update playbooks tasks

This commit is contained in:
Ruben Blanco 2023-10-18 09:09:20 +02:00
parent c47a74749b
commit 8c36bebe62
2 changed files with 19 additions and 4 deletions

View File

@ -1,5 +1,6 @@
--- ---
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# create user awx-user on debian os # create user awx-user on debian os
- name: Create a ssh user awx-user in the system - name: Create a ssh user awx-user in the system
user: user:
@ -9,31 +10,37 @@
groups: sudo groups: sudo
state: present state: present
comment: ssh user comment: ssh user
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# add ssh-key pub to user awx-user # add ssh-key pub to user awx-user
- name: Adding ssh-pub-key to user awx-user - name: Adding ssh-pub-key to user awx-user
authorized_key: authorized_key:
user: awx-user user: awx-user
key: "{{ key_to_add }}" key: "{{ key_to_add }}"
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# install sudo package # install sudo package
- name: Install sudo package - name: Install sudo package
apt: apt:
name: sudo name: sudo
state: present state: present
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# add awx-user to sudoers # add awx-user to sudoers
- name: Add awx-user to sudoers - name: Add awx-user to sudoers
file: file:
path: /etc/sudoers.d/awx-user path: /etc/sudoers.d/awx-user
state: touch state: touch
mode: u=rw,g=r,o=r mode: u=rw,g=r,o=r
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# add a line to /etc/sudoers.d/awx-user file # add a line to /etc/sudoers.d/awx-user file
- name: add a line to /etc/sudoers.d/awx-user file - name: add a line to /etc/sudoers.d/awx-user file
lineinfile: lineinfile:
path: /etc/sudoers.d/awx-user path: /etc/sudoers.d/awx-user
line: awx-user ALL=(ALL) NOPASSWD:ALL line: awx-user ALL=(ALL) NOPASSWD:ALL
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

View File

@ -1,5 +1,6 @@
--- ---
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# delete default user , only on VM # delete default user , only on VM
- name: delete default user , only on VM - name: delete default user , only on VM
user: user:
@ -8,13 +9,17 @@
remove: yes remove: yes
tags: tags:
- delete-user - delete-user
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# change root password # change root password
- name: change root password - name: change root password
user: user:
name: root name: root
password: "{{ ssh_password | password_hash('sha512') }}" password: "{{ ssh_password | password_hash('sha512') }}"
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# config sshd_config file , no root password # config sshd_config file , no root password
- name: change sshd_config to no root password - name: change sshd_config to no root password
copy: copy:
@ -24,10 +29,13 @@
owner: root owner: root
group: root group: root
mode: '0644' mode: '0644'
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# delete file sshd_config.orig # delete file sshd_config.orig
- name: delete /etc/ssh/sshd_config.orig file - name: delete /etc/ssh/sshd_config.orig file
file: file:
path: /etc/ssh/sshd_config.orig path: /etc/ssh/sshd_config.orig
state: absent state: absent
notify: Restart ssh service notify: Restart ssh service
#++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++