Dev to main #1

Merged
max merged 37 commits from dev into main 2026-08-17 16:15:03 +04:00
12 changed files with 0 additions and 220 deletions
Showing only changes of commit 4e6ffafeef - Show all commits
@@ -1,4 +0,0 @@
Host *
HashKnownHosts yes
GSSAPIAuthentication yes
KexAlgorithms mlkem768x25519-sha256,sntrup761x25519-sha512,curve25519-sha256
@@ -1,29 +0,0 @@
PubkeyAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys
PasswordAuthentication no
KbdInteractiveAuthentication no
UsePAM no
# Disable password authentication — keys only
PasswordAuthentication no
ChallengeResponseAuthentication no
AllowGroups sshusers
PrintMotd no
AcceptEnv LANG LC_*
ClientAliveCountMax 0
ClientAliveInterval 300
Port 22
# Disable root login entirely
PermitRootLogin no
# Limit authentication attempts
MaxAuthTries 3
MaxSessions 3
# Use modern key exchange and ciphers, prioritize post-quantum algorithms (mlkem and sntrup)
KexAlgorithms mlkem768x25519-sha256,sntrup761x25519-sha512,sntrup761x25519-sha512@openssh.com,curve25519-sha256,curve25519-sha256@libssh.org
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com
@@ -1,36 +0,0 @@
---
- name: Configure ssh-server daemon
ansible.builtin.copy:
src: "{{ role_path }}/files/hardened_sshd.conf"
dest: /etc/ssh/sshd_config.d/hardened_sshd.conf
mode: u=rw,g=r,o=r
when: ansible_facts['distribution'] == 'Ubuntu'
- name: Configure ssh-server daemon
ansible.builtin.copy:
src: "{{ role_path }}/files/hardened_sshd.conf"
dest: /etc/ssh/sshd_config.d/hardened_sshd.conf
mode: u=rw,g=r,o=r
when: ansible_facts['distribution'] == 'Debian'
- name: Configure ssh client
remote_user: ansible
ansible.builtin.copy:
src: "{{ role_path }}/files/hardened_ssh.conf"
dest: /etc/ssh/ssh_config.d/hardened_ssh.conf
mode: u=rw,g=r,o=r
- name: Restart ssh-server Debian
remote_user: ansible
ansible.builtin.service:
name: sshd
state: restarted
when: ansible_facts['distribution'] == 'Debian'
- name: Restart ssh-server Ubuntu
remote_user: ansible
ansible.builtin.service:
name: ssh
state: restarted
when: ansible_facts['distribution'] == 'Ubuntu'
@@ -1,42 +0,0 @@
---
- name: Installing basic utils for comfort work (apt-based system)
when: (ansible_facts['distribution'] == "Debian") or
(ansible_facts['distribution'] == "Ubuntu")
ansible.builtin.apt:
name:
- vim
- ranger
- zsh
- rsync
- git
- curl
- kitty
- unattended-upgrades
- ssh
- openssh-server
update-cache: true # Run apt update before installation
become: true
remote_user: ansible
- name: Install qemu-guest-agent on VM
when:
- ansible_facts['os_family'] == "Debian"
- ansible_facts['virtualization_type'] == "kvm"
ansible.builtin.apt:
name: qemu-guest-agent
state: present
update-cache: true # Run apt update before installation
become: true
remote_user: ansible
tags:
- kvm-guests
- packages
# The same commands for Alpine
- name: Update and install packages on Alpine
when: (ansible_facts['distribution'] == "Alpine")
community.general.apk:
name: vim ranger zsh rsync git curl kitty openssh
update_cache: true
remote_user: ansible
-18
View File
@@ -1,18 +0,0 @@
---
- name: Create and set up Ansible user and environment
ansible.builtin.include_tasks: prepare_ansible_user.yaml
- name: Improve SSH configuration
ansible.builtin.include_tasks: harden_ssh.yaml
- name: Install basic utils
ansible.builtin.include_tasks: install_basic_utils.yaml
- name: Remove unnecessary packages
ansible.builtin.include_tasks: remove_packages.yaml
- name: Create and set up a new user
ansible.builtin.include_tasks: create_new_user.yaml
- name: Set locale and time
ansible.builtin.include_tasks: set_locale_and_time.yaml
@@ -1,41 +0,0 @@
---
## Installing packages
- name: Install sudo on apt systems
when: (ansible_facts['distribution'] == "Debian") or
(ansible_facts['distribution'] == "Ubuntu")
ansible.builtin.apt:
name:
- sudo
update-cache: true
# The same commands for Alpine
- name: Update and install packages on Alpine
when: (ansible_facts['distribution'] == "Alpine")
community.general.apk:
name: sudo
update_cache: true
remote_user: ansible
## Creating and setting up the ansible user
## First, create sshusers group to grant ssh access
- name: Ensure group "sshusers" exists
ansible.builtin.group:
name: sshusers
state: present
## Add the user to sshusers (for ssh access) and sudo (gain root access)
- name: Create a new user with a password for Ansible
ansible.builtin.user:
name: ansible
password: "{{ ansible_user_passwd_hash }}"
groups: sshusers,sudo
append: true
## Since password authentication in SSH will be disabled, we need to add an authorized key
- name: Set authorized key taken from file
ansible.posix.authorized_key:
user: ansible
state: present
key: "{{ ansible_ssh_key }}"
@@ -1,31 +0,0 @@
---
# Remove multiple packages at once
- name: Remove unnecessary packages
remote_user: ansible
when: (ansible_facts['distribution'] == "Debian") or
(ansible_facts['distribution'] == "Ubuntu")
ansible.builtin.apt:
name:
- nano
state: absent
become: true
# Clean up all orphaned packages
- name: Remove all orphaned dependencies
remote_user: ansible
when: (ansible_facts['distribution'] == "Debian") or
(ansible_facts['distribution'] == "Ubuntu")
ansible.builtin.apt:
autoremove: true
purge: true
- name: Install sudo package on Alpine
remote_user: ansible
when: (ansible_facts['distribution'] == "Alpine")
community.general.apk:
name:
- nano
state: absent
become: true
@@ -1,19 +0,0 @@
---
- name: Generate locales
community.general.locale_gen:
name:
- en_US.UTF-8
- ru_RU.UTF-8
state: present
- name: Set locale
ansible.builtin.copy:
dest: /etc/locale.conf
mode: '0644'
content: |
LANG=en_US.UTF-8
LC_ALL=en_US.UTF-8
- name: Set time
community.general.timezone:
name: Europe/Samara