refctor: rework ci to ue ansible-lint and fix molecule
All checks were successful
ci/woodpecker/push/lint Pipeline was successful
ci/woodpecker/push/test Pipeline was successful
ci/woodpecker/push/docs Pipeline was successful
ci/woodpecker/push/notify Pipeline was successful

This commit is contained in:
Robert Kaussow 2024-08-19 16:06:14 +02:00
parent d0cfe2524e
commit efc4b023fb
Signed by: xoxys
GPG Key ID: 4E692A2EAECC03C0
12 changed files with 47 additions and 38 deletions

View File

@ -1,15 +0,0 @@
---
ansible:
custom_modules:
- iptables_raw
- openssl_pkcs12
- proxmox_kvm
- ucr
- corenetworks_dns
- corenetworks_token
rules:
exclude_files:
- "LICENSE*"
- "**/*.md"
- "**/*.ini"

View File

@ -9,11 +9,11 @@ steps:
- name: generate - name: generate
image: quay.io/thegeeklab/ansible-doctor image: quay.io/thegeeklab/ansible-doctor
environment: environment:
ANSIBLE_DOCTOR_EXCLUDE_FILES: molecule/ ANSIBLE_DOCTOR_EXCLUDE_FILES: "['molecule/']"
ANSIBLE_DOCTOR_FORCE_OVERWRITE: "true" ANSIBLE_DOCTOR_RENDERER__FORCE_OVERWRITE: "true"
ANSIBLE_DOCTOR_LOG_LEVEL: INFO ANSIBLE_DOCTOR_LOGGING__LEVEL: info
ANSIBLE_DOCTOR_ROLE_NAME: ${CI_REPO_NAME} ANSIBLE_DOCTOR_ROLE__NAME: ${CI_REPO_NAME}
ANSIBLE_DOCTOR_TEMPLATE: readme ANSIBLE_DOCTOR_TEMPLATE__NAME: readme
- name: format - name: format
image: quay.io/thegeeklab/alpine-tools image: quay.io/thegeeklab/alpine-tools

View File

@ -6,10 +6,10 @@ when:
- ${CI_REPO_DEFAULT_BRANCH} - ${CI_REPO_DEFAULT_BRANCH}
steps: steps:
- name: ansible-later - name: ansible-lint
image: quay.io/thegeeklab/ansible-later:4 image: quay.io/thegeeklab/ansible-dev-tools:1
commands: commands:
- ansible-later - ansible-lint
environment: environment:
FORCE_COLOR: "1" FORCE_COLOR: "1"

View File

@ -7,7 +7,7 @@ when:
variables: variables:
- &molecule_base - &molecule_base
image: quay.io/thegeeklab/molecule:6 image: quay.io/thegeeklab/ansible-dev-tools:1
group: molecule group: molecule
environment: environment:
PY_COLORS: "1" PY_COLORS: "1"

20
.yamllint Normal file
View File

@ -0,0 +1,20 @@
---
extends: default
rules:
truthy:
allowed-values: ["True", "False"]
comments:
min-spaces-from-content: 1
comments-indentation: False
line-length: disable
braces:
min-spaces-inside: 0
max-spaces-inside: 1
brackets:
min-spaces-inside: 0
max-spaces-inside: 0
indentation: enable
octal-values:
forbid-implicit-octal: True
forbid-explicit-octal: True

View File

@ -21,6 +21,3 @@ galaxy_info:
- sshd - sshd
- security - security
dependencies: [] dependencies: []
collections:
- xoxys.general
- community.general

View File

@ -4,11 +4,11 @@ driver:
dependency: dependency:
name: galaxy name: galaxy
options: options:
role-file: molecule/requirements.yml role-file: requirements.yml
requirements-file: molecule/requirements.yml requirements-file: requirements.yml
platforms: platforms:
- name: "rocky9-sshd" - name: "rocky9-sshd"
server_type: "CX22" server_type: "cx22"
image: "rocky-9" image: "rocky-9"
provisioner: provisioner:
name: ansible name: ansible

View File

@ -1,4 +0,0 @@
---
collections: []
roles: []

7
requirements.yml Normal file
View File

@ -0,0 +1,7 @@
---
collections:
- name: https://gitea.rknet.org/ansible/xoxys.general
type: git
version: main
roles: []

View File

@ -1,5 +1,6 @@
--- ---
- ansible.builtin.include_tasks: "{{ lookup('first_found', params) }}" - name: Configure sshd
ansible.builtin.include_tasks: "{{ lookup('first_found', params) }}"
vars: vars:
params: params:
files: files:
@ -8,5 +9,6 @@
- "ssh_default.yml" - "ssh_default.yml"
paths: paths:
- "tasks" - "tasks"
- ansible.builtin.include_tasks: ssh_2fa.yml - name: Configure sshd 2FA
ansible.builtin.include_tasks: ssh_2fa.yml
when: sshd_google_auth_enabled | bool when: sshd_google_auth_enabled | bool

View File

@ -22,6 +22,8 @@
ansible.builtin.shell: ansible.builtin.shell:
awk '$5 >= {{ sshd_moduli_minimum }}' /etc/ssh/moduli > /etc/ssh/moduli.new ; awk '$5 >= {{ sshd_moduli_minimum }}' /etc/ssh/moduli > /etc/ssh/moduli.new ;
[ -r /etc/ssh/moduli.new -a -s /etc/ssh/moduli.new ] && mv /etc/ssh/moduli.new /etc/ssh/moduli || true [ -r /etc/ssh/moduli.new -a -s /etc/ssh/moduli.new ] && mv /etc/ssh/moduli.new /etc/ssh/moduli || true
register: __sshd_register_moduli
changed_when: __sshd_register_moduli.rc != 0
notify: __sshd_restart notify: __sshd_restart
when: __sshd_register_moduli.stdout when: __sshd_register_moduli.stdout

View File

@ -1,6 +1,6 @@
--- ---
- name: Hardening sshd config - name: Hardening sshd config
ucr: xoxys.general.ucr:
path: "{{ item.path }}" path: "{{ item.path }}"
value: "{{ item.value }}" value: "{{ item.value }}"
loop: loop:
@ -33,7 +33,7 @@
notify: __sshd_restart notify: __sshd_restart
- name: Set allowed ssh groups - name: Set allowed ssh groups
ucr: xoxys.general.ucr:
path: "auth/sshd/group/{{ item }}" path: "auth/sshd/group/{{ item }}"
value: "yes" value: "yes"
loop: "{{ sshd_allow_groups }}" loop: "{{ sshd_allow_groups }}"