#Playbook to deploy Hardening Guide?

1 messages · Page 1 of 1 (latest)

scenic brook
#

Have we automated, in any way, the deployment of TR-4569, ONTAP Hardening Best Practices?

rose surge
#

On the Dev Side i'm not aware of one, just looking through the doc it looks like most if not could be automated in a playbook.

unkempt jolt
#

anyone already working on this....

rose surge
#

Not that i'm aware of.

magic spruce
#

Might try asking in 'security' or dm @midnight sail - I seem to recall something a while back that they posted on GitHub.

#

A few years old now - might need an update

midnight sail
#

Yes that's the one for Ansible. Does need an update but most it's still relevant. However both System Manager (via Sys Mgr Insights) and AIQUM (via AIQUM Security Dashboard) have graphical ways to configure security based on the hardening guide.

scenic brook
#

It's more about having a "Hardened by Default" sort of posture as a deployment option...

#

Not a Day2 "run these scripts once it's done" kind of thing.

#

Even if we could only get a %'age of the way there

latent sparrow
#

This approach would work well as a layer on top of what their ONTAP deployment process already is.