Fix in logic for Alma (#4)

* container standards

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* logic on handlers

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* initial container ignore

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* tags and containder discovery

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* logic on auditd task

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* tags and crypto logic

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* distro update for rocky

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* system_is_container updates

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* ssh pkg check

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* logrotate pkg check

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* logic in container check

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* add pkg fact and audit conditionals

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* tidy up crypto step

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Added missing tags

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* container vars file now a variable

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* added uid discovery and usage

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Updated OS checks and conditionals

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* fixed empty become

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* change audit to include task

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* Added OS_specific vars

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated import/include

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* OS Specific vars

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated tags

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* updated changed_when

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* fixed UID logic

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* changed reboot var

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* changed skip_reboot var name

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* masked only

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* fix logic

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* remove debug update logic 6.2.8

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* initial

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>

* removed CentOS

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
This commit is contained in:
uk-bolly 2022-02-02 11:25:03 +00:00 committed by GitHub
parent 876ac290d5
commit 02a36f7f8d
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
27 changed files with 392 additions and 113 deletions

95
vars/is_container.yml Normal file
View file

@ -0,0 +1,95 @@
---
# File to skip controls if container
# Based on standard image no changes
# it expected all pkgs required for the container are alreday installed
## controls
# Authconfig
rhel9cis_use_authconfig: false
# Firewall
rhel9cis_firewall: None
# SElinux
rhel9cis_selinux_disable: true
## Related individual rules
# Aide
rhel9cis_rule_1_4_1: false
rhel9cis_rule_1_4_2: false
# auditd
rhel9cis_rule_4_1_1_1: false
rhel9cis_rule_4_1_2_1: false
rhel9cis_rule_4_1_2_2: false
rhel9cis_rule_4_1_2_3: false
# time sync
rhel9cis_rule_2_2_1_1: false
rhel9cis_rule_2_2_1_2: false
# cron
rhel9cis_rule_5_1_1: false
rhel9cis_rule_5_1_2: false
rhel9cis_rule_5_1_3: false
rhel9cis_rule_5_1_4: false
rhel9cis_rule_5_1_5: false
rhel9cis_rule_5_1_6: false
rhel9cis_rule_5_1_7: false
rhel9cis_rule_5_1_8: false
# crypto
rhel9cis_rule_1_10: false
rhel9cis_rule_1_11: false
# grub
rhel9cis_rule_1_5_1: false
rhel9cis_rule_1_5_2: false
rhel9cis_rule_1_5_3: false
## mounts
# /tmp
rhel9cis_rule_1_1_2: false
rhel9cis_rule_1_1_3: false
rhel9cis_rule_1_1_4: false
rhel9cis_rule_1_1_5: false
#/var
rhel9cis_rule_1_1_6: false
# /var/tmp
rhel9cis_rule_1_1_7: false
rhel9cis_rule_1_1_8: false
rhel9cis_rule_1_1_9: false
rhel9cis_rule_1_1_10: false
# /var/log
rhel9cis_rule_1_1_11: false
# /var/log/audit
rhel9cis_rule_1_1_12: false
# /home
rhel9cis_rule_1_1_13: false
rhel9cis_rule_1_1_14: false
# /dev/shm
rhel9cis_rule_1_1_15: false
rhel9cis_rule_1_1_16: false
rhel9cis_rule_1_1_17: false
# usb-storage
rhel9cis_rule_1_1_23: false
# logging
rhel9cis_rule_4_2_1_1: false
rhel9cis_rule_4_2_1_2: false
rhel9cis_rule_4_2_1_3: false
rhel9cis_rule_4_2_1_4: false
rhel9cis_rule_4_2_1_5: false
rhel9cis_rule_4_2_1_6: false
rhel9cis_rule_4_2_2_1: false
rhel9cis_rule_4_2_2_2: false
rhel9cis_rule_4_2_2_3: false
# systemd
rhel9cis_rule_1_6_1: false
# Users/passwords/accounts
rhel9cis_rule_5_5_2: false