Files
ansible-role-aide/tasks/main.yml
T
Rich MegginsonandRichard Megginson 129feb1ac1 test: add cleanup for cron test; fix formatting
Ensure cron test restores state of crontab after test.
Fix formatting in a few places.
Do not check ansible managed header and fingerprint unless the test
uses a custom template with header and fingerprint.
Use default for gather_facts unless otherwise needed.

Signed-off-by: Rich Megginson <rmeggins@redhat.com>
2025-01-07 11:31:56 -07:00

127 lines
3.5 KiB
YAML

# SPDX-License-Identifier: MIT
---
- name: Set platform/version specific variables
include_tasks: tasks/set_vars.yml
# Examples of some tasks:
- name: Ensure required packages are installed
ansible.builtin.package:
name: "{{ __aide_packages }}"
state: present
use: "{{ (__aide_is_ostree | d(false)) |
ternary('ansible.posix.rhel_rpm_ostree', omit) }}"
- name: Ensure required services are enabled and started
ansible.builtin.service:
name: "{{ item }}"
state: started
enabled: true
loop: "{{ __aide_services }}"
- name: Generate "/etc/{{ __aide_config }}"
ansible.builtin.template:
src: "{{ aide_db_template }}"
dest: "/etc/{{ __aide_config }}"
mode: "0400"
when: aide_db_template is not none
# - name: Print Header
# ansible.builtin.command: head /etc/aide.conf || true
- name: Initialize AIDE database
when: aide_init | bool
block:
- name: Initialize AIDE database
ansible.builtin.command:
cmd: aide --init
changed_when: true
- name: Copy AIDE reference database
ansible.builtin.copy:
remote_src: true
src: "{{ __aide_db_new_name }}"
dest: "{{ __aide_db_name }}"
owner: root
group: root
mode: "0440"
force: true
when: not aide_fetch_db | bool
- name: Remove remote AIDE database file
ansible.builtin.file:
path: "{{ __aide_db_new_name }}"
state: absent
when: not aide_fetch_db | bool
- name: Fetch AIDE database
when: aide_fetch_db | bool
block:
- name: Fetch AIDE database
ansible.builtin.fetch:
src: "{{ __aide_db_new_name }}"
dest: "{{ aide_db_fetch_dir }}"
- name: Remove remote AIDE database file
ansible.builtin.file:
path: "{{ __aide_db_new_name }}"
state: absent
- name: Check AIDE integrity
when: aide_check | bool
block:
- name: Copy AIDE reference database
ansible.builtin.copy:
src: >-
{{ aide_db_fetch_dir }}/{{ inventory_hostname }}{{ __aide_db_new_name }}
dest: "{{ __aide_db_name }}"
owner: root
group: root
mode: "0440"
when: aide_fetch_db | bool
- name: Check against AIDE reference database
ansible.builtin.command:
cmd: aide --check
changed_when: true
- name: Update AIDE database and fetch it
when: aide_update | bool
block:
- name: Update AIDE database
ansible.builtin.command:
cmd: aide --update
register: __aide_update_result
failed_when: __msg not in __aide_update_result.stdout
changed_when: true
vars:
__msg: >-
AIDE found NO differences between database and filesystem. Looks okay!!
- name: Fetch AIDE database
ansible.builtin.fetch:
src: "{{ __aide_db_new_name }}"
dest: "{{ aide_db_fetch_dir }}"
- name: Remove remote AIDE database file
ansible.builtin.file:
path: "{{ __aide_db_new_name }}"
state: absent
- name: Update aide check cron configuration if necessary
ansible.builtin.lineinfile:
path: /etc/crontab
regexp: "^.* root /usr/sbin/aide --check"
line: "{{ aide_cron_interval }} root /usr/sbin/aide --check"
when:
- aide_cron_check is not none
- aide_cron_check | bool
- name: Remove aide check cron configuration if necessary
ansible.builtin.lineinfile:
path: /etc/crontab
state: absent
regexp: "^.* root /usr/sbin/aide --check"
when:
- aide_cron_check is not none
- not aide_cron_check | bool