{"repo":"konstruktoid/ansible-role-hardening","free":true,"listed":false,"github":"https://github.com/konstruktoid/ansible-role-hardening","clone":"git clone https://github.com/konstruktoid/ansible-role-hardening.git","description":"Ansible role to apply a security baseline. Systemd edition.","language":"Jinja","stars":640,"topics":["ansible","systemd","auditd","ubuntu","hardening","security","security-hardening","information-security","security-tools","security-compliance"],"license":"Apache-2.0","category":"deployment-docker-iac","readme_excerpt":"Ansible Role for Server Hardening This is an Ansible role designed to enhance the security of servers running on AlmaLinux, Debian, or Ubuntu. It's systemd focused and requires Ansible version 2.18 or higher. The role supports the following operating systems: - AlmaLinux 9 - AlmaLinux 10 - Debian 12 (Bookworm) - Debian 13 (trixie) - Ubuntu 24.04 (Noble Numbat) - Ubuntu 26.04 (Resolute Raccoon) For those using AWS or Azure, there are also hardened Ubuntu Amazon Machine Images (AMIs) and Azure virtual machine images available. These are available in the konstruktoid/hardened-images repository. These images are built using Packer and this Ansible role is used for configuration. Note Do not use this role without first testing in a non-operational environment. Note There is a SLSA artifact present under the slsa action workflow for verification. Note All options and defaults are documented in defaults/main.yml and meta/argument specs.yml. ansible-doc -t role can be used to view the documentation for this role as well. Note This role has been migrated to the ansible-collection-hardening collection, and switching to that is recommended for continued updates and support. Examples Requirements Playbook Local playbook using git checkout Note regarding UFW firewall rules Instead of resetting ufw every run and by doing so causing network traffic disruption, the role deletes every ufw rule that doesn't have a comment ending with ansible managed . The role also sets default deny policies, ","default_branch":null,"files":null,"tree":[],"storefront":"/r/konstruktoid","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/konstruktoid/ansible-role-hardening/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}