Make sshd restart handler multi-distro
The handler restarted the hardcoded service "ssh", which only exists on Debian-family distros; on RedHat, Suse, Arch etc. the unit is "sshd", so any sshd config change would fail there. Pick the name via a new users_sshd_service_name default keyed off ansible_facts['os_family'] (overridable for exotic distros). Since site.yaml runs with gather_facts: false, the role now gathers minimal facts itself when os_family is missing, tagged always so it also runs under --tags sshd. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
parent
c23e1b594c
commit
8b02e0363f
4 changed files with 18 additions and 1 deletions
|
|
@ -94,6 +94,8 @@ This role manages local Linux users, groups, SSH access, SSH keys, and sudo perm
|
|||
|
||||
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
|
||||
|
||||
The SSH service name is picked automatically (`ssh` on Debian-family distros, `sshd` elsewhere); set `users_sshd_service_name` if your distro uses a different name.
|
||||
|
||||
## Managed groups
|
||||
The role uses these groups:
|
||||
|
||||
|
|
|
|||
|
|
@ -1,2 +1,7 @@
|
|||
---
|
||||
# defaults file for users
|
||||
|
||||
# Name of the SSH service unit. Debian-family distros call it "ssh",
|
||||
# most others (RedHat, Suse, Arch, ...) call it "sshd".
|
||||
# Override this if your distro uses a different name.
|
||||
users_sshd_service_name: "{{ 'ssh' if ansible_facts['os_family'] == 'Debian' else 'sshd' }}"
|
||||
|
|
|
|||
|
|
@ -2,5 +2,5 @@
|
|||
---
|
||||
- name: Restart sshd
|
||||
ansible.builtin.service:
|
||||
name: ssh
|
||||
name: "{{ users_sshd_service_name }}"
|
||||
state: restarted
|
||||
|
|
|
|||
|
|
@ -1,5 +1,15 @@
|
|||
---
|
||||
|
||||
# The play runs with gather_facts: false, but the sshd handler needs
|
||||
# ansible_facts['os_family'] to pick the right service name.
|
||||
- name: Gather minimal facts if the play skipped fact gathering
|
||||
ansible.builtin.setup:
|
||||
gather_subset:
|
||||
- "!all"
|
||||
when: ansible_facts['os_family'] is not defined
|
||||
tags:
|
||||
- always
|
||||
|
||||
- name: Manage sudoers
|
||||
ansible.builtin.import_tasks: sudoers.yaml
|
||||
tags:
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue