6115d9d48f
- Document architecture decisions in README (Ansible + Docker Compose + Traefik) - Scaffold Ansible layout: inventory, site.yml, group_vars, 9 service roles - Implement base role: package install, deploy user, SSH hardening, UFW firewall (22/80/443), fail2ban, unattended-upgrades - Add reinstall runbook in docs/runbook.md - Add ansible/requirements.yml for community.general and ansible.posix
135 lines
2.5 KiB
YAML
135 lines
2.5 KiB
YAML
---
|
|
# --- Packages ---
|
|
|
|
- name: Update apt cache
|
|
ansible.builtin.apt:
|
|
update_cache: true
|
|
cache_valid_time: 3600
|
|
tags: base
|
|
|
|
- name: Upgrade all packages
|
|
ansible.builtin.apt:
|
|
upgrade: dist
|
|
tags: base
|
|
|
|
- name: Install base packages
|
|
ansible.builtin.apt:
|
|
name:
|
|
- curl
|
|
- git
|
|
- vim
|
|
- htop
|
|
- ufw
|
|
- fail2ban
|
|
- unattended-upgrades
|
|
- apt-listchanges
|
|
state: present
|
|
tags: base
|
|
|
|
# --- System ---
|
|
|
|
- name: Set timezone
|
|
community.general.timezone:
|
|
name: "{{ timezone }}"
|
|
tags: base
|
|
|
|
# --- Deploy user ---
|
|
|
|
- name: Create deploy user
|
|
ansible.builtin.user:
|
|
name: "{{ deploy_user }}"
|
|
shell: /bin/bash
|
|
create_home: true
|
|
groups: sudo
|
|
append: true
|
|
state: present
|
|
tags: base
|
|
|
|
- name: Add SSH authorized key for deploy user
|
|
ansible.posix.authorized_key:
|
|
user: "{{ deploy_user }}"
|
|
state: present
|
|
key: "{{ lookup('file', playbook_dir + '/../keys/notroot_cloud_ladkau_de.pub') }}"
|
|
tags: base
|
|
|
|
- name: Allow deploy user passwordless sudo
|
|
ansible.builtin.copy:
|
|
dest: /etc/sudoers.d/{{ deploy_user }}
|
|
content: "{{ deploy_user }} ALL=(ALL) NOPASSWD:ALL\n"
|
|
mode: "0440"
|
|
validate: visudo -cf %s
|
|
tags: base
|
|
|
|
# --- SSH hardening ---
|
|
|
|
- name: Deploy hardened sshd_config
|
|
ansible.builtin.template:
|
|
src: sshd_config.j2
|
|
dest: /etc/ssh/sshd_config
|
|
owner: root
|
|
group: root
|
|
mode: "0600"
|
|
validate: sshd -t -f %s
|
|
notify: Restart sshd
|
|
tags: base
|
|
|
|
# --- Firewall ---
|
|
|
|
- name: Set UFW default incoming policy to deny
|
|
community.general.ufw:
|
|
direction: incoming
|
|
policy: deny
|
|
tags: base
|
|
|
|
- name: Set UFW default outgoing policy to allow
|
|
community.general.ufw:
|
|
direction: outgoing
|
|
policy: allow
|
|
tags: base
|
|
|
|
- name: Allow SSH (22/tcp)
|
|
community.general.ufw:
|
|
rule: allow
|
|
port: "22"
|
|
proto: tcp
|
|
tags: base
|
|
|
|
- name: Allow HTTP (80/tcp)
|
|
community.general.ufw:
|
|
rule: allow
|
|
port: "80"
|
|
proto: tcp
|
|
tags: base
|
|
|
|
- name: Allow HTTPS (443/tcp)
|
|
community.general.ufw:
|
|
rule: allow
|
|
port: "443"
|
|
proto: tcp
|
|
tags: base
|
|
|
|
- name: Enable UFW
|
|
community.general.ufw:
|
|
state: enabled
|
|
tags: base
|
|
|
|
# --- Automatic security updates ---
|
|
|
|
- name: Enable unattended-upgrades
|
|
ansible.builtin.copy:
|
|
src: 20auto-upgrades
|
|
dest: /etc/apt/apt.conf.d/20auto-upgrades
|
|
owner: root
|
|
group: root
|
|
mode: "0644"
|
|
tags: base
|
|
|
|
# --- Fail2ban ---
|
|
|
|
- name: Enable and start fail2ban
|
|
ansible.builtin.service:
|
|
name: fail2ban
|
|
state: started
|
|
enabled: true
|
|
tags: base
|