forked from evolix/ansible-roles
112 lines
2.3 KiB
YAML
112 lines
2.3 KiB
YAML
---
|
|
|
|
- name: Git is installed (Debian)
|
|
apt:
|
|
name: git
|
|
state: present
|
|
tags:
|
|
- etc-git
|
|
|
|
- name: /etc is versioned with git
|
|
command: "git init ."
|
|
args:
|
|
chdir: /etc
|
|
creates: /etc/.git/
|
|
warn: no
|
|
register: git_init
|
|
tags:
|
|
- etc-git
|
|
|
|
- name: Git user.email is configured
|
|
git_config:
|
|
name: user.email
|
|
repo: /etc
|
|
scope: local
|
|
value: "root@{{ ansible_fqdn | default('localhost') }}"
|
|
tags:
|
|
- etc-git
|
|
|
|
- name: /etc/.git is restricted to root
|
|
file:
|
|
path: /etc/.git
|
|
owner: root
|
|
mode: "0700"
|
|
state: directory
|
|
tags:
|
|
- etc-git
|
|
|
|
- name: /etc/.gitignore is present
|
|
copy:
|
|
src: gitignore
|
|
dest: /etc/.gitignore
|
|
owner: root
|
|
mode: "0600"
|
|
force: no
|
|
tags:
|
|
- etc-git
|
|
|
|
- name: Some entries MUST be in the /etc/.gitignore file
|
|
lineinfile:
|
|
dest: /etc/.gitignore
|
|
line: "{{ item }}"
|
|
with_items:
|
|
- "aliases.db"
|
|
- "*.swp"
|
|
- "postfix/sa-blacklist.access"
|
|
- "postfix/*.db"
|
|
- "postfix/spamd.cidr"
|
|
tags:
|
|
- etc-git
|
|
|
|
- name: does /etc/ have any commit?
|
|
command: "git log"
|
|
args:
|
|
chdir: /etc
|
|
warn: no
|
|
changed_when: False
|
|
failed_when: False
|
|
register: git_log
|
|
check_mode: no
|
|
tags:
|
|
- etc-git
|
|
|
|
- name: initial commit is present?
|
|
shell: "git add -A . && git commit -m \"Initial commit via Ansible\""
|
|
args:
|
|
chdir: /etc
|
|
warn: no
|
|
register: git_commit
|
|
when: git_log.rc != 0 or (git_init is defined and git_init.changed)
|
|
tags:
|
|
- etc-git
|
|
|
|
- name: Optimize script is installed in monthly crontab
|
|
copy:
|
|
src: optimize-etc-git
|
|
dest: /etc/cron.monthly/optimize-etc-git
|
|
mode: "0750"
|
|
force: no
|
|
tags:
|
|
- etc-git
|
|
|
|
- name: regularly check for uncommited changes (if no one is connected)
|
|
cron:
|
|
name: git-status-except-connected
|
|
special_time: "hourly"
|
|
user: root
|
|
job: "who > /dev/null || git --git-dir=/etc/.git --work-tree=/etc status --short"
|
|
state: "{{ etc_git_monitor_status | bool | ternary("present","absent") }}"
|
|
tags:
|
|
- etc-git
|
|
|
|
- name: daily check for uncommited changes
|
|
cron:
|
|
name: git-status
|
|
user: root
|
|
hour: 21
|
|
minute: 21
|
|
job: "git --git-dir=/etc/.git --work-tree=/etc status --short"
|
|
state: "{{ etc_git_monitor_status | bool | ternary("present","absent") }}"
|
|
tags:
|
|
- etc-git
|