Files
Ansible/docs/SECURITY.md
T
2026-09-15 18:53:28 +02:00

1.6 KiB

AIM Sensitive Data and Security Notes

Sensitive files

AIM deliberately keeps secrets outside Git.

Important locations include:

/etc/ansible/inventories/<customer>/group_vars/all/vault.yml
/etc/ansible/inventories/<customer>/group_vars/linux/.ssh/

Vault files may contain Windows and Linux authentication material. .ssh directories may contain private keys that cannot be regenerated without coordinating key rotation on managed systems.

Backup requirement

Git is not a backup for ignored secrets.

System backup procedures must include customer Vaults and SSH key material. Recovery should preserve existing current files and restore only missing data unless an operator explicitly chooses otherwise.

Vault handling

AIM encrypts newly created Vaults with ansible-vault. Plaintext populated Vault data should not remain on disk after a failed encryption attempt.

Semantic Vault comparison must not print secret values. It should compare key existence/state rather than exposing plaintext.

SSH key handling

Private-key passphrases and remote SSH passwords are separate concepts.

The Linux private key location is:

group_vars/linux/.ssh/svc_bf-ansible

Private keys should have restrictive filesystem permissions.

Authorization

AIM authorization is based on membership in a configured group resolved through NSS/SSSD/winbind/local group services. The configured group name is authoritative; numeric GIDs may differ across hosts.

Operators should verify effective membership with:

getent group '<required-group>'
id