install_files/ansible-base/securedrop-prod.yml install_files/ansible-base/securedrop-prod.yml install_files/ansible-base/securedrop-prod.yml Play #1: Ensure validation is run before prod install (1) Play #1: Ensure validation is run before prod install (1) install_files/ansible-base/securedrop-prod.yml->Play #1: Ensure validation is run before prod install (1) 1 Play #2: Prepare servers for installation (0) Play #2: Prepare servers for installation (0) install_files/ansible-base/securedrop-prod.yml->Play #2: Prepare servers for installation (0) 2 Play #3: Add FPF apt repository and install base packages. (0) Play #3: Add FPF apt repository and install base packages. (0) install_files/ansible-base/securedrop-prod.yml->Play #3: Add FPF apt repository and install base packages. (0) 3 Play #4: Configure OSSEC. (0) Play #4: Configure OSSEC. (0) install_files/ansible-base/securedrop-prod.yml->Play #4: Configure OSSEC. (0) 4 Play #5: Configure mailing utilities. (0) Play #5: Configure mailing utilities. (0) install_files/ansible-base/securedrop-prod.yml->Play #5: Configure mailing utilities. (0) 5 Play #6: Configure SecureDrop Application Server. (0) Play #6: Configure SecureDrop Application Server. (0) install_files/ansible-base/securedrop-prod.yml->Play #6: Configure SecureDrop Application Server. (0) 6 Play #7: Lock down firewall configuration for Application and Monitor Servers. (0) Play #7: Lock down firewall configuration for Application and Monitor Servers. (0) install_files/ansible-base/securedrop-prod.yml->Play #7: Lock down firewall configuration for Application and Monitor Servers. (0) 7 Play #8: Reboot Application and Monitor Servers. (0) Play #8: Reboot Application and Monitor Servers. (0) install_files/ansible-base/securedrop-prod.yml->Play #8: Reboot Application and Monitor Servers. (0) 8 [role] validate [role] validate Play #1: Ensure validation is run before prod install (1)->[role] validate 1 [role] prepare-servers [role] prepare-servers Play #2: Prepare servers for installation (0)->[role] prepare-servers 1 [role] install-fpf-repo [role] install-fpf-repo Play #3: Add FPF apt repository and install base packages. (0)->[role] install-fpf-repo 6 [role] grsecurity [role] grsecurity Play #3: Add FPF apt repository and install base packages. (0)->[role] grsecurity 7 [role] common [role] common Play #3: Add FPF apt repository and install base packages. (0)->[role] common 8 [role] tor-hidden-services [role] tor-hidden-services Play #3: Add FPF apt repository and install base packages. (0)->[role] tor-hidden-services 9 pre_task_deebc439-042a-4fea-baec-59b4ca3b9674 [pre_task] Check if install has been done before Play #3: Add FPF apt repository and install base packages. (0)->pre_task_deebc439-042a-4fea-baec-59b4ca3b9674 1 pre_task_436b07a0-6299-43a7-af69-009a13be094d [pre_task] Seek for existing tor aths ssh files Play #3: Add FPF apt repository and install base packages. (0)->pre_task_436b07a0-6299-43a7-af69-009a13be094d 2  [when: not enable_ssh_over_torsd_dir_check.stat.exists] pre_task_0ae1a3c2-6f9c-4ce7-9195-5d9f84270b95 [pre_task] Delete any aths ssh files found Play #3: Add FPF apt repository and install base packages. (0)->pre_task_0ae1a3c2-6f9c-4ce7-9195-5d9f84270b95 3  [when: not enable_ssh_over_torsd_dir_check.stat.exists] pre_task_bdc0901a-dd59-472d-b34b-2e92bb852a43 [pre_task] Force a reboot conditionally, when tor_over_ssh status changed Play #3: Add FPF apt repository and install base packages. (0)->pre_task_bdc0901a-dd59-472d-b34b-2e92bb852a43 4  [when: not enable_ssh_over_torsd_dir_check.stat.existsaths_deletion_results.changed] pre_task_7cee7635-fd37-4f7d-b911-a92954b26b76 [pre_task] Provide helpful user message and end early Play #3: Add FPF apt repository and install base packages. (0)->pre_task_7cee7635-fd37-4f7d-b911-a92954b26b76 5  [when: not enable_ssh_over_torsd_dir_check.stat.existsaths_deletion_results.changed] [role] ossec [role] ossec Play #4: Configure OSSEC. (0)->[role] ossec 1 [role] postfix [role] postfix Play #5: Configure mailing utilities. (0)->[role] postfix 1 [role] app [role] app Play #6: Configure SecureDrop Application Server. (0)->[role] app 1 [role] restrict-direct-access [role] restrict-direct-access Play #7: Lock down firewall configuration for Application and Monitor Servers. (0)->[role] restrict-direct-access 1 [role] reboot-if-first-install [role] reboot-if-first-install Play #8: Reboot Application and Monitor Servers. (0)->[role] reboot-if-first-install 1