Files @ 770551dc8c6f
Branch filter:

Location: majic-ansible-roles/roles/bootstrap/tasks/main.yml

branko
MAR-148: Improve the SSH connectivity tests in backup_server role to be more reliable:

- Introduce a session-level fixture for setting permissions for client
SSH private keys (fixes errors related to SSH requesting tighter
permissions).
- Add assertions for the tests that verify the backup clients cannot
connect to the regular SSH server in case the SSH private keys do
not have correct permissions (just in case).
---

- name: Install sudo
  apt:
    name: sudo
    state: present

- name: Set-up the Ansible group
  group:
    name: ansible
    system: true

- name: Set-up the Ansible user
  user:
    name: ansible
    system: true
    group: ansible
    shell: /bin/bash

- name: Set-up authorized key for the Ansible user
  authorized_key:
    user: ansible
    key: "{{ ansible_key }}"

- name: Set-up password-less sudo for the ansible user
  copy:
    src: "ansible_sudo"
    dest: "/etc/sudoers.d/ansible"
    mode: 0640
    owner: root
    group: root

- name: Revoke rights for Ansible user to log-in as root to server via ssh
  authorized_key:
    user: root
    key: "{{ ansible_key }}"
    state: absent

- name: Explicitly run all handlers
  include: ../handlers/main.yml
  when: "run_handlers | default(False) | bool()"
  tags:
    - handlers