wulf-ansible/playbooks/bootstrap.yml

74 lines
2 KiB
YAML
Raw Normal View History

2026-04-02 15:07:28 -04:00
---
- name: Bootstrap new Linux host for Semaphore management
hosts: all
become: true
become_method: sudo
vars:
deploy_user: deploy
deploy_pub_key: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIFl9c6X1OWgfd7M3BCR689cKEMsZf5X7N6Jcp4EoZ5fj semaphore@wulf"
tasks:
- name: Create deploy user
ansible.builtin.user:
name: "{{ deploy_user }}"
shell: /bin/bash
create_home: true
state: present
- name: Ensure .ssh directory exists
ansible.builtin.file:
path: "/home/{{ deploy_user }}/.ssh"
state: directory
owner: "{{ deploy_user }}"
group: "{{ deploy_user }}"
mode: '0700'
- name: Install authorized key
ansible.posix.authorized_key:
user: "{{ deploy_user }}"
key: "{{ deploy_pub_key }}"
state: present
- name: Grant passwordless sudo via sudoers.d
ansible.builtin.copy:
dest: "/etc/sudoers.d/{{ deploy_user }}"
content: "{{ deploy_user }} ALL=(ALL) NOPASSWD:ALL\n"
mode: '0440'
validate: /usr/sbin/visudo -cf %s
- name: Disable SSH password authentication
ansible.builtin.lineinfile:
path: /etc/ssh/sshd_config
regexp: '^#?PasswordAuthentication'
line: 'PasswordAuthentication no'
state: present
notify: Restart sshd
- name: Ensure python3 is present
ansible.builtin.package:
name: python3
state: present
- name: Install common baseline packages
ansible.builtin.package:
name:
- curl
- wget
- git
- unzip
- htop
- ca-certificates
- gnupg
state: present
update_cache: true
- name: Set timezone to America/New_York
community.general.timezone:
name: America/New_York
handlers:
- name: Restart sshd
ansible.builtin.service:
name: "{{ 'ssh' if ansible_distribution == 'Ubuntu' else 'sshd' }}"
state: restarted