Commit graph

11 commits

Author SHA1 Message Date
NaeiKinDus
888590ed9f
chore!: separated galaxy deps and own collections; modified ansible script generation to use two paths for collections
REQUIRES REGENERATING ansible.cfg!
2025-02-23 00:00:00 +00:00
NaeiKinDus
f0d464d988
chore(security): updated default ClamAV version to 1.4.1 2024-12-27 00:00:00 +00:00
NaeiKinDus
21185a17c4
feat(security): moved nftables reserved networks behind a feature flag and no longer block 0.0.0.0/8 and 169.254.0.0/16 by default to ease DHCP and APIPA configuration 2024-12-27 00:00:00 +00:00
NaeiKinDus
3701ea6276
fix(security,common)!: moved sysctl and resolvconf tasks from common to security role to fix DNS resolution fail due to firewall rules 2024-08-08 00:00:00 +00:00
NaeiKinDus
e52f87a448
feat(security): update / install clamav only if desired version and installed version differs 2024-07-11 00:00:00 +00:00
NaeiKinDus
779f2766f2
refactor!: switch hosts variables to a flat layout 2024-01-21 00:00:00 +00:00
NaeiKinDus
da45c7c409
refactor(security): reworked firewall configuration and added support for DNS, HTTP and ICMP rules; added autoconf for resolv.conf to match FW rules 2024-01-06 00:00:00 +00:00
NaeiKinDus
639b01c351
feat(security): added nftables firewall 2023-12-12 00:00:00 +00:00
NaeiKinDus
a577af133d
feat(security): update apt source lists to use https instead of http 2023-11-29 00:00:00 +00:00
NaeiKinDus
dafa3fbc54
fix!: fixed molecule tests, rewrote how custom variables are handled for hosts overrides; fixed invalid services names for clamav handlers 2023-11-29 00:00:00 +00:00
NaeiKinDus
e4770a7343
feat: base configuration automation 2023-11-08 00:00:00 +00:00