Add user_password.yml
This commit is contained in:
@@ -0,0 +1,51 @@
|
|||||||
|
---
|
||||||
|
# set_user_password.yml
|
||||||
|
#
|
||||||
|
# Sets a user's password and forces them to change it on next login.
|
||||||
|
#
|
||||||
|
# Usage:
|
||||||
|
# ansible-playbook set_user_password.yml \
|
||||||
|
# -i inventory.ini \
|
||||||
|
# -e "target_user=alice new_password=TempPass123!"
|
||||||
|
#
|
||||||
|
# Variables (pass with -e or define in vars/group_vars):
|
||||||
|
# target_user – the Linux username to configure (required)
|
||||||
|
# new_password – the plaintext temporary password (required)
|
||||||
|
|
||||||
|
- name: Set user password and force change on next login
|
||||||
|
hosts: all
|
||||||
|
become: true
|
||||||
|
|
||||||
|
vars:
|
||||||
|
target_user: "{{ target_user | mandatory }}"
|
||||||
|
new_password: "{{ new_password | mandatory }}"
|
||||||
|
|
||||||
|
tasks:
|
||||||
|
|
||||||
|
- name: Ensure the user account exists
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: "{{ target_user }}"
|
||||||
|
state: present
|
||||||
|
shell: /bin/bash
|
||||||
|
|
||||||
|
- name: Set the user's password (hashed)
|
||||||
|
ansible.builtin.user:
|
||||||
|
name: "{{ target_user }}"
|
||||||
|
# password filter hashes the plaintext with SHA-512
|
||||||
|
password: "{{ new_password | password_hash('sha512') }}"
|
||||||
|
update_password: always
|
||||||
|
|
||||||
|
- name: Force password change on next login (chage -d 0)
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: "chage -d 0 {{ target_user }}"
|
||||||
|
changed_when: true # chage always returns 0; mark as changed for clarity
|
||||||
|
|
||||||
|
- name: Verify password expiry settings
|
||||||
|
ansible.builtin.command:
|
||||||
|
cmd: "chage -l {{ target_user }}"
|
||||||
|
register: chage_output
|
||||||
|
changed_when: false
|
||||||
|
|
||||||
|
- name: Show password expiry info
|
||||||
|
ansible.builtin.debug:
|
||||||
|
var: chage_output.stdout_lines
|
||||||
Reference in New Issue
Block a user