Cockpit Limited To An Admin Group, Root Refused

Cockpit from BaseOS bound to loopback, with logins limited to an admin group through PAM and root refused outright. The live test sees an administrator log in while an ordinary account, a wrong password and root, placed in the admin group to isolate its own rule, are refused, and reads the login banner. Original role, live-tested on Rocky Linux 10.

ansibleObservability

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-cockpit/badge)](https://www.iac-bazaar.com/catalog/ansible-cockpit?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [Cockpit Limited To An Admin Group, Root Refused](https://www.iac-bazaar.com/catalog/ansible-cockpit?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# Cockpit Limited To An Admin Group, Root Refused: https://www.iac-bazaar.com/catalog/ansible-cockpit (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

cockpit

Cockpit from BaseOS: the server web console bound to loopback (reach it through an SSH tunnel or a proxy that authenticates), logins limited to an admin group through PAM, root refused outright, idle sessions closed and a banner on the login page. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages cockpit, so the role installs it by name and takes what the distribution ships: a security update arrives through dnf, not through a new release of this role. What the role owns is the configuration and the proof that the service works.

Socket-activated, and bound where you say. The package's socket listens on every interface (*:9090, measured). The role binds it with a drop-in to 127.0.0.1:9090 by default; measured from another network namespace, the bound console refused the connection, while bound to every interface it served HTTPS and answered plain HTTP with a 301 to HTTPS.

Only the admin group gets in. Cockpit authenticates through PAM; the role puts pam_succeed_if ... user ingroup wheel first in its auth stack, so an account outside the group is refused before its password is checked. The live test sees an administrator log in, and an ordinary account and a wrong password refused.

root is refused by its own rule. disallowed-users (the distribution's default, now managed by the role) refuses root whatever its group: the live test puts root in wheel first, so it is that rule, not the group, which refuses it. Sessions close after 15 idle minutes, and the login page carries the banner, which the test reads.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-victoria-logs

VictoriaLogs from the upstream release as a hardened service on loopback. Its JSON-lines endpoint answers 200 and stores nothing when the content type is wrong, so the README names the one it needs. The live test ingests two lines, gets the right one back from LogsQL, and sees an unwritten stream come back empty and bad LogsQL refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-alertmanager

Prometheus Alertmanager from the upstream release (sha256-verified) as a hardened system service on loopback, its cluster gossip listener switched off and its configuration checked by amtool before it lands. The live test posts an alert through the API and reads it back active, held by the default receiver, and expects no 9094 listener at all. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-alloy

Grafana Alloy from the upstream release (sha256-verified) as a hardened system service on loopback with --disable-reporting, a self-scrape pipeline that proves the collector runs, and its configuration checked by alloy validate before it lands. The live test reads Alloy's own metrics and asks the component API for the scrape component's health. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-blackbox-exporter

Prometheus Blackbox exporter from the upstream release (sha256-verified) as a hardened system service on loopback with HTTP and TCP modules, checked by --config.check before the file lands. The live test has it probe itself over HTTP and TCP (probe_success 1) and a port with nothing behind it (probe_success 0): it measures, not only answers. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-fluent-bit

fluent-bit from EPEL, following a log-file glob it re-reads every few seconds and shipping over the Forward protocol, with retries unlimited instead of the default single retry. Its config is checked with --dry-run before it lands. The live test writes a line to a new file and watches it arrive at an aggregator it started. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-grafana-server

Grafana on loopback with a secret key of yours: every install that never set one shares the package's, which encrypts the data-source credentials in its database. Secure cookies and HSTS for the TLS proxy in front; public snapshots, plugin update checks, feedback links and Gravatar switched off. Settings verified through the API, not the file. Original role, live-tested on Rocky Linux 10.

View module