forked from mitre/chef-nginx-hardening
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy path.kitchen.ec2.yml
127 lines (113 loc) · 2.92 KB
/
.kitchen.ec2.yml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
<%
use_json = true
use_ebs = false
%>
---
driver:
name: ec2
chef_version: latest
privileged: true
security_group_ids: <%= ENV['AWS_SG_ID'] %>
aws_ssh_key_id: <%= ENV['AWS_SSH_KEY_ID'] %>
subnet_id: <%= ENV['AWS_SUBNET_ID'] %>
<% if use_ebs == true %>
ebs_optimized: true
instance_type: i3.2xlarge
block_device_mappings:
- device_name: /dev/sda1
ebs:
volume_type: gp2
delete_on_termination: true
<% end %>
provisioner:
name: chef_solo
transport:
name: ssh
connection_retries: 12
connection_retry_sleep: 10
ssh_key: ~/.ssh/<%= ENV['AWS_SSH_KEY_ID'] %>.pem
verifier:
name: inspec
sudo: true
sudo_options: '-u root'
inspec_tests:
- name: nginix-baseline
git: https://github.com/aaronlippold/nginx-baseline.git
attrs:
- aws.attributes.yml
<% if use_json == true %>
format: json
output: "%{platform}_%{suite}-<%= Time.now.iso8601 %>.json"
<% end %>
platforms:
- name: debian-7
driver:
image: debian:7
pid_one_command: /sbin/init
intermediate_instructions:
- RUN /usr/bin/apt-get update
- RUN /usr/bin/apt-get install lsb-release procps -y
- name: debian-8
driver:
image: debian:8
pid_one_command: /bin/systemd
intermediate_instructions:
- RUN /usr/bin/apt-get update
- RUN /usr/bin/apt-get install lsb-release -y
- name: centos-6
driver:
image: centos:6
platform: rhel
pid_one_command: /sbin/init
intermediate_instructions:
- RUN yum -y install which initscripts
- name: centos-7
driver:
image: centos:7
platform: rhel
pid_one_command: /usr/lib/systemd/systemd
intermediate_instructions:
- RUN yum -y install lsof which systemd-sysv initscripts
- name: fedora-latest
driver:
image: fedora:latest
pid_one_command: /usr/lib/systemd/systemd
intermediate_instructions:
- RUN dnf -y install yum which systemd-sysv initscripts
- name: ubuntu-12.04
driver:
image: ubuntu-upstart:12.04
pid_one_command: /sbin/init
intermediate_instructions:
- RUN /usr/bin/apt-get update
- name: ubuntu-14.04
driver:
image: ubuntu-upstart:14.04
pid_one_command: /sbin/init
intermediate_instructions:
- RUN /usr/bin/apt-get update
- name: ubuntu-16.04
driver:
image: ubuntu:16.04
pid_one_command: /bin/systemd
intermediate_instructions:
- RUN /usr/bin/apt-get update
- name: opensuse-13.2
driver:
image: opensuse:13.2
pid_one_command: /bin/systemd
intermediate_instructions:
- RUN zypper --non-interactive install aaa_base perl-Getopt-Long-Descriptive which
- name: opensuse-42.1
driver:
image: opensuse:42.1
pid_one_command: /bin/systemd
intermediate_instructions:
- RUN zypper --non-interactive install aaa_base perl-Getopt-Long-Descriptive which
suites:
- name: default
run_list:
- recipe[apt]
- recipe[nginx-hardening::upgrades]
- recipe[nginx]
- recipe[nginx-hardening]