Close RAIL-HO-WP-0009 declared-state gaps; leave live 6443 prune gated
Make the k3s API tunnel-only (ADR-005), stop declaring Flannel VXLAN open to Anywhere, tag the base role so firewall can be scoped, and schedule the Goss declared-vs-live check. CoulombCore sets ufw_manage false so a converge cannot enable UFW there. T02 still needs operator approval for make converge-firewall HOST=Railiance01.
This commit is contained in:
parent
434121be99
commit
4d9e77c968
29 changed files with 793 additions and 99 deletions
|
|
@ -5,8 +5,13 @@
|
|||
- ../inventory/group_vars/secrets.sops.yaml
|
||||
roles:
|
||||
- role: base
|
||||
tags: [base]
|
||||
- role: sops_agent
|
||||
tags: [sops]
|
||||
- role: custodian_agent # injects ~/.ssh/id_custodian_agent.pub into authorized_keys
|
||||
tags: [custodian_agent]
|
||||
- role: swapfile # provisions swap file (size + swappiness from host_vars)
|
||||
tags: [swap]
|
||||
- role: resource_limits # nproc PAM caps + systemd user slice memory limits
|
||||
tags: [resource_limits]
|
||||
# - role: wireguard # enable if you configure WireGuard variables
|
||||
|
|
|
|||
32
ansible/playbooks/goss-status.yaml
Normal file
32
ansible/playbooks/goss-status.yaml
Normal file
|
|
@ -0,0 +1,32 @@
|
|||
---
|
||||
# Fetch the last on-host Goss timer result. Does not run a new check.
|
||||
# Usage: ansible-playbook ansible/playbooks/goss-status.yaml
|
||||
# make goss-status
|
||||
|
||||
- hosts: all
|
||||
become: true
|
||||
gather_facts: false
|
||||
tasks:
|
||||
- name: Read last Goss timer status
|
||||
ansible.builtin.slurp:
|
||||
src: /var/lib/railiance/goss/last.status
|
||||
register: goss_status
|
||||
failed_when: false
|
||||
|
||||
- name: Show last Goss timer status
|
||||
ansible.builtin.debug:
|
||||
msg: >-
|
||||
{{ inventory_hostname }}:
|
||||
{{ goss_status.content | default('') | b64decode | trim
|
||||
if goss_status.content is defined
|
||||
else 'no timer result yet' }}
|
||||
|
||||
- name: Fail when the last on-host check reported FAILED
|
||||
ansible.builtin.stat:
|
||||
path: /var/lib/railiance/goss/FAILED
|
||||
register: goss_failed
|
||||
|
||||
- name: Report failed hosts
|
||||
ansible.builtin.fail:
|
||||
msg: "Goss baseline last run failed on {{ inventory_hostname }}"
|
||||
when: goss_failed.stat.exists | default(false)
|
||||
Loading…
Add table
Add a link
Reference in a new issue