Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
36 changes: 36 additions & 0 deletions molecule/docker/Dockerfile-ubuntu2404
Original file line number Diff line number Diff line change
@@ -0,0 +1,36 @@
FROM ubuntu:24.04

ENV container=docker \
LANGUAGE=en_US.UTF-8 \
LANG=en_US.UTF-8 \
LC_ALL=en_US.UTF-8 \
TERM=xterm \
DEBIAN_FRONTEND="noninteractive"

RUN find /etc/systemd/system \
/lib/systemd/system \
-path '*.wants/*' \
-not -name '*journald*' \
-not -name '*systemd-tmpfiles*' \
-not -name '*systemd-user-sessions*' \
-print0 | xargs -0 rm -vf

RUN apt-get update && \
INSTALL_PKGS="openssh-server rsyslog software-properties-common python3 python3-pip python3-setuptools curl sudo bash ca-certificates iproute2 python3-apt aptitude apt-utils locales dbus gnupg systemd systemd-cron" && \
apt-get install -y $INSTALL_PKGS && \
localedef -f UTF-8 -i en_US en_US.UTF-8

RUN cp /bin/true /sbin/agetty

RUN mkdir -p /etc/systemd/system/systemd-timesyncd.service.d/
RUN bash -c 'echo -e "[Unit]\nConditionVirtualization=" > /etc/systemd/system/systemd-timesyncd.service.d/override.conf'

# Créer un répertoire temporaire pour Ansible avec les permissions correctes
RUN mkdir -p /tmp/ansible && \
chmod 777 /tmp/ansible

STOPSIGNAL SIGRTMIN+3

VOLUME [ "/sys/fs/cgroup" ]

CMD ["/lib/systemd/systemd"]
21 changes: 21 additions & 0 deletions tasks/ssh.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,27 @@
state: present
notify: Restart ssh

# KbdInteractiveAuthentication only exists since OpenSSH 8.7 (Ubuntu 22.04+);
# older OS (Ubuntu <22.04, CentOS 7/8) need the legacy ChallengeResponseAuthentication name,
# otherwise sshd fails to parse the config.
# Only Ubuntu is checked here because the EL versions this role supports (see meta/main.yml:
# 7 and 8) both ship OpenSSH < 8.7 and always fall into the else branch. Revisit this condition
# if support for EL 9+ (OpenSSH >= 8.7) is ever added.
- name: Set keyboard-interactive authentication option name based on OS support
set_fact:
ssh_kbd_interactive_option_name: >-
{{ 'KbdInteractiveAuthentication' if ansible_distribution == 'Ubuntu' and ansible_distribution_version is version('22', '>=') else
'ChallengeResponseAuthentication' }}

# Prevents PAM from bypassing PasswordAuthentication=no via keyboard-interactive prompts
- name: Disallow keyboard-interactive authentication
lineinfile:
dest: /etc/ssh/sshd_config
regexp: "^(# *)?(ChallengeResponseAuthentication|KbdInteractiveAuthentication)"
line: "{{ ssh_kbd_interactive_option_name }} no"
state: present
notify: Restart ssh

- name: Allow agent forwarding
lineinfile:
dest: /etc/ssh/sshd_config
Expand Down
8 changes: 8 additions & 0 deletions tasks/users.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,6 +16,14 @@
validate: visudo -cf %s
when: basic_passwordless_sudo

- name: Log commands run through sudo with a pty (CVE-2005-4890)
lineinfile:
dest: /etc/sudoers
state: present
regexp: '^Defaults\s+use_pty'
line: 'Defaults use_pty'
validate: visudo -cf %s

- name: Creating users groups (1)
group:
name: "{{ item }}"
Expand Down