diff --git a/evolinux-base/defaults/main.yml b/evolinux-base/defaults/main.yml index 98ff43ef..26f6e4c8 100644 --- a/evolinux-base/defaults/main.yml +++ b/evolinux-base/defaults/main.yml @@ -51,7 +51,7 @@ evolinux_kernel_include: True evolinux_kernel_reboot_after_panic: True evolinux_kernel_disable_tcp_timestamps: True evolinux_kernel_customize_swappiness: True -evolinux_kernel_swappiness: 20 +evolinux_kernel_swappiness: "20" evolinux_kernel_cve20165696: True # fstab diff --git a/evolinux-base/tasks/kernel.yml b/evolinux-base/tasks/kernel.yml index 282e10eb..76965f47 100644 --- a/evolinux-base/tasks/kernel.yml +++ b/evolinux-base/tasks/kernel.yml @@ -44,7 +44,7 @@ - name: Patch for TCP stack vulnerability CVE-2016-5696 sysctl: name: net.ipv4.tcp_challenge_ack_limit - value: 1073741823 + value: "1073741823" sysctl_file: "{{ evolinux_kernel_sysctl_path }}" state: present reload: yes @@ -58,9 +58,9 @@ state: present reload: yes loop: - - { name: "net.ipv4.ipfrag_low_thresh", value: 196608 } - - { name: "net.ipv6.ip6frag_low_thresh", value: 196608 } - - { name: "net.ipv4.ipfrag_high_thresh", value: 262144 } - - { name: "net.ipv6.ip6frag_high_thresh", value: 262144 } + - { name: "net.ipv4.ipfrag_low_thresh", value: "196608" } + - { name: "net.ipv6.ip6frag_low_thresh", value: "196608" } + - { name: "net.ipv4.ipfrag_high_thresh", value: "262144" } + - { name: "net.ipv6.ip6frag_high_thresh", value: "262144" } - meta: flush_handlers