Fix yamllint issues

This commit is contained in:
saibotk 2021-03-05 13:02:55 +01:00
parent a93c313704
commit 951dbeb41d
Signed by: saibotk
GPG key ID: 67585F0065E261D5
36 changed files with 85 additions and 88 deletions

View file

@ -1,4 +1,4 @@
--- ---
collections: collections:
- name: devsec.hardening - name: devsec.hardening
version: 7.1.0 version: 7.1.0

View file

@ -47,8 +47,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ camo_install_location }}" project_src: "{{ camo_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- camo - camo
become: true become: true

View file

@ -50,7 +50,7 @@
become: true become: true
- name: Create data directory - name: Create data directory
file: # noqa 208 # Container adjusts permissions on its own file: # noqa risky-file-permissions # Container adjusts permissions on its own
path: "{{ item.location }}" path: "{{ item.location }}"
state: directory state: directory
setype: "container_file_t" setype: "container_file_t"
@ -83,8 +83,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ codimd_install_location }}" project_src: "{{ codimd_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- codimd - codimd
become: true become: true

View file

@ -18,7 +18,7 @@
- name: Prune docker images older than 3 days - name: Prune docker images older than 3 days
docker_prune: docker_prune:
images: yes images: true
images_filters: images_filters:
dangling: false dangling: false
until: 72h until: 72h

View file

@ -47,8 +47,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ docker_ipv6_nat_install_location }}" project_src: "{{ docker_ipv6_nat_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- docker - docker
- docker-ipv6-nat - docker-ipv6-nat

View file

@ -72,8 +72,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ factorio_install_location }}" project_src: "{{ factorio_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- factorio - factorio
become: true become: true

View file

@ -21,7 +21,7 @@
package: package:
name: "{{ fail2ban_package }}" name: "{{ fail2ban_package }}"
state: "{{ fail2ban_package_state }}" state: "{{ fail2ban_package_state }}"
become: yes become: true
- name: Deploy fail2ban jail config. - name: Deploy fail2ban jail config.
template: template:
@ -31,11 +31,11 @@
owner: 'root' owner: 'root'
group: 'root' group: 'root'
notify: restart fail2ban service notify: restart fail2ban service
become: yes become: true
- name: Ensure fail2ban service is enabled and started. - name: Ensure fail2ban service is enabled and started.
service: service:
name: fail2ban name: fail2ban
state: started state: started
enabled: yes enabled: true
become: yes become: true

View file

@ -45,7 +45,7 @@
become: true become: true
- name: Create data directory - name: Create data directory
file: # noqa 208 # Container manages permissions on its own file: # noqa risky-file-permissions # Container manages permissions on its own
path: "{{ item }}" path: "{{ item }}"
state: directory state: directory
owner: 'root' owner: 'root'
@ -76,8 +76,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ gitlab_install_location }}" project_src: "{{ gitlab_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- gitlab - gitlab
become: true become: true

View file

@ -77,8 +77,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ gitlabrunner_config_location }}" project_src: "{{ gitlabrunner_config_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- gitlab-runner - gitlab-runner
become: true become: true

View file

@ -28,5 +28,5 @@
service: service:
state: started state: started
name: haveged name: haveged
enabled: yes enabled: true
become: true become: true

View file

@ -43,7 +43,7 @@
become: true become: true
- name: Create data directory - name: Create data directory
file: # noqa 208 # Container manages permissions on its own file: # noqa risky-file-permissions # Container manages permissions on its own
path: "{{ item }}" path: "{{ item }}"
state: directory state: directory
setype: "container_file_t" setype: "container_file_t"
@ -71,8 +71,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ keycloak_install_location }}" project_src: "{{ keycloak_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- keycloak - keycloak
become: true become: true

View file

@ -118,8 +118,8 @@
- name: Disable rhel-import-state service, so that it doesn not overwrite ifcfg scripts. - name: Disable rhel-import-state service, so that it doesn not overwrite ifcfg scripts.
systemd: systemd:
name: "rhel-import-state" name: "rhel-import-state"
enabled: no enabled: false
masked: yes masked: true
become: true become: true
when: when:
- luks_ssh_disable_state_import - luks_ssh_disable_state_import

View file

@ -69,7 +69,7 @@
- name: Start & enable backup service timer. - name: Start & enable backup service timer.
systemd: systemd:
daemon_reload: yes daemon_reload: true
name: backup-lvm.timer name: backup-lvm.timer
enabled: '{{ backup_timer_enabled | bool }}' enabled: '{{ backup_timer_enabled | bool }}'
state: '{{ backup_timer_state }}' state: '{{ backup_timer_state }}'

View file

@ -44,7 +44,7 @@
become: true become: true
- name: Create data directories - name: Create data directories
file: # noqa 208 # Container manages permissions on its own file: # noqa risky-file-permissions # Container manages permissions on its own
path: "{{ item }}" path: "{{ item }}"
state: directory state: directory
setype: "container_file_t" setype: "container_file_t"
@ -78,7 +78,7 @@
- name: Check if migration is needed - name: Check if migration is needed
command: "grep -q 'tootsuite/mastodon:{{ mastodon_image_version }}' '{{ mastodon_install_location }}/docker-compose.yml'" command: "grep -q 'tootsuite/mastodon:{{ mastodon_image_version }}' '{{ mastodon_install_location }}/docker-compose.yml'"
register: mastodon_version_fact register: mastodon_version_fact
ignore_errors: yes ignore_errors: true
changed_when: mastodon_version_fact.rc > 0 changed_when: mastodon_version_fact.rc > 0
failed_when: false failed_when: false
become: true become: true
@ -98,7 +98,7 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ mastodon_install_location }}" project_src: "{{ mastodon_install_location }}"
stopped: yes stopped: true
tags: tags:
- docker - docker
- mastodon - mastodon
@ -159,8 +159,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ mastodon_install_location }}" project_src: "{{ mastodon_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- docker - docker
- mastodon - mastodon

View file

@ -24,7 +24,7 @@
- delegate - delegate
state: present state: present
project_src: "{{ matrix_install_location }}" project_src: "{{ matrix_install_location }}"
restarted: yes restarted: true
tags: tags:
- docker - docker
- matrix - matrix
@ -36,7 +36,7 @@
- appservice-webhooks - appservice-webhooks
state: present state: present
project_src: "{{ matrix_install_location }}" project_src: "{{ matrix_install_location }}"
restarted: yes restarted: true
tags: tags:
- docker - docker
- matrix - matrix

View file

@ -44,7 +44,7 @@
become: true become: true
- name: Create data directory - name: Create data directory
file: # noqa 208 # Container manages permissions on its own file: # noqa risky-file-permissions # Container manages permissions on its own
path: "{{ item }}" path: "{{ item }}"
state: directory state: directory
setype: "container_file_t" setype: "container_file_t"
@ -176,8 +176,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ matrix_install_location }}" project_src: "{{ matrix_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- docker - docker
- matrix - matrix

View file

@ -43,7 +43,7 @@
- minecraft - minecraft
- name: Create data directories - name: Create data directories
file: # noqa 208 # Container manages permissions on its own file: # noqa risky-file-permissions # Container manages permissions on its own
path: "{{ item }}" path: "{{ item }}"
state: directory state: directory
setype: "container_file_t" setype: "container_file_t"
@ -83,8 +83,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ minecraft_install_location }}" project_src: "{{ minecraft_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- minecraft - minecraft
become: true become: true

View file

@ -136,7 +136,7 @@
- name: Start & enable render service timer - name: Start & enable render service timer
systemd: systemd:
daemon_reload: yes daemon_reload: true
name: blockmap-render.timer name: blockmap-render.timer
enabled: '{{ minecraft_blockmap_timer_enabled | bool }}' enabled: '{{ minecraft_blockmap_timer_enabled | bool }}'
state: '{{ minecraft_blockmap_timer_state }}' state: '{{ minecraft_blockmap_timer_state }}'
@ -146,8 +146,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ minecraft_blockmap_install_location }}" project_src: "{{ minecraft_blockmap_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- blockmap - blockmap
become: true become: true

View file

@ -89,8 +89,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ minio_install_location }}" project_src: "{{ minio_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- minio - minio
become: true become: true

View file

@ -21,7 +21,7 @@
service: service:
name: "docker" name: "docker"
state: "{{ moby_engine_docker_restart_handler_state }}" state: "{{ moby_engine_docker_restart_handler_state }}"
become: yes become: true
- name: Regenerate grub config BIOS - name: Regenerate grub config BIOS
command: grub2-mkconfig -o /etc/grub2.cfg command: grub2-mkconfig -o /etc/grub2.cfg

View file

@ -24,11 +24,11 @@
login_password: "{{ monitoring_influxdb_admin_password }}" login_password: "{{ monitoring_influxdb_admin_password }}"
hostname: "{{ monitoring_influxdb_domain }}" hostname: "{{ monitoring_influxdb_domain }}"
port: 443 port: 443
ssl: yes ssl: true
validate_certs: yes validate_certs: true
database_name: "{{ database.name }}" database_name: "{{ database.name }}"
delegate_to: 127.0.0.1 delegate_to: 127.0.0.1
no_log: True no_log: true
- name: Create retention policies - name: Create retention policies
influxdb_retention_policy: influxdb_retention_policy:
@ -36,8 +36,8 @@
login_password: "{{ monitoring_influxdb_admin_password }}" login_password: "{{ monitoring_influxdb_admin_password }}"
hostname: "{{ monitoring_influxdb_domain }}" hostname: "{{ monitoring_influxdb_domain }}"
port: 443 port: 443
ssl: yes ssl: true
validate_certs: yes validate_certs: true
database_name: "{{ database.name }}" database_name: "{{ database.name }}"
policy_name: "{{ policy.name }}" policy_name: "{{ policy.name }}"
duration: "{{ policy.duration }}" duration: "{{ policy.duration }}"

View file

@ -24,13 +24,13 @@
login_password: "{{ monitoring_influxdb_admin_password }}" login_password: "{{ monitoring_influxdb_admin_password }}"
hostname: "{{ monitoring_influxdb_domain }}" hostname: "{{ monitoring_influxdb_domain }}"
port: 443 port: 443
ssl: yes ssl: true
validate_certs: yes validate_certs: true
user_name: "{{ monitoring_influxdb_admin_username }}" user_name: "{{ monitoring_influxdb_admin_username }}"
user_password: "{{ monitoring_influxdb_admin_password }}" user_password: "{{ monitoring_influxdb_admin_password }}"
admin: yes admin: true
delegate_to: 127.0.0.1 delegate_to: 127.0.0.1
no_log: True no_log: true
- name: Configure databases - name: Configure databases
include: database.yml include: database.yml
@ -45,11 +45,11 @@
login_password: "{{ monitoring_influxdb_admin_password }}" login_password: "{{ monitoring_influxdb_admin_password }}"
hostname: "{{ monitoring_influxdb_domain }}" hostname: "{{ monitoring_influxdb_domain }}"
port: 443 port: 443
ssl: yes ssl: true
validate_certs: yes validate_certs: true
user_name: "{{ item.username }}" user_name: "{{ item.username }}"
user_password: "{{ item.password }}" user_password: "{{ item.password }}"
grants: "{{ item.grants }}" grants: "{{ item.grants }}"
loop: "{{ monitoring_influxdb_users }}" loop: "{{ monitoring_influxdb_users }}"
delegate_to: 127.0.0.1 delegate_to: 127.0.0.1
no_log: True no_log: true

View file

@ -76,8 +76,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ monitoring_install_location }}" project_src: "{{ monitoring_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
register: monitoring_compose register: monitoring_compose
become: true become: true

View file

@ -24,7 +24,7 @@
- owncast - owncast
state: present state: present
project_src: "{{ owncast_install_location }}" project_src: "{{ owncast_install_location }}"
restarted: yes restarted: true
tags: tags:
- docker - docker
- owncast - owncast

View file

@ -81,8 +81,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ owncast_install_location }}" project_src: "{{ owncast_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- owncast - owncast
become: true become: true

View file

@ -40,7 +40,7 @@
become: true become: true
- name: Create data directories - name: Create data directories
file: # noqa 208 # Container manages permissions on its own file: # noqa risky-file-permissions # Container manages permissions on its own
path: "{{ item }}" path: "{{ item }}"
state: directory state: directory
setype: "container_file_t" setype: "container_file_t"
@ -66,8 +66,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ penpot_install_location }}" project_src: "{{ penpot_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- docker - docker
- penpot - penpot

View file

@ -20,5 +20,3 @@
- name: Reload firewalld - name: Reload firewalld
command: "firewall-cmd --reload" command: "firewall-cmd --reload"
become: true become: true

View file

@ -49,8 +49,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ static_websites_install_location }}" project_src: "{{ static_websites_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
become: true become: true
when: when:
- static_websites | length > 0 - static_websites | length > 0

View file

@ -41,7 +41,7 @@
become: true become: true
- name: Create data directory - name: Create data directory
file: # noqa 208 # Container manages permissions on its own file: # noqa risky-file-permissions # Container manages permissions on its own
path: "{{ item }}" path: "{{ item }}"
state: directory state: directory
setype: "container_file_t" setype: "container_file_t"
@ -69,8 +69,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ teamspeak_install_location }}" project_src: "{{ teamspeak_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- docker - docker
- teamspeak - teamspeak

View file

@ -19,6 +19,6 @@
- name: Restart telegraf - name: Restart telegraf
docker_compose: docker_compose:
project_src: "{{ telegraf_install_location }}" project_src: "{{ telegraf_install_location }}"
restarted: yes restarted: true
become: true become: true

View file

@ -73,6 +73,6 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ telegraf_install_location }}" project_src: "{{ telegraf_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
become: true become: true

View file

@ -73,7 +73,7 @@
- name: Create ipv6 frontend network - name: Create ipv6 frontend network
docker_network: docker_network:
name: "{{ traefik_ipv6.name }}" name: "{{ traefik_ipv6.name }}"
enable_ipv6: yes enable_ipv6: true
ipam_config: ipam_config:
- subnet: "{{ traefik_ipv6.subnet }}" - subnet: "{{ traefik_ipv6.subnet }}"
become: true become: true
@ -129,8 +129,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ traefik_install_location }}" project_src: "{{ traefik_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
become: true become: true
- name: Read tor hostname - name: Read tor hostname

View file

@ -72,8 +72,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ ts3audiobot_install_location }}" project_src: "{{ ts3audiobot_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- docker - docker
- ts3audiobot - ts3audiobot

View file

@ -42,7 +42,7 @@
become: true become: true
- name: Create data directory - name: Create data directory
file: # noqa 208 # Container manages permissions on its own file: # noqa risky-file-permissions # Container manages permissions on its own
path: "{{ item }}" path: "{{ item }}"
state: directory state: directory
setype: "container_file_t" setype: "container_file_t"
@ -79,8 +79,8 @@
docker_compose: docker_compose:
state: present state: present
project_src: "{{ unicorns_website_install_location }}" project_src: "{{ unicorns_website_install_location }}"
pull: yes pull: true
remove_orphans: yes remove_orphans: true
tags: tags:
- docker - docker
become: true become: true

View file

@ -26,4 +26,3 @@
become: true become: true
- role: epel - role: epel
- role: fail2ban - role: fail2ban

View file

@ -30,7 +30,7 @@
registry: registry.git.saibotk.de registry: registry.git.saibotk.de
username: "{{ unicorns_website_registry_username }}" username: "{{ unicorns_website_registry_username }}"
password: "{{ unicorns_website_registry_password }}" password: "{{ unicorns_website_registry_password }}"
reauthorize: yes reauthorize: true
changed_when: false changed_when: false
become: true become: true