MakerFLOSS_Mikrotik/roles/makerfloss.mikrotik_switch/tasks
sjat e6c1651da1 feat(users): model operators as accounts; add claus
Replace the single `switch_admin_user` day-2 task with a `switch_operators`
list in host_vars: one RouterOS user per person, each with the public keys
that may log in as it. Logins become attributable and revocable per person
instead of accreting as extra keys on `sjat`.

Adds claus@stjerno.dk as user `claus` (group full), and codifies the two
keys already on the device (sjat's mamba seat, the claude@ubongo automation
seat that was hand-imported earlier today).

Two things the mechanism has to get right:
- Idempotency: query /user/ssh-keys first and upload only missing keys.
  An unconditional net_put reports changed on every run.
- No passwordless accounts: WinBox/console accept an empty password and
  WinBox is deliberately left on for recovery, so each operator gets a
  vaulted password. users.yml asserts one exists before touching anything.

Verified: yamllint, ansible-lint (production), syntax-check, and the play
run twice against crs310-maker — second run changed=0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
2026-09-01 20:29:18 +02:00
..
backup.yml feat(backup): export + binary backup, fetch into repo 2026-06-08 19:36:14 +02:00
firmware.yml feat(firmware): opt-in RouterOS + RouterBOOT upgrade to pinned target 2026-06-08 19:40:24 +02:00
identity.yml feat(mgmt): DHCP server + web UI on the isolated mgmt VLAN 2026-06-09 12:55:03 +02:00
main.yml feat: role skeleton, host_vars, day-2 play (stubbed domains) 2026-06-07 08:34:13 +02:00
users.yml feat(users): model operators as accounts; add claus 2026-09-01 20:29:18 +02:00
vlans.yml feat(mgmt): DHCP server + web UI on the isolated mgmt VLAN 2026-06-09 12:55:03 +02:00