From e9ddf8804cf61c627f586fe960f8c16ef53d56dc Mon Sep 17 00:00:00 2001 From: Radovan Sroka Date: Fri, 20 Dec 2024 16:13:00 +0100 Subject: [PATCH] Fix suggestions Signed-off-by: Radovan Sroka --- README.md | 5 +++-- defaults/main.yml | 2 +- examples/default.yml | 1 - tasks/main.yml | 8 ++++++-- tests/tests_check_cron.yml | 36 +++++++++++++++++++++++++++++++----- 5 files changed, 41 insertions(+), 11 deletions(-) diff --git a/README.md b/README.md index 91b6ec2..14876bb 100644 --- a/README.md +++ b/README.md @@ -87,9 +87,10 @@ Type: `bool` ### aide_cron_check -Set up periodic cron check for aide +If set to `true`, configures periodic cron check for aide +If set to `false`, removes the periodic cron check -Default: `false` +Default: `null` Type: `bool` diff --git a/defaults/main.yml b/defaults/main.yml index 69a0f79..d2e909d 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -22,7 +22,7 @@ aide_check: false aide_update: false # Enable periodic check -aide_cron_check: false +aide_cron_check: null # Example of job definition: # .---------------- minute (0 - 59) diff --git a/examples/default.yml b/examples/default.yml index 663b482..8bcc5b2 100644 --- a/examples/default.yml +++ b/examples/default.yml @@ -10,6 +10,5 @@ aide_fetch_db: false aide_check: false aide_update: false - aide_cron_check: false ansible.builtin.include_role: name: linux-system-roles.aide diff --git a/tasks/main.yml b/tasks/main.yml index b8eaa7c..58571c0 100644 --- a/tasks/main.yml +++ b/tasks/main.yml @@ -110,11 +110,15 @@ path: /etc/crontab regexp: "^.* root /usr/sbin/aide --check" line: "{{ aide_cron_interval }} root /usr/sbin/aide --check" - when: aide_cron_check | bool + when: + - aide_cron_check is not none + - aide_cron_check | bool - name: Remove aide check cron configuration if necessary ansible.builtin.lineinfile: path: /etc/crontab state: absent regexp: "^.* root /usr/sbin/aide --check" - when: not aide_cron_check | bool + when: + - aide_cron_check is not none + - not aide_cron_check | bool diff --git a/tests/tests_check_cron.yml b/tests/tests_check_cron.yml index 28dd9bf..26cedec 100644 --- a/tests/tests_check_cron.yml +++ b/tests/tests_check_cron.yml @@ -2,7 +2,7 @@ --- - name: Ensure that the cron is set up hosts: all - gather_facts: false # test that role works in this case + gather_facts: false roles: - role: linux-system-roles.aide vars: @@ -10,12 +10,38 @@ aide_cron_check: true aide_cron_interval: "0 12 * * *" tasks: + - name: Print crontab 1 + ansible.builtin.shell: cat /etc/crontab + - name: Check file content ansible.builtin.lineinfile: path: /etc/crontab - regexp: "^0 12 \\* \\* \\* root /usr/bin/aide --check" - state: absent - check_mode: true - changed_when: false + regexp: "^.* root /usr/sbin/aide --check" + line: "0 12 * * * root /usr/sbin/aide --check" + state: present + register: result + failed_when: result.changed + vars: + __fingerprint: system_role:aide + +- name: Ensure that the cron is not set up + hosts: all + gather_facts: false + roles: + - role: linux-system-roles.aide + vars: + aide_cron_check: false + tasks: + - name: Print crontab 2 + ansible.builtin.shell: cat /etc/crontab + + - name: Check file content + ansible.builtin.lineinfile: + path: /etc/crontab + regexp: "^.* root /usr/sbin/aide --check" + line: "0 12 * * * root /usr/sbin/aide --check" + state: present + register: result + failed_when: not result.changed vars: __fingerprint: system_role:aide