Files
portfolio/enterprise-infra-simulator/playbooks/hardening.yml
T

127 lines
3.4 KiB
YAML
Raw Normal View History

2026-04-29 23:14:14 +00:00
---
- name: Harden Enterprise Infrastructure Nodes
hosts: all
become: true
gather_facts: true
vars_files:
- vars/vault.yml
pre_tasks:
- name: Validate hardening prerequisites
ansible.builtin.assert:
that:
- ansible_os_family == "Debian"
- cis_level in [1, 2]
fail_msg: "Invalid hardening configuration"
- name: Display hardening information
ansible.builtin.debug:
msg: |
Hardening {{ inventory_hostname }}
CIS Level: {{ cis_level }}
Disable Root Login: {{ disable_root_login }}
roles:
- role: hardening
tags: ['hardening', 'security']
post_tasks:
- name: Display hardening summary
ansible.builtin.debug:
msg: |
Hardening completed successfully!
Host: {{ inventory_hostname }}
2026-04-29 23:14:14 +00:00
when: ansible_os_family == "Debian"
- name: Configure auditd
when: auditd_enabled
2026-04-29 23:14:14 +00:00
block:
- name: Install auditd
ansible.builtin.apt:
2026-04-29 23:14:14 +00:00
name: auditd
state: present
when: ansible_os_family == "Debian"
- name: Configure audit rules
ansible.builtin.template:
2026-04-29 23:14:14 +00:00
src: templates/audit.rules.j2
dest: /etc/audit/rules.d/hardening.rules
mode: '0644'
2026-04-29 23:14:14 +00:00
- name: Enable auditd service
ansible.builtin.service:
2026-04-29 23:14:14 +00:00
name: auditd
state: started
enabled: true
2026-04-29 23:14:14 +00:00
- name: Configure AppArmor
when: apparmor_enabled and ansible_os_family == "Debian"
2026-04-29 23:14:14 +00:00
block:
- name: Install apparmor
ansible.builtin.apt:
2026-04-29 23:14:14 +00:00
name: apparmor
state: present
when: ansible_os_family == "Debian"
- name: Enable apparmor service
ansible.builtin.service:
2026-04-29 23:14:14 +00:00
name: apparmor
state: started
enabled: true
2026-04-29 23:14:14 +00:00
- name: Configure sysctl hardening
ansible.posix.sysctl:
2026-04-29 23:14:14 +00:00
name: "{{ item.key }}"
value: "{{ item.value }}"
state: present
reload: true
2026-04-29 23:14:14 +00:00
loop:
- { key: 'net.ipv4.ip_forward', value: '0' }
- { key: 'net.ipv4.conf.all.send_redirects', value: '0' }
- { key: 'net.ipv4.conf.default.send_redirects', value: '0' }
- { key: 'net.ipv4.tcp_syncookies', value: '1' }
- { key: 'net.ipv4.icmp_echo_ignore_broadcasts', value: '1' }
- name: Set secure file permissions
ansible.builtin.file:
2026-04-29 23:14:14 +00:00
path: "{{ item }}"
mode: '0644'
owner: root
group: root
loop:
- /etc/passwd
- /etc/group
- /etc/shadow
- /etc/gshadow
- name: Lock inactive user accounts
ansible.builtin.command: usermod -L "{{ item }}"
2026-04-29 23:14:14 +00:00
loop: "{{ inactive_users | default([]) }}"
changed_when: false
2026-04-29 23:14:14 +00:00
- name: Configure password policies
community.general.pam_limits:
2026-04-29 23:14:14 +00:00
domain: '*'
limit_type: hard
limit_item: nofile
value: 1024
- name: Generate hardening report
ansible.builtin.template:
2026-04-29 23:14:14 +00:00
src: templates/hardening_report.j2
dest: "/var/log/hardening_report_{{ ansible_date_time.iso8601 }}.log"
mode: '0644'
2026-04-29 23:14:14 +00:00
handlers:
- name: restart sshd
ansible.builtin.service:
2026-04-29 23:14:14 +00:00
name: ssh
state: restarted
- name: restart auditd
ansible.builtin.service:
2026-04-29 23:14:14 +00:00
name: auditd
state: restarted
when: auditd_enabled