|
@@ -1,137 +0,0 @@
|
1
|
|
----
|
2
|
|
-###############################################################################
|
3
|
|
-# DO NOT EDIT. Set your variables in `vars/user.yml` instead.
|
4
|
|
-# This is a reference of all the variables.
|
5
|
|
-###############################################################################
|
6
|
|
-
|
7
|
|
-# # common
|
8
|
|
-common_timezone: 'Etc/UTC'
|
9
|
|
-# domain: (required)
|
10
|
|
-# main_user_name: (required)
|
11
|
|
-admin_email: "{{ main_user_name }}@{{ domain }}"
|
12
|
|
-main_user_shell: "/bin/bash"
|
13
|
|
-# encfs_password: (required)
|
14
|
|
-friendly_networks:
|
15
|
|
- - ""
|
16
|
|
-letsencrypt_server: "https://acme-v01.api.letsencrypt.org/directory"
|
17
|
|
-
|
18
|
|
-# ssh
|
19
|
|
-kex_algorithms: "diffie-hellman-group-exchange-sha256"
|
20
|
|
-ciphers: "aes256-ctr,aes192-ctr,aes128-ctr"
|
21
|
|
-macs: "hmac-sha2-512,hmac-sha2-256,hmac-ripemd160"
|
22
|
|
-
|
23
|
|
-# ntp
|
24
|
|
-ntp_servers:
|
25
|
|
- # use nearby ntp servers by default
|
26
|
|
- - 0.pool.ntp.org
|
27
|
|
- - 1.pool.ntp.org
|
28
|
|
- - 2.pool.ntp.org
|
29
|
|
- - 3.pool.ntp.org
|
30
|
|
- # use servers tailored to the server location
|
31
|
|
- # See http://www.pool.ntp.org/en/use.html
|
32
|
|
- # - 0.north-america.pool.ntp.org
|
33
|
|
- # - 1.north-america.pool.ntp.org
|
34
|
|
- # - 2.north-america.pool.ntp.org
|
35
|
|
- # - 3.north-america.pool.ntp.org
|
36
|
|
-
|
37
|
|
-# collectd
|
38
|
|
-collectd_version: 5.4.1
|
39
|
|
-collectd_librato_version: 0.0.10
|
40
|
|
-collectd_librato_email: "" # (optional)
|
41
|
|
-collectd_librato_api_token: "" # (optional)
|
42
|
|
-
|
43
|
|
-# database
|
44
|
|
-db_admin_username: 'postgres'
|
45
|
|
-# db_admin_password: (required)
|
46
|
|
-
|
47
|
|
-# ircbouncer
|
48
|
|
-# irc_nick: (required)
|
49
|
|
-# irc_ident: (required)
|
50
|
|
-# irc_realname: (required)
|
51
|
|
-# irc_quitmsg: (required)
|
52
|
|
-# irc_password_hash: (required)
|
53
|
|
-# irc_password_salt: (required)
|
54
|
|
-
|
55
|
|
-# mailserver
|
56
|
|
-mail_server_hostname: "mail.{{ domain }}"
|
57
|
|
-mail_server_autoconfig_hostname: "autoconfig.{{ domain }}"
|
58
|
|
-mail_db_username: mailuser
|
59
|
|
-# mail_db_password: (required)
|
60
|
|
-mail_db_database: mailserver
|
61
|
|
-# mail_virtual_domains: (required)
|
62
|
|
-# mail_virtual_users: (required)
|
63
|
|
-# mail_virtual_aliases: (required)
|
64
|
|
-mail_db_opendmarc_username: opendmarc
|
65
|
|
-# mail_db_opendmarc_password: (required)
|
66
|
|
-mail_db_opendmarc_database: opendmarc
|
67
|
|
-
|
68
|
|
-# z-push
|
69
|
|
-zpush_version: 2.1.1-1788
|
70
|
|
-
|
71
|
|
-# owncloud
|
72
|
|
-owncloud_domain: "cloud.{{ domain }}"
|
73
|
|
-owncloud_db_username: owncloud
|
74
|
|
-# owncloud_db_password: (required)
|
75
|
|
-owncloud_db_database: owncloud
|
76
|
|
-
|
77
|
|
-# tarsnap
|
78
|
|
-tarsnap_version: 1.0.36.1
|
79
|
|
-
|
80
|
|
-# vpn
|
81
|
|
-# Notes about security: https://blog.g3rt.nl/openvpn-security-tips.html
|
82
|
|
-# Check privacy: http://witch.valdikss.org.ru/
|
83
|
|
-# openvpn_key_country: (required)
|
84
|
|
-# openvpn_key_province: (required)
|
85
|
|
-# openvpn_key_city: (required)
|
86
|
|
-# openvpn_key_org: (required)
|
87
|
|
-# openvpn_key_ou: (required)
|
88
|
|
-openvpn_days_valid: "1825"
|
89
|
|
-openssl_request_subject: "/C={{ openvpn_key_country }}/ST={{ openvpn_key_province }}/L={{ openvpn_key_city }}/O={{ openvpn_key_org }}/OU={{ openvpn_key_ou }}"
|
90
|
|
-openvpn_key_size: "2048"
|
91
|
|
-openvpn_cipher: "AES-256-CBC"
|
92
|
|
-openvpn_auth_digest: "SHA512"
|
93
|
|
-openvpn_path: "/etc/openvpn"
|
94
|
|
-openvpn_ca: "{{ openvpn_path }}/ca"
|
95
|
|
-openvpn_dhparam: "{{ openvpn_path }}/dh{{ openvpn_key_size }}.pem"
|
96
|
|
-openvpn_hmac_firewall: "{{ openvpn_path }}/ta.key"
|
97
|
|
-openvpn_server: "{{ domain }}"
|
98
|
|
-openvpn_port: "1194"
|
99
|
|
-openvpn_protocol: "udp"
|
100
|
|
-openvpn_mtu: "1300"
|
101
|
|
-openvpn_verb: "3" # "0" for anonymity
|
102
|
|
-# uncomment for openvpn 2.3.3 and >2.3.4
|
103
|
|
-openvpn_tls_version_min: "" # "tls-version-min 1.2"
|
104
|
|
-openvpn_tls_cipher: "" # "tls-cipher TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256:TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384:TLS-DHE-RSA-WITH-AES-256-CBC-SHA256"
|
105
|
|
-# openvpn_clients: (required)
|
106
|
|
-
|
107
|
|
-# webmail
|
108
|
|
-webmail_domain: "{{ mail_server_hostname }}"
|
109
|
|
-webmail_db_username: "roundcube"
|
110
|
|
-# webmail_db_password: (required)
|
111
|
|
-webmail_db_database: "roundcube"
|
112
|
|
-carddav_version: "1.0.0"
|
113
|
|
-
|
114
|
|
-# xmpp
|
115
|
|
-prosody_admin: "{{ admin_email }}"
|
116
|
|
-prosody_virtual_domain: "{{ domain }}"
|
117
|
|
-# prosody_accounts: (required)
|
118
|
|
-
|
119
|
|
-# news
|
120
|
|
-selfoss_domain: "news.{{ domain }}"
|
121
|
|
-selfoss_db_username: selfoss
|
122
|
|
-# selfoss_db_password: (required)
|
123
|
|
-selfoss_db_database: selfoss
|
124
|
|
-selfoss_version: 2.14
|
125
|
|
-
|
126
|
|
-# git
|
127
|
|
-cgit_version: 0.12
|
128
|
|
-cgit_domain: "git.{{ domain }}"
|
129
|
|
-gitolite_version: 3.6.4
|
130
|
|
-
|
131
|
|
-# wallabag
|
132
|
|
-wallabag_version: 1.9.1
|
133
|
|
-wallabag_domain: "read.{{ domain }}"
|
134
|
|
-# wallabag_salt: (required)
|
135
|
|
-wallabag_db_username: wallabag
|
136
|
|
-# wallabag_db_password: (required)
|
137
|
|
-wallabag_db_database: wallabag
|