common: Validate sshd_config before applying

master
Felix Stupp 4 years ago
parent e1a612966c
commit 15ad953131
Signed by: zocker
GPG Key ID: 93E1BD26F6B02FB7

@ -61,6 +61,7 @@ global_ssh_key_directory: "{{ global_public_key_directory }}/ssh"
global_ssh_host_key_directory: "{{ global_ssh_key_directory }}/hosts" global_ssh_host_key_directory: "{{ global_ssh_key_directory }}/hosts"
global_validate_shell_script: "/usr/bin/shellcheck %s" # TODO add "--format=" global_validate_shell_script: "/usr/bin/shellcheck %s" # TODO add "--format="
global_validate_sshd_config: "/usr/sbin/sshd -t -f %s"
global_validate_sudoers_file: "/usr/sbin/visudo -c -f %s" global_validate_sudoers_file: "/usr/sbin/visudo -c -f %s"
global_wireguard_private_directory: "{{ global_credentials_directory }}/wireguard" global_wireguard_private_directory: "{{ global_credentials_directory }}/wireguard"

@ -35,6 +35,7 @@
owner: root owner: root
group: root group: root
mode: "u=rw,g=r,o=r" mode: "u=rw,g=r,o=r"
validate: "{{ global_validate_sshd_config }}"
notify: reassemble sshd config notify: reassemble sshd config
- name: Upload main ssh_config - name: Upload main ssh_config

Loading…
Cancel
Save