Restrict access rights for credential file

This commit is contained in:
phil 2023-06-14 17:59:44 +02:00
parent 732d4ccabb
commit fb7718ee0f

View file

@ -32,27 +32,28 @@
- name: "Postfix | Copy lookup tables from templates" - name: "Postfix | Copy lookup tables from templates"
ansible.builtin.template: ansible.builtin.template:
src: "postfix/conf.d/{{ item }}.j2" src: "postfix/conf.d/{{ item.name }}.j2"
dest: "{{ postfix_conf_dir }}/{{ item }}" dest: "{{ postfix_conf_dir }}/{{ item.name }}"
mode: "0644" mode: "{{ item.mode | default(0644) }}"
loop: loop:
- bad_smtp_auth_users - name: bad_smtp_auth_users
- bogus_mx - name: bogus_mx
- canonical - name: canonical
- client_checks - name: client_checks
- destination_limit - name: destination_limit
- header_add - name: header_add
- header_treatment - name: header_treatment
- helo_checks - name: helo_checks
- permit_sasl_login_mismatch - name: permit_sasl_login_mismatch
- postscreen_access - name: postscreen_access
- relay_by_sender - name: relay_by_sender
- relay_checks - name: relay_checks
- sender_canonical - name: sender_canonical
- sender_checks - name: sender_checks
- smtp_sasl_auth_password - name: smtp_sasl_auth_password
- transport_global_exceptions mode: "0600"
- transport_relay - name: transport_global_exceptions
- name: transport_relay
notify: reload postfix notify: reload postfix
- name: "Postfix | Run postmap" - name: "Postfix | Run postmap"