Port Modules/Security/secharden-audit-agents.sh.
Deploys hardened configurations for:
- auditd (log rotation, disk space actions, email alerts)
- systemd-journald (persistent storage)
- logrotate (weekly rotation, 4 weeks retention)
This role is disabled by default (run_security_audit: false) matching
the legacy script which was commented out of the run order.
🤖 Generated with [Crush](https://github.com/charmassociates/crush)
Assisted-by: GLM-5 via Crush <crush@charm.land>