A Suricata IDS With ET Open And A Canary Rule
Suricata from EPEL watching the default-route interface as the suricata user, ET Open fetched at install and refreshed daily, plus a canary rule that proves the sensor is alive. A root-run check left root-owned logs and a daemon recording nothing; the role prevents it. The live test raises the canary alert while a second lookup is logged, not alerted. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-02 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-suricata?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [A Suricata IDS With ET Open And A Canary Rule](https://www.iac-bazaar.com/catalog/ansible-suricata?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# A Suricata IDS With ET Open And A Canary Rule: https://www.iac-bazaar.com/catalog/ansible-suricata (download from your IaC Bazaar account)
```Preview:
Documentation
suricata
Suricata from EPEL: a network IDS on the interface the default route leaves by, running as the suricata user, with the ET Open ruleset fetched at install and refreshed daily, your own rules beside it, and a canary rule that lets you prove at any time that the sensor sees traffic. Original role for EL 10, live-tested with podman on Rocky Linux 10.
From EPEL, with the ruleset the package does not ship. EL 10's EPEL packages
Suricata 8; its stock configuration expects suricata.rules, which only
suricata-update writes, so the stock suricata -T fails until then
(measured). The role fetches ET Open (53,000 signatures, about 30 s) before the
first start and installs a daily timer that updates and reloads - a reload
loads new rules without a restart (about 13 s, measured).
A daemon that runs and records nothing. A suricata -T run as root before
the first start left root-owned files in /var/log/suricata, and the daemon -
which drops to the suricata user - then ran with no events at all (measured).
Every check in this role logs to its own directory, the log directory belongs
to the suricata user, and the live test asserts who writes eve.json. Plan for
memory: with ET Open loaded the engine held about 500 MB.
Proven by an alert it raises. The live test looks up the canary name - a query that leaves by the watched interface - and finds sid 1000001 in eve.json, while a second lookup is logged as DNS and raises nothing; then it reads that the daemon runs as the suricata user, that the suricata user owns eve.json, that more than 10,000 signatures are loaded, and that the daily update timer is enabled. Suricata's privilege drop keeps CAP_SYS_NICE, which a container does not grant by default (measured: "capng_change_id ... failed"), so the live test grants it - a host has it.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-aide
AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.
ansible-389-ds
389 Directory Server from AppStream. A fresh instance listens on every interface and lets anonymous clients read the tree; this role binds both listeners to loopback and limits anonymous clients to the rootDSE. The live test adds a user who binds, sees a wrong password and an anonymous search refused, and reads the LDAPS certificate. Original role, live-tested on Rocky Linux 10.
ansible-authelia
Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.
ansible-bandit
bandit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a module that passes a string to subprocess.call with shell=True (B602, High, exit 1) and a clean module (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-boundary
boundary on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then runs authenticate against a dead address ('connection refused') and database init with a throwaway config (parsed, root key loaded, then the database refused). Pinned. Original role, live-tested on Rocky Linux 10.
ansible-clamav
ClamAV from EPEL: clamd on a local socket and loopback TCP, signatures fetched before it starts and freshclam enabled after, since every ClamAV unit ships disabled. The README measures where a size limit fails open. The live test decodes the EICAR test file on the target, so no role file holds it, and finds the signature by name on three client paths. Original role, live-tested on Rocky Linux 10.