first commit

This commit is contained in:
holger 2026-07-15 18:01:01 +02:00
commit ecbe40af1d
20 changed files with 415 additions and 0 deletions

93
README.md Normal file
View file

@ -0,0 +1,93 @@
# How to use:
## Adding a new user
To create a ssh key pair on the new users PC.
ssh-keygen -f new_floss_key
The 'private' part should NEVER leave the user's PC.
( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.)
you only need: new_floss_key.pub
open inventory/group_vars/all/users.yaml
add a new entry:
- username: alice
groups:
- ssh_login
- floss_sudo
- floss_admin
ssh_keys:
- ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop
- replace this ^^^^ line, with new_floss_key.pub...
deploy with:
ansible-playbook site.yaml
## delete user:
open inventory/group_vars/all/users.yaml
add:
- username: alice
__state: absent__
and rerun:
ansible-playbook site.yaml
# Troubleshoot:
## ssh:
Check permissions in the users home. All files must be owned by the user,
# sudo find ~alice -ls
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
check groups: ( look for ssh_login )
# id alice
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
check that sshd is running
# sudo systemctl status ssh # (or ps -ef | grep sshd )
and the config is ok:
# sudo sshd -t ( no output is good )
restart with:
# sudo systemctl status ssh
## sudo:
check groups ( look for floss_sudo and/or floss_admin )
check the sudoers file:
# visudo -cf /etc/sudoers.d/floss-sudo
/etc/sudoers.d/floss-sudo: parsed OK
Try to redeploy, if it was changed.
# About the role:
# Users Ansible Role
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
## Managed groups
The role uses these groups:
| Group | Purpose |
|---|---|
| `ssh_login` | Users in this group are allowed to log in via SSH |
| `floss_sudo` | Users in this group get passwordless sudo/root access |
| `floss_admin` | Users in this group get limited administrative commands |
Additional groups can be added as required.
License
-------
BSD
Author Information
------------------
version 1: holger + chatgpt

4
users/ansible.cfg Normal file
View file

@ -0,0 +1,4 @@
[defaults]
inventory = inventory/hosts.yaml
roles_path = roles

View file

@ -0,0 +1,27 @@
---
users:
- username: alice
groups:
- ssh_login
- floss_sudo
- floss_admin
ssh_keys:
- ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABvA6ktfo/Y2/bW5LY1EwnGCvN3oxRE4w9X+VLbIxys1mSUbbYHJNgoruFT5CgxQqKMJSWlUYw+BPusLnxRsq6u4OAwWsVIWV2aTCLZIP1UzvuqKl3xQ1lEOd+9sKIwOAvprimkDU4u9qC6/ls96raMZXqxQLqw6IL4b4wleednPdv4uLIpvjQpJ/xNFGTWFV43vnfGUVIMsF+wtVVWVKytQOgGcCxJK+tzKRmF/G/+QuDoGROhiytehb8d3hkykVqKP/aA32Xhwrvb6EIBxJkNb5whb+ZaB2xoLqqWA5ggGMy4taboaY0YIac8Y7Sm7Sv/Mx8C2zYTos63D7kbwsVmMsFOck8RB2ezUieZlccD1QelqS/kYI1y/BVqORPXDdPE7YXm4wPh0uebvmAtI2k/9hb73ejmMcOt6HH8Lo5ReQLNMwnwqcsTFGMCLQ8190d7xmnUH7iNvYQhtsX6e6lW/nZ0hYMLZI8S58Kxsf3rLaHhhtWA2FvRl0Mp4QurWtfrsR9etj0z8sFdSEHO6shv6j8/YX0rLkIyxjIe+NNmvpwSxaN4MI9ONvA52PqrxUeZZFg/3O4QuL7mFheHQ== holger2014
- username: bob
groups:
- ssh_login
- floss_admin
ssh_keys:
- ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABvA6ktfo/Y2/bW5LY1EwnGCvN3oxRE4w9X+VLbIxys1mSUbbYHJNgoruFT5CgxQqKMJSWlUYw+BPusLnxRsq6u4OAwWsVIWV2aTCLZIP1UzvuqKl3xQ1lEOd+9sKIwOAvprimkDU4u9qC6/ls96raMZXqxQLqw6IL4b4wleednPdv4uLIpvjQpJ/xNFGTWFV43vnfGUVIMsF+wtVVWVKytQOgGcCxJK+tzKRmF/G/+QuDoGROhiytehb8d3hkykVqKP/aA32Xhwrvb6EIBxJkNb5whb+ZaB2xoLqqWA5ggGMy4taboaY0YIac8Y7Sm7Sv/Mx8C2zYTos63D7kbwsVmMsFOck8RB2ezUieZlccD1QelqS/kYI1y/BVqORPXDdPE7YXm4wPh0uebvmAtI2k/9hb73ejmMcOt6HH8Lo5ReQLNMwnwqcsTFGMCLQ8190d7xmnUH7iNvYQhtsX6e6lW/nZ0hYMLZI8S58Kxsf3rLaHhhtWA2FvRl0Mp4QurWtfrsR9etj0z8sFdSEHO6shv6j8/YX0rLkIyxjIe+NNmvpwSxaN4MI9ONvA52PqrxUeZZFg/3O4QuL7mFheHQ== holger2014
- ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBBobKeyHere bob@workstation
#state: present
state: absent
- username: charlie
groups:
- ssh_login
- floss_sudo
ssh_keys:
- ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABvA6ktfo/Y2/bW5LY1EwnGCvN3oxRE4w9X+VLbIxys1mSUbbYHJNgoruFT5CgxQqKMJSWlUYw+BPusLnxRsq6u4OAwWsVIWV2aTCLZIP1UzvuqKl3xQ1lEOd+9sKIwOAvprimkDU4u9qC6/ls96raMZXqxQLqw6IL4b4wleednPdv4uLIpvjQpJ/xNFGTWFV43vnfGUVIMsF+wtVVWVKytQOgGcCxJK+tzKRmF/G/+QuDoGROhiytehb8d3hkykVqKP/aA32Xhwrvb6EIBxJkNb5whb+ZaB2xoLqqWA5ggGMy4taboaY0YIac8Y7Sm7Sv/Mx8C2zYTos63D7kbwsVmMsFOck8RB2ezUieZlccD1QelqS/kYI1y/BVqORPXDdPE7YXm4wPh0uebvmAtI2k/9hb73ejmMcOt6HH8Lo5ReQLNMwnwqcsTFGMCLQ8190d7xmnUH7iNvYQhtsX6e6lW/nZ0hYMLZI8S58Kxsf3rLaHhhtWA2FvRl0Mp4QurWtfrsR9etj0z8sFdSEHO6shv6j8/YX0rLkIyxjIe+NNmvpwSxaN4MI9ONvA52PqrxUeZZFg/3O4QuL7mFheHQ== holger2014

View file

@ -0,0 +1,6 @@
---
all:
hosts:
localhost:
ansible_connection: local

View file

@ -0,0 +1,93 @@
# How to use:
## Adding a new user
To create a ssh key pair on the new users PC.
ssh-keygen -f new_floss_key
The 'private' part should NEVER leave the user's PC.
( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.)
you only need: new_floss_key.pub
open inventory/group_vars/all/users.yaml
add a new entry:
- username: alice
groups:
- ssh_login
- floss_sudo
- floss_admin
ssh_keys:
- ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop
- replace this ^^^^ line, with new_floss_key.pub...
deploy with:
ansible-playbook site.yaml
## delete user:
open inventory/group_vars/all/users.yaml
add:
- username: alice
__state: absent__
and rerun:
ansible-playbook site.yaml
# Troubleshoot:
## ssh:
Check permissions in the users home. All files must be owned by the user,
# sudo find ~alice -ls
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
check groups: ( look for ssh_login )
# id alice
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
check that sshd is running
# sudo systemctl status ssh # (or ps -ef | grep sshd )
and the config is ok:
# sudo sshd -t ( no output is good )
restart with:
# sudo systemctl status ssh
## sudo:
check groups ( look for floss_sudo and/or floss_admin )
check the sudoers file:
# visudo -cf /etc/sudoers.d/floss-sudo
/etc/sudoers.d/floss-sudo: parsed OK
Try to redeploy, if it was changed.
# About the role:
# Users Ansible Role
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
## Managed groups
The role uses these groups:
| Group | Purpose |
|---|---|
| `ssh_login` | Users in this group are allowed to log in via SSH |
| `floss_sudo` | Users in this group get passwordless sudo/root access |
| `floss_admin` | Users in this group get limited administrative commands |
Additional groups can be added as required.
License
-------
BSD
Author Information
------------------
version 1: holger + chatgpt

View file

@ -0,0 +1,2 @@
---
# defaults file for users

7
users/roles/users/floss Normal file
View file

@ -0,0 +1,7 @@
-----BEGIN OPENSSH PRIVATE KEY-----
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW
QyNTUxOQAAACDal1rP22oyImJzn6y4bzX3jPbMb+/5uso7nDX5jICNEQAAAJDUrVqG1K1a
hgAAAAtzc2gtZWQyNTUxOQAAACDal1rP22oyImJzn6y4bzX3jPbMb+/5uso7nDX5jICNEQ
AAAEBl5KA/jERAaBNMVfdGKlssfRt2BEHlq7D9FHqOkErBitqXWs/bajIiYnOfrLhvNfeM
9sxv7/m6yjucNfmMgI0RAAAAB2htQHRpbmsBAgMEBQY=
-----END OPENSSH PRIVATE KEY-----

View file

@ -0,0 +1 @@
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINqXWs/bajIiYnOfrLhvNfeM9sxv7/m6yjucNfmMgI0R hm@tink

View file

@ -0,0 +1,6 @@
---
- name: Restart sshd
ansible.builtin.service:
name: ssh
state: restarted

View file

@ -0,0 +1,52 @@
galaxy_info:
author: your name
description: your role description
company: your company (optional)
# If the issue tracker for your role is not on github, uncomment the
# next line and provide a value
# issue_tracker_url: http://example.com/issue/tracker
# Choose a valid license ID from https://spdx.org - some suggested licenses:
# - BSD-3-Clause (default)
# - MIT
# - GPL-2.0-or-later
# - GPL-3.0-only
# - Apache-2.0
# - CC-BY-4.0
license: license (GPL-2.0-or-later, MIT, etc)
min_ansible_version: 2.1
# If this a Container Enabled role, provide the minimum Ansible Container version.
# min_ansible_container_version:
#
# Provide a list of supported platforms, and for each platform a list of versions.
# If you don't wish to enumerate all versions for a particular platform, use 'all'.
# To view available platforms and versions (or releases), visit:
# https://galaxy.ansible.com/api/v1/platforms/
#
# platforms:
# - name: Fedora
# versions:
# - all
# - 25
# - name: SomePlatform
# versions:
# - all
# - 1.0
# - 7
# - 99.99
galaxy_tags: []
# List tags for your role here, one per line. A tag is a keyword that describes
# and categorizes the role. Users find roles by searching for tags. Be sure to
# remove the '[]' above, if you add tags to this list.
#
# NOTE: A tag is limited to a single word comprised of alphanumeric characters.
# Maximum 20 tags per role.
dependencies: []
# List your role dependencies here, one per line. Be sure to remove the '[]' above,
# if you add dependencies to this list.

View file

@ -0,0 +1,7 @@
---
- name: Ensure user groups exist
ansible.builtin.group:
name: "{{ item }}"
state: present
loop: "{{ users | map(attribute='groups') | flatten | unique }}"

View file

@ -0,0 +1,21 @@
---
- name: Manage sudoers
ansible.builtin.import_tasks: sudoers.yaml
tags:
- sudoers
- name: Manage groups
ansible.builtin.import_tasks: groups.yaml
tags:
- groups
- name: Manage sshd
ansible.builtin.import_tasks: sshd.yaml
tags:
- sshd
- name: Manage users
ansible.builtin.import_tasks: users.yaml
tags:
- users

View file

@ -0,0 +1,14 @@
---
- name: Restrict SSH access to ssh_login group
ansible.builtin.copy:
dest: /etc/ssh/sshd_config.d/99-allowgroups.conf
content: |
AllowGroups ssh_login
owner: root
group: root
mode: "0644"
validate: "/usr/sbin/sshd -t -f %s"
notify: Restart sshd
...

View file

@ -0,0 +1,15 @@
---
- name: Configure passwordless sudo for sudo group
ansible.builtin.copy:
dest: /etc/sudoers.d/floss-sudo
content: |
Defaults shell_noargs
%floss_sudo ALL=(ALL) NOPASSWD: ALL
%floss_admin ALL=(ALL) NOPASSWD: /usr/bin/netstat -ltp
%floss_admin ALL=(ALL) NOPASSWD: /bin/netstat -ltp
owner: root
group: root
mode: "0440"
validate: "/usr/sbin/visudo -cf %s"

View file

@ -0,0 +1,12 @@
---
- name: Configure passwordless sudo for sudo group
ansible.builtin.copy:
dest: /etc/sudoers.d/floss-sudo
content: |
%sudo ALL=(ALL:ALL) NOPASSWD: ALL
owner: root
group: root
mode: "0440"
validate: "/usr/sbin/visudo -cf %s"

View file

@ -0,0 +1,36 @@
---
- name: Manage user accounts
ansible.builtin.user:
name: "{{ item.username }}"
state: "{{ item.state | default('present') }}"
create_home: "{{ item.create_home | default(true) }}"
shell: "{{ item.shell | default('/bin/bash') }}"
groups: "{{ item.groups | default([]) | join(',') }}"
append: true
remove: "{{ item.remove_home | default(true) }}"
loop: "{{ users }}"
- name: Create .ssh directories
ansible.builtin.file:
path: "/home/{{ item.username }}/.ssh"
state: directory
owner: "{{ item.username }}"
group: "{{ item.username }}"
mode: "0700"
loop: "{{ users }}"
when: item.state | default('present') == 'present'
- name: Add SSH authorized keys
ansible.builtin.lineinfile:
path: "/home/{{ item.0.username }}/.ssh/authorized_keys"
line: "{{ item.1 }}"
create: true
owner: "{{ item.0.username }}"
group: "{{ item.0.username }}"
mode: "0600"
state: present
loop: "{{ users | subelements('ssh_keys', skip_missing=True) }}"
when: item.0.state | default('present') == 'present'

View file

@ -0,0 +1,2 @@
localhost

View file

@ -0,0 +1,5 @@
---
- hosts: localhost
remote_user: root
roles:
- users

View file

@ -0,0 +1,2 @@
---
# vars file for users

10
users/site.yaml Normal file
View file

@ -0,0 +1,10 @@
---
- name: Configure Linux users and SSH access
hosts: all
become: true
gather_facts: false
roles:
- users