Skip to content

Conversation

@BGmot
Copy link
Collaborator

@BGmot BGmot commented May 14, 2025

SUMMARY

Replacement for #1489

Restrict access to the web frontend config file /etc/zabbix/web/zabbix.conf.php.
The file contains passwords, so should not be publicly readable. Also fix the owner for the case that the fpm user differs from the www user.

ISSUE TYPE
  • Bugfix Pull Request
COMPONENT NAME

zabbix_web role

Copy link
Collaborator

@eb4x eb4x left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Perfect! 👍

@eb4x
Copy link
Collaborator

eb4x commented May 14, 2025

You could also simplify the check in zabbix_web/templates/php-fpm.conf.j2 to just use the php value, since it's always provided by defaults/main.yml.

@BGmot BGmot merged commit cbb3c9f into ansible-collections:main May 14, 2025
75 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants