From 60bf25b43ee9789026ca9787a230b598e80fac4d Mon Sep 17 00:00:00 2001 From: root Date: Mon, 28 Sep 2026 20:58:58 +0000 Subject: [PATCH] Prvni initrole --- ansible.cfg | 10 +++++ inventory-init.yml | 6 +++ inventory.yml | 3 +- playbooks/initsystem.yml | 86 ++++++++++++++++----------------------- playbooks/update-pkgs.yml | 12 ++++++ soubory/sudo/ansibler | 2 + 6 files changed, 68 insertions(+), 51 deletions(-) create mode 100644 ansible.cfg create mode 100644 inventory-init.yml create mode 100644 playbooks/update-pkgs.yml create mode 100644 soubory/sudo/ansibler diff --git a/ansible.cfg b/ansible.cfg new file mode 100644 index 0000000..281a75f --- /dev/null +++ b/ansible.cfg @@ -0,0 +1,10 @@ +[defaults] +remote_user = ansibler +host_key_checking = false +inventory = inventory.yml + +[privilege_escalation] +become = false +become_method = sudo +become_user = root +become_ask_pass = false diff --git a/inventory-init.yml b/inventory-init.yml new file mode 100644 index 0000000..0863250 --- /dev/null +++ b/inventory-init.yml @@ -0,0 +1,6 @@ +--- +mailservers: + hosts: + devtest: + ansible_host: 192.168.162.35 + ansible_user: root diff --git a/inventory.yml b/inventory.yml index 709bb76..26d26e2 100644 --- a/inventory.yml +++ b/inventory.yml @@ -2,4 +2,5 @@ mailservers: hosts: devtest: - ansible_host: 192.168.162.37 + ansible_host: 192.168.162.35 + ansible_user: ansibler diff --git a/playbooks/initsystem.yml b/playbooks/initsystem.yml index 43021bd..ea81f03 100644 --- a/playbooks/initsystem.yml +++ b/playbooks/initsystem.yml @@ -1,68 +1,54 @@ # Jen kopie vim.yml, kterou chci upravit -# -# Nainstaluje vim, Pathogen, gruvbox +# Ma za ukol vytvorit uzivatele ansibler, nahrat mu klic, a zrusit klic z roota z onboardingu - name: Konfigurace Vimu hosts: devtest gather_facts: yes become: no - vars: - vim_dir: "{{ ansible_env.HOME }}/.vim" - vimrc: "{{ ansible_env.HOME }}/.vimrc" - bashrc: "{{ ansible_env.HOME }}/.bashrc" - tasks: - - name: Upgrade balicku - become: yes - ansible.builtin.apt: - update_cache: true - upgrade: full - - name: Instalace Balicku - become: yes - package: - name: "{{ item }}" + - name: Uzivatelske Ucty + user: + name: ansibler + create_home: true + comment: "JCH" + shell: "/bin/bash" + - name: instalace sudo + apt: + name: sudo state: present - loop: - - [ vim, git, mc, curl, wget ] - - - name: Stazeni dotfiles - get_url: - dest: "{{ item.dst }}" - url: "{{ item.src }}" - backup: yes - force: true - mode: 0640 - loop: - - {src: "https://www.martus.cz/soubory/ansible/bashrc.txt", dst: "{{ bashrc }}" } - - {src: "https://www.martus.cz/soubory/ansible/vimrc.txt", dst: "{{ vimrc }}" } - - - name: Adresarova struktura + update_cache: true + - name: ansible sudoer + copy: + owner: root + group: root + mode: 700 + src: /root/gitrepo/ansible/soubory/sudo/ansibler + dest: /etc/sudoers.d/ansibler + + - name: Adresarova Struktura /home/ansibler file: - path: "{{ item }}" state: directory + force: true + mode: 0750 + owner: ansibler + group: ansibler + path: "{{ item.path }}" + loop: + - {path: "/home/ansibler/.ssh"} + - name: SSH klic ansibler + copy: owner: ansibler group: ansibler mode: 0750 + src: "{{ item.src }}" + dest: "{{item .dst }}" loop: - - "{{ vim_dir }}" - - "{{ vim_dir }}/swap" - - "{{ vim_dir }}/backup" - - "{{ vim_dir }}/autoload" - - "{{ vim_dir }}/bundle" + - {src: "/root/.ssh/id_ed25519.pub", dst: "/home/ansibler/.ssh/authorized_keys"} + - name: Vymazat /root/.ssh/authorized_keys + file: + path: /root/.ssh/authorized_keys + state: absent - - name: Pathogen pro instalaci doplnku - get_url: - dest: "{{ vim_dir }}/autoload/pathogen.vim" - url: https://tpo.pe/pathogen.vim - - name: Vim Pluginy - git: - dest: "{{ vim_dir }}/bundle/{{ item.name }}" - repo: "{{ item.url }}" - clone: yes - update: yes - recursive: no - loop: - - { name: gruvbox, url: https://github.com/morhetz/gruvbox.git } diff --git a/playbooks/update-pkgs.yml b/playbooks/update-pkgs.yml new file mode 100644 index 0000000..195636a --- /dev/null +++ b/playbooks/update-pkgs.yml @@ -0,0 +1,12 @@ +--- +- name: upgrade balicku + hosts: devtest + + tasks: + - name: update a upgrade + become: yes + apt: + update_cache: true + upgrade: full + + diff --git a/soubory/sudo/ansibler b/soubory/sudo/ansibler new file mode 100644 index 0000000..ea0934d --- /dev/null +++ b/soubory/sudo/ansibler @@ -0,0 +1,2 @@ +ansibler ALL=(ALL) NOPASSWD: ALL +