Right, I was thinking myself... why not have a chef recipe do this, and walk through the systems as you do that.
Ideally the server comes up and applies chef, doing the needful to secure it. Hand-cooking a server is extremely painful.
Ideally the server comes up and applies chef, doing the needful to secure it. Hand-cooking a server is extremely painful.
We'll release an Ansible Playbook over the next week or so that follows these steps.
- https://github.com/openstack/openstack-ansible-security
- https://github.com/geerlingguy/ansible-role-security