Skip to main content

$ cat templates/ansible-baseline

Ansible server baseline

Harden a fresh box: users, SSH, firewall, unattended upgrades.

ansible-baselineDownload template

An idempotent role for the boring-but-critical first hour on any new server.

The problem

A small, annoying task that was eating time and attention every week. We measured it before touching anything.

The approach

One focused change, reproducible, with a guardrail and an obvious way to turn it off. No magic, no vibes.

$ ./run --dry-run
[ ok ] plan looks sane
$ ./run --apply

The receipts

Before/after benchmarks, the failure modes we hit, and the tradeoffs we accepted. The repo has the full runbook.