forked from evolix/ansible-roles
evolinux-users: better detection of AllowUsers
This commit is contained in:
parent
707aabb404
commit
8435ac192d
|
@ -9,7 +9,8 @@
|
||||||
msg: "Warning: empty 'evolinux_users' variable, tasks will be skipped!"
|
msg: "Warning: empty 'evolinux_users' variable, tasks will be skipped!"
|
||||||
when: evolinux_users == {}
|
when: evolinux_users == {}
|
||||||
|
|
||||||
- include: user.yml
|
- name: Create user accounts
|
||||||
|
include: user.yml
|
||||||
vars:
|
vars:
|
||||||
user: "{{ item.value }}"
|
user: "{{ item.value }}"
|
||||||
with_dict: "{{ evolinux_users }}"
|
with_dict: "{{ evolinux_users }}"
|
||||||
|
|
|
@ -46,7 +46,7 @@
|
||||||
- name: "Modify AllowUsers sshd directive for '{{ user.name }}'"
|
- name: "Modify AllowUsers sshd directive for '{{ user.name }}'"
|
||||||
replace:
|
replace:
|
||||||
dest: /etc/ssh/sshd_config
|
dest: /etc/ssh/sshd_config
|
||||||
regexp: '^(AllowUsers ((?!{{ user.name }}).)*)$'
|
regexp: '^(AllowUsers ((?!\b{{ user.name }}\b).)*)$'
|
||||||
replace: '\1 {{ user.name }}'
|
replace: '\1 {{ user.name }}'
|
||||||
validate: '/usr/sbin/sshd -T -f %s'
|
validate: '/usr/sbin/sshd -T -f %s'
|
||||||
notify: reload sshd
|
notify: reload sshd
|
||||||
|
|
Loading…
Reference in a new issue