ansible-roles/evolinux-users/tasks/ssh.yml

42 lines
1.1 KiB
YAML
Raw Normal View History

---
- name: "Create .ssh directory for '{{ user.name }}'"
file:
dest: '/home/{{ user.name }}/.ssh/'
state: directory
mode: "0700"
owner: '{{ user.name }}'
group: '{{ user.name }}'
- name: "Add user's SSH public key for '{{ user.name }}'"
2016-12-27 14:04:02 +01:00
authorized_key:
user: "{{ user.name }}"
key: "{{ user.ssh_key }}"
state: present
when: user.ssh_key is defined
- name: "Add user's SSH public keys for '{{ user.name }}'"
authorized_key:
user: "{{ user.name }}"
key: "{{ ssk_key }}"
state: present
with_items: "{{ user.ssh_keys }}"
loop_control:
loop_var: ssk_key
when: user.ssh_keys is defined
2016-12-27 14:04:02 +01:00
- name: verify AllowGroups directive
command: "grep -E '^AllowGroups' /etc/ssh/sshd_config"
2016-12-27 14:04:02 +01:00
changed_when: False
failed_when: False
2017-03-24 14:15:09 +01:00
check_mode: no
register: grep_allowgroups_ssh
2017-03-24 14:15:09 +01:00
# If AllowGroups is present or Debian 9+, use AllowGroups mode
2018-03-01 11:59:36 +01:00
- include: ssh_allowgroups.yml
when: grep_allowgroups_ssh.rc == 0 or ansible_distribution_major_version | version_compare('9', '>=')
# If AllowGroups is absent, use AllowUsers mode
2018-03-01 11:59:36 +01:00
- include: ssh_allowusers.yml
when: grep_allowgroups_ssh.rc != 0