Merge pull request 'Add playbook to deploy sudo update on all machines' (#34) from sudo_update into master
continuous-integration/drone/push Build is failing Details

Reviewed-on: Aurore/ansible#34
This commit is contained in:
jeltz 2021-03-11 14:22:20 +01:00
commit 974fcff1d3
1 changed files with 17 additions and 0 deletions

17
sudo_upgrade.yml Executable file
View File

@ -0,0 +1,17 @@
#!/usr/bin/env ansible-playbook
---
# This is a special playbook to upgrade sudo everywhere after the
# CVE-2021-3156: Heap-Based Buffer Overflow in Sudo (Baron Samedit)
# Please always use with --limit myserver.adm.auro.re
# And list updates with --check
- hosts: all
tasks:
- name: Upgrade sudo
apt:
name: sudo
state: latest
update_cache: true
cache_valid_time: 3600 # one hour
register: apt_result
retries: 3
until: apt_result is succeeded