tidy up layout

Signed-off-by: Mark Bolwell <mark.bollyuk@gmail.com>
This commit is contained in:
Mark Bolwell 2024-12-04 08:03:33 +00:00
parent 9f829accd0
commit 6ed7c7e420
No known key found for this signature in database
GPG key ID: 997FF7FE93AEB5B9

View file

@ -1,8 +1,7 @@
--- ---
- name: "1.1.1.1 | PATCH | Ensure cramfs kernel module is not available" - name: "1.1.1.1 | PATCH | Ensure cramfs kernel module is not available"
when: when: rhel9cis_rule_1_1_1_1
- rhel9cis_rule_1_1_1_1
tags: tags:
- level1-server - level1-server
- level1-workstation - level1-workstation
@ -35,8 +34,7 @@
state: absent state: absent
- name: "1.1.1.2 | PATCH | Ensure freevxfs kernel module is not available" - name: "1.1.1.2 | PATCH | Ensure freevxfs kernel module is not available"
when: when: rhel9cis_rule_1_1_1_2
- rhel9cis_rule_1_1_1_2
tags: tags:
- level1-server - level1-server
- level1-workstation - level1-workstation
@ -62,15 +60,13 @@
mode: '0600' mode: '0600'
- name: "1.1.1.2 | PATCH | Ensure freevxfs kernel module is not available | Disable freevxfs" - name: "1.1.1.2 | PATCH | Ensure freevxfs kernel module is not available | Disable freevxfs"
when: when: not system_is_container
- not system_is_container
community.general.modprobe: community.general.modprobe:
name: freevxfs name: freevxfs
state: absent state: absent
- name: "1.1.1.3 | PATCH | Ensure hfs kernel module is not available" - name: "1.1.1.3 | PATCH | Ensure hfs kernel module is not available"
when: when: rhel9cis_rule_1_1_1_3
- rhel9cis_rule_1_1_1_3
tags: tags:
- level1-server - level1-server
- level1-workstation - level1-workstation
@ -96,15 +92,13 @@
mode: '0600' mode: '0600'
- name: "1.1.1.3 | PATCH | Ensure hfs kernel module is not available | Disable hfs" - name: "1.1.1.3 | PATCH | Ensure hfs kernel module is not available | Disable hfs"
when: when: not system_is_container
- not system_is_container
community.general.modprobe: community.general.modprobe:
name: hfs name: hfs
state: absent state: absent
- name: "1.1.1.4 | PATCH | Ensure hfsplus kernel module is not available" - name: "1.1.1.4 | PATCH | Ensure hfsplus kernel module is not available"
when: when: rhel9cis_rule_1_1_1_4
- rhel9cis_rule_1_1_1_4
tags: tags:
- level1-server - level1-server
- level1-workstation - level1-workstation
@ -130,15 +124,13 @@
mode: '0600' mode: '0600'
- name: "1.1.1.4 | PATCH | Ensure hfsplus kernel module is not available | Disable hfsplus" - name: "1.1.1.4 | PATCH | Ensure hfsplus kernel module is not available | Disable hfsplus"
when: when: not system_is_container
- not system_is_container
community.general.modprobe: community.general.modprobe:
name: hfsplus name: hfsplus
state: absent state: absent
- name: "1.1.1.5 | PATCH | Ensure jffs2 kernel module is not available" - name: "1.1.1.5 | PATCH | Ensure jffs2 kernel module is not available"
when: when: rhel9cis_rule_1_1_1_5
- rhel9cis_rule_1_1_1_5
tags: tags:
- level1-server - level1-server
- level1-workstation - level1-workstation
@ -164,15 +156,13 @@
mode: '0600' mode: '0600'
- name: "1.1.1.5 | PATCH | Ensure jffs2 kernel module is not available | Disable jffs2" - name: "1.1.1.5 | PATCH | Ensure jffs2 kernel module is not available | Disable jffs2"
when: when: not system_is_container
- not system_is_container
community.general.modprobe: community.general.modprobe:
name: jffs2 name: jffs2
state: absent state: absent
- name: "1.1.1.6 | PATCH | Ensure squashfs kernel module is not available" - name: "1.1.1.6 | PATCH | Ensure squashfs kernel module is not available"
when: when: rhel9cis_rule_1_1_1_6
- rhel9cis_rule_1_1_1_6
tags: tags:
- level2-server - level2-server
- level2-workstation - level2-workstation
@ -198,15 +188,13 @@
mode: '0600' mode: '0600'
- name: "1.1.1.6 | PATCH | Ensure squashfs kernel module is not available | Disable squashfs" - name: "1.1.1.6 | PATCH | Ensure squashfs kernel module is not available | Disable squashfs"
when: when: not system_is_container
- not system_is_container
community.general.modprobe: community.general.modprobe:
name: squashfs name: squashfs
state: absent state: absent
- name: "1.1.1.7 | PATCH | Ensure udf kernel module is not available" - name: "1.1.1.7 | PATCH | Ensure udf kernel module is not available"
when: when: rhel9cis_rule_1_1_1_7
- rhel9cis_rule_1_1_1_7
tags: tags:
- level2-server - level2-server
- level2-workstation - level2-workstation
@ -232,15 +220,13 @@
mode: '0600' mode: '0600'
- name: "1.1.1.7 | PATCH | Ensure udf kernel module is not available | Disable udf" - name: "1.1.1.7 | PATCH | Ensure udf kernel module is not available | Disable udf"
when: when: not system_is_container
- not system_is_container
community.general.modprobe: community.general.modprobe:
name: udf name: udf
state: absent state: absent
- name: "1.1.1.8 | PATCH | Ensure usb-storage kernel module is not available" - name: "1.1.1.8 | PATCH | Ensure usb-storage kernel module is not available"
when: when: rhel9cis_rule_1_1_1_8
- rhel9cis_rule_1_1_1_8
tags: tags:
- level1-server - level1-server
- level2-workstation - level2-workstation
@ -266,15 +252,13 @@
mode: '0600' mode: '0600'
- name: "1.1.1.8 | PATCH | Ensure usb-storage kernel module is not available | Disable usb" - name: "1.1.1.8 | PATCH | Ensure usb-storage kernel module is not available | Disable usb"
when: when: not system_is_container
- not system_is_container
community.general.modprobe: community.general.modprobe:
name: usb-storage name: usb-storage
state: absent state: absent
- name: "1.1.1.9 | PATCH | Ensure unused filesystems kernel modules are not available" - name: "1.1.1.9 | PATCH | Ensure unused filesystems kernel modules are not available"
when: when: rhel9cis_rule_1_1_1_9
- rhel9cis_rule_1_1_1_9
tags: tags:
- level1-server - level1-server
- level1-workstation - level1-workstation