114 lines
2.6 KiB
Plaintext
114 lines
2.6 KiB
Plaintext
x root
|
|
x authorized_keys = heath
|
|
x hpf-ans
|
|
x system user
|
|
x /usr/bin/bash
|
|
x member of hpf-sudo-np
|
|
x authorized_keys = hpf-ans, heath
|
|
* first
|
|
* normal user
|
|
* /usr/bin/bash
|
|
* member of hpf-sudo
|
|
x authorized_keys = first, heath
|
|
* heath
|
|
* normal user
|
|
* /usr/bin/bash
|
|
* member of hpf-sudo
|
|
x authorized_keys = heath
|
|
|
|
|
|
|
|
|
|
|
|
* create production, development branches
|
|
* have bootstrap.sh get ansible_pull_branch variable value
|
|
|
|
|
|
|
|
|
|
# add /home/hpf-ans/bin/ansible-pull.sh crontab
|
|
|
|
|
|
|
|
* Configure hosts
|
|
# cat >>/etc/hosts <<!!TheEnd!!
|
|
|
|
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
|
|
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
|
|
!!TheEnd!!
|
|
* Configure chrony
|
|
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
|
|
pool 0.north-america.pool.ntp.org iburst
|
|
!!TheEnd!!
|
|
* Configure SSH
|
|
# cat >/etc/ssh/sshd_config.d/hpetersenfamily.conf <<!!TheEnd!!
|
|
PasswordAuthentication no
|
|
PermitEmptyPasswords no
|
|
PermitRootLogin no
|
|
!!TheEnd!!
|
|
# cat >>/home/first/.ssh/authorized_keys <<!!TheEnd!!
|
|
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBM5BBUOxkuSK7WlpaDvp6lrM9ajLSyh4PWD7VFzYOFN5/zfafy6Vf/oxtLE4UACw5ZGvBMQNH40bW+T9aO0lQ9g= first Heath@HPetersenFamily.com
|
|
ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBBFiio/AimTUloJdfk4TXyWO7A0Fd9SoUcqheBjEvj4TnrxpSL/EhwF2CU9jZTasm6NBo2eKcH4aMt1l2ejOtIM= heath Heath@HPetersenFamily.com
|
|
!!TheEnd!!
|
|
|
|
|
|
##########
|
|
########## normal tasks
|
|
##########
|
|
|
|
- name: Install openssh, openssh-server, openssh-sftp-server
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- openssh
|
|
- openssh-server
|
|
- openssh-sftp-server
|
|
|
|
- name: Install bash, bash-completion
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- bash
|
|
- bash-completion
|
|
|
|
- name: Install chrony
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- chrony
|
|
|
|
#- name: Set host name
|
|
# ansible.builtin.hostname:
|
|
# name: ## Fully qualified domain name ##
|
|
# use: systemd
|
|
|
|
|
|
|
|
|
|
proxmox-clients
|
|
hw:
|
|
pve-lxc:
|
|
pve-oci:
|
|
pve-kvm:
|
|
|
|
|
|
|
|
~heath/.ssh/heath ## WARNING - SeCrEt! - Make sure this is not in the repo! - Does this need to be on every machine?
|
|
~heath/.ssh/authorized_keys
|
|
~first/.ssh/authorized_keys
|
|
~heath/.gitconfig
|
|
|
|
|
|
|
|
|
|
fail2ban
|
|
uptime kuma
|
|
|
|
==============================================================
|
|
==============================================================
|
|
==============================================================
|
|
|
|
logrotate /var/log/ansible-pull.log
|
|
cron job for ansible-pull
|
|
|
|
|
|
use tags to do things like allow selecting software updates, software cleanup, etc.
|
|
|