--- - name: Guard against lock-out when disabling password auth ansible.builtin.assert: that: - not ssh_disable_password_auth or (admin_authorized_keys | length > 0) fail_msg: >- ssh_disable_password_auth is true but admin_authorized_keys is empty. Add the admin's public key(s) first, or you will lock yourself out. - name: Install admin authorized keys ansible.posix.authorized_key: user: "{{ admin_user }}" key: "{{ item }}" state: present loop: "{{ admin_authorized_keys }}" when: admin_authorized_keys | length > 0 - name: Create sftponly group (per-customer SFTP users join this in Phase 4) ansible.builtin.group: name: sftponly state: present - name: Deploy SSH hardening drop-in ansible.builtin.template: src: 10-heleos-hardening.conf.j2 dest: /etc/ssh/sshd_config.d/10-heleos-hardening.conf owner: root group: root mode: "0644" notify: Restart ssh - name: Validate the effective sshd configuration ansible.builtin.command: /usr/sbin/sshd -t changed_when: false # Runs after the template task; if the config is invalid the play fails here # and the Restart ssh handler never fires, leaving the running sshd untouched.