Skip to content

Commit 4ded47e

Browse files
committed
Support extending default hardening group
1 parent 1c3090f commit 4ded47e

File tree

5 files changed

+17
-4
lines changed

5 files changed

+17
-4
lines changed

doc/source/configuration/security-hardening.rst

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -54,4 +54,5 @@ host configure, simply set this flag to ``true``:
5454
stackhpc_enable_cis_benchmark_hardening: true
5555
5656
Alternatively, this can be toggled on a per-environment basis by
57-
setting it in an environment specific config file.
57+
setting it in an environment specific config file, or even on
58+
targeted hosts by using group or host vars.

etc/kayobe/ansible/cis.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22

33
- name: Security hardening
4-
hosts: overcloud
4+
hosts: cis-hardening
55
become: true
66
tasks:
77
# TODO: Remove this when Red Hat FIPS policy has been updated to allow ed25519 keys.
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,6 @@
1+
---
2+
###############################################################################
3+
# Feature flags
4+
5+
# Whether or not to run CIS benchmark hardening playbooks. Default is false.
6+
stackhpc_enable_cis_benchmark_hardening: false

etc/kayobe/inventory/groups

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -125,3 +125,9 @@ rgws
125125
[mgrs]
126126
[osds]
127127
[rgws]
128+
129+
###############################################################################
130+
# Feature control groups
131+
132+
[cis-hardening:children]
133+
overcloud

etc/kayobe/stackhpc.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -152,5 +152,5 @@ stackhpc_docker_registry_password: "{{ pulp_password }}"
152152
###############################################################################
153153
# Feature flags
154154

155-
# Whether or not to run CIS benchmark hardening playbooks
156-
stackhpc_enable_cis_benchmark_hardening: false
155+
# Whether or not to run CIS benchmark hardening playbooks. Default is false.
156+
#stackhpc_enable_cis_benchmark_hardening:

0 commit comments

Comments
 (0)