|
@@ -45,7 +45,7 @@
|
|
|
- /etc/ssh/ssh_host_ed25519_key.pub
|
|
|
- /etc/ssh/ssh_host_ecdsa_key.pub
|
|
|
|
|
|
- name: Force the use of internal-sftp subsystem fro SFTP
|
|
|
- name: Force the use of internal-sftp subsystem for SFTP
|
|
|
lineinfile:
|
|
|
path: /etc/ssh/sshd_config
|
|
|
regexp: "^Subsystem.*sftp"
|
|
@@ -94,15 +94,12 @@
|
|
|
|
|
|
- name: Change ownership of home directories for SFTP chroot to work
|
|
|
file:
|
|
|
path: "{{ item }}"
|
|
|
path: "/home/{{ item.name }}"
|
|
|
state: directory
|
|
|
owner: root
|
|
|
group: root
|
|
|
mode: 0755
|
|
|
with_items:
|
|
|
- /home/backupuser
|
|
|
- /home/bak-param-mandatory-buster
|
|
|
- /home/bak-param-mandatory-bullseye
|
|
|
with_items: "{{ backup_users }}"
|
|
|
|
|
|
- name: Set-up duplicity backup directories
|
|
|
file:
|
|
@@ -113,17 +110,6 @@
|
|
|
mode: 0770
|
|
|
with_items: "{{ backup_users }}"
|
|
|
|
|
|
|
|
|
- name: Set-up directories for parameters-optional backups
|
|
|
file:
|
|
|
path: "~backupuser/duplicity/{{ item }}"
|
|
|
state: directory
|
|
|
owner: backupuser
|
|
|
group: backupuser
|
|
|
mode: 0700
|
|
|
with_items:
|
|
|
- "param-optional-buster"
|
|
|
|
|
|
handlers:
|
|
|
- name: Restart ssh
|
|
|
service:
|
|
@@ -132,8 +118,6 @@
|
|
|
|
|
|
vars:
|
|
|
backup_users:
|
|
|
- name: bak-param-mandatory-buster
|
|
|
key: "{{ lookup('file', 'tests/data/ssh/parameters-mandatory.pub') }}"
|
|
|
- name: bak-param-mandatory-bullseye
|
|
|
key: "{{ lookup('file', 'tests/data/ssh/parameters-mandatory.pub') }}"
|
|
|
- name: backupuser
|