From 86ba06fa0ce907970bc20e5ae0e40170e60671e0 Mon Sep 17 00:00:00 2001 From: Radovan Sroka Date: Fri, 8 Nov 2024 15:38:51 +0100 Subject: [PATCH] Added custom template Signed-off-by: Radovan Sroka --- README.md | 27 +++++++++++++------ defaults/main.yml | 6 ++--- .../aide-custom.conf.j2 | 0 examples/custom-template.yml | 16 +++++++++++ examples/default.yml | 1 - examples/deploy.yml | 7 +++-- examples/just_check.yml | 1 - examples/just_update.yml | 1 - tasks/main.yml | 9 ++++--- templates/foo.conf.j2 | 9 ------- tests/files/aide-custom.conf.j2 | 1 + tests/tests_custom_template.yml | 17 ++++++++++++ tests/tests_default.yml | 17 ++++++++---- tests/tests_deploy.yml | 3 +-- 14 files changed, 78 insertions(+), 37 deletions(-) rename templates/aide.conf.j2 => examples/aide-custom.conf.j2 (100%) create mode 100644 examples/custom-template.yml delete mode 100644 templates/foo.conf.j2 create mode 120000 tests/files/aide-custom.conf.j2 create mode 100644 tests/tests_custom_template.yml diff --git a/README.md b/README.md index bec57af..79d18f2 100644 --- a/README.md +++ b/README.md @@ -35,6 +35,21 @@ only. ## Role Variables +### aide_custom_template + +This variable takes a string to specify a path where the custom template for aide.conf is located. + +To be sure that everething is correct, template needs to start with following snippet: + +``` jinja +{{ ansible_managed | comment }} +{{ "system_role:aide" | comment(prefix="", postfix="") }} +``` + +Default: `null` + +Type: `string` + ### aide_db_fetch_dir This variable takes a string to specify the directory on the Ansible Control @@ -45,17 +60,13 @@ same directory as the playbook. In case you like to store the fetched AIDE database files somewhere else you need to specify a different path here. -### aide_install +Default: `files` -With this variable the role ensures that the `aide` package is installed on the remote nodes - -Default: `false` +Type: `string -Type: `bool` - -### aide_generate_config +### aide_install -Generates the file `/etc/aide.conf` using `templates/aide.conf.j2`; the template needs to be adjusted to fit your requirements; if you do not use this varable the default configuration file shipped with the `aide` package will be used. +With this variable the role ensures that the `aide` package is installed on the remote nodes Default: `false` diff --git a/defaults/main.yml b/defaults/main.yml index 11db323..27479e2 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -3,15 +3,15 @@ # Here is the right place to put the role's input variables. # This file also serves as a documentation for such a variables. +# Path to template file +aide_custom_template: null + # Examples of role input variables: aide_db_fetch_dir: files # Enable install phase aide_install: false -# Enable config file generation phase -aide_generate_config: false - # Enable initialization of the database phase aide_init: false diff --git a/templates/aide.conf.j2 b/examples/aide-custom.conf.j2 similarity index 100% rename from templates/aide.conf.j2 rename to examples/aide-custom.conf.j2 diff --git a/examples/custom-template.yml b/examples/custom-template.yml new file mode 100644 index 0000000..f167e17 --- /dev/null +++ b/examples/custom-template.yml @@ -0,0 +1,16 @@ +# SPDX-License-Identifier: MIT +--- +- name: Example aide role invocation + hosts: targets + tasks: + - name: Include role aide + vars: + aide_custom_template: /tmp/aide-custom.conf.j2 + aide_db_fetch_dir: files + aide_install: true + aide_init: true + aide_fetch_db: true + aide_check: true + aide_update: true + ansible.builtin.include_role: + name: linux-system-roles.aide diff --git a/examples/default.yml b/examples/default.yml index 9425f00..2c27811 100644 --- a/examples/default.yml +++ b/examples/default.yml @@ -7,7 +7,6 @@ vars: aide_db_fetch_dir: files aide_install: false - aide_generate_config: false aide_init: false aide_fetch_db: false aide_check: false diff --git a/examples/deploy.yml b/examples/deploy.yml index 76f2df0..5c7bfc9 100644 --- a/examples/deploy.yml +++ b/examples/deploy.yml @@ -7,10 +7,9 @@ vars: aide_db_fetch_dir: files aide_install: true - aide_generate_config: true aide_init: true - aide_fetch_db: true - aide_check: true - aide_update: true + aide_fetch_db: false + aide_check: false + aide_update: false ansible.builtin.include_role: name: linux-system-roles.aide diff --git a/examples/just_check.yml b/examples/just_check.yml index ee161f5..ec3c325 100644 --- a/examples/just_check.yml +++ b/examples/just_check.yml @@ -7,7 +7,6 @@ vars: aide_db_fetch_dir: files aide_install: false - aide_generate_config: false aide_init: false aide_fetch_db: false aide_check: true diff --git a/examples/just_update.yml b/examples/just_update.yml index b26a498..1c6afbd 100644 --- a/examples/just_update.yml +++ b/examples/just_update.yml @@ -7,7 +7,6 @@ vars: aide_db_fetch_dir: files aide_install: false - aide_generate_config: false aide_init: false aide_fetch_db: false aide_check: false diff --git a/tasks/main.yml b/tasks/main.yml index 7f1aa31..669b989 100644 --- a/tasks/main.yml +++ b/tasks/main.yml @@ -22,12 +22,15 @@ - name: Generate "/etc/{{ __aide_config }}" ansible.builtin.template: - src: "{{ __aide_config }}.j2" +# remote_src: true + src: "{{ aide_custom_template }}" dest: "/etc/{{ __aide_config }}" - backup: true mode: "0400" when: - - aide_generate_config + - aide_custom_template + +#- name: Print Header +# ansible.builtin.shell: head /etc/aide.conf || true - name: Initialize AIDE database when: diff --git a/templates/foo.conf.j2 b/templates/foo.conf.j2 deleted file mode 100644 index 2ed6d2e..0000000 --- a/templates/foo.conf.j2 +++ /dev/null @@ -1,9 +0,0 @@ -# SPDX-License-Identifier: MIT -# -# Example of a template of configuration file -# -{{ ansible_managed | comment }} -{{ "system_role:aide" | comment(prefix="", postfix="") }} -[foo] -foo = {{ template_foo }} -bar = {{ template_bar }} diff --git a/tests/files/aide-custom.conf.j2 b/tests/files/aide-custom.conf.j2 new file mode 120000 index 0000000..0765c64 --- /dev/null +++ b/tests/files/aide-custom.conf.j2 @@ -0,0 +1 @@ +../../examples/aide-custom.conf.j2 \ No newline at end of file diff --git a/tests/tests_custom_template.yml b/tests/tests_custom_template.yml new file mode 100644 index 0000000..ebf5cad --- /dev/null +++ b/tests/tests_custom_template.yml @@ -0,0 +1,17 @@ +# SPDX-License-Identifier: MIT +--- +- name: Ensure that the role runs with default parameters + hosts: all + gather_facts: false # test that role works in this case + roles: + - role: linux-system-roles.aide + vars: + aide_custom_template: files/aide-custom.conf.j2 + aide_install: true + aide_init: true + tasks: + - name: Check header for ansible_managed, fingerprint + include_tasks: tasks/check_header.yml + vars: + __file: /etc/aide.conf + __fingerprint: system_role:aide diff --git a/tests/tests_default.yml b/tests/tests_default.yml index af98ed0..c450dde 100644 --- a/tests/tests_default.yml +++ b/tests/tests_default.yml @@ -6,8 +6,15 @@ roles: - linux-system-roles.aide tasks: - - name: Check header for ansible_managed, fingerprint - include_tasks: tasks/check_not_present_header.yml - vars: - __file: /etc/aide.conf - __fingerprint: system_role:aide + - name: Check if file exists + block: + - name: Check if the file exists + ansible.builtin.stat: + path: "/etc/aide.conf" + register: file_check + + - name: Assert that the file exists + ansible.builtin.assert: + that: + - not file_check.stat.exists + fail_msg: "The file does exist." diff --git a/tests/tests_deploy.yml b/tests/tests_deploy.yml index 2c09e27..d141281 100644 --- a/tests/tests_deploy.yml +++ b/tests/tests_deploy.yml @@ -7,11 +7,10 @@ - role: linux-system-roles.aide vars: aide_install: true - aide_generate_config: true aide_init: true tasks: - name: Check header for ansible_managed, fingerprint - include_tasks: tasks/check_header.yml + include_tasks: tasks/check_not_present_header.yml vars: __file: /etc/aide.conf __fingerprint: system_role:aide