Skip to content

Commit

Permalink
Merge pull request #9 from ansible-lockdown/discord_linting
Browse files Browse the repository at this point in the history
Discord linting
  • Loading branch information
uk-bolly authored Sep 18, 2023
2 parents bf38dd4 + b4b0a4c commit 46fb367
Show file tree
Hide file tree
Showing 29 changed files with 85 additions and 85 deletions.
2 changes: 1 addition & 1 deletion .github/workflows/devel_pipeline_validation.yml
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,7 @@
repo-token: ${{ secrets.GITHUB_TOKEN }}
pr-message: |-
Congrats on opening your first pull request and thank you for taking the time to help improve Ansible-Lockdown!
Please join in the conversation happening on the [Discord Server](https://discord.io/ansible-lockdown) as well.
Please join in the conversation happening on the [Discord Server](https://www.lockdownenterprise.com/discord) as well.
# This workflow contains a single job which tests the playbook
playbook-test:
Expand Down
4 changes: 2 additions & 2 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@ NOTE AUDIT NOT YET AVAILABLE
[![Main Pipeline Status](https://github.com/ansible-lockdown/AMAZON2023-CIS/actions/workflows/main_pipeline_validation.yml/badge.svg?)](https://github.com/ansible-lockdown/AMAZON2023-CIS/actions/workflows/main_pipeline_validation.yml)

[![Devel Pipeline Status](https://github.com/ansible-lockdown/AMAZON2023-CIS/actions/workflows/devel_pipeline_validation.yml/badge.svg?)](https://github.com/ansible-lockdown/AMAZON2023-CIS/actions/workflows/devel_pipeline_validation.yml)
![Devel Commits](https://img.shields.io/github/commit-activity/m/ansible-lockdown/AMAZON2023-CIS/devel?color=dark%20green&label=Devel%20Branch%20Commits)
![Devel Commits](https://img.shields.io/github/commit-activity/m/ansible-lockdown/AMAZON2023-CIS/devel?color=dark%20green&label=Devel%20Branch%20commits)

![Issues Open](https://img.shields.io/github/issues-raw/ansible-lockdown/AMAZON2023-CIS?label=Open%20Issues)
![Issues Closed](https://img.shields.io/github/issues-closed-raw/ansible-lockdown/AMAZON2023-CIS?label=Closed%20Issues&&color=success)
Expand All @@ -44,7 +44,7 @@ NOTE AUDIT NOT YET AVAILABLE

### Community

Join us on our [Discord Server](https://discord.io/ansible-lockdown) to ask questions, discuss features, or just chat with other Ansible-Lockdown users.
Join us on our [Discord Server](https://www.lockdownenterprise.com/discord) to ask questions, discuss features, or just chat with other Ansible-Lockdown users.

### Contributing

Expand Down
2 changes: 1 addition & 1 deletion tasks/auditd.yml
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@

- name: POST | AUDITD | Add Warning count for changes to template file | Warn Count # noqa no-handler
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml
vars:
warn_control_id: 'Auditd template updated, see diff output for details'
when:
Expand Down
22 changes: 11 additions & 11 deletions tasks/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -87,7 +87,7 @@

- name: Include preliminary steps
ansible.builtin.import_tasks:
file: prelim.yml
file: prelim.yml
tags:
- prelim_tasks
- always
Expand All @@ -96,69 +96,69 @@
when:
- run_audit
ansible.builtin.include_tasks:
file: pre_remediation_audit.yml
file: pre_remediation_audit.yml
tags:
- run_audit

- name: Run Section 1 tasks
when:
- amzn2023cis_section1
ansible.builtin.import_tasks:
file: section_1/main.yml
file: section_1/main.yml
tags:
- amzn2023cis_section1

- name: Run Section 2 tasks
when:
- amzn2023cis_section2
ansible.builtin.import_tasks:
file: section_2/main.yml
file: section_2/main.yml
tags:
- amzn2023cis_section2

- name: Run Section 3 tasks
when:
- amzn2023cis_section3
ansible.builtin.import_tasks:
file: section_3/main.yml
file: section_3/main.yml
tags:
- amzn2023cis_section3

- name: Run Section 4 tasks
when:
- amzn2023cis_section4
ansible.builtin.import_tasks:
file: section_4/main.yml
file: section_4/main.yml
tags:
- amzn2023cis_section4

- name: Run Section 5 tasks
when:
- amzn2023cis_section5
ansible.builtin.import_tasks:
file: section_5/main.yml
file: section_5/main.yml
tags:
- amzn2023cis_section5

- name: Run Section 6 tasks
when:
- amzn2023cis_section6
ansible.builtin.import_tasks:
file: section_6/main.yml
file: section_6/main.yml
tags:
- amzn2023cis_section6

- name: run auditd logic
when:
- update_audit_template
ansible.builtin.import_tasks:
file: auditd.yml
file: auditd.yml
tags:
- always

- name: run post remediation tasks
ansible.builtin.import_tasks:
file: post.yml
file: post.yml
tags:
- post_tasks
- always
Expand All @@ -167,7 +167,7 @@
when:
- run_audit
ansible.builtin.import_tasks:
file: post_remediation_audit.yml
file: post_remediation_audit.yml

- name: Show Audit Summary
when:
Expand Down
2 changes: 1 addition & 1 deletion tasks/post.yml
Original file line number Diff line number Diff line change
Expand Up @@ -47,7 +47,7 @@

- name: "POST | Warning a reboot required but skip option set | warning count"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml
when:
- change_requires_reboot
- skip_reboot
Expand Down
2 changes: 1 addition & 1 deletion tasks/pre_remediation_audit.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@

- name: Pre Audit Binary Setup | Setup the LE audit
ansible.builtin.include_tasks:
file: LE_audit_setup.yml
file: LE_audit_setup.yml
when:
- setup_audit
tags:
Expand Down
2 changes: 1 addition & 1 deletion tasks/prelim.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,7 @@

- name: "PRELIM | capture /etc/password variables"
ansible.builtin.include_tasks:
file: parse_etc_password.yml
file: parse_etc_password.yml
tags:
- rule_5.5.2
- rule_5.6.2
Expand Down
2 changes: 1 addition & 1 deletion tasks/section_1/cis_1.1.2.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@

- name: "1.1.2.1 | PATCH | Ensure /tmp is a separate partition | Present"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml
vars:
warn_control_id: '1.1.2.1'
required_mount: '/tmp'
Expand Down
2 changes: 1 addition & 1 deletion tasks/section_1/cis_1.1.3.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@

- name: "1.1.3.1 | AUDIT | Ensure separate partition exists for /var | Present"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml
vars:
warn_control_id: '1.1.3.1'
required_mount: '/var'
Expand Down
2 changes: 1 addition & 1 deletion tasks/section_1/cis_1.1.4.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@

- name: "1.1.4.1 | AUDIT | Ensure separate partition exists for /var/tmp | Present"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml
vars:
warn_control_id: '1.1.4.1'
required_mount: '/var/tmp'
Expand Down
2 changes: 1 addition & 1 deletion tasks/section_1/cis_1.1.5.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@

- name: "1.1.5.1 | AUDIT | Ensure separate partition exists for /var/log | Present"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml

vars:
warn_control_id: '1.1.5.1'
Expand Down
2 changes: 1 addition & 1 deletion tasks/section_1/cis_1.1.6.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@

- name: "1.1.6.1 | AUDIT | Ensure separate partition exists for /var/log/audit | Present"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml

vars:
warn_control_id: '1.1.6.1'
Expand Down
2 changes: 1 addition & 1 deletion tasks/section_1/cis_1.1.7.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@

- name: "1.1.7.1 | AUDIT | Ensure separate partition exists for /home | Present"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml

vars:
warn_control_id: '1.1.7.1'
Expand Down
2 changes: 1 addition & 1 deletion tasks/section_1/cis_1.1.8.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@

- name: "1.1.8.1 | AUDIT | Ensure separate partition exists for /home | Present"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml

vars:
warn_control_id: '1.1.8.1'
Expand Down
2 changes: 1 addition & 1 deletion tasks/section_1/cis_1.2.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -72,7 +72,7 @@

- name: "1.2.3 | AUDIT | Ensure package manager repositories are configured | Warn Count"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml
vars:
warn_control_id: '1.2.3'
when:
Expand Down
2 changes: 1 addition & 1 deletion tasks/section_1/cis_1.6.1.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -98,7 +98,7 @@

- name: "1.6.1.6 | AUDIT | Ensure no unconfined services exist | warning count"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml
when: amzn2023cis_1_6_1_6_unconf_services.stdout | length > 0
vars:
warn_control_id: '1.6.1.6'
Expand Down
34 changes: 17 additions & 17 deletions tasks/section_1/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,70 +2,70 @@

- name: "SECTION | 1.1.1.x | Disable unused filesystems"
ansible.builtin.import_tasks:
file: cis_1.1.1.x.yml
file: cis_1.1.1.x.yml

- name: "SECTION | 1.1.2.x | Configure /tmp"
ansible.builtin.import_tasks:
file: cis_1.1.2.x.yml
file: cis_1.1.2.x.yml

- name: "SECTION | 1.1.3.x | Configure /var"
ansible.builtin.import_tasks:
file: cis_1.1.3.x.yml
file: cis_1.1.3.x.yml

- name: "SECTION | 1.1.4.x | Configure /var/tmp"
ansible.builtin.import_tasks:
file: cis_1.1.4.x.yml
file: cis_1.1.4.x.yml

- name: "SECTION | 1.1.5.x | Configure /var/log"
ansible.builtin.import_tasks:
file: cis_1.1.5.x.yml
file: cis_1.1.5.x.yml

- name: "SECTION | 1.1.6.x | Configure /var/log/audit"
ansible.builtin.import_tasks:
file: cis_1.1.6.x.yml
file: cis_1.1.6.x.yml

- name: "SECTION | 1.1.7.x | Configure /home"
ansible.builtin.import_tasks:
file: cis_1.1.7.x.yml
file: cis_1.1.7.x.yml

- name: "SECTION | 1.1.8.x | Configure /dev/shm"
ansible.builtin.import_tasks:
file: cis_1.1.8.x.yml
file: cis_1.1.8.x.yml

- name: "SECTION | 1.1.9 | Disable various mounting"
ansible.builtin.import_tasks:
file: cis_1.1.9.yml
file: cis_1.1.9.yml

- name: "SECTION | 1.2 | Configure Software Updates"
ansible.builtin.import_tasks:
file: cis_1.2.x.yml
file: cis_1.2.x.yml

- name: "SECTION | 1.3 | Filesystem Integrity Checking"
ansible.builtin.import_tasks:
file: cis_1.3.x.yml
file: cis_1.3.x.yml
when: amzn2023cis_config_aide

- name: "SECTION | 1.4 | Secure Boot Settings"
ansible.builtin.import_tasks:
file: cis_1.4.x.yml
file: cis_1.4.x.yml

- name: "SECTION | 1.5 | Additional Process Hardening"
ansible.builtin.import_tasks:
file: cis_1.5.x.yml
file: cis_1.5.x.yml

- name: "SECTION | 1.6 | Mandatory Access Control"
ansible.builtin.include_tasks:
file: cis_1.6.1.x.yml
file: cis_1.6.1.x.yml
when: not amzn2023cis_selinux_disable

- name: "SECTION | 1.7 | Command Line Warning Banners"
ansible.builtin.import_tasks:
file: cis_1.7.x.yml
file: cis_1.7.x.yml

- name: "SECTION | 1.8 | Updates and Patches"
ansible.builtin.import_tasks:
file: cis_1.8.yml
file: cis_1.8.yml

- name: "SECTION | 1.9 | Crypto policies"
ansible.builtin.include_tasks:
file: cis_1.9.yml
file: cis_1.9.yml
2 changes: 1 addition & 1 deletion tasks/section_2/cis_2.4.yml
Original file line number Diff line number Diff line change
Expand Up @@ -26,7 +26,7 @@

- name: "2.4 | AUDIT | Ensure nonessential services listening on the system are removed or masked | Warn Count"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml
vars:
warn_control_id: '2.4'
when:
Expand Down
8 changes: 4 additions & 4 deletions tasks/section_2/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,16 +2,16 @@

- name: "SECTION | 2.1 | Time Synchronization"
ansible.builtin.import_tasks:
file: cis_2.1.x.yml
file: cis_2.1.x.yml

- name: "SECTION | 2.2 | Special Purpose Services"
ansible.builtin.import_tasks:
file: cis_2.2.x.yml
file: cis_2.2.x.yml

- name: "SECTION | 2.3 | Service Clients"
ansible.builtin.import_tasks:
file: cis_2.3.x.yml
file: cis_2.3.x.yml

- name: "SECTION | 2.4 | Nonessential services removed"
ansible.builtin.import_tasks:
file: cis_2.4.yml
file: cis_2.4.yml
2 changes: 1 addition & 1 deletion tasks/section_3/cis_3.4.2.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@

- name: "3.4.2.2 | AUDIT | Ensure an nftables table exists | Alert on no tables | warning count"
ansible.builtin.import_tasks:
file: warning_facts.yml
file: warning_facts.yml
when:
- amzn2023cis_3_4_2_2_nft_tables.stdout | length == 0
- not amzn2023cis_nft_tables_autonewtable
Expand Down
10 changes: 5 additions & 5 deletions tasks/section_3/main.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,20 +2,20 @@

- name: "SECTION | 3.1.x | Disable unused network protocols and devices"
ansible.builtin.import_tasks:
file: cis_3.1.x.yml
file: cis_3.1.x.yml

- name: "SECTION | 3.2.x | Network Parameters (Host Only)"
ansible.builtin.import_tasks:
file: cis_3.2.x.yml
file: cis_3.2.x.yml

- name: "SECTION | 3.3.x | Network Parameters (host and Router)"
ansible.builtin.import_tasks:
file: cis_3.3.x.yml
file: cis_3.3.x.yml

- name: "SECTION | 3.4.1.x | Firewall configuration"
ansible.builtin.import_tasks:
file: cis_3.4.1.x.yml
file: cis_3.4.1.x.yml

- name: "SECTION | 3.4.2.x | Configure firewall"
ansible.builtin.import_tasks:
file: cis_3.4.2.x.yml
file: cis_3.4.2.x.yml
Loading

0 comments on commit 46fb367

Please sign in to comment.