Files
fedora-infra_ansible/inventory/group_vars/packages
Nils Philippsen bd01967b92 ipa/client: enable for packages in prod
Signed-off-by: Nils Philippsen <nils@redhat.com>
2021-03-24 13:44:33 +01:00

43 lines
1.0 KiB
Plaintext

---
# Define resources for this group of hosts here.
lvm_size: 100000
mem_size: 8192
max_mem_size: 8192
num_cpus: 4
tcp_ports: [ 80, 443,
# This is for glusterd
6996,
# These 16 ports are used by fedmsg. One for each wsgi thread.
3000, 3001, 3002, 3003, 3004, 3005, 3006, 3007,
3008, 3009, 3010, 3011, 3012, 3013, 3014, 3015]
# Neeed for rsync from log01 for logs.
custom_rules: [ '-A INPUT -p tcp -m tcp -s 10.3.163.39 --dport 873 -j ACCEPT', '-A INPUT -p tcp -m tcp -s 192.168.1.59 --dport 873 -j ACCEPT' ]
primary_auth_source: ipa
ipa_host_group: packages
ipa_client_shell_groups:
- sysadmin-noc
- sysadmin-packages
- sysadmin-veteran
- sysadmin-web
ipa_client_sudo_groups:
- sysadmin-noc
- sysadmin-packages
- sysadmin-veteran
- sysadmin-web
# These are consumed by a task in roles/fedmsg/base/main.yml
fedmsg_certs:
- service: shell
owner: root
group: sysadmin
can_send:
- logger.log
freezes: false
pythonsitelib: /usr/lib/python2.7/site-packages
nfs_mount_opts: "rw,hard,bg,intr,noatime,nodev,nosuid,nfsvers=3"