Skip to content
Snippets Groups Projects
Commit a76410c5 authored by ale's avatar ale
Browse files

Do not run SSH-related tasks unless enable_ssh is set

parent 38c6838f
No related branches found
No related tags found
No related merge requests found
...@@ -33,19 +33,13 @@ ...@@ -33,19 +33,13 @@
dest: "{{ vars_dir }}/secrets.yml" dest: "{{ vars_dir }}/secrets.yml"
state: link state: link
# Generate the SSH CA.
- name: Generate SSH CA - name: Generate SSH CA
local_action: sshca ca="{{ credentials_dir }}/ssh/key" local_action: sshca ca="{{ credentials_dir }}/ssh/key"
when: enable_ssh
# Generate the SSO ED25519 key pair.
- name: Generate SSO credentials - name: Generate SSO credentials
local_action: ed25519 privkey="{{ credentials_dir }}/sso/secret.key" pubkey="{{ credentials_dir }}/sso/public.key" local_action: ed25519 privkey="{{ credentials_dir }}/sso/secret.key" pubkey="{{ credentials_dir }}/sso/public.key"
# Generate all the X509 service credentials. The first time this
# runs, the service CA will be initialized too.
#- name: Generate X509 credentials for all services
# local_action: x509 ca_root="{{ credentials_dir }}/x509" ca_subject="{{ x509_ca_subject | default('') }}" domain="{{ domain }}"
- name: Generate global DH params - name: Generate global DH params
local_action: command openssl dhparam -out "{{ credentials_dir }}/x509/dhparam" "{{ dhparam_bits | default('2048') }}" creates="{{ credentials_dir }}/x509/dhparam" local_action: command openssl dhparam -out "{{ credentials_dir }}/x509/dhparam" "{{ dhparam_bits | default('2048') }}" creates="{{ credentials_dir }}/x509/dhparam"
......
...@@ -9,3 +9,5 @@ ...@@ -9,3 +9,5 @@
copy: copy:
dest: /etc/ssh/authorized_keys/vagrant dest: /etc/ssh/authorized_keys/vagrant
content: "ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEA6NF8iallvQVp22WDkTkyrtvp9eWW6A8YVr+kz4TjGYe7gHzIw+niNltGEFHzD8+v1I2YJ6oXevct1YeS0o9HZyN1Q9qgCgzUFtdOKLv6IedplqoPkcmF0aYet2PkEDo3MlTBckFXPITAMzF8dJSIFo9D8HfdOV0IAdx4O7PtixWKn5y2hMNG0zQPyUecp4pzC6kivAIhyfHilFR61RGL+GPXQ2MWZWFYbAGjyiYJnAmCP3NOTd0jMZEnDkbUvxhMmBYSdETk1rRgm+R4LOzFUGaHqHDLKLX+FIPKcF96hrucXzcWyLbIbEgE98OHlnVYCzRdK8jlqm8tehUc9c9WhQ== vagrant insecure public key" content: "ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAQEA6NF8iallvQVp22WDkTkyrtvp9eWW6A8YVr+kz4TjGYe7gHzIw+niNltGEFHzD8+v1I2YJ6oXevct1YeS0o9HZyN1Q9qgCgzUFtdOKLv6IedplqoPkcmF0aYet2PkEDo3MlTBckFXPITAMzF8dJSIFo9D8HfdOV0IAdx4O7PtixWKn5y2hMNG0zQPyUecp4pzC6kivAIhyfHilFR61RGL+GPXQ2MWZWFYbAGjyiYJnAmCP3NOTd0jMZEnDkbUvxhMmBYSdETk1rRgm+R4LOzFUGaHqHDLKLX+FIPKcF96hrucXzcWyLbIbEgE98OHlnVYCzRdK8jlqm8tehUc9c9WhQ== vagrant insecure public key"
when: enable_ssh
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Please register or to comment