Add Debian 13 and Ubuntu 26.04 CIS-inspired hardening playbook

This commit is contained in:
Mateusz Suski
2026-05-06 08:56:45 +00:00
parent 75a11f7650
commit 2fd9c0b5ef
15 changed files with 778 additions and 0 deletions
@@ -0,0 +1,30 @@
---
- name: Validate ssh configuration
ansible.builtin.command: sshd -t
changed_when: false
listen: validate ssh
- name: Restart ssh service safely
ansible.builtin.service:
name: "{{ cis_ssh_service_name }}"
state: restarted
listen: restart ssh
- name: Restart auditd
ansible.builtin.service:
name: auditd
state: restarted
use: service
listen: restart auditd
- name: Restart rsyslog
ansible.builtin.service:
name: rsyslog
state: restarted
listen: restart rsyslog
- name: Restart chrony
ansible.builtin.service:
name: chrony
state: restarted
listen: restart chrony