REFACTOR: move SSH hardening into a separated role
This commit is contained in:
@@ -0,0 +1,36 @@
|
||||
---
|
||||
|
||||
- name: Configure ssh-server daemon
|
||||
ansible.builtin.copy:
|
||||
src: "{{ role_path }}/files/hardened_sshd.conf"
|
||||
dest: /etc/ssh/sshd_config.d/hardened_sshd.conf
|
||||
mode: u=rw,g=r,o=r
|
||||
when: ansible_facts['distribution'] == 'Ubuntu'
|
||||
|
||||
- name: Configure ssh-server daemon
|
||||
ansible.builtin.copy:
|
||||
src: "{{ role_path }}/files/hardened_sshd.conf"
|
||||
dest: /etc/ssh/sshd_config.d/hardened_sshd.conf
|
||||
mode: u=rw,g=r,o=r
|
||||
when: ansible_facts['distribution'] == 'Debian'
|
||||
|
||||
- name: Configure ssh client
|
||||
remote_user: ansible
|
||||
ansible.builtin.copy:
|
||||
src: "{{ role_path }}/files/hardened_ssh.conf"
|
||||
dest: /etc/ssh/ssh_config.d/hardened_ssh.conf
|
||||
mode: u=rw,g=r,o=r
|
||||
|
||||
- name: Restart ssh-server Debian
|
||||
remote_user: ansible
|
||||
ansible.builtin.service:
|
||||
name: sshd
|
||||
state: restarted
|
||||
when: ansible_facts['distribution'] == 'Debian'
|
||||
|
||||
- name: Restart ssh-server Ubuntu
|
||||
remote_user: ansible
|
||||
ansible.builtin.service:
|
||||
name: ssh
|
||||
state: restarted
|
||||
when: ansible_facts['distribution'] == 'Ubuntu'
|
||||
Reference in New Issue
Block a user