From 8b02e0363fa76634ec874c63423841b9011dd755 Mon Sep 17 00:00:00 2001 From: sjat Date: Thu, 16 Jul 2026 13:47:31 +0200 Subject: [PATCH] Make sshd restart handler multi-distro The handler restarted the hardcoded service "ssh", which only exists on Debian-family distros; on RedHat, Suse, Arch etc. the unit is "sshd", so any sshd config change would fail there. Pick the name via a new users_sshd_service_name default keyed off ansible_facts['os_family'] (overridable for exotic distros). Since site.yaml runs with gather_facts: false, the role now gathers minimal facts itself when os_family is missing, tagged always so it also runs under --tags sshd. Co-Authored-By: Claude Fable 5 --- README.md | 2 ++ users/roles/users/defaults/main.yaml | 5 +++++ users/roles/users/handlers/main.yaml | 2 +- users/roles/users/tasks/main.yaml | 10 ++++++++++ 4 files changed, 18 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index f25ce30..5526591 100644 --- a/README.md +++ b/README.md @@ -94,6 +94,8 @@ This role manages local Linux users, groups, SSH access, SSH keys, and sudo perm The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`. +The SSH service name is picked automatically (`ssh` on Debian-family distros, `sshd` elsewhere); set `users_sshd_service_name` if your distro uses a different name. + ## Managed groups The role uses these groups: diff --git a/users/roles/users/defaults/main.yaml b/users/roles/users/defaults/main.yaml index 4d24c02..5eeaccd 100644 --- a/users/roles/users/defaults/main.yaml +++ b/users/roles/users/defaults/main.yaml @@ -1,2 +1,7 @@ --- # defaults file for users + +# Name of the SSH service unit. Debian-family distros call it "ssh", +# most others (RedHat, Suse, Arch, ...) call it "sshd". +# Override this if your distro uses a different name. +users_sshd_service_name: "{{ 'ssh' if ansible_facts['os_family'] == 'Debian' else 'sshd' }}" diff --git a/users/roles/users/handlers/main.yaml b/users/roles/users/handlers/main.yaml index b689f6f..b0f617a 100644 --- a/users/roles/users/handlers/main.yaml +++ b/users/roles/users/handlers/main.yaml @@ -2,5 +2,5 @@ --- - name: Restart sshd ansible.builtin.service: - name: ssh + name: "{{ users_sshd_service_name }}" state: restarted diff --git a/users/roles/users/tasks/main.yaml b/users/roles/users/tasks/main.yaml index 62ce863..0f45668 100644 --- a/users/roles/users/tasks/main.yaml +++ b/users/roles/users/tasks/main.yaml @@ -1,5 +1,15 @@ --- +# The play runs with gather_facts: false, but the sshd handler needs +# ansible_facts['os_family'] to pick the right service name. +- name: Gather minimal facts if the play skipped fact gathering + ansible.builtin.setup: + gather_subset: + - "!all" + when: ansible_facts['os_family'] is not defined + tags: + - always + - name: Manage sudoers ansible.builtin.import_tasks: sudoers.yaml tags: