Files
ansible/scraps/TODO.txt
T
2026-08-22 10:59:19 -05:00

88 lines
1.9 KiB
Plaintext

Manually on each system:
* set hostname to fqdn
* set ansible branch if not production
* run bootstrap.yml
* update first password
iris.heath.hpetersenfamily.com admin-a.hpetersenfamily.com core.mary.hpetersenfamily.com
heath
authorized_keys:
- heath@hpetersenfamily.com
password:
status: VALID
value: COMMON STRONG FOR ALL HOSTS
first
authorized_keys:
- first@hpetersenfamily.com
- heath@hpetersenfamily.com
password:
status: VALID
value: UNIQUE LONG FOR EACH HOST
root
authorized_keys:
- heath@hpetersenfamily.com
password:
status: LOCKED
hpf-ans:
authorized_keys:
- heath@hpetersenfamily.com
password:
status: LOCKED
# Change to work with multiple distros (nothing hardcoded)
* create production, development branches
* cron job for ansible-pull
* Configure hosts
# cat >>/etc/hosts <<-!!TheEnd!!
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
!!TheEnd!!
##########
########## normal tasks
##########
- name: Install openssh, openssh-server, openssh-sftp-server
ansible.builtin.apt:
pkg:
- openssh
- openssh-server
- openssh-sftp-server
- name: Install bash, bash-completion
ansible.builtin.apt:
pkg:
- bash
- bash-completion
- name: Install chrony
ansible.builtin.apt:
pkg:
- chrony
* Configure chrony
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
pool 0.north-america.pool.ntp.org iburst
!!TheEnd!!
~heath/.gitconfig
fail2ban
uptime kuma
==============================================================
==============================================================
==============================================================
use tags to do things like allow selecting software updates, software cleanup, etc.