Files
gitlab-mirror/roles/borgmatic/tasks/handle-ssh-keys.yml
2025-12-15 12:20:12 +03:00

26 lines
747 B
YAML

---
- name: "Ensure the path for SSH keys exists"
ansible.builtin.file:
path: "{{ borgmatic_sshkey_path | dirname }}"
state: directory
owner: root
group: root
mode: "0700"
- name: "Generate an ed25519 SSH key pair with 100 KDF rounds"
register: borgmatic_ssh_key_pair
community.crypto.openssh_keypair:
type: ed25519
path: "{{ borgmatic_sshkey_path }}"
comment: "Generated by Ansible for Borgmatic"
force: false
mode: '0600'
- name: "Push the SSH key pair to the Borg repo host"
when: borgmatic_push_pubkey
delegate_to: "{{ repo_server_inventory_hostname }}"
ansible.posix.authorized_key:
user: "{{ repo_server_user }}"
key: "{{ borgmatic_ssh_key_pair.public_key }}"
state: present