ansible/inventory/group_vars/ipa
Nils Philippsen 006b2246b1 ipa/client: enable for ipa in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00

28 lines
617 B
Text

---
# Define resources for this group of hosts here.
lvm_size: 30000
mem_size: 6144
num_cpus: 2
tcp_ports: [ 80, 88, 389, 443, 464, 636 ]
custom_rules: [
'-A INPUT -p udp -m udp -s 10.5.0.0/16 --dport 53 -j ACCEPT'
]
primary_auth_source: ipa
ipa_host_group: ipa
ipa_host_group_desc: IPA service
ipa_client_shell_groups:
- sysadmin-accounts
ipa_client_sudo_groups:
- sysadmin-accounts
nrpe_procs_warn: 300
nrpe_procs_crit: 500
ipa_initial: false
ipa_dm_password: "{{ ipa_prod_dm_password }}"
ipa_ldap_socket: ldapi://%2fvar%2frun%2fslapd-FEDORAPROJECT-ORG.socket
host_backup_targets: ['/var/lib/ipa/backup']