You've already forked ansible-linux-infra
157 lines
4.1 KiB
YAML
157 lines
4.1 KiB
YAML
---
|
|
# Global variables for all managed Linux servers.
|
|
# Replace placeholder values (domain, hosts, URLs) before rollout.
|
|
|
|
# base_os
|
|
# Base package lists and unwanted-package lists are OS-family-specific
|
|
# (see roles/base_os/vars/RedHat.yml and roles/base_os/vars/Debian.yml).
|
|
# Use base_extra_packages for additions that apply across all hosts.
|
|
timezone: "Europe/Berlin"
|
|
ntp_servers:
|
|
- "0.de.pool.ntp.org"
|
|
- "1.de.pool.ntp.org"
|
|
base_extra_packages: []
|
|
base_unneeded_services:
|
|
- avahi-daemon
|
|
- cups
|
|
- rpcbind
|
|
- bluetooth
|
|
|
|
# repo_management
|
|
repo_mgmt_check_internet: true
|
|
repo_mgmt_internet_check_url: "https://dl.rockylinux.org"
|
|
# RedHat family
|
|
epel_enabled: false
|
|
epel_major_version: "9"
|
|
crb_enabled: true
|
|
custom_yum_repos: []
|
|
# custom_yum_repos:
|
|
# - name: "internal"
|
|
# description: "Internal repository"
|
|
# baseurl: "https://repo.example.corp/rocky9/internal/"
|
|
# gpgcheck: true
|
|
# gpgkey: "https://repo.example.corp/RPM-GPG-KEY-internal"
|
|
# Debian family
|
|
ubuntu_universe_enabled: false
|
|
debian_backports_enabled: false
|
|
custom_apt_repos: []
|
|
# custom_apt_repos:
|
|
# - name: "internal"
|
|
# uris: "https://repo.example.corp/ubuntu"
|
|
# suites: "{{ ansible_facts['distribution_release'] }}"
|
|
# components: ["main"]
|
|
# signed_by: "https://repo.example.corp/gpg"
|
|
|
|
# identity_ad
|
|
ad_domain: "example.corp"
|
|
ad_domain_realm: "EXAMPLE.CORP"
|
|
ad_ou: "OU=LinuxServers,DC=example,DC=corp"
|
|
ad_admin_group: "GG_Linux_Admins"
|
|
ad_operator_group: "GG_Linux_Operators"
|
|
sssd_use_fully_qualified_names: false
|
|
|
|
# sudo_rbac
|
|
sudo_rbac_rules:
|
|
- group: "{{ ad_admin_group }}"
|
|
commands: "ALL"
|
|
nopasswd: false
|
|
- group: "{{ ad_operator_group }}"
|
|
commands: "/usr/bin/systemctl restart *, /usr/bin/systemctl status *, /usr/bin/journalctl *"
|
|
nopasswd: false
|
|
|
|
# local_accounts
|
|
breakglass_username: "bglocal_admin"
|
|
breakglass_comment: "Local emergency (break-glass) account"
|
|
local_service_accounts: []
|
|
|
|
# ssh_hardening
|
|
ssh_allow_groups: "linux_admins linux_operators"
|
|
ssh_port: 22
|
|
ssh_max_auth_tries: 3
|
|
ssh_client_alive_interval: 300
|
|
ssh_client_alive_count_max: 2
|
|
|
|
# pam_hardening
|
|
pam_pwquality_minlen: 14
|
|
pam_pwquality_dcredit: -1
|
|
pam_pwquality_ucredit: -1
|
|
pam_pwquality_lcredit: -1
|
|
pam_pwquality_ocredit: -1
|
|
pam_pwquality_retry: 3
|
|
pam_faillock_deny: 5
|
|
pam_faillock_unlock_time: 900
|
|
|
|
# fail2ban
|
|
fail2ban_bantime: 3600
|
|
fail2ban_findtime: 600
|
|
fail2ban_maxretry: 5
|
|
fail2ban_ignoreip: "127.0.0.1/8 ::1 {{ firewall_admin_subnet }}"
|
|
|
|
# banners
|
|
banner_enabled: true
|
|
|
|
# cis_hardening
|
|
cis_level: 1 # raised to 2 in group_vars/dmz.yml
|
|
cis_disable_filesystems:
|
|
- cramfs
|
|
- freevxfs
|
|
- jffs2
|
|
- hfs
|
|
- hfsplus
|
|
- udf
|
|
cis_disable_modules_level2:
|
|
- usb-storage
|
|
- bluetooth
|
|
- firewire-core
|
|
cis_shell_tmout_seconds: 900
|
|
cis_umask: "027"
|
|
cis_disable_ctrl_alt_del: true
|
|
cis_sticky_bit_enforce: true
|
|
cis_journald_persistent: true
|
|
cis_journald_max_use: "500M"
|
|
cis_boot_hardening_enabled: false # requires reboot to take effect, verify manually first
|
|
cis_unowned_files_report_enabled: true
|
|
cis_unowned_files_report_cron_hour: 4
|
|
cis_grub_password_enabled: false
|
|
grub_bootloader_username: "grubadmin"
|
|
grub_bootloader_is_uefi: false
|
|
|
|
# selinux_config
|
|
selinux_state: enforcing
|
|
selinux_policy: targeted
|
|
|
|
# firewall_config
|
|
firewall_default_zone: "drop"
|
|
firewall_admin_subnet: "10.10.5.0/24"
|
|
firewall_allowed_services: []
|
|
firewall_log_denied: "unicast"
|
|
|
|
# falcon_onboarding
|
|
falcon_onboarding_cloud_region: "eu-1"
|
|
# falcon_onboarding_sensor_package_url / falcon_onboarding_sensor_package_src
|
|
# and falcon_cid are set per environment / in vault/secrets.yml
|
|
|
|
# logging_rsyslog
|
|
syslog_collector_host: "siem.example.corp"
|
|
syslog_collector_port: 6514
|
|
syslog_use_tls: true
|
|
syslog_ca_cert_enabled: false
|
|
syslog_ca_cert_src: "siem-ca.crt" # relative to roles/logging_rsyslog/files/
|
|
|
|
# aide_integrity
|
|
aide_check_cron_hour: 5
|
|
aide_check_cron_minute: 0
|
|
aide_notify_email: "root"
|
|
|
|
# patch_mgmt
|
|
dnf_automatic_apply_security: true
|
|
dnf_automatic_apply_other: false
|
|
patch_reboot_window_hosts: []
|
|
patch_reboot_day: "sun"
|
|
patch_reboot_time: "03:00"
|
|
|
|
# backup_agent
|
|
veeam_agent_enabled: false
|
|
# veeam_agent_repo_url (RedHat family) / veeam_agent_apt_repo_line (Debian family)
|
|
# are set per environment, see roles/backup_agent/defaults/main.yml
|