xpeditis2.0/infra/prod/terraform/cloud-init.yaml.tftpl
2026-09-07 21:40:50 +02:00

77 lines
2.0 KiB
Plaintext

#cloud-config
# =============================================================================
# Amorcage minimal des serveurs Xpeditis prod
# =============================================================================
# Ce fichier ne fait que le strict necessaire pour obtenir un serveur joignable
# en SSH par un compte non-root. Tout le durcissement reel est fait par
# scripts/00-bootstrap-common.sh, versionne et relisible.
hostname: ${hostname}
fqdn: ${hostname}
preserve_hostname: false
users:
- name: ${deploy_user}
groups: [sudo]
shell: /bin/bash
sudo: ["ALL=(ALL) NOPASSWD:ALL"]
lock_passwd: true
ssh_authorized_keys:
- ${ssh_public_key}
# Le compte root n'a ni mot de passe ni acces SSH par mot de passe.
disable_root: true
ssh_pwauth: false
package_update: true
package_upgrade: true
packages:
- curl
- ca-certificates
- gnupg
- ufw
- fail2ban
- unattended-upgrades
- chrony
- jq
- git
- htop
- rsync
write_files:
# Pare-feu local minimal des le premier boot : le serveur n'est jamais
# accessible "nu", meme entre cloud-init et l'execution du script de
# durcissement.
- path: /etc/ssh/sshd_config.d/99-xpeditis-hardening.conf
permissions: "0644"
content: |
PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
ChallengeResponseAuthentication no
PubkeyAuthentication yes
X11Forwarding no
AllowAgentForwarding no
AllowTcpForwarding yes
MaxAuthTries 3
MaxSessions 5
LoginGraceTime 20
ClientAliveInterval 300
ClientAliveCountMax 2
AllowUsers ${deploy_user}
runcmd:
- systemctl restart ssh || systemctl restart sshd
- systemctl enable --now fail2ban
- systemctl enable --now chrony
- |
ufw --force reset
ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw --force enable
- touch /var/log/cloud-init-xpeditis-done
final_message: "Xpeditis prod node ${hostname} pret. Lancer scripts/00-bootstrap-common.sh."