diff options
author | Steven Hardy <shardy@redhat.com> | 2017-01-18 12:25:56 +0000 |
---|---|---|
committer | lhinds <lhinds@redhat.com> | 2017-01-27 13:23:18 +0000 |
commit | afdc138987db8246be1f3a0948967f10c3011bb8 (patch) | |
tree | 3f3c040c0d70f923d9b07307e3693df9e12a8250 /puppet | |
parent | c349789089157b0210d8de4f317599df81fa9760 (diff) |
Add AuditD composable service
This patch allows the management of the AuditD service and its associated
files (such as `audit.rules`)
This is achieved by means of the `puppet-auditd` puppet module.
Also places ssh banner capabilities map on top of patch
Change-Id: Ib8bb52dde88304cb58b051bced9779c97a314d0d
Depends-On: Ie31c063b674075e35e1bfa28d1fc07f3f897407b
Diffstat (limited to 'puppet')
-rw-r--r-- | puppet/services/auditd.yaml | 34 |
1 files changed, 34 insertions, 0 deletions
diff --git a/puppet/services/auditd.yaml b/puppet/services/auditd.yaml new file mode 100644 index 00000000..639631e1 --- /dev/null +++ b/puppet/services/auditd.yaml @@ -0,0 +1,34 @@ +heat_template_version: ocata + +description: > + AuditD configured with Puppet + +parameters: + ServiceNetMap: + default: {} + description: Mapping of service_name -> network name. Typically set + via parameter_defaults in the resource registry. This + mapping overrides those in ServiceNetMapDefaults. + type: json + DefaultPasswords: + default: {} + type: json + EndpointMap: + default: {} + description: Mapping of service endpoint -> protocol. Typically set + via parameter_defaults in the resource registry. + type: json + AuditdRules: + description: Mapping of auditd rules + type: json + default: {} + +outputs: + role_data: + description: Role data for the auditd service + value: + service_name: auditd + config_settings: + auditd::rules: {get_param: AuditdRules} + step_config: | + include ::tripleo::profile::base::auditd |