1
0
Fork 0
forked from hmx/make_users
make_users/README.md
2026-07-15 18:33:53 +02:00

2.5 KiB

How to use:

Adding a new user

To create a ssh key pair on the new users PC:

ssh-keygen -f new_floss_key

The 'private' part should NEVER leave the user's PC.
 ( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.)

You only need: new_floss_key.pub

- open inventory/group_vars/all/users.yaml
- add a new entry:
```yaml
  - username: alice
    groups:
      - ssh_login
      - floss_sudo
      - floss_admin
    ssh_keys:
      - ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop
          - replace this ^^^^ line, with new_floss_key.pub...

### Deploy with:
- ansible-playbook site.yaml

## Delete user:
- open inventory/group_vars/all/users.yaml
- add:
```yaml
  - username: alice
    __state: absent__
- run:
```yaml
 ansible-playbook site.yaml


# Troubleshoot:

## ssh:
Check permissions in the users home. All files must be owned by the user, 
 # sudo find ~alice -ls
   4 drwxr-x---   6 alice    alice        4096 Jul 15 16:59 /home/alice
   4 drwx------   2 alice    alice        4096 Jul 15 16:58 /home/alice/.ssh
   4 -rw-------   1 alice    alice         709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...

check groups: ( look for ssh_login )
 # id alice
   uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)

check that sshd is running
 # sudo systemctl status ssh # (or ps -ef | grep sshd )
and the config is ok: 
 # sudo sshd -t ( no output is good )
restart with:
 # sudo systemctl status ssh

## sudo:
check groups ( look for floss_sudo and/or floss_admin )

check the sudoers file:
 # visudo -cf /etc/sudoers.d/floss-sudo 
  /etc/sudoers.d/floss-sudo: parsed OK

Try to redeploy, if it was changed.


# About the role:
# Users Ansible Role

This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.

The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.

## Managed groups

The role uses these groups:

| Group | Purpose |
|---|---|
| `ssh_login` | Users in this group are allowed to log in via SSH |
| `floss_sudo` | Users in this group get passwordless sudo/root access |
| `floss_admin` | Users in this group get limited administrative commands |

Additional groups can be added as required.


License
-------

BSD

Author Information
------------------
version 1: holger + chatgpt