aim-web2.1.0rc9
This commit is contained in:
@@ -0,0 +1,75 @@
|
||||
# AIM WebGUI 2.1.0rc9 release-managed configuration
|
||||
# Replaced on every managed install/update/rollback.
|
||||
# AIM core configuration is never modified.
|
||||
|
||||
[server]
|
||||
host = "127.0.0.1"
|
||||
port = 8080
|
||||
public_url = "https://aim.desq-gaming.de"
|
||||
|
||||
[proxy]
|
||||
proxy_headers = true
|
||||
forwarded_allow_ips = ["127.0.0.1"]
|
||||
|
||||
[session]
|
||||
session_hours = 8
|
||||
idle_minutes = 30
|
||||
|
||||
[aim]
|
||||
scripts_path = "/etc/ansible/scripts"
|
||||
|
||||
# Public core protocol, not an Ansible executable or private source import.
|
||||
[core]
|
||||
transport = "unix"
|
||||
command = ["/usr/local/bin/aimctl"]
|
||||
config = "/etc/ansible/scripts/aim.yml"
|
||||
socket = "/run/aim-web-executor/core.sock"
|
||||
executor_user = "svc_bf-ansible"
|
||||
client_user = "aim-web"
|
||||
# Dedicated writable process HOME for native caches; SSH trust uses effective SSH configuration.
|
||||
home = "/var/lib/aim-web-executor"
|
||||
|
||||
[state]
|
||||
state_dir = "/var/lib/aim/webgui"
|
||||
|
||||
# Browser -> NPM 192.168.20.3 -> HTTPS 192.168.20.46:8443 -> local nginx -> 127.0.0.1:8080.
|
||||
# This release does not create, replace or renew the separately installed TLS certificates.
|
||||
[execution]
|
||||
enabled = true
|
||||
playbooks = [
|
||||
"checkmk_install_agent",
|
||||
"checkmk_update_scripts_config",
|
||||
"checkmk_read_windows_config",
|
||||
"checkmk_cleanup_scripts",
|
||||
"debug_test_connection",
|
||||
"debug_show_disk_usage",
|
||||
"debug_detect_host_roles",
|
||||
"maintenance_export_event_logs",
|
||||
"maintenance_start_stopped_services",
|
||||
"maintenance_patch_os",
|
||||
"maintenance_reboot_hosts",
|
||||
"sophos_apply_baseline",
|
||||
"sophos_apply_customer",
|
||||
"pfsense_apply_baseline",
|
||||
]
|
||||
max_hosts = 25
|
||||
timeout_seconds = 1800
|
||||
require_approval = false
|
||||
# WebGUI policy only; core addons.execution_enabled is a separate operator opt-in.
|
||||
# Operator attestation for this deployment profile: backend CA trust has been established.
|
||||
transport_verified = true
|
||||
window_start_hour = 0
|
||||
window_end_hour = 24
|
||||
|
||||
[credentials]
|
||||
enabled = true
|
||||
|
||||
# Retained public metadata, not raw Ansible stdout/stderr. Deleted with the job.
|
||||
[journal]
|
||||
max_events = 20000
|
||||
max_bytes = 8388608
|
||||
|
||||
[reports]
|
||||
max_bytes = 16777216
|
||||
# Expanded configuration content retention requires explicit operator opt-in.
|
||||
retain_configuration = false
|
||||
Reference in New Issue
Block a user