Automate your workstation installation !

@sylvain_metayer

photo

πŸ‡«πŸ‡· Sylvain MΓ‰TAYER

logo

Tech Lead @Onepoint

Pros and Cons

Goal

State

Manage configuration files

?

Manage installed software

?

Version Control

?

Maintainability

?

Manage personal and pro workstation

?

Can handle secrets

?

What are dotfiles?

~/.bashrc
#!/usr/bin/env bash

if [ -f /etc/bashrc ]; then
 . /etc/bashrc
fi

export SSH_AUTH_SOCK=/run/user/1000/ssh-agent.socket
# ...

Others : vimrc, gitconfig, …​

How to manage them?

Stow

GNU Stow is a symlink farm manager which takes distinct sets of software and/or data located in separate directories on the filesystem, and makes them all appear to be installed in a single directory tree.
— https://www.gnu.org/software/stow/manual/stow.html#Bootstrapping

Pros and Cons

Goal

State

Manage configuration files

βœ…

Manage installed software

❌

Version Control

βœ…

Maintainability

βœ…

Manage personal and pro workstation

😐

Can handle secrets

❌

Homemade script

Bash, PHP…​ The choice is yours, let’s code!

Pros and Cons

Goal

State

Manage configuration files

βœ…

Manage installed software

βœ…

Version Control

βœ…

Maintainability

😐

Manage personal and pro workstation

βœ…

Can handle secrets

βœ…

Ansible

Structure

β”œβ”€β”€ playbooks
β”‚   β”œβ”€β”€ personal
β”‚   β”œβ”€β”€ work
β”‚   β”œβ”€β”€ β”œβ”€β”€ main.yaml
β”œβ”€β”€ roles
β”‚   β”œβ”€β”€ jetbrains_toolbox
β”‚   β”‚   β”œβ”€β”€ defaults
β”‚   β”‚   β”œβ”€β”€ tasks
β”‚   │── git_config
β”‚   β”‚   β”œβ”€β”€ tasks
β”‚   └── [...]

Playbook

- hosts: localhost
  tasks:
    - name: "Simple task"
      debug:
        msg: |-
Hello DevoxxUK ! :)
  roles:
    - role: geerlingguy.docker
      become: true
    - role: git_config

Usage

$ cat scripts/setup.sh
python3 -m pip install --user -r "requirements.txt"
ansible-galaxy role install -r "requirements.yml"
$ cat requirements.txt
ansible==7.0.0
$ cat requirements.yml
roles:
  - src: geerlingguy.docker
    version: 6.1.0

Usage

$ ansible-playbook playbooks/personal/main.yaml -K
BECOME password:
PLAY [localhost] ************************************

TASK [git_config : Ensure Git config file exists] ************************************
ok: [localhost]

TASK [git_config : Render Git config Template] ************************************
changed: [localhost]

PLAY RECAP ************************************
localhost                  : ok=1    changed=1    unreachable=0    failed=0    skipped=0    rescued=0    ignored=0

Playbook run took 0 days, 0 hours, 0 minutes, 1 seconds

Software installation

roles/commons/defaults/main.yaml
packages_to_install:
  - vim
  - firefox
  - code
roles/commons/tasks/main.yaml
- name: Install packages
  become: true
  ansible.builtin.package:
    name: "{{ packages_to_install }}"
    state: present
playbooks/personal/main.yaml
- hosts: localhost
  roles:
    - role: commons
      vars:
        packages_to_install: [vim, firefox]

Templating

- name: Template gitconfig
  ansible.builtin.template:
    src: templates/gitconfig.j2
    dest: "~/.gitconfig"
roles/git_config/templates/gitconfig.j2
[user]
{% if git_config_user is defined %}
  name = {{ git_config_user }}
{% endif %}
{% if git_config_email is defined %}
  email = {{ git_config_email }}
{% endif %}

Secrets

- name: "Copy secret file"
  copy:
    src: "secret_data.txt"
    dest: ~/secret_data.txt
    mode: "0600"

Secrets

$ANSIBLE_VAULT;1.1;AES256
62653039646462626165653337346538626534306332323566353963656633333066383732306637
3930366539386637616137336166636233303231666537650a666539623066303731376631616532
38613836653466323132316331646137323665383939376362656535633130646265356434346563
3066363264313834320a333432613265393630313235303161363731356266663733343362356462
37396131643235313936653139353036306363646234366532386138393165383962

Secrets

ansible-vault create secret_data.txt
$ ansible-vault view secret_data.txt
Vault password:
Hello DevoxxUK ! :)
$ ansible-playbook playbooks/work/main.yaml --ask-vault-pass

Many workstation?

β”œβ”€β”€ personal
β”‚   β”œβ”€β”€ main.yaml
└── work
    └── main.yaml

Pros and Cons

Goal

State

Manage configuration files

βœ…

Manage installed software

βœ…

Version Control

βœ…

Maintainability

βœ…

Manage personal and pro workstation

βœ…

Can handle secrets

βœ…

What if…​

Conclusion

Standard
Slides
Slides
Vos retours
Feedback