Cockpit Limited To An Admin Group, Root Refused
Cockpit from BaseOS bound to loopback, with logins limited to an admin group through PAM and root refused outright. The live test sees an administrator log in while an ordinary account, a wrong password and root, placed in the admin group to isolate its own rule, are refused, and reads the login banner. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-cockpit?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [Cockpit Limited To An Admin Group, Root Refused](https://www.iac-bazaar.com/catalog/ansible-cockpit?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# Cockpit Limited To An Admin Group, Root Refused: https://www.iac-bazaar.com/catalog/ansible-cockpit (download from your IaC Bazaar account)
```Preview:
Documentation
cockpit
Cockpit from BaseOS: the server web console bound to loopback (reach it through an SSH tunnel or a proxy that authenticates), logins limited to an admin group through PAM, root refused outright, idle sessions closed and a banner on the login page. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages cockpit, so the
role installs it by name and takes what the distribution ships: a security
update arrives through dnf, not through a new release of this role. What the
role owns is the configuration and the proof that the service works.
Socket-activated, and bound where you say. The package's socket listens on
every interface (*:9090, measured). The role binds it with a drop-in to
127.0.0.1:9090 by default; measured from another network namespace, the
bound console refused the connection, while bound to every interface it served
HTTPS and answered plain HTTP with a 301 to HTTPS.
Only the admin group gets in. Cockpit authenticates through PAM; the
role puts pam_succeed_if ... user ingroup wheel first in its auth stack, so
an account outside the group is refused before its password is checked. The
live test sees an administrator log in, and an ordinary account and a wrong
password refused.
root is refused by its own rule. disallowed-users (the distribution's
default, now managed by the role) refuses root whatever its group: the live
test puts root in wheel first, so it is that rule, not the group, which
refuses it. Sessions close after 15 idle minutes, and the login page carries
the banner, which the test reads.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-victoria-logs
VictoriaLogs from the upstream release as a hardened service on loopback. Its JSON-lines endpoint answers 200 and stores nothing when the content type is wrong, so the README names the one it needs. The live test ingests two lines, gets the right one back from LogsQL, and sees an unwritten stream come back empty and bad LogsQL refused. Original role, live-tested on Rocky Linux 10.
ansible-alertmanager
Prometheus Alertmanager from the upstream release (sha256-verified) as a hardened system service on loopback, its cluster gossip listener switched off and its configuration checked by amtool before it lands. The live test posts an alert through the API and reads it back active, held by the default receiver, and expects no 9094 listener at all. Original role, live-tested on Rocky Linux 10.
ansible-alloy
Grafana Alloy from the upstream release (sha256-verified) as a hardened system service on loopback with --disable-reporting, a self-scrape pipeline that proves the collector runs, and its configuration checked by alloy validate before it lands. The live test reads Alloy's own metrics and asks the component API for the scrape component's health. Original role, live-tested on Rocky Linux 10.
ansible-blackbox-exporter
Prometheus Blackbox exporter from the upstream release (sha256-verified) as a hardened system service on loopback with HTTP and TCP modules, checked by --config.check before the file lands. The live test has it probe itself over HTTP and TCP (probe_success 1) and a port with nothing behind it (probe_success 0): it measures, not only answers. Original role, live-tested on Rocky Linux 10.
ansible-fluent-bit
fluent-bit from EPEL, following a log-file glob it re-reads every few seconds and shipping over the Forward protocol, with retries unlimited instead of the default single retry. Its config is checked with --dry-run before it lands. The live test writes a line to a new file and watches it arrive at an aggregator it started. Original role, live-tested on Rocky Linux 10.
ansible-grafana-server
Grafana on loopback with a secret key of yours: every install that never set one shares the package's, which encrypts the data-source credentials in its database. Secure cookies and HSTS for the TLS proxy in front; public snapshots, plugin update checks, feedback links and Gravatar switched off. Settings verified through the API, not the file. Original role, live-tested on Rocky Linux 10.