xoxys.kernel/tasks/coredump.yml

34 lines
811 B
YAML

---
- name: Disable core dump for setuid programs
ansible.builtin.template:
src: etc/sysctl.d/99-dump.conf.j2
dest: /etc/sysctl.d/99-dump.conf
owner: root
group: root
mode: "0644"
notify: __kernel_reload
- name: Disable core dump for all users
ansible.builtin.template:
src: etc/security/limits.d/dump.conf.j2
dest: /etc/security/limits.d/dump.conf
owner: root
group: root
mode: "0644"
- name: Disable core dump via soft limits
ansible.builtin.template:
src: etc/profile.d/dump.sh.j2
dest: /etc/profile.d/dump.sh
owner: root
group: root
mode: "0644"
- name: Disable core dump via systemd
ansible.builtin.template:
src: etc/systemd/coredump.conf.j2
dest: /etc/systemd/coredump.conf
owner: root
group: root
mode: "0644"