Ansible Galaxy server uses HTTP

Use HTTPS and certificate verification for Galaxy server connections.

Description

An http:// URL for an Ansible Galaxy server can send role or collection requests and responses without encryption.

Potential impact

An actor able to intercept the network can read or alter metadata or download responses, undermining trust in automation dependencies.

Remediation

Set server in [galaxy] to a supported https:// URL and keep ignore_certs=False. Configure a trusted certificate for an internal server.

Examples

The examples compare connection schemes for the same Galaxy server. HTTPS protects transport; the packages themselves still need appropriate trust checks.

Before

text
[galaxy]
cache_dir=~/.ansible/galaxy_cache
ignore_certs=False
server=http://galaxy.ansible.com

After

text
[galaxy]
cache_dir=~/.ansible/galaxy_cache
ignore_certs=False
server=https://galaxy.ansible.com

References