diff --git a/ansible.cfg b/ansible.cfg new file mode 100644 index 0000000..362fe75 --- /dev/null +++ b/ansible.cfg @@ -0,0 +1,6 @@ +[defaults] +#Отключаем проверку fingerprnt при первом подключении к серверу +host_key_checking=false +#Задаём файл с хостами по умолчанию. Больше не нужно писать "ansible -i hosts.txt all -m ping", достаточно "ansible all -m ping" +inventory=/ansible/hosts.txt +interpreter_python=auto_silent diff --git a/hosts.txt b/hosts.txt new file mode 100644 index 0000000..6b7d4af --- /dev/null +++ b/hosts.txt @@ -0,0 +1,22 @@ +[ansible_servers] +rdb1 ansible_host=192.168.33.120 +rdb2 ansible_host=192.168.33.121 +ldcore1 ansible_host=192.168.33.124 +ldcore2 ansible_host=192.168.33.125 +lcloud1 ansible_host=192.168.33.129 + +hub ansible_host=192.168.33.220 +rdb3 ansible_host=192.168.33.221 + +#Тут не настроен wg +#icap ansible_host=10.10.10.10 + +ldext1 ansible_host=82.202.138.229 ansible_port=22233 +ldext2 ansible_host=176.108.251.94 ansible_port=22233 +app ansible_host=95.174.93.179 ansible_port=22233 + + + +[ansible_servers:vars] +ansible_user=zmaster +ansible_ssh_private_key_file=/home/zmaster/.ssh/zmasterKeys diff --git a/ping.yml b/ping.yml new file mode 100644 index 0000000..a0e6071 --- /dev/null +++ b/ping.yml @@ -0,0 +1,7 @@ +- name: ping + hosts: all + become: yes + + tasks: + - name: Ping + ping: diff --git a/prepeareLinux.yml b/prepeareLinux.yml new file mode 100644 index 0000000..864406b --- /dev/null +++ b/prepeareLinux.yml @@ -0,0 +1,47 @@ +- name: Prepeare OS Linux (Rocky + Ubuntu) after install + hosts: all + become: yes + + tasks: + - block: + - name: Remove soft + dnf: name="{{ item }}" state=absent autoremove=yes + loop: [qemu*, cockpit*, postfix*, libvirt*, podman*] + - name: Install soft + dnf: name="{{ item }}" state=latest + loop: [unzip, mtr, yum-utils, epel-release, net-tools, wget, tar, lsof, sysstat, smartmontools, which, iperf3, vim, htop, iftop, nethogs, tree] + - name: Remove services from firewall + firewalld: service="{{ item }}" state=disabled permanent=true immediate=true + loop: [cockpit, dhcpv6-client] + - name: Create aliases + lineinfile: path=/etc/bashrc line="{{ item }}" + loop: + - alias lll='ls -alh --color=auto' + - alias sss='ss -tulpn' + - alias df='df -h' + when: ansible_facts['os_family'] == "RedHat" + + - block: + - name: Remove soft + apt: name="{{ item }}" state=absent autoremove=yes + loop: [qemu*, cockpit*, postfix*, libvirt*, podman*] + - name: Install soft + apt: name="{{ item }}" state=latest + loop: [unzip, mtr, net-tools, wget, tar, lsof, sysstat, smartmontools, which, iperf3, vim, htop, iftop, nethogs, tree] + - name: Create aliases + lineinfile: path=/etc/bash.bashrc line="{{ item }}" + loop: + - alias lll='ls -alh --color=auto' + - alias sss='ss -tulpn' + - alias df='df -h' + when: ansible_facts['os_family'] == "Debian" + + - name: Disable SELinux + selinux: state=disabled + when: ansible_facts['selinux']['status']!="disabled" + + - name: Do not prompt for sudo password for zmaster + lineinfile: path="/etc/sudoers" line="{{ item }}" + loop: + - "zmaster ALL=(ALL) NOPASSWD: ALL" + diff --git a/roles/delsoft/tasks/main.yml b/roles/delsoft/tasks/main.yml new file mode 100644 index 0000000..6949231 --- /dev/null +++ b/roles/delsoft/tasks/main.yml @@ -0,0 +1,5 @@ +--- +- name: Remove soft + dnf: name="{{ item }}" state=absent autoremove=yes + loop: [qemu*, cockpit*, postfix*, libvirt*, podman*] + diff --git a/roles/inssoft/tasks/main.yml b/roles/inssoft/tasks/main.yml new file mode 100644 index 0000000..8a67c24 --- /dev/null +++ b/roles/inssoft/tasks/main.yml @@ -0,0 +1,4 @@ +--- +- name: Install soft + dnf: name="{{ item }}" state=latest + loop: [unzip, mtr, yum-utils, epel-release, net-tools, wget, tar, lsof, sysstat, smartmontools, which, iperf3, vim, htop, iftop, nethogs, tree] diff --git a/testrole.yml b/testrole.yml new file mode 100644 index 0000000..fbfc4e5 --- /dev/null +++ b/testrole.yml @@ -0,0 +1,7 @@ +--- +- name: Install Soft + hosts: all + become: yes + roles: + - delsoft + - inssoft diff --git a/updateLinux.yml b/updateLinux.yml new file mode 100644 index 0000000..a55d8b6 --- /dev/null +++ b/updateLinux.yml @@ -0,0 +1,20 @@ +- name: Update all system packages + hosts: all + become: yes + + tasks: + - name: Update packages to the latest version + dnf: name="*" state=latest + + - name: Check if a reboot is required + command: + cmd: needs-restarting -r + register: reboot_check + changed_when: false + failed_when: reboot_check.rc not in [0, 1] + + - name: Reboot the server only if needed + reboot: + when: reboot_check.rc == 1 + + diff --git a/updateLinux_run.log b/updateLinux_run.log new file mode 100644 index 0000000..7c3c71c --- /dev/null +++ b/updateLinux_run.log @@ -0,0 +1,63 @@ + +PLAY [Update all system packages] ********************************************** + +TASK [Gathering Facts] ********************************************************* +ok: [rdb1] +ok: [ldcore1] +ok: [ldcore2] +ok: [lcloud1] +ok: [hub] +ok: [rdb2] +ok: [rdb3] +ok: [ldext1] +ok: [ldext2] +ok: [app] + +TASK [Update packages to the latest version] *********************************** +ok: [rdb1] +ok: [ldcore1] +ok: [rdb2] +ok: [ldcore2] +ok: [lcloud1] +ok: [hub] +ok: [rdb3] +ok: [ldext1] +ok: [app] +ok: [ldext2] + +TASK [Check if a reboot is required] ******************************************* +ok: [ldcore2] +ok: [ldcore1] +ok: [rdb2] +ok: [lcloud1] +ok: [hub] +ok: [rdb3] +ok: [rdb1] +ok: [ldext2] +ok: [ldext1] +ok: [app] + +TASK [Reboot the server only if needed] **************************************** +skipping: [rdb1] +skipping: [rdb2] +skipping: [ldcore1] +skipping: [ldcore2] +skipping: [lcloud1] +skipping: [hub] +skipping: [rdb3] +skipping: [ldext1] +skipping: [ldext2] +skipping: [app] + +PLAY RECAP ********************************************************************* +app : ok=3 changed=0 unreachable=0 failed=0 skipped=1 rescued=0 ignored=0 +hub : ok=3 changed=0 unreachable=0 failed=0 skipped=1 rescued=0 ignored=0 +lcloud1 : ok=3 changed=0 unreachable=0 failed=0 skipped=1 rescued=0 ignored=0 +ldcore1 : ok=3 changed=0 unreachable=0 failed=0 skipped=1 rescued=0 ignored=0 +ldcore2 : ok=3 changed=0 unreachable=0 failed=0 skipped=1 rescued=0 ignored=0 +ldext1 : ok=3 changed=0 unreachable=0 failed=0 skipped=1 rescued=0 ignored=0 +ldext2 : ok=3 changed=0 unreachable=0 failed=0 skipped=1 rescued=0 ignored=0 +rdb1 : ok=3 changed=0 unreachable=0 failed=0 skipped=1 rescued=0 ignored=0 +rdb2 : ok=3 changed=0 unreachable=0 failed=0 skipped=1 rescued=0 ignored=0 +rdb3 : ok=3 changed=0 unreachable=0 failed=0 skipped=1 rescued=0 ignored=0 +