- name: 'Install SELinux' apt: pkg: - selinux-basics - selinux-policy-default - auditd state: present - name: 'Activate SELinux' shell: selinux-activate when: ansible_selinux.status == "disabled" - name: 'Reboot after SElLinux install' reboot: when: ansible_selinux.status == "disabled" - name: 'Check SELinux in permissive mode' ansible.posix.selinux: policy: default state: permissive