sandwich
3fd470d63e
fix(validation): align btrfs disk size check with new 2GB swap minimum
2026-02-21 01:28:32 +01:00
sandwich
a3cd507b2a
refactor(bootstrap): unify rocky, almalinux, and fedora into shared _dnf_family.yml
2026-02-21 01:27:33 +01:00
sandwich
f74ec325ea
refactor(cis): extract hardcoded values to cis_defaults and add _normalize.yml
2026-02-21 01:26:31 +01:00
sandwich
bef15af69f
refactor(cleanup): prioritize source-match over target-match in libvirt media removal
2026-02-21 01:22:44 +01:00
sandwich
7970d933e8
docs(cis): explain Fedora exclusion from crypto-policy configuration
2026-02-21 01:22:41 +01:00
sandwich
a123a32feb
fix(bootstrap): replace brittle sed with ansible.builtin.replace for ubuntu universe repo
2026-02-21 01:22:37 +01:00
sandwich
54c704de4e
refactor(virtualization): simplify cloud-user-data sudo to unconditional NOPASSWD
2026-02-21 01:22:34 +01:00
sandwich
9308d09d7b
fix(bootstrap): remove duplicate lrzsz and gate dbus-daemon on version in almalinux
2026-02-21 01:20:34 +01:00
sandwich
f367844239
fix(virtualization): fix cloud-user-data sudo logic to respect sudo: false
2026-02-21 01:20:31 +01:00
sandwich
53e4499d2b
fix(partitioning): lower swap minimum from 4GB to 2GB for small VMs
2026-02-21 01:19:23 +01:00
sandwich
eb63a4fa83
fix(partitioning): add wipefs before mkfs on extra disk partitions
2026-02-21 01:19:19 +01:00
sandwich
9e3688ae2b
fix(cis): strengthen kernel module blacklist and sysctl hardening
2026-02-21 01:18:52 +01:00
sandwich
dea01cc8a0
refactor(partitioning): split monolithic main.yml into focused task files
2026-02-21 00:39:03 +01:00
sandwich
92c9702e1d
fix(validation): add CIDR prefix range check and Ubuntu version validation
2026-02-21 00:38:57 +01:00
sandwich
c837a52a24
refactor(cis): remove redundant AllowUsers/AllowGroups/DenyUsers/DenyGroups from sshd
2026-02-21 00:38:52 +01:00
sandwich
fbd57e0603
fix(cis): skip squashfs blacklist on Ubuntu to preserve snap functionality
2026-02-21 00:38:47 +01:00
sandwich
40a9ee9882
fix(partitioning): correct changed_when on btrfs quota and qgroup commands
2026-02-21 00:38:43 +01:00
sandwich
3448e95e5c
fix(cis): add regexp to all lineinfile entries in security_lines.yml for idempotency
2026-02-21 00:38:36 +01:00
sandwich
074831833f
fix: add no_log to credential-handling pre_tasks and post_tasks in main.yml
2026-02-21 00:38:32 +01:00
sandwich
d1a5217e88
fix(virtualization): add no_log and secure temp file handling to libvirt cloud-init
2026-02-21 00:38:28 +01:00
sandwich
07492b5b57
refactor(cleanup): add configurable verify_boot, boot_timeout, and remove_on_failure defaults
2026-02-20 23:02:24 +01:00
sandwich
14913bcd3d
refactor: move playbook-root templates into their respective roles
2026-02-20 23:01:38 +01:00
sandwich
041650c287
refactor: add loop_control labels to dict-based loops across all roles
2026-02-20 23:00:53 +01:00
sandwich
a63ffbc731
refactor(partitioning): move btrfs home quota to configurable default
2026-02-20 22:55:37 +01:00
sandwich
9d2f1cc5bd
fix(environment): detect RHEL ISO device dynamically instead of hardcoded /dev/sr paths
2026-02-20 22:54:42 +01:00
sandwich
f72f9feb9a
refactor(global_defaults): split system.yml into composable normalization stages
2026-02-20 22:54:05 +01:00
sandwich
417737f904
refactor(global_defaults): extract OS family lists to single source of truth
2026-02-20 22:52:55 +01:00
sandwich
a06c2ebdcf
fix(partitioning): add failed_when to all blkid commands to catch empty UUIDs
2026-02-20 22:52:18 +01:00
sandwich
e174ecda42
fix(partitioning): add default fallbacks for is_rhel, os, os_version in defaults
2026-02-20 22:51:37 +01:00
sandwich
5246a905bb
fix(virtualization): use hostname variable instead of hardcoded archiso in cloud-user-data
2026-02-20 22:51:32 +01:00
sandwich
d00d84b69c
fix(virtualization): avoid no-handler lint finding in xen VM created tracking
2026-02-20 22:29:03 +01:00
sandwich
4dafa8c596
fix(partitioning): fix line length violation in home size calculation
2026-02-20 22:28:58 +01:00
sandwich
53584b8730
fix(configuration): add pipefail to root password shell pipe
2026-02-20 22:28:54 +01:00
sandwich
ce40468b77
fix(bootstrap): use release map for ubuntu version detection
2026-02-20 22:27:46 +01:00
sandwich
4b4fab3c33
chore: add .yamllint matching main project conventions
2026-02-20 22:27:31 +01:00
sandwich
db2fab5e7d
fix(configuration): use chpasswd for root password and separate shell setting
2026-02-20 22:27:17 +01:00
sandwich
42be0a5919
fix(configuration): add explicit LUKS auto-decrypt fallback state tracking and logging
2026-02-20 22:26:47 +01:00
sandwich
17400fa6ff
refactor(partitioning): externalize hardcoded LVM and disk sizing constants to defaults
2026-02-20 22:26:23 +01:00
sandwich
deb14d2c94
fix(virtualization): add xen VM existence check and improve changed_when
2026-02-20 22:25:10 +01:00
sandwich
65c5b1029b
fix(cis): add pipefail to sshd version detection and define binary defaults
2026-02-20 22:24:14 +01:00
sandwich
a1fbb7c21d
feat(cleanup): gate RHEL ISO disk and fstab handling on rhel_repo.source
2026-02-20 21:51:20 +01:00
sandwich
d076ac8fef
feat(global_defaults): add system.features.rhel_repo option (iso|satellite|none)
2026-02-20 21:51:16 +01:00
sandwich
c82e4afc4d
fix(encryption): add warning before silent TPM2-to-keyfile fallback
2026-02-20 21:51:12 +01:00
sandwich
ac72fdc4a6
fix(partitioning): correct wipefs changed_when to report actual disk modification
2026-02-20 21:51:09 +01:00
sandwich
b2e050c467
fix(validation): require password for primary user in system.users[0]
2026-02-20 21:51:06 +01:00
sandwich
914d7dd9d1
fix(system_check): move no_log from block to individual API tasks
2026-02-20 21:51:02 +01:00
sandwich
21bf8f79e2
fix(cis): make mlkem768x25519-sha256 KexAlgorithm conditional on OpenSSH 9.9+
2026-02-20 21:50:58 +01:00
sandwich
38feff4369
fix(cis): use is_rhel for journald config path instead of fedora-only check
2026-02-20 21:50:55 +01:00
sandwich
404529e8a4
refactor(configuration): add conditional dispatch to task includes
2026-02-20 21:16:52 +01:00
sandwich
3db18858c3
refactor(cis): move OS-specific binary resolution to vars/main.yml
2026-02-20 21:16:48 +01:00
sandwich
72a9576abe
refactor(configuration): split network.yml into per-init-system dispatch files
2026-02-20 21:16:45 +01:00
sandwich
462c2c7dfe
refactor(bootstrap): restructure conditional package lists to list concatenation
2026-02-20 21:16:40 +01:00
sandwich
ef8bfeaf84
refactor(configuration): convert services.yml to list-based loop
2026-02-20 21:16:37 +01:00
sandwich
ba6be037ac
refactor(virt): adopt module_defaults for hypervisor credentials
2026-02-20 21:16:33 +01:00
sandwich
5ca1c7f570
refactor(cleanup): restructure dispatch to use hypervisor_type include
2026-02-20 21:16:28 +01:00
sandwich
cd8e477534
refactor(partitioning): extract VG name to defaults variable
2026-02-20 21:16:25 +01:00
sandwich
c439e9741e
fix(configuration): remove trailing blank line from extras.yml
2026-02-20 20:20:33 +01:00
sandwich
0a5c70e49f
docs(environment): document RPM GPG policy relaxation
2026-02-20 20:19:57 +01:00
sandwich
19f2c9efe2
chore(bootstrap): align ansible.cfg with main project settings
2026-02-20 20:19:46 +01:00
sandwich
230c74fd9b
feat(system_check): add safety check for physical installs
2026-02-20 20:19:37 +01:00
sandwich
a2c19e2e49
fix(cleanup): fix vmware CD-ROM omit fragility and add cross-role defaults
2026-02-20 20:19:25 +01:00
sandwich
9f9a4b38b8
fix(virtualization): add XML safety attributes and switch xen to virtio
2026-02-20 20:18:49 +01:00
sandwich
524356cf8d
fix(cis): remove deprecated sshd options and update hardening values
2026-02-20 20:17:52 +01:00
sandwich
a2993212ca
fix(configuration): disambiguate BLS task names and clean up misc noise
2026-02-20 20:17:05 +01:00
sandwich
fba2e5fc94
refactor(configuration): relocate login banner and fix blockinfile markers
2026-02-20 20:16:19 +01:00
sandwich
cf68a93b45
fix(configuration): use short hostname and allow per-user shell
2026-02-20 20:15:49 +01:00
sandwich
3000268a0e
fix(partitioning): mount extra disks by UUID instead of device path
2026-02-20 20:15:25 +01:00
sandwich
196c5be67a
fix(partitioning): correct LVM swap sizing and harden UUID fallbacks
2026-02-20 20:15:00 +01:00
sandwich
33bad193b4
fix(configuration): add trailing semicolons to NM keyfile DNS fields
2026-02-20 20:14:06 +01:00
sandwich
d5277802f7
fix(bootstrap): add missing packages and remove duplicates
2026-02-20 20:13:53 +01:00
sandwich
28e6cf50d1
fix(bootstrap): add devpts mount and use ephemeral state for RHEL DVD
2026-02-20 20:12:59 +01:00
sandwich
42cb5071c2
fix(bootstrap): unify resolv.conf to live environment DNS symlink
2026-02-20 20:12:42 +01:00
sandwich
23a798a63a
fix(global_defaults): add no_log to hypervisor tasks and expand validation
2026-02-20 20:11:37 +01:00
sandwich
5dd84c6b39
fix: configurable OVMF/machine type, routes syntax, package lists, interface names
2026-02-20 18:47:12 +01:00
sandwich
d0ae20911b
fix(cleanup): keep RHEL ISO ide1 attached as local repo
2026-02-20 18:41:40 +01:00
sandwich
b6d06dd96d
fix: deep analysis audit — no_log, resolv.conf, service conflicts, lint
2026-02-20 18:34:59 +01:00
sandwich
09b3ed44ba
fix(bootstrap): RHEL 9 bootstrap from Arch ISO compatibility
...
- Generate resolv.conf from inventory DNS settings instead of copying
host file (Arch ISO has systemd-resolved stub 127.0.0.53)
- Add XFS compat options for GRUB 2.06 and kernel 5.14 across LVM
volumes, /boot partition, and data disks
- Mount API filesystems (proc, sys, dev) into chroot for RPM scriptlets
- Bypass GPG Sequoia validation with _pkgverify_level none
- Tolerate grub2-common scriptlet warnings
- Handle libvirt VM destroy gracefully during cleanup
2026-02-20 16:58:59 +01:00
sandwich
603abe63cb
refactor: make bootstrap host target configurable
2026-02-20 16:58:59 +01:00
sandwich
1c0e6533ae
fix(ubuntu): add initramfs-tools to debootstrap base packages
2026-02-20 16:58:59 +01:00
sandwich
00aa614cfd
fix(bootstrap): use explicit keyring for debootstrap and copy resolv.conf
2026-02-20 16:58:59 +01:00
sandwich
4905d10bc0
fix(cloud-init): handle boolean sudo values in user-data template
2026-02-20 16:58:59 +01:00
sandwich
b4e8ccb77f
fix: re-gather facts after reboot to detect target OS package manager
...
The live ISO (Arch) caches ansible_pkg_mgr=pacman. After rebooting
into the target OS (e.g. Debian), package module fails because pacman
is not available. Re-gather minimal facts including pkg_mgr.
2026-02-20 16:58:59 +01:00
sandwich
2a82ee4d5c
fix: resolve Jinja2 .keys ambiguity, fastfetch availability, and python interpreter
...
- Use bracket notation item['keys'] instead of item.keys to avoid
conflict with Python dict .keys() method
- Remove fastfetch from Debian 12 package list (only available in 13+)
- Set explicit python interpreter path for post-reboot tasks
2026-02-20 16:58:58 +01:00
sandwich and Claude Opus 4.6
7b213e7456
fix(partitioning): create separate /boot for LVM-based filesystems
...
VMware EFI firmware may not initialize all SCSI devices before GRUB
runs, preventing LVM assembly when the root LV spans multiple disks.
A separate /boot partition (the standard RHEL Anaconda layout) lets
GRUB load kernels without LVM; the kernel initramfs handles LVM
activation with proper device waiting.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-02-20 04:50:32 +01:00
sandwich and Claude Opus 4.6
cfc261878a
fix(bootloader): run efibootmgr on host for universal chroot compatibility
...
The previous approach ran efibootmgr inside the chroot, which only works
with arch-chroot (auto-mounts efivars) but fails silently with
systemd-nspawn or plain chroot. Move EFI boot entry creation to the host
where efivars is always available.
Also fixes wrong EFI loader path (\efi\EFI\... -> \EFI\...) and uses
the correct vendor label (e.g. "redhat" instead of raw os variable).
For non-RHEL distros, grub-install now uses --no-nvram to avoid
redundant NVRAM writes; the host efibootmgr handles entry creation
for all distros uniformly with idempotent pre-check.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com >
2026-02-20 03:36:20 +01:00
sandwich
eeb580f180
refactor(standardize): fix sudoers lecture syntax, extract ssh config, remove redundant os filters
2026-02-13 00:22:59 +01:00
sandwich
af5eecfc01
fix(configuration): correct fstab regexp escaping, sudoers newline, locales block scope
2026-02-13 00:02:54 +01:00
sandwich
bc43b3b994
refactor(standardize): remove redundant variables, deduplicate conditionals
2026-02-12 23:47:41 +01:00
sandwich
29d365293c
fix(banner): correct visudo validate, clean trailing whitespace
2026-02-12 23:33:55 +01:00
sandwich
c8806c9577
refactor(standardize): remove dead code, fix inconsistencies, update docs
2026-02-12 23:21:51 +01:00
sandwich
debd1e176f
refactor(bootstrap): standardize patterns, extract common logic, remove dead code
2026-02-12 23:14:17 +01:00
sandwich
8f8ce341ae
refactor(users): migrate system.user to system.users[] for multi-user support
2026-02-12 22:52:15 +01:00
sandwich
66057bc9b2
feat(network): make interfaces[] canonical, normalize flat fields as AWX compat
2026-02-12 22:17:02 +01:00
sandwich
5108e46a4c
fix(lint): wrap long lines to satisfy yaml[line-length] rule
2026-02-12 21:54:09 +01:00
sandwich
67c320fcc2
fix(vars): enforce strict list-only DNS and user.key format for IaC compatibility
2026-02-12 21:50:55 +01:00
sandwich
673a9b6062
fix(playbook): reset SSH connection before post-reboot tasks
2026-02-12 02:06:58 +01:00
sandwich
f8eaa41fc2
fix(partitioning): register swapoff result for changed_when handling
2026-02-11 23:47:36 +01:00
sandwich
ed8da6e4e2
fix(luks): complete migration of partitioning_luks_tpm2_device reference
2026-02-11 23:28:05 +01:00
sandwich
a60e6fd0d3
refactor(bootstrap): nest network fields under system.network to match main project schema
2026-02-11 23:03:37 +01:00
sandwich
45c002c2dd
fix(bootstrap): correct changed_when on state-changing commands
2026-02-11 21:06:10 +01:00