ansible/roles/users/tasks/woodpecker.yml

41 lines
935 B
YAML
Raw Normal View History

2022-08-30 15:06:40 +02:00
- name: create group 'woodpecker'
group:
name: woodpecker
gid: 502
- name: create user 'woodpecker'
user:
name: woodpecker
2022-08-30 15:34:11 +02:00
uid: 502
2022-08-30 15:06:40 +02:00
group: woodpecker
home: /var/lib/woodpecker
password: "*" # disabled password but can be accessed with SSH
groups:
- woodpecker
- name: make sure woodpecker owns its home
file:
state: directory
path: /var/lib/woodpecker
owner: woodpecker
group: woodpecker
mode: '2755'
- name: set woodpecker's authorized keys
authorized_key:
user: woodpecker
key: '{{ item }}'
path: /var/lib/woodpecker/.ssh/authorized_keys
with_file:
- public_keys/yubikey
- public_keys/woodpecker
2022-08-30 15:10:01 +02:00
- name: commit woodpecker's home to lbu
lbu:
include:
- /var/lib/woodpecker
- /var/lib/woodpecker/.ssh/authorized_keys
exclude:
- /var/lib/woodpecker/.ash_history
2022-08-30 17:39:14 +02:00
when: ansible_distribution == "Alpine" and use_lbu