Ansible role for security hardening
2a4875f2cd
Some of the NTP defaults used to deploy chrony were shared between both the RHEL6 and RHEL7 STIG tasks, however the required defaults for these vars were removed in Iaae52c97a35d82dd807ef78a1a6593ce3aa33540. Since they are still needed by the RHEL7 STIG chrony deployment we will need to add them back. I also removed a reference to "security_disable_ipv6" in the chrony config file which was used to determine if Chrony should bind ::1 for its management socket. Since the "security_disable_ipv6" var no longer exists, we will unconditionally bind the ::1 management address. Change-Id: Ic80bda5fbf5cb4424e305ff9839121416b8bea19 |
||
---|---|---|
defaults | ||
doc | ||
files | ||
handlers | ||
library | ||
meta | ||
releasenotes | ||
tasks | ||
templates | ||
test_plugins | ||
tests | ||
vars | ||
.gitignore | ||
.gitreview | ||
bindep.txt | ||
LICENSE | ||
manual-test.rc | ||
README.md | ||
README.rst | ||
run_tests.sh | ||
setup.cfg | ||
setup.py | ||
test-requirements.txt | ||
tox.ini | ||
Vagrantfile |
ansible-hardening
The ansible-hardening role applies security hardening configurations from the Security Technical Implementation Guide (STIG) to systems running the following distributions:
- CentOS 7
- Debian Jessie
- Fedora 26
- openSUSE Leap 42.2 and 42.3
- Red Hat Enterprise Linux 7
- SUSE Linux Enterprise 12 (experimental)
- Ubuntu 16.04
For more details, review the ansible-hardening documentation.
Requirements
This role can be used with or without OpenStack-Ansible. It requires Ansible 2.3 or later.
Role Variables
All of the variables for this role are in defaults/main.yml
.
Dependencies
This role has no dependencies.
Example Playbook
Using the role is fairly straightforward:
- hosts: servers
roles:
- ansible-hardening
Running with Vagrant
This role can be tested easily on multiple platforms using Vagrant.
The Vagrantfile
supports testing on:
- Ubuntu 16.04
- CentOS 7
To test on all platforms:
vagrant destroy --force && vagrant up
To test on Ubuntu 14.04 only:
vagrant destroy ubuntu1404 --force && vagrant up ubuntu1404
To test on Ubuntu 16.04 only:
vagrant destroy ubuntu1604 --force && vagrant up ubuntu1604
To test on CentOS 7 only:
vagrant destroy centos7 --force && vagrant up centos7
License
Apache 2.0
Author Information
For more information, join #openstack-ansible
on Freenode.