This commit is contained in:
2026-07-31 14:43:17 -05:00
parent 331b2ba504
commit bfe44f6b17
3 changed files with 63 additions and 34 deletions
+27 -24
View File
@@ -128,7 +128,9 @@
ansible.posix.authorized_key:
user: root
state: present
key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}"
key: "{{ lookup('file', item) }}"
loop:
- files/ssh-keys/heath.pub
#### User: first
@@ -186,7 +188,6 @@
state: present
key: "{{ lookup('file', item) }}"
loop:
- files/ssh-keys/hpf-ans.pub
- files/ssh-keys/heath.pub
- name: Make sure pip is up to date
@@ -205,27 +206,6 @@
virtualenv: $HOME/.ansible-venv
extra_args: --upgrade
- name: Make sure /home/hpf-ans/bin exists
become: true
become_user: hpf-ans
ansible.builtin.file:
path: $HOME/bin
state: directory
owner: hpf-ans
group: hpf-ans
mode: u=rwx,go=
- name: Get /home/hpf-ans/bin/ansible-pull.sh
become: true
become_user: hpf-ans
ansible.builtin.copy:
src: home/hpf-ans/bin/ansible-pull.sh
dest: $HOME/bin/ansible-pull.sh
owner: hpf-ans
group: hpf-ans
mode: u=rwx,go=
backup: true
#### User: heath
@@ -256,11 +236,34 @@
ansible.posix.authorized_key:
user: heath
state: present
key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}"
key: "{{ lookup('file', item) }}"
loop:
- files/ssh-keys/heath.pub
#### ansible-pull.sh
- name: Make sure /home/hpf-ans/bin exists
become: true
become_user: hpf-ans
ansible.builtin.file:
path: $HOME/bin
state: directory
owner: hpf-ans
group: hpf-ans
mode: u=rwx,go=
- name: Get /home/hpf-ans/bin/ansible-pull.sh
become: true
become_user: hpf-ans
ansible.builtin.copy:
src: home/hpf-ans/bin/ansible-pull.sh
dest: $HOME/bin/ansible-pull.sh
owner: hpf-ans
group: hpf-ans
mode: u=rwx,go=
backup: true
- name: Make sure log directory exists
become: true
ansible.builtin.file:
-1
View File
@@ -1 +0,0 @@
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBGKMs/y5N2ROuPabOAFUGDYb50ER/vssX9Zcsm/yPEn81EWl7NezZ1ULCchiXfEsC1qB4jm9NxocpwXmo0A5YbY= hpf-ans Heath@HPetersenFamily.com
+36 -9
View File
@@ -1,13 +1,41 @@
heath
authorized_keys:
- heath@hpetersenfamily.com
password:
status: VALID
value: COMMON STRONG FOR ALL HOSTS
private_keys:
- FOR WORKSTATIONS: heath@hpetersenfamily.com # Can this even be done securely through Ansible?
first
authorized_keys:
- first@hpetersenfamily.com
- heath@hpetersenfamily.com
password:
status: VALID
value: UNIQUE LONG FOR EACH HOST
private_keys:
root
authorized_keys:
- heath@hpetersenfamily.com
password:
status: LOCKED
private_keys:
hpf-ans:
authorized_keys:
- heath@hpetersenfamily.com
password:
status: LOCKED
private_keys:
******** CHANGE PASSWORDS ********
* Bitwarden MASTER
x Bitwarden MASTER
* Google - heathpetersen@hpetersenfamily.com
* Google - heathpetersen@kandre.com
* heath account on iris, admin-a, core
* first account ssh key
* heath account ssh key
* root account (UNIQUE) on iris, admin-a, core
* set ! as encrypted shadow password on hpf-ans on iris, admin-a, core
# Change to work with multiple distros (nothing hardcoded)
@@ -17,10 +45,9 @@
* Configure hosts
# cat >>/etc/hosts <<!!TheEnd!!
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
# cat >>/etc/hosts <<-!!TheEnd!!
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
!!TheEnd!!