disabled systemd_detect_virt due to issues
This commit is contained in:
parent
7e3287de15
commit
545f925e65
1 changed files with 6 additions and 6 deletions
12
common.yml
12
common.yml
|
@ -157,9 +157,9 @@
|
||||||
group: root
|
group: root
|
||||||
mode: '0644'
|
mode: '0644'
|
||||||
|
|
||||||
- name: "Register if we are running baremetal (none), virtualized (kvm) or container (lxc)"
|
# - name: "Register if we are running baremetal (none), virtualized (kvm) or container (lxc)"
|
||||||
command: systemd-detect-virt --container
|
# command: systemd-detect-virt --container
|
||||||
register: systemd_detect_virt
|
# register: systemd_detect_virt
|
||||||
|
|
||||||
# Set vm.swappiness to 1 in /etc/sysctl.conf
|
# Set vm.swappiness to 1 in /etc/sysctl.conf
|
||||||
- name: "Set swappiness to zero in sysctl.conf"
|
- name: "Set swappiness to zero in sysctl.conf"
|
||||||
|
@ -169,7 +169,7 @@
|
||||||
state: present
|
state: present
|
||||||
reload: yes
|
reload: yes
|
||||||
sysctl_file: /etc/sysctl.conf
|
sysctl_file: /etc/sysctl.conf
|
||||||
when: systemd_detect_virt.stdout == "none"
|
# when: systemd_detect_virt.stdout == "none"
|
||||||
|
|
||||||
- name: "Set nf_conntrack_max to 131072 in sysctl.conf, suitable for max 4gb of ram, conntrack_max = RAMSIZE (in bytes)/16384/2 = 4*1024*1024*1024/16384/2 = 4*32768 = 131072"
|
- name: "Set nf_conntrack_max to 131072 in sysctl.conf, suitable for max 4gb of ram, conntrack_max = RAMSIZE (in bytes)/16384/2 = 4*1024*1024*1024/16384/2 = 4*32768 = 131072"
|
||||||
sysctl:
|
sysctl:
|
||||||
|
@ -179,7 +179,7 @@
|
||||||
reload: yes
|
reload: yes
|
||||||
sysctl_file: /etc/sysctl.conf
|
sysctl_file: /etc/sysctl.conf
|
||||||
#source: https://support.huaweicloud.com/intl/en-us/trouble-ecs/ecs_trouble_0324.html
|
#source: https://support.huaweicloud.com/intl/en-us/trouble-ecs/ecs_trouble_0324.html
|
||||||
when: systemd_detect_virt.stdout == "none"
|
# when: systemd_detect_virt.stdout == "none"
|
||||||
|
|
||||||
- name: Disable IPv6 with sysctl
|
- name: Disable IPv6 with sysctl
|
||||||
sysctl: name={{ item }} value=1 state=present reload=yes
|
sysctl: name={{ item }} value=1 state=present reload=yes
|
||||||
|
@ -187,7 +187,7 @@
|
||||||
- net.ipv6.conf.all.disable_ipv6
|
- net.ipv6.conf.all.disable_ipv6
|
||||||
- net.ipv6.conf.default.disable_ipv6
|
- net.ipv6.conf.default.disable_ipv6
|
||||||
- net.ipv6.conf.lo.disable_ipv6
|
- net.ipv6.conf.lo.disable_ipv6
|
||||||
when: systemd_detect_virt.stdout == "none"
|
# when: systemd_detect_virt.stdout == "none"
|
||||||
|
|
||||||
- ansible.builtin.include_role:
|
- ansible.builtin.include_role:
|
||||||
name: ssh_hardening
|
name: ssh_hardening
|
||||||
|
|
Loading…
Reference in a new issue