update sshd configuration

This commit is contained in:
2026-07-25 11:00:19 -05:00
parent fa41c94b49
commit 839a136393
3 changed files with 62 additions and 16 deletions
+40
View File
@@ -79,6 +79,29 @@
backup: true
validate: /usr/sbin/visudo -csf %s
## New
- name: Make sure /etc/ssh/sshd_config.d exists
become: true
ansible.builtin.file:
path: /etc/ssh/sshd_config.d
state: directory
owner: root
group: root
mode: u=rwx,go=rx
## New
- name: Get /etc/ssh/sshd_config.d/hpf.conf
become: true
ansible.builtin.copy:
src: etc/ssh/sshd_config.d/hpf.conf
dest: /etc/ssh/sshd_config.d/hpf.conf
owner: root
group: root
mode: u=rwx,go=rx
backup: yes
validate: /usr/sbin/sshd -t -f %s
notify: Restart sshd
- name: Make sure /etc/skel/.profile.d exists
become: true
ansible.builtin.file:
@@ -175,6 +198,16 @@
group: root
mode: u=rwx,go=
- name: Remove packages installed as dependencies that are no longer required and purge their configuration files
ansible.builtin.apt:
autoremove: yes
purge: true
- name: Remove old downloaded packages
ansible.builtin.apt:
clean: yes
# - name: Create ansible-pull.sh crontab entry
# become: true
# ansible.builtin.cron:
@@ -182,3 +215,10 @@
# minute: "*/27"
# job: $HOME/bin/ansible-pull.sh
# backup: true
handlers:
- name: Restart sshd
ansible.builtin.service:
name: sshd
state: restarted
+3
View File
@@ -0,0 +1,3 @@
PermitRootLogin proibit_password # Key based root login required for some software like Proxmox
PasswordAuthentication no
PermitEmptyPasswords no
+19 -16
View File
@@ -1,3 +1,22 @@
* root
* authorized_keys = heath
* hpf-ans
* system user
* /usr/bin/bash
* member of hpf-sudo-ntp
* authorized_keys = hpf-ans
* first
* normal user
* /usr/bin/bash
* member of hpf-sudo
* authorized_keys = heath, first
* heath
* normal user
* /usr/bin/bash
* member of hpf-sudo
* authorized_keys = heath
@@ -61,21 +80,6 @@
# use: systemd
- name: Copy a new sudoers file into place, after passing validation with visudo
ansible.builtin.template:
src: /mine/sudoers
dest: /etc/sudoers
validate: /usr/sbin/visudo -cf %s
- name: Update sshd configuration safely, avoid locking yourself out
ansible.builtin.template:
src: etc/ssh/sshd_config.j2
dest: /etc/ssh/sshd_config
owner: root
group: root
mode: '0600'
validate: /usr/sbin/sshd -t -f %s
backup: yes
proxmox-clients
@@ -85,7 +89,6 @@ hw:
pve-kvm:
users: first, heath, hpf-ans
~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
~heath/.ssh/authorized_keys