diff --git a/ansible-role/tasks/main.yml b/ansible-role/tasks/main.yml new file mode 100644 index 0000000..55ed839 --- /dev/null +++ b/ansible-role/tasks/main.yml @@ -0,0 +1,52 @@ +--- +- name: Add the AuthForge PPA + ansible.builtin.apt_repository: + repo: "{{ authforge_ppa }}" + state: present + update_cache: true + +- name: Install AuthForge headless components + ansible.builtin.apt: + name: + - authforge-daemon + - authforge-pam + - authforge-cli + state: present + update_cache: true + +- name: Install AuthForge GUI (optional) + ansible.builtin.apt: + name: authforge-gui + state: present + when: authforge_install_gui | bool + +- name: Ensure /etc/authforge/policy.d exists + ansible.builtin.file: + path: /etc/authforge/policy.d + state: directory + owner: root + group: root + mode: "0755" + +- name: Render fleet policy file + ansible.builtin.template: + src: policy.conf.j2 + dest: /etc/authforge/policy.d/90-fleet.conf + owner: root + group: root + mode: "0644" + notify: restart authforge-daemon + +- name: Mark users as pending-enrollment + ansible.builtin.command: + argv: + - authforgectl + - pending + - set + - "{{ item.user }}" + - --methods + - "{{ item.methods | join(',') }}" + loop: "{{ authforge_pending_users }}" + loop_control: + label: "{{ item.user }}" + changed_when: true diff --git a/ansible-role/templates/policy.conf.j2 b/ansible-role/templates/policy.conf.j2 new file mode 100644 index 0000000..c9d56cf --- /dev/null +++ b/ansible-role/templates/policy.conf.j2 @@ -0,0 +1,18 @@ +# {{ ansible_managed }} +# Fleet-managed AuthForge policy. Hand-edits will be overwritten on the next +# Ansible run. To override locally, drop a higher-numbered file in +# /etc/authforge/policy.d/ (e.g. 99-local.conf). + +{% for stack, cfg in authforge_stacks.items() %} +[stacks.{{ stack }}] +mode = "{{ cfg.mode }}" +methods = {{ cfg.methods | to_json }} + +{% endfor %} +[storage] +backend = "{{ authforge_storage_backend }}" +central_path = "{{ authforge_storage_central_path }}" + +[firstrun] +default_required_methods = {{ authforge_firstrun_methods | to_json }} +deadline_hours = {{ authforge_firstrun_deadline_hours }}