129 lines
3.1 KiB
Bash
129 lines
3.1 KiB
Bash
#!/bin/sh
|
|
|
|
|
|
#
|
|
#### VARIABLES
|
|
#
|
|
|
|
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
|
GIT_REPO="${GIT_REPO_BASE}.git"
|
|
GIT_REPO_etc_sudoers_d_hpf="${GIT_REPO_BASE}/raw/branch/main/etc_sudoers_d_hpf"
|
|
GIT_REPO_home_hpf_ans_bin_ansible_pull_sh="${GIT_REPO_BASE}/raw/branch/main/home_hpf_ans_bin_ansible-pull.sh"
|
|
|
|
VENV_DIRECTORY="\${HOME}/.ansible-venv"
|
|
VENV_ACTIVATE="${VENV_DIRECTORY}/bin/activate"
|
|
|
|
ANSIBLE_PULL_LOG="/var/log/ansible-pull.log"
|
|
|
|
|
|
#
|
|
#### FUNCTIONS
|
|
#
|
|
|
|
# $group_name $group_number
|
|
group_exists () {
|
|
grep -q "^$1:[^:]*:$2:" /etc/group
|
|
}
|
|
|
|
# $user_name $user_number
|
|
user_exists () {
|
|
grep -q "^$1:[^:]*:$2:$2:" /etc/passwd
|
|
}
|
|
|
|
# $group_name $group_number
|
|
system_groupadd () {
|
|
if group_exists "$1" "$2" ; then return 0 ; fi
|
|
groupadd -r -g "$2" "$1"
|
|
rc=$?
|
|
if [ $rc -ne 0 ] ; then
|
|
echo "ERROR - Unable to add $1 group! ($rc)" 1>&2
|
|
exit 1
|
|
fi
|
|
}
|
|
|
|
# $user_name $user_number
|
|
system_useradd () {
|
|
if user_exists "$1" "$2" ; then return 0 ; fi
|
|
system_groupadd "${@}"
|
|
useradd -r -u "$2" -g "$2" -s /bin/bash -m "$1"
|
|
rc=$?
|
|
if [ $rc -ne 0 ] ; then
|
|
echo "ERROR - Unable to add $1 user! ($rc)" 1>&2
|
|
exit 2
|
|
fi
|
|
}
|
|
|
|
# $groups $user_name
|
|
add_groups_to_user () {
|
|
usermod -aG "$1" "$2"
|
|
rc=$?
|
|
if [ $rc -ne 0 ] ; then
|
|
echo "ERROR - Unable to add groups ($1) to user ($2)! ($rc)" 1>&2
|
|
exit 3
|
|
fi
|
|
}
|
|
|
|
# $command_line
|
|
as_hpf_ans () {
|
|
su --login hpf-ans -c "if [ -r \"${VENV_ACTIVATE}\" ] ; then source \"${VENV_ACTIVATE}\" ; fi ; ${1}"
|
|
}
|
|
|
|
|
|
#
|
|
#### PROCESS
|
|
#
|
|
|
|
# Make sure we're running as root
|
|
if [ $(id -u) -ne 0 ] ; then
|
|
echo "ERROR - Not running as root!" 1>&2
|
|
exit 100
|
|
fi
|
|
|
|
# Install minimal necessary packages
|
|
if which -s apt ; then
|
|
apt update
|
|
apt install bash curl python3 python3-pip python3-venv -y
|
|
else
|
|
echo "ERROR - Unable to determine how to install packages" 1>&2
|
|
exit 101
|
|
fi
|
|
|
|
# Create system group hpf-sudo for normal sudo users
|
|
system_groupadd hpf-sudo 700
|
|
|
|
# Create system group hpf-sudo-np for special sudo users that don't require a password
|
|
system_groupadd hpf-sudo-np 701
|
|
|
|
# Create the Ansible user
|
|
system_useradd hpf-ans 800
|
|
add_groups_to_user "hpf-sudo-np" hpf-ans
|
|
|
|
# Create /etc/sudoers.d/hpf
|
|
f="/etc/sudoers.d/hpf"
|
|
rm "${f}" 2>/dev/null
|
|
curl -o "$f" "${GIT_REPO_etc_sudoers_d_hpf}"
|
|
chown root:root "$f"
|
|
chmod u=rw,g=r,o= "$f"
|
|
|
|
# Make sure the hpf-ans ansible venv exists
|
|
as_hpf_ans "if [ ! -d \"${VENV_DIRECTORY}\" ] ; then python3 -m venv \"${VENV_DIRECTORY}\" ; fi"
|
|
|
|
# Make sure pip is up to date in .ansible-venv
|
|
as_hpf_ans "pip install --upgrade pip"
|
|
|
|
# Make sure ansible is installed in .ansible-venv
|
|
as_hpf_ans "pip install ansible"
|
|
|
|
# Create ~hpf-ans/bin directory
|
|
d="\${HOME}/bin"
|
|
as_hpf_ans "mkdir -p \"${d}\"; chown hpf-ans:hpf-ans \"${d}\"; chmod ug=rwx,o= \"${d}\""
|
|
|
|
# Create ~hpf-ans/bin/ansible-pull.sh
|
|
f="\${HOME}/bin/ansible-pull.sh"
|
|
as_hpf_ans "rm \"${f}\" 2>/dev/null"
|
|
as_hpf_ans "curl -o \"${f}\" \"${GIT_REPO_home_hpf_ans_bin_ansible_pull_sh}\""
|
|
as_hpf_ans "chown hpf-ans:hpf-ans \"${f}\"; chmod ug=rwx,o= \"${f}\""
|
|
|
|
# Run ansible-pull to finish up
|
|
as_hpf_ans "bin/ansible-pull.sh"
|