--- # Point d'entrée : configure et durcit l'ensemble des serveurs Linux. # # ansible-playbook site.yml # tout # ansible-playbook site.yml --tags ssh # un seul rôle # ansible-playbook site.yml --check --diff # simulation # # Ordre volontaire : le proxy et le DNS d'abord (sinon aucun paquet ne peut # être téléchargé), le SSH avant le pare-feu (la règle SSH doit exister # avant que la politique par défaut passe à « drop »). - name: Configuration et durcissement des serveurs Linux hosts: all become: true gather_facts: true roles: - role: common tags: [common, always] - role: proxy when: enable_proxy | bool tags: [proxy] - role: dns when: enable_dns | bool tags: [dns] - role: updates when: enable_updates | bool tags: [updates] - role: ssh when: enable_ssh | bool tags: [ssh] - role: firewall when: enable_firewall | bool tags: [firewall] - role: fail2ban when: enable_fail2ban | bool tags: [fail2ban] - role: os_hardening when: enable_os_hardening | bool tags: [os_hardening, hardening] - role: snmp when: enable_snmp | bool tags: [snmp, supervision] - role: nrpe when: enable_nrpe | bool tags: [nrpe, supervision] - role: glpi_agent when: enable_glpi_agent | bool tags: [glpi, glpi_agent] post_tasks: - name: Résumé de fin de passage ansible.builtin.debug: msg: - "Hôte : {{ inventory_hostname }} ({{ ansible_facts['distribution'] }} {{ ansible_facts['distribution_version'] }})" - "SSH : port {{ ssh_port }}, root={{ ssh_permit_root_login }}" - "Pare-feu : {{ firewall_backend_effective | default('non géré') }}" - "Redémarrage : {{ 'REQUIS' if (updates_reboot_required | default(false)) else 'non requis' }}" tags: [always]