roles/bootstrap/tasks/main.yml

Mon, 22 Oct 2018 20:45:59 -0500

author
Meredith Howard <mhoward@roomag.org>
date
Mon, 22 Oct 2018 20:45:59 -0500
changeset 82
ae08d6315368
parent 76
9c024e39a565
child 88
3dbfd253c775
permissions
-rw-r--r--

update debian-backports repo

73
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
1 ---
76
9c024e39a565 clean up task names
Meredith Howard <mhoward@roomag.org>
parents: 73
diff changeset
2 - name: "Ansible control user"
73
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
3 user:
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
4 name: ansible
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
5 comment: "Ansible Controller"
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
6 home: /var/lib/ansible
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
7 createhome: true
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
8 append: true
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
9 system: true
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
10 state: present
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
11
76
9c024e39a565 clean up task names
Meredith Howard <mhoward@roomag.org>
parents: 73
diff changeset
12 - name: "Ansible pubkeys"
73
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
13 authorized_key:
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
14 manage_dir: true
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
15 user: ansible
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
16 key: "{{item}}"
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
17 with_file:
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
18 - 'public_keys/ansible'
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
19
76
9c024e39a565 clean up task names
Meredith Howard <mhoward@roomag.org>
parents: 73
diff changeset
20 - name: "Ansible sudo"
73
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
21 lineinfile:
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
22 dest: /etc/sudoers
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
23 state: present
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
24 regexp: '^ansible'
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
25 line: 'ansible ALL=(ALL) NOPASSWD: ALL'
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
26 validate: 'visudo -cf "%s"'
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
27
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
28 - include: disable-stock.yml
8b0c09efbb5b add bootstrap role
Meredith Howard <mhoward@roomag.org>
parents:
diff changeset
29 when: disable_stock_users

mercurial