Skip to content

Commit

Permalink
Merge pull request #17 from QLPD/mounts-partitions
Browse files Browse the repository at this point in the history
Improvements around partitions & mount
  • Loading branch information
Maciej Drozdzowski authored Aug 21, 2020
2 parents d8faf4d + 8427f64 commit 29fd2d7
Show file tree
Hide file tree
Showing 5 changed files with 15 additions and 12 deletions.
16 changes: 10 additions & 6 deletions defaults/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -36,18 +36,22 @@ cis_sshd_config_filename: "/etc/ssh/sshd_config"
# Check specific values which can be overridden
###############################################
# Section 1
cis_partition_dev_val_log: "/dev/xvda2"
cis_partition_mnt_val_log: "/var/log"
cis_partition_fs_val_log: "ext4"
cis_partition_dev_var_log: "/dev/xvda2"
cis_partition_mnt_var_log: "/var/log"
cis_partition_fs_var_log: "ext4"

cis_partition_dev_val_log_audit: "/dev/xvda3"
cis_partition_mnt_val_log_audit: "/var/log/audit"
cis_partition_fs_val_log_audit: "ext4"
cis_partition_dev_var_log_audit: "/dev/xvda3"
cis_partition_mnt_var_log_audit: "/var/log/audit"
cis_partition_fs_var_log_audit: "ext4"

cis_partition_dev_home: "/dev/xvda4"
cis_partition_mnt_home: "/home"
cis_partition_fs_home: "ext4"

cis_partition_dev_var: "/dev/xvda5"
cis_partition_mnt_var: "/var"
cis_partition_fs_var: "ext4"

cis_aide_database_filename: "/var/lib/aide/aide.db.gz"
cis_aide_src_database_filename: "/var/lib/aide/aide.db.new.gz"

Expand Down
2 changes: 1 addition & 1 deletion tasks/level-1/1.1.11.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
fstype: "{{item.fstype}}"
src: "{{item.device}}"
with_items:
- { mountpoint: "{{cis_partition_mnt_val_log}}", device: "{{cis_partition_dev_val_log}}", fstype: "{{cis_partition_fs_val_log}}" }
- { mountpoint: "{{cis_partition_mnt_var_log}}", device: "{{cis_partition_dev_var_log}}", fstype: "{{cis_partition_fs_var_log}}" }
tags:
- level-1
- section-1
Expand Down
2 changes: 1 addition & 1 deletion tasks/level-1/1.1.12.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,7 +10,7 @@
fstype: "{{item.fstype}}"
src: "{{item.device}}"
with_items:
- { mountpoint: "{{cis_partition_mnt_val_log_audit}}", device: "{{cis_partition_dev_val_log_audit}}", fstype: "{{cis_partition_fs_val_log_audit}}" }
- { mountpoint: "{{cis_partition_mnt_var_log_audit}}", device: "{{cis_partition_dev_var_log_audit}}", fstype: "{{cis_partition_fs_var_log_audit}}" }
tags:
- level-1
- section-1
Expand Down
4 changes: 2 additions & 2 deletions tasks/level-1/1.1.13.yml
Original file line number Diff line number Diff line change
@@ -1,9 +1,9 @@
# Standards: 0.11
---

# 1.1.12 Ensure separate partition exists for /home (Scored)
# 1.1.13 Ensure separate partition exists for /home (Scored)

- name: 1.1.12 Ensure separate partition exists for /home (Scored)
- name: 1.1.13 Ensure separate partition exists for /home (Scored)
mount:
name: "{{ item.mountpoint }}"
state: present
Expand Down
3 changes: 1 addition & 2 deletions tasks/level-1/1.1.6.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,9 +9,8 @@
state: present
fstype: "{{item.fstype}}"
src: "{{item.device}}"
opts: "{{item.opts}}"
with_items:
- "{{ fs_mounts | selectattr('mountpoint', 'equalto', '/var') | list }}"
- { mountpoint: "{{cis_partition_mnt_var}}", device: "{{cis_partition_dev_var}}", fstype: "{{cis_partition_fs_var}}" }
tags:
- level-1
- section-1
Expand Down

0 comments on commit 29fd2d7

Please sign in to comment.