|
|
#### * bootstrap.yml
|
|
#### - at the end it should configure cron to schedule ansible-pull.sh
|
|
####
|
|
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
|
#### ! Make sure to keep them in sync !
|
|
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
|
####
|
|
|
|
|
|
# Update software repositories here
|
|
# Change the following to work with multiple distros
|
|
|
|
- name: bootstrap.yml
|
|
hosts: all
|
|
|
|
tasks:
|
|
|
|
- name: Update repositories
|
|
become: true
|
|
ansible.builtin.apt:
|
|
update_cache: yes
|
|
|
|
- name: Install bootstrap packages
|
|
become: true
|
|
ansible.builtin.apt:
|
|
state: latest
|
|
pkg:
|
|
- bash
|
|
- curl
|
|
- python3
|
|
- python3-pip
|
|
- python3-venv
|
|
- python3-virtualenv
|
|
|
|
- name: Create system group hpf-sudo for normal sudo users
|
|
become: true
|
|
ansible.builtin.group:
|
|
name: hpf-sudo
|
|
state: present
|
|
system: true
|
|
gid: 700
|
|
|
|
- name: Create system group hpf-sudo-np for special sudo users that don't require a password
|
|
become: true
|
|
ansible.builtin.group:
|
|
name: hpf-sudo-np
|
|
state: present
|
|
system: true
|
|
gid: 701
|
|
|
|
- name: Make sure /etc/sudoers.d exists
|
|
become: true
|
|
ansible.builtin.file:
|
|
path: /etc/sudoers.d
|
|
state: directory
|
|
owner: root
|
|
group: root
|
|
mode: u=rwx,go=
|
|
|
|
- name: Get /etc/sudoers.d/hpf
|
|
become: true
|
|
ansible.builtin.copy:
|
|
src: etc/sudoers.d/hpf
|
|
dest: /etc/sudoers.d/hpf
|
|
owner: root
|
|
group: root
|
|
mode: u=rw,go=
|
|
backup: true
|
|
validate: /usr/sbin/visudo -csf %s
|
|
|
|
- name: Make sure /etc/skel/.profile.d exists
|
|
become: true
|
|
ansible.builtin.file:
|
|
path: /etc/skel/.profile.d
|
|
state: directory
|
|
owner: root
|
|
group: root
|
|
mode: u=rwx,go=
|
|
|
|
- name: Get /etc/skel/.profile.d/ansible-venv.sh
|
|
become: true
|
|
ansible.builtin.copy:
|
|
src: etc/skel/.profile.d/ansible-venv.sh
|
|
dest: /etc/skel/.profile.d/ansible-venv.sh
|
|
owner: root
|
|
group: root
|
|
mode: u=rw,go=
|
|
backup: true
|
|
|
|
- name: Get /etc/skel/.profile
|
|
become: true
|
|
ansible.builtin.copy:
|
|
src: etc/skel/.profile
|
|
dest: /etc/skel/.profile
|
|
owner: root
|
|
group: root
|
|
mode: u=rw,go=
|
|
backup: true
|
|
|
|
- name: Create the hpf-ans group
|
|
become: true
|
|
ansible.builtin.group:
|
|
name: hpf-ans
|
|
state: present
|
|
system: true
|
|
gid: 800
|
|
|
|
- name: Create the hpf-ans user
|
|
become: true
|
|
ansible.builtin.user:
|
|
name: hpf-ans
|
|
state: present
|
|
system: true
|
|
uid: 800
|
|
group: hpf-ans
|
|
groups: hpf-sudo-np
|
|
append: yes
|
|
create_home: true
|
|
shell: /usr/bin/bash
|
|
|
|
- name: Make sure pip is up to date
|
|
become: false
|
|
ansible.builtin.pip:
|
|
name: pip
|
|
virtualenv: $HOME/.ansible-venv
|
|
extra_args: --upgrade
|
|
|
|
- name: Make sure ansible is up to date
|
|
become: false
|
|
ansible.builtin.pip:
|
|
name: ansible
|
|
virtualenv: $HOME/.ansible-venv
|
|
extra_args: --upgrade
|
|
|
|
- name: Make sure /home/hpf-ans/bin exists
|
|
become: false
|
|
ansible.builtin.file:
|
|
path: $HOME/bin
|
|
state: directory
|
|
owner: hpf-ans
|
|
group: hpf-ans
|
|
mode: u=rwx,go=
|
|
|
|
- name: Get /home/hpf-ans/bin/ansible-pull.sh
|
|
become: false
|
|
ansible.builtin.copy:
|
|
src: home/hpf-ans/bin/ansible-pull.sh
|
|
dest: $HOME/bin/ansible-pull.sh
|
|
owner: hpf-ans
|
|
group: hpf-ans
|
|
mode: u=rwx,go=
|
|
backup: true
|
|
|
|
- name: Make sure log directory exists
|
|
become: true
|
|
ansible.builtin.file:
|
|
path: /var/log/ansible-pull.sh
|
|
state: directory
|
|
owner: hpf-ans
|
|
group: root
|
|
mode: ug=rwx,o=
|
|
|
|
# - name: Create ansible-pull.sh crontab entry
|
|
# become: true
|
|
# ansible.builtin.cron:
|
|
# name: "ansible-pull"
|
|
# minute: "*/27"
|
|
# job: $HOME/bin/ansible-pull.sh
|
|
# backup: true
|