Skip to content

Commit 29fd2d7

Browse files
author
Maciej Drozdzowski
authored
Merge pull request #17 from QLPD/mounts-partitions
Improvements around partitions & mount
2 parents d8faf4d + 8427f64 commit 29fd2d7

File tree

5 files changed

+15
-12
lines changed

5 files changed

+15
-12
lines changed

defaults/main.yml

+10-6
Original file line numberDiff line numberDiff line change
@@ -36,18 +36,22 @@ cis_sshd_config_filename: "/etc/ssh/sshd_config"
3636
# Check specific values which can be overridden
3737
###############################################
3838
# Section 1
39-
cis_partition_dev_val_log: "/dev/xvda2"
40-
cis_partition_mnt_val_log: "/var/log"
41-
cis_partition_fs_val_log: "ext4"
39+
cis_partition_dev_var_log: "/dev/xvda2"
40+
cis_partition_mnt_var_log: "/var/log"
41+
cis_partition_fs_var_log: "ext4"
4242

43-
cis_partition_dev_val_log_audit: "/dev/xvda3"
44-
cis_partition_mnt_val_log_audit: "/var/log/audit"
45-
cis_partition_fs_val_log_audit: "ext4"
43+
cis_partition_dev_var_log_audit: "/dev/xvda3"
44+
cis_partition_mnt_var_log_audit: "/var/log/audit"
45+
cis_partition_fs_var_log_audit: "ext4"
4646

4747
cis_partition_dev_home: "/dev/xvda4"
4848
cis_partition_mnt_home: "/home"
4949
cis_partition_fs_home: "ext4"
5050

51+
cis_partition_dev_var: "/dev/xvda5"
52+
cis_partition_mnt_var: "/var"
53+
cis_partition_fs_var: "ext4"
54+
5155
cis_aide_database_filename: "/var/lib/aide/aide.db.gz"
5256
cis_aide_src_database_filename: "/var/lib/aide/aide.db.new.gz"
5357

tasks/level-1/1.1.11.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@
1010
fstype: "{{item.fstype}}"
1111
src: "{{item.device}}"
1212
with_items:
13-
- { mountpoint: "{{cis_partition_mnt_val_log}}", device: "{{cis_partition_dev_val_log}}", fstype: "{{cis_partition_fs_val_log}}" }
13+
- { mountpoint: "{{cis_partition_mnt_var_log}}", device: "{{cis_partition_dev_var_log}}", fstype: "{{cis_partition_fs_var_log}}" }
1414
tags:
1515
- level-1
1616
- section-1

tasks/level-1/1.1.12.yml

+1-1
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,7 @@
1010
fstype: "{{item.fstype}}"
1111
src: "{{item.device}}"
1212
with_items:
13-
- { mountpoint: "{{cis_partition_mnt_val_log_audit}}", device: "{{cis_partition_dev_val_log_audit}}", fstype: "{{cis_partition_fs_val_log_audit}}" }
13+
- { mountpoint: "{{cis_partition_mnt_var_log_audit}}", device: "{{cis_partition_dev_var_log_audit}}", fstype: "{{cis_partition_fs_var_log_audit}}" }
1414
tags:
1515
- level-1
1616
- section-1

tasks/level-1/1.1.13.yml

+2-2
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,9 @@
11
# Standards: 0.11
22
---
33

4-
# 1.1.12 Ensure separate partition exists for /home (Scored)
4+
# 1.1.13 Ensure separate partition exists for /home (Scored)
55

6-
- name: 1.1.12 Ensure separate partition exists for /home (Scored)
6+
- name: 1.1.13 Ensure separate partition exists for /home (Scored)
77
mount:
88
name: "{{ item.mountpoint }}"
99
state: present

tasks/level-1/1.1.6.yml

+1-2
Original file line numberDiff line numberDiff line change
@@ -9,9 +9,8 @@
99
state: present
1010
fstype: "{{item.fstype}}"
1111
src: "{{item.device}}"
12-
opts: "{{item.opts}}"
1312
with_items:
14-
- "{{ fs_mounts | selectattr('mountpoint', 'equalto', '/var') | list }}"
13+
- { mountpoint: "{{cis_partition_mnt_var}}", device: "{{cis_partition_dev_var}}", fstype: "{{cis_partition_fs_var}}" }
1514
tags:
1615
- level-1
1716
- section-1

0 commit comments

Comments
 (0)