php: enforce permissions on /etc directories

This commit is contained in:
Jérémy Lecour 2018-06-15 11:17:34 +02:00 committed by Jérémy Lecour
parent 82295b6f8c
commit 1593773937
3 changed files with 58 additions and 0 deletions

View file

@ -52,10 +52,29 @@
# Configuration
- name: Enforce permissions on PHP directory
file:
dest: /etc/php5
mode: "0755"
- include: config_cli.yml
- name: Enforce permissions on PHP cli directory
file:
dest: /etc/php5/cli
mode: "0755"
- include: config_fpm.yml
when: php_fpm_enable
- name: Enforce permissions on PHP fpm directory
file:
dest: /etc/php5/fpm
mode: "0755"
when: php_fpm_enable
- include: config_apache.yml
when: php_apache_enable
- name: Enforce permissions on PHP apache2 directory
file:
dest: /etc/php5/apache2
mode: "0755"
when: php_apache_enable

View file

@ -60,13 +60,35 @@
# Configuration
- name: Enforce permissions on PHP directory
file:
dest: "{{ item ss}}"
mode: "0755"
with_items:
- /etc/php
- /etc/php/7.0
- include: config_cli.yml
- name: Enforce permissions on PHP cli directory
file:
dest: /etc/php/7.0/cli
mode: "0755"
- include: config_fpm.yml
when: php_fpm_enable
- name: Enforce permissions on PHP fpm directory
file:
dest: /etc/php/7.0/fpm
mode: "0755"
when: php_fpm_enable
- include: config_apache.yml
when: php_apache_enable
- name: Enforce permissions on PHP apache2 directory
file:
dest: /etc/php/7.0/apache2
mode: "0755"
when: php_apache_enable
- include: sury_post.yml
when: php_sury_enable

View file

@ -10,6 +10,11 @@
- { src: "{{ php_cli_defaults_ini_file }}", dest: "/etc/php/7.2/cli/conf.d/z-evolinux-defaults.ini" }
- { src: "{{ php_cli_custom_ini_file }}", dest: "/etc/php/7.2/cli/conf.d/zzz-evolinux-custom.ini" }
- name: Enforce permissions on PHP 7.2/cli directory
file:
dest: /etc/php/7.2/cli
mode: "0755"
- name: Symlink Evolix Apache config files from 7.2 to 7.0
file:
src: "{{ item.src }}"
@ -21,6 +26,12 @@
- { src: "{{ php_apache_custom_ini_file }}", dest: "/etc/php/7.2/apache2/conf.d/zzz-evolinux-custom.ini" }
when: php_apache_enable
- name: Enforce permissions on PHP 7.2/cli directory
file:
dest: /etc/php/7.2/apache2
mode: "0755"
when: php_apache_enable
- name: Symlink Evolix FPM config files from 7.2 to 7.0
file:
src: "{{ item.src }}"
@ -33,3 +44,9 @@
- { src: "{{ php_fpm_defaults_conf_file }}", dest: "/etc/php/7.2/fpm/pool.d/z-evolinux-defaults.conf" }
- { src: "{{ php_fpm_custom_conf_file }}", dest: "/etc/php/7.2/fpm/pool.d/zzz-evolinux-custom.conf" }
when: php_fpm_enable
- name: Enforce permissions on PHP 7.2/cli directory
file:
dest: /etc/php/7.2/fpm
mode: "0755"
when: php_fpm_enable