Replace the single `switch_admin_user` day-2 task with a `switch_operators` list in host_vars: one RouterOS user per person, each with the public keys that may log in as it. Logins become attributable and revocable per person instead of accreting as extra keys on `sjat`. Adds claus@stjerno.dk as user `claus` (group full), and codifies the two keys already on the device (sjat's mamba seat, the claude@ubongo automation seat that was hand-imported earlier today). Two things the mechanism has to get right: - Idempotency: query /user/ssh-keys first and upload only missing keys. An unconditional net_put reports changed on every run. - No passwordless accounts: WinBox/console accept an empty password and WinBox is deliberately left on for recovery, so each operator gets a vaulted password. users.yml asserts one exists before touching anything. Verified: yamllint, ansible-lint (production), syntax-check, and the play run twice against crs310-maker — second run changed=0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
11 lines
426 B
YAML
11 lines
426 B
YAML
---
|
|
- name: Configure MikroTik switches (day-2, key auth)
|
|
hosts: mikrotik
|
|
gather_facts: false
|
|
# Operator passwords (users.yml) are vaulted; group_vars/mikrotik.vault.yml does not
|
|
# match the group-name convention, so load it explicitly. Decrypted via the makerfloss
|
|
# vault id in ansible.cfg — no --ask-vault-pass needed.
|
|
vars_files:
|
|
- group_vars/mikrotik.vault.yml
|
|
roles:
|
|
- makerfloss.mikrotik_switch
|