Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

V3R14 to main release #477

Merged
merged 111 commits into from
Nov 14, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
111 commits
Select commit Hold shift + click to select a range
f117074
Specify missing state parameter for package
anzoman Sep 15, 2023
130e021
Correct with_items indentation for package
anzoman Sep 15, 2023
601ef18
Replace inline strings with module parameters
anzoman Sep 15, 2023
b53d7be
Merge pull request #437 from anzoman/steampunk-spotter-fixes
uk-bolly Sep 15, 2023
dfb9791
updated link
uk-bolly Sep 15, 2023
5108506
lint updates
uk-bolly Sep 15, 2023
223624e
removed old
uk-bolly Sep 15, 2023
20a720a
added new defined secrets file
uk-bolly Sep 15, 2023
5956a0f
added precommit
uk-bolly Sep 15, 2023
395956a
Merge pull request #438 from ansible-lockdown/discord_updates
uk-bolly Sep 15, 2023
aa000e8
lint updates
uk-bolly Oct 9, 2023
d14af2e
updated
uk-bolly Oct 9, 2023
1dc0f9b
added pragma allow list
uk-bolly Oct 9, 2023
6098b02
updated due to galaxy changes
uk-bolly Oct 9, 2023
197f961
moved file
uk-bolly Oct 9, 2023
d49469b
updated path
uk-bolly Oct 9, 2023
5aae574
removed quality badge since galaxy-ng
uk-bolly Oct 9, 2023
32fe8c1
Merge pull request #439 from ansible-lockdown/collections_lint
uk-bolly Oct 10, 2023
fb6f4fe
Adding additional condition for rhel7stig_grub2_user_cfg for task
layluke Oct 18, 2023
5e47e97
Merge pull request #441 from layluke/440-Grub_Handler_Fix
uk-bolly Oct 25, 2023
88f570b
updated version
uk-bolly Oct 25, 2023
ea14041
quoted version
uk-bolly Oct 25, 2023
c48ab81
updated rule id 020230
uk-bolly Oct 25, 2023
d602fd9
rule ids and inactive variable added
uk-bolly Oct 25, 2023
f480204
updated
uk-bolly Oct 25, 2023
6a7137f
updated the workflow version and galaxy setup
uk-bolly Oct 31, 2023
b3f3248
updated the workflow version and galaxy setup
uk-bolly Oct 31, 2023
d26e104
Merge pull request #442 from ansible-lockdown/workflow_galaxy
uk-bolly Nov 1, 2023
d687371
removed file
uk-bolly Nov 1, 2023
9dd216c
updated
uk-bolly Nov 1, 2023
388f850
updated
uk-bolly Nov 1, 2023
22f7dab
lint update
uk-bolly Nov 1, 2023
51b2df3
fix typo
uk-bolly Nov 1, 2023
9943f97
Merge pull request #444 from ansible-lockdown/tidyup
uk-bolly Nov 1, 2023
fb58a03
lint
uk-bolly Nov 2, 2023
ad96dd7
updated precommit files
uk-bolly Nov 2, 2023
444074d
rhel7stig_boot_part variable now discovered
uk-bolly Nov 14, 2023
6276776
tidy up of rhel7stig_boot_part variable
uk-bolly Nov 14, 2023
ad3b174
changed logic on 20620
uk-bolly Nov 15, 2023
617e008
updated logic for uuid
uk-bolly Nov 20, 2023
6e7329b
removed extra line
uk-bolly Nov 21, 2023
212f524
Merge pull request #445 from ansible-lockdown/fix_021350
uk-bolly Nov 21, 2023
207be13
removed doc dir
uk-bolly Jan 11, 2024
4e0554f
Merge pull request #449 from ansible-lockdown/nodocs
uk-bolly Jan 11, 2024
3901021
[pre-commit.ci] pre-commit autoupdate
pre-commit-ci[bot] Jan 22, 2024
c294efb
Merge pull request #447 from ansible-lockdown/pre-commit-ci-update-co…
uk-bolly Jan 26, 2024
594ece9
Issue #446 tag update to always - thanks to @prestonSeaman2
uk-bolly Jan 26, 2024
e401d83
conditional updated 021000 & 021010 #448 thanks @erosen03
uk-bolly Jan 26, 2024
9f52057
Merge branch 'jan_24_updates' into stig_v3r13
uk-bolly Jan 26, 2024
3ce0e42
Merge pull request #450 from ansible-lockdown/jan_24_updates
uk-bolly Jan 26, 2024
1f997b7
[pre-commit.ci] pre-commit autoupdate (#451)
pre-commit-ci[bot] Feb 14, 2024
dfe8425
[pre-commit.ci] pre-commit autoupdate (#454)
pre-commit-ci[bot] Mar 5, 2024
df38ef9
Feb 24 updates (#455)
uk-bolly Mar 6, 2024
da5270f
Merge branch 'main' into devel
uk-bolly Mar 6, 2024
82abd51
incorporated Feb_24 fixes
uk-bolly Mar 14, 2024
e277b23
v3r14 ref updated
uk-bolly Mar 14, 2024
09e75c8
v3r14 update
uk-bolly Mar 14, 2024
82d5761
associated rule updated v3r14
uk-bolly Mar 14, 2024
6d800a4
Stig v3r13 into devel (#457)
uk-bolly Mar 14, 2024
8911cbd
updated meta
uk-bolly Mar 19, 2024
91fd0d9
[pre-commit.ci] pre-commit autoupdate (#458)
pre-commit-ci[bot] Apr 10, 2024
16f3465
prelim.yml fixes on when conditions on cronie passwd_tasks
frederickw082922 Apr 11, 2024
94964ab
Merge pull request #460 from ansible-lockdown/2024_APRIL_UPDATE
frederickw082922 Apr 11, 2024
c7ebdb0
audit rewrite and logic improvements
uk-bolly Apr 15, 2024
4edeb2a
added prelim to includes
uk-bolly Apr 15, 2024
509fa41
added prelim to includes quoted
uk-bolly Apr 15, 2024
3508dfc
[pre-commit.ci] pre-commit autoupdate (#461)
pre-commit-ci[bot] Apr 22, 2024
2db15ef
Excluding non-interactive logins shells from being parsed
layluke May 2, 2024
c0c0ba5
[pre-commit.ci] pre-commit autoupdate
pre-commit-ci[bot] Jun 17, 2024
3026fd9
Merge pull request #468 from ansible-lockdown/pre-commit-ci-update-co…
georgenalen Jun 18, 2024
a57f56e
[pre-commit.ci] pre-commit autoupdate
pre-commit-ci[bot] Jul 15, 2024
c5936ff
21350 improvements
uk-bolly Jul 17, 2024
ebaefbd
moved audit to prelim
uk-bolly Jul 17, 2024
bb6ed8d
Audit updates
uk-bolly Jul 17, 2024
6a1dd5c
moved var from site to vars/main.yml
uk-bolly Jul 17, 2024
a85ccc0
Merge pull request #466 from layluke/462
uk-bolly Jul 17, 2024
a501c7f
Merge pull request #469 from ansible-lockdown/pre-commit-ci-update-co…
uk-bolly Jul 17, 2024
1e000ce
reorder
uk-bolly Jul 17, 2024
aeef574
quotes on mode items
uk-bolly Jul 17, 2024
e00e54b
added update repo url for centos option
uk-bolly Jul 18, 2024
150a6b6
removed notify not required
uk-bolly Jul 18, 2024
ddd17c7
Updated
uk-bolly Jul 18, 2024
98d768f
Merge pull request #470 from ansible-lockdown/workflow_audit
uk-bolly Jul 18, 2024
d1ef065
Updated workflow
uk-bolly Jul 18, 2024
41a3edf
Merge pull request #471 from ansible-lockdown/workflow_audit
uk-bolly Jul 18, 2024
a25e8bf
[pre-commit.ci] pre-commit autoupdate
pre-commit-ci[bot] Sep 16, 2024
f697cfc
Merge pull request #472 from ansible-lockdown/pre-commit-ci-update-co…
uk-bolly Sep 17, 2024
2b1804d
Merge branch 'devel' into stig_v3r14
uk-bolly Sep 17, 2024
b51cdf4
added solution for gui and X11 for 040730
uk-bolly Sep 17, 2024
f2baee2
updated default var to use discovered value
uk-bolly Sep 17, 2024
b38ce35
Alignment
uk-bolly Sep 17, 2024
cbeab4a
remove jmespath on the way mountspoints are check
uk-bolly Sep 19, 2024
594c50f
removed breaking dupe line
uk-bolly Sep 19, 2024
c6d2e06
Updated goss version and added ARM
uk-bolly Sep 19, 2024
a94da63
updated mount and wireless checks
uk-bolly Sep 19, 2024
272ce78
aligned benchmark git version name
uk-bolly Sep 19, 2024
6304b8d
Merge branch 'devel' into stig_v3r14
uk-bolly Sep 23, 2024
06d5a34
removed empty line
uk-bolly Sep 23, 2024
df0e444
[pre-commit.ci] pre-commit autoupdate
pre-commit-ci[bot] Sep 23, 2024
5b6660e
Merge pull request #474 from ansible-lockdown/pre-commit-ci-update-co…
uk-bolly Sep 24, 2024
ebad8d3
Merge pull request #473 from ansible-lockdown/stig_v3r14
uk-bolly Sep 24, 2024
0b0049a
[pre-commit.ci] pre-commit autoupdate
pre-commit-ci[bot] Oct 21, 2024
2e45c3d
Merge pull request #475 from ansible-lockdown/pre-commit-ci-update-co…
uk-bolly Oct 22, 2024
e904997
[pre-commit.ci] pre-commit autoupdate
pre-commit-ci[bot] Oct 28, 2024
3623e05
Merge pull request #476 from ansible-lockdown/pre-commit-ci-update-co…
uk-bolly Oct 29, 2024
75bd5e6
Merge branch 'main' into devel
uk-bolly Oct 29, 2024
0e839b7
updated layout 21350
uk-bolly Oct 30, 2024
18f123f
fixed layout 041010
uk-bolly Oct 30, 2024
aa0be1c
moved check_mode
uk-bolly Nov 1, 2024
744f42e
moved check_mode
uk-bolly Nov 1, 2024
b223ae5
Merge pull request #478 from ansible-lockdown/Oct24
uk-bolly Nov 1, 2024
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
290 changes: 155 additions & 135 deletions .github/workflows/devel_pipeline_validation.yml
Original file line number Diff line number Diff line change
@@ -1,138 +1,158 @@
---

name: Devel pipeline

on: # yamllint disable-line rule:truthy
pull_request_target:
types: [opened, reopened, synchronize]
branches:
- devel
paths:
- '**.yml'
- '**.sh'
- '**.j2'
- '**.ps1'
- '**.cfg'

# A workflow run is made up of one or more jobs
# that can run sequentially or in parallel
jobs:
# This will create messages for first time contributers and direct them to the Discord server
welcome:
runs-on: ubuntu-latest

steps:
- uses: actions/first-interaction@main
with:
repo-token: ${{ secrets.GITHUB_TOKEN }}
pr-message: |-
Congrats on opening your first pull request and thank you for taking the time to help improve Ansible-Lockdown!
Please join in the conversation happening on the [Discord Server](https://www.lockdownenterprise.com/discord) as well.

# This workflow contains a single job that tests the playbook
playbook-test:
# The type of runner that the job will run on
runs-on: ubuntu-latest
env:
ENABLE_DEBUG: ${{ vars.ENABLE_DEBUG }}
# Imported as a variable by terraform
TF_VAR_repository: ${{ github.event.repository.name }}
defaults:
run:
shell: bash
working-directory: .github/workflows/github_linux_IaC

steps:
- name: Clone ${{ github.event.repository.name }}
uses: actions/checkout@v4
name: Devel pipeline

on: # yamllint disable-line rule:truthy
pull_request_target:
types: [opened, reopened, synchronize]
branches:
- devel
paths:
- '**.yml'
- '**.sh'
- '**.j2'
- '**.ps1'
- '**.cfg'
# Allow manual running of workflow
workflow_dispatch:

# Allow permissions for AWS auth
permissions:
id-token: write
contents: read
pull-requests: read

# A workflow run is made up of one or more jobs
# that can run sequentially or in parallel
jobs:
# This will create messages for first time contributers and direct them to the Discord server
welcome:
runs-on: ubuntu-latest

steps:
- uses: actions/first-interaction@main
with:
ref: ${{ github.event.pull_request.head.sha }}

# Pull in terraform code for linux servers
- name: Clone GitHub IaC plan
uses: actions/checkout@v4
with:
repository: ansible-lockdown/github_linux_IaC
path: .github/workflows/github_linux_IaC

- name: Add_ssh_key
working-directory: .github/workflows
env:
SSH_AUTH_SOCK: /tmp/ssh_agent.sock
PRIVATE_KEY: "${{ secrets.SSH_PRV_KEY }}"
run: |
mkdir .ssh
chmod 700 .ssh
echo $PRIVATE_KEY > .ssh/github_actions.pem
chmod 600 .ssh/github_actions.pem

- name: DEBUG - Show IaC files
if: env.ENABLE_DEBUG == 'true'
run: |
echo "OSVAR = $OSVAR"
echo "benchmark_type = $benchmark_type"
pwd
ls
env:
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
OSVAR: ${{ vars.OSVAR }}
benchmark_type: ${{ vars.BENCHMARK_TYPE }}

- name: Terraform_Init
id: init
run: terraform init
env:
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
OSVAR: ${{ vars.OSVAR }}
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}

- name: Terraform_Validate
id: validate
run: terraform validate
env:
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
OSVAR: ${{ vars.OSVAR }}
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}

- name: Terraform_Apply
id: apply
env:
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
OSVAR: ${{ vars.OSVAR }}
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
run: terraform apply -var-file "github_vars.tfvars" -var-file "${OSVAR}.tfvars" --auto-approve -input=false

## Debug Section
- name: DEBUG - Show Ansible hostfile
if: env.ENABLE_DEBUG == 'true'
run: cat hosts.yml

# Aws deployments taking a while to come up insert sleep or playbook fails

- name: Sleep for 60 seconds
run: sleep ${{ vars.BUILD_SLEEPTIME }}

# Run the Ansible playbook
- name: Run_Ansible_Playbook
uses: arillso/action.playbook@master
with:
playbook: site.yml
inventory: .github/workflows/github_linux_IaC/hosts.yml
galaxy_file: collections/requirements.yml
private_key: ${{ secrets.SSH_PRV_KEY }}
# verbose: 3
env:
ANSIBLE_HOST_KEY_CHECKING: "false"
ANSIBLE_DEPRECATION_WARNINGS: "false"

# Remove test system - User secrets to keep if necessary

- name: Terraform_Destroy
if: always() && env.ENABLE_DEBUG == 'false'
env:
AWS_ACCESS_KEY_ID: ${{ secrets.AWS_ACCESS_KEY_ID }}
AWS_SECRET_ACCESS_KEY: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
OSVAR: ${{ vars.OSVAR }}
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
run: terraform destroy -var-file "github_vars.tfvars" -var-file "${OSVAR}.tfvars" --auto-approve -input=false
repo-token: ${{ secrets.GITHUB_TOKEN }}
pr-message: |-
Congrats on opening your first pull request and thank you for taking the time to help improve Ansible-Lockdown!
Please join in the conversation happening on the [Discord Server](https://www.lockdownenterprise.com/discord) as well.

# This workflow contains a single job that tests the playbook
playbook-test:
# The type of runner that the job will run on
runs-on: self-hosted
env:
ENABLE_DEBUG: ${{ vars.ENABLE_DEBUG }}
# Imported as a variable by terraform
TF_VAR_repository: ${{ github.event.repository.name }}
AWS_REGION: "us-east-1"
ANSIBLE_VERSION: ${{ vars.ANSIBLE_RUNNER_VERSION }}
defaults:
run:
shell: bash
working-directory: .github/workflows/github_linux_IaC
# working-directory: .github/workflows

steps:

- name: Git clone the lockdown repository to test
uses: actions/checkout@v4
with:
ref: ${{ github.event.pull_request.head.sha }}

- name: If a variable for IAC_BRANCH is set use that branch
working-directory: .github/workflows
run: |
if [ ${{ vars.IAC_BRANCH }} != '' ]; then
echo "IAC_BRANCH=${{ vars.IAC_BRANCH }}" >> $GITHUB_ENV
echo "Pipeline using the following IAC branch ${{ vars.IAC_BRANCH }}"
else
echo IAC_BRANCH=main >> $GITHUB_ENV
fi

# Pull in terraform code for linux servers
- name: Clone GitHub IaC plan
uses: actions/checkout@v4
with:
repository: ansible-lockdown/github_linux_IaC
path: .github/workflows/github_linux_IaC
ref: ${{ env.IAC_BRANCH }}

# Uses dedicated restricted role and policy to enable this only for this task
# No credentials are part of github for AWS auth
- name: configure aws credentials
uses: aws-actions/configure-aws-credentials@main
with:
role-to-assume: ${{ secrets.AWS_ASSUME_ROLE }}
role-session-name: ${{ secrets.AWS_ROLE_SESSION }}
aws-region: ${{ env.AWS_REGION }}

- name: DEBUG - Show IaC files
if: env.ENABLE_DEBUG == 'true'
run: |
echo "OSVAR = $OSVAR"
echo "benchmark_type = $benchmark_type"
echo "PRIVSUBNET_ID = $AWS_PRIVSUBNET_ID"
echo "VPC_ID" = $AWS_VPC_SECGRP_ID"
pwd
ls
env:
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
OSVAR: ${{ vars.OSVAR }}
benchmark_type: ${{ vars.BENCHMARK_TYPE }}
PRIVSUBNET_ID: ${{ secrets.AWS_PRIVSUBNET_ID }}
VPC_ID: ${{ secrets.AWS_VPC_SECGRP_ID }}

- name: Tofu init
id: init
run: tofu init
env:
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
OSVAR: ${{ vars.OSVAR }}
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}

- name: Tofu validate
id: validate
run: tofu validate
env:
# Imported from GitHub variables this is used to load the relevant OS.tfvars file
OSVAR: ${{ vars.OSVAR }}
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}

- name: Tofu apply
id: apply
env:
OSVAR: ${{ vars.OSVAR }}
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
TF_VAR_privsubnet_id: ${{ secrets.AWS_PRIVSUBNET_ID }}
TF_VAR_vpc_secgrp_id: ${{ secrets.AWS_VPC_SECGRP_ID }}
run: tofu apply -var-file "${OSVAR}.tfvars" --auto-approve -input=false

## Debug Section
- name: DEBUG - Show Ansible hostfile
if: env.ENABLE_DEBUG == 'true'
run: cat hosts.yml

# Aws deployments taking a while to come up insert sleep or playbook fails

- name: Sleep to allow system to come up
run: sleep ${{ vars.BUILD_SLEEPTIME }}

# Run the Ansible playbook
- name: Run_Ansible_Playbook
env:
ANSIBLE_HOST_KEY_CHECKING: "false"
ANSIBLE_DEPRECATION_WARNINGS: "false"
run: |
/opt/ansible_${{ env.ANSIBLE_VERSION }}_venv/bin/ansible-playbook -i hosts.yml --private-key ~/.ssh/le_runner ../../../site.yml

# Remove test system - User secrets to keep if necessary

- name: Tofu Destroy
if: always() && env.ENABLE_DEBUG == 'false'
env:
OSVAR: ${{ vars.OSVAR }}
TF_VAR_benchmark_type: ${{ vars.BENCHMARK_TYPE }}
TF_VAR_privsubnet_id: ${{ secrets.AWS_PRIVSUBNET_ID }}
TF_VAR_vpc_secgrp_id: ${{ secrets.AWS_VPC_SECGRP_ID }}
run: tofu destroy -var-file "${OSVAR}.tfvars" --auto-approve -input=false
Loading
Loading