Use true instead of yes.
This commit is contained in:
@@ -15,7 +15,7 @@
|
||||
name:
|
||||
- doas
|
||||
register: doas_install
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
|
||||
- name: General | Software | DoAs | Configure [Linux]
|
||||
blockinfile:
|
||||
@@ -24,8 +24,8 @@
|
||||
{{ doas_config }}
|
||||
marker: '# {mark} MANAGED BY ANSIBLE | doas Linux'
|
||||
state: present
|
||||
create: yes
|
||||
backup: yes
|
||||
create: true
|
||||
backup: true
|
||||
when: not doas_install.failed and ansible_system in ("Linux")
|
||||
|
||||
- name: General | Software | DoAs | Configure [BSD]
|
||||
@@ -35,8 +35,8 @@
|
||||
{{ doas_config }}
|
||||
marker: '# {mark} MANAGED BY ANSIBLE | doas BSD'
|
||||
state: present
|
||||
create: yes
|
||||
backup: yes
|
||||
create: true
|
||||
backup: true
|
||||
when: not doas_install.failed and ansible_system in ("FreeBSD")
|
||||
|
||||
- name: General | Software | DoAs | Configure [Other]
|
||||
@@ -46,9 +46,9 @@
|
||||
{{ doas_config }}
|
||||
marker: '# {mark} MANAGED BY ANSIBLE | doas Other'
|
||||
state: present
|
||||
create: yes
|
||||
backup: yes
|
||||
create: true
|
||||
backup: true
|
||||
loop:
|
||||
- "{{ doas_conf_file_linux }}"
|
||||
- "{{ doas_conf_file_bsd }}"
|
||||
when: not doas_install.failed and ansible_system not in ("Linux", "FreeBSD")
|
||||
when: not doas_install.failed and ansible_system not in ("Linux", "FreeBSD")
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
---
|
||||
# Groups that do not come to all distros by default.
|
||||
|
||||
- name: General | Account Management | System Groups
|
||||
- name: General | Account Management | System Groups
|
||||
group:
|
||||
name: "{{ item }}"
|
||||
system: yes
|
||||
system: true
|
||||
state: present
|
||||
loop:
|
||||
- sudo
|
||||
|
||||
@@ -146,8 +146,8 @@
|
||||
[global]
|
||||
marker: '; {mark} MANAGED BY ANSIBLE | Generic Config'
|
||||
state: present
|
||||
create: yes
|
||||
backup: yes
|
||||
create: true
|
||||
backup: true
|
||||
|
||||
- name: General | Account Management | Provisioning Configuration | General | Load
|
||||
set_fact:
|
||||
@@ -246,8 +246,8 @@
|
||||
[global]
|
||||
marker: '; {mark} MANAGED BY ANSIBLE | Workstation Config'
|
||||
state: present
|
||||
create: yes
|
||||
backup: yes
|
||||
create: true
|
||||
backup: true
|
||||
|
||||
- name: General | Account Management | Provisioning Configuration | Workstation | Load
|
||||
set_fact:
|
||||
@@ -327,8 +327,8 @@
|
||||
# [global]
|
||||
# marker: '; {mark} MANAGED BY ANSIBLE | Miner Config'
|
||||
# state: present
|
||||
# create: yes
|
||||
# backup: yes
|
||||
# create: true
|
||||
# backup: true
|
||||
#
|
||||
#- name: General | Account Management | Provisioning Configuration | Miner | Load
|
||||
# set_fact:
|
||||
@@ -396,8 +396,8 @@
|
||||
[global]
|
||||
marker: '; {mark} MANAGED BY ANSIBLE | Server Config'
|
||||
state: present
|
||||
create: yes
|
||||
backup: yes
|
||||
create: true
|
||||
backup: true
|
||||
|
||||
- name: General | Account Management | Provisioning Configuration | Server | Load
|
||||
set_fact:
|
||||
|
||||
@@ -26,8 +26,8 @@
|
||||
regexp: '{{ item.key }}'
|
||||
line: '{{ item.value }} # MANAGED BY ANSIBLE'
|
||||
state: present
|
||||
create: yes
|
||||
backup: yes
|
||||
create: true
|
||||
backup: true
|
||||
loop:
|
||||
- { "key": '^[\#]?Defaults targetpw', "value": '#Defaults targetpw'}
|
||||
- { "key": '^[\#]?ALL ALL\=\(ALL\) ALL', "value": '#ALL ALL=(ALL) ALL'}
|
||||
|
||||
@@ -13,7 +13,7 @@
|
||||
regexp: "{{ bash_exec.stdout }}"
|
||||
line: "{{ bash_exec.stdout }}"
|
||||
insertbefore: "# End of file"
|
||||
backup: yes
|
||||
backup: true
|
||||
create: no
|
||||
state: present
|
||||
when: ansible_pkg_mgr == "pacman"
|
||||
@@ -29,7 +29,7 @@
|
||||
# regexp: "{{ zsh_exec.stdout }}"
|
||||
# line: "{{ zsh_exec.stdout }}"
|
||||
# insertbefore: "# End of file"
|
||||
# backup: yes
|
||||
# backup: true
|
||||
# create: no
|
||||
# state: present
|
||||
# when: ansible_pkg_mgr == "pacman"
|
||||
@@ -41,8 +41,8 @@
|
||||
user:
|
||||
name: root
|
||||
shell: "{{ bash_exec.stdout }}"
|
||||
create_home: yes
|
||||
generate_ssh_key: yes
|
||||
create_home: true
|
||||
generate_ssh_key: true
|
||||
register: user_root
|
||||
|
||||
|
||||
@@ -52,7 +52,7 @@
|
||||
user:
|
||||
name: ansible
|
||||
comment: Ansible
|
||||
system: yes
|
||||
system: true
|
||||
register: user_ansible
|
||||
|
||||
|
||||
@@ -67,10 +67,10 @@
|
||||
- video
|
||||
- render
|
||||
- wheel
|
||||
append: yes
|
||||
append: true
|
||||
shell: "{{ user_shell }}"
|
||||
create_home: yes
|
||||
generate_ssh_key: yes
|
||||
create_home: true
|
||||
generate_ssh_key: true
|
||||
register: user_user
|
||||
|
||||
- name: General | Account Management | Users | User | Test Logging In
|
||||
@@ -1324,7 +1324,7 @@
|
||||
echo "`date` - Ansible .profile loaded successfully!"
|
||||
marker: '# {mark} MANAGED BY ANSIBLE | Aliases'
|
||||
state: present
|
||||
create: yes
|
||||
create: true
|
||||
backup: no
|
||||
loop:
|
||||
- ".profile"
|
||||
@@ -1345,7 +1345,7 @@
|
||||
echo "`date` - Ansible .bashrc loaded successfully!"
|
||||
marker: '# {mark} MANAGED BY ANSIBLE | Aliases'
|
||||
state: present
|
||||
create: yes
|
||||
create: true
|
||||
backup: no
|
||||
loop:
|
||||
- "{{ user_root.home }}"
|
||||
@@ -1361,7 +1361,7 @@
|
||||
echo "`date` - Ansible .zshrc loaded successfully!"
|
||||
marker: '# {mark} MANAGED BY ANSIBLE | Aliases'
|
||||
state: present
|
||||
create: yes
|
||||
create: true
|
||||
backup: no
|
||||
loop:
|
||||
- "{{ user_root.home }}"
|
||||
@@ -1383,7 +1383,7 @@
|
||||
|
||||
- name: General | Account Management | Users | Files | Helper Functions (Reset)
|
||||
shell: "rm -v {{ global_bin }}/*.function"
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
|
||||
- name: General | Account Management | Users | Files | Helper Functions
|
||||
copy:
|
||||
@@ -1406,7 +1406,7 @@
|
||||
clone: true
|
||||
force: true
|
||||
update: true
|
||||
#ignore_errors: yes
|
||||
#ignore_errors: true
|
||||
|
||||
- name: General | Account Management | Users | env-shared | Install | .rc_shared
|
||||
copy:
|
||||
@@ -1418,7 +1418,7 @@
|
||||
loop:
|
||||
- "{{ user_root.home }}"
|
||||
- "{{ user_user.home }}"
|
||||
#ignore_errors: yes
|
||||
#ignore_errors: true
|
||||
when: user_root.home != "" and user_user.home != ""
|
||||
|
||||
- name: General | Account Management | Users | env-shared | Install | .vimrc
|
||||
@@ -1431,7 +1431,7 @@
|
||||
loop:
|
||||
- "{{ user_root.home }}"
|
||||
- "{{ user_user.home }}"
|
||||
#ignore_errors: yes
|
||||
#ignore_errors: true
|
||||
when: user_root.home != "" and user_user.home != ""
|
||||
|
||||
- name: General | Account Management | Users | env-shared | Permissions
|
||||
@@ -1443,4 +1443,4 @@
|
||||
loop:
|
||||
- .rc_shared
|
||||
- .vimrc
|
||||
#ignore_errors: yes
|
||||
#ignore_errors: true
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
marker_begin: "#!{{ bash_exec.stdout }}"
|
||||
marker_end: "exit 0"
|
||||
state: present
|
||||
create: yes
|
||||
create: true
|
||||
|
||||
- name: General | Scripts | Root | scm.sh Permissions
|
||||
file:
|
||||
@@ -41,7 +41,7 @@
|
||||
marker_begin: "#!{{ bash_exec.stdout }}"
|
||||
marker_end: "exit 0"
|
||||
state: present
|
||||
create: yes
|
||||
create: true
|
||||
|
||||
- name: General | Scripts | Root | scm-dev.sh Permissions
|
||||
file:
|
||||
|
||||
@@ -11,7 +11,7 @@
|
||||
marker_begin: "#!{{ bash_exec.stdout }}"
|
||||
marker_end: "exit 0"
|
||||
state: present
|
||||
create: yes
|
||||
create: true
|
||||
|
||||
- name: General | Scripts | User | scm.sh Permissions
|
||||
file:
|
||||
@@ -41,7 +41,7 @@
|
||||
marker_begin: "#!{{ bash_exec.stdout }}"
|
||||
marker_end: "exit 0"
|
||||
state: present
|
||||
create: yes
|
||||
create: true
|
||||
|
||||
- name: General | Scripts | User | scm-dev.sh Permissions
|
||||
file:
|
||||
|
||||
@@ -8,8 +8,8 @@
|
||||
regexp: '{{ item.key }}'
|
||||
line: '{{ item.value }}'
|
||||
state: present
|
||||
create: yes
|
||||
backup: yes
|
||||
create: true
|
||||
backup: true
|
||||
loop:
|
||||
#- { "key": '^[\#]?XKBMODEL', "value": 'XKBMODEL="pc105"'}
|
||||
- { "key": '^[\#]?XKBLAYOUT', "value": 'XKBLAYOUT="us"'}
|
||||
|
||||
@@ -29,8 +29,8 @@
|
||||
{{ nixos_swap }}
|
||||
}
|
||||
state: present
|
||||
backup: yes
|
||||
create: yes
|
||||
backup: true
|
||||
create: true
|
||||
|
||||
|
||||
# Maybe do home manager here? Or should it be under Workstation? Or maybe
|
||||
|
||||
@@ -7,7 +7,7 @@
|
||||
# so resetting the value to apt doesn't work. Just going to move it.
|
||||
shell: "mv `which zypper` `which zypper`.zz.`date +%Y%m%d`"
|
||||
register: parrotos_zypper_removed
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
when: ansible_distribution == "Parrot OS"
|
||||
|
||||
- name: General | Software | Packages | Fix Parrot OS (zypper), Exit Incoming
|
||||
@@ -23,13 +23,13 @@
|
||||
# have sudo or anything in it. Hide it in preference for .bashrc update function.
|
||||
- name: General | Software | Packages | Fix Parrot OS 2 (update)
|
||||
shell: "mv `which update` `which update`.zz.`date +%Y%m%d`"
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
when: ansible_distribution == "Parrot OS"
|
||||
|
||||
|
||||
- name: General | Software | Packages | Cache Refresh (Apt and Pacman)
|
||||
package:
|
||||
update_cache: yes
|
||||
update_cache: true
|
||||
name: htop
|
||||
when: ansible_pkg_mgr in ["apt", "pacman"]
|
||||
|
||||
@@ -77,7 +77,7 @@
|
||||
- "{{ microcode_intel }}"
|
||||
state: present
|
||||
when: branch == "dev"
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
|
||||
- name: General | Software | Packages | Add Generic Kernel + Tools (Ubuntu)
|
||||
package:
|
||||
@@ -88,7 +88,7 @@
|
||||
- linux-tools-common
|
||||
state: present
|
||||
when: ansible_distribution == "Ubuntu"
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
|
||||
- name: General | Software | Packages | Add Generic Kernel + Headers (Debian)
|
||||
package:
|
||||
@@ -97,7 +97,7 @@
|
||||
- linux-headers-amd64
|
||||
state: present
|
||||
when: ansible_distribution == "Debian"
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
|
||||
- name: General | Software | Packages | Install killall (Looking at you, Debian)
|
||||
package:
|
||||
@@ -150,7 +150,7 @@
|
||||
state: stopped
|
||||
enabled: no
|
||||
when: ansible_distribution != "Ubuntu"
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
|
||||
- name: General | Software | Packages | Remove Snap (Besides Ubuntu)
|
||||
package:
|
||||
@@ -158,7 +158,7 @@
|
||||
- snapd
|
||||
state: absent
|
||||
when: ansible_distribution != "Ubuntu"
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
|
||||
- name: General | Software | Packages | Other Debian Packages
|
||||
package:
|
||||
@@ -166,4 +166,4 @@
|
||||
- usbutils
|
||||
state: present
|
||||
when: ansible_distribution in ("Debian")
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
|
||||
@@ -10,11 +10,11 @@
|
||||
- name: Server | Sendmail | Check
|
||||
shell: which postfix
|
||||
register: postfix
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
|
||||
- name: Server | Sendmail | Install
|
||||
package:
|
||||
name:
|
||||
name:
|
||||
- "{{ sendmail }}"
|
||||
state: present
|
||||
when: postfix.failed
|
||||
@@ -27,8 +27,8 @@
|
||||
sendmail_msp_queue_enable="YES"
|
||||
marker: "# {mark} MANAGED BY ANSIBLE - sendmail"
|
||||
state: present
|
||||
create: yes
|
||||
backup: yes
|
||||
create: true
|
||||
backup: true
|
||||
when: postfix.failed and ansible_system == "FreeBSD"
|
||||
|
||||
- name: Server | Sendmail | Enable + Start | Main
|
||||
@@ -36,7 +36,7 @@
|
||||
name: "{{ sendmail }}"
|
||||
pattern: "{{ sendmail }}"
|
||||
state: started
|
||||
enabled: yes
|
||||
enabled: true
|
||||
when: postfix.failed
|
||||
|
||||
- name: Server | Sendmail | Enable + Start | Queue
|
||||
@@ -44,5 +44,5 @@
|
||||
name: "{{ sendmail_queue }}"
|
||||
pattern: "{{ sendmail_queue }}"
|
||||
state: started
|
||||
enabled: yes
|
||||
enabled: true
|
||||
when: postfix.failed and ansible_system == "FreeBSD"
|
||||
|
||||
@@ -8,7 +8,7 @@
|
||||
name: "{{ crond }}"
|
||||
pattern: "{{ crond_pattern }}"
|
||||
state: started
|
||||
enabled: yes
|
||||
enabled: true
|
||||
when: ansible_virtualization_type != 'docker'
|
||||
and ansible_service_mgr != "runit"
|
||||
register: cron_status
|
||||
@@ -20,7 +20,7 @@
|
||||
service:
|
||||
name: "{{ crond }}"
|
||||
state: started
|
||||
enabled: yes
|
||||
enabled: true
|
||||
when: ansible_virtualization_type != 'docker'
|
||||
and ansible_service_mgr == "runit"
|
||||
ignore_errors: true # Service module seems experimental for this init system.
|
||||
@@ -33,8 +33,8 @@
|
||||
regexp: '{{ item.key }}'
|
||||
line: '{{ item.value }} # MANAGED BY ANSIBLE'
|
||||
state: present
|
||||
create: yes
|
||||
backup: yes
|
||||
create: true
|
||||
backup: true
|
||||
loop:
|
||||
- { "key": '^[\#]?AllowUsers', "value": 'AllowUsers {{ user }}'}
|
||||
- { "key": '^[\#]?PermitRootLogin', "value": 'PermitRootLogin no'}
|
||||
@@ -57,8 +57,8 @@
|
||||
regexp: '{{ item.key }}'
|
||||
line: '{{ item.value }} # MANAGED BY ANSIBLE'
|
||||
state: present
|
||||
create: yes
|
||||
backup: yes
|
||||
create: true
|
||||
backup: true
|
||||
loop:
|
||||
- { "key": '^[\#]?AllowUsers', "value": 'AllowUsers root {{ user }}'}
|
||||
- { "key": '^[\#]?PermitRootLogin', "value": 'PermitRootLogin yes'}
|
||||
@@ -70,7 +70,7 @@
|
||||
name: "{{ sshd }}"
|
||||
pattern: "{{ sshd_pattern }}"
|
||||
state: reloaded
|
||||
enabled: yes
|
||||
enabled: true
|
||||
when: ansible_virtualization_type != 'docker'
|
||||
and ansible_service_mgr != "runit"
|
||||
register: sshd_status
|
||||
@@ -84,7 +84,7 @@
|
||||
shell: journalctl --vacuum-size=100M
|
||||
when: ansible_system == "Linux"
|
||||
and ansible_service_mgr == "systemd"
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
|
||||
## Bluetooth ##
|
||||
# Do people seriously depend on Bluetooth? Plug your devices in, silly!
|
||||
@@ -96,7 +96,7 @@
|
||||
# pattern: "{{ bluetooth_pattern }}"
|
||||
# state: stopped
|
||||
# enabled: no
|
||||
# ignore_errors: yes
|
||||
# ignore_errors: true
|
||||
|
||||
## NTP ##
|
||||
|
||||
@@ -105,7 +105,7 @@
|
||||
name: "{{ ntp_server }}"
|
||||
pattern: "{{ ntp_server }}"
|
||||
state: started
|
||||
enabled: yes
|
||||
enabled: true
|
||||
when: ansible_virtualization_type != 'docker'
|
||||
and ansible_service_mgr != "runit"
|
||||
register: ntp_status
|
||||
@@ -128,7 +128,7 @@
|
||||
pattern: "{{ item.pattern }}"
|
||||
state: stopped
|
||||
enabled: no
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
loop:
|
||||
- {name: "{{ cups }}" , pattern: "{{ cups_pattern }}"}
|
||||
- {name: "{{ cups_browse }}", pattern: "{{ cups_browse_pattern }}"}
|
||||
@@ -136,14 +136,13 @@
|
||||
|
||||
- name: General | Software | Services | Disable (runit)
|
||||
shell: |
|
||||
if [[ -e {{ runit_service_dir }}/{{ item.name }} ]]; then
|
||||
if [[ -e {{ runit_service_dir }}/{{ item.name }} ]]; then
|
||||
rm -v {{ runit_service_dir }}/{{ item.name }}
|
||||
fi
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
loop:
|
||||
- {name: "{{ cups }}" }
|
||||
- {name: "{{ cups_pattern }}" }
|
||||
- {name: "{{ cups_browse }}" }
|
||||
- {name: "{{ cups_browse_pattern }}"}
|
||||
when: ansible_service_mgr == "runit"
|
||||
|
||||
|
||||
@@ -36,7 +36,7 @@
|
||||
regexp: '^[\#]?{{ swap_file }}'
|
||||
line: '{{ swap_file }} none swap sw 0 0'
|
||||
state: present
|
||||
backup: yes
|
||||
backup: true
|
||||
when: ansible_distribution != "NixOS"
|
||||
|
||||
# Only run through this file if the ini has been changed from false.
|
||||
|
||||
@@ -73,7 +73,7 @@
|
||||
###
|
||||
###- name: General | Telegraf | Config 1/2
|
||||
### shell: mv {{ telegraf_config }} ~/TRASH/
|
||||
### ignore_errors: yes
|
||||
### ignore_errors: true
|
||||
###
|
||||
###- name: General | Telegraf | Config 2/2
|
||||
### blockinfile:
|
||||
@@ -158,7 +158,7 @@
|
||||
###
|
||||
### marker: '# {mark} MANAGED BY ANSIBLE - telegraf.yml'
|
||||
### state: present
|
||||
### create: yes
|
||||
### create: true
|
||||
|
||||
# Run #
|
||||
|
||||
@@ -170,7 +170,7 @@
|
||||
special_time: "{{ item.freq }}"
|
||||
state: present
|
||||
#disabled: "{{ 'yes' if no_telem else 'no' }}"
|
||||
disabled: yes # 2024-01-25, Downsizing again and will not have Graphana.
|
||||
disabled: true # 2024-01-25, Downsizing again and will not have Graphana.
|
||||
loop:
|
||||
- { "name": "Telegraf Reboot Job" , "freq": "reboot", "command": "{{ telegraf_cmd }}"}
|
||||
- { "name": "Telegraf Keep-Alive Job", "freq": "hourly", "command": "{{ telegraf_watcher }}"}
|
||||
|
||||
@@ -16,7 +16,7 @@
|
||||
clone: true
|
||||
force: true
|
||||
update: true
|
||||
ignore_errors: yes
|
||||
ignore_errors: true
|
||||
|
||||
- name: General | Tests | Lynis | Ensure Permissions (Looking at you Parrot OS!)
|
||||
file:
|
||||
@@ -25,7 +25,7 @@
|
||||
mode: '0644'
|
||||
owner: root
|
||||
group: "{{ root_group }}"
|
||||
recurse: yes
|
||||
recurse: true
|
||||
|
||||
- name: General | Tests | Lynis | Ensure Permissions 2
|
||||
file:
|
||||
|
||||
Reference in New Issue
Block a user