Compare commits
2 commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
40112bddc6 | ||
|
|
3e4f113d86 |
3 changed files with 23 additions and 9 deletions
|
|
@ -80,15 +80,17 @@
|
||||||
loop_var: rolename
|
loop_var: rolename
|
||||||
when: custom_roles is defined
|
when: custom_roles is defined
|
||||||
|
|
||||||
- name: Final tasks
|
- name: Import role security
|
||||||
ansible.builtin.include_role:
|
ansible.builtin.import_role:
|
||||||
name: "{{ role }}"
|
name: lmn_security
|
||||||
loop_control:
|
|
||||||
loop_var: role
|
- name: Import role finish
|
||||||
loop:
|
ansible.builtin.import_role:
|
||||||
- lmn_security
|
name: lmn_finish
|
||||||
- lmn_finish
|
|
||||||
- lmn_tmpfixes
|
- name: Import role tmpfixes
|
||||||
|
ansible.builtin.import_role:
|
||||||
|
name: lmn_tmpfixes
|
||||||
|
|
||||||
|
|
||||||
- name: Apply roles that must run serial
|
- name: Apply roles that must run serial
|
||||||
|
|
|
||||||
|
|
@ -167,6 +167,8 @@
|
||||||
src: reporter.j2
|
src: reporter.j2
|
||||||
dest: /usr/local/sbin/reporter
|
dest: /usr/local/sbin/reporter
|
||||||
mode: '0755'
|
mode: '0755'
|
||||||
|
tags:
|
||||||
|
- baseinstall
|
||||||
|
|
||||||
- name: Provide services and timers for reporter
|
- name: Provide services and timers for reporter
|
||||||
ansible.builtin.copy:
|
ansible.builtin.copy:
|
||||||
|
|
@ -177,12 +179,16 @@
|
||||||
- reporter.service
|
- reporter.service
|
||||||
- reporter.timer
|
- reporter.timer
|
||||||
when: misc_reporter
|
when: misc_reporter
|
||||||
|
tags:
|
||||||
|
- baseinstall
|
||||||
|
|
||||||
- name: Enable reporter.timer
|
- name: Enable reporter.timer
|
||||||
ansible.builtin.systemd:
|
ansible.builtin.systemd:
|
||||||
name: reporter.timer
|
name: reporter.timer
|
||||||
enabled: true
|
enabled: true
|
||||||
when: misc_reporter
|
when: misc_reporter
|
||||||
|
tags:
|
||||||
|
- baseinstall
|
||||||
|
|
||||||
# Prepare CloneScreen on Presenter PCs
|
# Prepare CloneScreen on Presenter PCs
|
||||||
|
|
||||||
|
|
|
||||||
|
|
@ -5,6 +5,8 @@
|
||||||
key: "{{ item }}"
|
key: "{{ item }}"
|
||||||
loop: "{{ keys2deploy }}"
|
loop: "{{ keys2deploy }}"
|
||||||
when: keys2deploy is defined
|
when: keys2deploy is defined
|
||||||
|
tags:
|
||||||
|
- baseinstall
|
||||||
|
|
||||||
- name: Allow sudo without password for ansible
|
- name: Allow sudo without password for ansible
|
||||||
ansible.builtin.lineinfile:
|
ansible.builtin.lineinfile:
|
||||||
|
|
@ -14,12 +16,16 @@
|
||||||
owner: root
|
owner: root
|
||||||
group: root
|
group: root
|
||||||
mode: '0700'
|
mode: '0700'
|
||||||
|
tags:
|
||||||
|
- baseinstall
|
||||||
|
|
||||||
- name: Disable ansible user login
|
- name: Disable ansible user login
|
||||||
ansible.builtin.user:
|
ansible.builtin.user:
|
||||||
name: ansible
|
name: ansible
|
||||||
password_lock: true
|
password_lock: true
|
||||||
when: security_defaultuser_login_disable
|
when: security_defaultuser_login_disable
|
||||||
|
tags:
|
||||||
|
- baseinstall
|
||||||
|
|
||||||
- name: Limit SSH access to user ansible
|
- name: Limit SSH access to user ansible
|
||||||
ansible.builtin.blockinfile:
|
ansible.builtin.blockinfile:
|
||||||
|
|
|
||||||
Loading…
Add table
Reference in a new issue