12.0.15
As noted in https://review.openstack.org/319438 , the /etc/apparmor.d/ directory was missing from the auditd rules applied for V-38541. This is a manual backport of I564b72d103fa13af4562e4b21d68ef6097cecf37. An clean cherry pick wasn't possible because of CentOS/SELinux changes in the master/Newton branch that don't belong in mitaka and liberty. Change-Id: Idf169538e3e155a9b9aa9119f65dc31428c9680c
openstack-ansible-security
The goal of the openstack-ansible-security role is to improve security within openstack-ansible deployments. The role is based on the Security Technical Implementation Guide (STIG) for Red Hat Enterprise Linux 6.
Requirements
This role can be used with or without the openstack-ansible role. It requires Ansible 1.8.3 at a minimum.
Role Variables
All of the variables for this role are in defaults/main.yml.
Dependencies
This role has no dependencies.
Example Playbook
Using the role is fairly straightforward:
- hosts: servers
roles:
- openstack-ansible-security
Running with Vagrant
Security Ansible can be easily run for testing using Vagrant.
To do so run:
vagrant destroy To destroy any previously created Vagrant setup
vagrant up Spin up Ubuntu Trusty VM and run ansible-security against it
License
Apache 2.0
Author Information
For more information, join #openstack-ansible on Freenode.
Description