-
Notifications
You must be signed in to change notification settings - Fork 5
Commit 85d8030

68570 cloudwatch exporter role pr devel 2.x (#2358)
* Bug fixes 2.x pr 2.x (#1752)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Bug fixes 2.x pr 2.x (#1754)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Bug fixes 2.x pr 2.x (#1756)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Redoing-changes-for-aws-acl-role (#1728)
* Redoing-changes-for-aws-acl-role
* retrigger checks
* Fixing-conflicts-4
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* Remvoing-scp-extra-args-temporary (#1761)
Co-authored-by: Matej Stajduhar <[email protected]>
* Bug fixes 2.x pr 2.x (#1765)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Bug fixes 2.x pr 2.x (#1767)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Fixing firewall.bash deletion issues.
* Bug fixes 2.x pr 2.x (#1769)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Fixing firewall.bash deletion issues.
* Getting rid of accidental extra braces.
* Bug fixes 2.x pr 2.x (#1771)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Fixing firewall.bash deletion issues.
* Getting rid of accidental extra braces.
* Simplifying usernames so you only need to set one var.
* Managing-mime-types-nginx (#1773)
* Whitelisting ce vpn ip wazuh pr 2.x (#1775)
* Whitelisting-CE-VPN-IP-wazuh
* Fixing-wazuh-whitelist-variable
* Updating-wazuh-vars (#1777)
* add community.postgresql collection and remove varnish master release (#1779)
* Updating wazuh vars pr 2.x (#1781)
* Updating-wazuh-vars
* Updating-manager-vars
* Updating wazuh vars pr 2.x (#1783)
* Updating-wazuh-vars
* Updating-manager-vars
* Updating-wazuh-manager-active-response
* Updating-wazuh-manager-active-response-2x
* Updating wazuh vars pr 2.x (#1785)
* Updating-wazuh-vars
* Updating-manager-vars
* Updating-wazuh-manager-active-response
* Updating-wazuh-manager-active-response-2x
* Fixing-wazuh-broken-pipeline
* Updating wazuh vars pr 2.x (#1787)
* Updating-wazuh-vars
* Updating-manager-vars
* Updating-wazuh-manager-active-response
* Updating-wazuh-manager-active-response-2x
* Fixing-wazuh-broken-pipeline
* Tweaking-wazuh-vars
* r68065 mattermost role first commit (#1789)
* r68065 mattermost role first commit
* fixing linting/syntax
* reload systemd with ansible.builtin.systemd_service
* handler for postgresql reloads
* default systemd unit file for mattermost role
* r68065 install python psycopg2 (#1791)
* r68065 use psycopg binary package as compiling creates depsolve issues (#1793)
* permissions for postgres setup (#1795)
* r68065 add mattermost group before user (#1797)
* Updating-duplicity (#1804)
* enable mattermost systemd unit (#1810)
* nginx include for mattermost (#1812)
* nginx include for mattermost
* add mattermost project type
* ssl on handled by nginx role (#1814)
* fix mattermost nginx include (#1822)
* remove unsupported nginx option (#1824)
* Restore testing update pr 2.x (#1832)
* Restore-testing-update
* Restore-testing-update-2
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* Resolving conflicts pr 2.x (#1834)
* Fixing-conflicts-and-updating-docs
* Fixed-conflicts
* Fixed-conflicts-2
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* initial commit - mattermost local backups (#1838)
* r69995-Updating-vhost-for-LE-validation (#1843)
Co-authored-by: Matej Stajduhar <[email protected]>
* Changing priority flexibility pr 2.x (#1841)
* Changing-priority-flexibility
* Changing-priority-flexibility-2
* Adding-aws-acl-to-meta
* Adding-cast-to-int-for-priority
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* Aws acl role changes for ip set pr 2.x (#1848)
* aws_acl-role-changes-for-ip-set
* aws_acl-role-changes-for-ip-set-docs-update
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* add_php_repo_before_apt_extra_packages_task_from_common_base (#1850)
* fix_opensearch_vars (#1852)
* wait_timeout_for_opensearch_domain_creation (#1854)
* wait_timeout_for_opensearch_domain_creation
* remove trailing space
* Updating-aws-acl-task (#1856)
Co-authored-by: Matej Stajduhar <[email protected]>
* Bug fixes 2.x pr 2.x (#1859)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Fixing firewall.bash deletion issues.
* Getting rid of accidental extra braces.
* Simplifying usernames so you only need to set one var.
* Docs update and making Ansible installation via _init an option.
* Bug fixes 2.x pr 2.x (#1860)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Fixing firewall.bash deletion issues.
* Getting rid of accidental extra braces.
* Simplifying usernames so you only need to set one var.
* Docs update and making Ansible installation via _init an option.
* Variable path error.
* Updating linter ignore paths.
* Small-changes-on-aws-acl-and-RDS-validation (#1863)
Co-authored-by: Matej Stajduhar <[email protected]>
* Updating-user-ansible-vars (#1864)
* Updating user ansible vars pr 2.x (#1867)
* Updating-user-ansible-vars
* Fixing-syntax
* add_vars_to_user_deploy_user_provision (#1869)
* Disabling-general-log-mariadb (#1871)
* Updating-aws_acl-role (#1873)
Co-authored-by: Matej Stajduhar <[email protected]>
* r70260-rkhunter-whitelist (#1877)
* fix(nginx): Remove default nginx dummy vhost that could clash with Varnish (#1750)
* fix(nginx): Remove default nginx dummy vhost that could clash with Varnish
* Fix variable naming and comment
* Implement keep_default_vhost setting
* Wazuh-var-update (#1903)
* Wazuh-agent-vars-more-readable (#1905)
* Filebeat-restart-task-wazuh (#1907)
* Filebeat restart task wazuh pr 2.x (#1909)
* Filebeat-restart-task-wazuh
* Fixing-wazuh-filebeat-restart
* Adding-gawk-to-extra-packages (#1910)
* Updating-filebeat-restart-task (#1913)
* Adding motd to exit role pr 2.x (#1915)
* Fixing-backup-validation-role-plicies
* Adding-parts-for-VPC-and-SG
* Adding-region-to-vpc-and-subnet-tasks
* Adding-region-to-vpc-and-subnet-tasks-2
* Updating-vars-for-vpc-and-subnet
* Updating-vars-for-vpc-and-subnet-2
* Updating-vars-for-vpc-and-subnet-3
* Adding-json-file-for-restore-testing
* Changing-user-where-json-file-is-generated
* Updating-json-file-location
* Updating-path-to-j2-file
* Changing-force-valkue
* Testing-file-creation
* Testing-file-creation-via-command-task
* Adding-motd-to-exit-role
* Commenting-out-task-that-will-fail
* Fixing-pipefail
* Fixing-syntax-issue
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* Fixing-motd-task (#1917)
* Motd-switch-egrep-with-awk (#1919)
* Motd-task-update (#1922)
* Motd-task-update
* Restoring-deleted-task
* Fixing motd task when running on localhost pr 2.x (#1924)
* Fixing-backup-validation-role-plicies
* Fixing-motd-task-when-running-on-localhost
* Updating-when-statement
* Adding-become-true-on-motd-update
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* Apt bug workaround pr 2.x (#1935)
* apt_bug_workaround
* apt_bug_workaround
* apt_bug_workaround
* apt_bug_workaround
* fix_var_logic
* Pushing-aws-backup-validation-role (#1944)
* Pushing-aws-backup-validation-role
* Fixing-linting
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* fix(redis): Convert maxmemory setting to int before comparing (#1897)
* Reverting-nginx-username (#1945)
* Reverting nginx username pr 2.x (#1947)
* Reverting-nginx-username
* Minor-fix-nginx-username
* Updating-nginx-vars (#1950)
* Bug fixes 2.x pr 2.x (#1952)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Fixing firewall.bash deletion issues.
* Getting rid of accidental extra braces.
* Simplifying usernames so you only need to set one var.
* Docs update and making Ansible installation via _init an option.
* Variable path error.
* Updating linter ignore paths.
* Making the NGINX test result var private.
* Documentation update.
* Fixing role dependency in NGINX role.
* r70597 new system role for ipv6 disablement (#1954)
* r70597 new system role for ipv6 disablement
* fix linting problem
* add readme for system role
* Fixing-json-file-for-restore-testing (#1956)
Co-authored-by: Matej Stajduhar <[email protected]>
* Fixing json file for restore testing pr 2.x (#1957)
* Fixing-json-file-for-restore-testing
* Missing-coma-in-json
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* updating asg role to support custom rule on http and https (#1959)
Co-authored-by: filip <[email protected]>
* Bug fixes 2.x pr 2.x (#1962)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Fixing firewall.bash deletion issues.
* Getting rid of accidental extra braces.
* Simplifying usernames so you only need to set one var.
* Docs update and making Ansible installation via _init an option.
* Variable path error.
* Updating linter ignore paths.
* Making the NGINX test result var private.
* Documentation update.
* Fixing role dependency in NGINX role.
* Adding installation path handling for Galaxy collections.
* Bug fixes 2.x pr 2.x (#1966)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Fixing firewall.bash deletion issues.
* Getting rid of accidental extra braces.
* Simplifying usernames so you only need to set one var.
* Docs update and making Ansible installation via _init an option.
* Variable path error.
* Updating linter ignore paths.
* Making the NGINX test result var private.
* Documentation update.
* Fixing role dependency in NGINX role.
* Adding installation path handling for Galaxy collections.
* Removing -p option due to unexpected ill effects for role paths.
* r70596 create swap directory (#1968)
* r70596 create swap directory
* remove stat check
* 70325 adding asg redirect pr 2.x (#1963)
* updating asg role to support custom rule on http and https
* updating readme properly
* updating docs for the asg role
---------
Co-authored-by: filip <[email protected]>
* swapfile path and clamav exclusion (#1970)
* Galaxy role pr 2.x (#1974)
* Deleting obsolete Debian 10 requirements files.
* Adding first pass at generic and reusable Ansible Galaxy role.
* Docs update.
* Updating README files.
* Updating ce_provision and ce_deploy to use ansible_galaxy role.
* Ansible Galaxy docs enhancement.
* Cannot use _ansible in variable names, reserved.
* Removing blocks for Galaxy installation, not needed.
* Variables passed to Galaxy role were wrong.
* Bug fixes 2.x pr 2.x (#1975)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Fixing firewall.bash deletion issues.
* Getting rid of accidental extra braces.
* Simplifying usernames so you only need to set one var.
* Docs update and making Ansible installation via _init an option.
* Variable path error.
* Updating linter ignore paths.
* Making the NGINX test result var private.
* Documentation update.
* Fixing role dependency in NGINX role.
* Adding installation path handling for Galaxy collections.
* Removing -p option due to unexpected ill effects for role paths.
* Moving X-Content-Type-Options header to project type templates.
* Adding some inline documentation.
* Bug fixes 2.x pr 2.x (#1978)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Fixing firewall.bash deletion issues.
* Getting rid of accidental extra braces.
* Simplifying usernames so you only need to set one var.
* Docs update and making Ansible installation via _init an option.
* Variable path error.
* Updating linter ignore paths.
* Making the NGINX test result var private.
* Documentation update.
* Fixing role dependency in NGINX role.
* Adding installation path handling for Galaxy collections.
* Removing -p option due to unexpected ill effects for role paths.
* Moving X-Content-Type-Options header to project type templates.
* Adding some inline documentation.
* Fixing Postfix template to allow external relays.
* Bug fixes 2.x pr 2.x (#1980)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
* Capturing lock file limitations in comment.
* Updating documentation for LE.
* Using pip to install certbot plugins.
* Updating README docs.
* Docs error corrected.
* Working around deprecated SSH algorithms.
* Upgrading SSH key type standard for controller and deploy users.
* Adding SCP args for legacy mode needed by Packer.
* Adding an extra when clause to ACM SAN cert check.
* Trying different approach to ACM SAN cert check.
* Removing /bin/which from rkhunter defaults, it isn't present in Debian 11.
* RDS param group module has changed name.
* Adding passlib to libraries installed for ce-provision.
* Adding in valid path for 'which' to rkhunter.
* Catching up documentation.
* Catching up documentation.
* Making user creation optional and home directories a variable.
* Missed passing new home var to task.
* Fixing firewall.bash deletion issues.
* Getting rid of accidental extra braces.
* Simplifying usernames so you only need to set one var.
* Docs update and making Ansible installation via _init an option.
* Variable path error.
* Updating linter ignore paths.
* Making the NGINX test result var private.
* Documentation update.
* Fixing role dependency in NGINX role.
* Adding installation path handling for Galaxy collections.
* Removing -p option due to unexpected ill effects for role paths.
* Moving X-Content-Type-Options header to project type templates.
* Adding some inline documentation.
* Fixing Postfix template to allow external relays.
* Adding a FQDN postfix transport map.
* Updating defaults pr 2.x (#1982)
* Updated-defaults-for-aws_acl-role
* Removing-Identity-search
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* Updating defaults pr 2.x (#1984)
* Updated-defaults-for-aws_acl-role
* Removing-Identity-search
* Removing-undefined-variable
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* Removing-gawk-apt (#1985)
* Adding-gawk-removing-gawk-csh (#1987)
* Adding-when-statement-for-assigning-instance (#1990)
* Adding-when-statement-for-assigning-instance
* Adding-check-prior-to-assigning-resources
* Adding-check-prior-to-assigning-resources
* Adding-region-to-aws-cli-command
* Print-protected-resource
* Adding-resource-type-definition
* Resolved-conflicts
* Removing-empty-line
* Disabling-assigning-instance-to-restore-testing-plan
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* Matching-2.x-and-devel-branches (#1999)
Co-authored-by: Matej Stajduhar <[email protected]>
* Adding-aws-ses-role (#2003)
* Adding-aws-ses-role
* Removing-python-script
* Changing-domain-name
* Using-variable-for-domain-name
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* Resolving-conflicts (#2015)
Co-authored-by: Matej Stajduhar <[email protected]>
* Resolving-conflicts (#2018)
Co-authored-by: Matej Stajduhar <[email protected]>
* Updating nginx ssl le roles pr 2.x (#2021)
* Updating-nginx-SSL-LE-roles
* Updating-nginx-vars
* r70260 Option to ignore false-positive shared memory segment warnings (#2023)
* Adding-wazuh-ossec-from-enigma00a (#2027)
* Updating-gitlab-runner-env (#2031)
* r70987-decom-vpn-guest (#2034)
* r70797 nodhcp module in system role for hetzner cloud systems (#2036)
* r70797 nodhcp module in system role for hetzner cloud systems
* fix syntax
* r70797 set pipefail to resolve linting failure
* fix pipefail with bash (#2038)
* fix var in templ (#2040)
* R70928 adding webroot option for le ssl task and fixing looping over domains pr 2.x (#2042)
* r70928-adding-webroot-option-for-LE-SSL-task-and-fixing-looping-over-domains
* Changing-LE-cron
* Changing-script-from-sh-to-bash
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* Updating-local-ossec-rules (#2045)
* Updating-local-ossec-rules
* Fixing-syntax
* Updating-wazuh-vars (#2048)
* Updating-wazuh-vars
* Changing-var-defaults
* Removing-wrong-variables
* r70260-rkhunter-tested-good-tweaks (#2051)
* Fixing-LE-renew-timer (#2052)
Co-authored-by: Matej Stajduhar <[email protected]>
* R70260 rkhunter tweak portpathwhitelist pr 2.x (#2055)
* r70260-rkhunter-tweak-portpathwhitelist TEST
* sanitise portpath items
* Updating-system-role-condition (#2056)
* Updating system role condition pr 2.x (#2059)
* Updating-system-role-condition
* Updating-system-role-condition-v2
* r71121-tweak-nohetznerdhcp-condition (#2061)
* Changing-aws-acl-when-statement (#2063)
Co-authored-by: Matej Stajduhar <[email protected]>
* R71127 r71052 check pr 2.x (#2073)
* r71127-r71052-attemt-to-workaround-elb-module-change-or-bug
* debug alb issue
* revert changes as the bug is outside of ce-provision https://github.com/ansible-collections/amazon.aws/issues/2376
* Newer aws collection test pr 2.x (#2077)
* newer_aws_collection_test
* 8.2.1 didnt work, back to 8.0.1
* r71171-efs-client-upgrade (#2079)
* Turning-off-ami-cleanup-task (#2083)
Co-authored-by: Matej Stajduhar <[email protected]>
* Changing subnet for rds pr 2.x (#2087)
* Changing-subnet-for-RDS
* Uncommenting-tasks
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* fix(debian/duplicity): Fix missing compilation dependencies (#2029)
* fix(php-fpm): Set a good process children default for bigger servers (#1895)
* fix(php-fpm): Set a good process children default for bigger servers
* Fix min max logic
* formatting
* Fixing-RDS-backup-validation (#2089)
Co-authored-by: Matej Stajduhar <[email protected]>
* Updating-postfix-default-transport-maps (#2092)
* Updated lambda backup validation reporting pr 2.x (#2099)
* Updated-lambda-backup-validation-reporting
* Updating-docs
* Updating-lambda-handler
* Adding-region-to-cloudwatch-task
* Trimming-version-number-from-lambda
* Fixing-text-manipulation
* Updating-arn-for-cloudwatch-task
---------
Co-authored-by: Matej Stajduhar <[email protected]>
* Bug fixes 2.x pr 2.x (#2096)
* Improving AWS subnet docs.
* Error in timers structure in the SSL role.
* Removing obsolete backports requirements.
* Allow the billing role to access Sustainability information.
* Missing comma in IAM billing policy.
* Removing broken GitLab Runner code.
* Fixed the include_role task in gitlab_runner.
* Suppressing a failure if there is no system pip to call.
* Logic error in Ansible installer username, needs to be set from calling role.
* ansible_user is a reserved variable, seems to be causing issues.
* _ansible_ANYTHING is reserved, using _install_username instead.
* python_boto role also needs the username set in the calling role.
* Updating python_boto docs.
* Making profile.d loading more robust.
* Also pip removing ansible-core and trying with pip and pip3 to cover all bases.
* Updating bad AWS SG role var namespacing in other roles.
* Refactoring how we handle python3-pip.
* Allow passing in of the Python interpreter to Ansible.
* Updating the packages server for CE.
* Installing Ansible in a venv on all machines.
* Changing common_base format for readability.
* No need to specify Python to the point release.
* Docs update.
* Fixing LDAP SSL to use systemd timer.
* Allowing different systemd timer names for different Ansible installs.
* Fixing dynamic key name in ansible role.
* Trying to debug missing timer_command var.
* Treating the timer string so it becomes a dict.
* Moving default log location for clamav.
* Updating ClamAV docs.
* Grouping systemd timer tasks together.
* Exposing ce-provision version in build output.
* Wrong variable in meta role for controller username.
* Removing any reference to _aws variables in debian role defaults.
* Setting more sane ASG defaults.
* Making ClamAV timers a list so they can be entirely replaced.
* Spacing fix for linting.
* Renaming npm module.
* Removing NGINX installation as part of phpMyAdmin role by default.
* Fixing Varnish handler names.
* Excluding name[casing] rule from linting due to false positives.
* Put rule in wrong place!
* Removing lock file behaviour from ASGs as it cannot work unless controller and ASG are in the same VPC.
*…1 parent 2883c4d commit 85d8030Copy full SHA for 85d8030
File tree
Expand file treeCollapse file tree
5 files changed
+284
-0
lines changedFilter options
- roles/debian/yace_exporter
- defaults
- tasks
- templates
Expand file treeCollapse file tree
5 files changed
+284
-0
lines changedCollapse file: roles/debian/yace_exporter/README.md
roles/debian/yace_exporter/README.md
Copy file name to clipboard+59Lines changed: 59 additions & 0 deletions
- Display the source diff
- Display the rich diff
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + |
Collapse file: roles/debian/yace_exporter/defaults/main.yml
roles/debian/yace_exporter/defaults/main.yml
Copy file name to clipboard+85Lines changed: 85 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + |
Collapse file: roles/debian/yace_exporter/tasks/main.yml
roles/debian/yace_exporter/tasks/main.yml
Copy file name to clipboard+109Lines changed: 109 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + |
Collapse file: roles/debian/yace_exporter/templates/yace_exporter.service.j2
roles/debian/yace_exporter/templates/yace_exporter.service.j2
Copy file name to clipboard+19Lines changed: 19 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + |
Collapse file: roles/debian/yace_exporter/templates/yace_exporter_policy.json.j2
roles/debian/yace_exporter/templates/yace_exporter_policy.json.j2
Copy file name to clipboard+12Lines changed: 12 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + |
0 commit comments