Petr Michalec | 56e329c | 2017-07-03 14:32:04 +0200 | [diff] [blame] | 1 | classes: |
| 2 | # RHEL/Centos based |
| 3 | #- system.linux.system.repo.saltstack.rhel7 |
| 4 | #- system.haproxy.proxy.listen. |
| 5 | #- system.salt.minion.cert. |
Petr Michalec | 6463b43 | 2017-08-17 11:52:59 +0200 | [diff] [blame] | 6 | - system.mysql.client |
Petr Michalec | b8e83fc | 2017-12-15 15:27:28 +0100 | [diff] [blame] | 7 | #- system.freeipa.server.cluster |
Petr Michalec | f05e3ea | 2017-08-21 17:33:16 +0200 | [diff] [blame] | 8 | - cluster.aaa-ha-freeipa.aaa |
Petr Michalec | 56e329c | 2017-07-03 14:32:04 +0200 | [diff] [blame] | 9 | parameters: |
| 10 | _param: |
| 11 | linux_system_codename: centos |
| 12 | keepalived_vip_interface: ${_param:primary_interface} |
| 13 | keepalived_vip_virtual_router_id: 99 |
| 14 | |
Petr Michalec | 6463b43 | 2017-08-17 11:52:59 +0200 | [diff] [blame] | 15 | freeipa_admin_password: password |
| 16 | freeipa_ldap_password: password |
| 17 | mysql_admin_user: admin |
| 18 | mysql_admin_password: password |
| 19 | freeipa_principal_user: principal |
| 20 | freeipa_dns_zone: aaa-freeipa.local |
Petr Michalec | b8e83fc | 2017-12-15 15:27:28 +0100 | [diff] [blame] | 21 | freeipa_realm: ${_param:cluster_domain} |
Petr Michalec | 6463b43 | 2017-08-17 11:52:59 +0200 | [diff] [blame] | 22 | |
Petr Michalec | 56e329c | 2017-07-03 14:32:04 +0200 | [diff] [blame] | 23 | freeipa: |
| 24 | server: |
| 25 | realm: ${_param:cluster_domain} |
| 26 | domain: ${_param:cluster_domain} |
| 27 | servers: |
| 28 | - idm01.${_param:cluster_domain} |
| 29 | - idm02.${_param:cluster_domain} |
| 30 | - idm03.${_param:cluster_domain} |
| 31 | admin: |
Petr Michalec | 6463b43 | 2017-08-17 11:52:59 +0200 | [diff] [blame] | 32 | password: ${_param:freeipa_admin_password} |
Petr Michalec | 56e329c | 2017-07-03 14:32:04 +0200 | [diff] [blame] | 33 | ldap: |
Petr Michalec | 6463b43 | 2017-08-17 11:52:59 +0200 | [diff] [blame] | 34 | password: ${_param:freeipa_ldap_password} |
Petr Michalec | 56e329c | 2017-07-03 14:32:04 +0200 | [diff] [blame] | 35 | dns: |
| 36 | key: |
| 37 | axfrkey: |
| 38 | # bind9utils |
| 39 | # dnssec-keygen -a HMAC-MD5 -b 128 -n HOST rndc-key |
| 40 | secret: "xoDeAf49FmBTiJWRJ1zNng==" |
| 41 | algorithm: hmac-md5 |
| 42 | # algorithm: hmac-sha512 |
| 43 | zone: |
| 44 | # Main zones |
| 45 | aaa-freeipa.local: ${_param:freeipa_dns_zone} |
| 46 | |
| 47 | # Additional/Internal zones |
| 48 | # opencontrail.cz: ${_param:freeipa_dns_zone} |
| 49 | |
| 50 | # Reverse zones |
| 51 | # 105.0.10.in-addr.arpa: ${_param:freeipa_dns_zone_reverse} |
| 52 | |