2015-05-28 11:32:57 +02:00
|
|
|
---
|
|
|
|
- name: Create the sudoers group if needed
|
|
|
|
group: name={{ users_sudoers_group }} state=present
|
|
|
|
when: users_sudoers_create_group
|
2016-03-10 16:53:35 +01:00
|
|
|
tags: users
|
2015-05-28 11:32:57 +02:00
|
|
|
|
|
|
|
- name: Add a sudo additional configuration for the new sudoers group
|
|
|
|
template: src=sudoers.j2 dest=/etc/sudoers.d/{{ users_sudoers_group }}
|
|
|
|
when: users_sudoers_create_sudo_conf
|
2016-03-10 16:53:35 +01:00
|
|
|
tags: users
|
2015-05-28 11:32:57 +02:00
|
|
|
|
|
|
|
- name: Create users
|
2016-09-08 12:06:23 +02:00
|
|
|
user: name={{ item.login }} comment="{{ item.name }}" home={{ item.home }}/{{ item.login }} createhome={{ item.createhome }} shell={{ item.shell }} password={{ item.password | default('*') }} update_password={{ item.update_password | default('on_create') }}
|
2016-03-10 16:53:35 +01:00
|
|
|
with_items: '{{ users_system_users }}'
|
|
|
|
when: users_system_users is defined
|
|
|
|
tags: users
|
2015-05-28 11:32:57 +02:00
|
|
|
|
|
|
|
- name: ensure that the users can login with their ssh keys
|
|
|
|
authorized_key: user="{{ item.login }}" key="{{ item.ssh_key }}" state=present
|
2016-03-10 16:53:35 +01:00
|
|
|
with_items: '{{ users_system_users }}'
|
2015-05-28 11:32:57 +02:00
|
|
|
when:
|
|
|
|
- users_system_users is defined
|
|
|
|
- item.ssh_key is defined
|
2016-03-10 16:53:35 +01:00
|
|
|
tags: users
|
2015-05-28 11:32:57 +02:00
|
|
|
|
|
|
|
- name: Add the admin users to the sudoers group
|
2015-09-03 02:36:22 +02:00
|
|
|
user: name={{ item.login }} groups={{ users_sudoers_group }} append=yes
|
2016-03-10 16:53:35 +01:00
|
|
|
with_items: '{{ users_system_users }}'
|
2015-05-28 11:32:57 +02:00
|
|
|
when:
|
|
|
|
- users_system_users is defined
|
2015-09-03 02:36:22 +02:00
|
|
|
- item.admin
|
2016-03-10 16:53:35 +01:00
|
|
|
tags: users
|
2015-07-13 17:54:21 +02:00
|
|
|
|
|
|
|
- name: ensure that the users can login with their ssh keys as root if we want ensure direct access
|
|
|
|
authorized_key: user=root key="{{ item.ssh_key }}" state=present
|
2016-03-10 16:53:35 +01:00
|
|
|
with_items: '{{ users_system_users }}'
|
2015-07-13 17:54:21 +02:00
|
|
|
when:
|
|
|
|
- users_system_users is defined
|
|
|
|
- item.ssh_key is defined
|
2015-09-03 02:36:22 +02:00
|
|
|
- ( item.log_as_root is defined ) and ( item.log_as_root )
|
2016-03-10 16:53:35 +01:00
|
|
|
tags: users
|
2015-07-13 17:54:21 +02:00
|
|
|
|