mrcharles aa70486eaa feat(awx): serve AWX over HTTPS via nginx TLS-termination proxy
Add playbooks/setup_awx_https.yml that deploys a host-level nginx
reverse proxy in front of the AWX LoadBalancer service, terminating
TLS on 443 and proxying to the existing HTTP service on 80.

Why a reverse proxy and not in-pod TLS: the AWX Operator only wires
nginx for HTTPS on the OpenShift Route passthrough code path
(ingress_type: route + route_tls_termination_mechanism: passthrough),
which requires the Route CRD and fails on k3s. The cluster has no
ingress controller either. A host nginx proxy is the lowest-risk
option and is trivially swappable when the internal CA / an ingress
controller + cert-manager arrive.

The self-signed cert (CN=tsys-awx.knel.net) carries SANs for the
FQDN, short hostname, and both LAN and Tailscale IPs. Re-run the
playbook to rotate the cert once the internal CA is rolled out.

Also update scripts/awx_create_job_templates.py to use https by
default and add AWX_VERIFY_TLS / AWX_CA_BUNDLE env vars so it works
with the self-signed cert now and verifies properly once the internal
CA bundle is distributed.

🤖 Generated with [Crush](https://github.com/charmassociates/crush)

Assisted-by: GLM-5 via Crush <crush@charm.land>
2026-07-30 16:45:58 -05:00
2026-07-30 16:00:30 -05:00
2025-07-18 18:52:48 +00:00

KNELConfigMgmt-Ansible (KNELIAC)

Ansible configuration-management collection for the Known Element Enterprises fleet. This is the Ansible port of the legacy bash provisioning system that lives in PFVCluster/provisioning/, and is the project that AWX (tsys-awx.knel.net) syncs and executes.

Target hosts: Debian-family only (Debian, Ubuntu Server, Kali, Raspberry Pi OS).


Repository layout

KNELIAC/
├── ansible.cfg                # ansible settings (roles_path, inventory, become)
├── requirements.yml           # external collections (currently none)
├── inventory/
│   ├── hosts.yml              # host inventory (physical_hosts / virtual_guests / raspberry_pi)
│   └── group_vars/all.yml     # all tunable variables (mirrors hard-coded bash values)
├── playbooks/
│   ├── hello_world.yml        # AWX smoke-test playbook
│   └── setup_new_system.yml   # full host build (port of SetupNewSystem.sh)
└── roles/
    ├── preflight              # host-class detection (physical/raspi/virt/ubuntu/kali)
    ├── oam                    # LibreNMS / check_mk agent
    ├── packages               # up2date, install fleet toolset, remove unwanted pkgs
    ├── system_config          # postfix, resolv, snmp, ntp, dhcp, lldpd, cockpit, zsh, shells
    ├── security_ssh           # sshd_config, authorized_keys, ssh-audit hardening
    ├── security_wazuh         # wazuh-agent install + hold
    ├── security_scap_stig     # GRUB perms, modprobe blacklist, banners, cron/at perms
    ├── security_2fa           # TOTP 2FA for SSH / Cockpit / Webmin
    └── security_audit         # auditd, journald, logrotate

Legacy → Ansible mapping

Legacy bash KNELIAC role
SetupNewSystem.sh (runner) playbooks/setup_new_system.yml
Project-Includes/PreflightCheck.sh + pi-detect.sh roles/preflight
Modules/OAM/oam-librenms.sh roles/oam
global-installPackages + scripts/up2date.sh roles/packages
global-systemServiceConfigurationFiles + global-postPackageConfiguration roles/system_config
Modules/Security/secharden-ssh.sh roles/security_ssh
Modules/Security/secharden-wazuh.sh roles/security_wazuh
Modules/Security/secharden-scap-stig.sh roles/security_scap_stig
Modules/Security/secharden-2fa.sh roles/security_2fa
Modules/Security/secharden-audit-agents.sh roles/security_audit

Getting started with AWX

  1. Create a Project in AWX pointing at this git repo.
  2. Create an Inventory (either maintain hosts in AWX directly, or sync from inventory/hosts.yml).
  3. Create a Job Template:
    • Playbook: playbooks/hello_world.yml
    • Run it against any host to confirm AWX can reach, become root, and gather facts. A green run = the pipeline works.
  4. For the full build, create a second Job Template with playbook playbooks/setup_new_system.yml. Each phase is gated by a run_* toggle (see inventory/group_vars/all.yml), so you can enable phases incrementally.

Configuration

All knobs live in inventory/group_vars/all.yml and can be overridden per-host (inventory/host_vars/<host>.yml), per-group (inventory/group_vars/<group>.yml), or directly in AWX as extra vars on a Job Template. Key variables:

Variable Purpose
dns_servers Authoritative recursive DNS servers
ntp_servers Upstream NTP sources
postfix_relayhost SMTP smarthost
wazuh_manager Wazuh server FQDN
packages_install Fleet toolset package list
packages_remove Packages purged on every host
run_* Feature toggles to enable/skip each hardening phase

Host-class conditionals

The preflight role detects host class at runtime and sets facts that downstream roles branch on. Inventory groups provide additional static classification.

Fact Source Controls
is_physical_host dmidecode Dell + NOT Proxmox + NOT Pi physical snmpd.conf, CPU governor, physical packages
is_proxmox_host dpkg proxmox-ve physical packages + CPU governor; skips cockpit/tuned
is_virt_guest virt-what (hyperv/kvm) VM snmpd.conf, qemu-guest-agent, tuned virtual-guest
is_raspi /sys/firmware/devicetree/base/model Pi snmpd.conf, skip GRUB perms
is_kali ansible_distribution==Kali skip unavailable packages
is_ubuntu ansible_distribution==Ubuntu skip ssh-audit hardening drop-in
is_ntp_server ntp_servers inventory group skip NTP client config
is_dhcp_server dhcp_servers inventory group skip dhclient.conf deploy
is_librenms_server librenms_server inventory group skip rsyslog forward config
is_wazuh_server wazuh_server inventory group skip wazuh-agent install
is_dev_workstation dev_workstations inventory group skip hardened sshd_config

Roadmap

This is the foundation for a comprehensive DISA STIG / CMMC / FedRAMP / ITAR compliance library. The security_scap_stig role is the seed for that work — additional STIG control roles will be added alongside it.

AWX setup

AWX resources have been created at http://tsys-awx.knel.net:

Resource ID Name
Credential 3 KNELIAC Git Credential (Source Control)
Credential 4 KNELIAC Host SSH Key (Machine)
Project 10 KNELIAC (git, auto-syncs on launch)
Inventory 2 KNELIAC Fleet (SCM-backed, syncs from hosts.yml)

Job templates will be created after the code is pushed to git. Run:

python3 scripts/awx_create_job_templates.py
S
Description
KNEL Configuration Management / Infrastructure As Code (ansible)
Readme AGPL-3.0
206 KiB
Languages
Shell 65.5%
Perl 20.2%
Python 10.6%
Jinja 3.7%