Compare commits

...

2 commits

Author SHA1 Message Date
758aebee4b Merge pull request 'Make sshd restart handler multi-distro' (#4) from sjat/make_users:multi-distro-sshd-service into main
Reviewed-on: #4
Reviewed-by: holger <hmx@noreply.88.99.32.236>
2026-07-16 14:01:44 +02:00
8b02e0363f Make sshd restart handler multi-distro
The handler restarted the hardcoded service "ssh", which only exists on
Debian-family distros; on RedHat, Suse, Arch etc. the unit is "sshd",
so any sshd config change would fail there.

Pick the name via a new users_sshd_service_name default keyed off
ansible_facts['os_family'] (overridable for exotic distros). Since
site.yaml runs with gather_facts: false, the role now gathers minimal
facts itself when os_family is missing, tagged always so it also runs
under --tags sshd.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-07-16 13:47:31 +02:00
4 changed files with 18 additions and 1 deletions

View file

@ -94,6 +94,8 @@ This role manages local Linux users, groups, SSH access, SSH keys, and sudo perm
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
The SSH service name is picked automatically (`ssh` on Debian-family distros, `sshd` elsewhere); set `users_sshd_service_name` if your distro uses a different name.
## Managed groups
The role uses these groups:

View file

@ -1,2 +1,7 @@
---
# defaults file for users
# Name of the SSH service unit. Debian-family distros call it "ssh",
# most others (RedHat, Suse, Arch, ...) call it "sshd".
# Override this if your distro uses a different name.
users_sshd_service_name: "{{ 'ssh' if ansible_facts['os_family'] == 'Debian' else 'sshd' }}"

View file

@ -2,5 +2,5 @@
---
- name: Restart sshd
ansible.builtin.service:
name: ssh
name: "{{ users_sshd_service_name }}"
state: restarted

View file

@ -1,5 +1,15 @@
---
# The play runs with gather_facts: false, but the sshd handler needs
# ansible_facts['os_family'] to pick the right service name.
- name: Gather minimal facts if the play skipped fact gathering
ansible.builtin.setup:
gather_subset:
- "!all"
when: ansible_facts['os_family'] is not defined
tags:
- always
- name: Manage sudoers
ansible.builtin.import_tasks: sudoers.yaml
tags: