rsync Daemon Serving Named Modules Read-Only, Chrooted, To Named Users

rsync daemon from AppStream serving your modules to the users and hosts you name: read-only by default, every transfer chrooted into its module, a password made for each user, and each file checked by running it, as rsync has no checker. The live test pulls with the made password and is refused a wrong one, an upload and a path out of the module. Original role, live-tested on Rocky Linux 10.

ansibleStorage

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-rsyncd/badge)](https://www.iac-bazaar.com/catalog/ansible-rsyncd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [rsync Daemon Serving Named Modules Read-Only, Chrooted, To Named Users](https://www.iac-bazaar.com/catalog/ansible-rsyncd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# rsync Daemon Serving Named Modules Read-Only, Chrooted, To Named Users: https://www.iac-bazaar.com/catalog/ansible-rsyncd (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

rsyncd

The rsync daemon from AppStream serving the modules you name, each to the users and hosts you name: read-only unless you say otherwise, every transfer chrooted into its module as nobody, a password made for each user, and the whole file checked by running it before it lands. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages rsyncd, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

The distribution's unit, our configuration. The role installs rsync and rsync-daemon, writes /etc/rsyncd.conf (root 0644: it holds no secrets) and /etc/rsyncd.secrets (root 0600), and enables the package's rsyncd.service. The listener is 127.0.0.1:873 by default; the live test reads the listening sockets and expects loopback only.

The package listens everywhere and serves nothing. The stock /etc/rsyncd.conf is all comments, so the daemon runs as root on 0.0.0.0:873 and [::]:873 with no modules (measured). The role binds the address you give (127.0.0.1:873 by default) and serves only the modules in rsyncd_modules.

The rsync protocol is not encrypted. The daemon authenticates users with a challenge, but the files cross the network in the clear. Keep the listener on loopback and reach it over SSH, or put TLS in front of it - this catalogue's stunnel role does that - before you open it to another host.

What a client is refused, measured. A wrong password, another user or no password: "auth failed on module". An upload: "module is read only". Each user's access decides, not the module's: a user's ro held with the module opened (read_only: false), and a user given rw wrote into a module set read_only: true (both measured). That is why every user defaults to ro. A path outside the module, or a symlink in it followed out with -L: nothing arrives, because the transfer runs chrooted. A host not in hosts_allow: "access denied". rsync also ignores a secrets file others can read, and then every login fails, so the role keeps it root 0600.

A checker, because rsync has none. A daemon given a bad file keeps running, and an unknown parameter is logged and ignored rather than refused. The role runs each candidate as a daemon on a spare loopback port, asks it for its module list once and reads its log; anything the log calls a problem stops the file before it reaches /etc/rsyncd.conf.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-borg

BorgBackup from EPEL: an encrypted, deduplicated repository, your paths backed up on a systemd timer with daily, weekly and monthly retention, the passphrase generated once and the key exported. The live test backs up a file through the unit, deletes it, restores it byte for byte, and sees a wrong passphrase refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-garage

Garage on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with a single-node layout applied on the first start; the live test creates a bucket and a key through the RPC, grants it, reads it back, and sees an anonymous S3 request refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kopia

kopia on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which creates a filesystem repository, snapshots a directory, lists the snapshot and has kopia verify read every object back, all offline. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-samba-share

Samba for named accounts over SMB 3 only. The package accepts SMB 2.0.2, encrypts and signs only when the client asks, shares every local home, exposes printer shares and runs NetBIOS on 139. This role requires encryption and signing (the live test reads it from the server), serves only the shares you list, and speaks on 445 alone. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-seaweedfs

SeaweedFS (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test writes a file through the filer, reads it back and deletes it, sees anonymous S3 refused, runs a SigV4-signed bucket/put/get/delete round trip with the configured identity, sees a wrong secret refused, and reads the metrics. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-syncthing

Syncthing from the upstream release with its API on loopback behind a key that never appears in the unit file. Discovery, relays, NAT traversal, crash reports and self-upgrade are switched off through the REST API. The live test sees a missing or wrong key refused, finds no key in the unit, and watches a shared folder get indexed. Original role, live-tested on Rocky Linux 10.

View module