first commit
This commit is contained in:
commit
ecbe40af1d
20 changed files with 415 additions and 0 deletions
93
README.md
Normal file
93
README.md
Normal file
|
|
@ -0,0 +1,93 @@
|
||||||
|
# How to use:
|
||||||
|
|
||||||
|
## Adding a new user
|
||||||
|
To create a ssh key pair on the new users PC.
|
||||||
|
ssh-keygen -f new_floss_key
|
||||||
|
The 'private' part should NEVER leave the user's PC.
|
||||||
|
( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.)
|
||||||
|
|
||||||
|
you only need: new_floss_key.pub
|
||||||
|
|
||||||
|
open inventory/group_vars/all/users.yaml
|
||||||
|
add a new entry:
|
||||||
|
- username: alice
|
||||||
|
groups:
|
||||||
|
- ssh_login
|
||||||
|
- floss_sudo
|
||||||
|
- floss_admin
|
||||||
|
ssh_keys:
|
||||||
|
- ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop
|
||||||
|
- replace this ^^^^ line, with new_floss_key.pub...
|
||||||
|
|
||||||
|
deploy with:
|
||||||
|
ansible-playbook site.yaml
|
||||||
|
|
||||||
|
## delete user:
|
||||||
|
open inventory/group_vars/all/users.yaml
|
||||||
|
add:
|
||||||
|
- username: alice
|
||||||
|
__state: absent__
|
||||||
|
and rerun:
|
||||||
|
ansible-playbook site.yaml
|
||||||
|
|
||||||
|
|
||||||
|
# Troubleshoot:
|
||||||
|
|
||||||
|
## ssh:
|
||||||
|
Check permissions in the users home. All files must be owned by the user,
|
||||||
|
# sudo find ~alice -ls
|
||||||
|
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
|
||||||
|
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
|
||||||
|
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
|
||||||
|
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
|
||||||
|
|
||||||
|
check groups: ( look for ssh_login )
|
||||||
|
# id alice
|
||||||
|
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
|
||||||
|
|
||||||
|
check that sshd is running
|
||||||
|
# sudo systemctl status ssh # (or ps -ef | grep sshd )
|
||||||
|
and the config is ok:
|
||||||
|
# sudo sshd -t ( no output is good )
|
||||||
|
restart with:
|
||||||
|
# sudo systemctl status ssh
|
||||||
|
|
||||||
|
## sudo:
|
||||||
|
check groups ( look for floss_sudo and/or floss_admin )
|
||||||
|
|
||||||
|
check the sudoers file:
|
||||||
|
# visudo -cf /etc/sudoers.d/floss-sudo
|
||||||
|
/etc/sudoers.d/floss-sudo: parsed OK
|
||||||
|
|
||||||
|
Try to redeploy, if it was changed.
|
||||||
|
|
||||||
|
|
||||||
|
# About the role:
|
||||||
|
# Users Ansible Role
|
||||||
|
|
||||||
|
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
|
||||||
|
|
||||||
|
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
|
||||||
|
|
||||||
|
## Managed groups
|
||||||
|
|
||||||
|
The role uses these groups:
|
||||||
|
|
||||||
|
| Group | Purpose |
|
||||||
|
|---|---|
|
||||||
|
| `ssh_login` | Users in this group are allowed to log in via SSH |
|
||||||
|
| `floss_sudo` | Users in this group get passwordless sudo/root access |
|
||||||
|
| `floss_admin` | Users in this group get limited administrative commands |
|
||||||
|
|
||||||
|
Additional groups can be added as required.
|
||||||
|
|
||||||
|
|
||||||
|
License
|
||||||
|
-------
|
||||||
|
|
||||||
|
BSD
|
||||||
|
|
||||||
|
Author Information
|
||||||
|
------------------
|
||||||
|
version 1: holger + chatgpt
|
||||||
|
|
||||||
4
users/ansible.cfg
Normal file
4
users/ansible.cfg
Normal file
|
|
@ -0,0 +1,4 @@
|
||||||
|
|
||||||
|
[defaults]
|
||||||
|
inventory = inventory/hosts.yaml
|
||||||
|
roles_path = roles
|
||||||
27
users/inventory/group_vars/all/users.yaml
Normal file
27
users/inventory/group_vars/all/users.yaml
Normal file
|
|
@ -0,0 +1,27 @@
|
||||||
|
---
|
||||||
|
users:
|
||||||
|
- username: alice
|
||||||
|
groups:
|
||||||
|
- ssh_login
|
||||||
|
- floss_sudo
|
||||||
|
- floss_admin
|
||||||
|
ssh_keys:
|
||||||
|
- ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABvA6ktfo/Y2/bW5LY1EwnGCvN3oxRE4w9X+VLbIxys1mSUbbYHJNgoruFT5CgxQqKMJSWlUYw+BPusLnxRsq6u4OAwWsVIWV2aTCLZIP1UzvuqKl3xQ1lEOd+9sKIwOAvprimkDU4u9qC6/ls96raMZXqxQLqw6IL4b4wleednPdv4uLIpvjQpJ/xNFGTWFV43vnfGUVIMsF+wtVVWVKytQOgGcCxJK+tzKRmF/G/+QuDoGROhiytehb8d3hkykVqKP/aA32Xhwrvb6EIBxJkNb5whb+ZaB2xoLqqWA5ggGMy4taboaY0YIac8Y7Sm7Sv/Mx8C2zYTos63D7kbwsVmMsFOck8RB2ezUieZlccD1QelqS/kYI1y/BVqORPXDdPE7YXm4wPh0uebvmAtI2k/9hb73ejmMcOt6HH8Lo5ReQLNMwnwqcsTFGMCLQ8190d7xmnUH7iNvYQhtsX6e6lW/nZ0hYMLZI8S58Kxsf3rLaHhhtWA2FvRl0Mp4QurWtfrsR9etj0z8sFdSEHO6shv6j8/YX0rLkIyxjIe+NNmvpwSxaN4MI9ONvA52PqrxUeZZFg/3O4QuL7mFheHQ== holger2014
|
||||||
|
|
||||||
|
- username: bob
|
||||||
|
groups:
|
||||||
|
- ssh_login
|
||||||
|
- floss_admin
|
||||||
|
ssh_keys:
|
||||||
|
- ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABvA6ktfo/Y2/bW5LY1EwnGCvN3oxRE4w9X+VLbIxys1mSUbbYHJNgoruFT5CgxQqKMJSWlUYw+BPusLnxRsq6u4OAwWsVIWV2aTCLZIP1UzvuqKl3xQ1lEOd+9sKIwOAvprimkDU4u9qC6/ls96raMZXqxQLqw6IL4b4wleednPdv4uLIpvjQpJ/xNFGTWFV43vnfGUVIMsF+wtVVWVKytQOgGcCxJK+tzKRmF/G/+QuDoGROhiytehb8d3hkykVqKP/aA32Xhwrvb6EIBxJkNb5whb+ZaB2xoLqqWA5ggGMy4taboaY0YIac8Y7Sm7Sv/Mx8C2zYTos63D7kbwsVmMsFOck8RB2ezUieZlccD1QelqS/kYI1y/BVqORPXDdPE7YXm4wPh0uebvmAtI2k/9hb73ejmMcOt6HH8Lo5ReQLNMwnwqcsTFGMCLQ8190d7xmnUH7iNvYQhtsX6e6lW/nZ0hYMLZI8S58Kxsf3rLaHhhtWA2FvRl0Mp4QurWtfrsR9etj0z8sFdSEHO6shv6j8/YX0rLkIyxjIe+NNmvpwSxaN4MI9ONvA52PqrxUeZZFg/3O4QuL7mFheHQ== holger2014
|
||||||
|
- ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBBobKeyHere bob@workstation
|
||||||
|
#state: present
|
||||||
|
state: absent
|
||||||
|
|
||||||
|
- username: charlie
|
||||||
|
groups:
|
||||||
|
- ssh_login
|
||||||
|
- floss_sudo
|
||||||
|
ssh_keys:
|
||||||
|
- ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABvA6ktfo/Y2/bW5LY1EwnGCvN3oxRE4w9X+VLbIxys1mSUbbYHJNgoruFT5CgxQqKMJSWlUYw+BPusLnxRsq6u4OAwWsVIWV2aTCLZIP1UzvuqKl3xQ1lEOd+9sKIwOAvprimkDU4u9qC6/ls96raMZXqxQLqw6IL4b4wleednPdv4uLIpvjQpJ/xNFGTWFV43vnfGUVIMsF+wtVVWVKytQOgGcCxJK+tzKRmF/G/+QuDoGROhiytehb8d3hkykVqKP/aA32Xhwrvb6EIBxJkNb5whb+ZaB2xoLqqWA5ggGMy4taboaY0YIac8Y7Sm7Sv/Mx8C2zYTos63D7kbwsVmMsFOck8RB2ezUieZlccD1QelqS/kYI1y/BVqORPXDdPE7YXm4wPh0uebvmAtI2k/9hb73ejmMcOt6HH8Lo5ReQLNMwnwqcsTFGMCLQ8190d7xmnUH7iNvYQhtsX6e6lW/nZ0hYMLZI8S58Kxsf3rLaHhhtWA2FvRl0Mp4QurWtfrsR9etj0z8sFdSEHO6shv6j8/YX0rLkIyxjIe+NNmvpwSxaN4MI9ONvA52PqrxUeZZFg/3O4QuL7mFheHQ== holger2014
|
||||||
|
|
||||||
6
users/inventory/hosts.yaml
Normal file
6
users/inventory/hosts.yaml
Normal file
|
|
@ -0,0 +1,6 @@
|
||||||
|
|
||||||
|
---
|
||||||
|
all:
|
||||||
|
hosts:
|
||||||
|
localhost:
|
||||||
|
ansible_connection: local
|
||||||
93
users/roles/users/README.md
Normal file
93
users/roles/users/README.md
Normal file
|
|
@ -0,0 +1,93 @@
|
||||||
|
# How to use:
|
||||||
|
|
||||||
|
## Adding a new user
|
||||||
|
To create a ssh key pair on the new users PC.
|
||||||
|
ssh-keygen -f new_floss_key
|
||||||
|
The 'private' part should NEVER leave the user's PC.
|
||||||
|
( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.)
|
||||||
|
|
||||||
|
you only need: new_floss_key.pub
|
||||||
|
|
||||||
|
open inventory/group_vars/all/users.yaml
|
||||||
|
add a new entry:
|
||||||
|
- username: alice
|
||||||
|
groups:
|
||||||
|
- ssh_login
|
||||||
|
- floss_sudo
|
||||||
|
- floss_admin
|
||||||
|
ssh_keys:
|
||||||
|
- ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop
|
||||||
|
- replace this ^^^^ line, with new_floss_key.pub...
|
||||||
|
|
||||||
|
deploy with:
|
||||||
|
ansible-playbook site.yaml
|
||||||
|
|
||||||
|
## delete user:
|
||||||
|
open inventory/group_vars/all/users.yaml
|
||||||
|
add:
|
||||||
|
- username: alice
|
||||||
|
__state: absent__
|
||||||
|
and rerun:
|
||||||
|
ansible-playbook site.yaml
|
||||||
|
|
||||||
|
|
||||||
|
# Troubleshoot:
|
||||||
|
|
||||||
|
## ssh:
|
||||||
|
Check permissions in the users home. All files must be owned by the user,
|
||||||
|
# sudo find ~alice -ls
|
||||||
|
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
|
||||||
|
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
|
||||||
|
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
|
||||||
|
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
|
||||||
|
|
||||||
|
check groups: ( look for ssh_login )
|
||||||
|
# id alice
|
||||||
|
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
|
||||||
|
|
||||||
|
check that sshd is running
|
||||||
|
# sudo systemctl status ssh # (or ps -ef | grep sshd )
|
||||||
|
and the config is ok:
|
||||||
|
# sudo sshd -t ( no output is good )
|
||||||
|
restart with:
|
||||||
|
# sudo systemctl status ssh
|
||||||
|
|
||||||
|
## sudo:
|
||||||
|
check groups ( look for floss_sudo and/or floss_admin )
|
||||||
|
|
||||||
|
check the sudoers file:
|
||||||
|
# visudo -cf /etc/sudoers.d/floss-sudo
|
||||||
|
/etc/sudoers.d/floss-sudo: parsed OK
|
||||||
|
|
||||||
|
Try to redeploy, if it was changed.
|
||||||
|
|
||||||
|
|
||||||
|
# About the role:
|
||||||
|
# Users Ansible Role
|
||||||
|
|
||||||
|
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
|
||||||
|
|
||||||
|
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
|
||||||
|
|
||||||
|
## Managed groups
|
||||||
|
|
||||||
|
The role uses these groups:
|
||||||
|
|
||||||
|
| Group | Purpose |
|
||||||
|
|---|---|
|
||||||
|
| `ssh_login` | Users in this group are allowed to log in via SSH |
|
||||||
|
| `floss_sudo` | Users in this group get passwordless sudo/root access |
|
||||||
|
| `floss_admin` | Users in this group get limited administrative commands |
|
||||||
|
|
||||||
|
Additional groups can be added as required.
|
||||||
|
|
||||||
|
|
||||||
|
License
|
||||||
|
-------
|
||||||
|
|
||||||
|
BSD
|
||||||
|
|
||||||
|
Author Information
|
||||||
|
------------------
|
||||||
|
version 1: holger + chatgpt
|
||||||
|
|
||||||
2
users/roles/users/defaults/main.yaml
Normal file
2
users/roles/users/defaults/main.yaml
Normal file
|
|
@ -0,0 +1,2 @@
|
||||||
|
---
|
||||||
|
# defaults file for users
|
||||||
7
users/roles/users/floss
Normal file
7
users/roles/users/floss
Normal file
|
|
@ -0,0 +1,7 @@
|
||||||
|
-----BEGIN OPENSSH PRIVATE KEY-----
|
||||||
|
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW
|
||||||
|
QyNTUxOQAAACDal1rP22oyImJzn6y4bzX3jPbMb+/5uso7nDX5jICNEQAAAJDUrVqG1K1a
|
||||||
|
hgAAAAtzc2gtZWQyNTUxOQAAACDal1rP22oyImJzn6y4bzX3jPbMb+/5uso7nDX5jICNEQ
|
||||||
|
AAAEBl5KA/jERAaBNMVfdGKlssfRt2BEHlq7D9FHqOkErBitqXWs/bajIiYnOfrLhvNfeM
|
||||||
|
9sxv7/m6yjucNfmMgI0RAAAAB2htQHRpbmsBAgMEBQY=
|
||||||
|
-----END OPENSSH PRIVATE KEY-----
|
||||||
1
users/roles/users/floss.pub
Normal file
1
users/roles/users/floss.pub
Normal file
|
|
@ -0,0 +1 @@
|
||||||
|
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINqXWs/bajIiYnOfrLhvNfeM9sxv7/m6yjucNfmMgI0R hm@tink
|
||||||
6
users/roles/users/handlers/main.yaml
Normal file
6
users/roles/users/handlers/main.yaml
Normal file
|
|
@ -0,0 +1,6 @@
|
||||||
|
|
||||||
|
---
|
||||||
|
- name: Restart sshd
|
||||||
|
ansible.builtin.service:
|
||||||
|
name: ssh
|
||||||
|
state: restarted
|
||||||
52
users/roles/users/meta/main.yaml
Normal file
52
users/roles/users/meta/main.yaml
Normal file
|
|
@ -0,0 +1,52 @@
|
||||||
|
galaxy_info:
|
||||||
|
author: your name
|
||||||
|
description: your role description
|
||||||
|
company: your company (optional)
|
||||||
|
|
||||||
|
# If the issue tracker for your role is not on github, uncomment the
|
||||||
|
# next line and provide a value
|
||||||
|
# issue_tracker_url: http://example.com/issue/tracker
|
||||||
|
|
||||||
|
# Choose a valid license ID from https://spdx.org - some suggested licenses:
|
||||||
|
# - BSD-3-Clause (default)
|
||||||
|
# - MIT
|
||||||
|
# - GPL-2.0-or-later
|
||||||
|
# - GPL-3.0-only
|
||||||
|
# - Apache-2.0
|
||||||
|
# - CC-BY-4.0
|
||||||
|
license: license (GPL-2.0-or-later, MIT, etc)
|
||||||
|
|
||||||
|
min_ansible_version: 2.1
|
||||||
|
|
||||||
|
# If this a Container Enabled role, provide the minimum Ansible Container version.
|
||||||
|
# min_ansible_container_version:
|
||||||
|
|
||||||
|
#
|
||||||
|
# Provide a list of supported platforms, and for each platform a list of versions.
|
||||||
|
# If you don't wish to enumerate all versions for a particular platform, use 'all'.
|
||||||
|
# To view available platforms and versions (or releases), visit:
|
||||||
|
# https://galaxy.ansible.com/api/v1/platforms/
|
||||||
|
#
|
||||||
|
# platforms:
|
||||||
|
# - name: Fedora
|
||||||
|
# versions:
|
||||||
|
# - all
|
||||||
|
# - 25
|
||||||
|
# - name: SomePlatform
|
||||||
|
# versions:
|
||||||
|
# - all
|
||||||
|
# - 1.0
|
||||||
|
# - 7
|
||||||
|
# - 99.99
|
||||||
|
|
||||||
|
galaxy_tags: []
|
||||||
|
# List tags for your role here, one per line. A tag is a keyword that describes
|
||||||
|
# and categorizes the role. Users find roles by searching for tags. Be sure to
|
||||||
|
# remove the '[]' above, if you add tags to this list.
|
||||||
|
#
|
||||||
|
# NOTE: A tag is limited to a single word comprised of alphanumeric characters.
|
||||||
|
# Maximum 20 tags per role.
|
||||||
|
|
||||||
|
dependencies: []
|
||||||
|
# List your role dependencies here, one per line. Be sure to remove the '[]' above,
|
||||||
|
# if you add dependencies to this list.
|
||||||
7
users/roles/users/tasks/groups.yaml
Normal file
7
users/roles/users/tasks/groups.yaml
Normal file
|
|
@ -0,0 +1,7 @@
|
||||||
|
|
||||||
|
---
|
||||||
|
- name: Ensure user groups exist
|
||||||
|
ansible.builtin.group:
|
||||||
|
name: "{{ item }}"
|
||||||
|
state: present
|
||||||
|
loop: "{{ users | map(attribute='groups') | flatten | unique }}"
|
||||||
21
users/roles/users/tasks/main.yaml
Normal file
21
users/roles/users/tasks/main.yaml
Normal file
|
|
@ -0,0 +1,21 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
- name: Manage sudoers
|
||||||
|
ansible.builtin.import_tasks: sudoers.yaml
|
||||||
|
tags:
|
||||||
|
- sudoers
|
||||||
|
|
||||||
|
- name: Manage groups
|
||||||
|
ansible.builtin.import_tasks: groups.yaml
|
||||||
|
tags:
|
||||||
|
- groups
|
||||||
|
|
||||||
|
- name: Manage sshd
|
||||||
|
ansible.builtin.import_tasks: sshd.yaml
|
||||||
|
tags:
|
||||||
|
- sshd
|
||||||
|
|
||||||
|
- name: Manage users
|
||||||
|
ansible.builtin.import_tasks: users.yaml
|
||||||
|
tags:
|
||||||
|
- users
|
||||||
14
users/roles/users/tasks/sshd.yaml
Normal file
14
users/roles/users/tasks/sshd.yaml
Normal file
|
|
@ -0,0 +1,14 @@
|
||||||
|
---
|
||||||
|
|
||||||
|
- name: Restrict SSH access to ssh_login group
|
||||||
|
ansible.builtin.copy:
|
||||||
|
dest: /etc/ssh/sshd_config.d/99-allowgroups.conf
|
||||||
|
content: |
|
||||||
|
AllowGroups ssh_login
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: "0644"
|
||||||
|
validate: "/usr/sbin/sshd -t -f %s"
|
||||||
|
notify: Restart sshd
|
||||||
|
|
||||||
|
...
|
||||||
15
users/roles/users/tasks/sudoers.yaml
Normal file
15
users/roles/users/tasks/sudoers.yaml
Normal file
|
|
@ -0,0 +1,15 @@
|
||||||
|
|
||||||
|
---
|
||||||
|
- name: Configure passwordless sudo for sudo group
|
||||||
|
ansible.builtin.copy:
|
||||||
|
dest: /etc/sudoers.d/floss-sudo
|
||||||
|
content: |
|
||||||
|
Defaults shell_noargs
|
||||||
|
%floss_sudo ALL=(ALL) NOPASSWD: ALL
|
||||||
|
%floss_admin ALL=(ALL) NOPASSWD: /usr/bin/netstat -ltp
|
||||||
|
%floss_admin ALL=(ALL) NOPASSWD: /bin/netstat -ltp
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: "0440"
|
||||||
|
validate: "/usr/sbin/visudo -cf %s"
|
||||||
|
|
||||||
12
users/roles/users/tasks/sudoers.yaml~
Normal file
12
users/roles/users/tasks/sudoers.yaml~
Normal file
|
|
@ -0,0 +1,12 @@
|
||||||
|
|
||||||
|
---
|
||||||
|
- name: Configure passwordless sudo for sudo group
|
||||||
|
ansible.builtin.copy:
|
||||||
|
dest: /etc/sudoers.d/floss-sudo
|
||||||
|
content: |
|
||||||
|
%sudo ALL=(ALL:ALL) NOPASSWD: ALL
|
||||||
|
owner: root
|
||||||
|
group: root
|
||||||
|
mode: "0440"
|
||||||
|
validate: "/usr/sbin/visudo -cf %s"
|
||||||
|
|
||||||
36
users/roles/users/tasks/users.yaml
Normal file
36
users/roles/users/tasks/users.yaml
Normal file
|
|
@ -0,0 +1,36 @@
|
||||||
|
---
|
||||||
|
- name: Manage user accounts
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: "{{ item.username }}"
|
||||||
|
state: "{{ item.state | default('present') }}"
|
||||||
|
create_home: "{{ item.create_home | default(true) }}"
|
||||||
|
shell: "{{ item.shell | default('/bin/bash') }}"
|
||||||
|
groups: "{{ item.groups | default([]) | join(',') }}"
|
||||||
|
append: true
|
||||||
|
remove: "{{ item.remove_home | default(true) }}"
|
||||||
|
loop: "{{ users }}"
|
||||||
|
|
||||||
|
|
||||||
|
- name: Create .ssh directories
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: "/home/{{ item.username }}/.ssh"
|
||||||
|
state: directory
|
||||||
|
owner: "{{ item.username }}"
|
||||||
|
group: "{{ item.username }}"
|
||||||
|
mode: "0700"
|
||||||
|
loop: "{{ users }}"
|
||||||
|
when: item.state | default('present') == 'present'
|
||||||
|
|
||||||
|
- name: Add SSH authorized keys
|
||||||
|
ansible.builtin.lineinfile:
|
||||||
|
path: "/home/{{ item.0.username }}/.ssh/authorized_keys"
|
||||||
|
line: "{{ item.1 }}"
|
||||||
|
create: true
|
||||||
|
owner: "{{ item.0.username }}"
|
||||||
|
group: "{{ item.0.username }}"
|
||||||
|
mode: "0600"
|
||||||
|
state: present
|
||||||
|
loop: "{{ users | subelements('ssh_keys', skip_missing=True) }}"
|
||||||
|
when: item.0.state | default('present') == 'present'
|
||||||
|
|
||||||
|
|
||||||
2
users/roles/users/tests/inventory
Normal file
2
users/roles/users/tests/inventory
Normal file
|
|
@ -0,0 +1,2 @@
|
||||||
|
localhost
|
||||||
|
|
||||||
5
users/roles/users/tests/test.yaml
Normal file
5
users/roles/users/tests/test.yaml
Normal file
|
|
@ -0,0 +1,5 @@
|
||||||
|
---
|
||||||
|
- hosts: localhost
|
||||||
|
remote_user: root
|
||||||
|
roles:
|
||||||
|
- users
|
||||||
2
users/roles/users/vars/main.yaml
Normal file
2
users/roles/users/vars/main.yaml
Normal file
|
|
@ -0,0 +1,2 @@
|
||||||
|
---
|
||||||
|
# vars file for users
|
||||||
10
users/site.yaml
Normal file
10
users/site.yaml
Normal file
|
|
@ -0,0 +1,10 @@
|
||||||
|
|
||||||
|
---
|
||||||
|
- name: Configure Linux users and SSH access
|
||||||
|
hosts: all
|
||||||
|
become: true
|
||||||
|
gather_facts: false
|
||||||
|
|
||||||
|
roles:
|
||||||
|
- users
|
||||||
|
|
||||||
Loading…
Add table
Reference in a new issue