From a457c0932b697fd32febe79c473c7e06dccd355a Mon Sep 17 00:00:00 2001 From: Luke Hoersten Date: Sat, 1 Aug 2026 09:53:44 -0500 Subject: rpi-base: role-owned netplan replaces wpa_supplicant; auto-upgrades gain -updates and 04:00 reboot Networking: one 40-net.yaml (eth0 always, wifi via rpi_base_wifi_*) with cloud-init's 50-cloud-init.yaml deleted after first boot. cloud-init still renders it on an instance_id bump, and it sorts later, so editing the card's network-config and bumping meta-data is the headless rescue path. ssh_deletekeys off so a rescue bump keeps the host keys. Auto-updates: periodic switches and local policy merged into one 52unattended-upgrades-local; 50unattended-upgrades stays a distro conffile and debconf's 20auto-upgrades can no longer disable anything. --- rpi-base/defaults/main.yaml | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'rpi-base/defaults/main.yaml') diff --git a/rpi-base/defaults/main.yaml b/rpi-base/defaults/main.yaml index 34f4072..696a179 100644 --- a/rpi-base/defaults/main.yaml +++ b/rpi-base/defaults/main.yaml @@ -1,6 +1,10 @@ --- rpi_base_enable_wifi: True +# Public key file on the controller, authorized for the admin and ansible +# users on every host. EXCLUSIVE: every other key gets removed from +# authorized_keys, so this must be the key used to reach the hosts. +rpi_base_ssh_public_key_file: "~/.ssh/id_ed25519.pub" rpi_base_timezone: "America/Chicago" rpi_base_log_size: "100M" rpi_base_apt_packages: -- cgit v1.2.3