AIDE, A Baseline And A Timer That Notices A Change

AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.

ansibleSecurity & Secrets

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-09-26 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-aide/badge)](https://www.iac-bazaar.com/catalog/ansible-aide?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [AIDE, A Baseline And A Timer That Notices A Change](https://www.iac-bazaar.com/catalog/ansible-aide?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# AIDE, A Baseline And A Timer That Notices A Change: https://www.iac-bazaar.com/catalog/ansible-aide (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

aide

A file-integrity database, and a timer that reports when the host stops matching it. The role writes the AIDE configuration (checked by AIDE itself before it lands), builds the baseline once, and installs the oneshot unit and timer the package does not ship. The unit's exit code is the signal: 0 means the host matches, 1 means it does not and the report says how, 2 means the check could not run and nothing is known.

No download, and no version to pin. EL 10 packages AIDE, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is what is watched, how often, and the proof that a change is noticed.

The units are ours, and the README says so. The EL 10 aide package ships /etc/aide.conf, a logrotate snippet and a tmpfiles entry - and no unit of any kind. So unlike the other package-shaped roles in this catalogue, this one writes aide-check.service and aide-check.timer itself; systemctl cat will show this role's text, not the distribution's.

"Nothing is known" is not the same as "nothing changed". AIDE reports differences with bits (1 added, 2 removed, 4 changed) and its own failures with 14 and above, so a wrapper that only tested for non-zero would report a missing database as a compromised host. The wrapper keeps them apart, and the live test checks all three outcomes: clean, changed, and clean again after the change is removed.

A removed file does not undo a report. A watched directory is checked with its mtime, so creating a file in /etc moves /etc's own mtime, and deleting the file again does not move it back: the check keeps reporting d = ... mc.. .. : /etc until the new state is accepted with aide --update. That is not a defect, it is what a baseline means, and it is why every legitimate change to a watched path has to end with an update. The live test walks exactly that: clean, changed, updated, clean again.

The baseline is built after the units are enabled, deliberately. Enabling a timer writes a symlink under /etc/systemd/system, which is inside a watched path: a database built before that would report the role's own symlink as an addition on the very first run.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-authelia

Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.

View module
Live-tested

ansible-bandit

bandit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a module that passes a string to subprocess.call with shell=True (B602, High, exit 1) and a clean module (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-boundary

boundary on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then runs authenticate against a dead address ('connection refused') and database init with a throwaway config (parsed, root key loaded, then the database refused). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-dockle

dockle on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then scans a one-layer image whose config names no user, expecting CIS-DI-0001 in the output, exit code 1 with --exit-level warn, and the warning counted in the JSON form. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-gitleaks

gitleaks on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then plants a file holding an AWS access key that is not one and runs gitleaks detect over it, expecting 'leaks found: 1'. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-grype

grype on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Anchore's checksums file, and re-checked with sha256sum -c by the live test, which then runs grype db status with no database fetched and expects 'database does not exist'. Anchore also signs the checksums with cosign; the role checks the hash. Original role, live-tested on Rocky Linux 10.

View module