diff --git a/bootstrap.yml b/bootstrap.yml index eb4099b..7d247b0 100644 --- a/bootstrap.yml +++ b/bootstrap.yml @@ -15,7 +15,7 @@ - name: Install bootstrap packages become: true ansible.builtin.apt: - state: latest + state: present pkg: - bash - python3 @@ -150,6 +150,12 @@ loop: - files/ssh-keys/heath.pub + - name: Lock the root user's password + become: true + ansible.builtin.user: + name: root + password_lock: true + #### User: first @@ -198,6 +204,7 @@ append: true create_home: true shell: /usr/bin/bash + password_lock: true - name: Set hpf-ans's authorized_keys become: true @@ -248,6 +255,7 @@ append: true create_home: true shell: /usr/bin/bash + password: '$y$j9T$.NJVASBkVLnvqgznpcpdx1$7poH23pou7VHti3IfvDzwECdLtTcMercYNCeevgV.xC' - name: Set heath's authorized_keys become: true diff --git a/scraps/TODO.txt b/scraps/TODO.txt index f974263..7945d01 100644 --- a/scraps/TODO.txt +++ b/scraps/TODO.txt @@ -1,3 +1,9 @@ +Manually on each system: + * set hostname to fqdn + * set ansible branch if not production + * run bootstrap.yml + * update first password + iris.heath.hpetersenfamily.com admin-a.hpetersenfamily.com core.mary.hpetersenfamily.com heath @@ -60,12 +66,7 @@ hpf-ans: ansible.builtin.apt: pkg: - chrony - -#- name: Set host name -# ansible.builtin.hostname: -# name: ## Fully qualified domain name ## -# use: systemd - + * Configure chrony # cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <