Baseline playbook to update and install all the packages needed for a server
- Ansible 2.18.0 or superior.
- This playbook now depends on the
community.generalcollection. You can install it using:More information can be found here.ansible-galaxy collection install -r requirements.yml
Baseline is already in Ansible Galaxy, so the only thing you need is to install this script in your machine is just use ansible-galaxy command:
ansible-galaxy install lucascbeyeler.baseline
When a new version of ansible-commons is released, you will need to run the install process again, but with the "-f" or "--force" parameter.
ansible-galaxy install -f lucascbeyeler.baseline
- Update the system and install some basic packages (like vim, unzip, and ca-certificates), plus EPEL on RedHat;
- Configure chrony as the NTP client and change the timezone to what you want;
- Change the hostname and update the /etc/hosts to include 127.0.1.1 to answer when the hostname is resolved;
- Enable the NTP service to start during the boot (SystemD);
- Including hushlogin in /etc/skel (new users) and root's home to hide the MOTD;
- Change the SSH default port (also allowed in SELinux when it is enabled);
- Disable Root login throught SSH.
Every change to /etc/ssh/sshd_config is validated with sshd -t before it is written, and sshd is reloaded afterwards.
Warning: when changing
ssh_port, make sure the new port is open in your firewall (firewalld, ufw, security groups) and updateansible_portfor the next runs, otherwise you will lose SSH access.
This playbook has been tested against:
- Rocky Linux 9
- Ubuntu Jammy Jellyfish
- hostname: set the hostname of your server WITHOUT the domain;
- domain: set the domain for the server and the primary domain for your server;
- timezone: inform the timezone the playbook should set in your server;
- enable_hushlogin: set to
trueto enable hush login (defaultfalse); - ssh_port: define the default port for OpenSSH Server (unset keeps the current port);
- baseline_ssh_permit_root_login: value for
PermitRootLogin(defaultno); - baseline_full_upgrade: upgrade all the packages on every run (default
true); - baseline_install_epel: install EPEL on RedHat systems (default
true); - baseline_ntp_servers: list of NTP servers used by chrony (default
pool.ntp.org); - multidist: packages installed on every distribution;
- debian / centos: extra packages installed only on Debian/Ubuntu or CentOS/RedHat;
Including an example of how to use your role (for instance, with variables passed in as parameters) is always nice for users too:
- hosts: all
become: yes
become_method: sudo
roles:
- role: lucascbeyeler.baseline
hostname: pikachu
domain: johto.com
timezone: America/Sao_Paulo
enable_hushlogin: true
ssh_port: 8080
View official GNU site http://www.gnu.org/licenses/gpl.html.
