feat(bootstrap-infra-ops): create new accounts at the fleet-pinned uid/gid 850
docs/pfi/fleet-conventions.md § 3 pins infra-ops to 850, but the bootstrap playbook let the OS allocate, so every host drifted (1001-2001). New accounts now get 850 when uid and gid 850 are both free, and fall back to OS allocation (with a note) when either is taken. The home is set to 0700 per § 1.2. Existing accounts are untouched (the step is gated on id). Scope note: vm-esh-nas is added to the operator-granted ESH exceptions (Prime, 2026-09-27).
This commit is contained in:
@@ -24,21 +24,35 @@
|
|||||||
# ALL FOUR PVE HYPERVISORS (pfi-pve, nh3-pve, esh-pve,
|
# ALL FOUR PVE HYPERVISORS (pfi-pve, nh3-pve, esh-pve,
|
||||||
# esh-pve-nas) DO get infra-ops — done that day.
|
# esh-pve-nas) DO get infra-ops — done that day.
|
||||||
# PVE ships without sudo: `apt-get install sudo` first.
|
# PVE ships without sudo: `apt-get install sudo` first.
|
||||||
|
# Also granted by operator request: esh-docker-vm,
|
||||||
|
# esh-vm-db (2026-08-24) and vm-esh-nas (2026-09-27).
|
||||||
# - nh3-nas (Synology DSM) (no standard useradd / sudoers.d)
|
# - nh3-nas (Synology DSM) (no standard useradd / sudoers.d)
|
||||||
#
|
#
|
||||||
# Idempotent: re-running reconciles the key + sudoers without error.
|
# Idempotent: re-running reconciles the key + sudoers without error.
|
||||||
|
|
||||||
vars:
|
vars:
|
||||||
ops_user: infra-ops
|
ops_user: infra-ops
|
||||||
|
ops_uid: "850"
|
||||||
ops_pubkey: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIN+1HBwfXrkfTYWdcnWCjLJ6VLAGC87gxH5h5vKaaA3c infra-ops@pfi-fleet"
|
ops_pubkey: "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIN+1HBwfXrkfTYWdcnWCjLJ6VLAGC87gxH5h5vKaaA3c infra-ops@pfi-fleet"
|
||||||
# Optional authorized_keys from="..." source restriction. Empty = none.
|
# Optional authorized_keys from="..." source restriction. Empty = none.
|
||||||
# Hardening follow-up once per-path source IPs (LAN vs WG tunnel) are pinned.
|
# Hardening follow-up once per-path source IPs (LAN vs WG tunnel) are pinned.
|
||||||
ssh_from: ""
|
ssh_from: ""
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- name: Create the infra-ops system user (home + bash shell)
|
# New accounts get the fleet-pinned UID/GID 850 (docs/pfi/fleet-conventions.md § 3)
|
||||||
|
# when both are free. Otherwise the OS allocates, as every pre-2026-09-27 host did.
|
||||||
|
- name: Create the infra-ops system user (home + bash shell; uid/gid 850 when free)
|
||||||
sudo: true
|
sudo: true
|
||||||
shell: useradd -m -s /bin/bash {{ ops_user }}
|
shell: |
|
||||||
|
set -eu
|
||||||
|
if ! getent passwd {{ ops_uid }} >/dev/null && ! getent group {{ ops_uid }} >/dev/null; then
|
||||||
|
groupadd -g {{ ops_uid }} {{ ops_user }}
|
||||||
|
useradd -m -s /bin/bash -u {{ ops_uid }} -g {{ ops_uid }} {{ ops_user }}
|
||||||
|
else
|
||||||
|
echo "uid/gid {{ ops_uid }} taken; letting the OS allocate"
|
||||||
|
useradd -m -s /bin/bash {{ ops_user }}
|
||||||
|
fi
|
||||||
|
chmod 0700 /home/{{ ops_user }}
|
||||||
when: "! id {{ ops_user }} >/dev/null 2>&1"
|
when: "! id {{ ops_user }} >/dev/null 2>&1"
|
||||||
|
|
||||||
- name: Add infra-ops to the docker group (only if docker is installed)
|
- name: Add infra-ops to the docker group (only if docker is installed)
|
||||||
|
|||||||
Reference in New Issue
Block a user