diff --git a/.github/workflows/lint-yaml.yml b/.github/workflows/lint-yaml.yml new file mode 100644 index 0000000..e71bac1 --- /dev/null +++ b/.github/workflows/lint-yaml.yml @@ -0,0 +1,58 @@ +name: Lint YAML and Auto-commit Fixes +on: + pull_request: + branches: [main] +jobs: + lint-and-fix: + name: Lint YAML and Auto-commit Fixes + if: github.event.pull_request.draft == false + runs-on: ubuntu-latest + permissions: + contents: write # Needed to push commits to the PR branch + steps: + - name: Checkout PR Branch + uses: actions/checkout@v3 + with: + ref: ${{ github.head_ref }} # Checkout the PR head branch + token: ${{ secrets.GITHUB_TOKEN }} # Use GITHUB_TOKEN for commit/push + - name: Set up Python + uses: actions/setup-python@v4 + with: + python-version: 3.x + - name: Install yamlfix + run: pip install yamlfix + - name: Run yamlfix to find and fix issues + id: yamlfix + run: | + # The yamlfix command will automatically find and apply fixes to any YAML files. + # It uses the `.yamllint.yml` configuration file for its rules. + yamlfix --exclude "**/templates/**" . + + # Check if there are any changes to commit. + # `git status --porcelain` will be empty if there are no changes. + if [[ -n $(git status --porcelain) ]]; then + echo "Changes detected, will commit and push." + echo "changes_detected=true" >> $GITHUB_ENV + else + echo "No changes detected." + echo "changes_detected=false" >> $GITHUB_ENV + fi + - name: Commit and Push Fixes + if: env.changes_detected == 'true' + run: | + git config --global user.name 'github-actions[bot]' + git config --global user.email 'github-actions[bot]@users.noreply.github.com' + git add . + git commit --amend --no-edit + git push --force-with-lease origin ${{ github.head_ref }} + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + - name: Final Check + if: env.changes_detected == 'true' + run: | + echo "YAML fixes have been committed and pushed to the PR branch." + echo "The PR will now reflect these automated changes." + - name: No Changes Needed + if: env.changes_detected == 'false' + run: |- + echo "✅ All YAML files are correctly formatted. No changes needed." diff --git a/.github/workflows/lint.yml b/.github/workflows/lint.yml index 692ceec..5168868 100644 --- a/.github/workflows/lint.yml +++ b/.github/workflows/lint.yml @@ -15,4 +15,4 @@ jobs: - uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0 - name: Lint Ansible Playbook - uses: ansible-lint@main \ No newline at end of file + uses: ansible/ansible-lint@main \ No newline at end of file diff --git a/requirements.yml b/requirements.yml index 4cbfe2b..dcab617 100644 --- a/requirements.yml +++ b/requirements.yml @@ -11,4 +11,4 @@ collections: - name: community.general version: 11.3.0 source: https://github.com/ansible-collections/community.general.git - type: git \ No newline at end of file + type: git diff --git a/roles/users_add/handlers/main.yml b/roles/users_add/handlers/main.yml index 0340d73..8b42d61 100644 --- a/roles/users_add/handlers/main.yml +++ b/roles/users_add/handlers/main.yml @@ -1,5 +1,5 @@ - name: Force password change on first login ansible.builtin.command: "chage -d 0 {{ item.username }}" loop: "{{ users_add_userlist | default([]) }}" - register: chage_output # This will register the output of the command to a variable - changed_when: "'Password aging updated' in chage_output.stdout" + register: users_add_chage_output # This will register the output of the command to a variable + changed_when: "'Password aging updated' in users_add_chage_output.stdout" diff --git a/roles/users_add/tasks/main.yml b/roles/users_add/tasks/main.yml index 43d848e..fcf45ac 100644 --- a/roles/users_add/tasks/main.yml +++ b/roles/users_add/tasks/main.yml @@ -299,25 +299,35 @@ state: started daemon_reload: true -- name: Setup MOTD for Debian systems (different from Ubuntu) +- name: Setup MOTD for Debian systems + when: ansible_os_family == "Debian" block: - name: Check if this is a Debian-based system without update-motd ansible.builtin.command: which update-motd - register: update_motd_exists + register: users_add_update_motd_exists failed_when: false changed_when: false + - name: Ensure PAM MOTD configuration for Ubuntu + ansible.builtin.lineinfile: + path: /etc/pam.d/sshd + line: "session optional pam_motd.so motd=/run/motd.dynamic" + insertafter: "# Print the message of the day upon successful login" + state: present + when: ansible_distribution == "Ubuntu" and users_add_update_motd_exists.rc != 0 + - name: Create PAM MOTD configuration for Debian ansible.builtin.lineinfile: path: /etc/pam.d/sshd line: "session optional pam_motd.so motd=/var/cache/motd-security-status" insertafter: "# Print the message of the day upon successful login" state: present - when: update_motd_exists.rc != 0 + become: true + when: ansible_distribution == "Debian" and users_add_update_motd_exists.rc != 0 - name: Generate initial security status and dynamic MOTD - ansible.builtin.shell: /usr/local/bin/update-security-status - when: update_motd_exists.rc != 0 + ansible.builtin.command: /usr/local/bin/update-security-status + when: users_add_update_motd_exists.rc != 0 changed_when: false - name: Ensure cache file permissions @@ -327,6 +337,4 @@ group: root mode: '0644' state: touch - when: update_motd_exists.rc != 0 - - when: ansible_distribution == "Debian" + when: users_add_update_motd_exists.rc != 0 diff --git a/setup-playbook.yml b/setup-playbook.yml index a961f16..f766f86 100644 --- a/setup-playbook.yml +++ b/setup-playbook.yml @@ -147,7 +147,7 @@ reboot: "{{ AUTO_UPDATES_OPTIONS.reboot | default(true) }}" reboot_from_time: "{{ AUTO_UPDATES_OPTIONS.reboot_from_time | default('2:00') }}" reboot_time_margin_mins: "{{ AUTO_UPDATES_OPTIONS.reboot_time_margin_mins | default(20) }}" - custom_origins: "{{ AUTO_UPDATES_OPTIONS.custom_origins | default('') }}" + custom_origins: "{{ AUTO_UPDATES_OPTIONS.custom_origins | default('') }}" # === LOGIN AND SESSION MANAGEMENT === logind: "{{ LOGIND_HARDENING }}" # Configure systemd-logind settings @@ -166,7 +166,7 @@ sshd_admin_net: "{{ SSHD_ADMIN_NET }}" # Networks allowed for SSH admin access sshd_allow_users: "{{ SSH_USERLIST | map(attribute='username') | list }}" # Users allowed SSH access sshd_allow_groups: "{{ SSH_USERLIST | map(attribute='username') | list }}" # Groups allowed SSH access - sshd_login_grace_time: "{{ SSHD_LOGIN_GRACE_TIME | default(60)}}" # SSH login grace period + sshd_login_grace_time: "{{ SSHD_LOGIN_GRACE_TIME | default(60) }}" # SSH login grace period sshd_max_auth_tries: "{{ SSHD_MAX_AUTH_TRIES | default(3) }}" # Maximum SSH auth attempts sshd_allow_tcp_forwarding: "{{ SSHD_ALLOW_TCP_FORWARDING | default(false) }}" # Allow SSH port forwarding sshd_client_alive_interval: "{{ SSHD_TIMEOUT_SECS | default(300) }}" # SSH client timeout (5 min default) @@ -248,14 +248,14 @@ changed_when: false # Prevent task from always reporting "changed" tags: [post-config, custom-commands] - - name: Create PAM MOTD configuration for Debian (erased by hardening manage_pam config template) + - name: Create PAM MOTD configuration for Debian-family (erased by hardening manage_pam config template) ansible.builtin.lineinfile: path: /etc/pam.d/sshd line: "session optional pam_motd.so motd=/var/cache/motd-security-status" insertafter: "# Print the message of the day upon successful login" state: present become: true - when: ansible_distribution == "Debian" + when: ansible_os_family == "Debian" # Post-execution validation and reporting post_tasks: