2023-09-30 14:25:06 +00:00
|
|
|
# vim: ft=yaml.ansible
|
2024-03-01 20:30:18 +00:00
|
|
|
# code: language=ansible
|
2023-09-30 14:25:06 +00:00
|
|
|
---
|
|
|
|
- name: Create SSH directory
|
|
|
|
file:
|
|
|
|
path: "{{ services.restic.volume_folder }}/ssh"
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: '0755'
|
|
|
|
state: directory
|
|
|
|
|
2023-10-03 19:19:51 +00:00
|
|
|
- name: Upload private SSH key
|
2023-09-30 14:25:06 +00:00
|
|
|
copy:
|
|
|
|
dest: "{{ services.restic.volume_folder }}/ssh/id_ed25519"
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: '0600'
|
|
|
|
content: "{{ restic_secrets.ssh_privkey }}"
|
|
|
|
|
|
|
|
- name: Derive public SSH key
|
|
|
|
shell: >-
|
|
|
|
ssh-keygen -f {{ services.restic.volume_folder }}/ssh/id_ed25519 -y
|
|
|
|
> {{ services.restic.volume_folder }}/ssh/id_ed25519.pub
|
|
|
|
args:
|
|
|
|
creates: "{{ services.restic.volume_folder }}/ssh/id_ed25519.pub"
|
|
|
|
|
|
|
|
- name: Set file permissions on public SSH key
|
|
|
|
file:
|
|
|
|
path: "{{ services.restic.volume_folder }}/ssh/id_ed25519.pub"
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: '0644'
|
|
|
|
state: touch
|
|
|
|
|
2023-10-03 19:19:51 +00:00
|
|
|
- name: Upload SSH config
|
2023-09-30 14:25:06 +00:00
|
|
|
template:
|
|
|
|
src: restic/ssh.config.j2
|
|
|
|
dest: "{{ services.restic.volume_folder }}/ssh/config"
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: '0600'
|
|
|
|
|
2023-10-03 19:19:51 +00:00
|
|
|
- name: Upload SSH known_hosts file
|
2023-09-30 14:25:06 +00:00
|
|
|
template:
|
|
|
|
src: restic/ssh.known_hosts.j2
|
|
|
|
dest: "{{ services.restic.volume_folder }}/ssh/known_hosts"
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: '0600'
|
2024-03-03 20:17:48 +00:00
|
|
|
|
|
|
|
- name: Create scripts directory
|
|
|
|
file:
|
|
|
|
path: "{{ services.restic.volume_folder }}/scripts"
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: '0755'
|
|
|
|
state: directory
|
|
|
|
|
|
|
|
- name: Upload failure.sh script
|
|
|
|
template:
|
|
|
|
src: restic/failure.sh.j2
|
|
|
|
dest: "{{ services.restic.volume_folder }}/scripts/failure.sh"
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: '0755'
|
2024-03-05 08:55:04 +00:00
|
|
|
|
2024-03-05 08:57:55 +00:00
|
|
|
- name: Upload success.sh script
|
2024-03-05 08:55:04 +00:00
|
|
|
template:
|
|
|
|
src: restic/success.sh.j2
|
|
|
|
dest: "{{ services.restic.volume_folder }}/scripts/success.sh"
|
|
|
|
owner: root
|
|
|
|
group: root
|
|
|
|
mode: '0755'
|