line: 'AUTOSTART="none"'
insertafter: '^#AUTOSTART="home office"$'
when: ansible_facts.os_family == 'Debian'
+
+- name: Allow passwordless sudo for up/down scripts
+ become: true
+ copy:
+ content: |
+ Defaults !admin_flag
+ openvpn ALL=(root:root) NOPASSWD: /etc/openvpn/up, NOPASSWD: /etc/openvpn/down
+ dest: /etc/sudoers.d/openvpn
+ owner: root
+ group: "{% if ansible_facts.os_family == 'Debian' %}sudo{% elif ansible_facts.os_family == 'RedHat' %}root{% endif %}"
+ mode: 0640