Commit Graph

56 Commits

Author SHA1 Message Date
niten 4b037178b9 Update paris for 24.05 2024-07-19 15:08:37 -07:00
niten 2105c0128e Don't add aliases 2024-06-19 18:10:04 -07:00
niten c50f459d7a serverAliases should be a list 2024-06-19 15:54:49 -07:00
niten 795e32f3d0 Accept acme terms 2024-06-19 15:52:47 -07:00
niten 82e051a753 enableAcme -> enableACME 2024-06-19 15:25:53 -07:00
niten 5224c8bbe0 Dupilcate tmpfiles rule 2024-06-19 14:56:15 -07:00
niten a73547ea79 Add nginx with user dirs 2024-06-19 14:54:04 -07:00
niten 46031af2a8 Ensure home directory exists 2024-06-19 14:37:50 -07:00
niten 98075785a3 Not sure how to specify modules... 2024-06-19 13:25:13 -07:00
niten 3a103270cc Import modules 2024-06-15 18:46:27 -07:00
niten 277ca76b31 Enable tailscale 2024-06-06 13:59:29 -07:00
niten 8be2c4eef5 Oops, specify SSL 2024-06-06 11:40:16 -07:00
niten d84a41ad58 permiitRootLogin -> permitRootLogin 2024-06-06 10:54:34 -07:00
niten 2c904663d1 Switch to SSL port, accepting any cert. 2024-06-06 10:34:50 -07:00
niten 58b406465c Okay, set an access filter 2024-06-05 23:11:35 -07:00
niten faf888ddaf I guess we need nscd 2024-06-05 18:18:06 -07:00
niten cdc933c50a What the hell...it's listening on 3389?! 2024-06-05 18:10:55 -07:00
niten f856f2bcc4 And don't create a secret, either 2024-06-05 14:08:29 -07:00
niten 0272bcadd3 Don't configure kerberos unless it's necessary 2024-06-05 14:07:24 -07:00
niten 2d01513547 `after` is a list 2024-06-05 13:53:21 -07:00
niten 3d4e281d8c Add kerberos configuration 2024-06-05 13:47:11 -07:00
niten bb84ade958 Remove filters, rather than specifying an ldap filter 2024-06-05 13:28:45 -07:00
niten 54d8c7d49d Lists are comma-separated 2024-06-05 12:29:04 -07:00
niten 590bc0abf2 Fix some errors in the config 2024-06-05 12:07:53 -07:00
niten 625def9947 Correct ssd env file 2024-06-05 11:26:37 -07:00
niten e917a10cc0 Yep, need to specify full URL. 2024-06-05 10:09:53 -07:00
niten 80ef83fdc7 Point at the right IP... 2024-06-05 10:07:18 -07:00
niten 5ad1bbee60 That's a crazy default... 2024-06-05 10:02:36 -07:00
niten 207585f7d0 Don't set hostAddress & localAddress anymore 2024-06-05 09:40:53 -07:00
niten fc6deaf71e macvlan on internal.interface, not interface 2024-06-05 09:39:16 -07:00
niten 6c0198e8ce listen-ips should be a list of strings 2024-06-05 09:37:00 -07:00
niten 44cc8635e5 Take an internal interface, and allow ldap on ips 2024-06-05 09:20:59 -07:00
niten ef3a826f94 Remove references to auth0, which no longer exists 2024-06-04 10:37:29 -07:00
niten 3d78628d2f Oh, does host/localAddress work? 2024-06-04 10:01:15 -07:00
niten 2a983b0c19 Use macvlan instead of bridge 2024-06-03 13:44:25 -07:00
niten 172b04ef07 Not sure which I want here... 2024-06-03 13:34:55 -07:00
niten 93e3a404a5 Fuckin weird bruh 2024-06-03 13:19:00 -07:00
niten 75fc648e01 Make a bridge from paris -> ldap 2024-06-03 12:59:55 -07:00
niten f4ba577185 Bind sssd env into paris 2024-06-03 11:30:07 -07:00
niten ab90edde10 opensssh -> openssh 2024-06-02 21:53:53 -07:00
niten f79530b949 keytab -> keypair typo 2024-06-02 18:18:07 -07:00
niten 2a338d45fb s/hostKeypairs/parisKeypairs/ 2024-06-02 17:02:37 -07:00
niten 8f1bc956d1 Pass in SSH keys 2024-06-02 16:56:56 -07:00
niten e9e7d25ba8 Don't launch if it's not enabled 2024-06-01 09:18:28 -07:00
niten d387167dec Oops, define target file 2024-05-28 11:45:05 -07:00
niten 79540cf3c6 Lists aren't allowed in INI, apparently 2024-05-28 11:41:46 -07:00
niten a063049045 Don't use tmpfs 2024-05-28 11:13:55 -07:00
niten 6a36a4521f oci-containers has a containers attribute 2024-05-28 11:11:59 -07:00
niten da49d47bca Add LDAP port (and firewall ports) 2024-05-28 11:09:29 -07:00
niten f25509454c Define hostSecrets 2024-05-28 11:05:33 -07:00