Map global defaults in playbook

This commit is contained in:
2026-01-02 12:20:15 +01:00
parent 78316a8946
commit f8e3ce62d4
4 changed files with 131 additions and 32 deletions

View File

@@ -1,27 +1,24 @@
---
hypervisor: "none"
custom_iso: false
cis: false
selinux: true
vmware_ssh: false
firewalld_enabled: true
global_defaults_hypervisor: "none"
global_defaults_custom_iso: false
global_defaults_cis: false
global_defaults_selinux: true
global_defaults_vmware_ssh: false
global_defaults_firewalld_enabled: true
cis_enabled: "{{ cis | bool }}"
custom_iso_enabled: "{{ custom_iso | bool }}"
luks_enabled: false
luks_mapper_name: "SYSTEM_DECRYPTED"
luks_auto_decrypt: true
luks_auto_decrypt_method: "tpm2"
luks_tpm2_device: "auto"
luks_tpm2_pcrs: ""
luks_keyfile_size: 64
luks_options: "discard,tries=3"
luks_type: "luks2"
luks_cipher: "aes-xts-plain64"
luks_hash: "sha512"
luks_iter_time: 4000
luks_key_size: 512
luks_pbkdf: "argon2id"
luks_use_urandom: true
luks_verify_passphrase: true
global_defaults_luks_enabled: false
global_defaults_luks_mapper_name: "SYSTEM_DECRYPTED"
global_defaults_luks_auto_decrypt: true
global_defaults_luks_auto_decrypt_method: "tpm2"
global_defaults_luks_tpm2_device: "auto"
global_defaults_luks_tpm2_pcrs: ""
global_defaults_luks_keyfile_size: 64
global_defaults_luks_options: "discard,tries=3"
global_defaults_luks_type: "luks2"
global_defaults_luks_cipher: "aes-xts-plain64"
global_defaults_luks_hash: "sha512"
global_defaults_luks_iter_time: 4000
global_defaults_luks_key_size: 512
global_defaults_luks_pbkdf: "argon2id"
global_defaults_luks_use_urandom: true
global_defaults_luks_verify_passphrase: true

View File

@@ -1,6 +1 @@
---
- name: Load global defaults
ansible.builtin.debug:
msg: "Global defaults loaded."
verbosity: 1
changed_when: false