mirror of
https://github.com/fscotto/infra.git
synced 2026-09-27 11:02:47 +00:00
Manage Aegis SSH authorized key fragments
This commit is contained in:
@@ -10,8 +10,11 @@ ansible_ssh_use_tty: false
|
|||||||
aegis_lan_subnet: 192.168.178.0/24
|
aegis_lan_subnet: 192.168.178.0/24
|
||||||
aegis_adguard_web_port: 80
|
aegis_adguard_web_port: 80
|
||||||
aegis_ssh_authorized_keys:
|
aegis_ssh_authorized_keys:
|
||||||
- "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINrIxXjA3ffPwziKGR5gzc4gAoBehQPlnEMcXF4Wl0ZS ikaros"
|
- name: ikaros
|
||||||
- "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEH/7GJfGt0ZVmKeEzceoFkFkeCXFryKK9vAbaip+HCx nymph"
|
key: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINrIxXjA3ffPwziKGR5gzc4gAoBehQPlnEMcXF4Wl0ZS ikaros"
|
||||||
- "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA95wYlzpfN3rjUhpMeP4KHn8I6ZrjQXoDTgwgRIa++b siren"
|
- name: nymph
|
||||||
|
key: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIEH/7GJfGt0ZVmKeEzceoFkFkeCXFryKK9vAbaip+HCx nymph"
|
||||||
|
- name: siren
|
||||||
|
key: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIA95wYlzpfN3rjUhpMeP4KHn8I6ZrjQXoDTgwgRIa++b siren"
|
||||||
|
|
||||||
aegis_icloudpd_apple_id: "{{ vault_aegis_icloudpd_apple_id | default('') }}"
|
aegis_icloudpd_apple_id: "{{ vault_aegis_icloudpd_apple_id | default('') }}"
|
||||||
|
|||||||
@@ -165,14 +165,27 @@
|
|||||||
path: "{{ aegis_ssh_user_home }}/.ssh/authorized_keys"
|
path: "{{ aegis_ssh_user_home }}/.ssh/authorized_keys"
|
||||||
register: aegis_authorized_keys
|
register: aegis_authorized_keys
|
||||||
|
|
||||||
- name: Manage Aegis SSH authorized keys
|
- name: Ensure Aegis SSH authorized key fragments directory exists
|
||||||
tags: [aegis, ssh, services]
|
tags: [aegis, ssh, services]
|
||||||
ansible.posix.authorized_key:
|
ansible.builtin.file:
|
||||||
user: "{{ ansible_user }}"
|
path: "{{ aegis_ssh_user_home }}/.ssh/authorized_keys.d"
|
||||||
key: "{{ aegis_ssh_authorized_keys | join('\n') }}"
|
state: directory
|
||||||
state: present
|
owner: "{{ ansible_user }}"
|
||||||
exclusive: true
|
group: "{{ ansible_user }}"
|
||||||
manage_dir: true
|
mode: "0700"
|
||||||
|
when: aegis_ssh_authorized_keys | length > 0
|
||||||
|
|
||||||
|
- name: Manage Aegis SSH authorized key fragments
|
||||||
|
tags: [aegis, ssh, services]
|
||||||
|
ansible.builtin.copy:
|
||||||
|
content: "{{ item.key }}\n"
|
||||||
|
dest: "{{ aegis_ssh_user_home }}/.ssh/authorized_keys.d/{{ item.name }}"
|
||||||
|
owner: "{{ ansible_user }}"
|
||||||
|
group: "{{ ansible_user }}"
|
||||||
|
mode: "0600"
|
||||||
|
loop: "{{ aegis_ssh_authorized_keys }}"
|
||||||
|
loop_control:
|
||||||
|
label: "{{ item.name }}"
|
||||||
when: aegis_ssh_authorized_keys | length > 0
|
when: aegis_ssh_authorized_keys | length > 0
|
||||||
|
|
||||||
- name: Find Aegis SSH authorized key fragments
|
- name: Find Aegis SSH authorized key fragments
|
||||||
|
|||||||
Reference in New Issue
Block a user