Multi-cloud & platform-agnostic Infrastructure-as-Code modules

209 verified ansible / terraform modules for Multi-cloud & platform-agnostic, spanning CI/CD & Automation, Cloud Tooling, Compute & VMs, Container Registry, and more. Every artifact is statically validated (tofu validate + tflint + Checkov) and passes the publish rules before it appears here. Each ships an annotated terraform.tfvars.example and a perpetual licence with 12 months of updates.

202 of 209 Multi-cloud & platform-agnostic modules are live-tested - really applied to a cloud account, verified, then destroyed. The remaining 7 are static-validated, live-test pending. We never label a module “live-tested” unless it actually passed apply→verify→destroy.

All Multi-cloud & platform-agnostic modules

Static validatedLive test pending

vault-kv-engine

KV v1 overwrites in place, so a bad write is the end of the previous secret; cas_required defaults to false, so two writers that read the same version both succeed and the second silently replaces the first; and version history is unbounded by default. v2 always, check-and-set on (off by name), versions bounded by count and age, the mount's lease ceilings set rather than inherited.

View module
Live-tested

ansible-unbound-resolver

Unbound on loopback: DNSSEC validated locally against the root anchor, query names minimised, version hidden, and upstream over DNS-over-TLS by default because many networks reset TCP 53 to anything but a known resolver, which breaks full recursion the moment a DNSKEY answer outgrows UDP. Recursion is one setting away. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

vault-pki-certificate-authority

Issuing from the root puts every leaf one signature from the root's compromise; a PKI role's defaults issue nothing until somebody reaches for allow_any_name, which issues for every hostname; and without AIA and CRL URLs a leaf is valid and unverifiable. A root that signs one intermediate, roles bound to allowed_domains, 30-day leaves under a 90-day ceiling, URLs on both mounts.

View module
Live-tested

ansible-aide

AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-alertmanager

Prometheus Alertmanager from the upstream release (sha256-verified) as a hardened system service on loopback, its cluster gossip listener switched off and its configuration checked by amtool before it lands. The live test posts an alert through the API and reads it back active, held by the default receiver, and expects no 9094 listener at all. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-alloy

Grafana Alloy from the upstream release (sha256-verified) as a hardened system service on loopback with --disable-reporting, a self-scrape pipeline that proves the collector runs, and its configuration checked by alloy validate before it lands. The live test reads Alloy's own metrics and asks the component API for the scrape component's health. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kafka

Apache Kafka 4 (SHA-512 pinned) on Java 21, one KRaft node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test creates a topic, produces one message, consumes it back and reads the metadata quorum; the metadata log is formatted once as the service user and the root-owned release tree is run in place. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-httpd-tls

httpd with mod_ssl from AppStream on EL 10: one TLS site, an explicit protocol floor and cipher list, HSTS, and the plain port doing nothing but redirecting. The live test reads the site with the certificate the role installed, checks the headers, and is refused when it asks for a cipher outside the list. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

vault-approle

A secret ID with no TTL and no use limit is a password, and both default to unlimited; a role with no bound CIDRs logs in from anywhere; and a role with no max TTL mints tokens that renew forever. Secret IDs that live an hour and are used once, roles bound to the ranges they run from with unbound accepted by name, and token ceilings set.

View module
Live-tested

ansible-argocd-cli

The argocd client on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's cli_checksums.txt, and re-checked with sha256sum -c by the live test, which then runs argocd app list with no server and expects 'server address unspecified'. The server is a cluster install, not this role. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-argo

argo on EL 10 from the GitHub release; the asset is a bare gzip; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has lint --offline pass a valid Workflow and fail one whose entrypoint is missing (exit 1); list stops at the missing cluster. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-atmos

atmos on EL 10 from the GitHub release, get_url refuses it unless its SHA-256 is the one in the vendor's SHA256SUMS, and the live test re-checks it, then writes an atmos.yaml, a stack and a component, validates the stacks and describes the component with no Terraform installed. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-authelia

Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.

View module
Live-tested

ansible-bind-authoritative

BIND as an authoritative-only server. The package is a loopback resolver; add a zone and anyone who can query can copy the whole zone, and version.bind names the 9.18 to attack. This role turns recursion off, refuses transfers to anyone not listed, hides the identity records, rate-limits responses, and renders zones from data checked before they land. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-bandit

bandit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a module that passes a string to subprocess.call with shell=True (B602, High, exit 1) and a clean module (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-blackbox-exporter

Prometheus Blackbox exporter from the upstream release (sha256-verified) as a hardened system service on loopback with HTTP and TCP modules, checked by --config.check before the file lands. The live test has it probe itself over HTTP and TCP (probe_success 1) and a port with nothing behind it (probe_success 0): it measures, not only answers. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-boundary

boundary on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then runs authenticate against a dead address ('connection refused') and database init with a throwaway config (parsed, root key loaded, then the database refused). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-cfssl

cfssl and cfssljson on EL 10 from the GitHub release, each refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which mints a root CA from a CSR, writes it as PEM through cfssljson and reads the subject back with certinfo. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-caddy-https

Caddy with HTTPS on: the package serves plain HTTP with a Server header and an admin API any local process can use. This role gives private names a certificate from Caddy's own CA (public ones get Let's Encrypt), redirects HTTP, sends HSTS and the security headers, drops Server, turns the admin API off, and serves files or proxies an upstream. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-checkov

Checkov pinned in /opt/checkov, a virtual environment apart from the system Python. The live test runs pip check, scans a one-resource module with the built-in checks and --skip-download and expects a 'Failed checks:' summary with no network, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-cilium-cli

cilium on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256sum Cilium publishes, and re-checked with sha256sum -c by the live test, which then runs cilium config view with no cluster and expects the refused connection. Installing Cilium into a cluster stays yours. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-clickhouse

ClickHouse on EL 10 from the upstream LTS release (sha512-verified), as a hardened systemd service on loopback with the default user behind a password; the live test creates a MergeTree table, inserts a row and selects it back over HTTP; a query without credentials is refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-conftest

conftest on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then writes a one-rule Rego v1 policy and a one-line document, runs conftest test and expects the denial in the report. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-consul-cli

consul on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs consul members against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-consul-server

HashiCorp Consul as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, DNS, RPC and both serf listeners on loopback and its configuration checked by consul validate before it lands. The live test waits for a leader, writes a KV key through the API, reads it back and reads the member alive. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-coredns

CoreDNS from the upstream release (sha256-verified) as a hardened system service answering authoritatively for your zones on 127.0.0.1:53 as a system user (CAP_NET_BIND_SERVICE through the unit), forwarding only when you name upstreams. The live test digs the example zone's A record with the aa flag, an NXDOMAIN in the zone and a REFUSED outside it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-dockle

dockle on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then scans a one-layer image whose config names no user, expecting CIS-DI-0001 in the output, exit code 1 with --exit-level warn, and the warning counted in the JSON form. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-dragonfly

Dragonfly on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback behind a password kept in a flagfile; the live test speaks RESP itself: an unauthenticated PING and a wrong password are refused, AUTH + SET + GET round-trip. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

vault-database-secrets

The credential Vault connects with is still a password somebody knows until Vault rotates it; a role with no max TTL issues credentials that renew forever; and creation statements are the privilege, so a careless one is a superuser factory. Root rotation daily, TTLs per role, statements that grant exactly the PostgreSQL role you name, and the connection verified at apply.

View module
Live-tested

ansible-flux-cli

flux on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked with sha256sum -c by the live test, which then runs flux check --pre with no cluster and expects the refused connection. Flux also signs the checksums with cosign; this role checks the hash. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-garage

Garage on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with a single-node layout applied on the first start; the live test creates a bucket and a key through the RPC, grants it, reads it back, and sees an anonymous S3 request refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-gh-cli

gh on EL 10 from the release tarball, refused by Ansible's get_url unless its SHA-256 is the one in GitHub's checksums file, and re-checked with sha256sum -c by the live test; one more file to trust and no more repositories. Tokens are per user; gh auth status with none stops at 'not logged into any GitHub hosts', the live test's proof the client ran. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-glab

glab on EL 10 from the GitLab-hosted release, get_url refuses it unless its SHA-256 is the one in the vendor's checksums file, and the live test re-checks it, then runs auth status to the 401 gitlab.com returns and round-trips a config value offline. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-gitea

Gitea from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; its secrets are generated once and read from files, so app.ini stays root's. The live test creates an administrator with gitea's own command, then a private repository through the API, reads it back, sees it hidden from anonymous eyes, deletes it. Original role, live-tested on Rocky 10.

View module
Live-tested

ansible-gitleaks

gitleaks on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then plants a file holding an AWS access key that is not one and runs gitleaks detect over it, expecting 'leaks found: 1'. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-goreleaser

goreleaser on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has goreleaser check validate a minimal configuration and refuse one with an unknown field at parse, exit 1. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-gotify

Gotify on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback with its settings in an EnvironmentFile; the live test creates an application, pushes a message with its token, reads it back as the admin, and sees a wrong password and a bad token refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-grafana-server

Grafana on loopback with a secret key of yours: every install that never set one shares the package's, which encrypts the data-source credentials in its database. Secure cookies and HSTS for the TLS proxy in front; public snapshots, plugin update checks, feedback links and Gravatar switched off. Settings verified through the API, not the file. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-k6

k6 on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs a script to 100% checks and one whose threshold cannot hold to exit code 99; usage reporting off from profile.d. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-grafana

Grafana (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads back the datasource this role provisioned, creates a dashboard and finds it by search, sees anonymous and wrong-password requests refused, and reads the build metric naming the version installed. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-grype

grype on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Anchore's checksums file, and re-checked with sha256sum -c by the live test, which then runs grype db status with no database fetched and expects 'database does not exist'. Anchore also signs the checksums with cosign; the role checks the hash. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-haproxy-tls

HAProxy terminating TLS 1.2 and 1.3 only with a modern cipher policy, HTTP redirected to HTTPS, HSTS on every response including HAProxy's own error pages (http-after-response, which the live test proved http-response does not cover), a self-signed certificate until yours arrives, stats kept local. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-resource-limits

Nothing limits an account on a stock EL 10 host: limits.d is empty and what ulimit reports is systemd's ceiling. This role sets hard limits on processes, open files and core dumps in both places that decide, because a systemd service never goes through PAM at all. The live test reads a real login session and a real service, and tries to raise both. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-headscale

Headscale, the self-hosted Tailscale control server, from the upstream release binary (sha256-verified) as a hardened system service on loopback with sqlite; configtest runs as the service user (it opens the database). The live test creates a user over the unix socket, issues a reusable pre-auth key for it, reads the user back from the key, destroys it. Original role, live-tested on Rocky 10.

View module
Live-tested

ansible-helm

helm on EL 10 from get.helm.sh, refused by Ansible's get_url unless its SHA-256 is the one in the .sha256sum file published beside the tarball, and re-checked with sha256sum -c by the live test, which then runs helm list with no cluster and expects 'kubernetes cluster unreachable'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-helmfile

helmfile on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then runs helmfile list on a one-release file with no helm on the host and expects it to read the file and stop at the missing helm; pair it with the helm role. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-influxdb3

InfluxDB 3 Core on EL 10 from the vendor's release (checksum-verified), as a hardened systemd service on loopback with file object storage; the binary runs from its release directory (it links the Python it ships); the live test writes a point in line protocol and reads it back with SQL. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-infracost

infracost on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256 Infracost publishes, re-checked by the live test, which then runs a breakdown with no API key and expects it to stop there. The role exports INFRACOST_SKIP_UPDATE_CHECK=true for login shells and the live test reads it back. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-jaeger

Jaeger v2, the tracing backend built on the OpenTelemetry Collector, from the upstream release (sha256-verified against the right checksum file) as a hardened system service on loopback with badger storage and the query API on loopback. The live test pushes a span over OTLP and reads the trace back by id with its name and service. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-jenkins

Jenkins LTS (sha256-verified war) on Java 21, secured on its first start without the wizard, on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test sees anonymous and wrong-password requests refused, creates a freestyle job through the API with a CSRF crumb, builds it to SUCCESS, reads the console and deletes it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-keycloak

Keycloak 26 (SHA-256 pinned) on Java 21, an image the service cannot write to, on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test takes an admin token, sees a wrong password and an anonymous admin request refused, creates a realm (201), duplicates it (409), reads its OpenID discovery document and deletes it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kopia

kopia on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which creates a filesystem repository, snapshots a directory, lists the snapshot and has kopia verify read every object back, all offline. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kube-linter

kube-linter on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then lints a Deployment with one container and nothing else, expecting run-as-non-root, no-read-only-root-fs and the two unset-resource checks with exit 1. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kyverno-cli

The kyverno CLI on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which applies a require-label policy offline: the unlabelled Pod fails, the labelled one passes. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-linkerd

linkerd (edge channel) on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then has install --ignore-cluster render the control plane (at least three Deployments expected) and check --pre stop at the missing cluster. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-rsyslog-forward

rsyslog ships logs in clear over port 514, which is what most examples do. This role configures the sending side with the gtls driver, the collector's CA and x509/name, so a host with a certificate from elsewhere in the estate cannot collect your logs. The live test watches a line arrive and reads the handshake. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-loki

Grafana Loki from the upstream release (sha256-verified) as a single-binary system service on loopback with filesystem storage, a TSDB index, retention the compactor enforces and usage reporting off, its configuration checked by loki -verify-config before it lands. The live test pushes one log line and queries it back. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-postfix-tls

An EL host opens no submission service, so every client sends on port 25 where plaintext is accepted. This role adds 587, which refuses mail until the session is encrypted, and 465, which is TLS from the first byte. Port 25 keeps taking plaintext on purpose and the live test asserts it, because a mail exchanger that demands STARTTLS loses mail. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-mariadb-server

MariaDB bound to loopback (the package listens everywhere), with the mariadb-secure-installation steps applied by the role: anonymous users, the test database and remote root gone, LOAD DATA LOCAL off, reverse DNS off. Provisions an application database and a user that can see nothing else. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-meilisearch

Meilisearch on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback in production mode behind a master key; the live test creates an index and documents, waits for the indexing task, searches and finds the one match, and sees a keyless request refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-mimir

Grafana Mimir from the upstream release binary (sha256-verified) in monolithic mode as a hardened system service on loopback with filesystem storage, every ring member on loopback, usage reporting off. The live test pushes a gauge over OTLP, queries it back through the Prometheus API with its labels and sees an unknown metric answered empty. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-mosquitto-broker

Mosquitto (MQTT) with accounts: the package starts in local-only mode with anonymous clients allowed, no persistence directory and no packet-size limit. This role writes a listener that refuses anonymous and wrong-password clients (proved live), keeps retained messages across restarts, caps packets at 1 MiB, and renders topic ACLs from a list. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nats

nats on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then saves a context under a throwaway config home, reads it back, and runs server check connection against a dead port expecting exit 2 and CRITICAL. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nats-server

NATS server from the upstream release (sha256-verified) as a hardened system service on loopback with JetStream under its own data directory and the configuration checked by nats-server -t before it lands. No client is installed, so the live test speaks the protocol itself: one session subscribes, publishes and reads its own message back. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nsq

NSQ (SHA-256 pinned): nsqd and nsqlookupd as two hardened services from one release on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test publishes four messages, sees the topic count them with the channel holding the last, and asks the directory which broker holds the topic. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nginx

Verified wrapper around geerlingguy.nginx pinned at 3.3.0 plus an IaC Bazaar hardening overlay (server_tokens off, security headers, default-vhost removal); live-tested for idempotence and functionally verified: systemd unit active, HTTP 200, headers present, no version leak.

View module
Live-tested

ansible-nomad-cli

nomad on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs nomad status against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nomad-pack

nomad-pack on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then scaffolds a pack, renders it with a variable override (the job name is read in the output) and lists its variables, all with no Nomad. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nomad-server

HashiCorp Nomad as a single-node server from the upstream release (sha256-verified), as a hardened system service with HTTP, RPC and serf on loopback, an explicit advertise block (Nomad refuses to start without one) and its configuration checked by nomad config validate. The live test waits for a leader and round-trips a variable with nomad var. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-notation

notation on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has cert generate-test mint a key and certificate under a throwaway config home, then lists the trust store and the default key. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-registry

The CNCF Distribution registry from the upstream release (sha256-verified) as a hardened system service on loopback with filesystem storage and deletion enabled, for a TLS proxy that authenticates. The live test walks the OCI protocol: starts an upload, puts a blob by digest, reads its headers back and deletes it. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

vault-oidc-auth

An OIDC role with no bound claims admits every user of the identity provider; a role with no bound audience accepts tokens minted for other services; and the client secret lands in state. Bound claims expected with none accepted by name, an audience required, callbacks listed rather than assumed, token ceilings set, and the write-only secret path named for Terraform 1.11+.

View module
Live-tested

ansible-opa

opa on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256 OPA publishes, and re-checked with sha256sum -c by the live test, which then evaluates a one-rule Rego v1 policy against a one-line input with opa eval and expects the denial. The binary only; no opa server. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-oras

oras on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked by the live test, which then pushes a file as an OCI artifact into a layout on disk and pulls it back byte for byte, no registry needed. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-ssh-ca

sshd can trust a CA and accept any certificate it signed, so access is granted by signing rather than by editing authorized_keys everywhere. The live test proves it four ways over a real connection: the matching certificate gets in, one for another principal does not, one that expired does not, and a key the CA never signed does not. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-openbao

OpenBao (the MPL-licensed Vault fork) as a server with raft storage, from the upstream release (sha256-verified), as a hardened system service on loopback; TLS on the listener when you give it a certificate. The role does not initialise it; the live test does, on its throwaway container: init, unseal, enable KV v2, write a secret, read it back. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-ssh-hardening

An sshd drop-in numbered 01, so it is read before the 50-redhat.conf that asks for X11 forwarding: root login off, passwords off, MaxAuthTries 4, idle timeouts. The live test proves the policy with the daemon rather than the file: a password login refused, a key login accepted, root refused, and the banner delivered before authentication. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-opensearch

OpenSearch 3 (sha512-verified min distribution, bundled JDK), one node on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads the root document, indexes one document with a refresh, finds it by a search, deletes the index and checks the keystore belongs to the service; the release tree stays read-only. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-otel-collector

The OpenTelemetry Collector (contrib) from the upstream release (sha256-verified) as a hardened system service on loopback: OTLP in, a Prometheus endpoint out, your whole configuration checked by the collector before it lands. The live test pushes a gauge over OTLP and reads it back from the Prometheus exporter with its labels and value. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-opentofu

tofu on EL 10 from the GitHub release. The role imports OpenTofu's OpenPGP key into a GnuPG home of its own, refuses a keyring whose fingerprint is not the pinned one, verifies the SHA256SUMS signature, and only then lets Ansible's get_url check the zip against that file. The live test re-verifies the signature and runs tofu init. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-php-fpm

php-fpm from AppStream on EL 10: one pool on a unix socket, open_basedir closed around its own tree, and the process-spawning functions removed. The live test runs PHP through the socket, is refused a read outside the tree, watches a call to a removed function stop the request, and finds nothing listening on TCP. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-packer-cli

packer on EL 10 from releases.hashicorp.com, the SHA256SUMS signature verified against HashiCorp's key in a GnuPG home of its own, pinned by fingerprint, before get_url checks the zip against that file. Pinned; the live test re-verifies the signature and runs packer validate to its 'no config file' answer. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-login-defs

EL ships PASS_MAX_DAYS 99999, so no password expires, and INACTIVE -1 in a second file, so one that does expire still lets you in. This role sets both, then brings the accounts created before it into the policy, which login.defs alone never does. The live test creates an account first, records what it was given, and proves the change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-password-quality

A pwquality drop-in on EL 10 with the length, class and dictionary rules an auditor asks for. Nothing validates pwquality.conf, so the live test scores four passwords and reads why each was refused: a dictionary word by the dictionary check, a password one under the minimum by its length, the same at the minimum accepted, and a passphrase accepted. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-pam-pwhistory

EL remembers nothing: pam_pwhistory is not in the authentication stack, the history file is empty, and a password can be put straight back. Measured, three changes, there and back. This role writes the policy, adds the module through authselect, and proves the refusal by attempting the reuse and reading the reason PAM gives for it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-pluto

pluto on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which writes an Ingress at extensions/v1beta1 and has pluto detect-files name the replacement and exit 3. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-pocketbase

PocketBase, the backend in one binary, from the upstream release (sha256-verified), a hardened system service on loopback, its data under one directory. The live test creates a superuser with PocketBase's own command, sees a wrong password refused, makes a collection and a record, reads it back, sees an anonymous read refused, deletes the collection. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-polaris

polaris on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which audits a minimal Deployment from disk with --set-exit-code-on-danger and expects the danger items and exit 3. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-postfix-null-client

Postfix as a send-only relay: no local delivery (a stock install spools root's mail on the box), one smarthost, TLS required rather than opportunistic, SASL credentials in a root-only lmdb map, local recipients rewritten to a real mailbox. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-postgresql

PostgreSQL server with guarded initdb, SCRAM-SHA-256 auth, managed conf.d drop-in, templated pg_hba, and app database + owner provisioning. Original, live-tested (Molecule/podman) role.

View module
Live-tested

ansible-powerdns

PowerDNS authoritative from EPEL with its SQLite backend; the live test adds a zone through the API, gets the record from dig and NXDOMAIN for an unknown name, sees the API refuse a caller with no key, and reads the query counter. The schema is recovered when a docs-stripped host lacks it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-prometheus-server

Prometheus from the upstream release (EL 10 has no package), sha256-verified, on loopback: the binary listens everywhere and authenticates nobody. Retention time and size as explicit flags, lifecycle and admin endpoints off (the live test POSTs to both), prometheus.yml checked by the promtool it installs. Pairs with grafana-server and node-exporter. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-node-exporter

Official node_exporter release (pinned v1.11.1) with sha256 checksum-verified install, dedicated shell-less system user, and a systemd unit on :9100; live-tested for idempotence with a functional /metrics verification.

View module
Live-tested

ansible-pushgateway

Prometheus Pushgateway from the upstream release (sha256-verified) as a hardened system service on loopback with pushed metrics written to disk every five minutes, so a restart does not lose a batch job's last push. The live test pushes a metric, reads it back with its job label, deletes the job and reads it gone. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-qdrant

Qdrant on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback behind an API key, HTTP only (gRPC off); the live test creates a collection, upserts two points with payloads, searches and gets the matching point back at score 1 with its payload. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-rekor

rekor-cli on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has loginfo verify rekor.sigstore.dev's signed tree head against the embedded root ('Verification Successful!'), fetches entry 1 as JSON, and sees a dead server refused. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-sops

sops on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test. sops --version asks GitHub for newer releases unless told not to; the live test says not to, then decrypts a file that was never encrypted and expects 'sops metadata not found'. Original role, live-tested on Rocky 10.

View module
Live-tested

ansible-samba-share

Samba for named accounts over SMB 3 only. The package accepts SMB 2.0.2, encrypts and signs only when the client asks, shares every local home, exposes printer shares and runs NetBIOS on 139. This role requires encryption and signing (the live test reads it from the server), serves only the shares you list, and speaks on 445 alone. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-seaweedfs

SeaweedFS (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test writes a file through the filer, reads it back and deletes it, sees anonymous S3 refused, runs a SigV4-signed bucket/put/get/delete round trip with the configured identity, sees a wrong secret refused, and reads the metrics. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-semgrep

semgrep on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then runs a one-rule file against a matching module with metrics off and the version check off (exit 1) and against a clean one (exit 0); nothing is fetched from the registry. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-sentinel

sentinel on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then applies a policy with a passing value (Pass, exit 0) and a failing one (Fail with trace, exit 1), runs sentinel test (PASS) and has fmt -check flag an unformatted file. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-skaffold

skaffold on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's per-asset .sha256, and the live test re-checks it, then has skaffold fix upgrade a v2beta29 config to the current schema, turns metrics off and reads the config back; the update check is off in profile.d. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-sonobuoy

sonobuoy on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has gen render a conformance run for Kubernetes 1.32 (the conformance image and at least five resources expected) and gen plugin render a plugin definition, offline. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-surrealdb

SurrealDB (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test sees an anonymous query and a wrong password refused, defines a namespace and a database, creates a record and reads it back, and checks the version endpoint; the root credentials live in the unit environment. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-syft

syft on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Anchore's checksums file, and re-checked with sha256sum -c by the live test, which then runs a real SBOM scan of an empty directory and expects 'No packages discovered'. Anchore also signs the checksums with cosign; this role checks the hash. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-tflint

tflint on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then lints a one-resource module with no required_providers and expects the bundled rule to say so. Provider rulesets are plugins, per repository, not this role. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-task

task (go-task) on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in task_checksums.txt, and re-checked with sha256sum -c by the live test, which then writes a one-task Taskfile and runs it, expecting the task's output. Shell completions ship in the tarball and are not installed. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-tkn

tkn on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which runs tkn pipeline list with no kubeconfig and expects 'no configuration has been provided'. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-telegraf

Telegraf on EL 10 from the vendor's release, pinned by the SHA-256 in InfluxData's release notes, as a hardened systemd service on loopback; the live test writes line protocol to the HTTP input and reads the metric from the Prometheus output; a malformed write is refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-tempo

Grafana Tempo from the upstream release (sha256-verified) as a single-binary hardened system service on loopback with local block storage, an OTLP/HTTP receiver, a block retention written down and usage reporting off. The live test sends one span over OTLP and reads the trace back by id with its service.name. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-terraform-cli

terraform on EL 10 from releases.hashicorp.com. HashiCorp's security key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again. BSL-licensed since 1.6; opentofu in this catalogue is the MPL alternative. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-terragrunt-cli

terragrunt on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Gruntwork's SHA256SUMS, and re-checked with sha256sum -c by the live test. The asset is the bare binary; the checksum file covers every build. Needs a tofu or terraform in the PATH; pair it with opentofu or terraform-cli. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-terramate

terramate on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then makes a git repository, has terramate create a stack, list it from another directory and generate a file from a generate_hcl block, read back. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-terrascan

terrascan on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then fetches the policy set once at install and scans a public-read bucket, expecting 'Violated Policies', exit 3 and allUsersReadAccess in the JSON. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-crypto-policy

One EL 10 setting that decides what OpenSSL, GnuTLS, NSS, OpenSSH and Java will negotiate, applied only when it differs and read back from both files that record it. The live test runs one TLS 1.2 handshake three times, under the configured policy, under FUTURE, and under the policy again, so the refusal in the middle is the policy's doing. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-dnf-security

dnf checks the signature on a package it downloads and not on one you hand it: localpkg_gpgcheck is absent from dnf.conf and defaults to off, and so is repo_gpgcheck. This role sets both and proves each by what it prevents, refusing an unsigned package and an unsigned repository it builds, then checking the distribution's repositories still verify. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

vault-transit

A Transit key never rotates by itself, so the key from day one encrypts everything for the life of the mount; deletion_allowed takes every ciphertext with the key; exportable means the material has left Vault; and min_decryption_version left at 1 keeps every retired version alive. Rotation every 90 days, deletion and export refused unless accepted by name, the retirement version taken.

View module
Live-tested

ansible-trivy

trivy on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Aqua's checksums file, and re-checked with sha256sum -c by the live test, which then runs a license scan of /etc, the one scanner that needs no database, and expects the report. The vulnerability database is fetched on first use, not by the role. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-trufflehog

trufflehog on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which plants an AWS key, sees it reported and --fail exit 183, and sees a clean tree exit 0. No verification calls, no self-update. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-typesense

Typesense on EL 10 from the vendor's release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), as a hardened systemd service on loopback behind an API key, the Raft peering port on loopback too; the live test creates a collection, indexes a document, searches and finds it, and sees a keyless request refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-dnf-automatic

dnf-automatic with apply_updates on: the package downloads updates daily and installs none, and enables no timer. This role installs security advisories on the one timer that reads the configuration, switches the other three off so nothing runs twice, staggers a fleet, and leaves the reboot policy an explicit choice. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-valkey-server

Valkey, the Redis successor EL 10 ships in place of a redis package that no longer exists. The package sets no password, no maxmemory and no append-only log; this role sets all three, on loopback, with the drop-in given the last word over the package configuration. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-vault-cli

vault on EL 10 from releases.hashicorp.com: the client binary, not a server. HashiCorp's key lives in a GnuPG home of its own, pinned by fingerprint; the SHA256SUMS signature is verified before get_url checks the zip against that file, and the live test verifies it again, then runs vault status against nothing and expects the refused connection. Original role, live-tested on Rocky Linux 10.

View module
Static validatedLive test pending

vault-policies

Vault policies, auth backends, and secret engine configuration as code.

View module
Live-tested

ansible-vault-server

HashiCorp Vault as a server with raft storage, from the upstream release (sha256-verified), as a hardened system service on loopback; TLS on the listener when you give it a certificate. The role does not initialise it; the live test does, on its throwaway container: init, unseal, enable KV v2, write a secret, read it back. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-vector

Vector on EL 10 from the vendor's release (checksum-verified), as a hardened systemd service on loopback, its configuration checked by vector validate before it lands; the live test appends a line to the file source and reads it out of the JSON file sink. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-velero-cli

The velero client on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's CHECKSUM file, and re-checked with sha256sum -c by the live test, which then runs velero backup get with no kubeconfig and expects 'no configuration has been provided'. The server is a per-cluster install, not this role. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-victoria-metrics

VictoriaMetrics single-node from the upstream release (sha256-verified) as a hardened system service on loopback with an explicit retention period in the unit. The live test imports one sample through the Prometheus import API, flushes, and queries it back with PromQL, stamped two minutes in the past because queries do not see points younger than the latency offset. Live-tested on Rocky Linux 10.

View module
Live-tested

ansible-cron-access

cronie ships an empty cron.deny and no cron.allow, so every account may schedule work, and at is the same. This role writes both allow files and clears the spools of accounts that may no longer use them, because the access check is in the crontab command: a crontab installed earlier keeps running. The live test watches one run, then stop. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-yor

yor on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has yor tag add yor_trace and yor_name to a Terraform resource, reads the file back, and runs it again expecting zero updated resources; telemetry off in profile.d. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-pam-access

EL ships /etc/security/access.conf with no active rule and pam_access is not in the stack to read it, so every account is admitted from anywhere. This role writes the policy, adds the module through authselect, and refuses to write a rule set that would lock out the account running it. The live test asks PAM, with the origin set. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-actionlint

actionlint on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then writes a workflow reading github.evnt and expects actionlint to say the property is not defined. shellcheck and pyflakes are optional and not installed. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-age

age and age-keygen on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then makes two identities, encrypts to one, decrypts with it, and sees the other refused; the ciphertext carries the age-encryption.org/v1 header. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-ansible-lint

ansible-lint pinned in /opt/ansible-lint, a virtual environment with its own ansible-core, apart from the system Python and the host's Ansible. The live test runs pip check, lints an unnamed play offline and expects name[play] among the findings, and asserts the system Python cannot import it. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-apache-exporter

apache_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up httpd with server-status on loopback as a fixture, sees apache_up 1 with the worker gauges, stops httpd and sees apache_up 0. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-bind-exporter

bind_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up named with one zone and a statistics channel on loopback as a fixture, asks it a name with dig, and reads bind_up 1 and the A query counted. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-chrony-nts

chrony on EL 10 taking time over NTS (RFC 8915), so every measurement is authenticated and the NTP listener is closed. The live test waits for an NTS source to be selected, restarts chronyd to make it dump its NTS cookies and finds them, checks the daemon is not controlling a clock that is not its own, and asserts nothing listens on UDP 123. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-consul-template

consul-template on EL 10 from releases.hashicorp.com; SHA256SUMS is signature-checked against HashiCorp's key before get_url trusts it, the live test re-checks both, then renders env and file templates with -once (to stdout, then to disk, read back) and runs a key template against a dead Consul with retries off, to 'connection refused'. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-cosign

cosign on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Sigstore's cosign_checksums.txt, and re-checked with sha256sum -c by the live test, which then asks cosign to verify a blob with a key that does not exist and expects it to stop at loading the key. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-crane

crane on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then builds an image tarball from one layer with append --oci-empty-base, lists its manifest.json, and has crane ls reach a registry on a dead port (connection refused). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-detect-secrets

detect-secrets on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then scans a file with an AWS-shaped key (reported as AWS Access Key), has the commit hook refuse it (exit 1) and pass a clean file (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-dive

dive on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a one-layer image in docker-archive form and has dive --ci analyse it (PASS) and export the analysis as JSON, asserting the layer and the file in it. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-elasticsearch-exporter

elasticsearch_exporter (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test brings up an OpenSearch node first (the exporter holds its listener while its target does not answer), sees the cluster health up and green, indexes one document and reads it counted for the index with the node's version. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-etcd

etcd from the upstream release (sha256-verified) as a single-member hardened system service on loopback with hourly auto-compaction and a data directory only the service can read; etcdctl and etcdutl are installed beside it. The live test writes a key with etcdctl, reads it back, checks the member's health and deletes the key. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-fail2ban

fail2ban from EPEL on EL 10, banning into nftables, with the jails and the server settings as .local files beside the package's own. The live test drives a jail past its limit and reads the ban out of nft rather than out of a status page, unbans it and reads the rule's absence, and checks that the same burst from an address in ignoreip is never banned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-flyctl

flyctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Fly.io's checksum file, re-checked by the live test. flyctl replaces its own binary unless told not to: the role exports FLY_NO_UPDATE_CHECK=1 for every login shell. Pinned; an API call without a token stops at 'no access token available'. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-gator

gator on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a ConstraintTemplate, a constraint requiring an owner label and two namespaces, and has gator test report the violation (exit 1) and pass the labelled one (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-graphite-exporter

graphite_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test sends plaintext samples over TCP and UDP and reads them back from /metrics with the dotted names flattened. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-hadolint

hadolint on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which lints a two-line Dockerfile with four things wrong and expects DL3008 among the findings and exit 1. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-hcledit

hcledit on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then reads a resource's bucket attribute, sets it in place, reads the file back with the neighbouring block untouched, and lists the blocks. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-istioctl

istioctl on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in Istio's per-asset .sha256, re-checked by the live test against the file's first field (one space, which sha256sum -c refuses). istioctl version waits for a cluster unless told --remote=false; the live test says so, then runs x precheck to the refused connection. Live-tested on Rocky Linux 10.

View module
Live-tested

ansible-jq

jq on EL 10 from the project's GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in sha256sum.txt, and re-checked with sha256sum -c by the live test, which then runs a filter and expects its result. The distribution's jq trails upstream by a major series; this one is pinned and installed ahead of it in the PATH. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-json-exporter

json_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test serves a JSON document on loopback as a fixture and scrapes it through the shipped module into a scalar and a labelled object metric; a dead target is a 503. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-just

just on EL 10 from the GitHub release (the static musl build), refused by Ansible's get_url unless its SHA-256 is the one in the vendor's SHA256SUMS, and re-checked by the live test, which writes a justfile, runs a recipe to its echo and lists the recipes. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-k9s

k9s on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums.sha256, and re-checked with sha256sum -c by the live test. A terminal UI needs a kubeconfig to show anything, so the live test uses k9s version and k9s info, which print the version and the per-user config paths. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kafka-exporter

kafka_exporter (SHA-256 pinned per architecture) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test brings up a KRaft broker first (the exporter exits without one), sees kafka_brokers 1, creates a topic, produces three messages and reads the partition's offset at 3. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-keepalived

keepalived on EL 10: one VRRP instance, checked by keepalived's own --config-test before it lands, with the configuration at 0600 because auth_pass is a cleartext secret. The live test waits for this node to take the virtual address, stops the service and asserts the address LEFT, then starts it and asserts it came back. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kind

kind on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256sum kind publishes, and re-checked with sha256sum -c by the live test. kind needs a container runtime it does not bring (podman on EL 10); kind get clusters with none stops at 'failed to list clusters'. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-krew

krew on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's per-asset .sha256, and the live test re-checks it, then has krew update clone the plugin index and krew install ctx land the plugin under a throwaway KREW_ROOT; a plugin the index lacks is refused. Installed as krew and kubectl-krew. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kube-bench

kube-bench on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then installs the benchmark definitions and runs the cis-1.10 node checks with --exit-code 42: on a host with no kubelet they FAIL, the summary prints, the exit code is 42. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kube-score

kube-score on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums file, and re-checked by the live test, which scores a minimal Deployment and expects the CRITICAL findings (resources, image tag, security context) and exit 1. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kubeconform

kubeconform on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the CHECKSUMS file, and re-checked by the live test, which validates two Deployments against the upstream schemas: the right one passes, the one with a string replicas is refused at /spec/replicas. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kubectl

kubectl on EL 10 from dl.k8s.io, refused by Ansible's get_url unless its SHA-256 is the one in the kubectl.sha256 file published beside it. The live test hashes the binary on disk against that file again and runs kubectl get nodes with no cluster, expecting the refused connection on localhost:8080. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kubectx

kubectx and kubens on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a two-context kubeconfig, has kubectx switch it offline and read it back, and kubens read the namespace. Both tools from one release, both checked. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kubent

kubent on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then reads a policy/v1beta1 PodDisruptionBudget from a file against a 1.32 target, expecting the finding and exit 200, then the same object on policy/v1 with exit 0. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kubeseal

kubeseal on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums file, and re-checked with sha256sum -c by the live test, which then generates a throwaway certificate, seals a one-key Secret against it with no cluster and expects a SealedSecret document. The controller stays per cluster. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-kustomize

kustomize on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's checksums.txt, and re-checked with sha256sum -c by the live test. The tag carries a slash (kustomize/v5.8.1), URL-encoded in the release path. Pinned; kustomize build against a directory with no kustomization stops where it should. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-lego

lego on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs the pinned binary and has dnshelp list the DNS-01 providers it can drive (route53, cloudflare, azuredns, gcloud among some two hundred). v5 command tree documented. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-logrotate-policy

logrotate on EL 10: one drop-in for this host's own logs, checked by logrotate before it lands, with the timer the package ships enabled. The live test writes one log past the size limit and one well under it, runs the unit the timer runs rather than forcing it, and asserts the first rotated and was truncated while the second was left alone. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-memcached

memcached from AppStream, configured through the one file its packaged unit reads; the live test stores a value and reads it back over the protocol, checks the statistics report the configured memory and threads, and asserts nothing listens on UDP, the amplification reflector's port. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-memcached-exporter

memcached_exporter (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads memcached_up 0 while nothing listens, brings up memcached on loopback as a fixture, sees memcached_up 1, stores one item over the protocol and sees it counted, stops memcached and sees memcached_up 0. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-minikube

minikube on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the per-asset .sha256 the project publishes, and compared again with the binary on disk by the live test, which then runs minikube status with no profile and expects the profile-not-found message. The driver (podman, docker, kvm2) is not this role's. Original role, live-tested on Rocky 10.

View module
Live-tested

ansible-mkcert

mkcert on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then points CAROOT at its own directory, has mkcert make the CA and a certificate for probe.test, verifies the chain with openssl and reads the SANs back; the system trust store is left alone. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-mtail

mtail on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test appends three lines to the followed log, one with ERROR, and reads lines_total 3 and errors_total 1; every program directory is compiled by --compile_only before a restart. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-mysqld-exporter

mysqld_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up MariaDB as a fixture, reads mysql_up 0 before the exporter's user exists, creates it with the monitoring grants, and reads mysql_up 1 with the status counters. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nftables

nftables from AppStream on EL 10: default-deny inbound with a port allowlist, in its own table, checked by nft before it loads. The live test opens a listener on an allowed port and on one that is not: the first answers, the second times out, the drop counter moves, and loopback still answers. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-nginx-exporter

nginx-prometheus-exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up nginx with stub_status on loopback as a fixture, sees nginx_up 1 with the connection gauges, stops nginx and sees nginx_up 0. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-ntfy

ntfy from the upstream release (sha256-verified) as a hardened system service on loopback with a message cache, a user database and deny-all as the default access. The live test sees an anonymous publish and a wrong password refused, creates a user with ntfy's own command, publishes a message and reads it back from the topic. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-pam-faillock

An account lockout on EL 10, put into the authentication stack through authselect because /etc/pam.d/system-auth is a generated symlink. The live test fails one account past the limit and watches the RIGHT password be refused, fails a second one short of the limit and watches it keep working, then resets the first and watches it come back. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-pip-audit

pip-audit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then audits a requirements file pinning requests 2.19.0 (PYSEC advisories, exit 1) and one pinning six 1.17.0 ('No known vulnerabilities found', exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-postgres-exporter

postgres_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up PostgreSQL 16 as a fixture, reads pg_up 0 before the exporter's role exists, creates it with pg_monitor, and reads pg_up 1 with per-database statistics. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-pre-commit

pre-commit on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then runs a repo-local hook over a staged repository: exit 1 naming the offending file, exit 0 with Passed once it is removed. git installed by the role. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-process-exporter

process-exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test reads /metrics and expects systemd and the exporter itself as named process groups with their CPU counters. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-rclone

rclone on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the vendor's SHA256SUMS, and re-checked by the live test, which copies a directory, lists the copy with its size and has rclone check report 0 differences. Remotes are rclone config, per user. Pinned; a newer release is a variable change. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-redis-exporter

redis_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up Valkey on loopback as a fixture, sees redis_up 1, writes a key and sees it counted in db0; the server password lives in an EnvironmentFile. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-rest-server

restic's REST backend server from the upstream release (sha256-verified) as a hardened system service on loopback, append-only and private repositories a variable away. No client is installed, so the live test speaks the protocol: creates a repository, writes its config object, reads it back, deletes it and sees it gone. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-rqlite

rqlite (SHA-256 pinned) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test sees an anonymous caller and a wrong password refused, writes a row through the HTTP API and reads it back, and finds the node leading its own raft; the users file is always written, because rqlite answers everyone without one. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-rsyslog-remote

rsyslog from AppStream as a remote receiver on EL 10: a plaintext port, RFC 5425's TLS port, and one file per sending host. The live test sends a message to each and finds both in the right file at 0640, pushes plaintext at the TLS port and finds nothing written, and checks that no remote message reached this host's own log. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-s5cmd

s5cmd on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then runs ls against a dead endpoint with the metadata service disabled, expecting NoCredentialProviders before any connection, and sees a local-to-local cp refused by design. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-slsa-verifier

slsa-verifier on EL 10 from the GitHub release, pinned by a SHA-256 the role carries (the vendor publishes no checksum file), re-checked by the live test, which then fetches the release's .intoto.jsonl and has the installed binary verify itself against it through Sigstore ('PASSED'); the wrong source tag is refused. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-snmp-exporter

snmp_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test brings up net-snmp's snmpd on loopback as a fixture and walks it through the if_mib module with the shipped snmp.yml; a dead target answers 500. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-sql-exporter

sql_exporter (sha256-verified) on EL 10 from the upstream release, as a hardened systemd service on loopback; the live test reads a 500 with no database (nothing invented), brings up PostgreSQL 16 as a fixture, reads the shipped query at 0, inserts three rows and reads 3; the config with the DSN is checked by -config.check before it lands. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-statsd-exporter

statsd_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test sends a counter, a gauge and a timer over UDP and a counter over TCP and reads them back from /metrics as Prometheus metrics. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-step

step on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then creates a root CA and a leaf offline, verifies the chain against the right root, sees it refused against another, and inspects the leaf as JSON. The client half of the step-ca role. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-step-ca

Smallstep step-ca and the step CLI from the upstream releases (sha256-verified) as a hardened system service on loopback, initialised once by its own user: root and intermediate keys, ca.json and a JWK provisioner. The live test reads the CA's health, has it issue a certificate, verifies it against the root and sees a wrong password refused. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-stern

stern on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's checksums.txt, and re-checked with sha256sum -c by the live test, which then runs stern with no kubeconfig and expects the refused connection on localhost:8080. Kubeconfig and contexts are per user. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-sudoers-policy

A sudo policy on EL 10 as a drop-in that visudo checks before it lands, with commands written out with their arguments. The live test runs the allowed command without a password and is refused three ways: another subcommand, the same command with a different argument, and a user outside the group. Both appear in sudo's own log. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-unit-hardening

The scheduler on a stock EL host scores 9.6 UNSAFE and holds every capability the kernel has. This role writes a sandboxing drop-in and proves both halves: systemd's own exposure level came down, and the service still runs its jobs. The capability set that scores best is the one that stops cron working, and the README has the table. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-journald-retention

systemd-journald on EL 10: a drop-in that moves the journal to persistent storage, seals it, and puts a ceiling on the disk it may take. The live test reads the EFFECTIVE settings back out of systemd rather than the file it wrote, finds a real journal file on disk, round-trips a message through it, and runs a vacuum. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-systemd-exporter

systemd_exporter on EL 10 from the upstream release (sha256-verified), as a hardened systemd service on loopback; the live test reads /metrics and expects the exporter's own unit reported active - D-Bus reached as an unprivileged service user. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-talosctl

talosctl on EL 10 from the GitHub release (the 118 MB bare binary), refused by Ansible's get_url unless its SHA-256 is the one in Sidero's sha256sum.txt, and re-checked by the live test, which generates a throwaway control-plane, worker and talosconfig set offline and validates the control-plane file for metal. Pinned; a newer release is a variable change. Original role, live-tested on Rocky 10.

View module
Live-tested

ansible-tenv

tenv on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then has tenv tofu install fetch OpenTofu 1.8.7 (the OpenPGP check runs when cosign is absent), lists it and runs it. Shims are opt-in so nothing shadows the host's tofu. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-terraform-docs

terraform-docs on EL 10 from the GitHub release, refused by Ansible's get_url unless its SHA-256 is the one in the project's .sha256sum, and re-checked with sha256sum -c by the live test, which then renders an empty module as a Markdown table and expects 'No requirements': parser and renderer both ran, with no terraform binary and no network. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-tfupdate

tfupdate on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then bumps required_version and the aws provider constraint in a module and reads both back; a file with an unclosed block is refused with 'failed to parse input'. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-vals

vals on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then expands a ref+file:// reference in a YAML file, sees a missing file refused, and runs ref+awsssm:// with no credentials to 'no EC2 IMDS role found'. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-yamlfmt

yamlfmt on EL 10 from the GitHub release; get_url refuses it unless its SHA-256 is in the vendor's checksums file, and the live test re-checks it, then writes a misindented file, expects -lint to exit 1, formats it in place, reads the result back byte for byte and expects the second lint to exit 0. Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-yamllint

yamllint on EL 10 from PyPI into a venv of its own with a link in the PATH; the live test runs pip check, then lints a file whose list is indented two ways (parsable output names the syntax error, exit 1) and a clean file (exit 0). Pinned. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-yq

Mike Farah's yq on EL 10 from the GitHub release, refused by get_url unless its SHA-256 is the pinned one: yq's checksum files are rhash and BSD forms that get_url cannot parse, so the live test fetches checksums-bsd for the version and asserts the SHA256 line is the pin, then reads a key from a YAML file through yq. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-zot

zot, the OCI-native registry, from the upstream release binary (sha256-verified, the minimal build by default) as a hardened system service on loopback with dedupe and garbage collection, its config checked by zot verify before it lands. The live test uploads a blob by digest, reads it back, sees the repository in the catalogue, deletes the blob. Original role, live-tested on Rocky Linux 10.

View module

Compare across clouds

All solutions →

See how the services Multi-cloud & platform-agnostic covers here compare on other providers.

Other providers