diff --git a/ansible/group_vars/all b/ansible/group_vars/all index f1b531bdd7b2b87183ec59c9ffeb81ce1c043b94..59f66120846a71436765cd010c51eda633854018 100644 --- a/ansible/group_vars/all +++ b/ansible/group_vars/all @@ -34,11 +34,10 @@ - /gpfs5 #SSH Host Keys - s3_endpoint: "" - ssh_host_keys_s3_bucket: "" - ssh_host_keys_s3_object: "" + S3_ENDPOINT: "" + SSH_HOST_KEYS_S3_BUCKET: "" + SSH_HOST_KEYS_S3_OBJECT: "" # AWS credentials - lts_access_key: "" - lts_secret_key: "" - + LTS_ACCESS_KEY: "" + LTS_SECRET_KEY: "" diff --git a/ansible/roles/ssh_host_keys/tasks/main.yml b/ansible/roles/ssh_host_keys/tasks/main.yml index cec0cb1ad9b6b0415c3764fa629c82151c8d55eb..aed8c6211cfe139aca551f7c1ece1977ed21ef32 100644 --- a/ansible/roles/ssh_host_keys/tasks/main.yml +++ b/ansible/roles/ssh_host_keys/tasks/main.yml @@ -10,18 +10,18 @@ - name: Download SSH host keys tar.gz from S3 aws_s3: mode: get - s3_url: "{{ s3_endpoint }}" - bucket: "{{ ssh_host_keys_s3_bucket }}" - object: "{{ ssh_host_keys_s3_object }}" - dest: "/tmp/ssh_keys/{{ ssh_host_keys_s3_object }}" - aws_access_key: "{{ lts_access_key }}" - aws_secret_key: "{{ lts_secret_key }}" + s3_url: "{{ S3_ENDPOINT }}" + bucket: "{{ SSH_HOST_KEYS_S3_BUCKET }}" + object: "{{ SSH_HOST_KEYS_S3_OBJECT }}" + dest: "/tmp/ssh_keys/{{ SSH_HOST_KEYS_S3_OBJECT }}" + aws_access_key: "{{ LTS_ACCESS_KEY }}" + aws_secret_key: "{{ LTS_SECRET_KEY }}" vars: ansible_python_interpreter: /usr/bin/python3 - name: Unpack SSH host keys to /etc/ssh unarchive: - src: "/tmp/ssh_keys/{{ ssh_host_keys_s3_object }}" + src: "/tmp/ssh_keys/{{ SSH_HOST_KEYS_S3_OBJECT }}" dest: "/etc/ssh" remote_src: yes become: true @@ -30,4 +30,4 @@ ansible.builtin.service: name: sshd state: restarted - become: true \ No newline at end of file + become: true