Permits invocations of ansible-playbook with the --check flag, essentially a dry run to inspect intended changes without actually changing the state of the server.
Also snips out the paxctl command, deferring to a separate role for managing paxctld when running under grsecurity. Will add docs once that role is available.
Permits invocations of
ansible-playbook
with the--check
flag, essentially a dry run to inspect intended changes without actually changing the state of the server.Also snips out the
paxctl
command, deferring to a separate role for managingpaxctld
when running under grsecurity. Will add docs once that role is available.