2023-03-29 13:35:19 +02:00

73 lines
4.7 KiB
YAML

ansible_python_interpreter: python3
silence_synchronize: true
distro_lookup_path:
- "{{ ansible_facts.distribution }}.{{ ansible_facts.lsb.codename|default() }}.{{ ansible_facts.architecture }}.yaml"
- "{{ ansible_facts.distribution }}.{{ ansible_facts.lsb.codename|default() }}.yaml"
- "{{ ansible_facts.distribution }}.{{ ansible_facts.architecture }}.yaml"
- "{{ ansible_facts.distribution }}.yaml"
- "{{ ansible_facts.os_family }}.yaml"
- default.yaml
iptables_base_allowed_hosts: []
iptables_extra_allowed_hosts: []
iptables_allowed_hosts: "{{ iptables_base_allowed_hosts + iptables_extra_allowed_hosts }}"
iptables_base_allowed_groups: []
iptables_extra_allowed_groups: []
iptables_allowed_groups: "{{ iptables_base_allowed_groups + iptables_extra_allowed_groups }}"
iptables_base_public_tcp_ports: []
iptables_extra_public_tcp_ports: []
firewalld_base_ports_enable: []
firewalld_extra_ports_enable: []
firewalld_base_services_enable: ['ssh']
firewalld_extra_services_enable: []
# iptables_test_public_tcp_ports is here only to allow the test
# framework to inject an iptables rule to allow zuul console
# streaming. Do not use it otherwise.
firewalld_ports_enable: "{{ firewalld_test_ports_enable|default([]) + firewalld_base_ports_enable + firewalld_extra_ports_enable }}"
firewalld_services_enable: "{{ firewalld_base_services_enable + firewalld_extra_services_enable }}"
iptables_base_public_udp_ports: []
iptables_extra_public_udp_ports: []
iptables_public_udp_ports: "{{ iptables_base_public_udp_ports + iptables_extra_public_udp_ports }}"
unbound_forward_zones: []
# When adding new users, always pick a UID larger than the last UID, do not
# fill in holes in the middle of the range.
all_users:
gtema:
comment: Artem Goncharov
key: |
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDBBVL8LJ14SfFPK2zNeuO8rglURUJ32LFQXn0IzinZ7Y3ic8vtmF+UBvg+h8th56GZ3/DR9b+zcXfbA+0cdfTr+BWlDCYwcLab2vgU/S9FyQBzYr7ZWxtEFOmb5ztVp2b5wFt/DD7YBfyJNzM9SpVQDO4furwNZDq5af0+D67KOsV2BPLXL4/zMGkLR3TSFNzdJCSLrWML96NWK1FvpEjDroyKXFTVVcLBTgtBnFtpjpUzmlJSntaUxTQq1htiWLTGQL3ApLqx7YYctxDDkeBrWGSQPZgFppqhk5U8sWE9ieGztGuVyYzAhvz8YO9nm8M26izVebjwe+9u1hqa3Pk9 artem.goncharov
sk-ssh-ed25519@openssh.com AAAAGnNrLXNzaC1lZDI1NTE5QG9wZW5zc2guY29tAAAAIFhfujbhx20AzKf2okw9WnduPe2keIWkFDhsSLNlvMd6AAAABHNzaDo= gtema@yubikey
uid: 2000
gid: 2000
zuul:
comment: Zuul CICD
key: |
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCqO/dXXqmBr1RP8+En5iuLDkPtk7S1jbqjD6QppHo3eKe0WDXeENydPQrXrYf1wJcRa9a8Mdxx2tSxVNqyNVLmlyzPzPc9K2TM6shtHoc3Jzd1HlmfB9MJU2amKuqePwAptCgsxxLBvK+mvh0kXmKnkfMSItCpjOyj6udwwFChJFU/2LB3X9FqLCQB7n3FYKwvbrFDtcIa1COo2h8TychwqWAPKj0Fh7M+mjaF41vcBcmz+uaNk5czC0c7b03TVjKTpYFEmZNtoc0taLP6Ya2exYdHo2uiPYmFiPdVFuv6AMpRnO9CRZzQv+1tlcEPVfsp8gHJVOI47NTx5c5PRTMl system-config
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDKiyOg0fZzcJtk2OGmEH279Hyur9714hbyZetMV01/iMrMtxpZn0AlBVUjJlOI83Da75bRHLdTG0W4xrax8b+DFsskuuEWo/xVwli9BOYuh5yKgW1Wx/vs4OsYIkFoQIColACGIEqO/ts7xdTUdGnp2nWjBauBocgL/2uc2ytT2PjlsJPZkvDd93nZsryEyFkTKjykS/OgnYfYUcOoI5Agn4cWZSaiGWzLbSp/ebe46g4cAzrOfgYgbPFw1rfooKjyjELdvfFot7Mxj28WsTv+FIGc+vU+KMejJmD00eNBSPbZJl0ogeD0YNEq3MSuhPqOYA6WJs5Sl8tZGNTMt2hB gl-ecosystem-system-config-20220110
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQDUM1QR8n5e20dmEjd4m556Ej6Spo4WTBI2OVzO4Rr63tylrHLEXkuzxTSPb87aBgmWulFND1+LBsivaFKdL12WF8elyy0T54cdW+O21isOLCVjRbSfjM0e8sme1lMoJXiupdAzWa3XD7cBCdRog79O/DYB/CLHq6gQuQt0a0+p0rea4dSAiXu5VYJ2IlH9hj3vmstuN8cDsGUNuqwyzFUWOgEQT0KMAjvPwoQ8Aft1LPDnEMhOk82JuQzLS8L3Vvpcwb00VqfC9eBGqBL/Rt6yWWERVxtHtdtGxzWz+5wMtUe6CK1lpa9TG2TbtBoSPoQjka8qh31M1TMRQbNvA4ap zuul-gitstyring-key-20210531
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCrm6Bl1RgJ76JwwN9TBoh0FzpcwHtYOuXA3Q5XVx7hZdo8vx+/djQ0wp/LNoE+OtW9yhsZstCcLXLk1Qt28Ce4KDY4eVrj0XhuMPQ8QLSPKqNYHoI0I8/fM/iDPln47KgV59o1kb5dQ4OcGgKcCWHN4fehYLPLi9BBJ+UK5Lrf7FNzCWz9UJBZ00xpjOKOKKFKLGNo+lVIUbj6Ay1OWfa1FxaQemG22rxJU6eI/nt2CWvq8FTt2Bpe0tnnJhvbgyf7o4kE6Rb1VORxzryvN31ruR8jMDI1arW5M2qKbgbNMz/zFhSaY+ophQKbOZVEyLRxDyKCOJpSVvYal03beJGZ zuul-gitstyring2-key-20211103
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC1tOTit52KNxZ74KYFy8P6lLvaPy48zvCIWatfN1TcS+buj3L5abA6Vrb9JPXyIBlRW7dBUy259yTX0RLd/f7uysoXMvTAaUBNG54K+fI6HfXxhrQOEaR0dgPHLMjVucZ+Vay3SPtntwci1A6Zq9GJOeC9iBzLlu5W6Q2Eyko7tA+aB4IVVXTKbAigIsgS0bwOoBDh7nA3xbeGsQnnzvcFTXEvLpoe/e+hIS+olsNTiT6CeTjyOTDZsbZqAG9YncZzWi+KXe31EJ2y13S9zWXnwhcZY0VdJHEZFjrEsYSjjOSeaV08sl/VWtRBP9H4hREw+JwcB2MrGaoAKOSzrkLT zuul-octavia-proxy-key-20211012
uid: 2031
gid: 2031
# List of users to install on all hosts
base_users:
- gtema
# Default empty list of users to install on specific hosts or groups
extra_users: []
# Users who should be removed
disabled_users: []
# Default distro cloud image names to remove
disabled_distro_cloud_users:
- ubuntu
- linux
- centos
- admin