Skip to content
This repository has been archived by the owner on Jun 10, 2024. It is now read-only.

Security Automation

Andrew Klychkov edited this page Jun 10, 2021 · 28 revisions

Security Automation Working Group

The Security Automation Working Group collaborates on Topics in Information Security Automation in Ansible.

Ansible can be the automation glue between disjoint systems and security appliances that have little to no integrations. Security Operators can utilize Ansible to be more productive, adapt to the growing demand of the modern IT landscape, ensure consistency in their IT environments, and respond to security incidents faster. Beyond that, Ansible can be utilized for automated implementation of security standards, systems hardening, and compliance. Our goal here is to help foster a cross discipline and cross functional collaborative community of Information Security Professionals through the power of automation via Ansible.

Learn more about security automation challenges at ansible.com.

News

We just had a new blog post: Getting Started with Ansible and Check Point (2020-04-13)

Community

Name GitHub (+ IRC) Role Affiliation
Adam Miller maxamillion Lead Red Hat/Ansible
Sumit Jaiswal justjais Lead Red Hat/Ansible
Abhijeet Kasurde Akasurde Member Red Hat/Ansible
James Cassell jamescassell Reviewer Independent
Thomas Young tyoung2018 Reviewer Red Hat
Jonathan Lozada De La Matta jlozadad Member Red Hat
Francisco Ramirez Cisco-redhat Member Red Hat
Roland Wolters liquidat Member Red Hat

Add yourself to this list as a Reviewer (help review PRs) or as a Member (discuss issues/roadmap) and join the IRC Channel! :)

Useful Links

Blog posts to learn more

Meetings

If you want to bring up an issue, a review-request or a PR to discuss on the meeting, just put it on the meeting agenda.

We have weekly meetings on Mondays at 15:00 UTC on IRC channel #ansible-security.

Meetings are managed and logged by meetbot, we use the Fedora Project møte: meeting wrangler. Meeting minutes and logs are available by channel or by team. For community members interested in how to use meetbot or how to host an effective meeting, please consult this guide.

Roadmap

Feedback welcome in the #ansible-security IRC channel!

  • Move modules from /network to security collections?
  • Improve existing collections
  • Identify missing collections/features
  • Get workshop in a shape to demo other vendors
  • Get workshop in a shape to demo more use cases

You can find the general Ansible roadmaps at Ansible Roadmaps.

Community effort (help welcome !)

  • Help foster a community of automation practitioners in Information Security
  • Collaborative development on various efforts in the community space
  • Engagement with the broader InfoSec Community (meetups, events, online communities, etc)
  • Your idea here!

Projects Maintained by this Working Group

Project Status
IBM QRadar Collection GitHub issues GitHub PRs
Splunk Enterprise Security Collection GitHub issues GitHub PRs
Symantec Endpoint Protection Manager GitHub issues GitHub PRs
ids_install Role GitHub issues GitHub PRs
ids_config Role GitHub issues GitHub PRs
ids_rule Role GitHub issues GitHub PRs
ids_rule_facts Role GitHub issues GitHub PRs
log_manager Role GitHub issues GitHub PRs
acl_manager Role GitHub issues GitHub PRs

Contact

We exist within the Ansible Community and therefore use all typical outlets you would expect us to. However, we do have our own #ansible-security IRC channel as our discussions would often be off-topic for other channels.

(ARchived) Working groups

Working groups are now in the Ansible forum

Ansible project:
Community, Contributor Experience, Docs, News, Outreach, RelEng, Testing

Cloud:
AWS, Azure, CloudStack, Container, DigitalOcean, Docker, hcloud, Kubernetes, Linode, OpenStack, oVirt, Virt, VMware

Networking:
ACI, AVI, F5, Meraki, Network, NXOS

Ansible Developer Tools:
Ansible-developer-tools

Software:
Crypto, Foreman, GDrive, GitLab, Grafana, IPA, JBoss, MongoDB, MySQL, PostgreSQL, RabbitMQ, Zabbix

System:
AIX, BSD, HP-UX, macOS, Remote Management, Solaris, Windows

Security:
Security-Automation, Lockdown

Tooling:
AWX, Galaxy, Molecule

Communities

Modules:
unarchive, xml

Plugins:
httpapi

Wiki

Roles, Communication, Reviewing, Checklist, TODO

Clone this wiki locally