update sshd configuration

This commit is contained in:
2026-07-25 11:00:19 -05:00
parent fa41c94b49
commit 839a136393
3 changed files with 62 additions and 16 deletions
+40
View File
@@ -79,6 +79,29 @@
backup: true
validate: /usr/sbin/visudo -csf %s
## New
- name: Make sure /etc/ssh/sshd_config.d exists
become: true
ansible.builtin.file:
path: /etc/ssh/sshd_config.d
state: directory
owner: root
group: root
mode: u=rwx,go=rx
## New
- name: Get /etc/ssh/sshd_config.d/hpf.conf
become: true
ansible.builtin.copy:
src: etc/ssh/sshd_config.d/hpf.conf
dest: /etc/ssh/sshd_config.d/hpf.conf
owner: root
group: root
mode: u=rwx,go=rx
backup: yes
validate: /usr/sbin/sshd -t -f %s
notify: Restart sshd
- name: Make sure /etc/skel/.profile.d exists
become: true
ansible.builtin.file:
@@ -175,6 +198,16 @@
group: root
mode: u=rwx,go=
- name: Remove packages installed as dependencies that are no longer required and purge their configuration files
ansible.builtin.apt:
autoremove: yes
purge: true
- name: Remove old downloaded packages
ansible.builtin.apt:
clean: yes
# - name: Create ansible-pull.sh crontab entry
# become: true
# ansible.builtin.cron:
@@ -182,3 +215,10 @@
# minute: "*/27"
# job: $HOME/bin/ansible-pull.sh
# backup: true
handlers:
- name: Restart sshd
ansible.builtin.service:
name: sshd
state: restarted