fix: relax dev template hardening, add docker + docker-compose

This commit is contained in:
mustard 2025-10-22 17:07:18 +02:00
parent ac12e08577
commit 02069d93fd

View file

@ -1,4 +1,4 @@
- name: Configure Fedora 42 Gnome Template - name: Configure Fedora 42 Dev Template
hosts: 127.0.0.1 hosts: 127.0.0.1
connection: local connection: local
tasks: tasks:
@ -6,10 +6,10 @@
ansible.builtin.include_role: ansible.builtin.include_role:
name: 'baseline' name: 'baseline'
vars: vars:
umask_changes: true umask_changes: false
manage_network: true manage_network: true
allow_ptrace: true allow_ptrace: true
use_hardened_malloc: true use_hardened_malloc: false
- name: 'Gnome package stuff' - name: 'Gnome package stuff'
ansible.builtin.include_role: ansible.builtin.include_role:
@ -39,6 +39,8 @@
- golang-gvisor # outdated, but sufficient for playing around with gvisor - golang-gvisor # outdated, but sufficient for playing around with gvisor
- glibc-devel - glibc-devel
- opentofu - opentofu
- docker
- docker-compose
state: 'present' state: 'present'
- name: 'Handle SUID binaries' - name: 'Handle SUID binaries'