SSH is used heavily by ansible to access Linux and RouterOS. Recent librar changes make it more paranoid about accessing hosts that are not in your known hosts file. You will need to either update your ansible.cfg file:
[defaults]
host_key_checking = False
or set the environment variable ANSIBLE_HOST_KEY_CHECKING=False
on the ansible command line or for your shell session.
In addtion, recent changes to libssh restrict the default available algorithm choices
to more secure options. This will prevent connections to older RouterOS versions.
You will probably want to update your ~/.ssh/config file with a stanza similar to this:
Host *.hamwan.net
MACs +hmac-sha1
KexAlgorithms +diffie-hellman-group14-sha1
HostKeyAlgorithms +ssh-rsa
PubkeyAcceptedAlgorithms +ssh-rsa
StrictHostKeyChecking no
UserKnownHostsFile /dev/null
Information on accessing organization hosts is stored in inventories/site/group_vars/group.yml. In the HamWAN case, all the hosts we manage are in the group owner_HamWAN, so we have a group_vars file owner_HamWAN.yml.
RouterOS specific configuration information is in group_vars/os_routeros.yml.
---
# vars file for users
users_admin:
- dylan
- eo
- kc7aad
- KD7DK
- kennyr
- KK7LZM
- nigel
- N7JMV
- NQ1E
- nr3o
- osburn
- tom
- va7dbi
- ve7alb
users_user:
- monitoring
group_admin: hamadmin
group_user: ham
group_managed_scope: /etc/group_managed_scope
authorized_key_scheme: ansible.builtin.url
authorized_key_location: https://monitoring.hamwan.net/keys/
test_flaky_network: false
users_admim are users who should be given admin access. users_user are users who should be given an unprivileged account. For RouterOS, admin_users are group=full and users_user are group=read.
Information specific to specific families of system (e.g. os_routeros and os_linux) are in respective inventories/site/group_vars files, and group_vars/group.yml (e.g. groups_vars/os_routeros.yml that has all the desired RouterOS settings).
cd ~
sudo dnf -y install ansible git jq
git clone --recursive https://github.com/HamWAN/infrastructure-configs.git
cd infrastructure-configs
cp .ansible.cfg ~
ansible-galaxy install -r roles/requirements.yml
ansible --list-hosts all
ansible --list-hosts os_linux
ansible --list-hosts 'os_linux:&owner_HamWAN'
ansible --list-hosts 'os_linux:&owner_HamWAN:!type_container'
Now that you know the basics of group matching, you can surf the available inventory:
~/infrastructure-configs/inventories/psdr/hosts.sh | jq | less
More details about selecting inventory subsets here.
ansible-playbook --limit <server> psdr.yml
ansible-playbook psdr.yml
We use Ansible Molecule for testing. This user role includes the necessary vagrant and molecule configuration to test various user management tasks using virtual machines under vagrant/libvirt. It also tests for behavior in the face of flakey connections. The routeros_common role tests for setting or changing settings that are both present or missing beforehand on both RouterOS 6 and 7.
(This is likely to need updates, to match what is being installed below for Debian. A Fedora user will need to do that.)
First, run the Operator Workstation Setup, then:
sudo dnf -y install vagrant-libvirt rubygem-rexml @virtualization
sudo systemctl enable --now libvirtd
sudo usermod --append --groups libvirt `whoami`
vagrant up --no-parallel
sudo apt install virtualenv
sudo apt install python3-pip libssl-dev
sudo apt install vagrant-libvirt
sudo apt install qemu-system libvirt-daemon-system
cd infrastructure_configs
virtualenv venv
. venv/bin/activate
pip3 install ansible-dev-tools
pip3 install molecule ansible-core ansible-pylibssh
pip3 install --upgrade setuptools
pip3 install "molecule-plugins[vagrant]"
ansible-galaxy collection install ansible.posix community.routeros
sudo systemctl enable --now libvirtd
sudo adduser libvirt
vagrant up --no-parallel
...
deactivate
roles/routeros_common/README.md