stuff
This commit is contained in:
@@ -0,0 +1,96 @@
|
||||
- name: Ingress-hardening
|
||||
hosts: animeistrash
|
||||
become: true
|
||||
tasks:
|
||||
- name: Check for an authorized key
|
||||
become: false
|
||||
ansible.builtin.stat:
|
||||
path: "~/.ssh/authorized_keys"
|
||||
register: authorized_keys
|
||||
|
||||
- name: Refuse to lock out
|
||||
ansible.builtin.assert:
|
||||
that:
|
||||
- authorized_keys.stat.exists
|
||||
- authorized_keys.stat.size > 0
|
||||
fail_msg: "No authorized_keys for the connecting user, refusing to disable password auth"
|
||||
|
||||
- name: Install packages
|
||||
ansible.builtin.apt:
|
||||
name:
|
||||
- unattended-upgrades
|
||||
- needrestart
|
||||
state: present
|
||||
|
||||
- name: Harden sshd
|
||||
ansible.builtin.copy:
|
||||
dest: /etc/ssh/sshd_config.d/00-hardening.conf
|
||||
content: |
|
||||
PermitRootLogin prohibit-password
|
||||
PasswordAuthentication no
|
||||
KbdInteractiveAuthentication no
|
||||
PubkeyAuthentication yes
|
||||
PermitEmptyPasswords no
|
||||
MaxAuthTries 3
|
||||
LoginGraceTime 30
|
||||
X11Forwarding no
|
||||
AllowAgentForwarding no
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
validate: /usr/sbin/sshd -t -f %s
|
||||
notify: Reload sshd
|
||||
|
||||
- name: Enable unattended upgrades
|
||||
ansible.builtin.copy:
|
||||
dest: /etc/apt/apt.conf.d/20auto-upgrades
|
||||
content: |
|
||||
APT::Periodic::Update-Package-Lists "1";
|
||||
APT::Periodic::Unattended-Upgrade "1";
|
||||
APT::Periodic::AutocleanInterval "7";
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Configure unattended upgrades
|
||||
ansible.builtin.copy:
|
||||
dest: /etc/apt/apt.conf.d/52unattended-upgrades-local
|
||||
content: |
|
||||
Unattended-Upgrade::Remove-Unused-Kernel-Packages "true";
|
||||
Unattended-Upgrade::Remove-Unused-Dependencies "true";
|
||||
Unattended-Upgrade::Automatic-Reboot "false";
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Restart services after library upgrades
|
||||
ansible.builtin.copy:
|
||||
dest: /etc/needrestart/conf.d/99-auto.conf
|
||||
content: "$nrconf{restart} = 'a';\n"
|
||||
owner: root
|
||||
group: root
|
||||
mode: '0644'
|
||||
|
||||
- name: Enable apt timers
|
||||
ansible.builtin.service:
|
||||
name: "{{ item }}"
|
||||
state: started
|
||||
enabled: true
|
||||
loop:
|
||||
- apt-daily.timer
|
||||
- apt-daily-upgrade.timer
|
||||
|
||||
- name: Debug
|
||||
ansible.builtin.debug:
|
||||
msg:
|
||||
- "Effective sshd config: sudo sshd -T | grep -E 'permitrootlogin|passwordauthentication|maxauthtries'"
|
||||
- "Dry-run upgrades: sudo unattended-upgrade --dry-run --debug"
|
||||
- "Read logs: sudo tail -50 /var/log/unattended-upgrades/unattended-upgrades.log"
|
||||
tags:
|
||||
- always
|
||||
|
||||
handlers:
|
||||
- name: Reload sshd
|
||||
ansible.builtin.service:
|
||||
name: ssh
|
||||
state: reloaded
|
||||
Reference in New Issue
Block a user