diff --git a/.ansible-lint b/.ansible-lint new file mode 100644 index 0000000..348c8aa --- /dev/null +++ b/.ansible-lint @@ -0,0 +1,19 @@ +--- +# ansible-lint configuration for KNELIAC +# https://ansible.readthedocs.io/projects/lint/ + +# Exclude vendored config files from formatting rules (they're content, not YAML) +exclude_paths: + - .git/ + - .fact_cache/ + - LICENSE + +# Use the default ruleset but be practical about it +skip_list: + # We use inline templates and command modules intentionally + - command-instead-of-shell # Some commands need shell for pipes + - risky-shell-pipe # Legacy script compat; we use set -o pipefail + +warn_list: + - experimental + - name[casing] # Our task names use sentence case intentionally diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..4b9a670 --- /dev/null +++ b/.gitignore @@ -0,0 +1,9 @@ +# Ansible / AWX local artifacts +.fact_cache/ +*.retry +*.log + +# Editor / OS +.DS_Store +*.swp +*~ diff --git a/ansible.cfg b/ansible.cfg new file mode 100644 index 0000000..0724721 --- /dev/null +++ b/ansible.cfg @@ -0,0 +1,17 @@ +[defaults] +# Where AWX/ansible looks for roles when not installed as collections. +roles_path = ./roles +inventory = ./inventory/hosts.yml +host_key_checking = False +# Use the default configured Python interpreter on each host. +interpreter_python = auto_silent +# Make output readable. +stdout_callback = yaml +gathering = smart +fact_caching = jsonfile +fact_caching_connection = ./.fact_cache +fact_caching_timeout = 86400 + +[privilege_escalation] +become = True +become_method = sudo diff --git a/requirements.yml b/requirements.yml new file mode 100644 index 0000000..863b221 --- /dev/null +++ b/requirements.yml @@ -0,0 +1,7 @@ +# requirements.yml +# +# External Ansible collections this project depends on. Currently empty — +# the roles in ./roles/ are self-contained and use only ansible.builtin.* +# modules. Add collections here as the STIG/CMMC/FedRAMP/ITAR hardening +# library grows (e.g. ansible.posix, community.crypto, community.general). +collections: []