xoxys.kernel/tasks/kernel.yml

31 lines
761 B
YAML

---
- name: Set default kernel hardening parameters
ansible.builtin.template:
src: etc/sysctl.d/99-local.conf.j2
dest: /etc/sysctl.d/99-local.conf
owner: root
group: root
mode: "0644"
notify: __kernel_reload
- name: Deploy custom kernel configurations
ansible.builtin.template:
src: etc/sysctl.d/xx-custom.conf.j2
dest: "/etc/sysctl.d/{{ item.file }}.conf"
owner: root
group: root
mode: "0644"
loop: "{{ kernel_custom_config }}"
loop_control:
label: "{{ item.file }}"
notify: __kernel_reload
- name: Deploy custom modprobe
ansible.builtin.template:
src: etc/modprobe.d/custom.conf.j2
dest: /etc/modprobe.d/custom.conf
owner: root
group: root
mode: "0644"
notify: __kernel_reload