Skip to content

Commit

Permalink
Linting.
Browse files Browse the repository at this point in the history
Signed-off-by: Bernd Grobauer <[email protected]>
  • Loading branch information
bgro committed Sep 22, 2023
1 parent a5a1a2d commit b766a87
Show file tree
Hide file tree
Showing 2 changed files with 8 additions and 10 deletions.
5 changes: 2 additions & 3 deletions tasks/prelim.yml
Original file line number Diff line number Diff line change
@@ -1,11 +1,10 @@
---
- name: "PRELIM | Set default values for facts"
ansible.builtin.set_fact:
control_1_6_1_4_was_run: false
ubtu22cis_apparmor_enforce_only: false
control_1_6_1_4_was_run: false
ubtu22cis_apparmor_enforce_only: false
changed_when: false


- name: "PRELIM | Register if snap being used"
ansible.builtin.shell: df -h | grep -wc "/snap"
changed_when: false
Expand Down
13 changes: 6 additions & 7 deletions tasks/section_1/cis_1.6.x.yml
Original file line number Diff line number Diff line change
Expand Up @@ -66,8 +66,8 @@
block:
- name: "1.6.1.4 | PATCH | Ensure all AppArmor Profiles are enforcing | Make sure that 1.6.1.3 is not run"
ansible.builtin.set_fact:
control_1_6_1_4_was_run: true
ubtu22cis_apparmor_enforce_only: true
control_1_6_1_4_was_run: true
ubtu22cis_apparmor_enforce_only: true
changed_when: false

- name: "1.6.1.4 | PATCH | Ensure all AppArmor Profiles are enforcing | Get pre apply enforce count"
Expand Down Expand Up @@ -108,16 +108,16 @@
block:
- name: "1.6.1.3 | AUDIT | Ensure all AppArmor Profiles are in enforce or complain | Set ubtu22cis_apparmor_enforce_only true for GOSS"
ansible.builtin.set_fact:
ubtu22cis_apparmor_enforce_only: true
ubtu22cis_apparmor_enforce_only: true
changed_when: false
when:
- ubtu22cis_apparmor_mode == "enforce"
- ubtu22cis_apparmor_mode == "enforce"
- name: "1.6.1.3 | AUDIT | Ensure all AppArmor Profiles are in enforce or complain | Set ubtu22cis_apparmor_enforce_only false for GOSS"
ansible.builtin.set_fact:
ubtu22cis_apparmor_enforce_only: false
ubtu22cis_apparmor_enforce_only: false
changed_when: false
when:
- ubtu22cis_apparmor_mode == "complain"
- ubtu22cis_apparmor_mode == "complain"
- name: "1.6.1.3 | PATCH | Ensure all AppArmor Profiles are in enforce or complain mode | Get pre apply enforce count"
ansible.builtin.shell: apparmor_status | grep "profiles are in {{ubtu22cis_apparmor_mode}} mode" | tr -d -c 0-9
changed_when: false
Expand Down Expand Up @@ -151,4 +151,3 @@
- patch
- rule_1.6.1.3
- apparmor

0 comments on commit b766a87

Please sign in to comment.