diff --git a/hardening.yml b/hardening.yml index 67ace23..970a793 100644 --- a/hardening.yml +++ b/hardening.yml @@ -2,7 +2,6 @@ # vars: become: true gather_facts: true - pre_tasks: - name: Set hostname @@ -81,33 +80,33 @@ # chmod go+r /usr/share/keyrings/netbird-archive-keyring.gpg for error: #||-----> GPG error: https://pkgs.netbird.io/debian stable InRelease: The following signatures couldn't be verified because the public key is not available - # roles: - # - robertdebock.update - # - devsec.hardening.os_hardening - # - devsec.hardening.ssh_hardening - # - maxlareo.rkhunter - # - maxlareo.chkrootkit - # - robertdebock.auditd - # - geerlingguy.firewall - # - grog.management-user - # - GROG.user - # - GROG.authorized-key - # - GROG.sudo - # - ansible_unattended_upgrades - # - buluma.lynis + roles: + - robertdebock.update + - devsec.hardening.os_hardening + - devsec.hardening.ssh_hardening + - maxlareo.rkhunter + - maxlareo.chkrootkit + - robertdebock.auditd + - geerlingguy.firewall + - grog.management-user + - GROG.user + - GROG.authorized-key + - GROG.sudo + - ansible_unattended_upgrades + - buluma.lynis # roles: # - role: netways.elasticstack.elasticsearch # tags: test2 tasks: - - name: Update repositories and install foo package + - name: Update repositories and install py3-pip package community.general.apk: name: py3-pip update_cache: true delegate_to: localhost - - name: Install bottle python package + - name: Install pip package ansible.builtin.pip: name: "{{ item }}" loop: @@ -122,8 +121,13 @@ firstmatch: true line: '#!Enable-HMAC-ETM' - - name: Retrieve private IP address netbird - ansible.builtin.gather_facts: + - name: Reload service httpd, in all cases + ansible.builtin.systemd_service: + name: sshd.service + state: reloaded + + # - name: Retrieve private IP address netbird + # ansible.builtin.gather_facts: - name: Set host_interfaces list ansible.builtin.set_fact: @@ -141,6 +145,7 @@ when: ansible_facts[item].ipv4.address | ansible.utils.ipaddr('100.96.0.0/16') loop: "{{ host_interfaces }}" + # - name: Debug fingerprint for ALL hosts # debug: # msg: "{{ group_names }}"