About this project

devsec.hardening is an Ansible collection that bundles hardening roles for common server components. According to the README, it covers Linux operating systems (CentOS Stream 9, AlmaLinux 8/9/10, Rocky Linux 8/9/10, Debian 12/13, Ubuntu 22.04/24.04/26.04, with some roles also supported on Amazon Linux, Arch Linux, Fedora 42/43/44 and Suse Tumbleweed), MySQL and MariaDB (MariaDB >= 5.5.65, >= 10.1.45, >= 10.3.17; MySQL >= 5.7.31, >= 8.0.3), Nginx 1.0.16 or later, and OpenSSH 5.3 and later. The stated goal is compliance with the Inspec DevSec Baselines for Linux, MySQL, nginx and SSH. The collection includes four roles: os_hardening, mysql_hardening, nginx_hardening and ssh_hardening. Two further roles, apache_hardening and windows_hardening, are described as in progress and not working. Installation is done through ansible-galaxy with `ansible-galaxy collection install devsec.hardening`. The minimum required Ansible version is 2.16. Usage examples are referenced in the individual role READMEs. The README notes that the roles were previously distributed as standalone roles; the last standalone release of os-hardening was 6.2.0, and the other roles now live in separate archive repositories. A roadmap lists finishing apache_hardening and windows_hardening and adding support for more operating systems. The project is licensed under Apache License 2.0.