From a06b1d633eecf703e80201cc2c5cbda7de8f7135 Mon Sep 17 00:00:00 2001 From: jaydee Date: Tue, 19 May 2026 23:58:46 +0200 Subject: [PATCH] build --- roles/init/tasks/main.yml | 146 ++++++++++++++++++++++++++++++++++++++ 1 file changed, 146 insertions(+) diff --git a/roles/init/tasks/main.yml b/roles/init/tasks/main.yml index 282cb0b..f16d7c5 100755 --- a/roles/init/tasks/main.yml +++ b/roles/init/tasks/main.yml @@ -72,3 +72,149 @@ regexp: "^127.0.0.1 .*" line: "127.0.0.1 {{ inventory_hostname }} {{ inventory_hostname.split('.')[0] }}" state: present + + - name: Install required dependencies + ansible.builtin.dnf: + name: + - dnf-plugins-core + - curl + state: present + + - name: Add HashiCorp repository + ansible.builtin.get_url: + url: https://rpm.releases.hashicorp.com/RHEL/hashicorp.repo + dest: /etc/yum.repos.d/hashicorp.repo + mode: "0644" + + - name: Clean DNF cache + ansible.builtin.command: dnf clean all + changed_when: false + + - name: Install Vault + ansible.builtin.dnf: + name: vault + state: present + update_cache: yes + + - name: Set vault address + copy: + dest: /etc/profile.d/vault.sh + content: "export VAULT_ADDR=http://vault.home.lan:8205\n" + owner: root + group: root + mode: '0644' + + - name: Read SSH CA public key from Vault + ansible.builtin.command: + cmd: vault read -field=public_key ssh/config/ca + register: vault_ca + changed_when: false + environment: + VAULT_ADDR: "{{ vault_addr }}" + VAULT_TOKEN: "{{ vault_token }}" + + - name: Install trusted SSH user CA + ansible.builtin.copy: + content: "{{ vault_ca.stdout }}\n" + dest: /etc/ssh/trusted-user-ca-keys.pem + owner: root + group: root + mode: '0644' + + - name: Enable Trusted User CA + ansible.builtin.lineinfile: + path: /etc/ssh/sshd_config + regexp: "^TrustedUserCAKeys" + line: "TrustedUserCAKeys /etc/ssh/trusted-user-ca-keys.pem" + state: present + + - name: Enable PubkeyAuthentication + ansible.builtin.lineinfile: + path: /etc/ssh/sshd_config + regexp: "^PubkeyAuthentication.*" + line: "PubkeyAuthentication yes" + state: present + + - name: Create vault agent dir + file: + path: /etc/vault-agent + state: directory + owner: root + group: root + mode: '0644' + + - name: Create vault agent config + copy: + dest: /etc/vault-agent/config.hcl + content: | + vault { + address = "http://vault.home.lan:8205" + } + + auto_auth { + method "token_file" { + config = { + token_file_path = "/etc/vault-agent/token" + } + } + + sink "file" { + config = { + path = "/tmp/vault-token" + } + } + } + + template { + destination = "/home/jd/.ssh/id_ed25519-cert.pub" + perms = "0644" + user = "jd" + group = "jd" + contents = <