vn-ansible/roles/debian-once/tasks/root.yml

31 lines
835 B
YAML
Raw Normal View History

- name: Generate a random root password
set_fact:
root_password: >
{{ lookup('password', '/dev/null length=18 chars=ascii_letters,digits') }}
- name: Save root password into Passbolt
debug:
msg: >
{{
lookup(passbolt, inventory_hostname_short,
username='root',
password=root_password,
uri='ssh://'+hostname_fqdn,
folder_parent_id=pb_servers_folder
)
}}
environment:
PASSBOLT_CREATE_NEW_RESOURCE: true
when: pb_folder is defined
- name: Save the root password to file
copy:
content: "{{ root_password }}\n"
dest: /root/root_password.txt
owner: root
group: root
mode: '0600'
when: pb_folder is not defined
- name: Change root password
user:
name: root
password: "{{ root_password | password_hash('sha512') }}"