Files @ 814be5def61d
Branch filter:

Location: majic-ansible-roles/testsite/group_vars/backup.yml - annotation

branko
MAR-189: Added support for Debian 11 Bullseye to xmpp_server role:

- Roll-out LDAP client configuration since Bullseye does not come with
a stock one at /etc/ldap/ldap.conf that sets the trust anchor
correctly for validating LDAP server certificates.
- Drop the backports pinning in case of Bullseye (for now let's try to
keep the Buster and Bullseye at same versions for simplicity).
- Drop installation of Python apt bindings (no longer used).
- Tests for Buster and Bullseye need to be split-up a bit due to some
differences around backports etc.
---

local_mail_aliases:
  root: "root john.doe@{{ testsite_domain }}"

smtp_relay_host: mail.{{ testsite_domain }}

smtp_relay_truststore: "{{ lookup('file', inventory_dir + '/tls/ca.pem') }}"

backup_clients:
  - server: web.{{ testsite_domain }}
    public_key: "{{ lookup('file', inventory_dir + '/ssh/web.' + testsite_domain + '.pub') }}"
    ip: 10.32.64.18
  - server: mail.{{ testsite_domain }}
    public_key: "{{ lookup('file', inventory_dir + '/ssh/mail.' + testsite_domain + '.pub') }}"
    ip: 10.32.64.15
  - server: ldap.{{ testsite_domain }}
    public_key: "{{ lookup('file', inventory_dir + '/ssh/ldap.' + testsite_domain + '.pub') }}"
    ip: 10.32.64.12
  - server: xmpp.{{ testsite_domain }}
    public_key: "{{ lookup('file', inventory_dir + '/ssh/xmpp.' + testsite_domain + '.pub') }}"
    ip: 10.32.64.16
  - server: backup.{{ testsite_domain }}
    public_key: "{{ lookup('file', inventory_dir + '/ssh/backup.' + testsite_domain + '.pub') }}"
    ip: 127.0.0.1
  - server: ws01.{{ testsite_domain }}
    public_key: "{{ lookup('file', inventory_dir + '/ssh/ws01.' + testsite_domain + '.pub') }}"
    ip: 10.32.64.22

backup_host_ssh_private_keys:
  rsa: "{{ lookup('file', inventory_dir + '/ssh/backup_server_rsa_key') }}"
  ed25519: "{{ lookup('file', inventory_dir + '/ssh/backup_server_ed25519_key') }}"
  ecdsa: "{{ lookup('file', inventory_dir + '/ssh/backup_server_ecdsa_key') }}"