85 lines
2.2 KiB
YAML
85 lines
2.2 KiB
YAML
---
|
|||
|
|
# Canonical project and asset inventory.
|
||
|
|
#
|
||
|
|
# This is both an Ansible YAML inventory and the input consumed by GitLab CI.
|
||
|
|
# Keep credentials out of this file. GitLab selects protected variables by the
|
||
|
|
# test_project.environment value, which must match TARGET_ENVIRONMENT.
|
||
|
|
all:
|
||
|
|
vars:
|
||
|
|
test_project:
|
||
|
|
id: "replace-with-project-id"
|
||
|
|
name: "Replace with project name"
|
||
|
|
environment: "test"
|
||
|
|
customer: ""
|
||
|
|
location: ""
|
||
|
|
|
||
|
|
children:
|
||
|
|
linux_vms:
|
||
|
|
hosts: {}
|
||
|
|
# Example:
|
||
|
|
# linux-app-01:
|
||
|
|
# ansible_host: 192.0.2.10
|
||
|
|
# asset_type: linux_vm
|
||
|
|
# test_profiles: [iec62443, sbom]
|
||
|
|
|
||
|
|
windows_servers:
|
||
|
|
vars:
|
||
|
|
ansible_connection: winrm
|
||
|
|
ansible_winrm_transport: ntlm
|
||
|
|
ansible_winrm_server_cert_validation: ignore
|
||
|
|
ansible_port: 5985
|
||
|
|
hosts: {}
|
||
|
|
|
||
|
|
windows_clients:
|
||
|
|
vars:
|
||
|
|
ansible_connection: winrm
|
||
|
|
ansible_winrm_transport: ntlm
|
||
|
|
ansible_winrm_server_cert_validation: ignore
|
||
|
|
ansible_port: 5985
|
||
|
|
hosts: {}
|
||
|
|
|
||
|
|
mssql_servers:
|
||
|
|
vars:
|
||
|
|
ansible_connection: winrm
|
||
|
|
ansible_winrm_transport: ntlm
|
||
|
|
ansible_winrm_server_cert_validation: ignore
|
||
|
|
ansible_port: 5985
|
||
|
|
hosts: {}
|
||
|
|
|
||
|
|
vmware_esxi:
|
||
|
|
vars:
|
||
|
|
ansible_connection: local
|
||
|
|
vmware_validate_certs: false
|
||
|
|
hosts: {}
|
||
|
|
|
||
|
|
hyperv_hosts:
|
||
|
|
vars:
|
||
|
|
ansible_connection: winrm
|
||
|
|
ansible_winrm_transport: ntlm
|
||
|
|
ansible_winrm_server_cert_validation: ignore
|
||
|
|
ansible_port: 5985
|
||
|
|
hosts: {}
|
||
|
|
|
||
|
|
cisco_switches:
|
||
|
|
vars:
|
||
|
|
ansible_connection: ansible.netcommon.network_cli
|
||
|
|
ansible_network_os: cisco.ios.ios
|
||
|
|
ansible_become: true
|
||
|
|
ansible_become_method: enable
|
||
|
|
hosts: {}
|
||
|
|
|
||
|
|
cisco_firewalls:
|
||
|
|
vars:
|
||
|
|
ansible_connection: ansible.netcommon.network_cli
|
||
|
|
ansible_network_os: cisco.asa.asa
|
||
|
|
ansible_become: true
|
||
|
|
ansible_become_method: enable
|
||
|
|
hosts: {}
|
||
|
|
|
||
|
|
web_applications:
|
||
|
|
hosts: {}
|
||
|
|
# Example:
|
||
|
|
# baggage-web:
|
||
|
|
# target_url: https://baggage-test.example.com
|
||
|
|
# asset_type: web_application
|
||
|
|
# test_profiles: [zap-baseline, asvs]
|