xoxys.kernel/tasks/coredump.yml
Robert Kaussow 1027a1ad75
All checks were successful
continuous-integration/drone/push Build is passing
fix: add missing task to deploy coredump.conf
2022-09-19 16:24:05 +02:00

37 lines
893 B
YAML

---
- block:
- name: Disable core dump for setuid programs
template:
src: etc/sysctl.d/dump.conf.j2
dest: /etc/sysctl.d/dump.conf
owner: root
group: root
mode: 0644
notify: __kernel_reload
- name: Disable core dump for all users
template:
src: etc/security/limits.d/dump.conf.j2
dest: /etc/security/limits.d/dump.conf
owner: root
group: root
mode: 0644
- name: Disable core dump via soft limits
template:
src: etc/profile.d/dump.sh.j2
dest: /etc/profile.d/dump.sh
owner: root
group: root
mode: 0644
- name: Disable core dump via systemd
template:
src: etc/systemd/coredump.conf.j2
dest: /etc/systemd/coredump.conf
owner: root
group: root
mode: 0644
become: True
become_user: root