FIX: default user is root, ansible is specified manually
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
---
|
||||
- name: Basic Proxmox guest deployment
|
||||
hosts: all
|
||||
remote_user: ansible
|
||||
remote_user: root
|
||||
roles:
|
||||
- ../roles/0_basic_postinstall
|
||||
vars_files:
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
---
|
||||
|
||||
- name: Configure ssh-server daemon
|
||||
remote_user: root
|
||||
copy:
|
||||
src: ../files/hardened_sshd.conf
|
||||
dest: /etc/ssh/sshd_config.d/hardened_sshd.conf
|
||||
@@ -10,6 +9,7 @@
|
||||
|
||||
|
||||
- name: Configure ssh client
|
||||
remote_user: ansible
|
||||
copy:
|
||||
src: ../files/hardened_ssh.conf
|
||||
dest: /etc/ssh/ssh_config.d/hardened_ssh.conf
|
||||
|
||||
@@ -14,13 +14,16 @@
|
||||
- unattended-upgrades
|
||||
update-cache: yes # Run apt update before installation
|
||||
become: yes
|
||||
remote_user: ansible
|
||||
|
||||
|
||||
# The same commands for Alpine
|
||||
- name: Update Alpine packages
|
||||
when: (ansible_facts['distribution'] == "Alpine")
|
||||
command: /sbin/apk update
|
||||
remote_user: ansible
|
||||
|
||||
- name: Install the packages on Alpine
|
||||
when: (ansible_facts['distribution'] == "Alpine")
|
||||
command: /sbin/apk add vim ranger zsh rsync git curl kitty
|
||||
remote_user: ansible
|
||||
@@ -1,7 +1,6 @@
|
||||
---
|
||||
## Installing packages
|
||||
- name: Install sudo on apt systems
|
||||
remote_user: root
|
||||
when: (ansible_facts['distribution'] == "Debian") or
|
||||
(ansible_facts['distribution'] == "Ubuntu")
|
||||
apt:
|
||||
@@ -10,12 +9,10 @@
|
||||
update-cache: yes
|
||||
|
||||
- name: Update Alpine packages
|
||||
remote_user: root
|
||||
when: (ansible_facts['distribution'] == "Alpine")
|
||||
command: /sbin/apk update
|
||||
|
||||
- name: Install sudo package on Alpine
|
||||
remote_user: root
|
||||
when: (ansible_facts['distribution'] == "Alpine")
|
||||
command: /sbin/apk add sudo
|
||||
|
||||
@@ -23,14 +20,12 @@
|
||||
## Creating and setting up the ansible user
|
||||
## First, create sshusers group to grant ssh access
|
||||
- name: Ensure group "sshusers" exists
|
||||
remote_user: root
|
||||
ansible.builtin.group:
|
||||
name: sshusers
|
||||
state: present
|
||||
|
||||
## Add the user to sshusers (for ssh access) and sudo (gain root access)
|
||||
- name: Create a new user with a password for Ansible
|
||||
remote_user: root
|
||||
user:
|
||||
name: ansible
|
||||
password: "{{ ansible_user_passwd_hash }}"
|
||||
@@ -40,7 +35,6 @@
|
||||
|
||||
## Since password authentication in SSH will be disabled, we need to add an authorized key
|
||||
- name: Set authorized key taken from file
|
||||
remote_user: root
|
||||
ansible.posix.authorized_key:
|
||||
user: ansible
|
||||
state: present
|
||||
|
||||
Reference in New Issue
Block a user