{"id":162,"sha1":"df0f105ee87e13af1bd0bf50bd3478ce4545754b","playbook":{"id":2,"items":{"plays":18,"tasks":608,"results":2412,"hosts":15,"files":158,"records":0},"arguments":{"version":null,"verbosity":0,"private_key_file":null,"remote_user":null,"connection":"openstack.osa.ssh","timeout":null,"ssh_common_args":null,"sftp_extra_args":null,"scp_extra_args":null,"ssh_extra_args":null,"ask_pass":false,"connection_password_file":null,"force_handlers":true,"flush_cache":false,"become":false,"become_method":"sudo","become_user":null,"become_ask_pass":false,"become_password_file":null,"tags":["all"],"skip_tags":[],"check":false,"diff":false,"inventory":["/home/zuul/src/opendev.org/openstack/openstack-ansible/inventory/dynamic_inventory.py","/home/zuul/src/opendev.org/openstack/openstack-ansible/inventory/inventory.ini","/etc/openstack_deploy/inventory.ini"],"listhosts":false,"subset":null,"extra_vars":"Not saved by ARA as configured by 'ignored_arguments'","vault_ids":[],"ask_vault_pass":false,"vault_password_files":[],"forks":4,"module_path":null,"syntax":false,"listtasks":false,"listtags":false,"step":false,"start_at_task":null,"args":["setup-hosts.yml"]},"labels":[{"id":1,"name":"check:False"},{"id":2,"name":"tags:all"}],"started":"2025-12-08T13:40:18.992997Z","ended":"2025-12-08T13:50:25.791366Z","duration":"00:10:06.798369","name":null,"ansible_version":"2.18.6","client_version":"1.7.4","python_version":"3.12.11","server_version":"1.7.4","status":"completed","path":"/home/zuul/src/opendev.org/openstack/openstack-ansible/playbooks/setup-hosts.yml","controller":"aio1.openstack.local","user":"root"},"content":"---\n# Copyright 2015, Rackspace US, Inc.\n#\n# Licensed under the Apache License, Version 2.0 (the \"License\");\n# you may not use this file except in compliance with the License.\n# You may obtain a copy of the License at\n#\n#     http://www.apache.org/licenses/LICENSE-2.0\n#\n# Unless required by applicable law or agreed to in writing, software\n# distributed under the License is distributed on an \"AS IS\" BASIS,\n# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.\n# See the License for the specific language governing permissions and\n# limitations under the License.\n\n- name: Gather variables for each operating system\n  ansible.builtin.include_vars: \"{{ lookup('first_found', params) }}\"\n  vars:\n    params:\n      files:\n        - \"{{ ansible_facts['distribution'] | lower }}-{{ ansible_facts['distribution_version'] | lower }}.yml\"\n        - \"{{ ansible_facts['distribution'] | lower }}-{{ ansible_facts['distribution_major_version'] | lower }}.yml\"\n        - \"{{ ansible_facts['os_family'] | lower }}-{{ ansible_facts['distribution_major_version'] | lower }}.yml\"\n        - \"{{ ansible_facts['distribution'] | lower }}.yml\"\n        - \"{{ ansible_facts['os_family'] | lower }}-{{ ansible_facts['distribution_version'].split('.')[0] }}.yml\"\n        - \"{{ ansible_facts['os_family'] | lower }}.yml\"\n      paths:\n        - \"{{ role_path }}/vars\"\n  tags:\n    - always\n\n- name: Check for check/audit mode\n  ansible.builtin.command: /bin/true\n  register: noop_result\n  changed_when: false\n  tags:\n    - always\n\n- name: Check to see if we are booting with EFI or UEFI\n  ansible.builtin.set_fact:\n    booted_with_efi: \"{{ ansible_facts['mounts'] | selectattr('mount', 'equalto', '/boot/efi') | list | length > 0 }}\"\n  tags:\n    - always\n\n- name: Set facts\n  ansible.builtin.set_fact:\n    check_mode: \"{{ noop_result is skipped }}\" # noqa: var-naming[no-reserved]\n    linux_security_module: \"{{ (ansible_facts['os_family'] == 'Debian') | ternary('apparmor', 'selinux') }}\"\n    grub_config_file_boot: \"{{ booted_with_efi | ternary(grub_conf_file_efi, grub_conf_file) }}\"\n  tags:\n    - always\n\n- name: Check if grub is present on the remote node\n  ansible.builtin.stat:\n    path: \"{{ grub_update_cmd.split(' ')[0] }}\"\n  register: grub_update_binary\n  tags:\n    - always\n\n- name: Importing STIG tasks\n  ansible.builtin.import_tasks: \"{{ stig_version }}stig/main.yml\"\n- name: Including contrib tasks\n  ansible.builtin.include_tasks: contrib/main.yml\n  when:\n    - security_contrib_enabled | bool\n","created":"2025-12-08T13:49:28.987578Z","updated":"2025-12-08T13:49:28.987590Z","path":"/home/zuul/src/opendev.org/openstack/ansible-hardening/tasks/main.yml"}