--- # user_bootstrap — create user account, SSH key, sudo access # Arch-only. Run on a fresh machine before other roles. - name: Create user account ansible.builtin.user: name: "{{ bootstrap_user }}" shell: /bin/bash create_home: true groups: wheel append: true - name: Set authorized SSH key ansible.posix.authorized_key: user: "{{ bootstrap_user }}" state: present key: "{{ bootstrap_ssh_pubkey }}" when: bootstrap_ssh_pubkey | default('') | length > 0 - name: Allow passwordless sudo for wheel group ansible.builtin.lineinfile: path: /etc/sudoers line: "%wheel ALL=(ALL) NOPASSWD: ALL" validate: "visudo -cf %s" state: present - name: Ensure SSH service is enabled ansible.builtin.service: name: sshd state: started enabled: true