diff --git a/roles/base/tasks/harden.yml b/roles/base/tasks/harden.yml index a23b0ced0c9d47686e71e3cbccd1c636271032e4..58234a1488b3b3a3ca6025f034ef73f20e68efc5 100644 --- a/roles/base/tasks/harden.yml +++ b/roles/base/tasks/harden.yml @@ -49,6 +49,7 @@ packages: - auditd - audisp-json + when: not enable_loki - name: Auditd default config removed file: @@ -63,6 +64,7 @@ - "templates/audit/rules.d/*.j2" notify: - restart auditd + when: not enable_loki - name: Auditd configured template: @@ -70,6 +72,7 @@ dest: /etc/audit/auditd.conf notify: - restart auditd + when: not enable_loki - name: Audispd plugins configured copy: @@ -80,11 +83,13 @@ - json.conf notify: - restart auditd + when: not enable_loki - name: Enable auditd service systemd: name: auditd.service enabled: yes + when: not enable_loki - name: Disable journald-auditd link systemd: @@ -92,3 +97,4 @@ state: stopped enabled: no masked: yes + when: not enable_loki