--- # --- Packages --- - name: Update apt cache ansible.builtin.apt: update_cache: true cache_valid_time: 3600 tags: base - name: Upgrade all packages ansible.builtin.apt: upgrade: dist tags: base - name: Install base packages ansible.builtin.apt: name: - curl - git - vim - htop - ufw - fail2ban - unattended-upgrades - apt-listchanges state: present tags: base # --- System --- - name: Set timezone community.general.timezone: name: "{{ timezone }}" tags: base # --- Deploy user --- - name: Create deploy user ansible.builtin.user: name: "{{ deploy_user }}" shell: /bin/bash create_home: true groups: sudo append: true state: present tags: base - name: Add SSH authorized key for deploy user ansible.posix.authorized_key: user: "{{ deploy_user }}" state: present key: "{{ lookup('file', playbook_dir + '/../keys/notroot_cloud_ladkau_de.pub') }}" tags: base - name: Allow deploy user passwordless sudo ansible.builtin.copy: dest: /etc/sudoers.d/{{ deploy_user }} content: "{{ deploy_user }} ALL=(ALL) NOPASSWD:ALL\n" mode: "0440" validate: visudo -cf %s tags: base # --- SSH hardening --- - name: Deploy hardened sshd_config ansible.builtin.template: src: sshd_config.j2 dest: /etc/ssh/sshd_config owner: root group: root mode: "0600" validate: sshd -t -f %s notify: Restart sshd tags: base # --- Firewall --- - name: Set UFW default incoming policy to deny community.general.ufw: direction: incoming policy: deny tags: base - name: Set UFW default outgoing policy to allow community.general.ufw: direction: outgoing policy: allow tags: base - name: Allow SSH (22/tcp) community.general.ufw: rule: allow port: "22" proto: tcp tags: base - name: Allow HTTP (80/tcp) community.general.ufw: rule: allow port: "80" proto: tcp tags: base - name: Allow HTTPS (443/tcp) community.general.ufw: rule: allow port: "443" proto: tcp tags: base - name: Enable UFW community.general.ufw: state: enabled tags: base # --- Automatic security updates --- - name: Enable unattended-upgrades ansible.builtin.copy: src: 20auto-upgrades dest: /etc/apt/apt.conf.d/20auto-upgrades owner: root group: root mode: "0644" tags: base # --- Fail2ban --- - name: Deploy fail2ban filter for Traefik ansible.builtin.copy: src: filter.d/traefik.conf dest: /etc/fail2ban/filter.d/traefik.conf owner: root group: root mode: "0644" notify: Restart fail2ban tags: base - name: Deploy fail2ban jail for Traefik ansible.builtin.copy: src: jail.d/traefik.conf dest: /etc/fail2ban/jail.d/traefik.conf owner: root group: root mode: "0644" notify: Restart fail2ban tags: base - name: Enable and start fail2ban ansible.builtin.service: name: fail2ban state: started enabled: true tags: base