Files
ansible-linux-infra/roles/local_accounts/tasks/main.yml
2026-08-19 09:51:43 +02:00

68 lines
2.1 KiB
YAML

---
- name: Create break-glass group
ansible.builtin.group:
name: "{{ breakglass_username }}"
state: present
tags: [local_accounts]
- name: Create break-glass account
ansible.builtin.user:
name: "{{ breakglass_username }}"
comment: "{{ breakglass_comment }}"
group: "{{ breakglass_username }}"
shell: /bin/bash
create_home: true
home: "/home/{{ breakglass_username }}"
password: "{{ breakglass_password_hash | default('!', true) }}"
update_password: on_create
state: present
tags: [local_accounts]
- name: Lock down break-glass home directory
ansible.builtin.file:
path: "/home/{{ breakglass_username }}"
owner: "{{ breakglass_username }}"
group: "{{ breakglass_username }}"
mode: "0700"
tags: [local_accounts]
- name: Deploy unrestricted sudo drop-in for break-glass account
ansible.builtin.copy:
dest: "/etc/sudoers.d/00-{{ breakglass_username }}"
owner: root
group: root
mode: "0440"
content: "{{ breakglass_username }} ALL=(ALL) ALL\n"
validate: "visudo -cf %s"
tags: [local_accounts]
- name: Block SSH access for the break-glass account
ansible.builtin.blockinfile:
path: /etc/ssh/sshd_config.d/00-breakglass-deny.conf
create: true
owner: root
group: root
mode: "0600"
marker: "# {mark} ANSIBLE MANAGED BLOCK"
block: |
Match User {{ breakglass_username }}
PasswordAuthentication no
PubkeyAuthentication no
validate: "/usr/sbin/sshd -t -f %s"
notify: restart sshd (local_accounts)
tags: [local_accounts]
- name: Create optional additional local service accounts
ansible.builtin.user:
name: "{{ item.name }}"
comment: "{{ item.comment | default('Local service account, managed via Ansible') }}"
system: "{{ item.system | default(true) }}"
shell: "{{ item.shell | default('/sbin/nologin') }}"
create_home: "{{ item.create_home | default(false) }}"
state: present
loop: "{{ local_service_accounts }}"
loop_control:
label: "{{ item.name }}"
when: local_service_accounts | length > 0
tags: [local_accounts]