Actions
Support #380
openSupport #311: OAM - Security Hardening Auditing and Compliance
OAM: FetchApply/NewServerBuild.sh -> KNELIAC migration
Support #380:
OAM: FetchApply/NewServerBuild.sh -> KNELIAC migration
Start date:
08/06/2026
Due date:
% Done:
0%
Estimated time:
Description
Parent/umbrella: #311 (OAM - Security Hardening Auditing and Compliance).
Convert the legacy NewServerBuild.sh / FetchApply setup into KNELIAC ansible playbooks and roles. This becomes the canonical, idempotent server-build + hardening framework.
Scope¶
- Port NewServerBuild.sh -> KNELIAC ansible roles
- Add lshw to the setup scripts
- Add ansible/salt to the FetchApply setup scripts
- Ensure roles are runnable via tsys-awx (AWX)
Context¶
- KNELIAC repo: /home/reachableceo/projects/KNELIAC/
- Existing roles (from parent note): security_ssh, security_scap_stig, security_wazuh, security_2fa.
- auditd/journald role currently disabled by default (run_security_audit=false).
- Intended to be iterated on by AI as it goes.
Dependencies¶
No dependencies. Feeds roles into #381, #382, #384 and all role-based work.
Actions