1
0
Fork 0
forked from hmx/make_users
make_users/README.md
2026-07-15 18:01:01 +02:00

93 lines
2.4 KiB
Markdown

# How to use:
## Adding a new user
To create a ssh key pair on the new users PC.
ssh-keygen -f new_floss_key
The 'private' part should NEVER leave the user's PC.
( It is a good idea to add a keyphrase to protect the key, if the client PC is ever stolen or hacked.)
you only need: new_floss_key.pub
open inventory/group_vars/all/users.yaml
add a new entry:
- username: alice
groups:
- ssh_login
- floss_sudo
- floss_admin
ssh_keys:
- ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAA... alice@laptop
- replace this ^^^^ line, with new_floss_key.pub...
deploy with:
ansible-playbook site.yaml
## delete user:
open inventory/group_vars/all/users.yaml
add:
- username: alice
__state: absent__
and rerun:
ansible-playbook site.yaml
# Troubleshoot:
## ssh:
Check permissions in the users home. All files must be owned by the user,
# sudo find ~alice -ls
4 drwxr-x--- 6 alice alice 4096 Jul 15 16:59 /home/alice
4 drwx------ 2 alice alice 4096 Jul 15 16:58 /home/alice/.ssh
4 -rw------- 1 alice alice 709 Jul 15 16:58 /home/alice/.ssh/authorized_keys
(only showing the important files ) Note, ssh may fail, if permission are too open, DONT do chmod 777 ...
check groups: ( look for ssh_login )
# id alice
uid=1005(alice) gid=1007(alice) groups=1007(alice),27(sudo),1005(ssh_login),1006(admin),1010(floss_sudo),1011(floss_admin)
check that sshd is running
# sudo systemctl status ssh # (or ps -ef | grep sshd )
and the config is ok:
# sudo sshd -t ( no output is good )
restart with:
# sudo systemctl status ssh
## sudo:
check groups ( look for floss_sudo and/or floss_admin )
check the sudoers file:
# visudo -cf /etc/sudoers.d/floss-sudo
/etc/sudoers.d/floss-sudo: parsed OK
Try to redeploy, if it was changed.
# About the role:
# Users Ansible Role
This role manages local Linux users, groups, SSH access, SSH keys, and sudo permissions.
The role is designed to be multi-distribution and does not rely on distro-specific groups such as `sudo` or `wheel`.
## Managed groups
The role uses these groups:
| Group | Purpose |
|---|---|
| `ssh_login` | Users in this group are allowed to log in via SSH |
| `floss_sudo` | Users in this group get passwordless sudo/root access |
| `floss_admin` | Users in this group get limited administrative commands |
Additional groups can be added as required.
License
-------
BSD
Author Information
------------------
version 1: holger + chatgpt