124 lines
3.2 KiB
Plaintext
124 lines
3.2 KiB
Plaintext
|
|
|
|
|
|
* create bootstrap, production, development branches
|
|
* have bootstrap.sh get ansible_pull_branch variable value
|
|
|
|
* have the following appended to .profile
|
|
if [ -d "$HOME/.profile.d" ] ; then
|
|
for profile_script in $HOME/.profile.d/*.sh ; do
|
|
. "${profile_script}"
|
|
done
|
|
fi
|
|
* create ~/.profile.d
|
|
* create ~/.profile.d/ansible-venv.sh
|
|
ansible.builtin.blockinfile
|
|
|
|
|
|
|
|
# add /home/hpf-ans/bin/ansible-pull.sh crontab
|
|
|
|
|
|
|
|
* Configure hosts
|
|
# cat >>/etc/hosts <<!!TheEnd!!
|
|
|
|
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
|
|
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
|
|
!!TheEnd!!
|
|
* Configure chrony
|
|
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
|
|
pool 0.north-america.pool.ntp.org iburst
|
|
!!TheEnd!!
|
|
* Configure SSH
|
|
# cat >/etc/ssh/sshd_config.d/hpetersenfamily.conf <<!!TheEnd!!
|
|
PasswordAuthentication no
|
|
PermitEmptyPasswords no
|
|
PermitRootLogin no
|
|
!!TheEnd!!
|
|
# cat >>/home/first/.ssh/authorized_keys <<!!TheEnd!!
|
|
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBM5BBUOxkuSK7WlpaDvp6lrM9ajLSyh4PWD7VFzYOFN5/zfafy6Vf/oxtLE4UACw5ZGvBMQNH40bW+T9aO0lQ9g= first Heath@HPetersenFamily.com
|
|
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBBFiio/AimTUloJdfk4TXyWO7A0Fd9SoUcqheBjEvj4TnrxpSL/EhwF2CU9jZTasm6NBo2eKcH4aMt1l2ejOtIM= heath Heath@HPetersenFamily.com
|
|
!!TheEnd!!
|
|
|
|
|
|
##########
|
|
########## normal tasks
|
|
##########
|
|
|
|
- name: Install openssh, openssh-server, openssh-sftp-server
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- openssh
|
|
- openssh-server
|
|
- openssh-sftp-server
|
|
|
|
- name: Install bash, bash-completion
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- bash
|
|
- bash-completion
|
|
|
|
- name: Install chrony
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- chrony
|
|
|
|
#- name: Set host name
|
|
# ansible.builtin.hostname:
|
|
# name: ## Fully qualified domain name ##
|
|
# use: systemd
|
|
|
|
|
|
- name: Copy a new sudoers file into place, after passing validation with visudo
|
|
ansible.builtin.template:
|
|
src: /mine/sudoers
|
|
dest: /etc/sudoers
|
|
validate: /usr/sbin/visudo -cf %s
|
|
|
|
- name: Update sshd configuration safely, avoid locking yourself out
|
|
ansible.builtin.template:
|
|
src: etc/ssh/sshd_config.j2
|
|
dest: /etc/ssh/sshd_config
|
|
owner: root
|
|
group: root
|
|
mode: '0600'
|
|
validate: /usr/sbin/sshd -t -f %s
|
|
backup: yes
|
|
|
|
|
|
proxmox-clients
|
|
hw:
|
|
pve-lxc:
|
|
pve-oci:
|
|
pve-kvm:
|
|
|
|
|
|
users: first, heath, hpf-ans
|
|
|
|
~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
|
|
~heath/.ssh/authorized_keys
|
|
~first/.ssh/authorized_keys
|
|
~heath/.gitconfig
|
|
|
|
|
|
|
|
|
|
fail2ban
|
|
uptime kuma
|
|
|
|
==============================================================
|
|
==============================================================
|
|
==============================================================
|
|
|
|
logrotate /var/log/ansible-pull.log
|
|
cron job for ansible-pull
|
|
|
|
|
|
use tags to do things like allow selecting software updates, software cleanup, etc.
|
|
ansible_os_family variable
|
|
ansible galaxy
|
|
|
|
have upgrade pip and ansible in ~hpf-ans/.ansible-venv
|
|
hashicorp vault
|
|
have ansible-pull.sh make sure only one copy is running |