205 lines
5.6 KiB
Bash
205 lines
5.6 KiB
Bash
#!/usr/bin/env sh
|
|
|
|
####
|
|
#### WARNING:
|
|
####
|
|
#### bootstrap.sh and bootstrap.yml should be updated together. They should do the
|
|
#### exact same things with the following exceptions:
|
|
####
|
|
#### * bootstrap.sh
|
|
#### - at the end it should run ansible-pull.sh against bootstrap.yml
|
|
####
|
|
#### * bootstrap.yml
|
|
#### - at the end it should configure cron to schedule ansible-pull.sh
|
|
####
|
|
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
|
#### ! Make sure to keep them in sync !
|
|
#### !!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
|
|
####
|
|
|
|
|
|
#
|
|
#### VARIABLES
|
|
#
|
|
|
|
TIMESTAMP="$(date "+%Y%m%d%H%M%S")"
|
|
|
|
GIT_REPO_BASE="https://gitea.admin-a.hpetersenfamily.com/heath/ansible"
|
|
GIT_REPO_BRANCH="${1:-"development"}"
|
|
|
|
GIT_REPO_FILES="${GIT_REPO_BASE}/raw/branch/${GIT_REPO_BRANCH}/files"
|
|
|
|
GIT_REPO_sudoers_d_hpf="${GIT_REPO_FILES}/etc/sudoers.d/hpf"
|
|
GIT_REPO_SKEL_ansible_venv_sh="${GIT_REPO_FILES}/etc/skel/.profile.d/ansible-venv.sh"
|
|
GIT_REPO_SKEL_profile="${GIT_REPO_FILES}/files/etc/skel/.profile"
|
|
GIT_REPO_ansible_pull_sh="${GIT_REPO_FILES}/ansible_pull_sh"
|
|
|
|
ETC_sudoers_d="/etc/sudoers.d"
|
|
ETC_sudoers_d_hpf="${ETC_sudoers_d}/hpf"
|
|
|
|
unset SKEL
|
|
if [ -r /etc/default/useradd ] ; then . /etc/default/useradd ; fi
|
|
SKEL="${SKEL:-/etc/skel}"
|
|
SKEL_profile_d="${SKEL}/.profile.d"
|
|
SKEL_ansible_venv_sh="${SKEL_profile_d}/ansible-venv.sh"
|
|
SKEL_profile="${SKEL}/.profile"
|
|
|
|
ANSIBLE_PULL_SH_LOG_DIR="/var/log/ansible-pull.sh"
|
|
|
|
|
|
#
|
|
#### FUNCTIONS
|
|
#
|
|
|
|
# $group_name $group_number
|
|
group_exists () {
|
|
grep -q "^$1:[^:]*:$2:" /etc/group
|
|
}
|
|
|
|
# $user_name $user_number
|
|
user_exists () {
|
|
grep -q "^$1:[^:]*:$2:$2:" /etc/passwd
|
|
}
|
|
|
|
# $group_name $group_number
|
|
system_groupadd () {
|
|
if group_exists "$1" "$2" ; then return 0 ; fi
|
|
groupadd -r -g "$2" "$1"
|
|
rc=$?
|
|
if [ $rc -ne 0 ] ; then
|
|
echo "ERROR - Unable to add $1 group! ($rc)" >&2
|
|
exit 1
|
|
fi
|
|
}
|
|
|
|
# $user_name $user_number
|
|
system_useradd () {
|
|
if user_exists "$1" "$2" ; then return 0 ; fi
|
|
system_groupadd "${@}"
|
|
useradd -r -u "$2" -g "$2" -s /bin/bash -m "$1"
|
|
rc=$?
|
|
if [ $rc -ne 0 ] ; then
|
|
echo "ERROR - Unable to add $1 user! ($rc)" >&2
|
|
exit 2
|
|
fi
|
|
}
|
|
|
|
# $groups $user_name
|
|
add_groups_to_user () {
|
|
usermod -aG "$1" "$2"
|
|
rc=$?
|
|
if [ $rc -ne 0 ] ; then
|
|
echo "ERROR - Unable to add groups ($1) to user ($2)! ($rc)" >&2
|
|
exit 3
|
|
fi
|
|
}
|
|
|
|
# $source_file $dest_file $dest_file_ownership $dest_file_permissions
|
|
get_file() {
|
|
local source_file dest_file dest_file_ownership dest_file_permissions
|
|
|
|
source_file="${1}"
|
|
dest_file="${2}"
|
|
dest_file_ownership="${3}"
|
|
dest_file_permissions="${4}"
|
|
|
|
if [ -e "${dest_file}" ] ; then mv "${dest_file}" "${dest_file}.${TIMESTAMP}" ; fi
|
|
if ! curl -f -o "${dest_file}" "${source_file}" ; then
|
|
echo "ERROR - Unable to download \"${source_file}\"" >&2
|
|
echo " to \"${dest_file}\"." >&2
|
|
exit 4
|
|
fi
|
|
chown "${dest_file_ownership}" "${dest_file}"
|
|
chmod "${dest_file_permissions}" "${dest_file}"
|
|
}
|
|
|
|
# $directory $directory_ownership $directory_permissions
|
|
create_directory() {
|
|
local directory directory_ownership directory_permissions
|
|
|
|
directory="${1}"
|
|
directory_ownership ="${2}"
|
|
directory_permissions="${3}"
|
|
|
|
mkdir -p "${directory}"
|
|
chown "${directory_ownership}" "${directory}"
|
|
chmod "${directory_permissions}" "${directory}"
|
|
}
|
|
|
|
# $command_line
|
|
as_hpf_ans () {
|
|
su --login hpf-ans --command "${1}"
|
|
}
|
|
|
|
|
|
#
|
|
#### PROCESS
|
|
#
|
|
|
|
# Make sure we're running as root
|
|
if [ "$(id -u)" -ne 0 ] ; then
|
|
echo "ERROR - Not running as root" >&2
|
|
exit 100
|
|
fi
|
|
|
|
# Install minimal necessary packages
|
|
if which -s apt ; then
|
|
apt update
|
|
apt install bash curl python3 python3-pip python3-venv python3-virtualenv -y
|
|
else
|
|
echo "ERROR - Unable to determine how to install packages" >&2
|
|
exit 101
|
|
fi
|
|
|
|
# Create system group hpf-sudo for normal sudo users
|
|
system_groupadd hpf-sudo 700
|
|
|
|
# Create system group hpf-sudo-np for special sudo users that don't require a password
|
|
system_groupadd hpf-sudo-np 701
|
|
|
|
# Make sure /etc/sudoers.d exists
|
|
create_directory "${ETC_sudoers_d}" "root:root" "u=rwx,go="
|
|
|
|
# Get /etc/sudoers.d/hpf
|
|
get_file "${GIT_REPO_sudoers_d_hpf}" "${ETC_sudoers_d_hpf}" "root:root" "u=rw,go="
|
|
|
|
# Make sure /etc/skel/.profile.d exists
|
|
create_directory "${SKEL_profile_d}" "root:root" "u=rwx,go="
|
|
|
|
# Get /etc/skel/.profile.d/ansible-venv.sh
|
|
get_file "${GIT_REPO_SKEL_ansible_venv_sh}" "${SKEL_ansible_venv_sh}" "root:root" "u=rwx,go="
|
|
|
|
# Get /etc/skel/.profile
|
|
get_file "${GIT_REPO_SKEL_profile}" "${SKEL_profile}" "root:root" "u=rw,go=r"
|
|
|
|
# Create the hpf-ans user
|
|
system_useradd hpf-ans 800
|
|
add_groups_to_user hpf-sudo-np hpf-ans
|
|
|
|
# Set HPF_ANS variables now that the user is created
|
|
HPF_ANS_HOME="$(as_hpf_ans 'echo "${HOME}"')"
|
|
HPF_ANS_ansible_venv="${HPF_ANS_HOME}/.ansible-venv"
|
|
HPF_ANS_bin="${HPF_ANS_HOME}/bin"
|
|
HPF_ANS_ansible_pull_sh="${HPF_ANS_bin}/ansible-pull.sh"
|
|
|
|
# Make sure /home/hpf-ans/.ansible-venv exists
|
|
as_hpf_ans "if [ ! -d \"${HPF_ANS_ansible_venv}\" ] ; then virtualenv \"${HPF_ANS_ansible_venv}\" ; fi"
|
|
|
|
# Make sure pip is up to date
|
|
as_hpf_ans "pip install --upgrade pip"
|
|
|
|
# Make sure ansible is installed
|
|
as_hpf_ans "pip install --upgrade ansible"
|
|
|
|
# Make sure /home/hpf-ans/bin exists
|
|
create_directory "${HPF_ANS_bin}" "hpf-ans:hpf-ans" "u=rwx,go="
|
|
|
|
# Get /home/hpf-ans/bin/ansible-pull.sh
|
|
get_file "${GIT_REPO_ansible_pull_sh}" "${HPF_ANS_ansible_pull_sh}" "hpf-ans:hpf-ans" "u=rwx,go="
|
|
|
|
# Make sure log directory exists
|
|
create_directory "${ANSIBLE_PULL_SH_LOG_DIR}" "hpf-ans:root" "u=rwx,go="
|
|
|
|
# Run ansible-pull to finish up
|
|
#as_hpf_ans "$HPF_ANS_ansible_pull_sh --branch ${GIT_REPO_BRANCH} bootstrap.yml"
|