Reader small image

You're reading from  Enterprise Cloud Security and Governance

Product typeBook
Published inDec 2017
PublisherPackt
ISBN-139781788299558
Edition1st Edition
Tools
Right arrow
Author (1)
Zeal Vora
Zeal Vora
author image
Zeal Vora

Zeal Vora works as a DevSecOps Engineer primarily in the area of Defensive Security. He spends his days protecting and implementing security controls to help mitigate attacks both on the Cloud and servers. He is actively involved in security consultation, helping various startups which have been breached to overcome the breach and start again with a secure infrastructure.
Read more about Zeal Vora

Right arrow

Attaining the desired state with Ansible pull

We used to run Ansible pull across 500+ servers to maintain a consistent image across all servers. It happens many times that a system administrator flushes iptables if things are not working or stops OSSEC if it blocks scans.

This leads to a lot of unexpected configurations everywhere, and during an audit period, OSSEC may be disabled in a few servers from the past few weeks.

So, our entire hardening stack was based on Ansible pull that used to run at midnight on all servers. If there were any configuration changes, then Ansible would update it back to the original consistent state.

This is extremely useful and makes the auditors smile as well.

Auditing servers with Ansible notifications

...
lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Enterprise Cloud Security and Governance
Published in: Dec 2017Publisher: PacktISBN-13: 9781788299558

Author (1)

author image
Zeal Vora

Zeal Vora works as a DevSecOps Engineer primarily in the area of Defensive Security. He spends his days protecting and implementing security controls to help mitigate attacks both on the Cloud and servers. He is actively involved in security consultation, helping various startups which have been breached to overcome the breach and start again with a secure infrastructure.
Read more about Zeal Vora