fix(tasks): derive a deterministic password salt per unix user
`password_hash('sha512')` without an explicit salt generates a new random salt on every invocation. The resulting hash
differed on each run, so the user module rewrote /etc/shadow and reported a change every time the role was applied. This
was the single biggest obstacle to a green idempotence check.
The salt is now derived from the user name, which keeps the hash stable across runs while still giving every account its
own salt, so two users sharing a password do not end up with an identical hash.
Verified locally: repeated runs produce a byte identical hash, and different user names produce different ones.
Co-authored-by: Copilot <copilot@github.com>
This commit is contained in:
@@ -40,7 +40,8 @@
|
||||
create_home: "{{ unix_user.value.create_home | default(true) }}"
|
||||
home: "{{ user_user_home }}"
|
||||
shell: "{{ unix_user.value.shell | default('/bin/bash') }}"
|
||||
password: "{{ unix_user.value.password | password_hash('sha512') if unix_user.value.password is defined and unix_user.value.password | length > 0 else '!' }}"
|
||||
# The salt is derived from the user name, a random one would produce a new hash and a change on every run.
|
||||
password: "{{ unix_user.value.password | password_hash('sha512', unix_user.key | hash('sha512') | truncate(16, true, '')) if unix_user.value.password is defined and unix_user.value.password | length > 0 else '!' }}"
|
||||
state: present
|
||||
|
||||
- name: "Adapt permissions and copy skel for unix user: {{ unix_user.key }}"
|
||||
|
||||
Reference in New Issue
Block a user