Mastering Ansible for Infrastructure as Code: A Beginner's ... (https://medium.com/@sriharimalapati/mastering-ansible-for-infrastructure-as-code-a-beginners-guide-119a5af69286)
about.gitlab.com - Build enterprise-grade IaC pipelines with GitLab DevSecOps (https://about.gitlab.com/blog/using-ansible-and-gitlab-as-infrastructure-for-code/)
coachdevops.com - How to setup Ansible on Red Hat Linux VM and Integrate with ... (https://www.coachdevops.com/2023/08/install-ansible-on-red-hat-linux-how-to.html)
https://www.google.com/search?q=googleusercontent.com - How to Create a DevSecOps CI/CD Pipeline (https://m.youtube.com/watch?v=mZoOnWjv_QM)
coachdevops.com - August 2023 - DevSecOps and Cloud Computing Coaching (https://www.coachdevops.com/2023/08/)
spacelift.io - 13 Popular Ansible Alternatives You Should Know in 2025 (https://spacelift.io/blog/ansible-alternatives)
github.com - dev-sec/ansible-collection-hardening (https://github.com/dev-sec/ansible-collection-hardening)
medium.com - Hardening Linux Server with Ansible (https://medium.com/@kayvan.sol2/hardening-linux-server-with-ansible-9cc9cd5d4d27)
github.com - Security automation content in SCAP, Bash, Ansible, and ... (https://github.com/ComplianceAsCode/content)
docs.redhat.com - Red Hat Ansible Automation Platform hardening guide (https://docs.redhat.com/en/documentation/red_hat_ansible_automation_platform/2.4/html-single/red_hat_ansible_automation_platform_hardening_guide/index)
reddit.com - Using Ansible to install CICD pipeline (https://www.reddit.com/r/ansible/comments/1h7zk66/using_ansible_to_install_cicd_pipeline/)
medium.com - Day 26: Integrating Ansible with CI/CD Pipelines (https://medium.com/@vinoji2005/day-26-integrating-ansible-with-ci-cd-pipelines-284637f83ba2)
docs.gitlab.com - CI/CD YAML syntax reference (https://docs.gitlab.com/ci/yaml/)
docs.gitlab.com - CI/CD pipelines (https://docs.gitlab.com/ee/ci/pipelines/)
spacelift.io - Writing .gitlab-ci.yml File with Examples [Tutorial] (https://spacelift.io/blog/gitlab-ci-yml)
stackoverflow.com - How do I add comments to .gitlab-ci.yaml file? (https://stackoverflow.com/questions/67327175/how-do-i-add-comments-to-gitlab-ci-yaml-file)
docs.gitlab.com - Get started with GitLab CI/CD (https://docs.gitlab.com/ci/)
docs.gitlab.com - CI/CD Jobs (https://docs.gitlab.com/ci/jobs/)
Ansible Playbook for hardening linux firewall:
# playbook_firewall.yml
- name: Harden Firewall
hosts: all
become: true
tasks:
- name: Ensure firewalld is enabled and running
service:
name: firewalld
enabled: true
state: started
- name: Allow SSH
firewalld:
service: ssh
permanent: true
state: enabled
- name: Reload firewall configuration
command: firewall-cmd --reload
#Ansible Playbook for hardening SSH Configuration
# playbook_ssh.yml
- name: Harden SSH Configuration
hosts: all
become: true
tasks:
- name: Ensure PermitRootLogin is no
lineinfile:
path: /etc/ssh/sshd_config
regexp: '^PermitRootLogin yes'
line: 'PermitRootLogin no'
- name: Change default SSH port (example: 2222)
lineinfile:
path: /etc/ssh/sshd_config
regexp: '^#Port 22'
line: 'Port 2222'
- name: Restart sshd service
service:
name: sshd
state: restarted
#Ansible inventory.ini file
# inventory.ini
[linux_servers]
server1.example.com
server2.example.com
# This is the main GitLab CI/CD configuration file.
# It defines the pipeline's stages and the jobs within each stage [[1](https://docs.gitlab.com/ci/yaml/), [5](https://docs.gitlab.com/ci/)].
stages:
- build_hardening # Stage for hardening build artifacts
- test # Stage for testing the hardened infrastructure
- apply_hardening # Stage for applying the hardening configurations
# Job to perform build hardening
build_hardening:
stage: build_hardening
image: your_docker_registry/hardening_tools:latest # Docker image containing your hardening tools
script:
- sh ./harden_build.sh # Execute the script to harden build artifacts (e.g., container image)
artifacts:
paths:
- hardened_build/ # Define the path to the hardened build artifacts
# Job to test the hardened infrastructure
test_infrastructure:
stage: test
image: your_test_image:latest # Docker image containing your testing tools
script:
- sh ./run_tests.sh hardened_build/inventory.ini # Execute tests against the hardened build using the inventory
dependencies:
- build_hardening # This job depends on the successful completion of the build_hardening job
# Job to apply firewall hardening using Ansible
apply_firewall:
stage: apply_hardening
image: registry.gitlab.com/ansible/ansible-runner:latest # Docker image with Ansible
script:
- ansible-playbook playbook_firewall.yml -i hardened_build/inventory.ini # Run the firewall hardening playbook
only:
- main # Only run this job on the main branch
dependencies:
- test_infrastructure # This job depends on the successful completion of the test_infrastructure job
# Job to apply SSH hardening using Ansible
apply_ssh_hardening:
stage: apply_hardening
image: registry.gitlab.com/ansible/ansible-runner:latest # Docker image with Ansible
script:
- ansible-playbook playbook_ssh.yml -i hardened_build/inventory.ini # Run the SSH hardening playbook
only:
- main # Only run this job on the main branch
dependencies:
- test_infrastructure # This job depends on the successful completion of the test_infrastructure job
Integrating the previously provided Ansible playbooks (playbook_firewall.yml and playbook_ssh.yml) into a DevSecOps pipeline involves automating security hardening as part of the software delivery process. This ensures infrastructure security is consistently applied and maintained. GitLab, along with Ansible, can be used to build such pipelines [1, 4].
DevSecOps Pipeline Integration:
Code Commit: Developers commit infrastructure-as-code (Ansible playbooks, inventory) and application code.
CI/CD Trigger: A commit triggers the CI/CD pipeline in a tool like GitLab CI.
Build Stage: Application code is built and tested.
Infrastructure Provisioning (Optional): Tools like Terraform might provision infrastructure [1].
Security Hardening (Ansible): Ansible playbooks (e.g., playbook_firewall.yml, playbook_ssh.yml) are executed against the target servers defined in the inventory.ini to apply security configurations [4].
Security Scanning: SAST, SCA, and DAST tools scan the application and infrastructure for vulnerabilities.
Compliance Checks: Tools or Ansible playbooks based on projects like ComplianceAsCode [6] can verify if the infrastructure meets security policies.
Testing: Integration tests are run against the hardened environment.
Deployment: Application code is deployed to the hardened infrastructure.
Monitoring: Continuous monitoring tracks security and performance.