rsync Daemon Serving Named Modules Read-Only, Chrooted, To Named Users
rsync daemon from AppStream serving your modules to the users and hosts you name: read-only by default, every transfer chrooted into its module, a password made for each user, and each file checked by running it, as rsync has no checker. The live test pulls with the made password and is refused a wrong one, an upload and a path out of the module. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-rsyncd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [rsync Daemon Serving Named Modules Read-Only, Chrooted, To Named Users](https://www.iac-bazaar.com/catalog/ansible-rsyncd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# rsync Daemon Serving Named Modules Read-Only, Chrooted, To Named Users: https://www.iac-bazaar.com/catalog/ansible-rsyncd (download from your IaC Bazaar account)
```Preview:
Documentation
rsyncd
The rsync daemon from AppStream serving the modules you name, each to the
users and hosts you name: read-only unless you say otherwise, every transfer
chrooted into its module as nobody, a password made for each user, and the
whole file checked by running it before it lands. Original role for EL 10,
live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages rsyncd, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
The distribution's unit, our configuration. The role installs rsync and
rsync-daemon, writes /etc/rsyncd.conf (root 0644: it holds no secrets) and
/etc/rsyncd.secrets (root 0600), and enables the package's rsyncd.service.
The listener is 127.0.0.1:873 by default; the live test reads the listening
sockets and expects loopback only.
The package listens everywhere and serves nothing. The stock
/etc/rsyncd.conf is all comments, so the daemon runs as root on 0.0.0.0:873
and [::]:873 with no modules (measured). The role binds the address you give
(127.0.0.1:873 by default) and serves only the modules in rsyncd_modules.
The rsync protocol is not encrypted. The daemon authenticates users with a challenge, but the files cross the network in the clear. Keep the listener on loopback and reach it over SSH, or put TLS in front of it - this catalogue's stunnel role does that - before you open it to another host.
What a client is refused, measured. A wrong password, another user or no
password: "auth failed on module". An upload: "module is read only". Each
user's access decides, not the module's: a user's ro held with the module
opened (read_only: false), and a user given rw wrote into a module set
read_only: true (both measured). That is why every user defaults to ro. A
path outside the module, or a symlink in it followed out with
-L: nothing arrives, because the transfer runs chrooted. A host not in
hosts_allow: "access denied". rsync also ignores a secrets file others can
read, and then every login fails, so the role keeps it root 0600.
A checker, because rsync has none. A daemon given a bad file keeps running,
and an unknown parameter is logged and ignored rather than refused. The role
runs each candidate as a daemon on a spare loopback port, asks it for its module
list once and reads its log; anything the log calls a problem stops the file
before it reaches /etc/rsyncd.conf.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-borg
BorgBackup from EPEL: an encrypted, deduplicated repository, your paths backed up on a systemd timer with daily, weekly and monthly retention, the passphrase generated once and the key exported. The live test backs up a file through the unit, deletes it, restores it byte for byte, and sees a wrong passphrase refused. Original role, live-tested on Rocky Linux 10.
ansible-garage
Garage on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with a single-node layout applied on the first start; the live test creates a bucket and a key through the RPC, grants it, reads it back, and sees an anonymous S3 request refused. Original role, live-tested on Rocky Linux 10.
ansible-kopia
kopia on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which creates a filesystem repository, snapshots a directory, lists the snapshot and has kopia verify read every object back, all offline. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.
ansible-samba-share
Samba for named accounts over SMB 3 only. The package accepts SMB 2.0.2, encrypts and signs only when the client asks, shares every local home, exposes printer shares and runs NetBIOS on 139. This role requires encryption and signing (the live test reads it from the server), serves only the shares you list, and speaks on 445 alone. Original role, live-tested on Rocky Linux 10.
ansible-seaweedfs
SeaweedFS (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test writes a file through the filer, reads it back and deletes it, sees anonymous S3 refused, runs a SigV4-signed bucket/put/get/delete round trip with the configured identity, sees a wrong secret refused, and reads the metrics. Original role, live-tested on Rocky Linux 10.
ansible-syncthing
Syncthing from the upstream release with its API on loopback behind a key that never appears in the unit file. Discovery, relays, NAT traversal, crash reports and self-upgrade are switched off through the REST API. The live test sees a missing or wrong key refused, finds no key in the unit, and watches a shared folder get indexed. Original role, live-tested on Rocky Linux 10.