-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathinit.sh
More file actions
executable file
·162 lines (134 loc) · 4.42 KB
/
Copy pathinit.sh
File metadata and controls
executable file
·162 lines (134 loc) · 4.42 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
#!/usr/bin/env bash
set -o errexit
set -o nounset
# Colors
GREEN_BG='\033[0;42m'
RED_BG='\033[0;41m'
YELLOW_BG='\033[1;43m'
NC='\033[0m' # No Color
log() {
echo -e "$1"
}
success() {
echo -e "${GREEN_BG} OK ${NC} $1"
}
warn() {
echo -e "\n${YELLOW_BG} WARN ${NC} $1\n"
}
error_exit() {
echo -e "${RED_BG} ERROR ${NC} $1"
exit 1
}
encrypt_vault_file() {
local example_file=$1
local output_file=$2
log "Processing $output_file..."
op inject -i $example_file -o $output_file --force > /dev/null
ansible-vault encrypt $output_file
}
fetch_1password_item() {
local item_path=$1
local output_file=$2
op read "$item_path" -o "$output_file" --force > /dev/null || error_exit "Failed to fetch $item_path"
success "Fetched $item_path"
}
install_1password_cli() {
# Check if 'op' command is already installed
if ! command -v op &> /dev/null; then
log "Installing 1Password CLI..."
# Add the key for the 1Password apt repository
curl -sS https://downloads.1password.com/linux/keys/1password.asc -o /tmp/1password.asc
sudo gpg --dearmor --yes --output /usr/share/keyrings/1password-archive-keyring.gpg /tmp/1password.asc
# Add the 1Password apt repository
echo "deb [arch=$(dpkg --print-architecture) signed-by=/usr/share/keyrings/1password-archive-keyring.gpg] https://downloads.1password.com/linux/debian/$(dpkg --print-architecture) stable main" | \
sudo tee /etc/apt/sources.list.d/1password.list
# Add the debsig-verify policy
sudo mkdir -p /etc/debsig/policies/AC2D62742012EA22/
sudo curl -sS https://downloads.1password.com/linux/debian/debsig/1password.pol -o /etc/debsig/policies/AC2D62742012EA22/1password.pol
# Import debsig keyring GPG key
sudo mkdir -p /usr/share/debsig/keyrings/AC2D62742012EA22
sudo gpg --dearmor --yes --output /usr/share/debsig/keyrings/AC2D62742012EA22/debsig.gpg /tmp/1password.asc
# Install 1Password CLI
sudo apt update
sudo apt install -y 1password-cli
success "1Password CLI installed"
else
success "1Password CLI is already installed"
fi
}
setup_all() {
log "Installing Ansible Galaxy requirements..."
ansible-galaxy install -r requirements.yml || error_exit "Failed to install Ansible Galaxy requirements"
success "Ansible Galaxy requirements installed"
setup_certs
setup_vaults
}
setup_certs() {
mkdir -p files || error_exit "Failed to create files directory"
fetch_1password_item "op://homelab/int.jrtashjian.com.fullchain/int.jrtashjian.com.fullchain.pem" "files/fullchain.pem"
fetch_1password_item "op://homelab/int.jrtashjian.com.privkey/int.jrtashjian.com.privkey.pem" "files/privkey.pem"
}
setup_vaults() {
fetch_1password_item "op://homelab/ansible-user/Credentials/.ansible-vault-password" ".ansible-vault-password"
local vault_files=(
"group_vars/all/vault.yml"
"group_vars/minecraft/vault.yml"
"host_vars/sso.int.jrtashjian.com/vault.yml"
)
for file in "${vault_files[@]}"; do
encrypt_vault_file "${file}.example" "$file"
done
}
usage() {
echo "Usage: $0 [options]"
echo "Options:"
echo " -c, --certs Update certificates only"
echo " -v, --vaults Update vaults only"
echo " -h, --help Display this help"
echo " (no option) Run full setup"
}
main() {
# Default to running everything
local run_all=true
local run_certs=false
local run_vaults=false
while [[ $# -gt 0 ]]; do
case $1 in
-c|--certs)
run_all=false
run_certs=true
shift
;;
-v|--vaults)
run_all=false
run_vaults=true
shift
;;
-h|--help)
usage
exit 0
;;
*)
warn "Unknown option: $1"
usage
exit 1
;;
esac
done
install_1password_cli
# Check if 'ansible' is already installed
if ! command -v ansible &> /dev/null; then
log "Installing Ansible..."
apt install -y ansible
success "Ansible installed"
fi
if $run_all; then
setup_all
elif $run_certs; then
setup_certs
elif $run_vaults; then
setup_vaults
fi
success "Setup completed"
}
main "$@"