Ross ROSS = Recommend OSS · open-source software intelligence for agents

dev-sec/ansible-collection-hardening

This Ansible collection provides battle tested hardening for Linux, SSH, nginx, MySQL observed · 2026-08-28

github.com/dev-sec/ansible-collection-hardening · homepage · Jinja · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

90/100

  • Activity 98
  • Release rhythm 74
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 63.5
  • age_days: 4139
  • days_rel: 99
  • days_push: 13
  • n_releases_24m: 9

Full methodology

Adoption not part of the score

5450 stars · 830 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

An Ansible collection of battle-tested hardening roles for Linux operating systems, SSH, nginx, and MySQL/MariaDB. It automates secure configuration and attack-surface reduction, aligned with the DevSec InSpec compliance baselines.

Use cases

  • harden linux servers with ansible
  • secure sshd configuration automatically
  • apply cis-style hardening to ubuntu and debian servers
  • harden nginx and mysql configurations
  • automate server security compliance
  • reduce attack surface of cloud vms
  • enforce secure sysctl kernel settings

When to choose

  • you use Ansible to provision or manage Linux servers and want automated, tested hardening
  • you need compliance with DevSec/InSpec baselines or similar security standards
  • you want maintained, community-validated secure defaults for SSH, nginx, MySQL, and the OS

When to avoid

  • your infrastructure is not managed with Ansible (consider the Chef or Puppet variants of dev-sec instead)
  • you need hardening for Windows servers or other services like Apache or PostgreSQL
  • you require fully hands-off compliance certification rather than configuration automation

Facets

plugin · maturity active

security configuration-management developer-tools security self-hosted infrastructure-as-code self-hosted cloud ansible ansible-collection hardening ssh-hardening os-hardening nginx-hardening mysql-hardening sysctl devsec compliance cis-benchmark devops linux

3 sources

Member repositories

RepositoryRoleHealth v2
dev-sec/ansible-collection-hardeningmain90

For agents

markdown · JSON · MCP: product_card(name="dev-sec/ansible-collection-hardening")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem