Skip to content

Commit f58ef17

Browse files
uk-bollyMrSteve81frederickw082922
authored
v4.0.0 Release to main (#521)
* updated lint files Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * remved not used var Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Lint and spacing Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated file mode to symbolic Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Tidy up layout Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * layout and title update Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * lint files updates Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated variable name for audit template update Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Adde conditional for UID discovery Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * lint layout update Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated variable name Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * removed variable not used Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Removed lines not used Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Updated company naming Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Updated titles Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated license file Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Updated logic for 6.2.11 Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * fix typo in title thanks to @berendiwema Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Updated to latest Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * typo fixes Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated permissions for audit files Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * fix permissions for audit files Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * fixed arm enablement Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * tag updates Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * QA Fixes Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * QA Fixes Default/main.yml Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * Update prelim logic with check_mode Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * Update 5.3.x section Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * Update 5.3.x section Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * Update 5.1.1.x section with improved rsyslog logic Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * Update parse_etc_password logic Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * based on @tgoetheyn improvements and fixes Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * 3.2.3 fix for rds Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * ChangeLog Update Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * update check_mode standard on tasks and typo fixes Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * Community Sync Update Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * Community alignment + typo fixes Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * fix for 5.2.4.x prelim Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * update 1.5.1.6 logic on shell Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * Update 1.5.1.6 log to grep -E Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * lint updates Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * added ability to fetch audit when audit_only chosen Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * update audit logic Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * resolved false warning adding changed_when statement Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Update 1.6.x logic Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * Update changelog Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * update handler for 1.6.x logic Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * Update based on Public 2025 August Fixes and Improvements Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * Tyto fix on handler Remount_tmp Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * roll-back ansible-lint conf Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> * v4.0.0 initial Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Tidy up an reorder Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * alignment Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * fix assert Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * 4.0.0 release updates Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated workflow files Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * v4.0.0 updates Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * added missing module Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * fixed invalid statement in 2.4.1.7 Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * sshd_improvements Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * aide enhancements Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Extra aide variables for sync Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * tmp mount updates Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * fix typo Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated workflows Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated readme Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Removed legacy badge info Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Removed more legacy badge info Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Fixed logic Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Update changelog, lic year, and 3.1.1 improved logic Signed-off-by: Frederick Witty <frederick.witty@gotyto.com> * Update changelog, lic year, and 3.1.1 improved logic Signed-off-by: Frederick Witty <frederick.witty@gotyto.com> * updated Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * removed scheduled update Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Updated company title Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Updated to add ability to use a hashed password - documented in defaults/main.yml Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * updated Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * tidied up comments to make it simpler Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Company title updates Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> * Typo Fix Signed-off-by: Frederick Witty <frederick.witty@gotyto.com> * QA Fixes Signed-off-by: Frederick Witty <frederick.witty@gotyto.com> --------- Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com> Signed-off-by: Frederick Witty <frederickw@mindpointgroup.com> Signed-off-by: Frederick Witty <frederick.witty@gotyto.com> Co-authored-by: Stephen Williams <92482471+MrSteve81@users.noreply.github.com> Co-authored-by: Fred W. <112580756+frederickw082922@users.noreply.github.com> Co-authored-by: Frederick Witty <frederickw@mindpointgroup.com> Co-authored-by: Frederick Witty <frederick.witty@gotyto.com>
1 parent cda1d63 commit f58ef17

File tree

132 files changed

+8467
-6253
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

132 files changed

+8467
-6253
lines changed

.ansible-lint

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,5 @@
11
---
22

3-
parseable: true
43
quiet: true
54
skip_list:
65
- 'package-latest'
Lines changed: 158 additions & 158 deletions
Original file line numberDiff line numberDiff line change
@@ -1,162 +1,162 @@
11
---
22

3-
name: Devel pipeline
4-
5-
on: # yamllint disable-line rule:truthy
6-
pull_request_target:
7-
types: [opened, reopened, synchronize]
8-
branches:
9-
- devel
10-
- benchmark*
11-
paths:
12-
- '**.yml'
13-
- '**.sh'
14-
- '**.j2'
15-
- '**.ps1'
16-
- '**.cfg'
17-
# Allow manual running of workflow
18-
workflow_dispatch:
19-
20-
# A workflow run is made up of one or more jobs
21-
# that can run sequentially or in parallel
22-
jobs:
23-
# This will create messages for first time contributers and direct them to the Discord server
24-
welcome:
25-
runs-on: ubuntu-latest
26-
27-
permissions:
28-
issues: write
29-
pull-requests: write
30-
31-
steps:
32-
- uses: actions/first-interaction@main
33-
with:
34-
repo_token: ${{ secrets.GITHUB_TOKEN }}
35-
issue_message: |-
36-
Congrats on opening your first issue and thank you for taking the time to help improve Ansible-Lockdown!
37-
Please join in the conversation happening on the [Discord Server](https://www.lockdownenterprise.com/discord) as well.
38-
pr_message: |-
39-
Congrats on opening your first pull request and thank you for taking the time to help improve Ansible-Lockdown!
40-
Please join in the conversation happening on the [Discord Server](https://www.lockdownenterprise.com/discord) as well.
41-
42-
# This workflow contains a single job that tests the playbook
43-
playbook-test:
44-
# The type of runner that the job will run on
45-
runs-on: self-hosted
46-
47-
# Allow permissions for AWS auth
48-
permissions:
49-
id-token: write
50-
contents: read
51-
pull-requests: read
52-
53-
env:
54-
ENABLE_DEBUG: ${{ vars.ENABLE_DEBUG }}
55-
# Imported as a variable by terraform
56-
TF_VAR_repository: ${{ github.event.repository.name }}
57-
AWS_REGION: "us-east-1"
58-
ANSIBLE_VERSION: ${{ vars.ANSIBLE_RUNNER_VERSION }}
59-
defaults:
60-
run:
61-
shell: bash
62-
working-directory: .github/workflows/github_linux_IaC
63-
# working-directory: .github/workflows
64-
65-
steps:
66-
67-
- name: Git clone the lockdown repository to test
68-
uses: actions/checkout@v4
69-
with:
70-
ref: ${{ github.event.pull_request.head.sha }}
71-
72-
- name: If a variable for IAC_BRANCH is set use that branch
73-
working-directory: .github/workflows
74-
run: |
75-
if [ ${{ vars.IAC_BRANCH }} != '' ]; then
76-
echo "IAC_BRANCH=${{ vars.IAC_BRANCH }}" >> $GITHUB_ENV
77-
echo "Pipeline using the following IAC branch ${{ vars.IAC_BRANCH }}"
78-
else
79-
echo IAC_BRANCH=main >> $GITHUB_ENV
80-
fi
81-
82-
# Pull in terraform code for linux servers
83-
- name: Clone GitHub IaC plan
84-
uses: actions/checkout@v4
85-
with:
86-
repository: ansible-lockdown/github_linux_IaC
87-
path: .github/workflows/github_linux_IaC
88-
ref: ${{ env.IAC_BRANCH }}
89-
90-
# Uses dedicated restricted role and policy to enable this only for this task
91-
# No credentials are part of github for AWS auth
92-
- name: configure aws credentials
93-
uses: aws-actions/configure-aws-credentials@main
94-
with:
95-
role-to-assume: ${{ secrets.AWS_ASSUME_ROLE }}
96-
role-session-name: ${{ secrets.AWS_ROLE_SESSION }}
97-
aws-region: ${{ env.AWS_REGION }}
98-
99-
- name: DEBUG - Show IaC files
100-
if: env.ENABLE_DEBUG == 'true'
101-
run: |
102-
echo "OSVAR = $OSVAR"
103-
echo "benchmark_type = $benchmark_type"
104-
pwd
105-
env:
106-
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
107-
OSVAR: ${{ vars.OSVAR }}
108-
benchmark_type: ${{ vars.BENCHMARK_TYPE }}
109-
110-
- name: Tofu init
111-
id: init
112-
run: tofu init
113-
env:
114-
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
115-
OSVAR: ${{ vars.OSVAR }}
116-
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
117-
118-
- name: Tofu validate
119-
id: validate
120-
run: tofu validate
121-
env:
122-
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
123-
OSVAR: ${{ vars.OSVAR }}
124-
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
125-
126-
- name: Tofu apply
127-
id: apply
128-
env:
129-
OSVAR: ${{ vars.OSVAR }}
130-
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
131-
TF_VAR_privsubnet_id: ${{ secrets.AWS_PRIVSUBNET_ID }}
132-
TF_VAR_vpc_secgrp_id: ${{ secrets.AWS_VPC_SECGRP_ID }}
133-
run: tofu apply -var-file "${OSVAR}.tfvars" --auto-approve -input=false
3+
name: Devel pipeline
4+
5+
on: # yamllint disable-line rule:truthy
6+
pull_request_target:
7+
types: [opened, reopened, synchronize]
8+
branches:
9+
- devel
10+
- benchmark*
11+
paths:
12+
- '**.yml'
13+
- '**.sh'
14+
- '**.j2'
15+
- '**.ps1'
16+
- '**.cfg'
17+
# Allow manual running of workflow
18+
workflow_dispatch:
19+
20+
# A workflow run is made up of one or more jobs
21+
# that can run sequentially or in parallel
22+
jobs:
23+
# This will create messages for first time contributers and direct them to the Discord server
24+
welcome:
25+
runs-on: ubuntu-latest
26+
27+
permissions:
28+
issues: write
29+
pull-requests: write
30+
31+
steps:
32+
- uses: actions/first-interaction@main
33+
with:
34+
repo_token: ${{ secrets.GITHUB_TOKEN }}
35+
issue_message: |-
36+
Congrats on opening your first issue and thank you for taking the time to help improve Ansible-Lockdown!
37+
Please join in the conversation happening on the [Discord Server](https://www.lockdownenterprise.com/discord) as well.
38+
pr_message: |-
39+
Congrats on opening your first pull request and thank you for taking the time to help improve Ansible-Lockdown!
40+
Please join in the conversation happening on the [Discord Server](https://www.lockdownenterprise.com/discord) as well.
41+
42+
# This workflow contains a single job that tests the playbook
43+
playbook-test:
44+
# The type of runner that the job will run on
45+
runs-on: self-hosted
46+
47+
# Allow permissions for AWS auth
48+
permissions:
49+
id-token: write
50+
contents: read
51+
pull-requests: read
52+
53+
env:
54+
ENABLE_DEBUG: ${{ vars.ENABLE_DEBUG }}
55+
# Imported as a variable by terraform
56+
TF_VAR_repository: ${{ github.event.repository.name }}
57+
AWS_REGION: "us-east-1"
58+
ANSIBLE_VERSION: ${{ vars.ANSIBLE_RUNNER_VERSION }}
59+
defaults:
60+
run:
61+
shell: bash
62+
working-directory: .github/workflows/github_linux_IaC
63+
# working-directory: .github/workflows
64+
65+
steps:
66+
67+
- name: Git clone the lockdown repository to test
68+
uses: actions/checkout@v4
69+
with:
70+
ref: ${{ github.event.pull_request.head.sha }}
71+
72+
- name: If a variable for IAC_BRANCH is set use that branch
73+
working-directory: .github/workflows
74+
run: |
75+
if [ ${{ vars.IAC_BRANCH }} != '' ]; then
76+
echo "IAC_BRANCH=${{ vars.IAC_BRANCH }}" >> $GITHUB_ENV
77+
echo "Pipeline using the following IAC branch ${{ vars.IAC_BRANCH }}"
78+
else
79+
echo IAC_BRANCH=main >> $GITHUB_ENV
80+
fi
81+
82+
# Pull in terraform code for linux servers
83+
- name: Clone GitHub IaC plan
84+
uses: actions/checkout@v4
85+
with:
86+
repository: ansible-lockdown/github_linux_IaC
87+
path: .github/workflows/github_linux_IaC
88+
ref: ${{ env.IAC_BRANCH }}
89+
90+
# Uses dedicated restricted role and policy to enable this only for this task
91+
# No credentials are part of github for AWS auth
92+
- name: configure aws credentials
93+
uses: aws-actions/configure-aws-credentials@main
94+
with:
95+
role-to-assume: ${{ secrets.AWS_ASSUME_ROLE }}
96+
role-session-name: ${{ secrets.AWS_ROLE_SESSION }}
97+
aws-region: ${{ env.AWS_REGION }}
98+
99+
- name: DEBUG - Show IaC files
100+
if: env.ENABLE_DEBUG == 'true'
101+
run: |
102+
echo "OSVAR = $OSVAR"
103+
echo "benchmark_type = $benchmark_type"
104+
pwd
105+
env:
106+
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
107+
OSVAR: ${{ vars.OSVAR }}
108+
benchmark_type: ${{ vars.BENCHMARK_TYPE }}
109+
110+
- name: Tofu init
111+
id: init
112+
run: tofu init
113+
env:
114+
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
115+
OSVAR: ${{ vars.OSVAR }}
116+
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
117+
118+
- name: Tofu validate
119+
id: validate
120+
run: tofu validate
121+
env:
122+
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
123+
OSVAR: ${{ vars.OSVAR }}
124+
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
125+
126+
- name: Tofu apply
127+
id: apply
128+
env:
129+
OSVAR: ${{ vars.OSVAR }}
130+
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
131+
TF_VAR_privsubnet_id: ${{ secrets.AWS_PRIVSUBNET_ID }}
132+
TF_VAR_vpc_secgrp_id: ${{ secrets.AWS_VPC_SECGRP_ID }}
133+
run: tofu apply -var-file "${OSVAR}.tfvars" --auto-approve -input=false
134134

135135
## Debug Section
136-
- name: DEBUG - Show Ansible hostfile
137-
if: env.ENABLE_DEBUG == 'true'
138-
run: cat hosts.yml
139-
140-
# Aws deployments taking a while to come up insert sleep or playbook fails
141-
142-
- name: Sleep to allow system to come up
143-
run: sleep ${{ vars.BUILD_SLEEPTIME }}
144-
145-
# Run the Ansible playbook
146-
- name: Run_Ansible_Playbook
147-
env:
148-
ANSIBLE_HOST_KEY_CHECKING: "false"
149-
ANSIBLE_DEPRECATION_WARNINGS: "false"
150-
run: |
151-
/opt/ansible_${{ env.ANSIBLE_VERSION }}_venv/bin/ansible-playbook -i hosts.yml --private-key ~/.ssh/le_runner ../../../site.yml
152-
153-
# Remove test system - User secrets to keep if necessary
154-
155-
- name: Tofu Destroy
156-
if: always() && env.ENABLE_DEBUG == 'false'
157-
env:
158-
OSVAR: ${{ vars.OSVAR }}
159-
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
160-
TF_VAR_privsubnet_id: ${{ secrets.AWS_PRIVSUBNET_ID }}
161-
TF_VAR_vpc_secgrp_id: ${{ secrets.AWS_VPC_SECGRP_ID }}
162-
run: tofu destroy -var-file "${OSVAR}.tfvars" --auto-approve -input=false
136+
- name: DEBUG - Show Ansible hostfile
137+
if: env.ENABLE_DEBUG == 'true'
138+
run: cat hosts.yml
139+
140+
# Aws deployments taking a while to come up insert sleep or playbook fails
141+
142+
- name: Sleep to allow system to come up
143+
run: sleep ${{ vars.BUILD_SLEEPTIME }}
144+
145+
# Run the Ansible playbook
146+
- name: Run_Ansible_Playbook
147+
env:
148+
ANSIBLE_HOST_KEY_CHECKING: "false"
149+
ANSIBLE_DEPRECATION_WARNINGS: "false"
150+
run: |
151+
/opt/ansible_${{ env.ANSIBLE_VERSION }}_venv/bin/ansible-playbook -i hosts.yml --private-key ~/.ssh/le_runner ../../../site.yml
152+
153+
# Remove test system - User secrets to keep if necessary
154+
155+
- name: Tofu Destroy
156+
if: always() && env.ENABLE_DEBUG == 'false'
157+
env:
158+
OSVAR: ${{ vars.OSVAR }}
159+
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
160+
TF_VAR_privsubnet_id: ${{ secrets.AWS_PRIVSUBNET_ID }}
161+
TF_VAR_vpc_secgrp_id: ${{ secrets.AWS_VPC_SECGRP_ID }}
162+
run: tofu destroy -var-file "${OSVAR}.tfvars" --auto-approve -input=false

.github/workflows/export_badges_private.yml

Lines changed: 0 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -2,18 +2,10 @@
22

33
name: Export Private Repo Badges
44

5-
# Use different minute offsets with the same hourly pattern:
6-
# Repo Group Suggested Cron Expression Explanation
7-
# Group A 0 */6 * * * Starts at top of hour
8-
# Group B 10 */6 * * * Starts at 10 after
9-
# And So On
10-
115
on:
126
push:
137
branches:
148
- latest
15-
schedule:
16-
- cron: '0 */6 * * *'
179
workflow_dispatch:
1810

1911
jobs:

0 commit comments

Comments
 (0)