mirror of
https://gitlab.sectorq.eu/jaydee/ansible.git
synced 2026-09-08 21:27:36 +02:00
build-all
This commit is contained in:
Executable
+153
@@ -0,0 +1,153 @@
|
||||
- name: Setup vault SSH keys
|
||||
become: "{{ 'no' if inventory_hostname in ['sectorq.cloud', 'nas.home.lan'] else 'yes' }}"
|
||||
block:
|
||||
|
||||
- name: Include vault
|
||||
ansible.builtin.include_vars:
|
||||
file: init.yml
|
||||
|
||||
- name: Install required dependencies
|
||||
ansible.builtin.dnf:
|
||||
name:
|
||||
- dnf-plugins-core
|
||||
- curl
|
||||
state: present
|
||||
|
||||
- name: Add HashiCorp repository
|
||||
ansible.builtin.get_url:
|
||||
url: https://rpm.releases.hashicorp.com/RHEL/hashicorp.repo
|
||||
dest: /etc/yum.repos.d/hashicorp.repo
|
||||
mode: "0644"
|
||||
|
||||
- name: Clean DNF cache
|
||||
ansible.builtin.command: dnf clean all
|
||||
changed_when: false
|
||||
|
||||
- name: Install Vault
|
||||
ansible.builtin.dnf:
|
||||
name: vault
|
||||
state: present
|
||||
update_cache: yes
|
||||
|
||||
- name: Set vault address
|
||||
copy:
|
||||
dest: /etc/profile.d/vault.sh
|
||||
content: "export VAULT_ADDR=http://vault.home.lan:8205\n"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Read SSH CA public key from Vault
|
||||
ansible.builtin.command:
|
||||
cmd: vault read -field=public_key ssh/config/ca
|
||||
register: vault_ca
|
||||
changed_when: false
|
||||
environment:
|
||||
VAULT_ADDR: "{{ vault_addr }}"
|
||||
VAULT_TOKEN: "{{ vault_token }}"
|
||||
|
||||
- name: Install trusted SSH user CA
|
||||
ansible.builtin.copy:
|
||||
content: "{{ vault_ca.stdout }}\n"
|
||||
dest: /etc/ssh/trusted-user-ca-keys.pem
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Enable Trusted User CA
|
||||
ansible.builtin.lineinfile:
|
||||
path: /etc/ssh/sshd_config
|
||||
regexp: "^TrustedUserCAKeys"
|
||||
line: "TrustedUserCAKeys /etc/ssh/trusted-user-ca-keys.pem"
|
||||
state: present
|
||||
|
||||
- name: Enable PubkeyAuthentication
|
||||
ansible.builtin.lineinfile:
|
||||
path: /etc/ssh/sshd_config
|
||||
regexp: "^PubkeyAuthentication.*"
|
||||
line: "PubkeyAuthentication yes"
|
||||
state: present
|
||||
|
||||
- name: Create vault agent dir
|
||||
file:
|
||||
path: /etc/vault-agent
|
||||
state: directory
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Create vault agent config
|
||||
copy:
|
||||
dest: /etc/vault-agent/config.hcl
|
||||
content: |
|
||||
vault {
|
||||
address = "http://vault.home.lan:8205"
|
||||
}
|
||||
|
||||
auto_auth {
|
||||
method "token_file" {
|
||||
config = {
|
||||
token_file_path = "/etc/vault-agent/token"
|
||||
}
|
||||
}
|
||||
|
||||
sink "file" {
|
||||
config = {
|
||||
path = "/tmp/vault-token"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
template {
|
||||
destination = "/home/jd/.ssh/id_ed25519-cert.pub"
|
||||
perms = "0644"
|
||||
user = "jd"
|
||||
group = "jd"
|
||||
contents = <<EOH
|
||||
{{ '{{' }} with secret "ssh/sign/admin" (printf "public_key=%s" (trimSpace (file "/home/jd/.ssh/id_ed25519.pub"))) "valid_principals=jd" {{ '}}' }}
|
||||
{{ '{{' }} .Data.signed_key {{ '}}' }}
|
||||
{{ '{{' }} end {{ '}}' }}
|
||||
EOH
|
||||
}
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Create file with token for vault agent
|
||||
copy:
|
||||
dest: /etc/vault-agent/token
|
||||
content: "{{ vault_sshcert_token }}"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0600'
|
||||
|
||||
- name: Create service for vault agent
|
||||
copy:
|
||||
dest: /etc/systemd/system/vault-agent.service
|
||||
content: |
|
||||
[Unit]
|
||||
Description=Vault Agent
|
||||
After=network-online.target
|
||||
|
||||
[Service]
|
||||
ExecStart=/usr/bin/vault agent -config=/etc/vault-agent/config.hcl
|
||||
Restart=always
|
||||
User=root
|
||||
Group=root
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Enable and start vault agent service
|
||||
systemd:
|
||||
name: vault-agent
|
||||
enabled: yes
|
||||
state: started
|
||||
|
||||
- name: Restart sshd
|
||||
ansible.builtin.service:
|
||||
name: sshd
|
||||
state: restarted
|
||||
Reference in New Issue
Block a user