make_users/README.md

118 lines
2.7 KiB
Markdown
Raw Normal View History

2026-07-16 12:57:19 +02:00
2026-07-15 18:01:01 +02:00
# How to use:
## Adding a new user
2026-07-15 18:33:53 +02:00
To create a ssh key pair on the new users PC:
```bash
2026-07-15 18:01:01 +02:00
ssh-keygen -f new_floss_key
2026-07-15 18:36:47 +02:00
```
2026-07-15 18:33:53 +02:00
2026-07-15 18:01:01 +02:00
The 'private' part should NEVER leave the user's PC.
( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.)
2026-07-15 18:36:47 +02:00
- You only need: new_floss_key.pub
2026-07-15 18:33:53 +02:00
- open inventory/group_vars/all/users.yaml
- add a new entry:
```yaml
2026-07-15 18:01:01 +02:00
- username: alice
groups:
- ssh_login
- floss_sudo
- floss_admin
ssh_keys:
- ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop
- replace this ^^^^ line, with new_floss_key.pub...
2026-07-15 18:36:47 +02:00
```
2026-07-15 18:01:01 +02:00
2026-07-15 18:33:53 +02:00
### Deploy with:
2026-07-15 18:36:47 +02:00
```bash
2026-07-15 18:33:53 +02:00
- ansible-playbook site.yaml
2026-07-15 18:36:47 +02:00
```
2026-07-15 18:01:01 +02:00
2026-07-15 18:33:53 +02:00
## Delete user:
- open inventory/group_vars/all/users.yaml
- add:
```yaml
2026-07-15 18:01:01 +02:00
- username: alice
__state: absent__
2026-07-15 18:33:53 +02:00
- run:
```yaml
2026-07-15 18:01:01 +02:00
ansible-playbook site.yaml
2026-07-15 18:36:47 +02:00
```
2026-07-15 18:01:01 +02:00
# Troubleshoot:
## ssh:
Check permissions in the users home. All files must be owned by the user,
2026-07-15 18:41:17 +02:00
```bash
sudo find ~alice -ls
2026-07-15 18:01:01 +02:00
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
2026-07-15 18:41:17 +02:00
```
2026-07-15 18:01:01 +02:00
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
check groups: ( look for ssh_login )
2026-07-15 18:41:17 +02:00
```bash
id alice
2026-07-15 18:01:01 +02:00
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
2026-07-15 18:41:17 +02:00
```
2026-07-15 18:01:01 +02:00
check that sshd is running
2026-07-15 18:41:17 +02:00
```bash
sudo systemctl status ssh # (or ps -ef | grep sshd )
2026-07-15 18:01:01 +02:00
and the config is ok:
2026-07-15 18:41:17 +02:00
sudo sshd -t # ( no output is good )
2026-07-15 18:01:01 +02:00
restart with:
2026-07-15 18:41:17 +02:00
sudo systemctl status ssh
```
2026-07-15 18:01:01 +02:00
## sudo:
check groups ( look for floss_sudo and/or floss_admin )
2026-07-15 18:41:17 +02:00
```bash
id alice
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
```
2026-07-15 18:01:01 +02:00
check the sudoers file:
2026-07-15 18:41:17 +02:00
```bash
visudo -cf /etc/sudoers.d/floss-sudo
/etc/sudoers.d/floss-sudo: parsed OK
```
2026-07-15 18:01:01 +02:00
Try to redeploy, if it was changed.
# About the role:
2026-07-15 18:41:17 +02:00
## Users Ansible Role
2026-07-15 18:01:01 +02:00
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
## Managed groups
The role uses these groups:
| Group | Purpose |
|---|---|
| `ssh_login` | Users in this group are allowed to log in via SSH |
| `floss_sudo` | Users in this group get passwordless sudo/root access |
| `floss_admin` | Users in this group get limited administrative commands |
Additional groups can be added as required.
2026-07-15 18:41:17 +02:00
##License
2026-07-15 18:01:01 +02:00
-------
BSD
2026-07-15 18:41:17 +02:00
##Author Information
2026-07-15 18:01:01 +02:00
------------------
version 1: holger + chatgpt