2023-10-28 23:00:05 +00:00
|
|
|
# vim: ft=yaml.ansible
|
2023-10-29 19:46:52 +00:00
|
|
|
# code: language=ansible
|
2023-10-28 23:00:05 +00:00
|
|
|
---
|
2023-11-15 19:30:53 +00:00
|
|
|
- name: Set hostname
|
|
|
|
ansible.builtin.hostname:
|
|
|
|
name: "{{ hostname }}"
|
|
|
|
|
|
|
|
- name: Set timezone
|
|
|
|
community.general.timezone:
|
|
|
|
name: "{{ timezone }}"
|
|
|
|
|
2023-10-28 23:00:05 +00:00
|
|
|
- name: Add users
|
|
|
|
ansible.builtin.user:
|
|
|
|
name: "{{ item.name }}"
|
|
|
|
comment: "{{ item.comment }}"
|
|
|
|
groups: "{{ item.groups }}"
|
|
|
|
shell: /bin/bash
|
2023-11-05 18:08:26 +00:00
|
|
|
state: present
|
2023-10-28 23:00:05 +00:00
|
|
|
loop: "{{ users }}"
|
|
|
|
|
2023-11-11 15:35:14 +00:00
|
|
|
- name: Add SSH keys to users
|
2023-10-28 23:00:05 +00:00
|
|
|
ansible.posix.authorized_key:
|
|
|
|
user: "{{ item.name }}"
|
|
|
|
key: "{{ item.ssh_keys | join('\n') }}"
|
|
|
|
exclusive: true
|
|
|
|
loop: "{{ users }}"
|
2023-11-11 15:35:14 +00:00
|
|
|
|
2023-11-11 15:41:47 +00:00
|
|
|
- name: Allow passwordless sudo
|
|
|
|
community.general.sudoers:
|
|
|
|
name: passwordless
|
|
|
|
group: sudo
|
|
|
|
host: ALL
|
|
|
|
commands: ALL
|
|
|
|
nopassword: true
|
2023-11-11 15:35:14 +00:00
|
|
|
state: present
|
2023-11-15 19:30:53 +00:00
|
|
|
|
|
|
|
- name: Copy sshd_config
|
|
|
|
ansible.builtin.copy:
|
|
|
|
src: sshd_config
|
|
|
|
dest: /etc/ssh/sshd_config
|
|
|
|
owner: root
|
|
|
|
mode: u=rw,g=r,o=r
|
|
|
|
validate: /usr/sbin/sshd -t -f %s
|
|
|
|
notify: Restart sshd
|