Make sshd restart handler multi-distro

The handler restarted the hardcoded service "ssh", which only exists on
Debian-family distros; on RedHat, Suse, Arch etc. the unit is "sshd",
so any sshd config change would fail there.

Pick the name via a new users_sshd_service_name default keyed off
ansible_facts['os_family'] (overridable for exotic distros). Since
site.yaml runs with gather_facts: false, the role now gathers minimal
facts itself when os_family is missing, tagged always so it also runs
under --tags sshd.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
sjat 2026-07-16 13:47:31 +02:00
parent c23e1b594c
commit 8b02e0363f
4 changed files with 18 additions and 1 deletions

View file

@ -94,6 +94,8 @@ This role manages local Linux users, groups, SSH access, SSH keys, and sudo perm
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`. The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
The SSH service name is picked automatically (`ssh` on Debian-family distros, `sshd` elsewhere); set `users_sshd_service_name` if your distro uses a different name.
## Managed groups ## Managed groups
The role uses these groups: The role uses these groups:

View file

@ -1,2 +1,7 @@
--- ---
# defaults file for users # defaults file for users
# Name of the SSH service unit. Debian-family distros call it "ssh",
# most others (RedHat, Suse, Arch, ...) call it "sshd".
# Override this if your distro uses a different name.
users_sshd_service_name: "{{ 'ssh' if ansible_facts['os_family'] == 'Debian' else 'sshd' }}"

View file

@ -2,5 +2,5 @@
--- ---
- name: Restart sshd - name: Restart sshd
ansible.builtin.service: ansible.builtin.service:
name: ssh name: "{{ users_sshd_service_name }}"
state: restarted state: restarted

View file

@ -1,5 +1,15 @@
--- ---
# The play runs with gather_facts: false, but the sshd handler needs
# ansible_facts['os_family'] to pick the right service name.
- name: Gather minimal facts if the play skipped fact gathering
ansible.builtin.setup:
gather_subset:
- "!all"
when: ansible_facts['os_family'] is not defined
tags:
- always
- name: Manage sudoers - name: Manage sudoers
ansible.builtin.import_tasks: sudoers.yaml ansible.builtin.import_tasks: sudoers.yaml
tags: tags: