ansible-collection-dotfiles/roles/ssh/defaults/main.yml

45 lines
1.5 KiB
YAML

---
ssh_become: true
ssh_become_user: "{{ lookup('env', 'USER') }}"
# Each item becomes ~/.ssh/config.d/<name>, included by ~/.ssh/config.
#
# name: file name inside ~/.ssh/config.d
# content: the ssh_config(5) stanzas to write into the file
ssh_configs: []
# - name: example
# content: |
# Host example
# HostName example.org
# User eriol
# IdentityFile ~/.ssh/example
# PubkeyAuthentication yes
# File names to remove from ~/.ssh/config.d.
ssh_configs_absent: []
# A script that loads the keys into the ssh agent.
ssh_load_keys_script: ~/.bin/ssh-load-keys
# Support Linux or Darwin.
ssh_is_darwin: "{{ ansible_system | default('Linux') == 'Darwin' }}"
ssh_askpass: "{{ '' if ssh_is_darwin else '/usr/bin/ksshaskpass' }}"
# Extra options passed to ssh-add for every key.
ssh_add_options: "{{ ['--apple-use-keychain'] if ssh_is_darwin else [] }}"
# Key files to load, as paths relative to ~/.ssh or absolute.
ssh_keys: []
# - id_ed25519
# - forges/codeberg/id_ed25519_eriol
# PKCS#11 provider to load with `ssh-add -s`, e.g. for a Yubikey.
# Set to an empty string to skip it.
#
# On Darwin the ssh-agent shipped by Apple does not load third party
# libraries: SSH_AUTH_SOCK must point to the OpenSSH agent from Homebrew,
# started with `-P '/opt/homebrew/*'` so that it accepts the library below.
ssh_pkcs11_provider: >-
{{ '/opt/homebrew/lib/libykcs11.dylib' if ssh_is_darwin
else '/usr/lib/x86_64-linux-gnu/libykcs11.so' }}