Adding SSSD config
ci/woodpecker/push/woodpecker Pipeline failed

This commit is contained in:
2026-09-28 10:21:34 -04:00
parent 43d7b9fce6
commit 61f3d73d70
2 changed files with 28 additions and 0 deletions
+21
View File
@@ -59,6 +59,27 @@ ntp_restrict:
- '127.0.0.1' - '127.0.0.1'
- '::1' - '::1'
# SSSD & OpenLDAP core settings
sssd_domain_name: "metaunix"
openldap_host: "ldap.int.metaunix.net"
openldap_port: 636
openldap_use_starttls: false
openldap_search_base: "dc=metaunix,dc=net"
openldap_schema: "rfc2307bis"
# TLS / Certificate validation
sssd_disable_tls_verify: true
# Behavior & Performance
sssd_enable_mkhomedir: true
sssd_cache_credentials: true
sssd_enumerate: false
sssd_default_shell: "/bin/bash"
# Bind Account (referencing vaulted secret below)
openldap_bind_dn: "cn=sssd-service,ou=Services,dc=internal,dc=local"
openldap_bind_password: "{{ vault_openldap_bind_password }}"
sudoers_sudoers: sudoers_sudoers:
privileges: privileges:
- name: '%sudo' - name: '%sudo'
+7
View File
@@ -1,5 +1,12 @@
--- ---
- name: Install and configure SSSD
hosts: all
become: true
roles:
- gballan.sssd
- name: Configure sudoers - name: Configure sudoers
hosts: all hosts: all
become: true become: true