76 lines
2.1 KiB
TOML
76 lines
2.1 KiB
TOML
# AIM WebGUI 2.1.0rc9 release-managed configuration
|
|
# Replaced on every managed install/update/rollback.
|
|
# AIM core configuration is never modified.
|
|
|
|
[server]
|
|
host = "127.0.0.1"
|
|
port = 8080
|
|
public_url = "https://aim.desq-gaming.de"
|
|
|
|
[proxy]
|
|
proxy_headers = true
|
|
forwarded_allow_ips = ["127.0.0.1"]
|
|
|
|
[session]
|
|
session_hours = 8
|
|
idle_minutes = 30
|
|
|
|
[aim]
|
|
scripts_path = "/etc/ansible/scripts"
|
|
|
|
# Public core protocol, not an Ansible executable or private source import.
|
|
[core]
|
|
transport = "unix"
|
|
command = ["/usr/local/bin/aimctl"]
|
|
config = "/etc/ansible/scripts/aim.yml"
|
|
socket = "/run/aim-web-executor/core.sock"
|
|
executor_user = "svc_bf-ansible"
|
|
client_user = "aim-web"
|
|
# Dedicated writable process HOME for native caches; SSH trust uses effective SSH configuration.
|
|
home = "/var/lib/aim-web-executor"
|
|
|
|
[state]
|
|
state_dir = "/var/lib/aim/webgui"
|
|
|
|
# Browser -> NPM 192.168.20.3 -> HTTPS 192.168.20.46:8443 -> local nginx -> 127.0.0.1:8080.
|
|
# This release does not create, replace or renew the separately installed TLS certificates.
|
|
[execution]
|
|
enabled = true
|
|
playbooks = [
|
|
"checkmk_install_agent",
|
|
"checkmk_update_scripts_config",
|
|
"checkmk_read_windows_config",
|
|
"checkmk_cleanup_scripts",
|
|
"debug_test_connection",
|
|
"debug_show_disk_usage",
|
|
"debug_detect_host_roles",
|
|
"maintenance_export_event_logs",
|
|
"maintenance_start_stopped_services",
|
|
"maintenance_patch_os",
|
|
"maintenance_reboot_hosts",
|
|
"sophos_apply_baseline",
|
|
"sophos_apply_customer",
|
|
"pfsense_apply_baseline",
|
|
]
|
|
max_hosts = 25
|
|
timeout_seconds = 1800
|
|
require_approval = false
|
|
# WebGUI policy only; core addons.execution_enabled is a separate operator opt-in.
|
|
# Operator attestation for this deployment profile: backend CA trust has been established.
|
|
transport_verified = true
|
|
window_start_hour = 0
|
|
window_end_hour = 24
|
|
|
|
[credentials]
|
|
enabled = true
|
|
|
|
# Retained public metadata, not raw Ansible stdout/stderr. Deleted with the job.
|
|
[journal]
|
|
max_events = 20000
|
|
max_bytes = 8388608
|
|
|
|
[reports]
|
|
max_bytes = 16777216
|
|
# Expanded configuration content retention requires explicit operator opt-in.
|
|
retain_configuration = false
|