- Rename inventory groups and group_vars to hostnames (phy-z-*) - Add group_vars for all servers incl. planned phy-z-srv-gpu01 - Add server/ docs: sftp01, git, gpu01 (README, HW specs, assessments) - Add rules set to CLAUDE.md Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
44 lines
1.2 KiB
YAML
44 lines
1.2 KiB
YAML
---
|
|
# generic settings
|
|
main_username: sbxadmin
|
|
main_groupname: "{{ main_username }}"
|
|
main_uid: "1000"
|
|
main_gid: "{{ main_uid }}"
|
|
|
|
# weareinteractive.environment
|
|
environment_config: { "PUID": "{{ main_gid }}", "PGID": "{{ main_gid }}" }
|
|
|
|
global_env_vars:
|
|
- "PUID={{ main_uid }}"
|
|
- "PGID={{ main_gid }}"
|
|
- "TZ={{ ntp_timezone }}"
|
|
|
|
# geerlingguy.ntp
|
|
ntp_timezone: "Europe/Berlin"
|
|
|
|
# geerlingguy.nfs
|
|
#nfs_exports: [ "/home/public *(rw,sync,no_root_squash)" ]
|
|
|
|
# geerlingguy.security
|
|
security_ssh_port: 22
|
|
security_ssh_password_authentication: "yes"
|
|
security_ssh_permit_root_login: "no"
|
|
security_ssh_usedns: "no"
|
|
security_ssh_permit_empty_password: "no"
|
|
security_ssh_challenge_response_auth: "no"
|
|
security_ssh_gss_api_authentication: "no"
|
|
security_ssh_x11_forwarding: "no"
|
|
security_ssh_allowed_users:
|
|
- "{{ main_username }}"
|
|
security_ssh_allowed_groups: []
|
|
security_sudoers_passwordless:
|
|
- "{{ main_username }}"
|
|
security_autoupdate_enabled: true
|
|
security_autoupdate_blacklist: []
|
|
security_autoupdate_reboot: reboot
|
|
security_autoupdate_reboot_time: "03:00"
|
|
security_autoupdate_mail_to: "service@softbox.de"
|
|
security_autoupdate_mail_on_error: true
|
|
security_fail2ban_enabled: true
|
|
security_fail2ban_custom_configuration_template: "jail.local.j2"
|