ansible-role-hardening
ansible-role-security
Our great sponsors
ansible-role-hardening | ansible-role-security | |
---|---|---|
1 | 7 | |
494 | 760 | |
- | - | |
9.5 | 5.0 | |
6 days ago | about 1 month ago | |
Jinja | Jinja | |
Apache License 2.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
ansible-role-hardening
-
AKS worker-node host operating systems
Many thanks u/pixelavenger. While I did not (yet) find the specific CIS recommendation, but I did find this which indicates that disabling SCTP module is perhaps too strong a reaction if the only justification is disabling those networking features that are usually not used frequently (to reduce attack surface). Apparently there was a vulnerability in WebRTC's user-space SCTP implementation, which has hence been fixed. There seem to be no known vulnerabilities in linux kernel SCTP implementation. Do you think Azure Support might be requested to optionally enable SCTP kernel module in the images ? Thanks also for the idea about using Daemon-set approach, perhaps a bit kludgy for the needs, as one'd need to invent a way to synchronize the completion of Daemon-set's task of enabling SCTP and startup of application that needs SCTP. Still better than nothing at all.
ansible-role-security
-
Can't access to my nas after I create some group
My playbook is only doing some software installation (openzfs, ...) and some SSH configuration (something really similar to jeff geerling : https://github.com/geerlingguy/ansible-role-security ), and it works perfectly without the tasks where I create groups and add user to these groups.
- Wie Rootserver sicher machen?
-
Selfhosting Security for Cloud Providers like Hetzner
I suggest these resources: - Some fundamentals: https://www.cyberciti.biz/tips/linux-security.html - One of the best imho ( exhaustive list ): https://github.com/imthenachoman/How-To-Secure-A-Linux-Server - Ansible playbook to harden security by Jeff Geerling: https://github.com/geerlingguy/ansible-role-security - OAWSP Check list ( targeted for web apps... and honestly a bit overkill ): https://github.com/0xRadi/OWASP-Web-Checklist
-
Good server setup tutorials
THAT all being said. Check out this: https://github.com/geerlingguy/ansible-role-security. YOu can see everything Jeff Does. My guy is a mad genious :).
-
My First 5 Minutes On A Server; Or, Essential Security for Linux Servers
Solid advice, most of it is now covered by GeerlingGuy's Security Ansible role (https://github.com/geerlingguy/ansible-role-security) and the Firewall one (https://github.com/geerlingguy/ansible-role-firewall).
-
Arma 3 Server tips?
yea, what jessel0l said (or vlan) plus you could use something like chroot or podman to separate privileges. Remember to set up fail2ban sane and easy starting point might be https://github.com/geerlingguy/ansible-role-security
- Secure your Cloud Server from Hackers with Fail2Ban
What are some alternatives?
CIS-Ubuntu-20.04-Ansible - Ansible Role to Automate CIS v1.1.0 Ubuntu Linux 18.04 LTS, 20.04 LTS Remediation
ansible-role-java - Ansible Role - Java
RHEL8-CIS - Ansible role for Red Hat 8 CIS Baseline
OS-Hardening - Hardening the Linux operating system for Debian like distributions.
hardening - Hardening Ubuntu. Systemd edition.
ansible-role-mysql - Ansible Role - MySQL
debops - DebOps - Your Debian-based data center in a box
ansible-role-nginx - Ansible Role - Nginx
debian - Reliably provision Debian hosts
anaconda - System installer for Fedora, RHEL and other distributions
ansible-role-docker-rootless - Ansible role to install a rootless Docker server
ubuntu_on_HPE_ProLiant_MS_GEN10 - Ubuntu Server on HPE ProLiant MicroServer Gen10 tutorial with extras.