| users | ||
| README.md | ||
How to use:
Adding a new user
To create a ssh key pair on the new users PC:
ssh-keygen -f new_floss_key
The 'private' part should NEVER leave the user's PC. ( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.)
- You only need: new_floss_key.pub
- open inventory/group_vars/all/users.yaml
- add a new entry:
- username: alice
groups:
- ssh_login
- floss_sudo
- floss_admin
ssh_keys:
- ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop
- replace this ^^^^ line, with new_floss_key.pub...
Deploy with:
- ansible-playbook site.yaml
Delete user:
- open inventory/group_vars/all/users.yaml
- add:
- username: alice
__state: absent__
- run:
```yaml
ansible-playbook site.yaml
Troubleshoot:
ssh:
Check permissions in the users home. All files must be owned by the user,
sudo find ~alice -ls
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice 4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh 4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys (only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
check groups: ( look for ssh_login )
id alice
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
check that sshd is running
sudo systemctl status ssh # (or ps -ef | grep sshd )
and the config is ok:
sudo sshd -t ( no output is good )
restart with:
sudo systemctl status ssh
sudo:
check groups ( look for floss_sudo and/or floss_admin )
check the sudoers file:
visudo -cf /etc/sudoers.d/floss-sudo
/etc/sudoers.d/floss-sudo: parsed OK
Try to redeploy, if it was changed.
About the role:
Users Ansible Role
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
The role is designed to be multi-distribution and does not rely on distro-specific groups such as sudo or wheel.
Managed groups
The role uses these groups:
| Group | Purpose |
|---|---|
ssh_login |
Users in this group are allowed to log in via SSH |
floss_sudo |
Users in this group get passwordless sudo/root access |
floss_admin |
Users in this group get limited administrative commands |
Additional groups can be added as required.
License
BSD
Author Information
version 1: holger + chatgpt