Feat: concatenate users and dotfiles into user

This commit is contained in:
Bertrand Benjamin 2022-01-11 21:58:59 +01:00
parent 0d3d0219a5
commit 9cc854401a
16 changed files with 322 additions and 0 deletions

29
roles/user/.travis.yml Normal file
View File

@ -0,0 +1,29 @@
---
language: python
python: "2.7"
# Use the new container infrastructure
sudo: false
# Install ansible
addons:
apt:
packages:
- python-pip
install:
# Install ansible
- pip install ansible
# Check ansible version
- ansible --version
# Create ansible.cfg with correct roles_path
- printf '[defaults]\nroles_path=../' >ansible.cfg
script:
# Basic role syntax check
- ansible-playbook tests/test.yml -i tests/inventory --syntax-check
notifications:
webhooks: https://galaxy.ansible.com/api/v1/notifications/

33
roles/user/.yamllint Normal file
View File

@ -0,0 +1,33 @@
---
# Based on ansible-lint config
extends: default
rules:
braces:
max-spaces-inside: 1
level: error
brackets:
max-spaces-inside: 1
level: error
colons:
max-spaces-after: -1
level: error
commas:
max-spaces-after: -1
level: error
comments: disable
comments-indentation: disable
document-start: disable
empty-lines:
max: 3
level: error
hyphens:
level: error
indentation: disable
key-duplicates: enable
line-length: disable
new-line-at-end-of-file: disable
new-lines:
type: unix
trailing-spaces: disable
truthy: disable

38
roles/user/README.md Normal file
View File

@ -0,0 +1,38 @@
Role Name
=========
A brief description of the role goes here.
Requirements
------------
Any pre-requisites that may not be covered by Ansible itself or the role should be mentioned here. For instance, if the role uses the EC2 module, it may be a good idea to mention in this section that the boto package is required.
Role Variables
--------------
A description of the settable variables for this role should go here, including any variables that are in defaults/main.yml, vars/main.yml, and any variables that can/should be set via parameters to the role. Any variables that are read from other roles and/or the global scope (ie. hostvars, group vars, etc.) should be mentioned here as well.
Dependencies
------------
A list of other roles hosted on Galaxy should go here, plus any details in regards to parameters that may need to be set for other roles, or variables that are used from other roles.
Example Playbook
----------------
Including an example of how to use your role (for instance, with variables passed in as parameters) is always nice for users too:
- hosts: servers
roles:
- { role: username.rolename, x: 42 }
License
-------
BSD
Author Information
------------------
An optional section for the role authors to include contact information, or a website (HTML is not allowed).

View File

@ -0,0 +1,2 @@
---
# defaults file for user

View File

@ -0,0 +1,2 @@
---
# handlers file for user

View File

@ -0,0 +1,23 @@
*********************************
Vagrant driver installation guide
*********************************
Requirements
============
* Vagrant
* Virtualbox, Parallels, VMware Fusion, VMware Workstation or VMware Desktop
Install
=======
Please refer to the `Virtual environment`_ documentation for installation best
practices. If not using a virtual environment, please consider passing the
widely recommended `'--user' flag`_ when invoking ``pip``.
.. _Virtual environment: https://virtualenv.pypa.io/en/latest/
.. _'--user' flag: https://packaging.python.org/tutorials/installing-packages/#installing-to-the-user-site
.. code-block:: bash
$ pip install 'molecule_vagrant'

View File

@ -0,0 +1,46 @@
---
- name: Converge
hosts: all
become: yes
vars:
users:
- username: user
password: "$y$j9T$PR8GfM2MjGudOCd7hF9NP1$/qRGtuNuWaRVVGmB1A4rgtaT0MMB9IoB4fnaxW1kvf4" #plop
shell: "/bin/zsh"
config:
giturl: "https://git.opytex.org/lafrite/dotfiles.git"
stowing: ["nvim", "tmux", "zsh"]
- username: admin
password: "$y$j9T$PR8GfM2MjGudOCd7hF9NP1$/qRGtuNuWaRVVGmB1A4rgtaT0MMB9IoB4fnaxW1kvf4" #plop
groups: ["wheel"]
system: yes
config:
giturl: "https://git.opytex.org/lafrite/dotfiles.git"
stowing: ["tmux"]
pre_tasks:
- name: update_cache for arch
pacman:
name:
- zsh
state: present
update_cache: yes
become: yes
when: ansible_os_family == "Archlinux"
- name: update_cache for debian
apt:
name:
- zsh
state: present
update_cache: yes
become: yes
when: ansible_os_family == "Debian"
tasks:
- name: "Include user"
include_role:
name: "user"
loop: "{{ users }}"
loop_control:
loop_var: user

View File

@ -0,0 +1,16 @@
---
dependency:
name: galaxy
driver:
name: vagrant
platforms:
- name: archlinux
box: "archlinux/archlinux"
- name: Debian
box: "debian/bullseye64"
provisioner:
name: ansible
verifier:
name: testinfra
options:
sudo: true

View File

@ -0,0 +1,22 @@
"""PyTest Fixtures."""
from __future__ import absolute_import
import os
import pytest
def pytest_runtest_setup(item):
"""Run tests only when under molecule with testinfra installed."""
try:
import testinfra
except ImportError:
pytest.skip("Test requires testinfra", allow_module_level=True)
if "MOLECULE_INVENTORY_FILE" in os.environ:
pytest.testinfra_hosts = testinfra.utils.ansible_runner.AnsibleRunner(
os.environ["MOLECULE_INVENTORY_FILE"]
).get_hosts("all")
else:
pytest.skip(
"Test should run only from inside molecule.", allow_module_level=True
)

View File

@ -0,0 +1,31 @@
"""Role testing files using testinfra."""
def test_create_users(host):
""" Validate user creation """
user = host.user("user")
assert user.exists
assert user.uid >= 1000
assert user.shell == "/bin/zsh"
assert user.home == f"/home/{user.name}"
admin = host.user("admin")
assert admin.exists
assert admin.uid < 1000
assert admin.shell == "/bin/bash"
assert admin.home == f"/home/{admin.name}"
def test_install_git_stow(host):
pass
def test_clone_dotfiles(host):
user = host.user("user")
dotfiles = host.file(user.home + "/.dotfiles")
assert dotfiles.exists
assert dotfiles.user == user.name
admin = host.user("admin")
dotfiles = host.file(admin.home + "/.dotfiles")
assert dotfiles.exists
assert dotfiles.user == admin.name

12
roles/user/tasks/arch.yml Normal file
View File

@ -0,0 +1,12 @@
---
- name: Install stow
community.general.pacman:
name: stow
state: present
become: true
- name: Install git
community.general.pacman:
name: git
state: present
become: true

View File

@ -0,0 +1,14 @@
---
- name: Install stow
apt:
name: stow
state: present
update_cache: yes
become: true
- name: Install git
apt:
name: git
state: present
update_cache: yes
become: true

45
roles/user/tasks/main.yml Normal file
View File

@ -0,0 +1,45 @@
---
# tasks file for user
- name: users -- Ensure wheel group exists
group:
name: wheel
state: present
- name: create users
ansible.builtin.user:
name: "{{ user.username }}"
update_password: on_create
password: "{{ user.password | password_hash('sha512')}}"
group: "{{ user.group | default('users') }}"
groups: "{{ user.groups | default('') }}"
shell: "{{ user.shell | default('/bin/bash') }}"
state: present
system: "{{ user.system | default('no') }}"
- name: Install for arch
import_tasks: arch.yml
when: ansible_os_family == "Archlinux"
- name: Install for debian
import_tasks: debian.yml
when: ansible_os_family == "Debian"
- name: Clone dotfiles
ansible.builtin.git:
repo: "{{ user.config.giturl }}"
dest: "/home/{{ user.username }}/.dotfiles"
become: yes
- name: user owns its dotfiles
ansible.builtin.file:
path: "/home/{{ user.username }}/.dotfiles"
owner: "{{ user.username }}"
become: yes
- name: stow configs
ansible.builtin.command:
cmd: stow {{ item }}
chdir: "/home/{{ user.username }}/.dotfiles"
with_items: "{{ user.config.stowing }}"
become: yes

View File

@ -0,0 +1,2 @@
localhost

View File

@ -0,0 +1,5 @@
---
- hosts: localhost
remote_user: root
roles:
- user

2
roles/user/vars/main.yml Normal file
View File

@ -0,0 +1,2 @@
---
# vars file for user