Add ldap-adm.adm.crans.org as main slapd server

main
_benjamin 2022-11-04 19:35:59 +01:00
parent 9377f67598
commit 90f4028597
8 changed files with 14 additions and 8 deletions

View File

@ -3,6 +3,7 @@ glob_ldap:
uri: 'ldap://re2o-ldap.adm.crans.org/' uri: 'ldap://re2o-ldap.adm.crans.org/'
users_base: 'cn=Utilisateurs,dc=crans,dc=org' users_base: 'cn=Utilisateurs,dc=crans,dc=org'
servers: servers:
- 172.16.10.100
- 172.16.10.1 - 172.16.10.1
- 172.16.10.11 - 172.16.10.11
- 172.16.10.12 - 172.16.10.12

View File

@ -12,4 +12,4 @@ glob_service_ssh_known_hosts:
frequency: "*/10 * * * *" frequency: "*/10 * * * *"
config: config:
ldap: ldap:
server: "ldaps://{{ query('ldap', 'ip', 'tealc', 'adm') | ansible.utils.ipv4 | first }}" server: "ldaps://{{ query('ldap', 'ip', 'ldap-adm', 'adm') | ansible.utils.ipv4 | first }}"

View File

@ -13,7 +13,7 @@ glob_service_prometheus_target:
options: "" options: ""
config: config:
ldap: ldap:
server: "ldaps://{{ query('ldap', 'ip', 'tealc', 'adm') | ansible.utils.ipv4 | first }}" server: "ldaps://{{ query('ldap', 'ip', 'ldap-adh', 'adm') | ansible.utils.ipv4 | first }}"
glob_ninjabot: glob_ninjabot:
config: config:

View File

@ -1,7 +1,7 @@
--- ---
glob_slapd: glob_slapd:
master_ip: "{{ query('ldap', 'ip', 'tealc', 'adm') | ansible.utils.ipv4 | first }}" master_ip: "{{ query('ldap', 'ip', 'ldap-adm', 'adm') | ansible.utils.ipv4 | first }}"
regex: "^(role:(dhcp|dns|dns-primary|dns-secondary|ftp|gitlab|miroir|ntp|pve|radius|backup)|ecdsa-sha2-nistp256:.*|ssh-(ed25519|dss|rsa):.*|description:.*|location:.*)$" regex: "^(role:(dhcp|dns|dns-primary|dns-secondary|ftp|gitlab|miroir|ntp|pve|radius|backup)|ecdsa-sha2-nistp256:.*|ssh-(ed25519|dss|rsa):.*|description:.*|location:.*)$"
replication_credentials: "{{ vault.slapd.tealc.replication_credentials }}" replication_credentials: "{{ vault.slapd.main.replication_credentials }}"
private_key: "{{ vault.slapd.tealc.private_key }}" private_key: "{{ vault.slapd.main.private_key }}"
certificate: "{{ vault.slapd.tealc.certificate }}" certificate: "{{ vault.slapd.main.certificate }}"

View File

@ -12,7 +12,7 @@ glob_service_proxmox_user:
config: config:
ldap: ldap:
admin: admin:
uri: "ldaps://{{ query('ldap', 'ip', 'tealc', 'adm') | ansible.utils.ipv4 | first }}/" uri: "ldaps://{{ query('ldap', 'ip', 'ldap-adm', 'adm') | ansible.utils.ipv4 | first }}/"
userBase: "ou=passwd,dc=crans,dc=org" userBase: "ou=passwd,dc=crans,dc=org"
realm: "pam" realm: "pam"
user: user:

View File

@ -63,7 +63,7 @@ loc_wireguard:
loc_service_proxy: loc_service_proxy:
config: config:
ldap: ldap:
server: "ldaps://{{ query('ldap', 'ip', 'tealc', 'adm') | ansible.utils.ipv4 | first }}/" server: "ldaps://{{ query('ldap', 'ip', 'ldap-adm', 'adm') | ansible.utils.ipv4 | first }}/"
protocol: "proxy" protocol: "proxy"
filter: "adm.crans.org" filter: "adm.crans.org"
proxy: proxy:

View File

@ -0,0 +1,3 @@
loc_slapd:
ip: "{{ query('ldap', 'ip', 'ldap-adm', 'adm') | ipv4 | first }}"
replica: false

2
hosts
View File

@ -238,6 +238,7 @@ helloworld.adm.crans.org
daniel.adm.crans.org daniel.adm.crans.org
ft.adm.crans.org ft.adm.crans.org
jack.adm.crans.org jack.adm.crans.org
ldap-adm.adm.crans.org
sam.adm.crans.org sam.adm.crans.org
sputnik.adm.crans.org sputnik.adm.crans.org
tealc.adm.crans.org tealc.adm.crans.org
@ -317,6 +318,7 @@ irc.adm.crans.org
jitsi.adm.crans.org jitsi.adm.crans.org
kenobi.adm.crans.org kenobi.adm.crans.org
kiwi.adm.crans.org kiwi.adm.crans.org
ldap-adm.adm.crans.org
linx.adm.crans.org linx.adm.crans.org
mailman.adm.crans.org mailman.adm.crans.org
neree.adm.crans.org neree.adm.crans.org