Commit graph

1139 commits

Author SHA1 Message Date
47e5fe321c More lint fixes 2020-08-26 21:53:35 +03:00
d4a11404fd Lint fixes 2020-08-26 21:38:18 +03:00
65fcb4035e Aggressive line shortening to get past yamllint 2020-08-26 21:22:22 +03:00
18df5f418c Fix typo, rename disk vars and cleanup 2020-08-26 21:03:05 +03:00
6798c71285 Make vars more readable and fix one lint error 2020-08-26 20:28:15 +03:00
d54fe7975c Don't set password for root. Just lock account. 2020-08-26 20:24:08 +03:00
54b5a74f54 Use cpu cores instead of sockets for kvm guests 2020-08-26 20:20:04 +03:00
6bf4815503 Store console output to logfile on kvm guests 2020-08-26 20:12:12 +03:00
40963ea620 Relocate kvm guest disk images 2020-08-26 20:07:55 +03:00
af6e3098d5 fix centos8 mirror location 2020-08-26 19:53:03 +03:00
08d1495026 syslogd: lint fixes 2020-02-28 00:09:17 +02:00
302427c85f selinux: update module to support centos 8 2020-02-28 00:07:10 +02:00
7a19cf852c add support for installing centos 8 virtual machines 2020-02-27 14:24:16 +02:00
3dbb65302e base: fix warning of cron job hour value (should be string) 2020-02-27 14:12:09 +02:00
08466f3143 base: remove rcs from default installs 2020-02-27 14:08:12 +02:00
1fcc2dd407 add remote logging support to rsyslog 2019-07-19 18:04:53 +03:00
53c31e62d1 add log.yml playbook to site wide playbook 2019-07-19 17:59:10 +03:00
bc37d38eaf do not restrict syslog port by ip address 2019-07-19 17:58:14 +03:00
6085718f5d enable remote logging for syslogd 2019-07-19 17:55:54 +03:00
d11300df60 add syslog support for proxies 2019-07-19 17:55:22 +03:00
afd81c714c add log01 host 2019-07-19 17:20:15 +03:00
7088bc9b14 add server support for syslogd 2019-07-19 17:16:59 +03:00
9b3bfe9bc8 nginx: use mozilla recommended ssl options 2019-07-05 10:20:25 +03:00
6cd29b72a7 nginx: enable http2 protocol 2019-07-05 10:20:00 +03:00
84db430875 add foo.sh layout to cups web interface 2019-06-14 11:20:51 +03:00
a496da62b0 add more cups configuration 2019-06-14 11:09:23 +03:00
5afff575c5 change cups authentication to use kerberos 2019-06-14 10:12:07 +03:00
bd1205af61 add ldap/nss role to git hosts to fix repository owner name 2019-06-13 20:02:22 +03:00
8920d79078 selinux file context fixes for nginx data directories 2019-06-11 15:53:55 +03:00
5016b70292 make sure that selinux contexts are correct in ldap data directory 2019-06-11 15:52:53 +03:00
020a10677b add ldap/nss to cups/server dependency to get group access correct 2019-06-10 21:06:00 +03:00
9fc02e7bef add role ldap/nss 2019-06-10 21:05:08 +03:00
998dc0b643 install htop on all hosts 2019-06-10 19:24:15 +03:00
3129b5e58c first version of cups server role 2019-06-10 19:23:36 +03:00
6541059276 set sasl-host to get kerberos tickets match hostname 2019-06-08 17:28:58 +03:00
6c6dcda8ac add ldap02 host 2019-06-08 17:28:29 +03:00
d599adcd95 enable ldap slave 2019-06-08 17:24:42 +03:00
8335a9723e copy keytab instead of generating it 2019-06-08 17:23:51 +03:00
c69316ec6f remove unused ldap02.foo.sh site from proxies 2019-06-06 23:16:54 +03:00
bc51574113 rename ansible_dir_private to ansible_private 2019-06-06 23:16:06 +03:00
b13fbe1c2a add support for ldap replication 2019-06-06 22:11:10 +03:00
b6b3dbbca3 more authz regexp base dn's for gssapi authentication 2019-06-06 02:30:56 +03:00
da6ed9d4ac force sasl to use external (certificates) when connecting ldap as root 2019-06-06 02:29:59 +03:00
1a22ce543b lint fixes 2019-06-06 02:04:51 +03:00
d512c8b8bd add gssapi auth support for ldap server 2019-06-06 01:58:04 +03:00
9cd3910f42 rename keytab to be more logical 2019-06-06 01:56:52 +03:00
b533542b57 add support for defining multiple upstream servers for proxy sites 2019-06-06 01:56:00 +03:00
11e4a82a35 configure authz mappings for gssapi authenticated users 2019-06-06 01:54:54 +03:00
1979925f7e always install login/plain support for sasl 2019-06-06 01:52:36 +03:00
00f7b86de6 first version of kerberos/keytab role 2019-06-06 00:29:10 +03:00