diff --git a/bootstrap.yml b/bootstrap.yml index 72928b4..0cbf345 100644 --- a/bootstrap.yml +++ b/bootstrap.yml @@ -148,6 +148,31 @@ key: "{{ lookup('file', 'files/ssh-keys/heath.pub') }}" +#### User: first + + - name: Create the first user + become: true + ansible.builtin.user: + name: first + comment: First User + state: present + system: false + groups: hpf-sudo-np + append: true + create_home: true + shell: /usr/bin/bash + + - name: Set first's authorized_keys + become: true + ansible.posix.authorized_key: + user: first + state: present + key: "{{ lookup('file', item) }}" + loop: + - files/ssh-keys/first.pub + - files/ssh-keys/heath.pub + + #### User: hpf-ans - name: Create the hpf-ans group @@ -219,32 +244,6 @@ backup: true -#### User: first - - - name: Create the first user - become: true - ansible.builtin.user: - name: first - comment: First User - state: present - system: false - groups: hpf-sudo-np - append: true - create_home: true - shell: /usr/bin/bash - uid_max: 1000 - - - name: Set first's authorized_keys - become: true - ansible.posix.authorized_key: - user: first - state: present - key: "{{ lookup('file', item) }}" - loop: - - files/ssh-keys/first.pub - - files/ssh-keys/heath.pub - - #### User: heath - name: Create the heath group diff --git a/scraps/TODO.txt b/scraps/TODO.txt index 23f29f6..55236ed 100644 --- a/scraps/TODO.txt +++ b/scraps/TODO.txt @@ -1,26 +1,6 @@ -x root - x authorized_keys = heath -x hpf-ans - x system user - x /usr/bin/bash - x member of hpf-sudo-np - x authorized_keys = hpf-ans, heath -x first - x normal user - x /usr/bin/bash - x member of hpf-sudo-np - x authorized_keys = first, heath -x heath - x normal user w/ special number - x /usr/bin/bash - x member of hpf-sudo - x authorized_keys = heath - - # Change to work with multiple distros (nothing hardcoded) - * create production, development branches logrotate /var/log/ansible-pull.log diff --git a/scraps/create_user.yml b/scraps/create_user.yml index 962f991..6fea50c 100644 --- a/scraps/create_user.yml +++ b/scraps/create_user.yml @@ -8,8 +8,21 @@ become: true ansible.builtin.user: name: second - comment: Second User + comment: second User state: present system: false + groups: hpf-sudo-np + append: true create_home: true shell: /usr/bin/bash + uid: 60002 + + - name: Set second's authorized_keys + become: true + ansible.posix.authorized_key: + user: second + state: present + key: "{{ lookup('file', item) }}" + loop: + - files/ssh-keys/second.pub + - files/ssh-keys/heath.pub