Add user_password.yml
This commit is contained in:
@@ -0,0 +1,51 @@
|
||||
---
|
||||
# set_user_password.yml
|
||||
#
|
||||
# Sets a user's password and forces them to change it on next login.
|
||||
#
|
||||
# Usage:
|
||||
# ansible-playbook set_user_password.yml \
|
||||
# -i inventory.ini \
|
||||
# -e "target_user=alice new_password=TempPass123!"
|
||||
#
|
||||
# Variables (pass with -e or define in vars/group_vars):
|
||||
# target_user – the Linux username to configure (required)
|
||||
# new_password – the plaintext temporary password (required)
|
||||
|
||||
- name: Set user password and force change on next login
|
||||
hosts: all
|
||||
become: true
|
||||
|
||||
vars:
|
||||
target_user: "{{ target_user | mandatory }}"
|
||||
new_password: "{{ new_password | mandatory }}"
|
||||
|
||||
tasks:
|
||||
|
||||
- name: Ensure the user account exists
|
||||
ansible.builtin.user:
|
||||
name: "{{ target_user }}"
|
||||
state: present
|
||||
shell: /bin/bash
|
||||
|
||||
- name: Set the user's password (hashed)
|
||||
ansible.builtin.user:
|
||||
name: "{{ target_user }}"
|
||||
# password filter hashes the plaintext with SHA-512
|
||||
password: "{{ new_password | password_hash('sha512') }}"
|
||||
update_password: always
|
||||
|
||||
- name: Force password change on next login (chage -d 0)
|
||||
ansible.builtin.command:
|
||||
cmd: "chage -d 0 {{ target_user }}"
|
||||
changed_when: true # chage always returns 0; mark as changed for clarity
|
||||
|
||||
- name: Verify password expiry settings
|
||||
ansible.builtin.command:
|
||||
cmd: "chage -l {{ target_user }}"
|
||||
register: chage_output
|
||||
changed_when: false
|
||||
|
||||
- name: Show password expiry info
|
||||
ansible.builtin.debug:
|
||||
var: chage_output.stdout_lines
|
||||
Reference in New Issue
Block a user