-
Notifications
You must be signed in to change notification settings - Fork 0
/
server-iam.yml
36 lines (32 loc) · 1.96 KB
/
server-iam.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
---
#python3 -c 'import crypt; print(crypt.crypt("password"))'
#ruby -e 'puts "password".crypt("$6$saltsalt$")'
- hosts: hardening
become: yes
become_user: root
### Variable
vars:
# Define Credential User root
- user_root: root
- password_root: "$6$jVLEyaF6j.ps2f18$PcjXwVBqhvoUXXuIRLEsDlRiMhCEN7h1PYvItAMAUMbUCBux2ZfibFRobaLSzjWgwugAvTJj72qDafiXlCFeT1"
# Define Credential User Admin
- user_admin: admin
- password_admin: "$6$MnL9IZTgizW6MAnI$5jZwBOAQVdmN1BF1VgnfJNovf0lV49clJ8rXKw4FcHBLLXDjXHu9S2DQhPubsUrmnGijylTTdU17EqbQxaUww0"
# Define Credential User For Applications
- user_other: operation
- password_other: "$6$c3WakKIr9WdbUH56$Lgn.ub3Cenry7qswZ04MhZuUxvlH/qt7soOTIQCalX5zTFhw104/vE7XJ/2/RU.59F2MVYj9OaXdld24SF6Jp0"
# Attached Public Key, Hardener
- public_key: "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDdA4sdMITuL88nV4XP44MF/uvUwoSl08ExgRE3xNdUsIZaSa+VeNiLVwZGoGdvQf6F5CYSXl4kpUyQZspYQvu+H6VEU/bhYvHFHok+BLZPLg9IJERCK8l/8tnRRv3DllSFGx9zSTEaAy6mA3JiObNwf0WmnWkmFMKroqkvV+ss/PUCQvYbLkmUXuaAgDISisj0YYYk8eFg8RdDxk0Z5T8UrO4Gm7NTH6T/BtXP5UATHmDIG/jWMS+tn6PKh/pXpq6oS/epx3Uyz38h8p6Hjs/Xlo1c6989uDqh+035bX7vGYpWcBlq3UsYOMHP7vmqm6yUOV8fUyvK0D7MmtQuLVNI72fjbqkFM+REQ7RniXi9WqgzTEgL0WYtbGa0bTvBxwu6QkhDXucr8fCFKQ3+9I4LzXEz6aobRw7N0Myi/rltqcVbNJb9hc3uHggXvhINu/wQfoIcxK2lWUXPapR07Lzs8pIT6miv/r5A9rgztFViPwe1MkFlqGoEWYgbtCZuT9E= neareth@127block"
# Define Allow List IP Private Internal for access ssh via Port 22
- iptables_ssh_access_ip_allow: 10.32.5.0/24,10.32.16.179,10.32.16.180
# Define Allow Any Access for access ssh via Port $port_ssh
- port_ssh: 12920
# Define for Create SWAP File Or Not (True or False)
- swap_support: False
### Or Define using file external
#vars_files:
# - ./global_variables.yml
### Or Define Variable as Host Or Group in inventories/production/group_vars/app
### Currently Variable For Hardening put in Variable Global Inventory - all
roles:
- luneareth_iam