forked from dev-sec/ansible-collection-hardening
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Add travis builds for official nginx role (dev-sec#21)
* test official nginx role with travis Signed-off-by: szEvEz <szivos.john@gmail.com> * split up test playbook for different distros due to required vars Signed-off-by: szEvEz <szivos.john@gmail.com> * make debian distros use the debian playbook Signed-off-by: szEvEz <szivos.john@gmail.com> * update README Signed-off-by: szEvEz <szivos.john@gmail.com>
- Loading branch information
Showing
4 changed files
with
115 additions
and
15 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,40 @@ | ||
--- | ||
- name: wrapper playbook for kitchen testing "ansible-nginx-hardening" with custom settings | ||
hosts: localhost | ||
vars: | ||
- nginx_main_template_enable: true | ||
- nginx_main_template: | ||
template_file: nginx.conf.j2 | ||
conf_file_name: nginx.conf | ||
conf_file_location: /etc/nginx/ | ||
user: www-data | ||
worker_processes: auto | ||
error_level: warn | ||
worker_connections: 1024 | ||
http_enable: true | ||
http_settings: | ||
keepalive_timeout: 65 | ||
cache: false | ||
rate_limit: false | ||
keyval: false | ||
stream_enable: false | ||
http_global_autoindex: false | ||
pre_tasks: | ||
- apt_repository: | ||
repo: "deb http://ftp.debian.org/debian jessie-backports main" | ||
state: present | ||
when: ansible_distribution == 'Debian' and ansible_distribution_major_version == '8' | ||
- set_fact: | ||
nginx_default_release: "jessie-backports" | ||
when: ansible_distribution == 'Debian' and ansible_distribution_major_version == '8' | ||
- package: name="{{item}}" state=installed | ||
with_items: | ||
- "systemd" | ||
ignore_errors: true | ||
- apt: name="{{item}}" state=installed update_cache=true | ||
with_items: | ||
- "systemd" | ||
ignore_errors: true | ||
roles: | ||
- nginxinc.nginx | ||
- ansible-nginx-hardening |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
--- | ||
- name: wrapper playbook for kitchen testing "ansible-nginx-hardening" with custom settings | ||
hosts: localhost | ||
pre_tasks: | ||
- package: name="{{item}}" state=installed | ||
with_items: | ||
- "systemd" | ||
ignore_errors: true | ||
- apt: name="{{item}}" state=installed update_cache=true | ||
with_items: | ||
- "systemd" | ||
ignore_errors: true | ||
roles: | ||
- nginxinc.nginx | ||
- ansible-nginx-hardening |