diff --git a/ansible/cluster.yml b/ansible/cluster.yml index ef6c9524e97c7ed8964449489b789f2e566ec77e..3197a1198d31246aa41952b3affce773a049a6db 100644 --- a/ansible/cluster.yml +++ b/ansible/cluster.yml @@ -7,3 +7,4 @@ - { name: 'nfs_mounts', tags: 'nfs_mounts' } - { name: 'ldap_config', tags: 'ldap_config' } - { name: 'slurm_client', tags: 'slurm_client', when: enable_slurm_client } + - { name: 'ssh_host_keys', tags: 'ssh_host_keys' } diff --git a/ansible/group_vars/all b/ansible/group_vars/all index e95c617fc3bb3b9a8e4b117d7468836226e34ea5..f1b531bdd7b2b87183ec59c9ffeb81ce1c043b94 100644 --- a/ansible/group_vars/all +++ b/ansible/group_vars/all @@ -33,3 +33,12 @@ - /gpfs4 - /gpfs5 +#SSH Host Keys + s3_endpoint: "" + ssh_host_keys_s3_bucket: "" + ssh_host_keys_s3_object: "" + +# AWS credentials + lts_access_key: "" + lts_secret_key: "" + diff --git a/ansible/roles/ssh_host_keys/tasks/main.yml b/ansible/roles/ssh_host_keys/tasks/main.yml new file mode 100644 index 0000000000000000000000000000000000000000..cec0cb1ad9b6b0415c3764fa629c82151c8d55eb --- /dev/null +++ b/ansible/roles/ssh_host_keys/tasks/main.yml @@ -0,0 +1,33 @@ +--- +- name: Ensure destination directory exists only if not present + file: + path: /tmp/ssh_keys + state: directory + mode: '0755' + args: + creates: /tmp/ssh_keys + +- name: Download SSH host keys tar.gz from S3 + aws_s3: + mode: get + s3_url: "{{ s3_endpoint }}" + bucket: "{{ ssh_host_keys_s3_bucket }}" + object: "{{ ssh_host_keys_s3_object }}" + dest: "/tmp/ssh_keys/{{ ssh_host_keys_s3_object }}" + aws_access_key: "{{ lts_access_key }}" + aws_secret_key: "{{ lts_secret_key }}" + vars: + ansible_python_interpreter: /usr/bin/python3 + +- name: Unpack SSH host keys to /etc/ssh + unarchive: + src: "/tmp/ssh_keys/{{ ssh_host_keys_s3_object }}" + dest: "/etc/ssh" + remote_src: yes + become: true + +- name: Restart SSH service + ansible.builtin.service: + name: sshd + state: restarted + become: true \ No newline at end of file