The handler restarted the hardcoded service "ssh", which only exists on Debian-family distros; on RedHat, Suse, Arch etc. the unit is "sshd", so any sshd config change would fail there. Pick the name via a new users_sshd_service_name default keyed off ansible_facts['os_family'] (overridable for exotic distros). Since site.yaml runs with gather_facts: false, the role now gathers minimal facts itself when os_family is missing, tagged always so it also runs under --tags sshd. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
31 lines
675 B
YAML
31 lines
675 B
YAML
---
|
|
|
|
# The play runs with gather_facts: false, but the sshd handler needs
|
|
# ansible_facts['os_family'] to pick the right service name.
|
|
- name: Gather minimal facts if the play skipped fact gathering
|
|
ansible.builtin.setup:
|
|
gather_subset:
|
|
- "!all"
|
|
when: ansible_facts['os_family'] is not defined
|
|
tags:
|
|
- always
|
|
|
|
- name: Manage sudoers
|
|
ansible.builtin.import_tasks: sudoers.yaml
|
|
tags:
|
|
- sudoers
|
|
|
|
- name: Manage groups
|
|
ansible.builtin.import_tasks: groups.yaml
|
|
tags:
|
|
- groups
|
|
|
|
- name: Manage sshd
|
|
ansible.builtin.import_tasks: sshd.yaml
|
|
tags:
|
|
- sshd
|
|
|
|
- name: Manage users
|
|
ansible.builtin.import_tasks: users.yaml
|
|
tags:
|
|
- users
|