Manually on each system:
  * set hostname to fqdn
  * set ansible branch if not production
  * run bootstrap.yml
  * update first password

iris.heath.hpetersenfamily.com admin-a.hpetersenfamily.com core.mary.hpetersenfamily.com


heath
  authorized_keys:
    - heath@hpetersenfamily.com
  password:
    status: VALID
    value: COMMON STRONG FOR ALL HOSTS
first
  authorized_keys:
    - first@hpetersenfamily.com
    - heath@hpetersenfamily.com
  password:
    status: VALID
    value: UNIQUE LONG FOR EACH HOST
root
  authorized_keys:
    - heath@hpetersenfamily.com
  password:
    status: LOCKED
hpf-ans:
  authorized_keys:
    - heath@hpetersenfamily.com
  password:
    status: LOCKED


# Change to work with multiple distros (nothing hardcoded)

* create production, development branches
* cron job for ansible-pull



  * Configure hosts
    # cat >>/etc/hosts <<-!!TheEnd!!   
      ::1       name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
      127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
      !!TheEnd!!


##########
########## normal tasks
##########
  
- name: Install openssh, openssh-server, openssh-sftp-server
  ansible.builtin.apt:
    pkg:
    - openssh
    - openssh-server
    - openssh-sftp-server
    
- name: Install bash, bash-completion
  ansible.builtin.apt:
    pkg:
    - bash
    - bash-completion
    
- name: Install chrony
  ansible.builtin.apt:
    pkg:
    - chrony

  * Configure chrony
    # cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
      pool 0.north-america.pool.ntp.org iburst
      !!TheEnd!!
  

~heath/.gitconfig

fail2ban
uptime kuma

==============================================================
==============================================================
==============================================================

use tags to do things like allow selecting software updates, software cleanup, etc.

