Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
58 changes: 58 additions & 0 deletions .github/workflows/lint-yaml.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,58 @@
name: Lint YAML and Auto-commit Fixes
on:
pull_request:
branches: [main]
jobs:
lint-and-fix:
name: Lint YAML and Auto-commit Fixes
if: github.event.pull_request.draft == false
runs-on: ubuntu-latest
permissions:
contents: write # Needed to push commits to the PR branch
steps:
- name: Checkout PR Branch
uses: actions/checkout@v3
with:
ref: ${{ github.head_ref }} # Checkout the PR head branch
token: ${{ secrets.GITHUB_TOKEN }} # Use GITHUB_TOKEN for commit/push
- name: Set up Python
uses: actions/setup-python@v4
with:
python-version: 3.x
- name: Install yamlfix
run: pip install yamlfix
- name: Run yamlfix to find and fix issues
id: yamlfix
run: |
# The yamlfix command will automatically find and apply fixes to any YAML files.
# It uses the `.yamllint.yml` configuration file for its rules.
yamlfix --exclude "**/templates/**" .

# Check if there are any changes to commit.
# `git status --porcelain` will be empty if there are no changes.
if [[ -n $(git status --porcelain) ]]; then
echo "Changes detected, will commit and push."
echo "changes_detected=true" >> $GITHUB_ENV
else
echo "No changes detected."
echo "changes_detected=false" >> $GITHUB_ENV
fi
- name: Commit and Push Fixes
if: env.changes_detected == 'true'
run: |
git config --global user.name 'github-actions[bot]'
git config --global user.email 'github-actions[bot]@users.noreply.github.com'
git add .
git commit --amend --no-edit
git push --force-with-lease origin ${{ github.head_ref }}
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
- name: Final Check
if: env.changes_detected == 'true'
run: |
echo "YAML fixes have been committed and pushed to the PR branch."
echo "The PR will now reflect these automated changes."
- name: No Changes Needed
if: env.changes_detected == 'false'
run: |-
echo "✅ All YAML files are correctly formatted. No changes needed."
2 changes: 1 addition & 1 deletion .github/workflows/lint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,4 +15,4 @@ jobs:

- uses: actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v5.0.0
- name: Lint Ansible Playbook
uses: ansible-lint@main
uses: ansible/ansible-lint@main
2 changes: 1 addition & 1 deletion requirements.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,4 +11,4 @@ collections:
- name: community.general
version: 11.3.0
source: https://github.com/ansible-collections/community.general.git
type: git
type: git
4 changes: 2 additions & 2 deletions roles/users_add/handlers/main.yml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
- name: Force password change on first login
ansible.builtin.command: "chage -d 0 {{ item.username }}"
loop: "{{ users_add_userlist | default([]) }}"
register: chage_output # This will register the output of the command to a variable
changed_when: "'Password aging updated' in chage_output.stdout"
register: users_add_chage_output # This will register the output of the command to a variable
changed_when: "'Password aging updated' in users_add_chage_output.stdout"
24 changes: 16 additions & 8 deletions roles/users_add/tasks/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -44,18 +44,18 @@
# ===================================================================
# Limited sudo access for user: {{ item.username }}.
# ===================================================================
#

Check failure on line 47 in roles/users_add/tasks/main.yml

View workflow job for this annotation

GitHub Actions / build

yaml[trailing-spaces]

Trailing spaces
# This user is granted limited sudo privileges for system maintenance.
#

Check failure on line 49 in roles/users_add/tasks/main.yml

View workflow job for this annotation

GitHub Actions / build

yaml[trailing-spaces]

Trailing spaces
# ALLOWED COMMANDS: {{ item.non_admin_allowed_commands }}
#
# To see this help again, run: sudo cat /etc/sudoers.d/{{ item.username }}
# ===================================================================

Check failure on line 54 in roles/users_add/tasks/main.yml

View workflow job for this annotation

GitHub Actions / build

yaml[trailing-spaces]

Trailing spaces
# Show lecture message on sudo use
Defaults:{{ item.username }} lecture = always
Defaults:{{ item.username }} lecture_file = /etc/sudoers.d/.{{ item.username }}_lecture

Check failure on line 58 in roles/users_add/tasks/main.yml

View workflow job for this annotation

GitHub Actions / build

yaml[trailing-spaces]

Trailing spaces
# Actual sudo rules:
{{ item.username }} ALL=(ALL) {{ item.non_admin_allowed_commands }}
state: present
Expand Down Expand Up @@ -299,25 +299,35 @@
state: started
daemon_reload: true

- name: Setup MOTD for Debian systems (different from Ubuntu)
- name: Setup MOTD for Debian systems
when: ansible_os_family == "Debian"
block:
- name: Check if this is a Debian-based system without update-motd
ansible.builtin.command: which update-motd
register: update_motd_exists
register: users_add_update_motd_exists
failed_when: false
changed_when: false

- name: Ensure PAM MOTD configuration for Ubuntu
ansible.builtin.lineinfile:
path: /etc/pam.d/sshd
line: "session optional pam_motd.so motd=/run/motd.dynamic"
insertafter: "# Print the message of the day upon successful login"
state: present
when: ansible_distribution == "Ubuntu" and users_add_update_motd_exists.rc != 0

- name: Create PAM MOTD configuration for Debian
ansible.builtin.lineinfile:
path: /etc/pam.d/sshd
line: "session optional pam_motd.so motd=/var/cache/motd-security-status"
insertafter: "# Print the message of the day upon successful login"
state: present
when: update_motd_exists.rc != 0
become: true
when: ansible_distribution == "Debian" and users_add_update_motd_exists.rc != 0

- name: Generate initial security status and dynamic MOTD
ansible.builtin.shell: /usr/local/bin/update-security-status
when: update_motd_exists.rc != 0
ansible.builtin.command: /usr/local/bin/update-security-status
when: users_add_update_motd_exists.rc != 0
changed_when: false

- name: Ensure cache file permissions
Expand All @@ -327,6 +337,4 @@
group: root
mode: '0644'
state: touch
when: update_motd_exists.rc != 0

when: ansible_distribution == "Debian"
when: users_add_update_motd_exists.rc != 0
8 changes: 4 additions & 4 deletions setup-playbook.yml
Original file line number Diff line number Diff line change
Expand Up @@ -147,7 +147,7 @@
reboot: "{{ AUTO_UPDATES_OPTIONS.reboot | default(true) }}"
reboot_from_time: "{{ AUTO_UPDATES_OPTIONS.reboot_from_time | default('2:00') }}"
reboot_time_margin_mins: "{{ AUTO_UPDATES_OPTIONS.reboot_time_margin_mins | default(20) }}"
custom_origins: "{{ AUTO_UPDATES_OPTIONS.custom_origins | default('') }}"
custom_origins: "{{ AUTO_UPDATES_OPTIONS.custom_origins | default('') }}"

# === LOGIN AND SESSION MANAGEMENT ===
logind: "{{ LOGIND_HARDENING }}" # Configure systemd-logind settings
Expand All @@ -166,7 +166,7 @@
sshd_admin_net: "{{ SSHD_ADMIN_NET }}" # Networks allowed for SSH admin access
sshd_allow_users: "{{ SSH_USERLIST | map(attribute='username') | list }}" # Users allowed SSH access
sshd_allow_groups: "{{ SSH_USERLIST | map(attribute='username') | list }}" # Groups allowed SSH access
sshd_login_grace_time: "{{ SSHD_LOGIN_GRACE_TIME | default(60)}}" # SSH login grace period
sshd_login_grace_time: "{{ SSHD_LOGIN_GRACE_TIME | default(60) }}" # SSH login grace period
sshd_max_auth_tries: "{{ SSHD_MAX_AUTH_TRIES | default(3) }}" # Maximum SSH auth attempts
sshd_allow_tcp_forwarding: "{{ SSHD_ALLOW_TCP_FORWARDING | default(false) }}" # Allow SSH port forwarding
sshd_client_alive_interval: "{{ SSHD_TIMEOUT_SECS | default(300) }}" # SSH client timeout (5 min default)
Expand Down Expand Up @@ -248,14 +248,14 @@
changed_when: false # Prevent task from always reporting "changed"
tags: [post-config, custom-commands]

- name: Create PAM MOTD configuration for Debian (erased by hardening manage_pam config template)
- name: Create PAM MOTD configuration for Debian-family (erased by hardening manage_pam config template)
ansible.builtin.lineinfile:
path: /etc/pam.d/sshd
line: "session optional pam_motd.so motd=/var/cache/motd-security-status"
insertafter: "# Print the message of the day upon successful login"
state: present
become: true
when: ansible_distribution == "Debian"
when: ansible_os_family == "Debian"

# Post-execution validation and reporting
post_tasks:
Expand Down
Loading