Skip to content

Commit 3daba1f

Browse files
authored
Merge pull request #797 from dev-sec/remdep
Remove unused files and variables
2 parents ba5d025 + 2b495bf commit 3daba1f

File tree

5 files changed

+4
-121
lines changed

5 files changed

+4
-121
lines changed

molecule/os_hardening/converge.yml

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,11 +16,10 @@
1616
vars:
1717
os_security_users_allow: change_user
1818
os_security_kernel_enable_core_dump: false
19-
os_auditd_num_logs: 10
19+
os_auditd_enabled: false
2020
os_security_suid_sgid_remove_from_unknown: true
2121
os_auth_pam_passwdqc_enable: false
2222
os_auth_lockout_time: 15
23-
os_desktop_enable: true
2423
os_env_extra_user_paths: [/home]
2524
os_auth_allow_homeless: true
2625
os_security_suid_sgid_blacklist: [/bin/umount]

molecule/os_hardening/verify.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -67,12 +67,14 @@
6767
http_proxy: "{{ lookup('env', 'http_proxy') | default(omit) }}"
6868
https_proxy: "{{ lookup('env', 'https_proxy') | default(omit) }}"
6969
no_proxy: "{{ lookup('env', 'no_proxy') | default(omit) }}"
70+
vars:
71+
os_auditd_enabled: false
72+
os_env_umask: "027 #override"
7073
tasks:
7174
# test if variable can be overridden
7275
- name: Workaround for https://github.com/ansible/ansible/issues/66304
7376
ansible.builtin.set_fact:
7477
ansible_virtualization_type: docker
75-
os_env_umask: "027 #override"
7678

7779
- name: Include os_hardening role
7880
ansible.builtin.include_role:

roles/os_hardening/defaults/main.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,4 @@
11
---
2-
os_desktop_enable: false
32
os_env_user_paths: [/usr/local/sbin, /usr/local/bin, /usr/sbin, /usr/bin, /sbin, /bin]
43
os_env_extra_user_paths: []
54
os_auth_pw_max_age: 60

roles/os_hardening/meta/argument_specs.yml

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -4,10 +4,6 @@ argument_specs:
44
short_description: The main entry point for the os hardening role.
55
version_added: 8.8.0
66
options:
7-
os_desktop_enable:
8-
default: false
9-
type: bool
10-
description: true if this is a desktop system, ie Xorg, KDE/GNOME/Unity/etc.
117
os_env_user_paths:
128
default: [/usr/local/sbin, /usr/local/bin, /usr/sbin, /usr/bin, /sbin, /bin]
139
type: list

roles/os_hardening/templates/etc/initramfs-tools/modules.j2

Lines changed: 0 additions & 113 deletions
This file was deleted.

0 commit comments

Comments
 (0)