1
0
forked from infra/ansible
infra/roles/common/tasks/Debian.yml

105 lines
2.5 KiB
YAML
Raw Normal View History

2015-12-13 18:54:49 +01:00
---
- name: Install misc software
2017-07-02 22:17:32 +02:00
apt: name={{ item }}
loop:
2016-02-01 21:01:52 +01:00
- dnsutils
2015-12-13 18:54:49 +01:00
- htop
- less
- net-tools
- openssl
2018-01-14 19:06:25 +01:00
- psmisc
2015-12-13 18:54:49 +01:00
- pydf
2016-04-08 09:12:19 +02:00
- rsync
2016-02-15 21:04:37 +01:00
- sudo
2015-12-13 18:54:49 +01:00
- vim-nox
- zsh
- name: Install software on KVM VMs
apt: name={{ item }}
loop:
- acpid
- qemu-guest-agent
when: ansible_virtualization_role == "guest" and ansible_virtualization_type == "kvm"
2018-05-01 11:47:57 +02:00
2015-12-13 18:54:49 +01:00
- name: Configure misc software
copy: src={{ item.src }} dest={{ item.dest }}
diff: no
loop:
2015-12-13 18:54:49 +01:00
- { src: '.zshrc', dest: '/root/.zshrc' }
- { src: '.zshrc.local', dest: '/root/.zshrc.local' }
2016-03-04 13:02:55 +01:00
- { src: 'motd', dest: '/etc/motd' }
2017-09-20 13:24:30 +02:00
- { src: 'vimrc.local', dest: '/etc/vim/vimrc.local' }
2015-12-13 18:54:49 +01:00
- name: Set shell for root user
user: name=root shell=/bin/zsh
2016-03-03 08:09:26 +01:00
- name: Create LDAP client config
template: src=ldap.conf.j2 dest=/etc/ldap/ldap.conf mode=0644
- name: Disable hibernation/resume
copy: src=resume dest=/etc/initramfs-tools/conf.d/resume
notify: update-initramfs
# TODO template /etc/network/interfaces
- name: Fix network interface names
copy: src={{ item }} dest=/etc/systemd/network/{{ item }}
loop:
- 50-virtio-kernel-names.link
- 99-default.link
notify: update-initramfs
- name: Prevent normal users from running su
lineinfile:
path: /etc/pam.d/su
2018-07-17 13:26:45 +02:00
regexp: '^.*auth\s+required\s+pam_wheel.so$'
line: 'auth required pam_wheel.so'
- name: Configure journald retention
lineinfile:
path: "/etc/systemd/journald.conf"
state: "present"
regexp: "^#?MaxRetentionSec=.*"
line: "MaxRetentionSec=7day"
notify: Restart journald
- name: Set logrotate.conf to daily
replace:
path: "/etc/logrotate.conf"
regexp: "(?:weekly|monthly)"
replace: "daily"
- name: Set logrotate.conf rotation to 7
replace:
path: "/etc/logrotate.conf"
regexp: "rotate [0-9]+"
replace: "rotate 7"
- name: Find logrotate.d configuration files
find:
paths: "/etc/logrotate.d/"
register: "logrotateconfigs"
- name: Convert found files to path list
set_fact:
alllogrotateconfigpaths: "{{ logrotateconfigs.files | map(attribute='path') | list }}"
- name: Exclude files from ansible management
set_fact:
logrotateconfigpaths: "{{ alllogrotateconfigpaths | difference(logrotate_excludes) }}"
- name: 'Set logrotate.d/* to daily'
replace:
path: "{{ item }}"
regexp: "(?:weekly|monthly)"
replace: "daily"
loop: "{{ logrotateconfigpaths }}"
- name: 'Set /etc/logrotate.d/* rotation to 7'
replace:
path: "{{ item }}"
regexp: "rotate [0-9]+"
replace: "rotate 7"
loop: "{{ logrotateconfigpaths }}"