From ec3311057a9bd5e68c5af298474eb9d1b1d3b4e8 Mon Sep 17 00:00:00 2001 From: Prafull Date: Wed, 7 Jan 2026 23:01:10 +0530 Subject: [PATCH 01/19] Added ansible role and packaer configuration --- ansible/playbooks/configure.yml | 10 +++++ ansible/roles/base/defaults/main.yml | 12 ++++++ ansible/roles/base/handlers/main.yml | 0 ansible/roles/base/tasks/main.yml | 32 ++++++++++++++++ ansible/roles/hardening/defaults/main.yml | 4 ++ ansible/roles/hardening/handlers/main.yml | 5 +++ ansible/roles/hardening/tasks/main.yml | 25 ++++++++++++ .../roles/hardening/templates/sshd_config.j2 | 11 ++++++ ansible/roles/monitoring/defaults/main.yml | 1 + ansible/roles/monitoring/handlers/main.yml | 0 ansible/roles/monitoring/tasks/main.yml | 14 +++++++ packer/ubuntu/ubuntu.pkr.hcl | 38 +++++++++++++++++++ packer/ubuntu/variables.pkr.hcl | 38 +++++++++++++++++++ 13 files changed, 190 insertions(+) create mode 100644 ansible/playbooks/configure.yml create mode 100644 ansible/roles/base/defaults/main.yml create mode 100644 ansible/roles/base/handlers/main.yml create mode 100644 ansible/roles/base/tasks/main.yml create mode 100644 ansible/roles/hardening/defaults/main.yml create mode 100644 ansible/roles/hardening/handlers/main.yml create mode 100644 ansible/roles/hardening/tasks/main.yml create mode 100644 ansible/roles/hardening/templates/sshd_config.j2 create mode 100644 ansible/roles/monitoring/defaults/main.yml create mode 100644 ansible/roles/monitoring/handlers/main.yml create mode 100644 ansible/roles/monitoring/tasks/main.yml create mode 100644 packer/ubuntu/ubuntu.pkr.hcl create mode 100644 packer/ubuntu/variables.pkr.hcl diff --git a/ansible/playbooks/configure.yml b/ansible/playbooks/configure.yml new file mode 100644 index 0000000..8462a7b --- /dev/null +++ b/ansible/playbooks/configure.yml @@ -0,0 +1,10 @@ +--- +- name: Configure Azure Golden Image + hosts: all + become: yes + vars: + ansible_python_interpreter: /usr/bin/python3 + roles: + - base + - hardening + - monitoring \ No newline at end of file diff --git a/ansible/roles/base/defaults/main.yml b/ansible/roles/base/defaults/main.yml new file mode 100644 index 0000000..923a571 --- /dev/null +++ b/ansible/roles/base/defaults/main.yml @@ -0,0 +1,12 @@ +timezone: UTC + +base_packages: + - git + - curl + - wget + - apt-transport-https + - unzip + - net-tools + - ca-certificates + - gnupg + - software-properties-common \ No newline at end of file diff --git a/ansible/roles/base/handlers/main.yml b/ansible/roles/base/handlers/main.yml new file mode 100644 index 0000000..e69de29 diff --git a/ansible/roles/base/tasks/main.yml b/ansible/roles/base/tasks/main.yml new file mode 100644 index 0000000..78643ed --- /dev/null +++ b/ansible/roles/base/tasks/main.yml @@ -0,0 +1,32 @@ +--- + +- name: Set Timezone to UTC + command: timedatectl set-timezone {{ timezone | default('UTC') }} + args: + creates: "/etc/timezone" + +- name: Update apt cache + apt: + update_cache: yes + cache_valid_time: 3600 + +- name: Upgrade all packages + apt: + upgrade: dist + +- name: Install base packages + apt: + name: "{{ base_packages }}" + state: present + +- name: Enable automatice security updates + apt: + name: unattended-upgrades + state: present + +- name: Configure unattended-upgrades + copy: + dest: /etc/apt/apt.conf.d/20auto-upgrades + content: | + APT::Periodic::Update-Package-Lists "1"; + APT::Periodic::Unattended-Upgrade "1"; diff --git a/ansible/roles/hardening/defaults/main.yml b/ansible/roles/hardening/defaults/main.yml new file mode 100644 index 0000000..592993a --- /dev/null +++ b/ansible/roles/hardening/defaults/main.yml @@ -0,0 +1,4 @@ +--- +ssh_port: 22 +disble_root_login: true +password_authentication: false \ No newline at end of file diff --git a/ansible/roles/hardening/handlers/main.yml b/ansible/roles/hardening/handlers/main.yml new file mode 100644 index 0000000..9c4c94c --- /dev/null +++ b/ansible/roles/hardening/handlers/main.yml @@ -0,0 +1,5 @@ +--- +- name: Restart SSH + service: + name: ssh + state: restarted \ No newline at end of file diff --git a/ansible/roles/hardening/tasks/main.yml b/ansible/roles/hardening/tasks/main.yml new file mode 100644 index 0000000..7e84e84 --- /dev/null +++ b/ansible/roles/hardening/tasks/main.yml @@ -0,0 +1,25 @@ +--- +- name: Ensure UFW Insalled + apt: + name: ufw + state: present + +- name: Allow SSH + ufw: + rule: allow + port: "{{ ssh_port}}" + proto: tcp + +- name: Enable UFW + ufw: + state: enabled + policy: deny + +- name: Configure SSH hardening + template: + src: sshd_config.j2 + dest: /etc/ssh/sshd_config + owner: root + group: root + mode: '0600' + notify: Restart SSH \ No newline at end of file diff --git a/ansible/roles/hardening/templates/sshd_config.j2 b/ansible/roles/hardening/templates/sshd_config.j2 new file mode 100644 index 0000000..0284fef --- /dev/null +++ b/ansible/roles/hardening/templates/sshd_config.j2 @@ -0,0 +1,11 @@ +Port {{ ssh_port }} +Protocol 2 +PermitRootLogin {{ 'no' if disable_root_login else 'yes' }} +PasswordAuthentication {{ 'yes' if password_authentication else 'no' }} +ChallengeResponseAuthentication no +UsePAM yes +X11Forwarding no +AllowTcpForwarding no +ClientAliveInterval 300 +ClientAliveCountMax 2 +MaxAuthTries 3 \ No newline at end of file diff --git a/ansible/roles/monitoring/defaults/main.yml b/ansible/roles/monitoring/defaults/main.yml new file mode 100644 index 0000000..4668fc9 --- /dev/null +++ b/ansible/roles/monitoring/defaults/main.yml @@ -0,0 +1 @@ +install_azure_monitoring_agent: true \ No newline at end of file diff --git a/ansible/roles/monitoring/handlers/main.yml b/ansible/roles/monitoring/handlers/main.yml new file mode 100644 index 0000000..e69de29 diff --git a/ansible/roles/monitoring/tasks/main.yml b/ansible/roles/monitoring/tasks/main.yml new file mode 100644 index 0000000..1d377f4 --- /dev/null +++ b/ansible/roles/monitoring/tasks/main.yml @@ -0,0 +1,14 @@ +--- +- name: Install Azure Monitor Agent + when: install_azure_monitoring_agent + block: + - name: Download Azure Monitor Agent installation script + get_url: + url: https://aka.ms/InstallAzureMonitorAgentLinux + dest: /tmp/install_ama.sh + mode: '0755' + + - name: Install AMA + command: /tmp/install_ama.sh + args: + creates: /opt/microsoft/azuremonitoragent \ No newline at end of file diff --git a/packer/ubuntu/ubuntu.pkr.hcl b/packer/ubuntu/ubuntu.pkr.hcl new file mode 100644 index 0000000..c8cb4a5 --- /dev/null +++ b/packer/ubuntu/ubuntu.pkr.hcl @@ -0,0 +1,38 @@ +packer { + required_plugins { + azure = { + source = "github.com/hashicorp/azure" + version = "~> 2.0" + } + } +} + +source "azure-arm" "ubuntu" { + client_id = var.client_id + client_secret = var.client_secret + subscription_id = var.subscription_id + tenant_id = var.tenant_id + + managed_image_resource_group_name = var.resource_group + managed_image_name = "${var.image_name}-golden-${formatdate("DDMMMYY", timestamp())}" + + os_type = var.os_type + image_publisher = "Canonical" + image_offer = "0001-com-ubuntu-server-jammy" + image_sku = var.image_sku + + azure_tags = { + dept = "engineering" + } + + location = var.location + vm_size = "Standard_B1s" +} + +build { + sources = ["sources.azure-arm.ubuntu"] + + provisioner "ansible" { + playbook_file = "../../ansible/playbook.yml" + } +} \ No newline at end of file diff --git a/packer/ubuntu/variables.pkr.hcl b/packer/ubuntu/variables.pkr.hcl new file mode 100644 index 0000000..dfc2e9c --- /dev/null +++ b/packer/ubuntu/variables.pkr.hcl @@ -0,0 +1,38 @@ +variable "subscription_id"{ + type = string +} + +variable "client_id"{ + type = string + description = "Client_id" +} + +variable "client_secret"{ + type = string + description = "clinet secret" +} + +variable "tenant_id"{ + type = string + description ="tenent id" +} + +variable "image_name" { + default = "ubuntu-22_04-lts" +} + +variable "location" { + default = "West Europe" +} + +variable "resource_group" { + default = "TResourceGroup" +} + +variable "os_type" { + default = "Linux" +} + +variable "image_sku" { + default = "22.04-lts" +} \ No newline at end of file From e51f12c8ae5874de36d4a966810add4f93d9d03b Mon Sep 17 00:00:00 2001 From: Prafull Date: Thu, 8 Jan 2026 00:19:54 +0530 Subject: [PATCH 02/19] Added all the configuration --- .github/workflows/build-image.yml | 35 +++++++++++++++++++++++++++++++ .github/workflows/validate.yml | 11 ++++++++++ packer/ubuntu/ubuntu.pkr.hcl | 6 +----- packer/ubuntu/version.json | 6 ++++++ scripts/generate-metadata.sh | 3 +++ 5 files changed, 56 insertions(+), 5 deletions(-) create mode 100644 .github/workflows/build-image.yml create mode 100644 .github/workflows/validate.yml create mode 100644 packer/ubuntu/version.json create mode 100644 scripts/generate-metadata.sh diff --git a/.github/workflows/build-image.yml b/.github/workflows/build-image.yml new file mode 100644 index 0000000..9dc3038 --- /dev/null +++ b/.github/workflows/build-image.yml @@ -0,0 +1,35 @@ +on: + push: + branches: + - feature1 + +jobs: + build: + runs-on: ubuntu-latest + + steps: + - uses: actions/checkout@v4 + + - name: Azure Login + uses: azure/login@v2 + with : + creds: ${{ secrets.AZURE_CREDENTIALS }} + + - name: Set up Packer + uses: hashicorp/setup-packer@v3 + + - name: Build Golden Image + run: packer build packer/ubuntu + + # - name: Upload Golden Image to Storage Account + # run: | + # # Get the image URI from Packer output + # IMAGE_URI=$(packer build -machine-readable packer/ubuntu | grep 'artifact,0,id' | cut -d',' -f6) + + # # Upload to Azure Storage Account + # az storage blob upload \ + # --account-name ${{ secrets.STORAGE_ACCOUNT_NAME }} \ + # --container-name ${{ secrets.STORAGE_CONTAINER_NAME }} \ + # --name "golden-image-$(date +%Y%m%d-%H%M%S).vhd" \ + # --file "$IMAGE_URI" \ + # --auth-mode login \ No newline at end of file diff --git a/.github/workflows/validate.yml b/.github/workflows/validate.yml new file mode 100644 index 0000000..51ad17e --- /dev/null +++ b/.github/workflows/validate.yml @@ -0,0 +1,11 @@ +on: [pull_request] + +jobs: + validate: + runs-on: ubuntu-latest + + steps: + - uses: actions/checkout@v4 + - uses: hashicorp/setup-packer@v3 + - run: packer validate packer/ubuntu + - run: ansible-lint ansible \ No newline at end of file diff --git a/packer/ubuntu/ubuntu.pkr.hcl b/packer/ubuntu/ubuntu.pkr.hcl index c8cb4a5..5358170 100644 --- a/packer/ubuntu/ubuntu.pkr.hcl +++ b/packer/ubuntu/ubuntu.pkr.hcl @@ -21,10 +21,6 @@ source "azure-arm" "ubuntu" { image_offer = "0001-com-ubuntu-server-jammy" image_sku = var.image_sku - azure_tags = { - dept = "engineering" - } - location = var.location vm_size = "Standard_B1s" } @@ -33,6 +29,6 @@ build { sources = ["sources.azure-arm.ubuntu"] provisioner "ansible" { - playbook_file = "../../ansible/playbook.yml" + playbook_file = "../../ansible/playbooks/configure.yml" } } \ No newline at end of file diff --git a/packer/ubuntu/version.json b/packer/ubuntu/version.json new file mode 100644 index 0000000..2e920e0 --- /dev/null +++ b/packer/ubuntu/version.json @@ -0,0 +1,6 @@ +{ + "os": "ubuntu-22.04", + "version": "1.0.0", + "build_date": "" , + "git_commit": "" +} \ No newline at end of file diff --git a/scripts/generate-metadata.sh b/scripts/generate-metadata.sh new file mode 100644 index 0000000..e31530c --- /dev/null +++ b/scripts/generate-metadata.sh @@ -0,0 +1,3 @@ +export VERSION=$(jq -r '.version' ../packer/ubuntu/version.json) +export BUILD_DATE=$(date -u +"%Y-%m-%dT%H:%M:%SZ") +export GIT_COMMIT=$(git rev-parse --short HEAD) From 7220180968bc0426183e02132992a3988d522d81 Mon Sep 17 00:00:00 2001 From: Prafull Date: Thu, 8 Jan 2026 00:21:49 +0530 Subject: [PATCH 03/19] Added all the configuration --- .github/workflows/build-image.yml | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.github/workflows/build-image.yml b/.github/workflows/build-image.yml index 9dc3038..8e374d6 100644 --- a/.github/workflows/build-image.yml +++ b/.github/workflows/build-image.yml @@ -17,6 +17,9 @@ jobs: - name: Set up Packer uses: hashicorp/setup-packer@v3 + + - name: Packer Initialize + run: packer init packer/ubuntu - name: Build Golden Image run: packer build packer/ubuntu From 0488bab158b0f8bb1470060c9490ab0c46b565cc Mon Sep 17 00:00:00 2001 From: Prafull Date: Thu, 8 Jan 2026 00:31:21 +0530 Subject: [PATCH 04/19] fixed pipeline --- packer/ubuntu/ubuntu.pkr.hcl | 11 +++++++---- packer/ubuntu/values.pkrvars.hcl | 5 +++++ packer/ubuntu/variables.pkr.hcl | 19 ------------------- 3 files changed, 12 insertions(+), 23 deletions(-) create mode 100644 packer/ubuntu/values.pkrvars.hcl diff --git a/packer/ubuntu/ubuntu.pkr.hcl b/packer/ubuntu/ubuntu.pkr.hcl index 5358170..c9246dc 100644 --- a/packer/ubuntu/ubuntu.pkr.hcl +++ b/packer/ubuntu/ubuntu.pkr.hcl @@ -5,13 +5,16 @@ packer { version = "~> 2.0" } } + + required_plugins { + ansible = { + source = "github.com/hashicorp/ansible" + version = "~> 1.0" + } + } } source "azure-arm" "ubuntu" { - client_id = var.client_id - client_secret = var.client_secret - subscription_id = var.subscription_id - tenant_id = var.tenant_id managed_image_resource_group_name = var.resource_group managed_image_name = "${var.image_name}-golden-${formatdate("DDMMMYY", timestamp())}" diff --git a/packer/ubuntu/values.pkrvars.hcl b/packer/ubuntu/values.pkrvars.hcl new file mode 100644 index 0000000..4e4f817 --- /dev/null +++ b/packer/ubuntu/values.pkrvars.hcl @@ -0,0 +1,5 @@ +resource_group = "TResourceGroup" +location= "West Europe" +image_name="ubuntu-22_04-lts" +os_type="Linux" +image_sku="22.04-lts" \ No newline at end of file diff --git a/packer/ubuntu/variables.pkr.hcl b/packer/ubuntu/variables.pkr.hcl index dfc2e9c..05b8f38 100644 --- a/packer/ubuntu/variables.pkr.hcl +++ b/packer/ubuntu/variables.pkr.hcl @@ -1,22 +1,3 @@ -variable "subscription_id"{ - type = string -} - -variable "client_id"{ - type = string - description = "Client_id" -} - -variable "client_secret"{ - type = string - description = "clinet secret" -} - -variable "tenant_id"{ - type = string - description ="tenent id" -} - variable "image_name" { default = "ubuntu-22_04-lts" } From 2da0904df011c8ec6b3b542a3a8e023d9dd7dc4e Mon Sep 17 00:00:00 2001 From: Prafull Date: Thu, 8 Jan 2026 00:34:58 +0530 Subject: [PATCH 05/19] fixed pipeline --- .github/workflows/build-image.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build-image.yml b/.github/workflows/build-image.yml index 8e374d6..0fb8ba1 100644 --- a/.github/workflows/build-image.yml +++ b/.github/workflows/build-image.yml @@ -19,10 +19,10 @@ jobs: uses: hashicorp/setup-packer@v3 - name: Packer Initialize - run: packer init packer/ubuntu + run: packer init packer/ubuntu . - name: Build Golden Image - run: packer build packer/ubuntu + run: packer build packer/ubuntu . # - name: Upload Golden Image to Storage Account # run: | From 50348d023b02fba538b21c7347d6dde9d768a537 Mon Sep 17 00:00:00 2001 From: Prafull Date: Thu, 8 Jan 2026 00:35:57 +0530 Subject: [PATCH 06/19] fixed pipeline --- .github/workflows/build-image.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/build-image.yml b/.github/workflows/build-image.yml index 0fb8ba1..d1ec430 100644 --- a/.github/workflows/build-image.yml +++ b/.github/workflows/build-image.yml @@ -19,7 +19,7 @@ jobs: uses: hashicorp/setup-packer@v3 - name: Packer Initialize - run: packer init packer/ubuntu . + run: packer init packer/ubuntu - name: Build Golden Image run: packer build packer/ubuntu . From 77c3bb7f0946ab81cef6db3a46df07e7474500a3 Mon Sep 17 00:00:00 2001 From: Prafull Date: Thu, 8 Jan 2026 00:38:03 +0530 Subject: [PATCH 07/19] fixed ansible provisioner path --- packer/ubuntu/ubuntu.pkr.hcl | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packer/ubuntu/ubuntu.pkr.hcl b/packer/ubuntu/ubuntu.pkr.hcl index c9246dc..404761c 100644 --- a/packer/ubuntu/ubuntu.pkr.hcl +++ b/packer/ubuntu/ubuntu.pkr.hcl @@ -32,6 +32,6 @@ build { sources = ["sources.azure-arm.ubuntu"] provisioner "ansible" { - playbook_file = "../../ansible/playbooks/configure.yml" + playbook_file = "ansible/playbooks/configure.yml" } } \ No newline at end of file From 88b3f41b5b56d9843dc2c0e759553cd2a010c880 Mon Sep 17 00:00:00 2001 From: Prafull Date: Thu, 8 Jan 2026 00:42:39 +0530 Subject: [PATCH 08/19] fixed ansible provisioner path --- .github/workflows/build-image.yml | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build-image.yml b/.github/workflows/build-image.yml index d1ec430..a1ca613 100644 --- a/.github/workflows/build-image.yml +++ b/.github/workflows/build-image.yml @@ -21,8 +21,9 @@ jobs: - name: Packer Initialize run: packer init packer/ubuntu - - name: Build Golden Image - run: packer build packer/ubuntu . + + - name: Packer Build + run: packer build -var-file=packer/ubuntu/values.pkrvars.hcl packer/ubuntu # - name: Upload Golden Image to Storage Account # run: | From cd47e79d70faaa9ced81b14448184d574644cc92 Mon Sep 17 00:00:00 2001 From: Prafull Date: Thu, 8 Jan 2026 00:46:09 +0530 Subject: [PATCH 09/19] updated source block --- .github/workflows/build-image.yml | 3 +++ packer/ubuntu/ubuntu.pkr.hcl | 1 + 2 files changed, 4 insertions(+) diff --git a/.github/workflows/build-image.yml b/.github/workflows/build-image.yml index a1ca613..35bc55f 100644 --- a/.github/workflows/build-image.yml +++ b/.github/workflows/build-image.yml @@ -15,6 +15,9 @@ jobs: with : creds: ${{ secrets.AZURE_CREDENTIALS }} + - name: Verify Azure Login + run: az account show + - name: Set up Packer uses: hashicorp/setup-packer@v3 diff --git a/packer/ubuntu/ubuntu.pkr.hcl b/packer/ubuntu/ubuntu.pkr.hcl index 404761c..3cdf2bf 100644 --- a/packer/ubuntu/ubuntu.pkr.hcl +++ b/packer/ubuntu/ubuntu.pkr.hcl @@ -15,6 +15,7 @@ packer { } source "azure-arm" "ubuntu" { + use_azure_cli_auth = true managed_image_resource_group_name = var.resource_group managed_image_name = "${var.image_name}-golden-${formatdate("DDMMMYY", timestamp())}" From 7abb17ee0eca5672df2d284b657dfd348843b9c0 Mon Sep 17 00:00:00 2001 From: prafullb3 <42909468+prafullb3@users.noreply.github.com> Date: Thu, 8 Jan 2026 04:46:26 +0000 Subject: [PATCH 10/19] corrected image sku --- packer/ubuntu/values.pkrvars.hcl | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packer/ubuntu/values.pkrvars.hcl b/packer/ubuntu/values.pkrvars.hcl index 4e4f817..1b814cd 100644 --- a/packer/ubuntu/values.pkrvars.hcl +++ b/packer/ubuntu/values.pkrvars.hcl @@ -2,4 +2,4 @@ resource_group = "TResourceGroup" location= "West Europe" image_name="ubuntu-22_04-lts" os_type="Linux" -image_sku="22.04-lts" \ No newline at end of file +image_sku="server" \ No newline at end of file From 0f3adfdcdf53d8e1f5a3dcdfa3bf8302ed018ebf Mon Sep 17 00:00:00 2001 From: prafullb3 <42909468+prafullb3@users.noreply.github.com> Date: Thu, 8 Jan 2026 04:47:51 +0000 Subject: [PATCH 11/19] corrected image sku --- packer/ubuntu/values.pkrvars.hcl | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packer/ubuntu/values.pkrvars.hcl b/packer/ubuntu/values.pkrvars.hcl index 1b814cd..92190ef 100644 --- a/packer/ubuntu/values.pkrvars.hcl +++ b/packer/ubuntu/values.pkrvars.hcl @@ -2,4 +2,4 @@ resource_group = "TResourceGroup" location= "West Europe" image_name="ubuntu-22_04-lts" os_type="Linux" -image_sku="server" \ No newline at end of file +image_sku="22_04-lts-gen2" \ No newline at end of file From aa5803f59531febc89cda2db0522fdae246ee842 Mon Sep 17 00:00:00 2001 From: prafullb3 <42909468+prafullb3@users.noreply.github.com> Date: Thu, 8 Jan 2026 04:57:14 +0000 Subject: [PATCH 12/19] Added Roles path --- packer/ubuntu/ubuntu.pkr.hcl | 1 + 1 file changed, 1 insertion(+) diff --git a/packer/ubuntu/ubuntu.pkr.hcl b/packer/ubuntu/ubuntu.pkr.hcl index 3cdf2bf..0130626 100644 --- a/packer/ubuntu/ubuntu.pkr.hcl +++ b/packer/ubuntu/ubuntu.pkr.hcl @@ -34,5 +34,6 @@ build { provisioner "ansible" { playbook_file = "ansible/playbooks/configure.yml" + roles_path= "ansible/roles } } \ No newline at end of file From 681ab5c6cb84fb030bebbabd7dd7a20b7b02c34c Mon Sep 17 00:00:00 2001 From: prafullb3 <42909468+prafullb3@users.noreply.github.com> Date: Thu, 8 Jan 2026 04:58:25 +0000 Subject: [PATCH 13/19] Added Roles path --- packer/ubuntu/ubuntu.pkr.hcl | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/packer/ubuntu/ubuntu.pkr.hcl b/packer/ubuntu/ubuntu.pkr.hcl index 0130626..22b8d08 100644 --- a/packer/ubuntu/ubuntu.pkr.hcl +++ b/packer/ubuntu/ubuntu.pkr.hcl @@ -34,6 +34,6 @@ build { provisioner "ansible" { playbook_file = "ansible/playbooks/configure.yml" - roles_path= "ansible/roles + roles_path= "ansible/roles" } } \ No newline at end of file From aac31ef5b4d0067b4fdfdf75e5fd2c0e507b641a Mon Sep 17 00:00:00 2001 From: prafullb3 <42909468+prafullb3@users.noreply.github.com> Date: Thu, 8 Jan 2026 05:11:52 +0000 Subject: [PATCH 14/19] added configure.yml and roles in a folder --- ansible/{ => playbooks}/roles/base/defaults/main.yml | 0 ansible/{ => playbooks}/roles/base/handlers/main.yml | 0 ansible/{ => playbooks}/roles/base/tasks/main.yml | 0 ansible/{ => playbooks}/roles/hardening/defaults/main.yml | 0 ansible/{ => playbooks}/roles/hardening/handlers/main.yml | 0 ansible/{ => playbooks}/roles/hardening/tasks/main.yml | 0 ansible/{ => playbooks}/roles/hardening/templates/sshd_config.j2 | 0 ansible/{ => playbooks}/roles/monitoring/defaults/main.yml | 0 ansible/{ => playbooks}/roles/monitoring/handlers/main.yml | 0 ansible/{ => playbooks}/roles/monitoring/tasks/main.yml | 0 10 files changed, 0 insertions(+), 0 deletions(-) rename ansible/{ => playbooks}/roles/base/defaults/main.yml (100%) rename ansible/{ => playbooks}/roles/base/handlers/main.yml (100%) rename ansible/{ => playbooks}/roles/base/tasks/main.yml (100%) rename ansible/{ => playbooks}/roles/hardening/defaults/main.yml (100%) rename ansible/{ => playbooks}/roles/hardening/handlers/main.yml (100%) rename ansible/{ => playbooks}/roles/hardening/tasks/main.yml (100%) rename ansible/{ => playbooks}/roles/hardening/templates/sshd_config.j2 (100%) rename ansible/{ => playbooks}/roles/monitoring/defaults/main.yml (100%) rename ansible/{ => playbooks}/roles/monitoring/handlers/main.yml (100%) rename ansible/{ => playbooks}/roles/monitoring/tasks/main.yml (100%) diff --git a/ansible/roles/base/defaults/main.yml b/ansible/playbooks/roles/base/defaults/main.yml similarity index 100% rename from ansible/roles/base/defaults/main.yml rename to ansible/playbooks/roles/base/defaults/main.yml diff --git a/ansible/roles/base/handlers/main.yml b/ansible/playbooks/roles/base/handlers/main.yml similarity index 100% rename from ansible/roles/base/handlers/main.yml rename to ansible/playbooks/roles/base/handlers/main.yml diff --git a/ansible/roles/base/tasks/main.yml b/ansible/playbooks/roles/base/tasks/main.yml similarity index 100% rename from ansible/roles/base/tasks/main.yml rename to ansible/playbooks/roles/base/tasks/main.yml diff --git a/ansible/roles/hardening/defaults/main.yml b/ansible/playbooks/roles/hardening/defaults/main.yml similarity index 100% rename from ansible/roles/hardening/defaults/main.yml rename to ansible/playbooks/roles/hardening/defaults/main.yml diff --git a/ansible/roles/hardening/handlers/main.yml b/ansible/playbooks/roles/hardening/handlers/main.yml similarity index 100% rename from ansible/roles/hardening/handlers/main.yml rename to ansible/playbooks/roles/hardening/handlers/main.yml diff --git a/ansible/roles/hardening/tasks/main.yml b/ansible/playbooks/roles/hardening/tasks/main.yml similarity index 100% rename from ansible/roles/hardening/tasks/main.yml rename to ansible/playbooks/roles/hardening/tasks/main.yml diff --git a/ansible/roles/hardening/templates/sshd_config.j2 b/ansible/playbooks/roles/hardening/templates/sshd_config.j2 similarity index 100% rename from ansible/roles/hardening/templates/sshd_config.j2 rename to ansible/playbooks/roles/hardening/templates/sshd_config.j2 diff --git a/ansible/roles/monitoring/defaults/main.yml b/ansible/playbooks/roles/monitoring/defaults/main.yml similarity index 100% rename from ansible/roles/monitoring/defaults/main.yml rename to ansible/playbooks/roles/monitoring/defaults/main.yml diff --git a/ansible/roles/monitoring/handlers/main.yml b/ansible/playbooks/roles/monitoring/handlers/main.yml similarity index 100% rename from ansible/roles/monitoring/handlers/main.yml rename to ansible/playbooks/roles/monitoring/handlers/main.yml diff --git a/ansible/roles/monitoring/tasks/main.yml b/ansible/playbooks/roles/monitoring/tasks/main.yml similarity index 100% rename from ansible/roles/monitoring/tasks/main.yml rename to ansible/playbooks/roles/monitoring/tasks/main.yml From 56219c31f70ea6349cfcdbe2703a01149da6dffb Mon Sep 17 00:00:00 2001 From: prafullb3 <42909468+prafullb3@users.noreply.github.com> Date: Thu, 8 Jan 2026 06:14:21 +0000 Subject: [PATCH 15/19] modified hardening ansible role --- .../roles/hardening/defaults/main.yml | 9 ++++--- .../roles/hardening/tasks/enable.yml | 6 +++++ .../roles/hardening/tasks/install.yml | 6 +++++ .../playbooks/roles/hardening/tasks/main.yml | 25 +++-------------- .../playbooks/roles/hardening/tasks/rules.yml | 27 +++++++++++++++++++ .../roles/hardening/templates/sshd_config.j2 | 11 -------- 6 files changed, 48 insertions(+), 36 deletions(-) create mode 100644 ansible/playbooks/roles/hardening/tasks/enable.yml create mode 100644 ansible/playbooks/roles/hardening/tasks/install.yml create mode 100644 ansible/playbooks/roles/hardening/tasks/rules.yml delete mode 100644 ansible/playbooks/roles/hardening/templates/sshd_config.j2 diff --git a/ansible/playbooks/roles/hardening/defaults/main.yml b/ansible/playbooks/roles/hardening/defaults/main.yml index 592993a..20141a3 100644 --- a/ansible/playbooks/roles/hardening/defaults/main.yml +++ b/ansible/playbooks/roles/hardening/defaults/main.yml @@ -1,4 +1,7 @@ --- -ssh_port: 22 -disble_root_login: true -password_authentication: false \ No newline at end of file +ufw_enabled: true +ufw_allow_ssh: true +ufw_ssh_port: 22 +ufw_default_incoming: deny +ufw_default_outgoing: allow +ufw_allowed_ports: [] diff --git a/ansible/playbooks/roles/hardening/tasks/enable.yml b/ansible/playbooks/roles/hardening/tasks/enable.yml new file mode 100644 index 0000000..b915a60 --- /dev/null +++ b/ansible/playbooks/roles/hardening/tasks/enable.yml @@ -0,0 +1,6 @@ +--- +- name: Enable UFW safely + command: ufw --force enable + async: 30 + poll: 0 + when: ufw_enabled | default(true) diff --git a/ansible/playbooks/roles/hardening/tasks/install.yml b/ansible/playbooks/roles/hardening/tasks/install.yml new file mode 100644 index 0000000..dd06297 --- /dev/null +++ b/ansible/playbooks/roles/hardening/tasks/install.yml @@ -0,0 +1,6 @@ +--- +- name: Install UFW + apt: + name: ufw + state: present + update_cache: yes diff --git a/ansible/playbooks/roles/hardening/tasks/main.yml b/ansible/playbooks/roles/hardening/tasks/main.yml index 7e84e84..e149819 100644 --- a/ansible/playbooks/roles/hardening/tasks/main.yml +++ b/ansible/playbooks/roles/hardening/tasks/main.yml @@ -1,25 +1,6 @@ --- -- name: Ensure UFW Insalled - apt: +- name: Install UFW + apt: name: ufw state: present - -- name: Allow SSH - ufw: - rule: allow - port: "{{ ssh_port}}" - proto: tcp - -- name: Enable UFW - ufw: - state: enabled - policy: deny - -- name: Configure SSH hardening - template: - src: sshd_config.j2 - dest: /etc/ssh/sshd_config - owner: root - group: root - mode: '0600' - notify: Restart SSH \ No newline at end of file + update_cache: yes \ No newline at end of file diff --git a/ansible/playbooks/roles/hardening/tasks/rules.yml b/ansible/playbooks/roles/hardening/tasks/rules.yml new file mode 100644 index 0000000..32ff399 --- /dev/null +++ b/ansible/playbooks/roles/hardening/tasks/rules.yml @@ -0,0 +1,27 @@ +--- +# Allow SSH first to prevent lockout +- name: Allow SSH + ufw: + rule: allow + port: "{{ ssh_port | default(22) }}" + proto: tcp + +# Optional extra ports (if defined in defaults/main.yml) +- name: Allow additional ports + ufw: + rule: allow + port: "{{ item.port }}" + proto: "{{ item.proto | default('tcp') }}" + loop: "{{ ufw_allowed_ports | default([]) }}" + when: ufw_allowed_ports | length > 0 + +# Set default incoming and outgoing policies +- name: Set default incoming policy + ufw: + direction: incoming + policy: "{{ ufw_default_incoming | default('deny') }}" + +- name: Set default outgoing policy + ufw: + direction: outgoing + policy: "{{ ufw_default_outgoing | default('allow') }}" diff --git a/ansible/playbooks/roles/hardening/templates/sshd_config.j2 b/ansible/playbooks/roles/hardening/templates/sshd_config.j2 deleted file mode 100644 index 0284fef..0000000 --- a/ansible/playbooks/roles/hardening/templates/sshd_config.j2 +++ /dev/null @@ -1,11 +0,0 @@ -Port {{ ssh_port }} -Protocol 2 -PermitRootLogin {{ 'no' if disable_root_login else 'yes' }} -PasswordAuthentication {{ 'yes' if password_authentication else 'no' }} -ChallengeResponseAuthentication no -UsePAM yes -X11Forwarding no -AllowTcpForwarding no -ClientAliveInterval 300 -ClientAliveCountMax 2 -MaxAuthTries 3 \ No newline at end of file From 20689502729c36032495b5f79c7ecc6c14596ce8 Mon Sep 17 00:00:00 2001 From: prafullb3 <42909468+prafullb3@users.noreply.github.com> Date: Thu, 8 Jan 2026 06:22:15 +0000 Subject: [PATCH 16/19] fixed azure Monitoring agent config --- ansible/playbooks/roles/monitoring/tasks/main.yml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/ansible/playbooks/roles/monitoring/tasks/main.yml b/ansible/playbooks/roles/monitoring/tasks/main.yml index 1d377f4..530b0a6 100644 --- a/ansible/playbooks/roles/monitoring/tasks/main.yml +++ b/ansible/playbooks/roles/monitoring/tasks/main.yml @@ -8,7 +8,7 @@ dest: /tmp/install_ama.sh mode: '0755' - - name: Install AMA - command: /tmp/install_ama.sh + - name: Install AMA + shell: bash /tmp/install_ama.sh args: - creates: /opt/microsoft/azuremonitoragent \ No newline at end of file + creates: /opt/microsoft/azuremonitoragent From 153ceabb1826bd137a22daca7c41b0347c3991ed Mon Sep 17 00:00:00 2001 From: prafullb3 <42909468+prafullb3@users.noreply.github.com> Date: Thu, 8 Jan 2026 06:34:38 +0000 Subject: [PATCH 17/19] removed monitoring ansible role --- ansible/playbooks/configure.yml | 3 +-- .../playbooks/roles/monitoring/defaults/main.yml | 1 - .../playbooks/roles/monitoring/handlers/main.yml | 0 ansible/playbooks/roles/monitoring/tasks/main.yml | 14 -------------- 4 files changed, 1 insertion(+), 17 deletions(-) delete mode 100644 ansible/playbooks/roles/monitoring/defaults/main.yml delete mode 100644 ansible/playbooks/roles/monitoring/handlers/main.yml delete mode 100644 ansible/playbooks/roles/monitoring/tasks/main.yml diff --git a/ansible/playbooks/configure.yml b/ansible/playbooks/configure.yml index 8462a7b..16ccae7 100644 --- a/ansible/playbooks/configure.yml +++ b/ansible/playbooks/configure.yml @@ -6,5 +6,4 @@ ansible_python_interpreter: /usr/bin/python3 roles: - base - - hardening - - monitoring \ No newline at end of file + - hardening \ No newline at end of file diff --git a/ansible/playbooks/roles/monitoring/defaults/main.yml b/ansible/playbooks/roles/monitoring/defaults/main.yml deleted file mode 100644 index 4668fc9..0000000 --- a/ansible/playbooks/roles/monitoring/defaults/main.yml +++ /dev/null @@ -1 +0,0 @@ -install_azure_monitoring_agent: true \ No newline at end of file diff --git a/ansible/playbooks/roles/monitoring/handlers/main.yml b/ansible/playbooks/roles/monitoring/handlers/main.yml deleted file mode 100644 index e69de29..0000000 diff --git a/ansible/playbooks/roles/monitoring/tasks/main.yml b/ansible/playbooks/roles/monitoring/tasks/main.yml deleted file mode 100644 index 530b0a6..0000000 --- a/ansible/playbooks/roles/monitoring/tasks/main.yml +++ /dev/null @@ -1,14 +0,0 @@ ---- -- name: Install Azure Monitor Agent - when: install_azure_monitoring_agent - block: - - name: Download Azure Monitor Agent installation script - get_url: - url: https://aka.ms/InstallAzureMonitorAgentLinux - dest: /tmp/install_ama.sh - mode: '0755' - - - name: Install AMA - shell: bash /tmp/install_ama.sh - args: - creates: /opt/microsoft/azuremonitoragent From 1700a6da212ef3cc8d5a4220d9ffeb44fbc06017 Mon Sep 17 00:00:00 2001 From: prafullb3 <42909468+prafullb3@users.noreply.github.com> Date: Thu, 8 Jan 2026 06:42:05 +0000 Subject: [PATCH 18/19] updated ansible role hardening\tasks\main.yml --- ansible/playbooks/roles/hardening/tasks/main.yml | 8 +++----- 1 file changed, 3 insertions(+), 5 deletions(-) diff --git a/ansible/playbooks/roles/hardening/tasks/main.yml b/ansible/playbooks/roles/hardening/tasks/main.yml index e149819..0a15e68 100644 --- a/ansible/playbooks/roles/hardening/tasks/main.yml +++ b/ansible/playbooks/roles/hardening/tasks/main.yml @@ -1,6 +1,4 @@ --- -- name: Install UFW - apt: - name: ufw - state: present - update_cache: yes \ No newline at end of file +- import_tasks: install.yml +- import_tasks: rules.yml +- import_tasks: enable.yml \ No newline at end of file From 0cb58599be9a5015ccfb6c016364de1001e6101f Mon Sep 17 00:00:00 2001 From: prafullb3 <42909468+prafullb3@users.noreply.github.com> Date: Thu, 8 Jan 2026 09:31:48 +0000 Subject: [PATCH 19/19] modified build_image.yml --- .github/workflows/build-image.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/build-image.yml b/.github/workflows/build-image.yml index 35bc55f..a4daac6 100644 --- a/.github/workflows/build-image.yml +++ b/.github/workflows/build-image.yml @@ -1,7 +1,7 @@ on: push: branches: - - feature1 + - main jobs: build: