Replace the single `switch_admin_user` day-2 task with a `switch_operators` list in host_vars: one RouterOS user per person, each with the public keys that may log in as it. Logins become attributable and revocable per person instead of accreting as extra keys on `sjat`. Adds claus@stjerno.dk as user `claus` (group full), and codifies the two keys already on the device (sjat's mamba seat, the claude@ubongo automation seat that was hand-imported earlier today). Two things the mechanism has to get right: - Idempotency: query /user/ssh-keys first and upload only missing keys. An unconditional net_put reports changed on every run. - No passwordless accounts: WinBox/console accept an empty password and WinBox is deliberately left on for recovery, so each operator gets a vaulted password. users.yml asserts one exists before touching anything. Verified: yamllint, ansible-lint (production), syntax-check, and the play run twice against crs310-maker — second run changed=0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EyYJWABgSEHzbjsZGrkxVE
50 lines
1.8 KiB
YAML
50 lines
1.8 KiB
YAML
---
|
|
# ----- Identity / management -----
|
|
switch_identity_name: "{{ inventory_hostname }}"
|
|
switch_mgmt_vlan_id: 99
|
|
switch_mgmt_address: "192.168.88.1/24" # PLACEHOLDER — override in host_vars
|
|
switch_mgmt_gateway: "192.168.88.254" # PLACEHOLDER — override in host_vars
|
|
switch_dns_servers: "192.168.88.254"
|
|
switch_ntp_enabled: true # set false for an isolated mgmt plane
|
|
switch_ntp_servers: "192.168.88.254"
|
|
|
|
# Services to disable for hardening (winbox kept on by default for recovery)
|
|
switch_disabled_services:
|
|
- telnet
|
|
- ftp
|
|
- www
|
|
- www-ssl
|
|
- api
|
|
- api-ssl
|
|
switch_ssh_port: 22
|
|
switch_web_enabled: false # enable the WWW (HTTP) admin UI
|
|
|
|
# Optional DHCP server on the management VLAN (convenience; login still required).
|
|
switch_mgmt_dhcp_enabled: false
|
|
switch_mgmt_dhcp_pool: "" # e.g. "192.168.88.10-192.168.88.254"
|
|
switch_mgmt_dhcp_network: "" # e.g. "192.168.88.0/24"
|
|
|
|
# ----- Users -----
|
|
# Bootstrap only (play_bootstrap.yml, first contact over password auth).
|
|
switch_admin_user: "sjat"
|
|
switch_admin_group: "full"
|
|
switch_admin_ssh_pubkey_file: "~/.ssh/id_ed25519.pub"
|
|
switch_disable_default_admin: true
|
|
|
|
# Day-2 operator accounts. Real list lives in host_vars; each name needs a matching
|
|
# vault_operator_passwords entry. `pubkey_files` are repo-relative paths.
|
|
switch_operators: []
|
|
|
|
# ----- VLAN / bridge / ports (PLACEHOLDER example) -----
|
|
# Real topology is defined in host_vars/<switch>.yml.
|
|
switch_bridge_name: "bridge"
|
|
switch_vlans:
|
|
- {id: 99, name: "mgmt"}
|
|
- {id: 10, name: "members"}
|
|
switch_bridge_ports:
|
|
# ether1..ether8 = 2.5GbE access ports; sfp-sfpplus1/2 = 10G uplinks
|
|
- {interface: "ether1", pvid: 10, mode: access}
|
|
- {interface: "sfp-sfpplus1", pvid: 1, mode: trunk, tagged_vlans: [99, 10]}
|
|
|
|
# ----- Firmware -----
|
|
switch_firmware_target: "" # set in host_vars when opting into upgrades
|