added tasks for a bastion host

This commit is contained in:
2025-10-01 14:22:25 +02:00
parent 54fc2ad535
commit 19e616845e
13 changed files with 299 additions and 11 deletions

View File

@@ -0,0 +1,28 @@
- name: users | lowpriv | add user to system
user:
name: lowpriv
comment: Restricted user for interactive shell
shell: /usr/bin/rbash
state: present
create_home: True
generate_ssh_key: False
password_lock: True
- name: users | lowpriv | getent user home directory
getent:
database: passwd
key: "lowpriv"
split: ":"
register: getent_passwd_lowpriv
changed_when: false
- name: users | lowpriv | set home directory fact
set_fact:
user_home: "{{ getent_passwd_lowpriv.ansible_facts.getent_passwd['lowpriv'][4] }}"
user: "lowpriv"
- name: users | lowpriv | import ssh configuration tasks from base role
import_tasks: ../../../base/tasks/users/install_public_keys.yml
- name: users | lowpriv | import known_hosts task from base role
import_tasks: ../../../base/tasks/users/install_known_hosts.yml