--- - name: Ensure GNOME desktop user config directories exist tags: [dotfiles, dotfiles:desktop, gnome] ansible.builtin.file: path: "{{ item }}" state: directory owner: "{{ username }}" group: "{{ user_group }}" mode: "0755" loop: - "{{ user_home }}/.config" - "{{ user_home }}/.config/autostart" - "{{ user_home }}/.local" - "{{ user_home }}/.local/bin" - "{{ user_home }}/.bashrc.d" - "{{ user_home }}/.tmux" - "{{ user_home }}/.tmux/bin" - "{{ user_home }}/.tmux/plugins" - name: Ensure GNOME desktop private directories exist tags: [dotfiles, dotfiles:desktop, gnome] ansible.builtin.file: path: "{{ item.path }}" state: directory owner: "{{ username }}" group: "{{ user_group }}" mode: "{{ item.mode }}" loop: - path: "{{ user_home }}/.gnupg" mode: "0700" - path: "{{ user_home }}/.ssh" mode: "0700" - path: "{{ user_home }}/.local/state/ssh/sockets" mode: "0700" - name: Copy GNOME desktop dotfiles tags: [dotfiles, dotfiles:desktop, gnome] ansible.builtin.copy: src: "{{ playbook_dir }}/../dotfiles/desktop/{{ item.src }}" dest: "{{ user_home }}/{{ item.dest }}" owner: "{{ username }}" group: "{{ user_group }}" mode: "{{ item.mode }}" loop: "{{ desktop_common_dotfiles | default([]) }}" loop_control: label: "{{ item.dest }}" - name: Copy GNOME Emacs desktop dotfiles tags: [dotfiles, dotfiles:desktop, emacs, gnome] ansible.builtin.copy: src: "{{ playbook_dir }}/../dotfiles/desktop/{{ item.src }}" dest: "{{ user_home }}/{{ item.dest }}" owner: "{{ username }}" group: "{{ user_group }}" mode: "{{ item.mode }}" loop: "{{ desktop_emacs_dotfiles | default([]) }}" when: emacs_enabled | default(false) | bool loop_control: label: "{{ item.dest }}" - name: Configure GNOME gpg-agent for Fedora tags: [dotfiles, dotfiles:desktop, git, gnome] ansible.builtin.copy: dest: "{{ user_home }}/.gnupg/gpg-agent.conf" content: | pinentry-program /usr/bin/pinentry-gnome3 enable-ssh-support default-cache-ttl 600 max-cache-ttl 7200 owner: "{{ username }}" group: "{{ user_group }}" mode: "0600" notify: Reload GNOME gpg-agent - name: Render GNOME git configuration with private values tags: [dotfiles, dotfiles:desktop, git, gnome] ansible.builtin.template: src: desktop/.gitconfig.j2 dest: "{{ user_home }}/.gitconfig" owner: "{{ username }}" group: "{{ user_group }}" mode: "0644" - name: Check whether SSH host ed25519 key exists on GNOME desktop tags: [services, gnome] ansible.builtin.stat: path: /etc/ssh/ssh_host_ed25519_key register: gnome_ssh_host_ed25519_key when: - (host_sshd_settings | default({})) | length > 0 or (host_sshd_allow_users | default([])) | length > 0 - name: Generate missing SSH host keys on GNOME desktop tags: [services, gnome] ansible.builtin.command: ssh-keygen -A changed_when: true when: - (host_sshd_settings | default({})) | length > 0 or (host_sshd_allow_users | default([])) | length > 0 - not gnome_ssh_host_ed25519_key.stat.exists - name: Require authorized SSH keys before disabling password authentication on GNOME desktop tags: [services, gnome] ansible.builtin.assert: that: - (host_authorized_ssh_keys | default([])) | length > 0 fail_msg: >- SSH password authentication is disabled for this host, but no authorized SSH keys are defined. Set host_authorized_ssh_keys via vault variables before applying this configuration. when: - "'sshd' in (host_enabled_services | default([]))" - (host_sshd_settings | default({})).PasswordAuthentication | default('yes') == 'no' - name: Ensure GNOME desktop user authorized_keys file exists tags: [services, dotfiles, gnome] ansible.builtin.file: path: "{{ user_home }}/.ssh/authorized_keys" state: touch owner: "{{ username }}" group: "{{ user_group }}" mode: "0600" when: (host_authorized_ssh_keys | default([])) | length > 0 - name: Manage GNOME desktop user authorized SSH keys exclusively tags: [services, dotfiles, gnome] ansible.posix.authorized_key: user: "{{ username }}" key: "{{ host_authorized_ssh_keys | join('\n') }}" state: present exclusive: true manage_dir: false when: (host_authorized_ssh_keys | default([])) | length > 0 - name: Apply SSH daemon settings on GNOME desktop tags: [services, gnome] ansible.builtin.lineinfile: path: /etc/ssh/sshd_config regexp: '^\s*{{ item.key }}\s+' line: "{{ item.key }} {{ item.value }}" state: present validate: "sshd -t -f %s" notify: Reload SSH service loop: "{{ host_sshd_settings | default({}) | dict2items }}" loop_control: label: "{{ item.key }}" when: (host_sshd_settings | default({})) | length > 0 - name: Restrict SSH login to allowed GNOME desktop users tags: [services, gnome] ansible.builtin.lineinfile: path: /etc/ssh/sshd_config regexp: '^\s*AllowUsers\s+' line: "AllowUsers {{ host_sshd_allow_users | join(' ') }}" state: present validate: "sshd -t -f %s" notify: Reload SSH service when: (host_sshd_allow_users | default([])) | length > 0 - name: Apply host firewalld rich rules on GNOME desktop tags: [services, packages, gnome] ansible.posix.firewalld: rich_rule: "{{ item }}" permanent: true immediate: true state: enabled loop: "{{ host_firewalld_rich_rules | default([]) }}" loop_control: label: "{{ item }}" when: workstation_firewall_backend | default('firewalld') == 'firewalld'