From e125f9952f1204c80987fa1d2a35e9f8f0d7ca14 Mon Sep 17 00:00:00 2001 From: Christoph Date: Wed, 29 Jul 2026 23:30:04 +0200 Subject: [PATCH] fix(samba-user.yml): improve command structure and enhance error handling for samba user management --- roles/common/tasks/samba-user.yml | 39 ++++++++++++++++++++----------- 1 file changed, 25 insertions(+), 14 deletions(-) diff --git a/roles/common/tasks/samba-user.yml b/roles/common/tasks/samba-user.yml index 28ff912..e8e36c1 100644 --- a/roles/common/tasks/samba-user.yml +++ b/roles/common/tasks/samba-user.yml @@ -3,7 +3,7 @@ # - default user/groups # --- -# To be precise, samba groups are system groups. +# To be precise, samba groups are system groups. # - name: (samba-user.yml) Ensure samba groups exists ansible.builtin.group: @@ -35,13 +35,16 @@ # Samba users mut be also system users # - name: (samba_user.yml) Add (system) users if not yet exists.. - ansible.builtin.command: "/root/bin/admin-stuff/add_new_user.sh {{ item.name }} '{{ item.password }}'" + ansible.builtin.command: + cmd: "/root/bin/admin-stuff/add_new_user.sh {{ item.name }} '{{ item.password }}'" + creates: "/home/{{ item.name }}" loop: "{{ samba_user }}" loop_control: label: "{{ item.name }}" when: - ansible_facts.getent_passwd is defined - item.name not in ansible_facts.getent_passwd + changed_when: true tags: - samba-server - samba-user @@ -52,7 +55,7 @@ name: "{{ item.name }}" state: present uid: "{{ item.user_id | default(omit) }}" - #group: '{{ item.0.name | default(omit) }}' + # group: '{{ item.0.name | default(omit) }}' groups: "{{ item.groups | join(', ') }}" password: "{{ item.password | password_hash('sha512') }}" update_password: on_create @@ -66,10 +69,14 @@ - system-user - name: (samba-user.yml) Check if samba user exists - ansible.builtin.shell: pdbedit -w -L | awk -F":" '{ print $1 }' | grep -e "^{{ item.name }}" - register: samba_user_present - changed_when: "samba_user_present.rc == 1" - failed_when: "samba_user_present.rc > 1" + ansible.builtin.shell: + executable: /bin/bash + cmd: | + set -o pipefail + pdbedit -w -L | awk -F":" '{ print $1 }' | grep -e "^{{ item.name }}" + register: common_samba_user_present + changed_when: "common_samba_user_present.rc == 1" + failed_when: "common_samba_user_present.rc > 1" loop: "{{ samba_user }}" loop_control: label: "{{ item.name }}" @@ -77,24 +84,28 @@ - samba-server - samba-user -- name: (samba-user.yml) Add user to samba (with system users password) - ansible.builtin.shell: > - (echo '{{ item.item.password }}'; echo '{{ item.item.password }}') | smbpasswd -s -a {{ item.item.name }} - loop: "{{ samba_user_present.results }}" +- name: (samba-user.yml) Add user to samba (with system users password) # noqa no-handler + ansible.builtin.shell: + executable: /bin/bash + cmd: | + set -o pipefail + (echo '{{ item.item.password }}'; echo '{{ item.item.password }}') | smbpasswd -s -a {{ item.item.name }} + loop: "{{ common_samba_user_present.results }}" when: item.changed loop_control: label: "{{ item.item.name }}" + changed_when: true tags: - samba-server - samba-user # Only on fileservers: -# zapata.opp.netz +# zapata.opp.netz - name: (samba_user.yml) Check if folder '/data/backup' exists using file module ansible.builtin.stat: path: /data/backup - register: data_backup_dir + register: common_data_backup_dir when: - inventory_hostname == 'zapata.opp.netz' tags: @@ -114,7 +125,7 @@ label: "{{ item.name }}" when: - inventory_hostname == 'zapata.opp.netz' - - data_backup_dir.stat.isdir is defined and data_backup_dir.stat.isdir + - common_data_backup_dir.stat.isdir is defined and common_data_backup_dir.stat.isdir tags: - samba-server - samba-user