Commit bfd03029 authored by Derek Nola's avatar Derek Nola
Browse files

Add apparmor-parser support for SUSE



Signed-off-by: default avatarDerek Nola <derek.nola@suse.com>
parent e9a283b4
Loading
Loading
Loading
Loading
+19 −0
Original line number Diff line number Diff line
@@ -118,6 +118,25 @@
    - net.bridge.bridge-nf-call-iptables
    - net.bridge.bridge-nf-call-ip6tables

- name: Check for Apparmor existence
  ansible.builtin.stat:
    path: /sys/module/apparmor/parameters/enabled
  register: apparmor_enabled

- name: Check if Apparmor is enabled
  when: apparmor_enabled.stat.exists
  ansible.builtin.command: cat /sys/module/apparmor/parameters/enabled
  register: apparmor_status
  changed_when: false

- name: Install Apparmor Parser
  when:
    - apparmor_status.stdout == "Y"
    - ansible_os_family == 'Suse'
  ansible.builtin.package:
    name: apparmor-parser
    state: present

- name: Add /usr/local/bin to sudo secure_path
  ansible.builtin.lineinfile:
    line: 'Defaults    secure_path = /sbin:/bin:/usr/sbin:/usr/bin:/usr/local/bin'