88 lines
1.9 KiB
Plaintext
88 lines
1.9 KiB
Plaintext
Manually on each system:
|
|
* set hostname to fqdn
|
|
* set ansible branch if not production
|
|
* run bootstrap.yml
|
|
* update first password
|
|
|
|
iris.heath.hpetersenfamily.com admin-a.hpetersenfamily.com core.mary.hpetersenfamily.com
|
|
|
|
|
|
heath
|
|
authorized_keys:
|
|
- heath@hpetersenfamily.com
|
|
password:
|
|
status: VALID
|
|
value: COMMON STRONG FOR ALL HOSTS
|
|
first
|
|
authorized_keys:
|
|
- first@hpetersenfamily.com
|
|
- heath@hpetersenfamily.com
|
|
password:
|
|
status: VALID
|
|
value: UNIQUE LONG FOR EACH HOST
|
|
root
|
|
authorized_keys:
|
|
- heath@hpetersenfamily.com
|
|
password:
|
|
status: LOCKED
|
|
hpf-ans:
|
|
authorized_keys:
|
|
- heath@hpetersenfamily.com
|
|
password:
|
|
status: LOCKED
|
|
|
|
|
|
# Change to work with multiple distros (nothing hardcoded)
|
|
|
|
* create production, development branches
|
|
* cron job for ansible-pull
|
|
|
|
|
|
|
|
* Configure hosts
|
|
# cat >>/etc/hosts <<-!!TheEnd!!
|
|
::1 name.f.q.d.n name-ipv6.f.q.d.n name name-ipv6
|
|
127.0.0.1 name.f.q.d.n name-ipv4.f.q.d.n name name-ipv4
|
|
!!TheEnd!!
|
|
|
|
|
|
##########
|
|
########## normal tasks
|
|
##########
|
|
|
|
- name: Install openssh, openssh-server, openssh-sftp-server
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- openssh
|
|
- openssh-server
|
|
- openssh-sftp-server
|
|
|
|
- name: Install bash, bash-completion
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- bash
|
|
- bash-completion
|
|
|
|
- name: Install chrony
|
|
ansible.builtin.apt:
|
|
pkg:
|
|
- chrony
|
|
|
|
* Configure chrony
|
|
# cat >/etc/chrony/sources.d/hpetersenfamily-north-america.sources <<!!TheEnd!!
|
|
pool 0.north-america.pool.ntp.org iburst
|
|
!!TheEnd!!
|
|
|
|
|
|
~heath/.gitconfig
|
|
|
|
fail2ban
|
|
uptime kuma
|
|
|
|
==============================================================
|
|
==============================================================
|
|
==============================================================
|
|
|
|
use tags to do things like allow selecting software updates, software cleanup, etc.
|
|
|