make_users/README.md
2026-07-16 12:57:19 +02:00

2.7 KiB

How to use:

Adding a new user

To create a ssh key pair on the new users PC:

ssh-keygen -f new_floss_key

The 'private' part should NEVER leave the user's PC. ( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.)

  • You only need: new_floss_key.pub
  • open inventory/group_vars/all/users.yaml
  • add a new entry:
  - username: alice
    groups:
      - ssh_login
      - floss_sudo
      - floss_admin
    ssh_keys:
      - ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop
          - replace this ^^^^ line, with new_floss_key.pub...

Deploy with:

- ansible-playbook site.yaml

Delete user:

  • open inventory/group_vars/all/users.yaml
  • add:
  - username: alice
    __state: absent__
- run:
```yaml
 ansible-playbook site.yaml

Troubleshoot:

ssh:

Check permissions in the users home. All files must be owned by the user,

sudo find ~alice -ls
   4 drwxr-x---   6 alice    alice        4096 Jul 15 16:59 /home/alice
   4 drwx------   2 alice    alice        4096 Jul 15 16:58 /home/alice/.ssh
   4 -rw-------   1 alice    alice         709 Jul 15 16:58 /home/alice/.ssh/authorized_keys

(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...

check groups: ( look for ssh_login )

id alice
   uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)

check that sshd is running

sudo systemctl status ssh # (or ps -ef | grep sshd )

and the config is ok: 
sudo sshd -t # ( no output is good )

restart with:
sudo systemctl status ssh

sudo:

check groups ( look for floss_sudo and/or floss_admin )

id alice
   uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)

check the sudoers file:

visudo -cf /etc/sudoers.d/floss-sudo 

/etc/sudoers.d/floss-sudo: parsed OK

Try to redeploy, if it was changed.

About the role:

Users Ansible Role

This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.

The role is designed to be multi-distribution and does not rely on distro-specific groups such as sudo or wheel.

Managed groups

The role uses these groups:

Group Purpose
ssh_login Users in this group are allowed to log in via SSH
floss_sudo Users in this group get passwordless sudo/root access
floss_admin Users in this group get limited administrative commands

Additional groups can be added as required.

##License

BSD

##Author Information

version 1: holger + chatgpt