Files

66 lines
2.4 KiB
YAML
Raw Permalink Normal View History

2026-07-07 16:57:37 +00:00
---
# site.yml — IEC 62443-3-3 SL2 Compliance Validation
#
# Entry point for the compliance testing framework. This playbook:
#
# 1. Runs against all hosts in the inventory
# 2. Gathers facts first (ansible_date_time, ansible_user_id, etc.)
# 3. Executes each FR suite as a named task inside an ignore_errors block
# 4. Invokes library/report.yml to aggregate test_results[] and write JSON
#
# Usage:
2026-09-22 00:00:45 +02:00
# ansible-playbook -i assets.yml methodologies/ansible/playbooks/site.yml --limit <host> -K
# ./methodologies/ansible/run.sh --limit <host> -K
2026-07-07 16:57:37 +00:00
#
# Adding a new suite:
# Copy the block below, change the name and include_tasks path:
#
# - name: "Suite: FRN — Category Name"
# block:
# - ansible.builtin.include_tasks: suites/frN_category.yml
# ignore_errors: yes
#
# Variables:
2026-09-22 00:00:45 +02:00
# report_dir: Where raw JSON reports land (default: artifacts/raw/ansible)
2026-07-07 16:57:37 +00:00
- name: "IEC 62443-3-3 SL2 Compliance — All Targets"
hosts: all
gather_facts: yes
become: yes
vars:
2026-09-22 00:00:45 +02:00
report_dir: "./artifacts/raw/ansible"
2026-07-07 16:57:37 +00:00
pre_tasks:
- name: "Ensure report directory exists"
ansible.builtin.file:
path: "{{ report_dir }}"
state: directory
mode: "0755"
delegate_to: localhost
run_once: true
tasks:
# ─────── FR1: Identification & Authentication ──────────────
- name: "Suite: FR1 — Identification & Authentication Control"
block:
- ansible.builtin.include_tasks: suites/fr1_auth.yml
ignore_errors: yes
# ─────── FR2: Use Control ─────────────────────────────────
- name: "Suite: FR2 — Use Control"
block:
- ansible.builtin.include_tasks: suites/fr2_use_control.yml
ignore_errors: yes
# ─────── FR5: Restricted Data Flow ────────────────────────
- name: "Suite: FR5 — Restricted Data Flow"
block:
- ansible.builtin.include_tasks: suites/fr5_data_flow.yml
ignore_errors: yes
# TODO: Add FR3, FR4, FR6, FR7 suites
# ─────── REPORT ───────────────────────────────────────────
- name: "Generate compliance report"
ansible.builtin.include_tasks: library/report.yml