added again ansible-role-security

This commit is contained in:
git
2024-01-25 14:48:21 +01:00
parent 6dcf62acd7
commit eee0e16ae8
19 changed files with 460 additions and 0 deletions

View File

@@ -0,0 +1,4 @@
APT::Periodic::Update-Package-Lists "1";
APT::Periodic::Download-Upgradeable-Packages "1";
APT::Periodic::AutocleanInterval "7";
APT::Periodic::Unattended-Upgrade "1";

View File

@@ -0,0 +1,20 @@
Unattended-Upgrade::Automatic-Reboot "{{ security_autoupdate_reboot }}";
Unattended-Upgrade::Automatic-Reboot-Time "{{ security_autoupdate_reboot_time }}";
{% if security_autoupdate_mail_to %}
Unattended-Upgrade::Mail "{{ security_autoupdate_mail_to }}";
{% if security_autoupdate_mail_on_error %}
Unattended-Upgrade::MailOnlyOnError "true";
{% endif %}
{% endif %}
Unattended-Upgrade::Allowed-Origins {
"${distro_id} ${distro_codename}-security";
// "${distro_id} ${distro_codename}-updates";
};
Unattended-Upgrade::Package-Blacklist{
{% for package in security_autoupdate_blacklist %}
"{{package}}";
{% endfor %}
}

View File

@@ -0,0 +1,4 @@
[sshd]
enabled = true
port = {{ security_ssh_port }}
filter = sshd