--- - name: Bootstrap node hosts: all become: true tasks: - name: Add the ansible group ansible.builtin.group: name: ansible gid: "1100" state: present - name: Add the ansible user as a system user ansible.builtin.user: name: ansible uid: "1100" group: ansible # Directly generate hash # https://www.lisenet.com/2019/ansible-generate-crypted-passwords-for-the-user-module/ password: "{{ ansible_crypted_password | password_hash('sha512') }}" shell: /bin/bash # Uncomment to prevent password reset update_password: on_create system: true home: /home/ansible state: present - name: Set ansible user as sudoer ansible.builtin.copy: content: "ansible ALL = (ALL) NOPASSWD:ALL" dest: /etc/sudoers.d/ansible owner: root group: root mode: "0440" - name: Init cache directory ansible.builtin.file: path: /var/cache/ansible owner: ansible group: ansible state: directory mode: u=rwx,g=rw,o=r - name: Init etc directory ansible.builtin.file: path: /etc/ansible owner: ansible group: ansible state: directory mode: u=rwx,g=rw,o=r # Inserts public keys of allowed externals users to log in as ansible # e.g. fabio - name: Create the .ssh directory ansible.builtin.file: path: /home/ansible/.ssh owner: ansible group: ansible mode: "0700" state: directory - name: Add the mandatory ssh keys to the ansible user ansible.builtin.template: src: templates/ansible_auth_keys.j2 dest: /home/ansible/.ssh/authorized_keys owner: ansible group: ansible mode: "0600"