# How to use: ## Adding a new user To create a ssh key pair on the new users PC. ssh-keygen -f new_floss_key The 'private' part should NEVER leave the user's PC. ( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.) you only need: new_floss_key.pub open inventory/group_vars/all/users.yaml add a new entry: - username: alice groups: - ssh_login - floss_sudo - floss_admin ssh_keys: - ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop - replace this ^^^^ line, with new_floss_key.pub... deploy with: ansible-playbook site.yaml ## delete user: open inventory/group_vars/all/users.yaml add: - username: alice __state: absent__ and rerun: ansible-playbook site.yaml # Troubleshoot: ## ssh: Check permissions in the users home. All files must be owned by the user, # sudo find ~alice -ls 4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice 4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh 4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys (only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ... check groups: ( look for ssh_login ) # id alice uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin) check that sshd is running # sudo systemctl status ssh # (or ps -ef | grep sshd ) and the config is ok: # sudo sshd -t ( no output is good ) restart with: # sudo systemctl status ssh ## sudo: check groups ( look for floss_sudo and/or floss_admin ) check the sudoers file: # visudo -cf /etc/sudoers.d/floss-sudo /etc/sudoers.d/floss-sudo: parsed OK Try to redeploy, if it was changed. # About the role: # Users Ansible Role This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions. The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`. ## Managed groups The role uses these groups: | Group | Purpose | |---|---| | `ssh_login` | Users in this group are allowed to log in via SSH | | `floss_sudo` | Users in this group get passwordless sudo/root access | | `floss_admin` | Users in this group get limited administrative commands | Additional groups can be added as required. License ------- BSD Author Information ------------------ version 1: holger + chatgpt