report changed properly for "deactivate short moduli" task
This fixes the ansible-lint no-changed-when complaint and also allows to notify the reboot handler.
This commit is contained in:
parent
e3a29c422a
commit
e6d6d9eed0
|
@ -17,4 +17,20 @@
|
||||||
|
|
||||||
- name: deactivate short moduli
|
- name: deactivate short moduli
|
||||||
ansible.builtin.shell:
|
ansible.builtin.shell:
|
||||||
cmd: awk '$5 >= 3071' /etc/ssh/moduli > /etc/ssh/moduli.tmp && mv /etc/ssh/moduli.tmp /etc/ssh/moduli
|
executable: /bin/bash
|
||||||
|
cmd: |
|
||||||
|
set -eo pipefail
|
||||||
|
|
||||||
|
awk '$5 >= 3071' /etc/ssh/moduli > /etc/ssh/moduli.tmp
|
||||||
|
if diff /etc/ssh/moduli /etc/ssh/moduli.tmp; then
|
||||||
|
rm /etc/ssh/moduli.tmp
|
||||||
|
else
|
||||||
|
mv /etc/ssh/moduli.tmp /etc/ssh/moduli
|
||||||
|
echo "ansible-changed: changed /etc/ssh/moduli"
|
||||||
|
fi
|
||||||
|
register: result
|
||||||
|
changed_when:
|
||||||
|
- '"ansible-changed" in result.stdout'
|
||||||
|
notify:
|
||||||
|
# Reboot instead of just restarting the ssh service, since I don't know how Ansible reacts, when it restarts the service it probably needs for the connection.
|
||||||
|
- reboot the system
|
||||||
|
|
Loading…
Reference in a new issue