diff --git a/roles/0_basic_postinstall/files/.vimrc b/roles/0_basic_postinstall/files/.vimrc new file mode 100644 index 0000000..70d5a79 --- /dev/null +++ b/roles/0_basic_postinstall/files/.vimrc @@ -0,0 +1,16 @@ +set number +set tabstop=2 +" Disable compatibility with vi which can cause unexpected issues. +set nocompatible + +" Enable type file detection. Vim will be able to try to detect the type of file in use. +filetype on + +" Enable plugins and load plugin for the detected file type. +filetype plugin on + +" Load an indent file for the detected file type. +filetype indent on + +" Turn syntax highlighting on. +syntax on diff --git a/roles/0_basic_postinstall/files/.zshrc b/roles/0_basic_postinstall/files/.zshrc new file mode 100644 index 0000000..fdc37d9 --- /dev/null +++ b/roles/0_basic_postinstall/files/.zshrc @@ -0,0 +1,109 @@ +export PATH=$HOME/bin:$HOME/.local/bin:/usr/local/bin:/home/max/soft/gnu_linux:$PATH + +# Path to your Oh My Zsh installation. +export ZSH="$HOME/.oh-my-zsh" + +export GTK_THEME=Adwaita-dark + +# Set name of the theme to load --- if set to "random", it will +# load a random theme each time Oh My Zsh is loaded, in which case, +# to know which specific one was loaded, run: echo $RANDOM_THEME +# See https://github.com/ohmyzsh/ohmyzsh/wiki/Themes +ZSH_THEME="gnzh" + +# Set list of themes to pick from when loading at random +# Setting this variable when ZSH_THEME=random will cause zsh to load +# a theme from this variable instead of looking in $ZSH/themes/ +# If set to an empty array, this variable will have no effect. +# ZSH_THEME_RANDOM_CANDIDATES=( "robbyrussell" "agnoster" ) + +# Uncomment the following line to use case-sensitive completion. +# CASE_SENSITIVE="true" + +# Uncomment the following line to use hyphen-insensitive completion. +# Case-sensitive completion must be off. _ and - will be interchangeable. +# HYPHEN_INSENSITIVE="true" + +# Uncomment one of the following lines to change the auto-update behavior +# zstyle ':omz:update' mode disabled # disable automatic updates +# zstyle ':omz:update' mode auto # update automatically without asking +# zstyle ':omz:update' mode reminder # just remind me to update when it's time + +# Uncomment the following line to change how often to auto-update (in days). +# zstyle ':omz:update' frequency 13 + +# Uncomment the following line if pasting URLs and other text is messed up. +# DISABLE_MAGIC_FUNCTIONS="true" + +# Uncomment the following line to disable colors in ls. +# DISABLE_LS_COLORS="true" + +# Uncomment the following line to disable auto-setting terminal title. +# DISABLE_AUTO_TITLE="true" + +# Uncomment the following line to enable command auto-correction. +# ENABLE_CORRECTION="true" + +# Uncomment the following line to display red dots whilst waiting for completion. +# You can also set it to another string to have that shown instead of the default red dots. +# e.g. COMPLETION_WAITING_DOTS="%F{yellow}waiting...%f" +# Caution: this setting can cause issues with multiline prompts in zsh < 5.7.1 (see #5765) +# COMPLETION_WAITING_DOTS="true" + +# Uncomment the following line if you want to disable marking untracked files +# under VCS as dirty. This makes repository status check for large repositories +# much, much faster. +# DISABLE_UNTRACKED_FILES_DIRTY="true" + +# Uncomment the following line if you want to change the command execution time +# stamp shown in the history command output. +# You can set one of the optional three formats: +# "mm/dd/yyyy"|"dd.mm.yyyy"|"yyyy-mm-dd" +# or set a custom format using the strftime function format specifications, +# see 'man strftime' for details. +# HIST_STAMPS="mm/dd/yyyy" + +# Would you like to use another custom folder than $ZSH/custom? +# ZSH_CUSTOM=/path/to/new-custom-folder + +# Which plugins would you like to load? +# Standard plugins can be found in $ZSH/plugins/ +# Custom plugins may be added to $ZSH_CUSTOM/plugins/ +# Example format: plugins=(rails git textmate ruby lighthouse) +# Add wisely, as too many plugins slow down shell startup. +#plugins=(git) + +source $ZSH/oh-my-zsh.sh + +# User configuration + +# export MANPATH="/usr/local/man:$MANPATH" + +# You may need to manually set your language environment +# export LANG=en_US.UTF-8 + +# Preferred editor for local and remote sessions +# if [[ -n $SSH_CONNECTION ]]; then +# export EDITOR='vim' +# else +# export EDITOR='nvim' +# fi + +# Compilation flags +# export ARCHFLAGS="-arch $(uname -m)" + +# Set personal aliases, overriding those provided by Oh My Zsh libs, +# plugins, and themes. Aliases can be placed here, though Oh My Zsh +# users are encouraged to define aliases within a top-level file in +# the $ZSH_CUSTOM folder, with .zsh extension. Examples: +# - $ZSH_CUSTOM/aliases.zsh +# - $ZSH_CUSTOM/macos.zsh +# For a full list of active aliases, run `alias`. +# +# Example aliases +# alias zshconfig="mate ~/.zshrc" +# alias ohmyzsh="mate ~/.oh-my-zsh" +alias run_jabref="/home/max/projects/utils/jabref/build/image/bin/JabRef" +alias run_freecad="/home/max/Soft/gnu_linux/FreeCAD_1.0.0-conda-Linux-aarch64-py311.AppImage" +alias run_freecad_new="COIN_GL_NO_CURRENT_CONTEXT_CHECK=yes /home/max/projects/utils/freecad-source/build/bin/FreeCAD" +alias run_orca="/home/max/utils/OrcaSlicer_Linux_AppImage_V2.3.0.AppImage" diff --git a/roles/0_basic_postinstall/files/install_omz.sh b/roles/0_basic_postinstall/files/install_omz.sh new file mode 100644 index 0000000..e0e5f8d --- /dev/null +++ b/roles/0_basic_postinstall/files/install_omz.sh @@ -0,0 +1,15 @@ +#!/bin/sh + +FILE=/home/$USER/.oh-my-zsh/oh-my-zsh.sh +if [ -f "$FILE" ]; then + echo "$FILE exists and we not installing ohmyzsh" + exit 0 +else + echo "$FILE does not exist and we install ohmyzsh" + cd /home/max + wget https://raw.githubusercontent.com/ohmyzsh/ohmyzsh/master/tools/install.sh + chmod +x /home/max/install.sh + timeout -s 15 -k 30s 20s /home/max/install.sh --unattendend --keep-zshrc || exit 0 + exit 0 +fi + diff --git a/roles/0_basic_postinstall/tasks/create_new_user.yaml b/roles/0_basic_postinstall/tasks/create_new_user.yaml new file mode 100644 index 0000000..6129c1e --- /dev/null +++ b/roles/0_basic_postinstall/tasks/create_new_user.yaml @@ -0,0 +1,65 @@ +--- +- name: Create a new user with a password, set shell + remote_user: ansible + user: + name: max + groups: sshusers + password: "{{ user_passwd_hash }}" + shell: /bin/zsh + +- name: Set authorized key taken from file + remote_user: ansible + ansible.posix.authorized_key: + user: max + state: present + key: "{{ lookup('file', lookup('env','HOME') + '/.ssh/ansible_key.pub') }}" + +- name: Copy omz installation wrapper script to the target machine + remote_user: ansible + copy: + src: ../files/install_omz.sh + dest: /home/max/install_omz.sh + owner: max + group: max + mode: u=rwx,g=r,o-rwx + +# WARNING: UNPRIVILEGED USER (not ansible) COMMANDS +- name: Install oh my zsh + remote_user: max + become: no + command: /home/max/install_omz.sh + +- name: Configure oh my zsh, by pushing the config file + remote_user: ansible + copy: + src: ../files/.zshrc + dest: /home/max/.zshrc + owner: max + group: max + mode: u=rw,g=r,o-rwx + +- name: Configure vim, by pushing the config + remote_user: ansible + copy: + src: ../files/.vimrc + dest: /home/max/.vimrc + owner: max + group: max + mode: u=rw,g=r,o-rwx + + +# WARNING: we've finished with the initial setup, drop ansible key +# Push regular user key +- name: Set authorized key taken from file + remote_user: ansible + ansible.posix.authorized_key: + user: max + state: absent + key: "{{ lookup('file', lookup('env','HOME') + '/.ssh/ansible_key.pub') }}" + +- name: Set authorized key taken from file + remote_user: ansible + ansible.posix.authorized_key: + user: max + state: present + key: "{{ lookup('file', lookup('env','HOME') + '/.ssh/max_regular_key.pub') }}" diff --git a/roles/0_basic_postinstall/tasks/main.yaml b/roles/0_basic_postinstall/tasks/main.yaml index b42f03d..89d7d9d 100644 --- a/roles/0_basic_postinstall/tasks/main.yaml +++ b/roles/0_basic_postinstall/tasks/main.yaml @@ -6,4 +6,7 @@ ansible.builtin.include_tasks: harden_ssh.yaml - name: Install basic utils - ansible.builtin.include_tasks: install_basic_utils.yaml \ No newline at end of file + ansible.builtin.include_tasks: install_basic_utils.yaml + +- name: Create and set up a new user + ansible.builtin.include_tasks: create_new_user.yaml \ No newline at end of file diff --git a/roles/0_basic_postinstall/tasks/remove_packages.yml b/roles/0_basic_postinstall/tasks/remove_packages.yml new file mode 100644 index 0000000..ac5835e --- /dev/null +++ b/roles/0_basic_postinstall/tasks/remove_packages.yml @@ -0,0 +1,27 @@ +--- +# Remove multiple packages at once +- name: Remove unnecessary packages + remote_user: ansible + when: (ansible_facts['distribution'] == "Debian") or + (ansible_facts['distribution'] == "Ubuntu") + apt: + name: + - nano + state: absent + become: yes + + +# Clean up all orphaned packages +- name: Remove all orphaned dependencies + remote_user: ansible + when: (ansible_facts['distribution'] == "Debian") or + (ansible_facts['distribution'] == "Ubuntu") + apt: + autoremove: yes + purge: yes + + +- name: Install sudo package on Alpine + remote_user: ansible + when: (ansible_facts['distribution'] == "Alpine") + command: /sbin/apk del nano