X-Git-Url: https://git.realraum.at/?a=blobdiff_plain;f=ansible%2Fhost_vars%2Ftorwaechter%2Fmain.yml;h=9e9e990a2bc6bfdaca93d9e36c899dd73847bcb0;hb=a3d5e25cfdd49ba6fb525abcf3704afdc6e018c8;hp=2a2316f49d4d43e7b45b26316c35b1fd47eaa052;hpb=630b0f012f1b6a579cffddfcf20f0574e5d21a9f;p=noc.git diff --git a/ansible/host_vars/torwaechter/main.yml b/ansible/host_vars/torwaechter/main.yml index 2a2316f..9e9e990 100644 --- a/ansible/host_vars/torwaechter/main.yml +++ b/ansible/host_vars/torwaechter/main.yml @@ -1,9 +1,13 @@ --- +ssh_users_tuergit: "{{ user_groups.noc | union(['fgenesis']) }}" + +openwrt_variant: openwrt +openwrt_release: 18.06.4 openwrt_arch: x86 openwrt_target: geode openwrt_output_image_suffixes: - combined-ext4.img.gz - - combined-squashfs.img + - combined-squashfs.img.gz openwrt_packages_extra: - "-dropbear" @@ -16,8 +20,15 @@ openwrt_packages_extra: - screen - sudo - usbutils + - rsync + - lsblk openwrt_mixin: + /home: + directory: + /run: + link: "/var/run" + # Go binaries /usr/local/bin/door_client: mode: '0755' @@ -29,13 +40,33 @@ openwrt_mixin: mode: '0755' file: "{{ global_cache_dir }}/{{ inventory_hostname }}/door_and_sensors/update-keys/update-keys" + # door daemon init scripts and configs + /etc/init.d/doord: + mode: '0755' + file: "{{ global_cache_dir }}/{{ inventory_hostname }}/door_and_sensors/initscripts/doord.openwrt" + /etc/default/door: + mode: '0755' + file: "{{ global_cache_dir }}/{{ inventory_hostname }}/door_and_sensors/initscripts/door.default" + /etc/default/tuer: + link: "./door" + /etc/rc.d/S50doord: + link: "../init.d/doord" + + # hotplug files + /etc/hotplug.d/tty/door.tty: + mode: '0755' + file: "{{ global_cache_dir }}/{{ inventory_hostname }}/door_and_sensors/scripts/door.tty" + /etc/hotplug.d/usb/door.usb: + mode: '0755' + file: "{{ global_cache_dir }}/{{ inventory_hostname }}/door_and_sensors/scripts/door.usb" + /usr/local/bin/authorized_keys.sh: mode: '0755' - file: "{{ global_artifacts_dir }}/{{ inventory_hostname }}/authorized_keys.sh" + file: "{{ global_files_dir }}/{{ inventory_hostname }}/authorized_keys.sh" /usr/local/bin/update-keys-from-stdin.sh: mode: '0755' - file: "{{ global_artifacts_dir }}/{{ inventory_hostname }}/update-keys-from-stdin.sh" + file: "{{ global_files_dir }}/{{ inventory_hostname }}/update-keys-from-stdin.sh" /etc/ssh/sshd_config: content: | @@ -58,16 +89,10 @@ openwrt_mixin: AuthorizedKeysCommandUser tuergit /etc/ssh/authorized_keys.d/root: - content: |- - {% for key in noc_ssh_keys %} - {{ key }} - {% endfor %} + content: "{{ ssh_users_root | user_ssh_keys(users) | join('\n') }}\n" /etc/ssh/authorized_keys.d/tuergit: - content: |- - {% for key in noc_ssh_keys %} - {{ key }} - {% endfor %} + content: "{{ ssh_users_tuergit | user_ssh_keys(users) | join('\n') }}\n" openwrt_uci: system: @@ -113,6 +138,7 @@ openwrt_uci: dns_search: realraum.at +# does not work, using symlink to /var/run instead for now openwrt_mounts: - path: /run src: none