Compare commits

...

9 Commits

Author SHA1 Message Date
deabcf2f69 Merge pull request 'Usertwist update' (#6) from main into dev
Reviewed-on: #6
2024-07-30 12:54:52 +00:00
a5a4c6ab90 usertwist executable 2024-07-30 14:53:12 +02:00
8336445ae8 New version of usertwist 2024-07-30 14:51:51 +02:00
82151639ab Bootstrap get dev branch instead of main 2024-07-30 14:50:57 +02:00
2082ccb5b5 Hardened systemd unit (4.8 score) 2024-07-30 14:44:15 +02:00
5ebad367b4 Convert setup_iptables to ansible role + Fix usertwist group don't exist error 2024-07-30 14:06:48 +02:00
18f2d62a24 revert d84517026d
revert Added usertwist group
2024-07-30 12:02:42 +00:00
f1fea14b41 revert 46f876f5a4
revert Edit usertwist port
2024-07-30 12:02:30 +00:00
e136006c1c revert 70d8e574b9
revert Merge branch 'main' of git.athelas-conseils.fr:Stage/ansible_playbooks
2024-07-30 12:02:16 +00:00
6 changed files with 19 additions and 13 deletions

View File

@@ -24,7 +24,7 @@ sudo apt install git git-lfs -y
git lfs install
# Clone ansible_playbooks repo
git clone https://git.athelas-conseils.fr/Stage/ansible_playbooks.git
git clone -b dev https://git.athelas-conseils.fr/Stage/ansible_playbooks.git
~/.local/bin/ansible-playbook ansible_playbooks/tasks/full_setup.yml -i ansible_playbooks/inventory.ini --extra-vars "ansible_ssh_pass=$password ansible_ssh_common_args='-o StrictHostKeyChecking=no'"

BIN
files/usertwist (Stored with Git LFS)

Binary file not shown.

View File

@@ -5,6 +5,16 @@ Description=Simple Web Service
User=usertwist
Group=usertwist
ExecStart=/usr/local/bin/usertwist
PrivateTmp=yes
NoNewPrivileges=true
RestrictNamespaces=uts ipc pid user cgroup
ProtectSystem=strict
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
ProtectKernelTunables=yes
ProtectKernelModules=yes
ProtectControlGroups=yes
PrivateDevices=yes
RestrictSUIDSGID=true
[Install]
WantedBy=multi-user.target
WantedBy=multi-user.target

View File

@@ -60,11 +60,6 @@
enabled: true
state: started
- name: Edit usertwist default port
ansible.builtin.lineinfile:
path: /etc/environment
line: "PORT={{ usertwist_port | default('8080')}}"
- name: Restart Caddy service
ansible.builtin.service:
name: caddy

View File

@@ -1,7 +1,7 @@
galaxy_info:
author: your name
description: your role description
company: your company (optional)
author: Motysten
description: Dev
company: Athelas
# If the issue tracker for your role is not on github, uncomment the
# next line and provide a value

View File

@@ -1,5 +1,6 @@
- name: Edit iptables settings
hosts: athelas
become: true
roles:
- setup_iptables
- setup_iptables