summaryrefslogtreecommitdiff
path: root/roles/core
diff options
context:
space:
mode:
authorChristian Pointner <equinox@spreadspace.org>2021-04-22 23:35:28 +0200
committerChristian Pointner <equinox@spreadspace.org>2021-04-22 23:35:28 +0200
commit30afd60db59e68915ae4b48a8e00ee289e451ec6 (patch)
treed7bd21009365b7b49afcffd6731e2e751778a437 /roles/core
parentcosmetic changes (diff)
minor sshd role refactoring
Diffstat (limited to 'roles/core')
-rw-r--r--roles/core/sshd/base/tasks/main.yml30
1 files changed, 15 insertions, 15 deletions
diff --git a/roles/core/sshd/base/tasks/main.yml b/roles/core/sshd/base/tasks/main.yml
index 15ae6032..9793d831 100644
--- a/roles/core/sshd/base/tasks/main.yml
+++ b/roles/core/sshd/base/tasks/main.yml
@@ -7,6 +7,21 @@
- "{{ ansible_os_family }}.yml"
include_vars: "{{ item }}"
+- name: install config barriers for other roles to use
+ loop:
+ - line: "### ansible core/sshd/base config barrier ###"
+ insertbefore: "### ansible core/sshd config barrier ###"
+ - line: "### ansible core/sshd config barrier ###"
+ insertafter: "### ansible core/sshd/base config barrier ###"
+ loop_control:
+ label: "{{ item.line }}"
+ lineinfile:
+ dest: /etc/ssh/sshd_config
+ line: "{{ item.line }}"
+ insertbefore: "{{ item.insertbefore | default(omit) }}"
+ insertafter: "{{ item.insertafter | default(omit) }}"
+ notify: restart ssh
+
- name: hardening ssh-server config
vars:
sshd_options:
@@ -68,21 +83,6 @@
state: absent
notify: restart ssh
-- name: install config barriers for other roles to use
- loop:
- - line: "### ansible core/sshd/base config barrier ###"
- insertbefore: "### ansible core/sshd config barrier ###"
- - line: "### ansible core/sshd config barrier ###"
- insertafter: "### ansible core/sshd/base config barrier ###"
- loop_control:
- label: "{{ item.line }}"
- lineinfile:
- dest: /etc/ssh/sshd_config
- line: "{{ item.line }}"
- insertbefore: "{{ item.insertbefore | default(omit) }}"
- insertafter: "{{ item.insertafter | default(omit) }}"
- notify: restart ssh
-
- name: install ssh keys for root
authorized_key:
user: root