x
This commit is contained in:
+27
-24
@@ -128,7 +128,9 @@
|
|||||||
ansible.posix.authorized_key:
|
ansible.posix.authorized_key:
|
||||||
user: root
|
user: root
|
||||||
state: present
|
state: present
|
||||||
key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}"
|
key: "{{ lookup('file', item) }}"
|
||||||
|
loop:
|
||||||
|
- files/ssh-keys/heath.pub
|
||||||
|
|
||||||
|
|
||||||
#### User: first
|
#### User: first
|
||||||
@@ -186,7 +188,6 @@
|
|||||||
state: present
|
state: present
|
||||||
key: "{{ lookup('file', item) }}"
|
key: "{{ lookup('file', item) }}"
|
||||||
loop:
|
loop:
|
||||||
- files/ssh-keys/hpf-ans.pub
|
|
||||||
- files/ssh-keys/heath.pub
|
- files/ssh-keys/heath.pub
|
||||||
|
|
||||||
- name: Make sure pip is up to date
|
- name: Make sure pip is up to date
|
||||||
@@ -205,27 +206,6 @@
|
|||||||
virtualenv: $HOME/.ansible-venv
|
virtualenv: $HOME/.ansible-venv
|
||||||
extra_args: --upgrade
|
extra_args: --upgrade
|
||||||
|
|
||||||
- name: Make sure /home/hpf-ans/bin exists
|
|
||||||
become: true
|
|
||||||
become_user: hpf-ans
|
|
||||||
ansible.builtin.file:
|
|
||||||
path: $HOME/bin
|
|
||||||
state: directory
|
|
||||||
owner: hpf-ans
|
|
||||||
group: hpf-ans
|
|
||||||
mode: u=rwx,go=
|
|
||||||
|
|
||||||
- name: Get /home/hpf-ans/bin/ansible-pull.sh
|
|
||||||
become: true
|
|
||||||
become_user: hpf-ans
|
|
||||||
ansible.builtin.copy:
|
|
||||||
src: home/hpf-ans/bin/ansible-pull.sh
|
|
||||||
dest: $HOME/bin/ansible-pull.sh
|
|
||||||
owner: hpf-ans
|
|
||||||
group: hpf-ans
|
|
||||||
mode: u=rwx,go=
|
|
||||||
backup: true
|
|
||||||
|
|
||||||
|
|
||||||
#### User: heath
|
#### User: heath
|
||||||
|
|
||||||
@@ -256,11 +236,34 @@
|
|||||||
ansible.posix.authorized_key:
|
ansible.posix.authorized_key:
|
||||||
user: heath
|
user: heath
|
||||||
state: present
|
state: present
|
||||||
key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}"
|
key: "{{ lookup('file', item) }}"
|
||||||
|
loop:
|
||||||
|
- files/ssh-keys/heath.pub
|
||||||
|
|
||||||
|
|
||||||
#### ansible-pull.sh
|
#### ansible-pull.sh
|
||||||
|
|
||||||
|
- name: Make sure /home/hpf-ans/bin exists
|
||||||
|
become: true
|
||||||
|
become_user: hpf-ans
|
||||||
|
ansible.builtin.file:
|
||||||
|
path: $HOME/bin
|
||||||
|
state: directory
|
||||||
|
owner: hpf-ans
|
||||||
|
group: hpf-ans
|
||||||
|
mode: u=rwx,go=
|
||||||
|
|
||||||
|
- name: Get /home/hpf-ans/bin/ansible-pull.sh
|
||||||
|
become: true
|
||||||
|
become_user: hpf-ans
|
||||||
|
ansible.builtin.copy:
|
||||||
|
src: home/hpf-ans/bin/ansible-pull.sh
|
||||||
|
dest: $HOME/bin/ansible-pull.sh
|
||||||
|
owner: hpf-ans
|
||||||
|
group: hpf-ans
|
||||||
|
mode: u=rwx,go=
|
||||||
|
backup: true
|
||||||
|
|
||||||
- name: Make sure log directory exists
|
- name: Make sure log directory exists
|
||||||
become: true
|
become: true
|
||||||
ansible.builtin.file:
|
ansible.builtin.file:
|
||||||
|
|||||||
@@ -1 +0,0 @@
|
|||||||
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBGKMs/y5N2ROuPabOAFUGDYb50ER/vssX9Zcsm/yPEn81EWl7NezZ1ULCchiXfEsC1qB4jm9NxocpwXmo0A5YbY= hpf-ans Heath@HPetersenFamily.com
|
|
||||||
+36
-9
@@ -1,13 +1,41 @@
|
|||||||
|
|
||||||
|
heath
|
||||||
|
authorized_keys:
|
||||||
|
- heath@hpetersenfamily.com
|
||||||
|
password:
|
||||||
|
status: VALID
|
||||||
|
value: COMMON STRONG FOR ALL HOSTS
|
||||||
|
private_keys:
|
||||||
|
- FOR WORKSTATIONS: heath@hpetersenfamily.com # Can this even be done securely through Ansible?
|
||||||
|
first
|
||||||
|
authorized_keys:
|
||||||
|
- first@hpetersenfamily.com
|
||||||
|
- heath@hpetersenfamily.com
|
||||||
|
password:
|
||||||
|
status: VALID
|
||||||
|
value: UNIQUE LONG FOR EACH HOST
|
||||||
|
private_keys:
|
||||||
|
root
|
||||||
|
authorized_keys:
|
||||||
|
- heath@hpetersenfamily.com
|
||||||
|
password:
|
||||||
|
status: LOCKED
|
||||||
|
private_keys:
|
||||||
|
hpf-ans:
|
||||||
|
authorized_keys:
|
||||||
|
- heath@hpetersenfamily.com
|
||||||
|
password:
|
||||||
|
status: LOCKED
|
||||||
|
private_keys:
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
******** CHANGE PASSWORDS ********
|
******** CHANGE PASSWORDS ********
|
||||||
* Bitwarden MASTER
|
x Bitwarden MASTER
|
||||||
* Google - heathpetersen@hpetersenfamily.com
|
* Google - heathpetersen@hpetersenfamily.com
|
||||||
* Google - heathpetersen@kandre.com
|
* Google - heathpetersen@kandre.com
|
||||||
* heath account on iris, admin-a, core
|
|
||||||
* first account ssh key
|
|
||||||
* heath account ssh key
|
|
||||||
* root account (UNIQUE) on iris, admin-a, core
|
|
||||||
* set ! as encrypted shadow password on hpf-ans on iris, admin-a, core
|
|
||||||
|
|
||||||
# Change to work with multiple distros (nothing hardcoded)
|
# Change to work with multiple distros (nothing hardcoded)
|
||||||
|
|
||||||
@@ -17,10 +45,9 @@
|
|||||||
|
|
||||||
|
|
||||||
* Configure hosts
|
* Configure hosts
|
||||||
# cat >>/etc/hosts <<!!TheEnd!!
|
# cat >>/etc/hosts <<-!!TheEnd!!
|
||||||
|
|
||||||
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
|
|
||||||
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
|
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
|
||||||
|
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
|
||||||
!!TheEnd!!
|
!!TheEnd!!
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user