diff options
| -rw-r--r-- | playbook.yml | 8 | ||||
| -rw-r--r-- | tasks/jail_diddle.yml | 6 | ||||
| -rw-r--r-- | tasks/jail_hommabot.yml | 62 | ||||
| -rw-r--r-- | tasks/jail_ingress.yml | 2 | ||||
| -rw-r--r-- | templates/diddle/root_clone.sh | 14 | ||||
| -rw-r--r-- | templates/hommabot/etc_crontab.j2 | 10 | ||||
| -rw-r--r-- | templates/hommabot/root_hommabot_deps.sh | 14 | ||||
| -rw-r--r-- | templates/hommabot/root_hommabot_env.j2 | 4 | ||||
| -rw-r--r-- | templates/root_clone.sh | 21 |
9 files changed, 123 insertions, 18 deletions
diff --git a/playbook.yml b/playbook.yml index c1923fb..1ee0817 100644 --- a/playbook.yml +++ b/playbook.yml @@ -29,6 +29,10 @@ backup_zfs_dataset: zroot diddle_email_host_user: "{{ lookup('env', 'DIDDLE_EMAIL_HOST_USER') }}" diddle_email_host_password: "{{ lookup('env', 'DIDDLE_EMAIL_HOST_PASSWORD') }}" + hommabot_telegram_bot_token: "{{ lookup('env', 'HOMMABOT_TELEGRAM_BOT_TOKEN') }}" + hommabot_g_sa_json_b64: "{{ lookup('env', 'HOMMABOT_G_SA_JSON_B64') }}" + hommabot_sheets_spreadsheet_id: "{{ lookup('env', 'HOMMABOT_SHEETS_SPREADSHEET_ID') }}" + hommabot_sheets_range: "{{ lookup('env', 'HOMMABOT_SHEETS_RANGE') }}" lan_ipv4_cidr: 192.168.0.10/16 lan_ipv4_gateway: 192.168.0.1 lan_search_domain: local.jan.systems @@ -81,3 +85,7 @@ - name: Run diddle jail tasks tags: [jail_diddle] import_tasks: tasks/jail_diddle.yml + + - name: Run hommabot jail tasks + tags: [jail_hommabot] + import_tasks: tasks/jail_hommabot.yml diff --git a/tasks/jail_diddle.yml b/tasks/jail_diddle.yml index ccc1c4b..73424f5 100644 --- a/tasks/jail_diddle.yml +++ b/tasks/jail_diddle.yml @@ -1,4 +1,4 @@ -- name: Install packages inside ingress jail +- name: Install packages inside jail loop: - { jail: diddle, package: python311 } - { jail: diddle, package: py311-sqlite3 } @@ -7,14 +7,14 @@ - name: Install clone.sh template: - src: diddle/root_clone.sh + src: root_clone.sh dest: /usr/local/jails/containers/diddle/root/clone.sh owner: root group: wheel mode: "0755" - name: Clone & update diddle - shell: jexec diddle sh /root/clone.sh + shell: jexec diddle sh /root/clone.sh https://github.com/jantuomi/diddle.git /root/diddle register: diddle_git changed_when: diddle_git.rc == 100 failed_when: diddle_git.rc != 0 and diddle_git.rc != 100 diff --git a/tasks/jail_hommabot.yml b/tasks/jail_hommabot.yml new file mode 100644 index 0000000..b86d5d6 --- /dev/null +++ b/tasks/jail_hommabot.yml @@ -0,0 +1,62 @@ +- name: Install packages inside jail + loop: + - { jail: hommabot, package: npm } + include_tasks: pkg_jail_install.yml + +- name: Build hommabot on this machine + delegate_to: localhost + shell: | + cd ../hommabot2 + npm run build + +- name: Create hommabot directory + file: + path: /usr/local/jails/containers/hommabot/root/hommabot + state: directory + owner: root + group: wheel + mode: "0755" + +- name: Install index.js + copy: + src: "{{ item }}" + dest: /usr/local/jails/containers/hommabot/root/hommabot/ + owner: root + group: wheel + mode: "0644" + loop: + - "../hommabot2/build/index.js" + - "../hommabot2/package.json" + - "../hommabot2/package-lock.json" + +- name: Install hommabot env file + template: + src: hommabot/root_hommabot_env.j2 + dest: /usr/local/jails/containers/hommabot/root/hommabot/.env + owner: root + group: wheel + mode: "0600" + +- name: Install deps.sh + copy: + src: templates/hommabot/root_hommabot_deps.sh + dest: /usr/local/jails/containers/hommabot/root/hommabot/deps.sh + owner: root + group: wheel + mode: "0755" + +- name: Install dependencies + shell: jexec hommabot /root/hommabot/deps.sh + +- name: Set up crontab + template: + src: hommabot/etc_crontab.j2 + dest: /usr/local/jails/containers/hommabot/etc/crontab + owner: root + group: wheel + mode: "0644" + register: jail_hommabot_etc_crontab + +- name: Restart cron + shell: jexec hommabot service cron restart + when: jail_hommabot_etc_crontab.changed diff --git a/tasks/jail_ingress.yml b/tasks/jail_ingress.yml index d5cb2e7..794c66a 100644 --- a/tasks/jail_ingress.yml +++ b/tasks/jail_ingress.yml @@ -1,4 +1,4 @@ -- name: Install packages inside ingress jail +- name: Install packages inside jail loop: - { jail: ingress, package: nginx } - { jail: ingress, package: py311-certbot } diff --git a/templates/diddle/root_clone.sh b/templates/diddle/root_clone.sh deleted file mode 100644 index a3dbdac..0000000 --- a/templates/diddle/root_clone.sh +++ /dev/null @@ -1,14 +0,0 @@ -#!/bin/sh - -# Exits with 100 if the directory was changed - -if [ ! -f /root/diddle ]; then - git clone https://github.com/jantuomi/diddle.git /root/diddle && exit 100 -fi - -cd /root/diddle -before=$(git rev-parse HEAD) -git fetch && git pull --ff-only --quiet -after=$(git rev-parse HEAD) - -if [ "$before" != "$after" ]; then exit 100; fi diff --git a/templates/hommabot/etc_crontab.j2 b/templates/hommabot/etc_crontab.j2 new file mode 100644 index 0000000..556d12a --- /dev/null +++ b/templates/hommabot/etc_crontab.j2 @@ -0,0 +1,10 @@ +# /etc/crontab - root's crontab for FreeBSD +# +# +SHELL=/bin/sh +PATH=/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin +# +#minute hour mday month wday who command + +# Run hommabot every Monday at 9:00 AM +0 9 * * 1 root /bin/sh -c "cd /root/hommabot && node index.js" diff --git a/templates/hommabot/root_hommabot_deps.sh b/templates/hommabot/root_hommabot_deps.sh new file mode 100644 index 0000000..25c0e56 --- /dev/null +++ b/templates/hommabot/root_hommabot_deps.sh @@ -0,0 +1,14 @@ +#!/bin/sh + +set -eux +cd /root/hommabot +npm ci + +# We need to build the better-sqlite3.node file before running the app +if [ ! -f build/better_sqlite3.node ]; then ( + mkdir -p build + cd node_modules/better-sqlite3 + npm run build-release + cp build/Release/better_sqlite3.node ../../build/better_sqlite3.node +) +fi diff --git a/templates/hommabot/root_hommabot_env.j2 b/templates/hommabot/root_hommabot_env.j2 new file mode 100644 index 0000000..c66c666 --- /dev/null +++ b/templates/hommabot/root_hommabot_env.j2 @@ -0,0 +1,4 @@ +TELEGRAM_BOT_TOKEN="{{ hommabot_telegram_bot_token }}" +SHEETS_SPREADSHEET_ID="{{ hommabot_sheets_spreadsheet_id }}" +SHEETS_RANGE="{{ hommabot_sheets_range }}" +G_SA_JSON_B64="{{ hommabot_g_sa_json_b64 }}" diff --git a/templates/root_clone.sh b/templates/root_clone.sh new file mode 100644 index 0000000..7f92c5f --- /dev/null +++ b/templates/root_clone.sh @@ -0,0 +1,21 @@ +#!/bin/sh + +REPO="$1" +TARGET="$2" + +set -eux + +# Exits with 100 if the directory was changed + +if [ ! -d "$TARGET" ]; then + git clone --depth=1 --branch main --single-branch "$REPO" "$TARGET" + exit 100 +fi + +cd "$TARGET" +before=$(git rev-parse HEAD) +git fetch --depth=1 --prune origin main +git reset --hard origin/main +after=$(git rev-parse HEAD) + +if [ "$before" != "$after" ]; then exit 100; fi |
