Project

General

Profile

Actions

Support #380

open

Support #311: OAM - Security Hardening Auditing and Compliance

OAM: FetchApply/NewServerBuild.sh -> KNELIAC migration

Support #380: OAM: FetchApply/NewServerBuild.sh -> KNELIAC migration

Added by Charles N 1 day ago. Updated 1 day ago.

Status:
Feedback
Priority:
Normal
Assignee:
Target version:
-
Start date:
08/06/2026
Due date:
% Done:

0%

Estimated time:

Description

Parent/umbrella: #311 (OAM - Security Hardening Auditing and Compliance).

Convert the legacy NewServerBuild.sh / FetchApply setup into KNELIAC ansible playbooks and roles. This becomes the canonical, idempotent server-build + hardening framework.

Scope

  • Port NewServerBuild.sh -> KNELIAC ansible roles
  • Add lshw to the setup scripts
  • Add ansible/salt to the FetchApply setup scripts
  • Ensure roles are runnable via tsys-awx (AWX)

Context

  • KNELIAC repo: /home/reachableceo/projects/KNELIAC/
  • Existing roles (from parent note): security_ssh, security_scap_stig, security_wazuh, security_2fa.
  • auditd/journald role currently disabled by default (run_security_audit=false).
  • Intended to be iterated on by AI as it goes.

Dependencies

No dependencies. Feeds roles into #381, #382, #384 and all role-based work.

Updated by Charles N 1 day ago Actions #1

  • Status changed from New to Feedback

Updated by Charles N 1 day ago Actions #2

  • Description updated (diff)
Actions

Also available in: PDF Atom