--- - name: Install raspberry pi become: true hosts: raspberry_pis # roles: # These roles are disabled after they have being applied once for performance reasons, it should be safe to enable them again. # Notice that this role changes some settings on reruns (on the "Change various sysctl-settings" task), doesn't seem problematic though. # - devsec.hardening.os_hardening vars: # devsec.hardening.os_hardening vars: os_auth_pw_max_age: 99999 # Effectively disables the setting as mentioned in the docs. os_cron_enabled: false # Cron isn't needed for the installation. sysctl_overwrite: vm.mmap_rnd_bits: 16 # See the "sysctl - vm.mmap_rnd_bits" section of the docs. tasks: # Disable warning on updating latest packages, it should be safe enough for this system. - name: Update all packages to their latest version # noqa: package-latest ansible.builtin.apt: name: "*" state: latest