updates
This commit is contained in:
@@ -0,0 +1,6 @@
|
||||
---
|
||||
gitea_ssh_host: git.aimloperations.com
|
||||
gitea_ssh_port: 30009
|
||||
gitea_key_path: "/home/{{ admin_user }}/.ssh/id_ed25519"
|
||||
# Any repo the deploy user should be able to read; used only as an access probe.
|
||||
gitea_test_repo: "ai_ml_operations/company_site.git"
|
||||
@@ -0,0 +1,74 @@
|
||||
---
|
||||
# Per-server SSH key for cloning from Gitea.
|
||||
# 1. Generate an ed25519 key for the deploy user (if absent).
|
||||
# 2. Configure SSH for the Gitea host (port + identity).
|
||||
# 3. Test access first; only surface the "add this key" step when it's missing.
|
||||
|
||||
- name: gitea-key | ensure .ssh dir
|
||||
ansible.builtin.file:
|
||||
path: "/home/{{ admin_user }}/.ssh"
|
||||
state: directory
|
||||
owner: "{{ admin_user }}"
|
||||
group: "{{ admin_user }}"
|
||||
mode: "0700"
|
||||
|
||||
- name: gitea-key | generate deploy key
|
||||
become_user: "{{ admin_user }}"
|
||||
ansible.builtin.command:
|
||||
cmd: "ssh-keygen -t ed25519 -N '' -f {{ gitea_key_path }} -C '{{ admin_user }}@{{ inventory_hostname }}-gitea'"
|
||||
creates: "{{ gitea_key_path }}"
|
||||
|
||||
- name: gitea-key | configure SSH for Gitea host
|
||||
become_user: "{{ admin_user }}"
|
||||
ansible.builtin.blockinfile:
|
||||
path: "/home/{{ admin_user }}/.ssh/config"
|
||||
create: true
|
||||
owner: "{{ admin_user }}"
|
||||
group: "{{ admin_user }}"
|
||||
mode: "0600"
|
||||
marker: "# {mark} ANSIBLE MANAGED gitea"
|
||||
block: |
|
||||
Host {{ gitea_ssh_host }}
|
||||
User git
|
||||
Port {{ gitea_ssh_port }}
|
||||
IdentityFile {{ gitea_key_path }}
|
||||
IdentitiesOnly yes
|
||||
StrictHostKeyChecking accept-new
|
||||
|
||||
- name: gitea-key | read public key
|
||||
ansible.builtin.slurp:
|
||||
src: "{{ gitea_key_path }}.pub"
|
||||
register: _gitea_pubkey
|
||||
|
||||
- name: gitea-key | check Gitea access (permission probe)
|
||||
become_user: "{{ admin_user }}"
|
||||
ansible.builtin.command:
|
||||
cmd: "git ls-remote {{ git_base_url }}/{{ gitea_test_repo }}"
|
||||
register: _gitea_access
|
||||
failed_when: false
|
||||
changed_when: false
|
||||
|
||||
- name: gitea-key | access OK
|
||||
ansible.builtin.debug:
|
||||
msg: "{{ inventory_hostname }} already has Gitea access; nothing to add."
|
||||
when: _gitea_access.rc == 0
|
||||
|
||||
- name: gitea-key | ADD THIS KEY to Gitea (access missing)
|
||||
ansible.builtin.debug:
|
||||
msg: |
|
||||
================= ACTION REQUIRED on {{ inventory_hostname }} =================
|
||||
This server cannot reach Gitea yet. Add its public key:
|
||||
|
||||
{{ _gitea_pubkey.content | b64decode | trim }}
|
||||
|
||||
Where (either works):
|
||||
* User key : Gitea > Settings > SSH / GPG Keys > Add Key
|
||||
* Deploy key: repo > Settings > Deploy Keys (per repo, read-only)
|
||||
Then re-run provisioning to continue.
|
||||
==============================================================================
|
||||
when: _gitea_access.rc != 0
|
||||
|
||||
- name: gitea-key | fail until key is added
|
||||
ansible.builtin.fail:
|
||||
msg: "No Gitea access from {{ inventory_hostname }}. Add the key shown above, then re-run."
|
||||
when: _gitea_access.rc != 0
|
||||
Reference in New Issue
Block a user