vsftpd As FTPS Only, TLS 1.3, Chrooted Local Users

vsftpd from AppStream made into an FTPS server: TLS for every login and transfer, TLS 1.3 only, data connections tied to the logged-in session, users chrooted, no anonymous access, passive ports on a fixed range, each file checked by vsftpd first. The live test transfers a file over TLS and is refused in clear, anonymously and over TLS 1.2. Original role, live-tested on Rocky Linux 10.

ansibleStorage

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-08 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-vsftpd/badge)](https://www.iac-bazaar.com/catalog/ansible-vsftpd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [vsftpd As FTPS Only, TLS 1.3, Chrooted Local Users](https://www.iac-bazaar.com/catalog/ansible-vsftpd?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# vsftpd As FTPS Only, TLS 1.3, Chrooted Local Users: https://www.iac-bazaar.com/catalog/ansible-vsftpd (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

vsftpd

vsftpd from AppStream, made into an FTPS server: TLS required for every login and every transfer, TLS 1.3 only by default, the host's own accounts each locked into their home, passive data ports on a fixed range, no anonymous access, and every configuration checked by vsftpd itself before it lands. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages vsftpd, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

The distribution's unit, our configuration. The role installs vsftpd and openssl, writes the whole of /etc/vsftpd/vsftpd.conf (root 0600), and enables the unit the package ships: systemctl cat vsftpd shows the distribution's own unit. The listener is 127.0.0.1:21 by default; the live test reads the listening sockets and expects loopback only.

The package's own file is plain FTP on every interface. The stock vsftpd.conf listens on [::]:21 (listen_ipv6=YES, a dual-stack socket), lets local users log in and write, and configures no TLS at all, so a password crosses the network in clear (read in the package). The role writes the whole file instead: TLS forced for logins and for data - a plain-text login gets "530 Non-anonymous sessions must use encryption." and a data connection in clear "522 Data connections must be encrypted." (both measured) - TLS 1.3 only (a TLS 1.2 client is refused; vsftpd_tls12: true accepts it for older clients), anonymous off, active mode off, passive mode on a fixed port range. A data connection must resume the control connection's TLS session, which proves it comes from the client that logged in: one that does not gets "522 SSL connection failed: session reuse required" (measured; vsftpd_require_ssl_reuse: false lifts it for clients that cannot resume).

Local users, chrooted. Logins are the host's own accounts through PAM (/etc/pam.d/vsftpd requires a shell listed in /etc/shells), each locked into its home: the live test's user is still at / after cd ... vsftpd refuses a chroot root the user can write to, and the role keeps that refusal (it does not set allow_writeable_chroot), so a user's home belongs to root and the user writes in a directory inside it - tests/pre-converge.yml makes one that way. /etc/vsftpd/user_list keeps its stock deny list (root and the system accounts), and vsftpd_denied_users adds to it.

Checked before it lands, without a check flag. vsftpd has no test mode. Given the file and then -olisten=NO, it parses the whole file, loads the certificate and stops at its inetd check - "not configured for standalone, must be started from inetd" - binding nothing; any other message is the file's own error ("unrecognised variable in config file", "bad bool value", "SSL: cannot load RSA certificate" - measured). The order matters: vsftpd applies options in the order given, so with -olisten=NO BEFORE the file, the file's listen=YES wins and a real server starts - an earlier draft of this check did exactly that, and left a server holding port 21 that the real start then could not bind. /usr/local/libexec/iacbazaar-vsftpd-check is the template's validate.

A certificate is made if you bring none. Self-signed, P-256, 825 days, the common name from vsftpd_tls_common_name, the key root 0600. Point vsftpd_tls_cert and vsftpd_tls_key at your own and set vsftpd_tls_generate: false.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-borg

BorgBackup from EPEL: an encrypted, deduplicated repository, your paths backed up on a systemd timer with daily, weekly and monthly retention, the passphrase generated once and the key exported. The live test backs up a file through the unit, deletes it, restores it byte for byte, and sees a wrong passphrase refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-garage

Garage on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with a single-node layout applied on the first start; the live test creates a bucket and a key through the RPC, grants it, reads it back, and sees an anonymous S3 request refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kopia

kopia on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which creates a filesystem repository, snapshots a directory, lists the snapshot and has kopia verify read every object back, all offline. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-samba-share

Samba for named accounts over SMB 3 only. The package accepts SMB 2.0.2, encrypts and signs only when the client asks, shares every local home, exposes printer shares and runs NetBIOS on 139. This role requires encryption and signing (the live test reads it from the server), serves only the shares you list, and speaks on 445 alone. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-seaweedfs

SeaweedFS (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test writes a file through the filer, reads it back and deletes it, sees anonymous S3 refused, runs a SigV4-signed bucket/put/get/delete round trip with the configured identity, sees a wrong secret refused, and reads the metrics. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-syncthing

Syncthing from the upstream release with its API on loopback behind a key that never appears in the unit file. Discovery, relays, NAT traversal, crash reports and self-upgrade are switched off through the REST API. The live test sees a missing or wrong key refused, finds no key in the unit, and watches a shared folder get indexed. Original role, live-tested on Rocky Linux 10.

View module