File: ansible.template

package info (click to toggle)
scap-security-guide 0.1.78-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 114,600 kB
  • sloc: xml: 245,305; sh: 84,381; python: 33,093; makefile: 27
file content (19 lines) | stat: -rw-r--r-- 890 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
# platform = multi_platform_rhel,multi_platform_fedora,multi_platform_ol,multi_platform_almalinux,multi_platform_rhv,multi_platform_ubuntu,multi_platform_sle,multi_platform_slmicro
# reboot = true
# strategy = disable
# complexity = low
# disruption = medium
- name: Ensure kernel module '{{{ KERNMODULE }}}' is disabled
  ansible.builtin.lineinfile:
    create: yes
    dest: "/etc/modprobe.d/{{{ KERNMODULE }}}.conf"
    regexp: 'install\s+{{{ KERNMODULE }}}'
    line: "install {{{ KERNMODULE }}} /bin/false"
{{% if 'ol' in product or 'rhel' in product or 'sle' in product or 'slmicro' in product or 'ubuntu' in product %}}
- name: Ensure kernel module '{{{ KERNMODULE }}}' is blacklisted
  ansible.builtin.lineinfile:
    create: yes
    dest: "/etc/modprobe.d/{{{ KERNMODULE }}}.conf"
    regexp: '^blacklist {{{ KERNMODULE }}}$'
    line: "blacklist {{{ KERNMODULE }}}"
{{% endif %}}