Commit graph

2 commits

Author SHA1 Message Date
4dc335321d feat(users): add lars as a switch operator
RSA key lars@hrossen.dk, taken from his VPS authorized_keys and confirmed
identical to the key on his forgejo.makerfloss.eu account, so this is the
same identity he already uses across MakerFLOSS. Group full, vaulted
password like the other operators.

NOT yet applied to the device: mamba's wired link currently lands on
10.0.0.118/24 (gateway 10.0.0.1), not the CRS310 mgmt VLAN, so 192.168.88.1
is unreachable. Lint, syntax-check and the operator list are verified; the
run-twice check is owed once the cable is back in ether8.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
2026-09-01 21:35:41 +02:00
e6c1651da1 feat(users): model operators as accounts; add claus
Replace the single `switch_admin_user` day-2 task with a `switch_operators`
list in host_vars: one RouterOS user per person, each with the public keys
that may log in as it. Logins become attributable and revocable per person
instead of accreting as extra keys on `sjat`.

Adds claus@stjerno.dk as user `claus` (group full), and codifies the two
keys already on the device (sjat's mamba seat, the claude@ubongo automation
seat that was hand-imported earlier today).

Two things the mechanism has to get right:
- Idempotency: query /user/ssh-keys first and upload only missing keys.
  An unconditional net_put reports changed on every run.
- No passwordless accounts: WinBox/console accept an empty password and
  WinBox is deliberately left on for recovery, so each operator gets a
  vaulted password. users.yml asserts one exists before touching anything.

Verified: yamllint, ansible-lint (production), syntax-check, and the play
run twice against crs310-maker — second run changed=0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
2026-09-01 20:29:18 +02:00