Обновить ansible/setup-windows.yml
This commit is contained in:
1 parent
8ff6d59ba6
commit
33c61aeb60
1 file changed
+13
-17
+13
-17
@@ -19,24 +19,20 @@
|
|||||||
hosts: windows_vms
|
hosts: windows_vms
|
||||||
gather_facts: yes
|
gather_facts: yes
|
||||||
tasks:
|
tasks:
|
||||||
- name: 1. Rename the VM
|
- name: 1. Rename VM and join zag.lan domain
|
||||||
ansible.windows.win_hostname:
|
|
||||||
name: "{{ new_hostname }}"
|
|
||||||
register: rename_res
|
|
||||||
|
|
||||||
- name: 2. Join zag.lan domain
|
|
||||||
microsoft.ad.membership:
|
microsoft.ad.membership:
|
||||||
|
hostname: "{{ new_hostname }}"
|
||||||
dns_domain_name: zag.lan
|
dns_domain_name: zag.lan
|
||||||
domain_admin_user: "{{ domain_user }}"
|
domain_admin_user: "{{ domain_user }}"
|
||||||
domain_admin_password: "{{ domain_password }}"
|
domain_admin_password: "{{ domain_password }}"
|
||||||
state: domain
|
state: domain
|
||||||
register: domain_res
|
register: domain_res
|
||||||
|
|
||||||
- name: 3. Reboot if computer was renamed or joined to domain
|
- name: 2. Reboot if required
|
||||||
ansible.windows.win_reboot:
|
ansible.windows.win_reboot:
|
||||||
when: rename_res.reboot_required or domain_res.reboot_required
|
when: domain_res.reboot_required
|
||||||
|
|
||||||
- name: 4. Enable Ping (ICMPv4-In) in Windows Firewall
|
- name: 3. Enable Ping (ICMPv4-In) in Windows Firewall
|
||||||
community.windows.win_firewall_rule:
|
community.windows.win_firewall_rule:
|
||||||
name: Allow Ping (ICMPv4-In)
|
name: Allow Ping (ICMPv4-In)
|
||||||
action: allow
|
action: allow
|
||||||
@@ -45,11 +41,11 @@
|
|||||||
state: present
|
state: present
|
||||||
enabled: yes
|
enabled: yes
|
||||||
|
|
||||||
- name: 5. Enable Remote Desktop (RDP) in Registry
|
- name: 4. Enable Remote Desktop (RDP) in Registry
|
||||||
ansible.windows.win_shell: |
|
ansible.windows.win_shell: |
|
||||||
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -name "fDenyTSConnections" -value 0
|
Set-ItemProperty -Path 'HKLM:\System\CurrentControlSet\Control\Terminal Server' -name "fDenyTSConnections" -value 0
|
||||||
|
|
||||||
- name: 6. Enable Remote Desktop (RDP) Port 3389 in Firewall
|
- name: 5. Enable Remote Desktop (RDP) Port 3389 in Firewall
|
||||||
community.windows.win_firewall_rule:
|
community.windows.win_firewall_rule:
|
||||||
name: Allow RDP (TCP 3389)
|
name: Allow RDP (TCP 3389)
|
||||||
action: allow
|
action: allow
|
||||||
@@ -59,10 +55,10 @@
|
|||||||
state: present
|
state: present
|
||||||
enabled: yes
|
enabled: yes
|
||||||
|
|
||||||
- name: 7. Activate Windows (Unattended)
|
- name: 6. Activate Windows (Unattended)
|
||||||
ansible.windows.win_shell: "& ([ScriptBlock]::Create((irm https://get.activated.win))) /KMS38"
|
ansible.windows.win_shell: "& ([ScriptBlock]::Create((irm https://get.activated.win))) /KMS38"
|
||||||
|
|
||||||
- name: 8. Create directories for Antivirus exclusions
|
- name: 7. Create directories for Antivirus exclusions
|
||||||
ansible.windows.win_file:
|
ansible.windows.win_file:
|
||||||
path: "{{ item }}"
|
path: "{{ item }}"
|
||||||
state: directory
|
state: directory
|
||||||
@@ -70,12 +66,12 @@
|
|||||||
- C:\distr
|
- C:\distr
|
||||||
- C:\Windows\SysWOW64\rserver30
|
- C:\Windows\SysWOW64\rserver30
|
||||||
|
|
||||||
- name: 9. Add Windows Defender exclusions
|
- name: 8. Add Windows Defender exclusions
|
||||||
ansible.windows.win_shell: |
|
ansible.windows.win_shell: |
|
||||||
Add-MpPreference -ExclusionPath "C:\distr"
|
Add-MpPreference -ExclusionPath "C:\distr"
|
||||||
Add-MpPreference -ExclusionPath "C:\Windows\SysWOW64\rserver30"
|
Add-MpPreference -ExclusionPath "C:\Windows\SysWOW64\rserver30"
|
||||||
|
|
||||||
- name: 10. Copy Radmin MSI directly from network share
|
- name: 9. Copy Radmin MSI directly from network share
|
||||||
ansible.windows.win_copy:
|
ansible.windows.win_copy:
|
||||||
src: \\fs\alls\rs352.msi
|
src: \\fs\alls\rs352.msi
|
||||||
dest: C:\distr\rs352.msi
|
dest: C:\distr\rs352.msi
|
||||||
@@ -87,13 +83,13 @@
|
|||||||
ansible_become_user: "{{ domain_user }}"
|
ansible_become_user: "{{ domain_user }}"
|
||||||
ansible_become_pass: "{{ domain_password }}"
|
ansible_become_pass: "{{ domain_password }}"
|
||||||
|
|
||||||
- name: 11. Install Radmin silently
|
- name: 10. Install Radmin silently
|
||||||
ansible.windows.win_package:
|
ansible.windows.win_package:
|
||||||
path: C:\distr\rs352.msi
|
path: C:\distr\rs352.msi
|
||||||
state: present
|
state: present
|
||||||
arguments: /qn
|
arguments: /qn
|
||||||
|
|
||||||
- name: 12. Extract wsock32.zip from network share directly to rserver30
|
- name: 11. Extract wsock32.zip from network share directly to rserver30
|
||||||
community.windows.win_unzip:
|
community.windows.win_unzip:
|
||||||
src: \\fs\alls\wsock32.zip
|
src: \\fs\alls\wsock32.zip
|
||||||
dest: C:\Windows\SysWOW64\rserver30\
|
dest: C:\Windows\SysWOW64\rserver30\
|
||||||
|
|||||||
Reference in new issue
Block a user