xoxys.kernel/tasks/kernel.yml

34 lines
859 B
YAML
Raw Normal View History

2019-11-04 00:22:18 +01:00
---
- block:
- name: Set default kernel hardening parameters
2019-11-04 00:22:18 +01:00
template:
src: etc/sysctl.d/99-local.conf.j2
dest: /etc/sysctl.d/99-local.conf
2019-11-04 00:22:18 +01:00
owner: root
group: root
mode: 0644
notify: __kernel_reload
- name: Deploy custom kernel configurations
template:
src: etc/sysctl.d/xx-custom.conf.j2
dest: "/etc/sysctl.d/{{ item.file }}.conf"
owner: root
group: root
mode: 0644
loop: "{{ kernel_custom_config }}"
loop_control:
label: "{{ item.file }}"
notify: __kernel_reload
2019-11-04 00:22:18 +01:00
- name: Deploy custom modprobe
template:
src: etc/modprobe.d/custom.conf.j2
dest: /etc/modprobe.d/custom.conf
owner: root
group: root
mode: 0644
notify: __kernel_reload
become: True
become_user: root