base: Factor out SSH host, user cert roles

Moving the SSH host and user certificate configuration roles out of
`base.yml` into their own playbooks.  This will make it easier to deploy
them separately, and target different sets of hosts.  The main driver
for this change is the OVH VPS; being external, it cannot communicate
with SSHCA and thus cannot have a signed host certificate.  As such, we
do not want to try to configure the SSHCA client on it at all.
This commit is contained in:
2025-02-01 12:36:39 -06:00
parent a3a2dde6ab
commit 34c1256f27
4 changed files with 9 additions and 3 deletions

4
ssh-host-certs.yml Normal file
View File

@@ -0,0 +1,4 @@
- hosts: '!vps'
roles:
- role: ssh-host-certs
tags: ssh-host-certs