We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
2 parents 457b145 + 361f9f5 commit 56be8d5Copy full SHA for 56be8d5
tasks/cis.yml
@@ -13,9 +13,14 @@
13
comment: etcd user
14
state: present
15
16
+- name: Check if separate partition
17
+ ansible.builtin.command: grep '/usr/local ' /proc/mounts
18
+ changed_when: false
19
+ register: partition_result
20
+
21
- name: Copy systemctl config file for kernel hardening
22
ansible.builtin.copy:
- src: "{{ '/usr/local/share/rke2/rke2-cis-sysctl.conf' if usr_local.stat.writeable == True else '/opt/rke2/share/rke2/rke2-cis-sysctl.conf' }}"
23
+ src: "{{ '/usr/local/share/rke2/rke2-cis-sysctl.conf' if (usr_local.stat.writeable) and (partition_result.rc == 1) else '/opt/rke2/share/rke2/rke2-cis-sysctl.conf' }}"
24
dest: /etc/sysctl.d/60-rke2-cis.conf
25
mode: 0600
26
remote_src: true
0 commit comments