pezhore,
@pezhore@lemmy.ml avatar

Personally, I find Ansible to be much more intuitive than other products in the configuration management space. Start small, think about what you want your system to look like.

Do you want Firefox installed? Use ansible.builtin.package to install it!

Do you want to have ssh server configured to disallow password authentication (and only allow ssh keys)? Use ansible.builtin.blockinfile on your sshd.config file!

Regarding SELinux vs apparmor, they both are designed to lock down a system, but they have different philosophies about how to approach the problem.

SELinux says block all by default and only if it’s configured to allow it will it be allowed to happen.

Apparmor on the other hand is permissive by default, and it will only restrict if it is configured to do so.

By the way, both can be managed by Ansible, and SELinux even has a module to do so: docs.ansible.com/ansible/…/selinux_module.html.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • [email protected]
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • oklahoma
  • Socialism
  • KbinCafe
  • TheResearchGuardian
  • Ask_kbincafe
  • SuperSentai
  • feritale
  • KamenRider
  • All magazines