RETIRED, Security Role for OpenStack-Ansible
Go to file
Major Hayden e26c9112f9 Restart auditd after running augenrules
The augenrules command joins together all of the audit rules from
rules.d and it is run any time the audit rules template changes. However,
the augenrules handler didn't actually restart auditd to apply the
changes to the system.

This patch fires off the auditd restart handler anytime the augenrules
handler is notified.

Closes-bug: 1590916

Change-Id: Ice83fe17ebb0e9edff9da897e435ae96c1778580
(cherry picked from commit 809b6cb52d)
2016-06-10 12:55:02 +00:00
defaults Switch from dict to individual variables 2016-05-06 17:42:56 +00:00
doc Fix auditd log permission bug 2016-05-24 16:17:32 +00:00
files V-38682: Disable bluetooth modules 2015-10-14 21:23:11 -05:00
handlers Restart auditd after running augenrules 2016-06-10 12:55:02 +00:00
meta Bump minimum required version of Ansible 2016-01-13 12:41:02 -08:00
releasenotes Restart auditd after running augenrules 2016-06-10 12:55:02 +00:00
tasks Set check_mode variable every time 2016-06-09 13:24:54 +00:00
templates Add /etc/apparmor.d/ for auditing 2016-06-01 12:50:30 +00:00
tests Security: Check for grub.cfg first 2016-02-29 14:15:29 -06:00
vars Enable role testing and make structure ansible-galaxy compatible 2015-10-09 11:47:23 +00:00
.gitignore Add dependencies for paramiko 2.0 2016-05-05 16:34:22 +01:00
.gitreview Update .gitreview for Liberty 2016-04-08 16:34:10 +01:00
LICENSE Initial import of openstack-ansible-security role 2015-10-07 07:27:39 -05:00
README.md Merge "Adding Vagrant setup for deploying security-ansible" 2016-02-05 16:12:33 +00:00
README.rst Add new docs URL to README 2015-10-09 08:25:56 -05:00
Vagrantfile Adding Vagrant setup for deploying security-ansible 2016-01-25 08:04:26 -08:00
other-requirements.txt Add dependencies for paramiko 2.0 2016-05-05 16:34:22 +01:00
run_tests.sh Add dependencies for paramiko 2.0 2016-05-05 16:34:22 +01:00
setup.cfg Initial import of openstack-ansible-security role 2015-10-07 07:27:39 -05:00
setup.py Initial import of openstack-ansible-security role 2015-10-07 07:27:39 -05:00
test-requirements.txt Add dependencies for paramiko 2.0 2016-05-05 16:34:22 +01:00
tox.ini Add dependencies for paramiko 2.0 2016-05-05 16:34:22 +01:00

README.md

openstack-ansible-security

The goal of the openstack-ansible-security role is to improve security within openstack-ansible deployments. The role is based on the Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 6.

Requirements

This role can be used with or without the openstack-ansible role. It requires Ansible 1.8.3 at a minimum.

Role Variables

All of the variables for this role are in defaults/main.yml.

Dependencies

This role has no dependencies.

Example Playbook

Using the role is fairly straightforward:

- hosts: servers
  roles:
     - openstack-ansible-security

Running with Vagrant

Security Ansible can be easily run for testing using Vagrant.

To do so run: vagrant destroy To destroy any previously created Vagrant setup vagrant up Spin up Ubuntu Trusty VM and run ansible-security against it

License

Apache 2.0

Author Information

For more information, join #openstack-ansible on Freenode.