diff --git a/setup/modules/FreeipaAnsible/ansible/ansipa-enforce-policies.sh b/setup/modules/FreeipaAnsible/ansible/ansipa-enforce-policies.sh index 5e5a370..275f9c0 100755 --- a/setup/modules/FreeipaAnsible/ansible/ansipa-enforce-policies.sh +++ b/setup/modules/FreeipaAnsible/ansible/ansipa-enforce-policies.sh @@ -21,6 +21,29 @@ # dev_local-sudo- Grant full sudo on this specific device by adding # them to the local sudoers drop-in. Leaving the group removes # the drop-in on the next run. +# dev_ssh_ Distribute 's SSH public keys from their IPA profile to +# /home//.ssh/authorized_keys on this device (ansipa-managed +# section; manually added keys are preserved). Leaving the group +# removes only the ansipa-managed section on the next run. +# Keys stored in IPA via: ipa user-mod --sshpubkey='...' +# +# CheckMK monitoring host-groups (device policies — require dev_mon_base first): +# dev_mon_base Install CheckMK agent; register host in CheckMK under /ansipa; +# enable check_mk.socket (port 6556) for pull mode, or +# cmk-agent-ctl push timer for push mode (when server can't +# reach the client directly). +# Built-in sections report CPU, RAM, disk, uptime. +# Custom check: installed package count (rpm / dpkg / pacman). +# Credentials are auto-discovered from the IPA dev_mon_base +# description (populated by ansipa-checkmk-setup.sh on the server). +# Leaving the group deregisters the host and disables the agent. +# dev_mon_malware Local check reporting ClamAV scan results from the +# dev_security-scan log. Requires dev_security-scan to run first; +# both groups can coexist independently. +# dev_mon_timeshift Local check for most-recent Timeshift snapshot age. +# WARN if >5 days, CRIT if >10 days; CRIT if no snapshots found. +# dev_mon_power Local check for CPU package power via Intel RAPL (preferred) +# or lm-sensors fallback. WARN >65 W, CRIT >95 W. # # User-group naming conventions (per-user policies — follow the user across devices): # usr_admin Members get full sudo on every enrolled host via a sudoers @@ -48,10 +71,23 @@ # only for group members (checked via id(1) / SSSD). # Deleting the IPA user group removes the timer and profile.d # snippet on the next enforcer run. +# usr_smb_r_ Mount a read-only Samba share as ~/‹name› for members on any +# usr_smb_rw_ enrolled host where they are logged in. rw membership takes +# precedence over r when both exist for the same share name. +# Credential string is stored in the IPA group description by +# ansipa-smb-setup.sh (cifs://::). +# Leaving the group unmounts the share on the next run. +# Requires: cifs-utils installed on the client. +# usr_mon_logins (CheckMK) Local check for SSH login attempts in the last 24 h: +# successful + failed + invalid-user counts with thresholds. +# WARN: ≥10 failed or ≥5 invalid; CRIT: ≥50 failed or ≥20 invalid. +# Installed fleet-wide when the group exists; requires dev_mon_base. # # Notes: # - Install scan tools first: add the host to dev_mod_anti-malware. # - Configure Timeshift (type + target device) before enabling dev_timeshift-backup. +# - CheckMK server must be running and accessible before adding hosts to dev_mon_base. +# Run ansipa-checkmk-setup.sh on the FreeIPA container to seed credentials and groups. set -euo pipefail @@ -1310,8 +1346,18 @@ UNIT # ── dev_mon_base: installed-packages local check ─────────────────────── # CPU, RAM, disk, uptime are reported by the built-in check_mk_agent sections. _cmk_write_check "ansipa_packages" '#!/bin/bash -PKG_COUNT=$(rpm -qa --qf "%{NAME}\n" 2>/dev/null | wc -l || dpkg-query -f "${Package}\n" -W 2>/dev/null | wc -l || echo 0) -RECENT=$(rpm -qa --qf "%{INSTALLTIME} %{NAME}\n" 2>/dev/null | sort -rn | head -5 | awk "{print \$2}" | tr "\n" "," | sed "s/,\$//" || echo "n/a") +PKG_COUNT=0 +RECENT="n/a" +if command -v rpm &>/dev/null; then + PKG_COUNT=$(rpm -qa --qf "%{NAME}\n" 2>/dev/null | wc -l) + RECENT=$(rpm -qa --qf "%{INSTALLTIME} %{NAME}\n" 2>/dev/null | sort -rn | head -5 | awk "{print \$2}" | tr "\n" "," | sed "s/,\$//") +elif command -v dpkg &>/dev/null; then + PKG_COUNT=$(dpkg --list 2>/dev/null | grep -c "^ii") + RECENT=$(grep " install " /var/log/dpkg.log 2>/dev/null | tail -5 | awk "{print \$4}" | tr "\n" "," | sed "s/,\$//") +elif command -v pacman &>/dev/null; then + PKG_COUNT=$(pacman -Qq 2>/dev/null | wc -l) + RECENT=$(grep "\[ALPM\] installed" /var/log/pacman.log 2>/dev/null | tail -5 | awk "{print \$4}" | tr "\n" "," | sed "s/,\$//") +fi echo "0 Ansipa_Packages packages=${PKG_COUNT} ${PKG_COUNT} packages installed. Recent: ${RECENT}"' # ── dev_mon_malware: ClamAV scan result check ────────────────────────── diff --git a/setup/modules/FreeipaAnsible/ansible/deploy-ansipa-policies.yml b/setup/modules/FreeipaAnsible/ansible/deploy-ansipa-policies.yml index 0817215..5fd22e4 100644 --- a/setup/modules/FreeipaAnsible/ansible/deploy-ansipa-policies.yml +++ b/setup/modules/FreeipaAnsible/ansible/deploy-ansipa-policies.yml @@ -41,6 +41,10 @@ # - For dev_security-scan / usr_scan-notify: smb_scan_password set (use ansible-vault in production) # - For security-scan tools: also add host to dev_mod_anti-malware group # - For timeshift-backup: also add host to dev_mod_timeshift group +# - For dev_mon_*: CheckMK CE must be up; run ansipa-checkmk-setup.sh on the FreeIPA +# container first (seeds credentials + groups in IPA) +# - For usr_smb_r_*/usr_smb_rw_*: cifs-utils installed (handled below); Samba service +# running on the IPA container (ansipa-smb.service auto-starts) # # Usage: # ansible-playbook -i inventory deploy-ansipa-policies.yml \ diff --git a/setup/modules/FreeipaAnsible/image/.env.example b/setup/modules/FreeipaAnsible/image/.env.example index d663333..22825a5 100644 --- a/setup/modules/FreeipaAnsible/image/.env.example +++ b/setup/modules/FreeipaAnsible/image/.env.example @@ -20,6 +20,14 @@ IPA_SETUP_KRA=false SMB_SCAN_PASSWORD=ChangeMe_ScanPass! LUKS_KEY_UPLOAD_PASSWORD=ChangeMe_LuksUpload! +# ── CheckMK CE monitoring ───────────────────────────────────────────────────── +# CMK_ADMIN_PASSWORD — web UI password for cmkadmin. +# CMK_SITE_ID — OMD site name (default: cmk). Used in all CheckMK URLs and +# agent registration. Must match whatever was used on first start. +# Web UI: http://localhost:8090/cmk/ after `docker compose up -d` +CMK_ADMIN_PASSWORD=ChangeMe_CMK! +CMK_SITE_ID=cmk + # ── Keycloak ────────────────────────────────────────────────────────────────── KC_HOSTNAME=keycloak.corp.example.com KC_REALM=corp