feat (roles): copies a config with hosts rules in human admin ~/.ssh
This commit is contained in:
@@ -0,0 +1,15 @@
|
|||||||
|
# PUT NEW BLOCKS STRICTLY BEFORE ANY MATCH BLOCK
|
||||||
|
|
||||||
|
|
||||||
|
# Private keys are NOT distributed via Ansible
|
||||||
|
# They must to be copied manually ONLY to those hosts that need access to others
|
||||||
|
|
||||||
|
# Most of the home major LAN hosts should be accessible with this key
|
||||||
|
Match 192.168.0.0/24
|
||||||
|
User max
|
||||||
|
IdentityFile ~/.ssh/max_regular_key
|
||||||
|
|
||||||
|
# This virtual network has the same hosts range
|
||||||
|
Match 10.9.2.0/24
|
||||||
|
User max
|
||||||
|
IdentityFile ~/.ssh/max_regular_key
|
||||||
@@ -48,6 +48,15 @@
|
|||||||
group: "{{ human_admin_user }}"
|
group: "{{ human_admin_user }}"
|
||||||
mode: u=rw,g=r,o-rwx
|
mode: u=rw,g=r,o-rwx
|
||||||
|
|
||||||
|
- name: Configure ssh client, by pushing the config
|
||||||
|
remote_user: ansible
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: "{{ role_path }}/files/ssh_config"
|
||||||
|
dest: "/home/{{ human_admin_user }}/.ssh/config"
|
||||||
|
owner: "{{ human_admin_user }}"
|
||||||
|
group: "{{ human_admin_user }}"
|
||||||
|
mode: u=rw,g=r,o-rwx
|
||||||
|
|
||||||
|
|
||||||
# WARNING: we've finished with the initial setup, drop ansible key
|
# WARNING: we've finished with the initial setup, drop ansible key
|
||||||
# Push regular user key
|
# Push regular user key
|
||||||
|
|||||||
Reference in New Issue
Block a user