band-on-iac/roles/users/tasks/main.yml

49 lines
1.9 KiB
YAML

---
- name: Ensure group "admins" exists
# include_tasks: create_groups.yml
ansible.builtin.group:
name: admins
state: present
- name: Grant sudo without PW to admins group
ansible.builtin.template:
src: roles/users/files/sudo_group_admins
dest: /etc/sudoers.d/admins
owner: root
group: root
mode: '0440'
- name: Enable sudoers.d subdir
ansible.builtin.lineinfile:
path: /etc/sudoers
state: present
regexp: '^#includedir'
line: '#includedir /etc/sudoers.d'
validate: /usr/sbin/visudo -cf %s
- name: Ensure user "lea" exists
ansible.builtin.user:
name: lea
shell: /bin/bash
groups: admins
append: yes
ssh_public_key: "'ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDShIcp8vkYwQOFYHEFlGUB6jbhwKTT/1SZgsIGCkNGamclxzg141q+k4891aIyaJfpWp/sGZUqBullKrgRdyOoRAZaCcECu29NXm4SNyoh8krYL6NL1R4uzwbt3xiyXrfSuw1qNwAtDOhVMINH+92jTo+2fqaXzrHoG0xnNClokOApIkwNHabpU8SG3dKgQrIHughWfdNq6Ot55hy4yV/34AhUbyKnLRjRJ0GlIc7IcyxmIzUCsD30ALXSdawdAWfFpkHvEbYzbMDfYJGB1EOqIdnCbIHJ7GTn6Q0gZkLQXcQxxQw13pHAMlsBHfbdAWKN0KOpULNKBYhhJaMs43dBeL6GWpWD1quO2tBQV9ddIPmhp3IJHpFss+MuLBv3vFP3x9Hvxau9sHoL1pSXp3Itn9mxftJ5VEnBmSsfEE+3+i0+fXspkHeGWc8qOgVfDc3UjoMBFBpo1FMMqQrRncV1CEpb7ODt2JlGmSkfUtSPdb6bHRYCmhoIUz47QOpU8gs= lea@MBP-von-Lea
'\n"
- name: Ensure user "beat" exists
ansible.builtin.user:
name: beat
shell: /bin/bash
groups: admins
append: yes
ssh_public_key: "'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILz8hrUqVpZxTsXCo0CH5KzNB+t7skM4DdKfyri+R+eX'\n
'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPy52w3bK6XDfcQu/Z83hP6+ApvS2nDOdlMSkMOCRV1I beat@wall-e.sunnig.ch'\n
'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIPv1RlUA6Zupypx5LY9BP6kzwZbdPnpjTDT26b6W860x administrator@36154.hostserv.eu'\n"
- name: Ensure user "rulrich" exists
ansible.builtin.user:
name: rulrich
shell: /bin/bash
groups: admins
append: yes
ssh_public_key: "'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEecPevXnWu9Rs7QhDFAdeKl/E6cBPwUno+nEd4qoUAK rulrich@rabbit'\n"