diff --git a/ansible/roles/bastion/tasks/sudoers.yml b/ansible/roles/bastion/tasks/sudoers.yml index ca03846..d703a74 100755 --- a/ansible/roles/bastion/tasks/sudoers.yml +++ b/ansible/roles/bastion/tasks/sudoers.yml @@ -5,7 +5,7 @@ state: present - name: "get current users" - shell: "cat /etc/passwd | egrep -iv '(false|nologin|sync|root)' | awk -F: '{print $1}'" + shell: "cat /etc/passwd | egrep -iv '(false|nologin|sync|root|dev2-iac)' | awk -F: '{print $1}'" register: deleting_users - name: "Delete users" diff --git a/ansible/roles/bastion/templates/allow_users.j2 b/ansible/roles/bastion/templates/allow_users.j2 index ad7f003..fab55dc 100755 --- a/ansible/roles/bastion/templates/allow_users.j2 +++ b/ansible/roles/bastion/templates/allow_users.j2 @@ -1,3 +1,4 @@ +AllowUsers dev2-iac@10.10.43.* {% if admin_users is defined %} {% for user in admin_users %} AllowUsers {{ user.name }}@{{ user.ip }}