99 lines
1.9 KiB
Plaintext
99 lines
1.9 KiB
Plaintext
x root
|
|
x authorized_keys = heath
|
|
x hpf-ans
|
|
x system user
|
|
x /usr/bin/bash
|
|
x member of hpf-sudo-np
|
|
x authorized_keys = hpf-ans, heath
|
|
* first
|
|
x normal user
|
|
x /usr/bin/bash
|
|
x member of hpf-sudo-np
|
|
x authorized_keys = first, heath
|
|
* heath
|
|
x normal user w/ special number
|
|
x /usr/bin/bash
|
|
x member of hpf-sudo
|
|
x authorized_keys = heath
|
|
|
|
|
|
|
|
# Change to work with multiple distros (nothing hardcoded)
|
|
|
|
|
|
* create production, development branches
|
|
|
|
logrotate /var/log/ansible-pull.log
|
|
cron job for ansible-pull
|
|
|
|
|
|
|
|
# add /home/hpf-ans/bin/ansible-pull.sh crontab
|
|
|
|
|
|
|
|
* Configure hosts
|
|
# cat >>/etc/hosts <<!!TheEnd!!
|
|
|
|
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
|
|
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
|
|
!!TheEnd!!
|
|
* Configure chrony
|
|
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
|
|
pool 0.north-america.pool.ntp.org iburst
|
|
!!TheEnd!!
|
|
|
|
|
|
##########
|
|
########## normal tasks
|
|
##########
|
|
|
|
- name: Install openssh, openssh-server, openssh-sftp-server
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- openssh
|
|
- openssh-server
|
|
- openssh-sftp-server
|
|
|
|
- name: Install bash, bash-completion
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- bash
|
|
- bash-completion
|
|
|
|
- name: Install chrony
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- chrony
|
|
|
|
#- name: Set host name
|
|
# ansible.builtin.hostname:
|
|
# name: ## Fully qualified domain name ##
|
|
# use: systemd
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
|
|
~heath/.ssh/authorized_keys
|
|
~first/.ssh/authorized_keys
|
|
~heath/.gitconfig
|
|
|
|
|
|
|
|
|
|
fail2ban
|
|
uptime kuma
|
|
|
|
==============================================================
|
|
==============================================================
|
|
==============================================================
|
|
|
|
|
|
|
|
use tags to do things like allow selecting software updates, software cleanup, etc.
|
|
|