Replace the single `switch_admin_user` day-2 task with a `switch_operators` list in host_vars: one RouterOS user per person, each with the public keys that may log in as it. Logins become attributable and revocable per person instead of accreting as extra keys on `sjat`. Adds claus@stjerno.dk as user `claus` (group full), and codifies the two keys already on the device (sjat's mamba seat, the claude@ubongo automation seat that was hand-imported earlier today). Two things the mechanism has to get right: - Idempotency: query /user/ssh-keys first and upload only missing keys. An unconditional net_put reports changed on every run. - No passwordless accounts: WinBox/console accept an empty password and WinBox is deliberately left on for recovery, so each operator gets a vaulted password. users.yml asserts one exists before touching anything. Verified: yamllint, ansible-lint (production), syntax-check, and the play run twice against crs310-maker — second run changed=0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
1 line
98 B
Text
1 line
98 B
Text
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAID0J3ugdd8GF8bGULk6O+tNKinNsil0ks7cLaStVUQR4 claus@stjerno.dk
|