| .. | ||
| defaults | ||
| handlers | ||
| meta | ||
| tasks | ||
| tests | ||
| vars | ||
| floss | ||
| floss.pub | ||
| README.md | ||
How to use:
Adding a new user
To create a ssh key pair on the new users PC. ssh-keygen -f new_floss_key The 'private' part should NEVER leave the user's PC. ( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.)
you only need: new_floss_key.pub
open inventory/group_vars/all/users.yaml add a new entry:
- username: alice
groups:
- ssh_login
- floss_sudo
- floss_admin ssh_keys:
- ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop
- replace this ^^^^ line, with new_floss_key.pub...
deploy with: ansible-playbook site.yaml
delete user:
open inventory/group_vars/all/users.yaml add:
- username: alice state: absent and rerun: ansible-playbook site.yaml
Troubleshoot:
ssh:
Check permissions in the users home. All files must be owned by the user,
sudo find ~alice -ls
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice 4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh 4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys (only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
check groups: ( look for ssh_login )
id alice
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
check that sshd is running
sudo systemctl status ssh # (or ps -ef | grep sshd )
and the config is ok:
sudo sshd -t ( no output is good )
restart with:
sudo systemctl status ssh
sudo:
check groups ( look for floss_sudo and/or floss_admin )
check the sudoers file:
visudo -cf /etc/sudoers.d/floss-sudo
/etc/sudoers.d/floss-sudo: parsed OK
Try to redeploy, if it was changed.
About the role:
Users Ansible Role
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
The role is designed to be multi-distribution and does not rely on distro-specific groups such as sudo or wheel.
Managed groups
The role uses these groups:
| Group | Purpose |
|---|---|
ssh_login |
Users in this group are allowed to log in via SSH |
floss_sudo |
Users in this group get passwordless sudo/root access |
floss_admin |
Users in this group get limited administrative commands |
Additional groups can be added as required.
License
BSD
Author Information
version 1: holger + chatgpt