$ cat templates/ansible-baseline
Ansible server baseline
Harden a fresh box: users, SSH, firewall, unattended upgrades.
ansible-baselineDownload template
An idempotent role for the boring-but-critical first hour on any new server.
The problem
A small, annoying task that was eating time and attention every week. We measured it before touching anything.
The approach
One focused change, reproducible, with a guardrail and an obvious way to turn it off. No magic, no vibes.
$ ./run --dry-run
[ ok ] plan looks sane
$ ./run --applyThe receipts
Before/after benchmarks, the failure modes we hit, and the tradeoffs we accepted. The repo has the full runbook.