From bfe44f6b1759e352d13e9b648a3090be82a13962ecd7a430f68902d3068621de Mon Sep 17 00:00:00 2001 From: Heath Petersen Date: Fri, 31 Jul 2026 14:43:17 -0500 Subject: [PATCH] x --- bootstrap.yml | 51 ++++++++++++++++++++------------------ files/ssh-keys/hpf-ans.pub | 1 - scraps/TODO.txt | 45 ++++++++++++++++++++++++++------- 3 files changed, 63 insertions(+), 34 deletions(-) delete mode 100644 files/ssh-keys/hpf-ans.pub diff --git a/bootstrap.yml b/bootstrap.yml index ddfb019..4dd0517 100644 --- a/bootstrap.yml +++ b/bootstrap.yml @@ -128,7 +128,9 @@ ansible.posix.authorized_key: user: root state: present - key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}" + key: "{{ lookup('file', item) }}" + loop: + - files/ssh-keys/heath.pub #### User: first @@ -186,7 +188,6 @@ state: present key: "{{ lookup('file', item) }}" loop: - - files/ssh-keys/hpf-ans.pub - files/ssh-keys/heath.pub - name: Make sure pip is up to date @@ -205,27 +206,6 @@ virtualenv: $HOME/.ansible-venv extra_args: --upgrade - - name: Make sure /home/hpf-ans/bin exists - become: true - become_user: hpf-ans - ansible.builtin.file: - path: $HOME/bin - state: directory - owner: hpf-ans - group: hpf-ans - mode: u=rwx,go= - - - name: Get /home/hpf-ans/bin/ansible-pull.sh - become: true - become_user: hpf-ans - ansible.builtin.copy: - src: home/hpf-ans/bin/ansible-pull.sh - dest: $HOME/bin/ansible-pull.sh - owner: hpf-ans - group: hpf-ans - mode: u=rwx,go= - backup: true - #### User: heath @@ -256,11 +236,34 @@ ansible.posix.authorized_key: user: heath state: present - key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}" + key: "{{ lookup('file', item) }}" + loop: + - files/ssh-keys/heath.pub #### ansible-pull.sh + - name: Make sure /home/hpf-ans/bin exists + become: true + become_user: hpf-ans + ansible.builtin.file: + path: $HOME/bin + state: directory + owner: hpf-ans + group: hpf-ans + mode: u=rwx,go= + + - name: Get /home/hpf-ans/bin/ansible-pull.sh + become: true + become_user: hpf-ans + ansible.builtin.copy: + src: home/hpf-ans/bin/ansible-pull.sh + dest: $HOME/bin/ansible-pull.sh + owner: hpf-ans + group: hpf-ans + mode: u=rwx,go= + backup: true + - name: Make sure log directory exists become: true ansible.builtin.file: diff --git a/files/ssh-keys/hpf-ans.pub b/files/ssh-keys/hpf-ans.pub deleted file mode 100644 index 5958033..0000000 --- a/files/ssh-keys/hpf-ans.pub +++ /dev/null @@ -1 +0,0 @@ -ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBGKMs/y5N2ROuPabOAFUGDYb50ER/vssX9Zcsm/yPEn81EWl7NezZ1ULCchiXfEsC1qB4jm9NxocpwXmo0A5YbY= hpf-ans Heath@HPetersenFamily.com diff --git a/scraps/TODO.txt b/scraps/TODO.txt index 923bb5f..c6c6b73 100644 --- a/scraps/TODO.txt +++ b/scraps/TODO.txt @@ -1,13 +1,41 @@ +heath + authorized_keys: + - heath@hpetersenfamily.com + password: + status: VALID + value: COMMON STRONG FOR ALL HOSTS + private_keys: + - FOR WORKSTATIONS: heath@hpetersenfamily.com # Can this even be done securely through Ansible? +first + authorized_keys: + - first@hpetersenfamily.com + - heath@hpetersenfamily.com + password: + status: VALID + value: UNIQUE LONG FOR EACH HOST + private_keys: +root + authorized_keys: + - heath@hpetersenfamily.com + password: + status: LOCKED + private_keys: +hpf-ans: + authorized_keys: + - heath@hpetersenfamily.com + password: + status: LOCKED + private_keys: + + + + + ******** CHANGE PASSWORDS ******** -* Bitwarden MASTER +x Bitwarden MASTER * Google - heathpetersen@hpetersenfamily.com * Google - heathpetersen@kandre.com -* heath account on iris, admin-a, core -* first account ssh key -* heath account ssh key -* root account (UNIQUE) on iris, admin-a, core -* set ! as encrypted shadow password on hpf-ans on iris, admin-a, core # Change to work with multiple distros (nothing hardcoded) @@ -17,10 +45,9 @@ * Configure hosts - # cat >>/etc/hosts <>/etc/hosts <<-!!TheEnd!! ::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6 + 127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4 !!TheEnd!!