REC-418 Disable NFS services
[ta/infra-ansible.git] / roles / ops-hardening / tasks / main.yaml
index 71218a0..3381cea 100644 (file)
     - cramfs
     - usb-storage
     - udf
+    - nfsd
 
 #
 # Disable interactive boot
     state: "mounted"
     fstype: "{{device_fstype.stdout}}"
 
+#
+# Disable NFS service
+#
+
+- name: disable NFS related services
+  service:
+    name: "{{ item }}"
+    enabled: no
+    state: stopped
+  ignore_errors: yes
+  with_items:
+    - nfslock
+    - rpcgssd
+    - rpcidmapd
+    - nfs-idmap
+    - nfs-server
+    - nfs
+
+- name: remove nfs-utils package
+  yum:
+    name: nfs-utils
+    state: absent
+
 #
 # Setting file permissions
 #