Files
ansible/inventory/group_vars/all.yml
T
2026-10-05 19:14:46 -04:00

86 lines
1.7 KiB
YAML

---
#ansible_user: xadmin
packages_common:
- 'bash'
- 'curl'
- 'screen'
- 'unzip'
- 'vim'
- 'wget'
- 'zip'
# common apache config
apache_listen_ip: '*'
apache_listen_port: 80
# merge apache config arrays
apache_mods_enabled: >-
{{
(apache_mods_enabled_gitea | default([]))
+ (apache_mods_enabled_munin | default([]))
}}
apache_vhosts: >-
{{
(apache_vhosts_gitea | default([]))
+ (apache_vhosts_munin | default([]))
}}
docker_add_repo: true
docker_install_compose_plugin: false
docker_users:
- 'gballan'
munin_node_host_name: "{{ ansible_fqdn }}"
munin_node_allowed_ips:
- '^10\.7\.10\.35$'
- '^127\.0\.0\.1$'
- '^::1$'
munin_node_plugins:
- name: 'cpu'
- name: 'df'
- name: 'memory'
- name: 'swap'
- name: 'threads'
- name: 'uptime'
- name: 'users'
ntp_enabled: true
ntp_timezone: 'America/New_York'
ntp_package: 'chrony'
ntp_daemon: 'chronyd'
ntp_config_file: '/etc/chrony/chrony.conf'
ntp_driftfile: '/var/lib/chrony/chrony.drift'
ntp_manage_config: true
ntp_servers:
- 'virginia.time.system76.com iburst'
- 'ohio.time.system76.com iburst'
- 'oregon.time.system76.com iburst'
ntp_restrict:
- '127.0.0.1'
- '::1'
# SSSD & OpenLDAP core settings
sssd_nss_homedir_substring: '/nfs/users'
sssd_domain_name: "metaunix"
openldap_host: "ldap.int.metaunix.net"
openldap_port: 636
openldap_use_starttls: false
openldap_search_base: "dc=metaunix,dc=net"
openldap_schema: "rfc2307"
# TLS / Certificate validation
sssd_disable_tls_verify: true
# Behavior & Performance
sssd_enable_mkhomedir: true
sssd_cache_credentials: true
sssd_enumerate: false
sssd_default_shell: "/bin/bash"
sudoers_sudoers:
privileges:
- name: '%sudo'
entry: 'ALL=(ALL) ALL'
- name: '%linuxadmins'
entry: 'ALL=NOPASSWD:ALL'