29 lines
692 B
YAML
29 lines
692 B
YAML
|
---
|
||
|
- block:
|
||
|
- name: Disable core dump for setuid programs
|
||
|
template:
|
||
|
src: etc/sysctl.d/dump.conf.j2
|
||
|
dest: /etc/sysctl.d/dump.conf
|
||
|
owner: root
|
||
|
group: root
|
||
|
mode: 0644
|
||
|
notify: __kernel_reload
|
||
|
|
||
|
- name: Disable core dump for all users
|
||
|
template:
|
||
|
src: etc/security/limits.d/dump.conf.j2
|
||
|
dest: /etc/security/limits.d/dump.conf
|
||
|
owner: root
|
||
|
group: root
|
||
|
mode: 0644
|
||
|
|
||
|
- name: Disable core dump via soft limits
|
||
|
template:
|
||
|
src: etc/profile.d/dump.sh.j2
|
||
|
dest: /etc/profile.d/dump.sh
|
||
|
owner: root
|
||
|
group: root
|
||
|
mode: 0644
|
||
|
become: True
|
||
|
become_user: root
|