--- - name: Verify this role only runs on RedHat-family hosts ansible.builtin.assert: that: - ansible_facts['os_family'] == "RedHat" fail_msg: "selinux_config only supports RedHat-family hosts. Use apparmor_config for Debian family." tags: [selinux_config, always] - name: Install SELinux management tools ansible.builtin.dnf: name: - policycoreutils-python-utils - setroubleshoot-server - checkpolicy state: present tags: [selinux_config] - name: Set SELinux mode and policy ansible.posix.selinux: state: "{{ selinux_state }}" policy: "{{ selinux_policy }}" tags: [selinux_config] - name: Set application-specific SELinux booleans ansible.posix.seboolean: name: "{{ item.name }}" state: "{{ item.state }}" persistent: true loop: "{{ selinux_config_booleans }}" when: selinux_config_booleans | length > 0 tags: [selinux_config] - name: Set application-specific file contexts community.general.sefcontext: target: "{{ item.target }}" setype: "{{ item.setype }}" state: present loop: "{{ selinux_config_fcontexts }}" register: selinux_config_fcontext_result tags: [selinux_config] - name: Apply restorecon to changed file context paths ansible.builtin.command: "restorecon -Rv {{ item.item.target | regex_replace('\\(/\\.\\*\\)\\?$', '') }}" loop: "{{ selinux_config_fcontext_result.results }}" when: selinux_config_fcontext_result.changed and item.changed changed_when: true tags: [selinux_config] - name: Query current SELinux status ansible.builtin.command: getenforce register: selinux_config_current changed_when: false tags: [selinux_config] - name: Report SELinux status ansible.builtin.debug: msg: "SELinux status on {{ inventory_hostname }}: {{ selinux_config_current.stdout }}" tags: [selinux_config]