File tree Expand file tree Collapse file tree 4 files changed +11
-14
lines changed
images/capi/ansible/roles Expand file tree Collapse file tree 4 files changed +11
-14
lines changed Original file line number Diff line number Diff line change 8989
9090- name : Configure auditd rules for containerd
9191 ansible.builtin.copy :
92- src : etc/audit/rules.d/containerd.rules
92+ src : " etc/audit/rules.d/containerd.rules{{ '-flatcar' if ansible_os_family == 'Flatcar' else '' }} "
9393 dest : /etc/audit/rules.d/containerd.rules
9494 owner : root
9595 group : root
9696 mode : " 0644"
97- when : ansible_os_family != "Flatcar" and enable_containerd_audit
98-
99- - name : Configure auditd rules for containerd (Flatcar)
100- ansible.builtin.copy :
101- src : etc/audit/rules.d/containerd.rules-flatcar
102- dest : /etc/audit/rules.d/containerd.rules
103- owner : root
104- group : root
105- mode : " 0644"
106- when : ansible_os_family == "Flatcar" and enable_containerd_audit
97+ when : enable_containerd_audit|default(false)|bool
10798
10899- name : Ensure reverse packet filtering is set as strict
109100 ansible.posix.sysctl :
Original file line number Diff line number Diff line change 3030 path : /etc/apt/sources.list.d/{{ item | basename }}
3131 state : absent
3232 loop : " {{ extra_repos.split() }}"
33- when : remove_extra_repos and extra_repos != ""
33+ when :
34+ - remove_extra_repos|default(false)|bool
35+ - extra_repos != ""
3436
3537- name : Find disabled repo files
3638 ansible.builtin.find :
Original file line number Diff line number Diff line change 3737 ansible.builtin.file :
3838 path : /etc/pip.conf
3939 state : absent
40- when : remove_extra_repos and pip_conf_file != ""
40+ when :
41+ - remove_extra_repos|default(false)|bool
42+ - pip_conf_file != ""
4143
4244- name : Truncate machine id
4345 ansible.builtin.file :
Original file line number Diff line number Diff line change 1717 path : /etc/yum.repos.d/{{ item | basename }}
1818 state : absent
1919 loop : " {{ extra_repos.split() }}"
20- when : remove_extra_repos and extra_repos != ""
20+ when :
21+ - remove_extra_repos|default(false)|bool
22+ - extra_repos != ""
2123
2224- name : Find disabled repo files
2325 ansible.builtin.find :
You can’t perform that action at this time.
0 commit comments