infra/ansible/bootstrap.yml
Graham McIntire 0970e29364
ansible: fix two latent bugs surfaced by repo audit
- grafana role: empty grafana_admin_password by default, and only emit
  admin_password into grafana.ini when the var is set. Previously the
  default 'admin' was rewritten on every run, clobbering passwords
  rotated via the Grafana UI.

- bootstrap.yml: probe for sudo state before attempting su-as-root.
  The first play was using become_method=su unconditionally; on hosts
  where graham already has passwordless sudo (or where -K isn't passed),
  ansible blocked indefinitely waiting for a root password prompt.
  Now the install-via-su task only runs when sudo is actually missing,
  and the python3 task uses sudo when available.

Also bring in latest microwaveprop dashboard tweaks.
2026-05-08 11:09:14 -05:00

81 lines
2.5 KiB
YAML

---
- name: Bootstrap new host - Setup sudo
hosts: all
tags: bootstrap
remote_user: graham
gather_facts: no
vars:
ansible_user: graham
tasks:
# Probe before attempting privilege escalation. If sudo already works for
# graham, the install-via-su tasks below would otherwise block on a root
# password prompt that the Makefile's `-K` is designed to feed — and on a
# passwordless-sudo host with no `-K` provided, hang indefinitely.
- name: Probe sudo state
raw: |
if command -v sudo >/dev/null 2>&1; then
if sudo -n true 2>/dev/null; then
echo "sudo-passwordless"
else
echo "sudo-needs-password"
fi
else
echo "sudo-missing"
fi
register: sudo_state
changed_when: false
- name: Ensure sudo is present
raw: |
if command -v apt-get >/dev/null 2>&1; then
apt-get update && apt-get install -y sudo
elif command -v dnf >/dev/null 2>&1; then
dnf install -y sudo
elif command -v yum >/dev/null 2>&1; then
yum install -y sudo
elif command -v apk >/dev/null 2>&1; then
apk add --no-cache sudo
else
echo "Unsupported package manager for sudo installation" >&2
exit 1
fi
become: yes
become_method: su
become_user: root
when: "'sudo-missing' in sudo_state.stdout"
- name: Ensure Python 3 is present
raw: |
if command -v python3 >/dev/null 2>&1; then
exit 0
fi
if command -v apt-get >/dev/null 2>&1; then
apt-get update && apt-get install -y python3 python3-apt
elif command -v dnf >/dev/null 2>&1; then
dnf install -y python3
elif command -v yum >/dev/null 2>&1; then
yum install -y python3
elif command -v apk >/dev/null 2>&1; then
apk add --no-cache python3 py3-pip
else
echo "Unsupported package manager for python3 installation" >&2
exit 1
fi
changed_when: false
become: yes
# Once sudo exists (newly installed or pre-existing) prefer it; only fall
# back to `su` if sudo really isn't there.
become_method: "{{ 'su' if 'sudo-missing' in sudo_state.stdout else 'sudo' }}"
become_user: root
- name: Bootstrap new host - Base configuration
hosts: all
tags: bootstrap
remote_user: graham
become: yes
become_method: sudo
vars:
ansible_user: graham
ansible_python_interpreter: /usr/bin/python3
roles:
- base