91 lines
1.9 KiB
Plaintext
91 lines
1.9 KiB
Plaintext
|
|
|
|
heath
|
|
authorized_keys:
|
|
- heath@hpetersenfamily.com
|
|
password:
|
|
status: VALID
|
|
value: COMMON STRONG FOR ALL HOSTS
|
|
private_keys:
|
|
- FOR WORKSTATIONS: heath@hpetersenfamily.com # Can this even be done securely through Ansible?
|
|
first
|
|
authorized_keys:
|
|
- first@hpetersenfamily.com
|
|
- heath@hpetersenfamily.com
|
|
password:
|
|
status: VALID
|
|
value: UNIQUE LONG FOR EACH HOST
|
|
private_keys:
|
|
root
|
|
authorized_keys:
|
|
- heath@hpetersenfamily.com
|
|
password:
|
|
status: LOCKED
|
|
private_keys:
|
|
hpf-ans:
|
|
authorized_keys:
|
|
- heath@hpetersenfamily.com
|
|
password:
|
|
status: LOCKED
|
|
private_keys:
|
|
|
|
|
|
# Change to work with multiple distros (nothing hardcoded)
|
|
|
|
* create production, development branches
|
|
* cron job for ansible-pull
|
|
|
|
|
|
|
|
* Configure hosts
|
|
# cat >>/etc/hosts <<-!!TheEnd!!
|
|
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
|
|
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
|
|
!!TheEnd!!
|
|
|
|
|
|
##########
|
|
########## normal tasks
|
|
##########
|
|
|
|
- name: Install openssh, openssh-server, openssh-sftp-server
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- openssh
|
|
- openssh-server
|
|
- openssh-sftp-server
|
|
|
|
- name: Install bash, bash-completion
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- bash
|
|
- bash-completion
|
|
|
|
- name: Install chrony
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- chrony
|
|
|
|
#- name: Set host name
|
|
# ansible.builtin.hostname:
|
|
# name: ## Fully qualified domain name ##
|
|
# use: systemd
|
|
|
|
* Configure chrony
|
|
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
|
|
pool 0.north-america.pool.ntp.org iburst
|
|
!!TheEnd!!
|
|
|
|
|
|
~heath/.gitconfig
|
|
|
|
fail2ban
|
|
uptime kuma
|
|
|
|
==============================================================
|
|
==============================================================
|
|
==============================================================
|
|
|
|
use tags to do things like allow selecting software updates, software cleanup, etc.
|
|
|