{"repo":"githubixx/ansible-role-harden-linux","free":true,"listed":false,"github":"https://github.com/githubixx/ansible-role-harden-linux","clone":"git clone https://github.com/githubixx/ansible-role-harden-linux.git","description":"Ansible role for hardening Linux","language":"Jinja","stars":141,"topics":["ansible","networking","security","linux","firewall","ssh","ansible-role","sshguard","firewall-rules","harden"],"license":"GPL-3.0","category":"deployment-docker-iac","readme_excerpt":"ansible-role-harden-linux This Ansible role was mainly created for my blog series Kubernetes the not so hard way with Ansible - Harden the instances. But it can be used also standalone of course to harden Linux. It has the following features (some of them are optional): - Add a regular/deploy user used for administration (e.g. for Ansible or login via SSH) - Adjust APT update intervals - Setup UFW firewall and allow only SSH access by default (add more rules/allowed networks if you like) - Adjust security related sysctl settings - Adjust sshd settings e.g disable sshd password authentication, disable sshd root login and disable sshd PermitTunnel - Install sshguard and adjust whitelist - Change root password - Install/configure Network Time Synchronization (NTP) e.g. openntpd / ntp / ntpd-rs / systemd-timesyncd - Change systemd-resolved configuration Versions I tag every release and try to stay with semantic versioning. If you want to use the role I recommend to checkout the latest tag. The master branch is basically development while the tags mark stable releases. But in general I try to keep master in good shape too. Changelog Change history: See full CHANGELOG.md Recent changes: v9.1.0 - FEATURE - add support for Ubuntu 26.04 - add ntpd-rs support for Ubuntu 26.04 - MOLECULE - more tests in verify.yml v9.0.0 - BREAKING - remove support for Ubuntu 20.04 (reached EOL) - OTHER - replace injected ansible facts usage with ansible facts[...] (prepares for ansible-core 2.24 where ","default_branch":null,"files":null,"tree":[],"storefront":"/r/githubixx","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/githubixx/ansible-role-harden-linux/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}