Users Management

Dalet Flex allows you to create various UNIX admin user accounts on the different instances.

Warning

These are not application accounts.

They are DevOps system account meant to operate on the core system.

Note

Admin accounts:

  • are nominative (one per user).
  • have password-less escalation privileges. sudo command grants root rights.
  • have no password set.
  • require public key SSH authentication.

You can extend the following variables with a list of nominative user accounts to be created and paths to local directories where their respective public SSH keys are to be found, e.g.:

dalet_baseos_users_admin_accounts_enabled: ["jdoe", "ops", "it"]
dalet_baseos_users_admin_accounts_pubkey_dirs: ["files/ssh", "files/pubkeys"]

Note that the directories must contain one PEM-formated public SSH key file per user account to be created.

The file is to be named with the account name (e.g.: jdoe).

User Removal

Over the lifespan of your project, some people may not require any admin account any more.

One can easily remove or disable deprecated admin users by extending the

dalet_baseos_users_admin_accounts_disabled: []

variable with the list of account names to be removed.

Updating system accounts (creating new ones, removing disabled ones) can be done through:

$ opsctl deploy -p dalet.flex.users