From d1e4062604fdf9ff97959e396f6be4aac2c33478 Mon Sep 17 00:00:00 2001 From: Yujun Zhang Date: Wed, 23 Nov 2016 16:02:35 +0800 Subject: Reorganize the inventory - update server name and spec - group servers by usage - assign roles for each group - rename role ssh to user Change-Id: Ibc0a599adfabee296510f140319889775d9ae6cc Signed-off-by: Yujun Zhang --- opt/servers/roles/user/tasks/main.yml | 35 +++++++++++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) create mode 100644 opt/servers/roles/user/tasks/main.yml (limited to 'opt/servers/roles/user/tasks') diff --git a/opt/servers/roles/user/tasks/main.yml b/opt/servers/roles/user/tasks/main.yml new file mode 100644 index 00000000..b1b5be9b --- /dev/null +++ b/opt/servers/roles/user/tasks/main.yml @@ -0,0 +1,35 @@ +- name: add group qtip + become: true + group: name=qtip state=present +- name: add qtip to sudoers without password + become: true + file: + src: sudoers.d-qtip + dest: /etc/sudoers.d/50-qtip + mode: 0440 +- name: add users for ssh access + become: true + user: + name: "{{ item.name }}" + comment: "{{ item.comment }}" + groups: "qtip" + append: yes + with_items: "{{ users }}" +- name: create .ssh directory + become: true + file: + path: "/home/{{ item.name }}/.ssh" + state: directory + owner: "{{ item.name }}" + group: "{{ item.name }}" + mode: 0700 + with_items: "{{ users }}" +- name: authorize public key + become: true + copy: + src: "{{ item.name }}.authorized_keys" + dest: "/home/{{ item.name }}/.ssh/authorized_keys" + owner: "{{ item.name }}" + group: "{{ item.name }}" + mode: 0600 + with_items: "{{ users }}" -- cgit 1.2.3-korg