- name: Gather the package facts
package_facts:
manager: auto
tags:
- disable_strategy
- low_complexity - low_disruption
- low_severity
- no_reboot_needed
- service_snmpd_disabled
- name: Block Disable service snmpd
block:
- name: Disable service snmpd
block:
- name: Disable service snmpd
systemd:
name: snmpd.service
enabled: 'no'
state: stopped
masked: 'yes'
rescue:
- name: Intentionally ignored previous 'Disable service snmpd' failure, service
was already disabled
meta: noop
when: ( ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman",
"container"] and "snmpd" in ansible_facts.packages )
tags:
- disable_strategy
- low_complexity
- low_disruption
- low_severity
- no_reboot_needed
- service_snmpd_disabled
- name: Unit Socket Exists - snmpd.socket
command: systemctl -q list-unit-files snmpd.socket
register: socket_file_exists
changed_when: false
failed_when: socket_file_exists.rc not in [0, 1]
check_mode: false
when: ( ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman",
"container"] and "snmpd" in ansible_facts.packages )
tags:
- disable_strategy
- low_complexity
- low_disruption
- low_severity
- no_reboot_needed
- service_snmpd_disabled
- name: Disable socket snmpd
systemd:
name: snmpd.socket
enabled: 'no'
state: stopped
masked: 'yes'
when:
- ( ansible_virtualization_type not in ["docker", "lxc", "openvz", "podman", "container"]
and "snmpd" in ansible_facts.packages )
- socket_file_exists.stdout_lines is search("snmpd.socket",multiline=True)
tags:
- disable_strategy
- low_complexity
- low_disruption
- low_severity
- no_reboot_needed
- service_snmpd_disabled