sandwich
|
2c80c01b1a
|
refactor(global_defaults): consolidate hypervisor auth into shared credential dicts
|
2026-02-22 02:35:04 +01:00 |
|
sandwich
|
1b58a20c45
|
refactor(bootstrap,configuration,environment): add defaults/main.yml and extract hardcoded values
|
2026-02-22 02:32:36 +01:00 |
|
sandwich
|
6b1686e652
|
refactor(bootstrap,configuration): add per-role _normalize.yml for platform resolution
|
2026-02-22 02:27:46 +01:00 |
|
sandwich
|
a460584c5d
|
refactor(configuration): add platform_config dict and replace is_rhel/is_debian with os_family lookups
|
2026-02-22 02:26:54 +01:00 |
|
sandwich
|
9c0f00f1ec
|
feat(global_defaults): add os_family_map and os_family fact for platform config lookups
|
2026-02-22 02:23:05 +01:00 |
|
sandwich
|
6ebceb8ee2
|
fix(virtualization): add vTPM2 result validation before VMware power-on
|
2026-02-22 02:22:37 +01:00 |
|
sandwich
|
5e72394bf8
|
feat(global_defaults): add semantic validations for IP, hostname, LUKS method, and interface prefix
|
2026-02-22 02:22:05 +01:00 |
|
sandwich
|
5abdc76c86
|
refactor(global_defaults): extract physical_default_os to configurable default
|
2026-02-22 02:21:34 +01:00 |
|
sandwich
|
bcfd5d5a89
|
fix(global_defaults): normalize system.type 'vm' to 'virtual' for main project compatibility
|
2026-02-22 02:21:22 +01:00 |
|
sandwich
|
c91e049378
|
docs(bootstrap): add section comments, role boundary docs, and pipeline overview
|
2026-02-22 01:59:12 +01:00 |
|
sandwich
|
b9e8aa283b
|
refactor(global_defaults): data-driven hypervisor validation and shared constants
|
2026-02-22 01:59:09 +01:00 |
|
sandwich
|
734ed822d6
|
refactor(extras): convert custom.sh from template to static copy
|
2026-02-22 01:59:04 +01:00 |
|
sandwich
|
3f2f4055f0
|
fix(cleanup,config): xen tmp cleanup, tpm2 fallback warning, add code comments
|
2026-02-22 01:59:01 +01:00 |
|
sandwich
|
a2b206127f
|
fix(partitioning,network): swapon idempotency, DNS search domains, tune2fs changed_when
|
2026-02-22 01:58:56 +01:00 |
|
sandwich
|
6985235e70
|
fix(encryption): add no_log to LUKS configuration block
|
2026-02-22 01:58:52 +01:00 |
|
sandwich
|
25b1eeec45
|
fix(network): bind NM connections to detected interface names for multi-NIC
|
2026-02-21 16:51:15 +01:00 |
|
sandwich
|
3f65585e5c
|
fix(bootstrap): make dhcp-client conditional for EL < 10 (removed in EL 10)
|
2026-02-21 13:43:41 +01:00 |
|
sandwich
|
74f1365a06
|
fix(bootstrap): remove --asexplicit from pacstrap to preserve dependency metadata
|
2026-02-21 13:26:59 +01:00 |
|
sandwich
|
9d19f628aa
|
fix(bootstrap): add kernel package to rocky and almalinux extra packages
|
2026-02-21 12:06:09 +01:00 |
|
sandwich
|
ced0da7bd1
|
fix(bootstrap): detect kernel package name for dnf family reinstall step
|
2026-02-21 11:46:57 +01:00 |
|
sandwich
|
cf49d30916
|
fix(bootstrap): ensure chroot DNS resolution before installing extra packages
|
2026-02-21 11:30:28 +01:00 |
|
sandwich
|
46b5223da5
|
fix(environment): align repo IDs in rocky and almalinux templates with bootstrap config
|
2026-02-21 11:18:34 +01:00 |
|
sandwich
|
494f0b58b2
|
fix(configuration): omit interface-name when not explicitly provided to avoid predictable naming mismatch
|
2026-02-21 08:29:24 +01:00 |
|
sandwich
|
d84b867cef
|
refactor(configuration): rename _uid to configuration_uid for role prefix convention
|
2026-02-21 05:14:33 +01:00 |
|
sandwich
|
39c786305f
|
fix(configuration): handle boolean sudo values in sudoers deployment
|
2026-02-21 05:14:29 +01:00 |
|
sandwich
|
72e2263f5c
|
fix(configuration): use full path for chpasswd in chroot
|
2026-02-21 05:03:36 +01:00 |
|
sandwich
|
ac532578b8
|
fix(global_defaults): enrich pre-computed system_cfg with bootstrap defaults
|
2026-02-21 04:24:23 +01:00 |
|
sandwich
|
34f35bb5ac
|
chore(lint): suppress var-naming for user-facing API dicts
|
2026-02-21 02:58:10 +01:00 |
|
sandwich
|
6de88a911a
|
fix(configuration): remove unnecessary changed_when on set_fact tasks
|
2026-02-21 02:56:58 +01:00 |
|
sandwich
|
fa78edf2e2
|
refactor(cis): align normalization with main project activation gate pattern
|
2026-02-21 02:56:39 +01:00 |
|
sandwich
|
a1c8b5e2dd
|
fix(global_defaults): remove dead /swap and make pacman cache arch-only in reserved mounts
|
2026-02-21 02:56:20 +01:00 |
|
sandwich
|
19da8c0e68
|
fix(global_defaults): set filesystem default to ext4 instead of empty string
|
2026-02-21 02:56:08 +01:00 |
|
sandwich
|
ff1a4df960
|
refactor(bootstrap): restructure package lists to self-contained per-OS dicts with base/extra/conditional
|
2026-02-21 02:39:06 +01:00 |
|
sandwich
|
f0c0b54e7f
|
refactor(environment): split main.yml into focused sub-task files
|
2026-02-21 02:39:05 +01:00 |
|
sandwich
|
a868c6bb47
|
refactor(global_defaults): add idempotency guards to normalization tasks
|
2026-02-21 02:39:03 +01:00 |
|
sandwich
|
dd0d70f4fd
|
fix(global_defaults): default interface name to eth0 instead of empty string
|
2026-02-21 02:38:59 +01:00 |
|
sandwich
|
c08e1fe4e0
|
docs(cis): add comment explaining squashfs/snap Ubuntu exclusion
|
2026-02-21 02:38:58 +01:00 |
|
sandwich
|
c3ccce97ae
|
chore(bootstrap): pin collection versions in requirements.yml
|
2026-02-21 02:38:57 +01:00 |
|
sandwich
|
d9ca905b73
|
fix(bootstrap): move Jinja to end of task name and rename registers to bootstrap_dnf_*
|
2026-02-21 02:38:27 +01:00 |
|
sandwich
|
6085336f96
|
docs: update README with cis dict API, execution pipeline, and cleanup defaults
|
2026-02-21 01:30:36 +01:00 |
|
sandwich
|
2831479e77
|
fix(validation): align btrfs disk size check with new 2GB swap minimum
|
2026-02-21 01:28:32 +01:00 |
|
sandwich
|
608cbf3196
|
refactor(bootstrap): unify rocky, almalinux, and fedora into shared _dnf_family.yml
|
2026-02-21 01:27:33 +01:00 |
|
sandwich
|
382e48176d
|
refactor(cis): extract hardcoded values to cis_defaults and add _normalize.yml
|
2026-02-21 01:26:31 +01:00 |
|
sandwich
|
0372e35ea3
|
refactor(cleanup): prioritize source-match over target-match in libvirt media removal
|
2026-02-21 01:22:44 +01:00 |
|
sandwich
|
6e055de457
|
docs(cis): explain Fedora exclusion from crypto-policy configuration
|
2026-02-21 01:22:41 +01:00 |
|
sandwich
|
f7e1bd4d49
|
fix(bootstrap): replace brittle sed with ansible.builtin.replace for ubuntu universe repo
|
2026-02-21 01:22:37 +01:00 |
|
sandwich
|
58c9b264f9
|
refactor(virtualization): simplify cloud-user-data sudo to unconditional NOPASSWD
|
2026-02-21 01:22:34 +01:00 |
|
sandwich
|
11a4794ac2
|
fix(bootstrap): remove duplicate lrzsz and gate dbus-daemon on version in almalinux
|
2026-02-21 01:20:34 +01:00 |
|
sandwich
|
d3c8c6c975
|
fix(virtualization): fix cloud-user-data sudo logic to respect sudo: false
|
2026-02-21 01:20:31 +01:00 |
|
sandwich
|
ba8ab340f7
|
fix(partitioning): lower swap minimum from 4GB to 2GB for small VMs
|
2026-02-21 01:19:23 +01:00 |
|
sandwich
|
474ebbb513
|
fix(partitioning): add wipefs before mkfs on extra disk partitions
|
2026-02-21 01:19:19 +01:00 |
|
sandwich
|
5df369b151
|
fix(cis): strengthen kernel module blacklist and sysctl hardening
|
2026-02-21 01:18:52 +01:00 |
|
sandwich
|
08c518bd5b
|
refactor(partitioning): split monolithic main.yml into focused task files
|
2026-02-21 00:39:03 +01:00 |
|
sandwich
|
e200774c8e
|
fix(validation): add CIDR prefix range check and Ubuntu version validation
|
2026-02-21 00:38:57 +01:00 |
|
sandwich
|
6e0c289226
|
refactor(cis): remove redundant AllowUsers/AllowGroups/DenyUsers/DenyGroups from sshd
|
2026-02-21 00:38:52 +01:00 |
|
sandwich
|
3be725633e
|
fix(cis): skip squashfs blacklist on Ubuntu to preserve snap functionality
|
2026-02-21 00:38:47 +01:00 |
|
sandwich
|
6c02eab159
|
fix(partitioning): correct changed_when on btrfs quota and qgroup commands
|
2026-02-21 00:38:43 +01:00 |
|
sandwich
|
99c579bec0
|
fix(cis): add regexp to all lineinfile entries in security_lines.yml for idempotency
|
2026-02-21 00:38:36 +01:00 |
|
sandwich
|
be5d2e9f94
|
fix: add no_log to credential-handling pre_tasks and post_tasks in main.yml
|
2026-02-21 00:38:32 +01:00 |
|
sandwich
|
e334c82b26
|
fix(virtualization): add no_log and secure temp file handling to libvirt cloud-init
|
2026-02-21 00:38:28 +01:00 |
|
sandwich
|
5008d97bc8
|
refactor(cleanup): add configurable verify_boot, boot_timeout, and remove_on_failure defaults
|
2026-02-20 23:02:24 +01:00 |
|
sandwich
|
06b8058c1d
|
refactor: move playbook-root templates into their respective roles
|
2026-02-20 23:01:38 +01:00 |
|
sandwich
|
aec82e4241
|
refactor: add loop_control labels to dict-based loops across all roles
|
2026-02-20 23:00:53 +01:00 |
|
sandwich
|
f36d9b7ca3
|
refactor(partitioning): move btrfs home quota to configurable default
|
2026-02-20 22:55:37 +01:00 |
|
sandwich
|
0950db7011
|
fix(environment): detect RHEL ISO device dynamically instead of hardcoded /dev/sr paths
|
2026-02-20 22:54:42 +01:00 |
|
sandwich
|
4f3e39398f
|
refactor(global_defaults): split system.yml into composable normalization stages
|
2026-02-20 22:54:05 +01:00 |
|
sandwich
|
e3c21168fd
|
refactor(global_defaults): extract OS family lists to single source of truth
|
2026-02-20 22:52:55 +01:00 |
|
sandwich
|
643fec1cc6
|
fix(partitioning): add failed_when to all blkid commands to catch empty UUIDs
|
2026-02-20 22:52:18 +01:00 |
|
sandwich
|
bbbdcfc9b6
|
fix(partitioning): add default fallbacks for is_rhel, os, os_version in defaults
|
2026-02-20 22:51:37 +01:00 |
|
sandwich
|
9347140808
|
fix(virtualization): use hostname variable instead of hardcoded archiso in cloud-user-data
|
2026-02-20 22:51:32 +01:00 |
|
sandwich
|
b8af8b3fdd
|
fix(virtualization): avoid no-handler lint finding in xen VM created tracking
|
2026-02-20 22:29:03 +01:00 |
|
sandwich
|
94ea082e63
|
fix(partitioning): fix line length violation in home size calculation
|
2026-02-20 22:28:58 +01:00 |
|
sandwich
|
3361ee3de8
|
fix(configuration): add pipefail to root password shell pipe
|
2026-02-20 22:28:54 +01:00 |
|
sandwich
|
06f6203674
|
fix(bootstrap): use release map for ubuntu version detection
|
2026-02-20 22:27:46 +01:00 |
|
sandwich
|
a385c27963
|
chore: add .yamllint matching main project conventions
|
2026-02-20 22:27:31 +01:00 |
|
sandwich
|
04340d1a04
|
fix(configuration): use chpasswd for root password and separate shell setting
|
2026-02-20 22:27:17 +01:00 |
|
sandwich
|
4c8021fc2e
|
fix(configuration): add explicit LUKS auto-decrypt fallback state tracking and logging
|
2026-02-20 22:26:47 +01:00 |
|
sandwich
|
6a6a43ae96
|
refactor(partitioning): externalize hardcoded LVM and disk sizing constants to defaults
|
2026-02-20 22:26:23 +01:00 |
|
sandwich
|
2a7340af37
|
fix(virtualization): add xen VM existence check and improve changed_when
|
2026-02-20 22:25:10 +01:00 |
|
sandwich
|
e0687269d4
|
fix(cis): add pipefail to sshd version detection and define binary defaults
|
2026-02-20 22:24:14 +01:00 |
|
sandwich
|
1634af552e
|
feat(cleanup): gate RHEL ISO disk and fstab handling on rhel_repo.source
|
2026-02-20 21:51:20 +01:00 |
|
sandwich
|
0077f05654
|
feat(global_defaults): add system.features.rhel_repo option (iso|satellite|none)
|
2026-02-20 21:51:16 +01:00 |
|
sandwich
|
33d46274bd
|
fix(encryption): add warning before silent TPM2-to-keyfile fallback
|
2026-02-20 21:51:12 +01:00 |
|
sandwich
|
ed6b604302
|
fix(partitioning): correct wipefs changed_when to report actual disk modification
|
2026-02-20 21:51:09 +01:00 |
|
sandwich
|
fc2ddfea8a
|
fix(validation): require password for primary user in system.users[0]
|
2026-02-20 21:51:06 +01:00 |
|
sandwich
|
efdbc0c04e
|
fix(system_check): move no_log from block to individual API tasks
|
2026-02-20 21:51:02 +01:00 |
|
sandwich
|
5769bd456d
|
fix(cis): make mlkem768x25519-sha256 KexAlgorithm conditional on OpenSSH 9.9+
|
2026-02-20 21:50:58 +01:00 |
|
sandwich
|
b7ffcfecd4
|
fix(cis): use is_rhel for journald config path instead of fedora-only check
|
2026-02-20 21:50:55 +01:00 |
|
sandwich
|
f18881328c
|
refactor(configuration): add conditional dispatch to task includes
|
2026-02-20 21:16:52 +01:00 |
|
sandwich
|
05aeb0676b
|
refactor(cis): move OS-specific binary resolution to vars/main.yml
|
2026-02-20 21:16:48 +01:00 |
|
sandwich
|
5b5c94cb8b
|
refactor(configuration): split network.yml into per-init-system dispatch files
|
2026-02-20 21:16:45 +01:00 |
|
sandwich
|
4a89911a54
|
refactor(bootstrap): restructure conditional package lists to list concatenation
|
2026-02-20 21:16:40 +01:00 |
|
sandwich
|
b61fecfc88
|
refactor(configuration): convert services.yml to list-based loop
|
2026-02-20 21:16:37 +01:00 |
|
sandwich
|
b690bddaec
|
refactor(virt): adopt module_defaults for hypervisor credentials
|
2026-02-20 21:16:33 +01:00 |
|
sandwich
|
8e92f40b2a
|
refactor(cleanup): restructure dispatch to use hypervisor_type include
|
2026-02-20 21:16:28 +01:00 |
|
sandwich
|
c8c9a9c9f5
|
refactor(partitioning): extract VG name to defaults variable
|
2026-02-20 21:16:25 +01:00 |
|
sandwich
|
7a666239b6
|
fix(configuration): remove trailing blank line from extras.yml
|
2026-02-20 20:20:33 +01:00 |
|
sandwich
|
7181679d7c
|
docs(environment): document RPM GPG policy relaxation
|
2026-02-20 20:19:57 +01:00 |
|
sandwich
|
32f22e94bd
|
chore(bootstrap): align ansible.cfg with main project settings
|
2026-02-20 20:19:46 +01:00 |
|
sandwich
|
15122b924d
|
feat(system_check): add safety check for physical installs
|
2026-02-20 20:19:37 +01:00 |
|