dotfiles-ansible/roles/system/tasks/apparmor.yml

27 lines
685 B
YAML

---
- name: apparmor | Install apparmor and default profiles
community.general.apk:
name: apparmor, apparmor-profiles
state: present
- name: apparmor | Enable writing cache and faster DFA transition table compression
lineinfile:
path: /etc/apparmor/parser.conf
state: present
search_string: '{{ item }}'
line: '{{ item }}'
owner: root
group: root
mode: '644'
loop:
- write-cache
- Optimize=compress-fast
# Don't start it yet, as it requires the kernel parameters
- name: apparmor | Add apparmor service to runlevel 'boot'
service:
name: apparmor
runlevel: boot
enabled: true
notify: Notify apparmor kernel parameters