--- - name: Ensure group "admins" exists # include_tasks: create_groups.yml ansible.builtin.group: name: admins state: present - name: Grant sudo without PW to admins group ansible.builtin.template: src: roles/users/files/sudo_group_admins dest: /etc/sudoers.d/admins owner: root group: root mode: '0440' - name: Enable sudoers.d subdir ansible.builtin.lineinfile: path: /etc/sudoers state: present regexp: '^#includedir' line: '#includedir /etc/sudoers.d' validate: /usr/sbin/visudo -cf %s #- name: Ensure user "lea" exists # ansible.builtin.user: # name: lea # shell: /bin/bash # groups: admins # append: yes # ssh_public_key: "'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDShIcp8vkYwQOFYHEFlGUB6jbhwKTT/1SZgsIGCkNGamclxzg141q+k4891aIyaJfpWp/sGZUqBullKrgRdyOoRAZaCcECu29NXm4SNyoh8krYL6NL1R4uzwbt3xiyXrfSuw1qNwAtDOhVMINH+92jTo+2fqaXzrHoG0xnNClokOApIkwNHabpU8SG3dKgQrIHughWfdNq6Ot55hy4yV/34AhUbyKnLRjRJ0GlIc7IcyxmIzUCsD30ALXSdawdAWfFpkHvEbYzbMDfYJGB1EOqIdnCbIHJ7GTn6Q0gZkLQXcQxxQw13pHAMlsBHfbdAWKN0KOpULNKBYhhJaMs43dBeL6GWpWD1quO2tBQV9ddIPmhp3IJHpFss+MuLBv3vFP3x9Hvxau9sHoL1pSXp3Itn9mxftJ5VEnBmSsfEE+3+i0+fXspkHeGWc8qOgVfDc3UjoMBFBpo1FMMqQrRncV1CEpb7ODt2JlGmSkfUtSPdb6bHRYCmhoIUz47QOpU8gs= lea@MBP-von-Lea'\n" # #- name: Ensure user "beat" exists # ansible.builtin.user: # name: beat # shell: /bin/bash # groups: admins # append: yes # ssh_public_key: "'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILz8hrUqVpZxTsXCo0CH5KzNB+t7skM4DdKfyri+R+eX'\n #'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPy52w3bK6XDfcQu/Z83hP6+ApvS2nDOdlMSkMOCRV1I beat@wall-e.sunnig.ch'\n #'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPv1RlUA6Zupypx5LY9BP6kzwZbdPnpjTDT26b6W860x administrator@36154.hostserv.eu'\n" - name: Ensure user "rulrich" exists ansible.builtin.user: name: rulrich shell: /bin/bash groups: admins append: yes - name: Set up authorized keys for user rulrich ansible.posix.authorized_key: user: rulrich state: present key: '{{ item }}' with_file: - public_keys/rulrich