diff --git a/playbooks/deploy.yaml b/playbooks/deploy.yaml index cb1d8fe..16d5029 100644 --- a/playbooks/deploy.yaml +++ b/playbooks/deploy.yaml @@ -1,7 +1,7 @@ --- - name: Basic Proxmox guest deployment hosts: all - remote_user: ansible + remote_user: root roles: - ../roles/0_basic_postinstall vars_files: diff --git a/roles/0_basic_postinstall/tasks/harden_ssh.yaml b/roles/0_basic_postinstall/tasks/harden_ssh.yaml index c3f58a9..d4a2180 100644 --- a/roles/0_basic_postinstall/tasks/harden_ssh.yaml +++ b/roles/0_basic_postinstall/tasks/harden_ssh.yaml @@ -1,7 +1,6 @@ --- - name: Configure ssh-server daemon - remote_user: root copy: src: ../files/hardened_sshd.conf dest: /etc/ssh/sshd_config.d/hardened_sshd.conf @@ -10,6 +9,7 @@ - name: Configure ssh client + remote_user: ansible copy: src: ../files/hardened_ssh.conf dest: /etc/ssh/ssh_config.d/hardened_ssh.conf diff --git a/roles/0_basic_postinstall/tasks/install_basic_utils.yaml b/roles/0_basic_postinstall/tasks/install_basic_utils.yaml index b0c386f..0b4c609 100644 --- a/roles/0_basic_postinstall/tasks/install_basic_utils.yaml +++ b/roles/0_basic_postinstall/tasks/install_basic_utils.yaml @@ -14,13 +14,16 @@ - unattended-upgrades update-cache: yes # Run apt update before installation become: yes + remote_user: ansible # The same commands for Alpine - name: Update Alpine packages when: (ansible_facts['distribution'] == "Alpine") command: /sbin/apk update + remote_user: ansible - name: Install the packages on Alpine when: (ansible_facts['distribution'] == "Alpine") - command: /sbin/apk add vim ranger zsh rsync git curl kitty \ No newline at end of file + command: /sbin/apk add vim ranger zsh rsync git curl kitty + remote_user: ansible \ No newline at end of file diff --git a/roles/0_basic_postinstall/tasks/prepare_ansible_user.yaml b/roles/0_basic_postinstall/tasks/prepare_ansible_user.yaml index f89040b..b44f405 100644 --- a/roles/0_basic_postinstall/tasks/prepare_ansible_user.yaml +++ b/roles/0_basic_postinstall/tasks/prepare_ansible_user.yaml @@ -1,7 +1,6 @@ --- ## Installing packages - name: Install sudo on apt systems - remote_user: root when: (ansible_facts['distribution'] == "Debian") or (ansible_facts['distribution'] == "Ubuntu") apt: @@ -10,12 +9,10 @@ update-cache: yes - name: Update Alpine packages - remote_user: root when: (ansible_facts['distribution'] == "Alpine") command: /sbin/apk update - name: Install sudo package on Alpine - remote_user: root when: (ansible_facts['distribution'] == "Alpine") command: /sbin/apk add sudo @@ -23,14 +20,12 @@ ## Creating and setting up the ansible user ## First, create sshusers group to grant ssh access - name: Ensure group "sshusers" exists - remote_user: root ansible.builtin.group: name: sshusers state: present ## Add the user to sshusers (for ssh access) and sudo (gain root access) - name: Create a new user with a password for Ansible - remote_user: root user: name: ansible password: "{{ ansible_user_passwd_hash }}" @@ -40,7 +35,6 @@ ## Since password authentication in SSH will be disabled, we need to add an authorized key - name: Set authorized key taken from file - remote_user: root ansible.posix.authorized_key: user: ansible state: present