continuation of new policy for sudo in Debian 9

This commit is contained in:
Gregory Colpart 2017-08-22 02:58:38 +02:00
parent bbdbd53cca
commit 2d17c60f39
2 changed files with 10 additions and 3 deletions

View file

@ -40,9 +40,9 @@
system: yes
when: ansible_distribution_major_version | version_compare('9', '>=')
- name: "Add user to sudo group (Debian 9 or later)"
- name: "Add user to evolinux-sudo group (Debian 9 or later)"
user:
name: '{{ user.name }}'
groups: 'evolinux-sudo,{{ admin_users_group }}'
groups: 'evolinux-sudo'
append: yes
when: ansible_distribution_major_version | version_compare('9', '>=')

View file

@ -35,11 +35,18 @@
update_password: on_create
when: loginisbusy.rc != 0 and uidisbusy.rc == 0
- name: "Create {{ admin_users_group }} group"
- name: "Create {{ admin_users_group }} group (Debian 9 or later)"
group:
name: "{{ admin_users_group }}"
when: ansible_distribution_major_version | version_compare('9', '>=')
- name: "Add user to {{ admin_users_group }} group (Debian 9 or later)"
user:
name: '{{ user.name }}'
groups: '{{ admin_users_group }}'
append: yes
when: ansible_distribution_major_version | version_compare('9', '>=')
- name: "Fix perms on homedirectory for '{{ user.name }}'"
file:
name: '/home/{{ user.name }}'