mirror of
https://github.com/DO1JLR/ansible_playbook_servers.git
synced 2024-09-14 19:53:56 +02:00
102 lines
2.5 KiB
YAML
102 lines
2.5 KiB
YAML
---
|
|
users:
|
|
l3d:
|
|
- l3d@pinkie.l3d.yt
|
|
- l3d@mobile.l3d.yt
|
|
- l3d@backup.l3d.yt
|
|
- l3d@derpy.l3d.yt
|
|
- l3d@backup-rsa.l3d.yt
|
|
- l3d@business.wingcon.com
|
|
weechat:
|
|
- l3d@pinkie.l3d.yt
|
|
- l3d@mobile.l3d.yt
|
|
- l3d@backup.l3d.yt
|
|
- l3d@derpy.l3d.yt
|
|
- l3d@backup-rsa.l3d.yt
|
|
- l3d@business.wingcon.com
|
|
mailwebuser:
|
|
- l3d@pinkie.l3d.yt
|
|
- l3d@mobile.l3d.yt
|
|
- l3d@backup.l3d.yt
|
|
- l3d@derpy.l3d.yt
|
|
- l3d@backup-rsa.l3d.yt
|
|
- l3d@business.wingcon.com
|
|
|
|
accounts:
|
|
- l3d
|
|
- mailwebuser
|
|
- weechat
|
|
|
|
# mail domains
|
|
additional_dns_maildomains: 'mail.l3d.space imap.l3d.space smtp.l3d.space'
|
|
|
|
# mailserver
|
|
mailserver_domain: "{{ _mailserver_domain }}"
|
|
postfix__inet_interfaces: "127.0.0.1, ::1, {{ hostvars[ inventory_hostname ].ansible_default_ipv4.address }}, {{ hostvars[ inventory_hostname ].ansible_default_ipv6.address }}"
|
|
|
|
# mail mysql access
|
|
mailserver__mysql_password: "{{ _mailserver__mysql_password }}"
|
|
mailserver__mysql_user: "{{ _mailserver__mysql_user }}"
|
|
mailserver__mysql_database: "{{ _mailserver__mysql_database }}"
|
|
mailserver__ssl_cert: "{{ _mailserver__ssl_cert }}"
|
|
mailserver__ssl_key: "{{ _mailserver__ssl_key }}"
|
|
postfix__db_user: "{{ _mailserver__mysql_user }}"
|
|
postfix__db_password: "{{ _mailserver__mysql_password }}"
|
|
postfix__db_name: "{{ _mailserver__mysql_database }}"
|
|
|
|
nginx_sites:
|
|
- name: 'mail.l3d.space'
|
|
webroot:
|
|
user: 'mailwebuser'
|
|
- name: "{{ mailserver_domain }}"
|
|
|
|
# letsencrypt
|
|
acme_notification_email: "{{ _acme_notification_email }}"
|
|
|
|
# firewall
|
|
fail2ban_destemail: "{{ _fail2ban_destemail }}"
|
|
firewall_allowed_tcp_ports:
|
|
- "22"
|
|
- "25"
|
|
- "80"
|
|
- "143"
|
|
- "443"
|
|
- "465"
|
|
- "587"
|
|
- "993"
|
|
- "4190"
|
|
- "42023"
|
|
|
|
# mysql
|
|
mysql_bind_address: "{{ _mysql_bind_address }}"
|
|
mysql_root_password: "{{ _mysql_root_password }}"
|
|
|
|
# weechat
|
|
weechat__install: true
|
|
weechat__autostart: true
|
|
weechat__user: 'weechat'
|
|
weechat__home_directory: '/home/weechat'
|
|
weechat__install_plugins: true
|
|
weechat__use_custom_config: true
|
|
weechat__custom_private_repo: 'gitea@backwesen.de:l3d/weechat-config.git'
|
|
weechat__custom_gen_ssh_key_pair: true
|
|
weechat__custom_version: 'main'
|
|
|
|
# postfix
|
|
postfix__myhostname: "{{ mailserver_domain }}"
|
|
postfix__tls_cert: "{{ mailserver__ssl_cert }}"
|
|
postfix__tls_key: "{{ mailserver__ssl_key }}"
|
|
|
|
# fail2ban
|
|
fail2ban_jail_configuration:
|
|
- option: 'enabled'
|
|
value: 'true'
|
|
section: 'postfix'
|
|
- option: 'mode'
|
|
value: 'extra'
|
|
section: 'postfix'
|
|
- option: 'enabled'
|
|
value: 'true'
|
|
section: 'dovecot'
|
|
|
|
nginx__infrastructure_domain__enabled: false
|