Some checks failed
Ansible Testing / lint (push) Has been cancelled
Ansible Testing / test (default) (push) Has been cancelled
Ansible Testing / test (minimal) (push) Has been cancelled
Ansible Testing / test (performance) (push) Has been cancelled
Ansible Testing / deploy-check (push) Has been cancelled
- Убраны пакеты: vim, jq, git, htop, tree из всех Dockerfile - Закомментированы установки Docker, Docker Compose, yq - Обновлен Rocky Linux до версии 9 с Python 3 - Исправлена проблема с passlib в ansible-controller - Оставлены только необходимые пакеты: systemd, curl, wget, nano, python3, sudo
83 lines
2.4 KiB
YAML
83 lines
2.4 KiB
YAML
---
|
||
#description: Пресет для тестирования безопасности с 10 хостами (bastion + internal + monitoring)
|
||
# Автор: Сергей Антропов
|
||
# Сайт: https://devops.org.ru
|
||
|
||
docker_network: labnet
|
||
generated_inventory: "{{ molecule_ephemeral_directory }}/inventory/hosts.ini"
|
||
|
||
# systemd-ready образы
|
||
images:
|
||
alt: "inecs/ansible-lab:alt-linux-latest"
|
||
astra: "inecs/ansible-lab:astra-linux-latest"
|
||
rhel: "inecs/ansible-lab:rhel-latest"
|
||
centos: "inecs/ansible-lab:centos-latest"
|
||
alma: "inecs/ansible-lab:alma-latest"
|
||
rocky: "inecs/ansible-lab:rocky-latest"
|
||
redos: "inecs/ansible-lab:redos-latest"
|
||
ubuntu: "inecs/ansible-lab:ubuntu-latest"
|
||
debian: "inecs/ansible-lab:debian-latest"
|
||
|
||
systemd_defaults:
|
||
privileged: true
|
||
command: "/sbin/init"
|
||
volumes:
|
||
- "/sys/fs/cgroup:/sys/fs/cgroup:rw"
|
||
tmpfs: ["/run", "/run/lock"]
|
||
capabilities: ["SYS_ADMIN"]
|
||
|
||
# Описание кластера для тестирования безопасности
|
||
hosts:
|
||
# Bastion хосты (точки входа)
|
||
- name: bastion1
|
||
family: rhel
|
||
groups: [bastion, security, jump]
|
||
publish: ["2222:22"]
|
||
- name: bastion2
|
||
family: debian
|
||
groups: [bastion, security, jump]
|
||
publish: ["2223:22"]
|
||
|
||
# Внутренние серверы (без внешнего доступа)
|
||
- name: internal1
|
||
family: rhel
|
||
groups: [internal, servers, app]
|
||
- name: internal2
|
||
family: debian
|
||
groups: [internal, servers, app]
|
||
- name: internal3
|
||
family: rhel
|
||
groups: [internal, servers, app]
|
||
|
||
# База данных (изолированная сеть)
|
||
- name: db-secure1
|
||
family: rhel
|
||
groups: [database, secure, internal]
|
||
- name: db-secure2
|
||
family: debian
|
||
groups: [database, secure, internal]
|
||
|
||
# Мониторинг и логирование
|
||
- name: monitor1
|
||
family: debian
|
||
groups: [monitoring, security, logs]
|
||
- name: monitor2
|
||
family: rhel
|
||
groups: [monitoring, security, logs]
|
||
|
||
# Firewall и сетевые компоненты
|
||
- name: fw1
|
||
family: rhel
|
||
groups: [firewall, network, security]
|
||
- name: fw2
|
||
family: debian
|
||
groups: [firewall, network, security]
|
||
|
||
# DOoD узел для тестирования Docker безопасности
|
||
- name: docker-secure
|
||
type: dood
|
||
family: debian
|
||
groups: [docker, security, apps]
|
||
publish: ["8080:8080"]
|
||
env:
|
||
DOCKER_HOST: "unix:///var/run/docker.sock" |