Compare commits

...
725 Commits
Author SHA1 Message Date
jmrothst 58de00baa2 Add some missing depends in the make file
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-07-25 19:21:22 -05:00
jmrothst 5cc1ad43f2 Blank role requirements so makefile works
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-06-26 20:38:32 -05:00
jmrothst fc34b2d249 Removed known host manipulation
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-06-26 20:38:07 -05:00
jmrothst aaf2424540 Remove duplicate gitignore, and relicense all as CC BY-NC-ND 4.0
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-24 11:10:10 -05:00
jmrothst 2bf9948c5a Use package repo from gitea.fdragon.com with $releasever
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-17 22:21:53 -05:00
jmrothst 604afa87f6 Replace with version from Fedora 44 instead of carry forward old version
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-17 22:21:01 -05:00
jmrothst 9803968104 Attempt to support WebSocket redirects
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-12 16:10:17 -05:00
jmrothst 5e9faf389f Remove role requirements now that all roles have been merged
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:50:08 -05:00
jmrothst 06fe023836 Merge ensure_mariadb
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:49:31 -05:00
jmrothst 02b18d6f8c Add 'roles/ensure_mariadb/' from commit '5a4e112c0b22c32ceda74023dfe10ab5a1dc7116'
git-subtree-dir: roles/ensure_mariadb
git-subtree-mainline: 49513ee522
git-subtree-split: 5a4e112c0b
2026-05-10 21:49:13 -05:00
jmrothst 49513ee522 Merge ensure_gitea
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:48:42 -05:00
jmrothst 4d410d147d Add 'roles/ensure_gitea/' from commit 'ce657f8ad4ad5f1ab15314e1007f647c50ea6a46'
git-subtree-dir: roles/ensure_gitea
git-subtree-mainline: ba0de90bed
git-subtree-split: ce657f8ad4
2026-05-10 21:48:13 -05:00
jmrothst ba0de90bed Add 'roles/ensure_rsync/' from commit '1d91e5f0fcb5211a2cc6dc129ca375dc4198fcfd'
git-subtree-dir: roles/ensure_rsync
git-subtree-mainline: 8a784c8b59
git-subtree-split: 1d91e5f0fc
2026-05-10 21:47:30 -05:00
jmrothst 8a784c8b59 Merge ensure_dovecot
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:46:45 -05:00
jmrothst 0b3d325490 Add 'roles/ensure_dovecot/' from commit '08733e1772a1fd9dfb9e6838f864e93cec524835'
git-subtree-dir: roles/ensure_dovecot
git-subtree-mainline: 8c4b30b750
git-subtree-split: 08733e1772
2026-05-10 21:46:18 -05:00
jmrothst 8c4b30b750 Merge ensure_postfix
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:45:44 -05:00
jmrothst 2b45ea745b Add 'roles/ensure_postfix/' from commit 'cee46b68246e8207cbe24c9efe07fc1fe548a89b'
git-subtree-dir: roles/ensure_postfix
git-subtree-mainline: b53ecda58c
git-subtree-split: cee46b6824
2026-05-10 21:45:26 -05:00
jmrothst b53ecda58c Merge ensure_apache
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:44:48 -05:00
jmrothst 64ae500730 Add 'roles/ensure_apache/' from commit '5f5133a14d007558861282c4925c468052706bc8'
git-subtree-dir: roles/ensure_apache
git-subtree-mainline: 0869eeaaf4
git-subtree-split: 5f5133a14d
2026-05-10 21:44:33 -05:00
jmrothst 0869eeaaf4 Merge ensure_sudo
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:44:09 -05:00
jmrothst da154c7f58 Add 'roles/ensure_sudo/' from commit 'de4fc58c9753aa4d5bb339d6cd0757cbd4e25e20'
git-subtree-dir: roles/ensure_sudo
git-subtree-mainline: 328ebb72c0
git-subtree-split: de4fc58c97
2026-05-10 21:43:48 -05:00
jmrothst 328ebb72c0 Merge ensure_rsync
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:43:20 -05:00
jmrothst 681692051b Merge ensure_repo_epel
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:41:52 -05:00
jmrothst b1cb692752 Add 'roles/ensure_repo_epel/' from commit 'c002fc4649ee199a91c74e0112804c0c1e6bcc0e'
git-subtree-dir: roles/ensure_repo_epel
git-subtree-mainline: f5428c4176
git-subtree-split: c002fc4649
2026-05-10 21:41:37 -05:00
jmrothst f5428c4176 Merge ensure_repo_rpmfusion
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:41:08 -05:00
jmrothst d21f0a2b02 Add 'roles/ensure_repo_rpmfusion/' from commit '08c814c28758bf08dee46d056a8a687b0afeb42d'
git-subtree-dir: roles/ensure_repo_rpmfusion
git-subtree-mainline: b956799cc7
git-subtree-split: 08c814c287
2026-05-10 21:40:53 -05:00
jmrothst b956799cc7 Merge ensure_timezone
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:40:15 -05:00
jmrothst 51c0509bd6 Add 'roles/ensure_timezone/' from commit 'f60fb072a0b6c2bd2e933fc649d282eef458dec7'
git-subtree-dir: roles/ensure_timezone
git-subtree-mainline: 848f01cece
git-subtree-split: f60fb072a0
2026-05-10 21:39:59 -05:00
jmrothst 848f01cece Merge ensure_vim
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:39:37 -05:00
jmrothst 68217c0582 Add 'roles/ensure_vim/' from commit '88ee7d94bdab9a59ffc06f71e38691d81cd8381a'
git-subtree-dir: roles/ensure_vim
git-subtree-mainline: b01bd6ad5c
git-subtree-split: 88ee7d94bd
2026-05-10 21:39:19 -05:00
jmrothst b01bd6ad5c Merge ensure_selinux
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:38:51 -05:00
jmrothst 8437f7242a Add 'roles/ensure_selinux/' from commit '3df6ef38ce8e94aad5718d5641a2bcc3a14a806f'
git-subtree-dir: roles/ensure_selinux
git-subtree-mainline: 5b5250046b
git-subtree-split: 3df6ef38ce
2026-05-10 21:38:33 -05:00
jmrothst 5b5250046b Merge ensure_podman
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:37:34 -05:00
jmrothst 18c28344ba Add 'roles/ensure_podman/' from commit 'b1d5b6cc7554cabe223c6cda4433a54cea06ec48'
git-subtree-dir: roles/ensure_podman
git-subtree-mainline: 84858ae442
git-subtree-split: b1d5b6cc75
2026-05-10 21:37:09 -05:00
jmrothst 84858ae442 Merge ensure_os_patch
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:36:47 -05:00
jmrothst 041cde7fe3 Add 'roles/ensure_os_patch/' from commit '0092e5d0892f4820426635128d0e4a150f2ee1a0'
git-subtree-dir: roles/ensure_os_patch
git-subtree-mainline: bae0615e37
git-subtree-split: 0092e5d089
2026-05-10 21:36:33 -05:00
jmrothst bae0615e37 Merge ensure_log_rotation
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:36:02 -05:00
jmrothst 46d51180c7 Add 'roles/ensure_log_rotation/' from commit '38364cec4fda418e640ed85852f00746e684a0aa'
git-subtree-dir: roles/ensure_log_rotation
git-subtree-mainline: b4b2b24c85
git-subtree-split: 38364cec4f
2026-05-10 21:35:40 -05:00
jmrothst b4b2b24c85 Merge ensure_git
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:35:14 -05:00
jmrothst 7e8ec16873 Add 'roles/ensure_git/' from commit '4efaa9713c914be36e0cb40f94a16f0cc24e56b4'
git-subtree-dir: roles/ensure_git
git-subtree-mainline: d59786f05e
git-subtree-split: 4efaa9713c
2026-05-10 21:34:53 -05:00
jmrothst d59786f05e Merge ensure_cockpit
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:34:20 -05:00
jmrothst 15216eb9ca Add 'roles/ensure_cockpit/' from commit '9587886d949ddfa817a4d131539923aacbcfe441'
git-subtree-dir: roles/ensure_cockpit
git-subtree-mainline: 72d5dca63a
git-subtree-split: 9587886d94
2026-05-10 21:34:03 -05:00
jmrothst 72d5dca63a Merge ensure_ansible_prereq
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:33:33 -05:00
jmrothst 986cd07ecd Add 'roles/ensure_ansible_prereq/' from commit '86d8ce5ca1642e62be06847784476865514416ea'
git-subtree-dir: roles/ensure_ansible_prereq
git-subtree-mainline: 5fb6077dbc
git-subtree-split: 86d8ce5ca1
2026-05-10 21:33:11 -05:00
jmrothst 5fb6077dbc Merge ensure_os_upgrade
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:29:52 -05:00
jmrothst 75b8a6bd72 Add 'roles/ensure_os_upgrade/' from commit 'e56a0039033222ab73c80f54987733eeab813c33'
git-subtree-dir: roles/ensure_os_upgrade
git-subtree-mainline: 6db10d3c26
git-subtree-split: e56a003903
2026-05-10 21:28:57 -05:00
jmrothst 6db10d3c26 Merge ensure_hostname
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:27:29 -05:00
jmrothst 3c106b9bf8 Add 'roles/ensure_hostname/' from commit 'ff4effc62c3643cdefb0b819e76185cdaa4a2164'
git-subtree-dir: roles/ensure_hostname
git-subtree-mainline: 75a6f350d2
git-subtree-split: ff4effc62c
2026-05-10 21:27:06 -05:00
jmrothst 75a6f350d2 Merge ensure_repo_fdragon
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:24:11 -05:00
jmrothst e5c830f86a Add 'roles/ensure_repo_fdragon/' from commit '5aeefca7241c6b62bebd2f8f92ddab6d608b28ab'
git-subtree-dir: roles/ensure_repo_fdragon
git-subtree-mainline: 8a8d6bef90
git-subtree-split: 5aeefca724
2026-05-10 21:23:19 -05:00
jmrothst 8a8d6bef90 Merged ensure_docker
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:22:03 -05:00
jmrothst f68d962df6 Add 'roles/ensure_docker/' from commit '61f5aa283b5dc6fdb97867333ba51e7e70d99c98'
git-subtree-dir: roles/ensure_docker
git-subtree-mainline: c7d00d588f
git-subtree-split: 61f5aa283b
2026-05-10 21:21:11 -05:00
jmrothst c7d00d588f Merge ensure_clamav
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-10 21:19:33 -05:00
jmrothst f155699877 Add 'roles/ensure_clamav/' from commit 'f3959f6d098abdf6c1794a3d3d0923c86fcca0b6'
git-subtree-dir: roles/ensure_clamav
git-subtree-mainline: ad56516ef9
git-subtree-split: f3959f6d09
2026-05-10 21:18:37 -05:00
jmrothst 5a4e112c0b Pass the user list to user creation instead of the db list
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 19:47:58 -04:00
jmrothst ce657f8ad4 Start gitea by default and remove mariadb configurations
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 19:20:08 -04:00
jmrothst fccb6e850c Disable gpg checks until I can find out why gitea isn't signing them
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 19:06:49 -04:00
jmrothst 575934b9b4 Fix loop label
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 19:04:34 -04:00
jmrothst c7e8426f35 Add state
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 17:54:40 -04:00
jmrothst 942be664eb Fix the ansible fact for architecture
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 17:52:57 -04:00
jmrothst ba1562f5a9 Allow UNIX Socket connections to function
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 17:27:46 -04:00
jmrothst ad56516ef9 Add rsync and gitea roles
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 16:23:19 -04:00
jmrothst 4d263d0116 Remove templates we don't need
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 16:19:01 -04:00
jmrothst 4e8ee4301f Initial Version
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 16:18:30 -04:00
jmrothst 23a2c69ac2 Use the preferred python mysql client
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 15:09:21 -04:00
jmrothst a225aabd4e Add python mysql drivers to manage with
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 14:06:36 -04:00
jmrothst 454a5004d9 default(omit)
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 13:51:00 -04:00
jmrothst 08d2eb2138 Add db and user management
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 11:34:22 -04:00
jmrothst 7e92974962 use the correct .pem file extension for certificates
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-09 00:45:03 -04:00
jmrothst e4ca65d661 Fix mariadb and phpMyAdmin templates not change what shouldn't be
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-08 23:57:51 -04:00
jmrothst 2ffa82d4f4 More ansible-core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-08 23:57:33 -04:00
jmrothst 08733e1772 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-08 20:02:04 -04:00
jmrothst cee46b6824 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-08 20:01:10 -04:00
jmrothst 5f5133a14d Fix directory typo
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-08 19:59:38 -04:00
jmrothst 8b675a773e Move ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-08 19:59:17 -04:00
jmrothst de4fc58c97 Fixes for EL10
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-06 00:03:26 -05:00
jmrothst 1d91e5f0fc Fix fedora package list
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 23:24:26 -05:00
jmrothst 6bc518b694 Initial Version
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 22:57:10 -05:00
jmrothst efb8c739c6 First pass fix the sudo files for EL
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 22:53:32 -05:00
jmrothst c002fc4649 Syntax fix
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 22:47:24 -05:00
jmrothst 08c814c287 More ansible-core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 22:46:56 -05:00
jmrothst 5add9282f0 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 22:45:09 -05:00
jmrothst f60fb072a0 Remove Ubuntu's cron.service that doesn't exist
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 19:38:04 -05:00
jmrothst 300f8fbd1a Fix fedora 44 sudo.conf
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:40:50 -05:00
jmrothst 5158ed362a Fix fedora 43 sudo.conf
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:40:22 -05:00
jmrothst 6c229c85d4 Fix Fedora 42 sudo.conf
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:39:01 -05:00
jmrothst 0ef012d42f Add default variable file to handle the unknown
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:29:24 -05:00
jmrothst 8d5fe0733d Add templates for EL 8/9/10
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:27:53 -05:00
jmrothst 88ee7d94bd More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:18:50 -05:00
jmrothst d111b82dd1 More ansible 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:18:19 -05:00
jmrothst 3df6ef38ce More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:17:39 -05:00
jmrothst dd12b18aee More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:17:12 -05:00
jmrothst a4a1be2bcf More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:16:40 -05:00
jmrothst e2971304c5 Fix ansible core 2.20 and supported OS list
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:16:12 -05:00
jmrothst b1d5b6cc75 Fix ansible core 2.20 and supported OS list
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:15:09 -05:00
jmrothst 0092e5d089 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:13:53 -05:00
jmrothst 035d9ed288 Fix ansible core 2.20 and supported OS list
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:13:17 -05:00
jmrothst 38364cec4f More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:12:18 -05:00
jmrothst 4efaa9713c More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:11:25 -05:00
jmrothst cfd7e36bb5 Fix ansible core 2.20 and sync the supported OS versions
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:10:49 -05:00
jmrothst 46d841b6c6 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 18:09:18 -05:00
jmrothst 9587886d94 Fix handlers vs ansible core 2.20
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 17:27:48 -05:00
jmrothst 86d8ce5ca1 Fix handlers vs ansible core 2.20
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 17:26:57 -05:00
jmrothst c52da7c031 Rewrite to act like rest of roles, add common OS list
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 17:25:32 -05:00
jmrothst 819b4cc4f9 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 17:10:29 -05:00
jmrothst edfc45ac32 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 17:09:41 -05:00
jmrothst 03993abe57 More ansible-core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 17:07:51 -05:00
jmrothst 50b94195fb More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 15:07:58 -05:00
jmrothst c90290fbe7 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 15:03:36 -05:00
jmrothst abb2885a98 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 15:03:03 -05:00
jmrothst dc43680f0e More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 15:02:32 -05:00
jmrothst 0f63b7e149 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 15:01:52 -05:00
jmrothst 197e712b3b More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 15:01:05 -05:00
jmrothst 9648466450 Ansible core 2.20 fixes and supported OS change
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 14:32:46 -05:00
jmrothst 1efd9640a8 Remove deplicate code
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 14:28:22 -05:00
jmrothst 061fcdfe0b Fix ansible core 2.20
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 14:19:45 -05:00
jmrothst 14aaa3c723 Fix ansible core 2.20 and supported OS list
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 14:12:48 -05:00
jmrothst f9ad1bab85 Fix ansible core 2.20 and supported OS list
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 14:10:43 -05:00
jmrothst 8ca1a1fb75 Ansible Core 2.20 fixes and Supported OS fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 14:06:42 -05:00
jmrothst 861ef05b58 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 10:48:46 -05:00
jmrothst 59a3e26407 Ansible core 2.20 fixes and only supported OS releases
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-05 10:44:39 -05:00
jmrothst df13a42912 Fix ansible core 2.20 and update supported OS list
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 22:23:31 -05:00
jmrothst 5311bcc0ff More ansible 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 22:17:49 -05:00
jmrothst 8ab0fc6d60 Fix ansible core 2.20 deprecations and make the OS list the supported
one

Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 22:15:10 -05:00
jmrothst 9c973b997b More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 22:09:59 -05:00
jmrothst e56a003903 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 22:06:46 -05:00
jmrothst 2fc0ad4d34 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 22:05:47 -05:00
jmrothst 6e95a50a44 More ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 22:03:10 -05:00
jmrothst 6c21335fc5 More ansible 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 22:02:19 -05:00
jmrothst d1db8bad37 Add Ubuntu support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 21:50:34 -05:00
jmrothst 4ca97a9401 Ansible core 2.20 fixes plus only supported os versions
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 21:46:55 -05:00
jmrothst eac7d9a037 Ansible core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 21:28:43 -05:00
jmrothst b37943dbc9 Fix ansible core 2.20 changes and remove OS that are out of support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 21:21:20 -05:00
jmrothst ff4effc62c Ansible Core 2.20 fixes
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-04 21:15:56 -05:00
jmrothst e9e8e40f3e More ansible-core 2.20 fixes 2026-05-04 21:14:34 -05:00
jmrothst 4a30473d40 Fedora 44 baseline update 2026-05-04 21:09:35 -05:00
jmrothst 2f9348dde3 Bring all templates to Fedora 42 baseline 2026-05-04 20:59:48 -05:00
jmrothst c359f71a22 More ansible-core 2.20 updates 2026-05-04 19:31:47 -05:00
jmrothst 2e09ba159f Ansible-core 2.20 fixes 2026-05-04 19:20:17 -05:00
jmrothst d872806031 Drop unsupported OS versions 2026-05-04 19:17:58 -05:00
jmrothst a02bf02521 Remove issues file as we don't fix anything except removing the debian cdrom repos 2026-05-04 19:16:01 -05:00
jmrothst 7dfca58e89 Update for Ansible Core 2.20 and remove items for unsupported OS versions 2026-05-04 19:14:57 -05:00
jmrothst e2f86bbb44 Fix package_list name
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-03 01:04:27 -05:00
jmrothst fa10a9340e Fix package_list variable name
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-03 01:03:04 -05:00
jmrothst 4324ca7474 Fix Alma and Oracle 9 and 10 spelling
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-02 23:49:41 -05:00
jmrothst 46b48fb084 Stop asking for python-apt as it isn't there on any supported release
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-02 22:50:48 -05:00
jmrothst 209526bc2d Safer removal of debian CDROM from apt sources.list
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-05-02 22:49:52 -05:00
jmrothst 14da351e6f Fedora 43, 44
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-04-30 19:46:18 -05:00
jmrothst ca025bc614 Fedora 43, 44
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-04-30 19:45:01 -05:00
jmrothst d316bc5a2e Add Fedora 43, 44, Alma 9, 10, CentOS 10, Oracle 9, 10, Rocky 9, 10
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-04-30 19:43:39 -05:00
jmrothst b3904985fa Fix OL9, add Alma, CentOS, Oracle, and Rocky 10
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-04-30 19:40:22 -05:00
jmrothst 436aad959a Fedora 43, 44, Alma 8, 9, 10, CentOS 10, Oracle 8, 9, 10, Rocky 8, 9, 10
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-04-30 15:34:14 -05:00
jmrothst 5af1e0106e Fix logrotate.conf for EL10
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-04-30 00:09:39 -05:00
jmrothst 0ae0f71644 Fedora 44 2026-04-29 23:51:56 -05:00
jmrothst 6957f1f13c Fedora 43 and 44 2026-04-29 23:50:10 -05:00
jmrothst afe0b3b3d6 Fedora 43, 44, Alma 10, CentOS 10, Oracle 10 and Rocky 10 2026-04-29 23:47:06 -05:00
jmrothst f782f11284 Fedora 43 and 44 2026-04-29 23:41:46 -05:00
jmrothst 96d428294b Fedora 44 2026-04-29 23:39:19 -05:00
jmrothst 3893991c0a Fedora 43 and 44 2026-04-29 23:28:27 -05:00
jmrothst 140a90783b Fedora 44 2026-04-29 23:23:55 -05:00
jmrothst 4859039edb Fix yamllint issues and turn on SSH Connection Pooling 2026-04-29 23:16:14 -05:00
jmrothst dc345d2594 Fixed EL9, Added EL10 and Fedora43 2026-03-09 00:57:40 -05:00
jmrothst 972807b75b Fix Fedora 43 vars 2026-03-09 00:38:16 -05:00
jmrothst 94f6f6244a Add Fedora 43 and EL 10, and if using dnf/dnf5/yum package manager we patch by default, allowing duplicate data removal 2026-03-09 00:33:51 -05:00
jmrothst 1d08be944e Removed ansible.utils as it doesn't appear to exist any more
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2026-03-09 00:11:42 -05:00
jmrothst 139bf58528 Add Fedora 43, and EL 10 support 2026-03-08 23:32:26 -05:00
jmrothst f6f8e4baba Trust traffic originating from localhost (outbound)
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-09-01 14:01:33 -05:00
jmrothst 122983206e Update the collections requirements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-06-07 18:43:31 -05:00
jmrothst 5815c32a2e Clean up ~/.ssh/known_hosts
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-06-07 18:41:58 -05:00
jmrothst bbd73c818e Handler Improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:14:37 -05:00
jmrothst f35e3052a2 Handler Improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:14:21 -05:00
jmrothst e9b5070620 Handler Improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:14:03 -05:00
jmrothst 338b51fb7a Handler improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:13:45 -05:00
jmrothst 2c4486c599 Hanlder improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:13:31 -05:00
jmrothst 5aeefca724 Hanlder improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:13:13 -05:00
jmrothst 0030c4dbcf Hanlder improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:12:59 -05:00
jmrothst ec394365b0 Handler improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:12:42 -05:00
jmrothst 632b070017 Hanlder improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:12:26 -05:00
jmrothst ba18694e6e Hanlder improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:12:07 -05:00
jmrothst 57a05dd3cb Handler improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:11:36 -05:00
jmrothst 515f9b7fce Handler improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:08:44 -05:00
jmrothst b2fb62be40 Handler improvement
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:08:20 -05:00
jmrothst eeb2051b75 yaml format
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:07:45 -05:00
jmrothst 0dc1846feb Handler improvement
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:07:09 -05:00
jmrothst aec51abc17 Handler improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:06:35 -05:00
jmrothst 61f5aa283b Handler improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:06:14 -05:00
jmrothst 9ec2b2160e Handler improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:05:26 -05:00
jmrothst f3959f6d09 Handler improvements 2025-05-25 20:05:09 -05:00
jmrothst 2a66da8e00 Handler improvements
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:03:49 -05:00
jmrothst 674b6c9b4c Hanlder improvements and sync to common values
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-05-25 20:03:13 -05:00
jmrothst 4ecac052e7 Fedora 42 moved postfix binaries to /usr/bin
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 13:09:07 -05:00
jmrothst 8285638d49 Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:50:01 -05:00
jmrothst 8aaa553e56 Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:49:05 -05:00
jmrothst 2910df6a20 Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:48:16 -05:00
jmrothst cb9b788fb8 Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:47:30 -05:00
jmrothst c33b463e80 Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:46:36 -05:00
jmrothst 5b71793729 Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:45:05 -05:00
jmrothst e29c759925 Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:42:09 -05:00
jmrothst 0f17999e87 Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:39:58 -05:00
jmrothst 276b0ee5d4 Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:38:38 -05:00
jmrothst 54c2bf0ebb Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:35:26 -05:00
jmrothst 89374746ae Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:34:04 -05:00
jmrothst b512d27c13 Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:24:49 -05:00
jmrothst 106ef5f5ab Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:22:36 -05:00
jmrothst c018f39ef8 Fedora 42
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:21:02 -05:00
jmrothst 25b472e806 Add Fedora 42 and update ISSUES.md
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2025-04-27 12:19:17 -05:00
jmrothst a9f65eda6f Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-28 19:40:17 -06:00
jmrothst e031226505 Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-28 19:25:23 -06:00
jmrothst d8f7cc34c3 Only template configs if config variable is set
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-28 18:57:08 -06:00
jmrothst 04b4322270 Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 21:58:17 -06:00
jmrothst e6bd36fc6f Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 20:49:45 -06:00
jmrothst 6aee899a95 Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 20:48:23 -06:00
jmrothst f2b31c2e9b Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 20:47:43 -06:00
jmrothst dfc50a380e Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 20:39:33 -06:00
jmrothst f89189ffba Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 20:36:58 -06:00
jmrothst f217a798df Fedora 41 specific dnf5 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 20:36:23 -06:00
jmrothst 67a3eee78a Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 20:30:05 -06:00
jmrothst 0be2010a58 Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 19:51:12 -06:00
jmrothst c265b87035 Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 19:42:15 -06:00
jmrothst cc9e96de8d Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 16:17:36 -06:00
jmrothst f3bf9ddd2d Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 16:16:18 -06:00
jmrothst 5a2daf0d7e Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 16:14:36 -06:00
jmrothst fc480a0586 Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 15:57:19 -06:00
jmrothst 61060dca2b Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 15:56:01 -06:00
jmrothst 8e919868e9 Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 15:54:53 -06:00
jmrothst 9a66d0da86 Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 15:53:54 -06:00
jmrothst fabfe6d8a3 Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 15:52:41 -06:00
jmrothst bfb53cbef9 Fedora 41
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-12-27 15:40:09 -06:00
jmrothst cbbc4a1870 Upgrade to Fedora 40
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-07-10 21:51:31 -05:00
jmrothst e4e49bb1ca Add Alma/CentOS/Oracle/Rocky 9
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-30 23:04:25 -05:00
jmrothst cf28d56914 Enable EPEL for Alma/Oracle/Rocky 9
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-30 19:18:34 -05:00
jmrothst 2dda9f7759 Add Alma/Oracle/Rocky 8 and 9
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-30 13:45:17 -05:00
jmrothst 23e2d00ca5 Add Fedora 40, Alma/Oracle/Rocky 8 and 9
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-30 13:42:58 -05:00
jmrothst 0143ddbe68 Add Alma/Oracle/Rocky 8 and 9
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-30 13:41:28 -05:00
jmrothst de06728914 Add Alma/Oracle/Rocky 8 and 9
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-30 13:39:42 -05:00
jmrothst 2a7221c741 Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:28:27 -05:00
jmrothst cdb1b29f5d Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:27:32 -05:00
jmrothst 4b135b0c43 Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:26:49 -05:00
jmrothst 4d0a704c23 Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:26:12 -05:00
jmrothst 3eca9aca37 Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:25:14 -05:00
jmrothst 45e7216a21 Fix Fedora 39 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:25:02 -05:00
jmrothst 4b584f39e5 Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:23:21 -05:00
jmrothst c03dd1e993 Fix typo in Fedora 39 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:21:53 -05:00
jmrothst bf29f2d384 Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:19:36 -05:00
jmrothst 4531208c08 Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:18:11 -05:00
jmrothst 943d8fdeaa Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:16:06 -05:00
jmrothst 68b56dc722 Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:14:56 -05:00
jmrothst b620b55fac Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:12:58 -05:00
jmrothst 171def47a6 Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:10:56 -05:00
jmrothst 8964c203d7 Fedora 40 support
Signed-off-by: Jason Rothstein <fdragon@fdragon.org>
2024-06-02 12:09:07 -05:00
jmrothst d83b6471a6 Add Fedora 39 2024-03-16 21:04:53 -05:00
jmrothst 8052567d60 Add Fedora 39 2024-03-16 21:04:11 -05:00
jmrothst a6e36f0f4d Add Fedora 39 2024-03-16 21:03:31 -05:00
jmrothst 22ec1562d2 Add Fedora 38 to 39 2024-03-16 21:02:48 -05:00
jmrothst baefe60a45 Add Fedora 39 2024-03-16 21:01:52 -05:00
jmrothst c880ccdf8c Add Fedora 39 2024-03-16 21:01:06 -05:00
jmrothst 97b9cf7613 Add Fedora 39 2024-03-16 20:58:55 -05:00
jmrothst e26663bd31 Add Fedora 39 2024-03-16 20:26:09 -05:00
jmrothst aaa04fce58 Add Fedora 39 2024-03-16 20:25:22 -05:00
jmrothst e8ace75b42 Add Fedora 39 2024-03-16 20:24:36 -05:00
jmrothst 7b4cadbe17 Add Fedora 39 2024-03-16 20:23:11 -05:00
jmrothst d7f75dd9b0 Add Fedora 39 2024-03-16 20:21:45 -05:00
jmrothst b4bf5998f6 Add Fedora 39 2024-03-16 20:19:44 -05:00
jmrothst be5078063e Add Fedora 39 2024-03-16 20:18:57 -05:00
jmrothst 2757cc4dcf Add Fedora 39 2024-03-16 20:17:54 -05:00
jmrothst 1c61932ba0 Convert back to INET sockets for milters 2023-05-14 22:26:19 -05:00
jmrothst 317d59b75c Fix for milters on Fedora 38 2023-05-14 21:29:45 -05:00
jmrothst 7ea0a06718 Update to Postfix 3.7 and local sockets for milters 2023-05-14 20:56:06 -05:00
jmrothst ab09787165 Update OpenDMARC Configuration 2023-05-14 20:45:40 -05:00
jmrothst a5b9c295d7 Update OpenDKIM configuration 2023-05-14 20:43:09 -05:00
jmrothst 2f090a96f3 Add Fedora 38 2023-04-30 17:53:01 -05:00
jmrothst 5be3cc49b3 Add Fedora 38 2023-04-30 17:51:17 -05:00
jmrothst 12fc8105cf Add Fedora 38 and CentOS 9 2023-04-30 17:50:05 -05:00
jmrothst 00fa96521e Add Fedora 38 2023-04-30 17:47:39 -05:00
jmrothst d06c33fa00 Add Fedora 38 and CentOS 9 2023-04-30 17:45:12 -05:00
jmrothst 21058229ef Add Fedora 38 and CentOS 9 2023-04-30 17:41:23 -05:00
jmrothst f66f2dd464 Add Fedora 38 and CentOS 9 2023-04-30 17:38:40 -05:00
jmrothst a918395d1a Add Fedora 38 2023-04-29 20:36:51 -05:00
jmrothst c35e9f8998 Add Fedora 38 2023-04-29 20:35:13 -05:00
jmrothst 31ad38da59 Fedora 37 to 38 upgrade 2023-04-29 20:17:00 -05:00
jmrothst 4f290c7bf5 Fedora 36 to 37 upgrade 2023-04-29 20:16:25 -05:00
jmrothst cd0c5bd513 Add Fedora 38 2023-04-29 20:15:16 -05:00
jmrothst a675616a2b Use Fedora 38 sudo.conf 2023-04-23 17:02:34 -05:00
jmrothst 7ece3d489e Add Fedora 38 2023-04-23 16:46:02 -05:00
jmrothst 1e2cf18eed Add Fedora 38 2023-04-23 16:44:47 -05:00
jmrothst 2b2c75bbe1 Add Fedora 38 2023-04-23 16:42:55 -05:00
jmrothst 936af40aed Add CentOS 9 2023-04-23 16:41:40 -05:00
jmrothst 1080ab5e42 Add CentOS 9 and Fedora 38 2023-04-23 16:40:20 -05:00
jmrothst 265fd0310d Stop sending delivery status notifications due to creating backskatter spam 2023-02-20 12:47:06 -06:00
jmrothst 2616b724ec Fedora 37 hates the oxford comma? 2023-02-12 22:27:18 -06:00
jmrothst 879c8560c3 Add submissions service to Fedora37 now too 2023-02-12 22:19:55 -06:00
jmrothst a54a230582 Uptake changes with htcacheclean service 2023-02-12 22:18:14 -06:00
jmrothst 2281e970a8 New default service for submissions? 2023-02-12 22:15:28 -06:00
jmrothst 32bbda7fea Fedora 36 likes Oxford Comma now? 2023-02-12 21:25:25 -06:00
jmrothst f3cfa3a798 Add Fedora 37 2022-12-06 22:00:55 -06:00
jmrothst ef36b81762 Add Fedora 35/36/37 2022-12-06 21:59:17 -06:00
jmrothst d7e5708486 Add Fedora 37 2022-12-06 21:57:12 -06:00
jmrothst 894b0d4eaf Add Fedora 37 2022-12-06 21:56:26 -06:00
jmrothst eb44ddd6a1 Add Fedora 37 2022-12-06 21:55:08 -06:00
jmrothst 71213708e9 Add Fedora 37 2022-12-06 21:51:53 -06:00
jmrothst cdb373c772 Add Fedora 37 2022-12-06 21:45:25 -06:00
jmrothst 58a721a51c Add Fedora 37 2022-12-06 21:40:03 -06:00
jmrothst 06d4b49d8e Add Fedora 37 2022-12-06 21:35:12 -06:00
jmrothst 90f9eed049 Add Fedora 37 2022-12-06 21:34:28 -06:00
jmrothst 346c60d26b Add Fedora 37 2022-12-06 20:46:18 -06:00
jmrothst 650eda56da Add Fedora 37 2022-12-06 20:43:47 -06:00
jmrothst 5ddfa04551 Add Fedora 37 2022-12-06 20:43:04 -06:00
jmrothst 378b5cfbfb Add Fedora 34/35 upgrade to 35/36 2022-12-06 20:38:08 -06:00
jmrothst 563802d7f4 Add Fedora 37 2022-12-06 20:36:06 -06:00
jmrothst cc12c22d91 Add Fedora 37 2022-12-06 20:33:51 -06:00
jmrothst eea23ac367 If we use dnf-automatic, install the packages too 2022-10-03 23:13:10 -05:00
jmrothst c6fe3b53b2 Add sudo_intercept.so comments from latest sudo package 2022-10-03 00:03:08 -05:00
jmrothst 6c7b885f0a Restrict clients to those with valid DNS and HELO 2022-09-15 21:08:08 -05:00
jmrothst e39d194684 Make size of email permitted configurable 2022-09-15 20:41:20 -05:00
jmrothst 5703270588 Ensure variable name consistency 2022-06-05 22:19:13 -05:00
jmrothst eee0a155bd Variable names 2022-06-05 22:11:58 -05:00
jmrothst 8ff91ac08a Variable names 2022-06-05 22:04:22 -05:00
jmrothst e31af87c3a Use role local permission list, not global variable 2022-06-05 21:23:06 -05:00
jmrothst 7e5a008161 Set the hostname when localhost is found 2022-06-05 21:06:29 -05:00
jmrothst 5a216542f0 New role shell 2022-06-05 20:55:14 -05:00
AnsibleRoles 463a97d027 Initial commit 2022-06-06 01:52:53 +00:00
jmrothst 8b69508cf6 Enable Fedora 36 2022-06-05 18:30:32 -05:00
jmrothst db20dd86f9 Enable Fedora 36 2022-06-05 18:29:32 -05:00
jmrothst 99fa61907f Enable Fedora 36 2022-06-05 18:27:57 -05:00
jmrothst 6511f9a8fd Enable Fedora 36 2022-06-05 18:26:56 -05:00
jmrothst 49e0d92541 Enable Fedora 36 2022-06-05 18:25:22 -05:00
jmrothst a97fd11554 Enable Fedora 36 2022-06-05 18:23:37 -05:00
jmrothst c5eed3200f Enable Fedora 36 2022-06-05 17:53:09 -05:00
jmrothst 8fa4d26dfa Update tasks 2022-06-05 16:48:56 -05:00
jmrothst f2d38a6b3c Update tasks 2022-06-05 16:48:50 -05:00
jmrothst 15b37d9082 Update tasks 2022-06-05 16:48:45 -05:00
jmrothst 33b77ba1c0 Update tasks 2022-06-05 16:48:40 -05:00
jmrothst 9268a5f06a Update tasks 2022-06-05 16:48:35 -05:00
jmrothst 04e0c60bf1 Update tasks 2022-06-05 16:48:23 -05:00
jmrothst 0b5d854109 Update tasks 2022-06-05 16:48:16 -05:00
jmrothst 3e2777ae6a Update tasks 2022-06-05 16:48:11 -05:00
jmrothst bb21596a63 UPdate tasks 2022-06-05 16:48:06 -05:00
jmrothst 08be9269f7 Update tasks 2022-06-05 16:48:01 -05:00
jmrothst 3e6db2254f Update tasks 2022-06-05 16:47:55 -05:00
jmrothst 187a156ea8 Update tasks 2022-06-05 16:47:48 -05:00
jmrothst c410470a7a Update tasks 2022-06-05 16:47:43 -05:00
jmrothst b48ecea6a0 Update tasks 2022-06-05 16:47:39 -05:00
jmrothst 8d0529d65b Update tasks 2022-06-05 16:47:34 -05:00
jmrothst b23f198df8 Update tasks 2022-06-05 16:47:30 -05:00
jmrothst 9c769d54f9 Update tasks 2022-06-05 16:47:25 -05:00
jmrothst 6869e73220 Update tasks 2022-06-05 16:47:16 -05:00
jmrothst 8795a5cbc5 Update handlers 2022-06-05 16:30:26 -05:00
jmrothst bac97012c0 Update handlers 2022-06-05 16:30:22 -05:00
jmrothst b504262c8c Update handlers 2022-06-05 16:30:17 -05:00
jmrothst 6044ac3c43 Update handlers 2022-06-05 16:30:12 -05:00
jmrothst 0bff064626 Update handlers 2022-06-05 16:30:07 -05:00
jmrothst c8aae64b19 Update handlers 2022-06-05 16:30:01 -05:00
jmrothst 5c439dcf5c Update handlers 2022-06-05 16:29:55 -05:00
jmrothst fd71e3a9e6 Update handlers 2022-06-05 16:29:50 -05:00
jmrothst 67c740b417 Update handlers 2022-06-05 16:29:45 -05:00
jmrothst 1176408bc6 Update handlers 2022-06-05 16:29:40 -05:00
jmrothst d2ffeca9c0 Update handlers 2022-06-05 16:29:33 -05:00
jmrothst 532b4173ab Update handlers 2022-06-05 16:29:28 -05:00
jmrothst 2f15945fb2 Update handlers 2022-06-05 16:29:23 -05:00
jmrothst 328d61d73c Update handlers 2022-06-05 16:29:17 -05:00
jmrothst 857f5338af Update handlers 2022-06-05 16:29:09 -05:00
jmrothst f24acd039b Correct the git package name... 2022-06-05 16:08:33 -05:00
jmrothst 8f26f1a4d9 Remove nano and set vim as the default editor 2022-06-05 16:05:29 -05:00
jmrothst 725964dcb7 Initial Version 2022-06-05 15:59:38 -05:00
AnsibleRoles 71a6be2841 Initial commit 2022-06-05 20:55:44 +00:00
AnsibleRoles d23d38eda3 Initial commit 2022-06-05 20:54:57 +00:00
jmrothst 6372ce0a67 Add Fedora 36 2022-06-05 12:27:29 -05:00
jmrothst 0c4ca9103f Add Fedora 36 2022-06-05 12:25:49 -05:00
jmrothst 0ca1e888fc Add Fedora 36 2022-06-05 12:21:47 -05:00
jmrothst 7482ed1dd4 Add Fedora 36 2022-06-05 12:20:19 -05:00
jmrothst 4223a36844 Add Fedora 36 2022-06-05 12:18:58 -05:00
jmrothst 66800e623d Make permissions set OS Vendor/Version specific (aka /etc/httpd/mod_md) 2022-06-04 21:11:07 -05:00
jmrothst 462b3d47bc Another URI to block 2022-05-08 17:40:43 -05:00
jmrothst ee4873fe45 Redirect postmaster mail to the postmaster 2022-04-12 22:57:01 -05:00
jmrothst bb6d266585 Disable tcp/465 (SMTP SSL) and tcp/587 (SMTP Submission) listeners 2022-04-12 22:56:20 -05:00
jmrothst 355a44a3c3 Enable Dovecot to accept mail for delivery through postfix 2022-04-12 22:55:30 -05:00
jmrothst 6f4cc5f430 Fully working IMAP with TLS and passwd like auth 2022-04-10 23:21:48 -05:00
jmrothst ee1bcfe0fb Enable TLS with Postfix 2022-04-10 22:36:09 -05:00
jmrothst 7151bc4540 Remove sql include for passwd in MySQL 2022-04-10 22:30:00 -05:00
jmrothst 7834094fa3 Fix order of defined test to match syntax 2022-04-10 18:18:32 -05:00
jmrothst aab894353f Template syntax error 2022-04-10 18:07:19 -05:00
jmrothst b4a1479bb7 php-json is provided by php-common 2022-04-10 18:00:54 -05:00
jmrothst 1b2a2d33ef Rename postfix_domains to make it easier to use 2022-04-10 17:56:34 -05:00
jmrothst 18964c7f00 Add missing endif in template for accounts 2022-04-10 17:52:19 -05:00
jmrothst bb569255f7 Fix mail acceptance domain list variable names 2022-04-10 17:49:36 -05:00
jmrothst 50a5d87305 Single account file with email address as the username 2022-04-10 17:40:27 -05:00
jmrothst 5eb4c39645 Add plugins for future usage of MySQL auth 2022-04-10 17:09:49 -05:00
jmrothst d0bf3db3fb Fix home directories for file based virtual users 2022-04-10 01:11:45 -05:00
jmrothst ccbc78f344 Document the variable for virtual domains 2022-04-10 01:10:00 -05:00
jmrothst 0a15d67927 Ensure virtual domains go through LMTP 2022-04-10 01:08:19 -05:00
jmrothst 067f28d32a Remove MySQL and use dynamic file based accounts instead. 2022-04-07 22:41:04 -05:00
jmrothst fd5ccb52dd If anything changes, notify all handlers 2022-01-30 21:41:18 -06:00
jmrothst 472dfaae23 If anything changes, notify all handlers 2022-01-30 21:39:31 -06:00
jmrothst 655238922f If anything changes, notify all handlers 2022-01-30 21:38:09 -06:00
jmrothst 1b027f038e If things change, always notify all the handlers 2022-01-30 21:36:26 -06:00
jmrothst 52ff28b938 Adding services to validate are running 2022-01-30 18:58:42 -06:00
jmrothst 2a1e196d17 Make the certificates directory instead of find it 2022-01-23 18:53:11 -06:00
jmrothst 436b7f5065 Make the certificates directory instead of finding it 2022-01-23 18:50:18 -06:00
jmrothst fdc713f9d1 Make the certificates directory instead of find it 2022-01-23 18:49:55 -06:00
jmrothst af4ceeed53 Enable selecting the TLS Certificate 2022-01-23 18:09:53 -06:00
jmrothst 12c5304c00 Enable selecting the TLS Certificate 2022-01-23 18:09:27 -06:00
jmrothst dd2d53e22b Allow choice in TLS Certificate from mod_md 2022-01-23 17:07:18 -06:00
jmrothst 821c03ce0d Add SpamAssassin packages 2022-01-06 21:04:46 -06:00
jmrothst 0c7947dad0 Work around Jinja2 bug? where %} and {{ need a space between 2022-01-02 23:48:17 -06:00
jmrothst 1ce810c8c8 Enable OpenDKIM and OpenDMARC as MILTER 2022-01-02 19:55:17 -06:00
jmrothst eb2a735d8f Use mod_md certificates 2021-12-05 20:32:36 -06:00
jmrothst 8fee9c2f38 typo in minimum TLS version requirements 2021-12-05 18:55:55 -06:00
jmrothst 9a2d28f824 Enable mod_md fetched ACME TLS Certificates 2021-12-05 14:47:01 -06:00
jmrothst 5ef2aa3947 Typo in local.conf 2021-12-05 12:20:08 -06:00
jmrothst 33b76dd919 Enable MySQL user accounts 2021-12-05 11:54:39 -06:00
jmrothst c58804c9b3 Postfix listening 2021-11-16 19:29:51 -06:00
jmrothst 40d2d61351 OpenDKIM verify only mode config 2021-11-14 16:10:05 -06:00
jmrothst 2923577976 OpenDMARC config 2021-11-14 15:47:49 -06:00
jmrothst 25e340f729 Add dkim and dmarc service 2021-11-14 15:42:18 -06:00
jmrothst 126c2f386e Base configuration 2021-11-14 15:08:15 -06:00
jmrothst 373a9aa141 Base configuration 2021-11-14 15:05:38 -06:00
jmrothst b34c9864c7 Add dovecot service 2021-11-14 14:05:02 -06:00
jmrothst 746d918acb Add OpenDMARC, OpenDKIM, and postfix service 2021-11-14 14:01:54 -06:00
jmrothst 7481d4934c Package deploy 2021-11-14 11:46:42 -06:00
jmrothst 97660aad2f Package deploy 2021-11-14 11:46:26 -06:00
jmrothst 8e02895574 default vars 2021-11-14 11:36:01 -06:00
jmrothst 9417177d07 Default vars 2021-11-14 11:35:50 -06:00
jmrothst 0dfa4415c9 role shell 2021-11-14 11:33:13 -06:00
jmrothst 125a84b3c7 Role shell 2021-11-14 11:33:05 -06:00
jmrothst 362460919e Blank role 2021-11-14 10:19:29 -06:00
jmrothst 4dbf2395ae Blank role 2021-11-14 10:19:15 -06:00
jmrothst a4af49b0f7 Initial commit 2021-11-14 16:03:46 +00:00
AnsibleRoles d8e4d96975 Initial commit 2021-11-14 16:02:42 +00:00
jmrothst 562263efce Add Fedora 35 2021-11-13 21:25:06 -06:00
jmrothst 9e73ae40c2 Add Fedora 35 2021-11-13 21:22:43 -06:00
jmrothst 09dceb1a8f Add Fedora 35 Support 2021-11-13 20:45:36 -06:00
jmrothst cdba9dfef4 Fedora 35 support 2021-11-13 20:30:16 -06:00
jmrothst f6c2bfd964 Blank line removal 2021-11-13 20:28:45 -06:00
jmrothst f30c8c6a5b Enable Fedora 35 2021-11-07 23:04:21 -06:00
jmrothst 0ff46c167a Enable Fedora 35 2021-11-07 23:02:25 -06:00
jmrothst 352a8b4424 Enable Fedora 35 2021-11-07 23:00:39 -06:00
jmrothst ca6e67006c Enable Fedora 35 2021-11-07 22:59:06 -06:00
jmrothst 069d8b2779 Enable Fedora 35 and use variables instead of hard code version numbers 2021-11-07 22:57:10 -06:00
jmrothst 281d958bd4 Enable Fedora 35, remove clamav config in favor of clamav role 2021-11-07 22:54:22 -06:00
jmrothst 810a6c47a2 Add missing when clause to reboot requests 2021-11-07 10:29:49 -06:00
jmrothst 4ca5ddfe68 Rename defaults so that unknown target OS have no change 2021-11-05 21:54:53 -05:00
jmrothst 9834017ac7 Fix the TLS copy error and MariaDB not liking the CA Bundle 2021-10-31 18:37:59 -05:00
jmrothst 058b31a3f6 Fix path names for templates to match target system 2021-10-31 18:03:51 -05:00
jmrothst 1daaf66ff4 Template path corrected for systemd unit files 2021-10-31 17:59:41 -05:00
jmrothst 8202a0e2f4 Enable Apache mod_md Lets Encrypt Certificates with MariaDB 2021-10-31 17:55:14 -05:00
jmrothst 893a69ed0b Fix unit types and dependency 2021-10-31 17:51:02 -05:00
jmrothst a6d958e002 Fix jinja2 syntax to expand a variable 2021-10-31 01:45:55 -05:00
jmrothst a0bc660199 recurse instead of recursive on find... 2021-10-31 01:40:53 -05:00
jmrothst bccbac47d2 Find certificates and include them by direct name 2021-10-31 01:29:43 -05:00
jmrothst 66dd3a95b0 Fix template pathname for phpMyAdmin... 2021-10-31 01:06:48 -05:00
jmrothst a2e47eb111 Enable /phpMyAdmin if SSL, Use UTF8 char set, Try to auto use TLS in mariadb 2021-10-31 01:02:06 -05:00
jmrothst 3b0c73ca0d Removed apache specific items from mariadb task template... 2021-10-31 00:15:20 -05:00
jmrothst 36091b9e7b Install phpMyAdmin and MariaDB service 2021-10-31 00:08:05 -05:00
jmrothst cee6cbc638 Initial Role 2021-10-30 23:58:33 -05:00
AnsibleRoles e8358723a6 Initial commit 2021-10-31 04:57:37 +00:00
jmrothst 77d82b5410 Reload apache 5 minutes after timer start, instead of every minute 2021-10-30 23:37:24 -05:00
jmrothst 619614b4ea Full list of RPMs actually used 2021-10-30 11:44:20 -05:00
jmrothst 79622c572a Add base php configuration files 2021-10-30 11:42:10 -05:00
jmrothst 9e856a324d Enable SELinux for MySQL Connections... 2021-10-30 09:24:32 -05:00
jmrothst 3d10e3497b Enable php MySQL support 2021-10-30 09:22:59 -05:00
jmrothst a972900152 List the features 2021-10-27 00:02:56 -05:00
jmrothst 1d24646a0f Start PHP FPM... 2021-10-26 23:50:42 -05:00
jmrothst bfc0258fbd Adding php 2021-10-26 23:46:29 -05:00
jmrothst 9a58585d8b Make git checkout happy with SSH URLs 2021-10-26 23:12:53 -05:00
jmrothst 3236204446 Ensure git is present to git checkouts work... 2021-10-26 23:09:00 -05:00
jmrothst 0bb423012c Actually push the files for httpd-reload service and timer... 2021-10-26 23:04:02 -05:00
jmrothst fc9aaa66ec Add git repo deployments 2021-10-26 23:00:46 -05:00
jmrothst 0bd5f30d10 Reload apache config automatically for Lets Encrypt 2021-10-26 22:14:09 -05:00
jmrothst 1ea9466064 Redirect everything excepting .well-known requests... 2021-10-26 21:34:32 -05:00
jmrothst fbcdfc7a48 Fix redirect to be redirectmatch so it passes the syntax checks... 2021-10-26 21:30:47 -05:00
jmrothst 1086a9103e Max username length = 32, thus ownership of docroot breaks 2021-10-26 21:24:15 -05:00
jmrothst 8ca27246a1 Add URL Redirection for websites 2021-10-26 21:21:39 -05:00
jmrothst 3bf06efa08 mod_md doesn't actually write to disk unless MDStoreDir is defined 2021-10-26 01:33:13 -05:00
jmrothst d9577593f8 Fix disk storage location permissions for mod_md 2021-10-26 01:10:57 -05:00
jmrothst 6d8c42bfb0 Update readme for usage 2021-10-26 00:20:30 -05:00
jmrothst da62d4234b First working mod_md with Lets Encrypt Staging 2021-10-26 00:12:43 -05:00
jmrothst 41c23e2917 Take2 on selinux 2021-10-25 23:17:37 -05:00
jmrothst ebf2e5f173 Set SELinux Context per mod_md issue #253 2021-10-25 23:14:58 -05:00
jmrothst e5a5c3fb6b Fix mod_md renew window to have a value 2021-10-25 23:00:24 -05:00
jmrothst f8d7354b86 Attempt apache mod_md with Lets Encrypt Staging 2021-10-25 22:56:29 -05:00
jmrothst 8aa1c7fbeb Only block what is actually going to be in a docroot 2021-10-25 22:44:05 -05:00
jmrothst ca61be29ff Add default TLS Certificates for "localhost" 2021-10-25 22:39:42 -05:00
jmrothst 6605338f82 Create vhosts, users, and document roots 2021-10-25 21:41:35 -05:00
jmrothst 7eadb6ae5d Default apache configuration enforcement 2021-10-24 23:43:15 -05:00
jmrothst 6a6dd752d3 Remove php so it can be dedicated ansible role 2021-10-24 23:33:59 -05:00
jmrothst 544fb4bab2 Enable php 2021-10-24 23:31:13 -05:00
jmrothst 17da7d1937 Add mod_ssl and mod_md 2021-10-24 23:13:25 -05:00
jmrothst 153cc9ba5c Test for firewalld before configuring with it 2021-10-24 23:07:10 -05:00
jmrothst 6baadbe0fa Remove firewalld configs for now... 2021-10-24 23:00:02 -05:00
jmrothst 123399a31b Typos 2021-10-24 22:56:44 -05:00
jmrothst e9645e026d Default framework with packages, firewall, selinux, and services 2021-10-24 22:54:14 -05:00
jmrothst 4894f90d1c Initial Role 2021-10-24 22:35:34 -05:00
AnsibleRoles fce9a5b4c2 Initial commit 2021-10-25 03:34:04 +00:00
jmrothst 96100c9325 Search via regex instead of shell glob 2021-07-26 04:13:16 +00:00
jmrothst 3d66c3356f Delete failed freshclam updates >= 1 day old... 2021-07-26 04:00:06 +00:00
jmrothst 70ba1bb497 Correct typo 2021-07-25 04:15:17 +00:00
jmrothst 700944c9d8 Missing code 2021-07-25 04:14:50 +00:00
jmrothst 449ca519c0 Missing code... 2021-07-25 04:13:50 +00:00
jmrothst 0f5c6e1e6e Really only remove one set of flush handlers... 2021-07-25 04:11:20 +00:00
jmrothst 7e9a8b55bf Prevent multiple service restarts 2021-07-25 04:08:57 +00:00
jmrothst e4f35cd5fd Templatize SELinux configuration 2021-07-25 04:08:01 +00:00
jmrothst e51df84af3 Enable possibility of services 2021-07-25 03:58:08 +00:00
jmrothst 808e9a0adb Update task list to match base template 2021-07-25 03:54:17 +00:00
jmrothst 3ee35f3991 Fix formatting 2021-07-25 03:52:58 +00:00
jmrothst 492b3ceaf9 Prevent multiple service restarts 2021-07-25 03:52:24 +00:00
jmrothst adffa6a934 Prevent multiple service restarts 2021-07-25 03:51:13 +00:00
jmrothst e3a8f8c01f Prevent multiple service restarts 2021-07-25 03:50:25 +00:00
jmrothst 8e5b513494 Prevent multiple service restarts 2021-07-25 03:49:51 +00:00
jmrothst 45d6cd0fdd Prevent multiple service restarts 2021-07-25 03:49:00 +00:00
jmrothst 7a39c8a6ad Remove handler flush triggering multiple service restarts 2021-07-25 03:48:19 +00:00
jmrothst 82983cf57e Flush handlers triggered multiple service restarts 2021-07-25 03:47:10 +00:00
jmrothst 4a54147893 Add some flushing of handlers 2021-07-25 03:26:39 +00:00
jmrothst 2d696a22e7 Genericize the roal to look like the rest 2021-07-25 03:23:32 +00:00
jmrothst 8009f1265a Attempt to prevent disk full on freshclam failure 2021-07-22 03:18:25 +00:00
jmrothst 603d5e4422 Flush handlers after the package install 2021-07-21 03:04:50 +00:00
jmrothst 44f834157c Flush notifications after templating configs 2021-07-21 02:42:35 +00:00
jmrothst a9b38df978 Update task template for config files when required 2021-07-21 02:40:28 +00:00
jmrothst 91e41d1bc6 Update task template to deploy config files if needed 2021-07-21 02:39:29 +00:00
jmrothst ed9d4f4fba Update task template for config files if needed 2021-07-21 02:37:29 +00:00
jmrothst 2bb361c37b Don't scan root activity 2021-07-21 01:40:00 +00:00
jmrothst 5deef5463b pulling the value of a single element didn't work... 2021-07-20 00:47:57 +00:00
jmrothst a278340dad Sort the mounts so they are idempotent 2021-07-20 00:37:04 +00:00
jmrothst 51e73b97ec Add remaining configuration files 2021-07-18 03:47:40 +00:00
jmrothst 6cdcc99c9c All systemd units now restart on failure 2021-07-18 03:41:24 +00:00
jmrothst 1919debccb Ensure that clamonacc restarts when it fails 2021-07-15 00:51:34 +00:00
jmrothst be7b29ca58 Ensure the quarantine directory exists 2021-07-13 05:03:40 +00:00
jmrothst 64b2784052 Remove tcp connectivity 2021-07-13 04:51:17 +00:00
jmrothst 7130712048 If templates changed, reload systemd always 2021-07-13 04:41:51 +00:00
jmrothst 0d81758b2c Quotes 2021-07-13 04:09:53 +00:00
jmrothst c0efdca246 Enable quarantine and priv sep 2021-07-13 04:08:12 +00:00
jmrothst 520e265fea Add the missing loop 2021-07-12 04:05:17 +00:00
jmrothst fb68687c40 Increase inotify capacity to prevent Clam OnAccess Scanner from failing 2021-07-12 04:00:57 +00:00
jmrothst 8b20159801 Add TCP Connectivity 2021-07-06 23:06:47 -05:00
jmrothst fe652fce8b Run clamd as root so clamonacc works 2021-07-06 22:56:10 -05:00
jmrothst 2cc7cbd065 Template syntax error 2021-07-06 20:49:21 -05:00
jmrothst 3cffa5f9ba Template the mount points to scan 2021-07-06 20:39:44 -05:00
jmrothst 758fddfe87 Spelling 2021-07-06 03:28:47 +00:00
jmrothst da7d6cdb66 Fix service order and add SELinux support 2021-07-06 03:26:42 +00:00
jmrothst fdc2dd5c44 OnAccess scan the / mount, not just /home 2021-07-06 03:15:56 +00:00
jmrothst 62aac3c9d2 state not enable parameter should be tested 2021-07-06 03:04:23 +00:00
jmrothst f1de46c73c If changed configs, restart service 2021-07-06 03:02:30 +00:00
jmrothst dd49d58a63 Enable OnAccess scanner for /home 2021-07-06 02:43:52 +00:00
jmrothst 349b702296 Deploy configuration before services 2021-07-06 02:36:56 +00:00
jmrothst 70f337c37d Deploy configuration before starting service 2021-07-06 02:35:57 +00:00
jmrothst 645065a029 Enable clamd with OnAccess scanning 2021-07-06 02:30:41 +00:00
jmrothst 254ee004b2 Initial version with only updating for Fedora 34 2021-07-06 01:38:24 +00:00
AnsibleRoles b5089f5201 Initial commit 2021-07-06 01:10:25 +00:00
jmrothst 1e7d659787 template should not have had packages check 2021-07-05 04:53:08 +00:00
jmrothst 93556a4d84 Skip packages that already installed 2021-07-05 04:49:28 +00:00
jmrothst e3270a8755 Skip packages that already installed 2021-07-05 04:47:05 +00:00
jmrothst a12292ecea Skip packages that already installed 2021-07-05 04:46:03 +00:00
jmrothst c47b4fa519 Remove cockpit-dashboard as it was rolled into cockpit 2021-06-29 22:30:53 -05:00
jmrothst d1cf439611 Enable Fedora 34 2021-06-29 22:25:36 -05:00
jmrothst c0f41d246d Enable Fedora 34 2021-06-29 22:24:50 -05:00
jmrothst 8a78182de4 Enable Fedora 34 2021-06-29 22:23:28 -05:00
jmrothst 87c3b98a83 Enable Fedora 34 2021-06-29 22:20:53 -05:00
jmrothst 37cd99d22e Enable Fedora 34 2021-06-29 21:04:11 -05:00
jmrothst 784c65b12b Enable Fedora 34 2021-06-29 21:01:16 -05:00
jmrothst 96422490b4 Enable Fedora 34 2021-06-29 20:28:35 -05:00
jmrothst 5fa4c57f3c Make patching async because it can take some time. 2021-06-28 20:13:49 -05:00
jmrothst 173cff470f Enable Fedora 33 upgrades to 34 2021-06-14 22:37:03 -05:00
jmrothst 1e9f2eb112 Remove warn because ansible cannot handle both a warn and ansible.builting.shell ?! 2021-03-28 05:24:30 +00:00
jmrothst 2318c37337 Disable warnings on dnf system-upgrade plugin calls 2021-03-28 05:02:16 +00:00
jmrothst 5f430875ad Enable Fedora 23-29 to upgrade via DNF 2021-03-27 23:58:14 -05:00
jmrothst 4cc4d6c0f6 Fix indentation syntax error 2021-03-28 04:43:40 +00:00
jmrothst 7fae75d1e3 Ensure Fedora 32 can only upgrade to 33 2021-03-28 04:40:15 +00:00
jmrothst 79f12c739d Ensure Fedora 31 can only upgrade to 32 2021-03-28 04:39:55 +00:00
jmrothst e348c25119 Ensure Fedora 30 can only upgrade to 31 2021-03-28 04:39:34 +00:00
jmrothst 36377d9111 Remove default targets 2021-03-28 04:39:05 +00:00
jmrothst 5c5594be6e If we know how to upgrade Fedora via DNF... do it. 2021-03-28 04:38:25 +00:00
jmrothst be05345429 Enable Fedora 30 to upgrade 2021-03-28 04:29:37 +00:00
jmrothst 25d554da9a Enable Fedora 31 to upgrade 2021-03-28 04:29:15 +00:00
jmrothst 16494c44cf Enable Fedora 32 to upgrade 2021-03-28 04:28:03 +00:00
jmrothst a6c22bd920 Add default OS/Vendor config of do nothing 2021-03-28 04:26:13 +00:00
jmrothst 3059a0ec23 Define basic role feature 2021-03-28 04:16:53 +00:00
jmrothst 08d1e4f3cd Setup default handlers to gather facts 2021-03-28 04:11:57 +00:00
jmrothst dffd55bc44 Set the default target Fedora to upgrade to 2021-03-28 04:10:14 +00:00
jmrothst df3d243d8f Initial Ansible Role 2021-03-27 23:08:41 -05:00
jmrothst 057bf4bf2e Initial Ansible Role 2021-03-27 23:07:49 -05:00
AnsibleRoles c48179e9d2 Initial commit 2021-03-28 04:03:44 +00:00
jmrothst 583010597a CentOS 8 Stream didn't Obsolete cockpit-dashboard correctly 2021-02-20 20:29:26 -06:00
jmrothst 2713fc3d40 Use ansible_cmdline to detect cgroup status 2021-02-08 22:41:16 -06:00
jmrothst eede7f1129 Fix task label to make sense 2021-02-08 22:39:16 -06:00
jmrothst a0ae8d612f Use ansible_cmdline instead of cat for /proc/cmdline 2021-02-08 22:37:11 -06:00
jmrothst 4b5964e8e1 Test variables before use to make check mode work 2021-02-08 22:23:31 -06:00
jmrothst 11cbd7a6b8 Remove debugt, everything is working 2021-02-08 22:21:59 -06:00
jmrothst 767bfce236 Add debugging to find out why check mode is broken 2021-02-08 22:20:04 -06:00
jmrothst 2c85c790ad Only run grubby if cat runs (fixes check mode) 2021-02-08 22:14:56 -06:00
jmrothst 7e8f49f46b Add missing handlers 2021-02-08 21:31:27 -06:00
jmrothst 70ae010387 ENsure correct variable file names 2021-02-08 21:29:30 -06:00
jmrothst 580586ea5a Ensure correct variable file names 2021-02-08 21:28:53 -06:00
jmrothst 2d159bcf30 Ensure correct variable file names 2021-02-08 21:28:25 -06:00
jmrothst 0a8f593877 Use correct variable names 2021-02-08 21:25:07 -06:00
jmrothst 309c6221b0 Correct the task label for when the variable isn't defined 2020-12-28 17:48:52 -06:00
jmrothst b1c4d3ff7d Clean logs older than 90d by default to add missing feature to sudo 2020-12-28 17:39:10 -06:00
jmrothst 45c76ba052 Fix template_list variable name error 2020-12-28 15:15:27 -06:00
jmrothst cb7e9b28f6 Add role meta 2020-12-28 15:13:28 -06:00
jmrothst 7bc9d63a0a Add missing handlers 2020-12-28 15:12:30 -06:00
jmrothst a96d016077 Use correct variable names to ensure sudo is deployed 2020-12-28 15:10:50 -06:00
jmrothst 773058c735 Ensure sudo with local session logs for Fedora 33 2020-12-28 14:56:37 -06:00
jmrothst 0449d81189 Initial Role 2020-12-28 14:11:34 -06:00
AnsibleRoles 8837fed490 Initial commit 2020-12-28 20:09:46 +00:00
jmrothst f5ff83c468 Fix syntax 2020-12-20 17:41:16 -06:00
jmrothst aa1a61e81c Fix syntax 2020-12-20 17:40:57 -06:00
jmrothst 24cec463eb Enable docker for CentOS >= 7 and Fedora >= 30 2020-12-20 17:31:30 -06:00
jmrothst ce238951db Fix syntax on grubby to remove the parameter 2020-12-20 17:23:52 -06:00
jmrothst aa7e6e128d Initial Role 2020-12-20 17:20:10 -06:00
jmrothst 640ca9a5ed Ensure CGroupV2 is enabled 2020-12-20 17:18:24 -06:00
jmrothst 0a1ba4e9e3 Deploy podman for CentOS >= 8, Fedora >= 31 2020-12-20 17:06:38 -06:00
jmrothst 86936812af Initial Role 2020-12-20 17:00:41 -06:00
AnsibleRoles ec45534242 Initial commit 2020-12-20 22:49:46 +00:00
AnsibleRoles d1281a6e77 Initial commit 2020-12-20 22:48:33 +00:00
jmrothst 23d3e3e6d6 Now adding Fedora 21+ support 2020-12-20 15:17:54 -06:00
jmrothst 0003db02da Add CentOS 7+ and Fedora 30+ support 2020-12-20 14:52:18 -06:00
jmrothst 766274f4ac Spelling 2020-12-20 08:13:20 -06:00
jmrothst 22d27cef2f Syntax cleanup for style 2020-12-20 07:56:36 -06:00
jmrothst 8ce72d3689 CentOS >= 8 has dnf-automatic, so enable it 2020-12-20 07:51:47 -06:00
jmrothst 18a9565390 Do service discovery as well as package discovery 2020-12-20 07:45:25 -06:00
jmrothst bce2321f37 Do service discovery as well as package discovery 2020-12-20 07:44:31 -06:00
jmrothst 0b530f5a29 Do service discovery as well as package discovery 2020-12-20 07:43:19 -06:00
jmrothst ad8f19fe14 Do service discovery as well as package discovery 2020-12-20 07:42:49 -06:00
jmrothst ef9269bbba Do service discovery as well as package discovery 2020-12-20 07:42:01 -06:00
jmrothst c568d85bfb Do service discovery as well as package discovery 2020-12-20 07:41:33 -06:00
jmrothst 718dd49262 Do service discovery as well as package discovery 2020-12-20 07:41:01 -06:00
jmrothst 03153b9e98 Do service discovery as well as package discovery 2020-12-20 07:40:15 -06:00
jmrothst d2e3fa413e Do service discovery as well as package discovery 2020-12-20 07:39:46 -06:00
jmrothst be72b70c4a Do service discovery as well as package discovery 2020-12-20 07:39:11 -06:00
jmrothst af72c4a0d6 Disable GPG key check for Fedora 32 install 2020-12-07 05:57:44 -06:00
jmrothst c1884d8e09 Sort the keys 2020-12-07 05:56:19 -06:00
jmrothst ae51d56ecc Disable GPG check for repo install 2020-12-07 05:55:42 -06:00
jmrothst c9d4e3933d Sort the keys 2020-12-07 05:55:14 -06:00
jmrothst ac4f2e19ed Fedora 32 should ignore the gpg check on package install 2020-12-06 21:51:42 -06:00
jmrothst 7a1b1a74cd Ignore GPG for Fedora 33 2020-12-06 21:33:23 -06:00
jmrothst 6915ca636c Fix syntax to be default(omit) 2020-12-06 21:15:06 -06:00
jmrothst 2d50aa0a7d Fix syntax to be default(omit) 2020-12-06 21:14:18 -06:00
jmrothst 2b125364b4 Fix the default(omit) syntax 2020-12-06 21:13:20 -06:00
jmrothst 98bf037636 Ensure generic OS are actually generic, and add Fedora 32, 33 2020-12-06 20:31:24 -06:00
jmrothst cb3b64616e Use standardized / generic method to install packages for EPEL 2020-12-06 19:57:08 -06:00
jmrothst 047a208507 Make disable_gpg_check default unless overridden 2020-12-06 16:35:19 -06:00
jmrothst 3fbb29ec47 Allow CentOS 8 to disable GPG check to install the repo 2020-12-06 15:42:25 -06:00
jmrothst 0962e8f74b Enable override of timezone name or hwclock independently 2020-12-06 00:44:26 -06:00
jmrothst 99a92efe44 Enable SELinux, by default to enforce the targeted policy 2020-12-05 23:53:18 -06:00
jmrothst fb4f9061c9 Track the issues we address 2020-12-06 05:41:04 +00:00
jmrothst 7b36753efe Ensure services needed start 2020-12-05 23:32:03 -06:00
jmrothst 553b0d3805 YAML syntax 2020-12-05 23:29:25 -06:00
jmrothst 78ccbdd9a3 Use common package install via variables rather than hard code the task 2020-12-05 23:23:46 -06:00
jmrothst 36568d7d00 Ansible Role Init 2020-12-05 23:07:12 -06:00
AnsibleRoles 786efc258b Initial commit 2020-12-06 05:02:43 +00:00
jmrothst 86c66a7632 Only restart cron if time zone actually changed... 2020-11-29 23:54:27 -06:00
jmrothst 743b9592bb Enable cockpit, initially Fedora 33 with others later 2020-11-29 23:21:17 -06:00
jmrothst cd4e29d5a4 Default Ansible role content 2020-11-29 23:06:29 -06:00
AnsibleRoles 12c4875a71 Initial commit 2020-11-30 05:05:22 +00:00
jmrothst a6d1e5fe60 Be specific about OS Vendors 2020-11-29 21:50:56 -06:00
jmrothst 624cd476a7 Be specific about OS Vendor support, and add additional EL 6 fixups 2020-11-29 21:49:46 -06:00
jmrothst 3dc9a81373 Use Ansible FQCN 2020-11-29 21:44:30 -06:00
jmrothst eb0ebd829b Be specific about the supported EL release 2020-11-29 21:42:47 -06:00
jmrothst 01012ddeff Add Fedora 32 support 2020-11-29 21:42:28 -06:00
jmrothst 2b50b89402 disable gpg check on rpm install from URLs 2020-11-29 21:38:58 -06:00
jmrothst dfbfedb495 Be specific with Oracle Linux and EPEL RPMs 2020-11-29 21:34:09 -06:00
jmrothst 4fc9faa2d6 Document and ensure Ansible FQCN 2020-11-29 21:27:46 -06:00
jmrothst e3e0a81f21 Use Ansible FQCN 2020-11-29 21:24:11 -06:00
jmrothst 8fe4ea7eff Prefer Ansible Disitribution over Ansible OS Family 2020-11-29 21:21:48 -06:00
jmrothst 999c28b75b Ensure SELinux python bindings exist on EL 6 2020-11-29 21:03:40 -06:00
jmrothst 229049b12d Remove FQCN 2020-11-30 01:15:12 +00:00
jmrothst 8856668fb3 remote collections line for meta 2020-11-29 18:17:23 -06:00
jmrothst d1d7ab2f47 Ansible 2.9 does not let FQCN be used with meta 2020-11-29 18:14:15 -06:00
jmrothst 1af187e701 Update to use FQCN 2020-11-29 18:09:48 -06:00
jmrothst ecbcb975b6 All tasks now use FQCN 2020-11-29 17:53:24 -06:00
jmrothst 54ae65a7af Update 'tasks/RedHat-6-default.yml' 2020-11-29 23:40:12 +00:00
jmrothst 61e01617f1 Enable OracleLinux to use EPEL (Different method from CentOS) 2020-11-22 16:17:22 -06:00
jmrothst 0893312567 Remove duplicate service restart code 2020-11-22 16:11:44 -06:00
jmrothst c85dd54ded Ansible doesn't like FQCN on meta?! 2020-11-22 15:58:37 -06:00
jmrothst 34f2e118b4 Support Collections, and native epel-release packages 2020-11-22 15:50:07 -06:00
jmrothst 7d88e699bf Configure timezones, defaulting to UTC 2020-11-22 14:41:50 -06:00
jmrothst c5c16f9b2c Enable Fedora 32 and Fedora 33 support 2020-11-22 14:28:46 -06:00
AnsibleRoles 7bd875e21e Initial commit 2020-11-22 13:28:27 -06:00
jmrothst 7b393ff720 started not running 2020-08-16 15:13:20 -05:00
jmrothst cf7832b3fb Use ansible version to perform the version compare 2020-08-16 15:09:56 -05:00
jmrothst f424b64571 Enable Fedora to use dnf-automatic to install os patches 2020-08-16 13:43:17 -05:00
jmrothst d98ddda666 Make dictionaries matainable 2020-03-28 17:49:23 -05:00
jmrothst 1d3e7d79c1 Galaxy Metadata update 2020-03-28 17:46:11 -05:00
jmrothst f8c7c135e7 Make dictionaries maintainable 2020-03-28 17:44:10 -05:00
jmrothst 7a94ac696f update galaxy metadat 2020-03-28 17:42:13 -05:00
jmrothst aeaaab59bb Update galaxy metadata 2020-03-28 17:39:40 -05:00
jmrothst 616690e6d7 Make galaxy metadata match 2020-03-28 17:38:34 -05:00
jmrothst f629a58962 Make metadata match license 2020-03-28 17:37:34 -05:00
jmrothst 9bd038d8d1 Make dictionaries maintainable 2020-03-28 17:36:22 -05:00
jmrothst ba98012947 Update license to be correct 2020-03-28 17:34:59 -05:00
jmrothst 61a88d1aa3 Make dictionaries maintainable 2020-03-28 17:31:55 -05:00
jmrothst acc77d87cc Make syntax maintainable and find the spelling error 2020-03-28 17:29:44 -05:00
jmrothst bb5ea2126a Markdown table adjustment for strict interpretations 2020-03-28 16:42:37 -05:00
jmrothst 8256227922 Revert because gitea cannot format markdown tables *grrr* 2020-03-28 16:40:11 -05:00
jmrothst b3f424ab78 Markdown format issue in readme for table 2020-03-28 16:38:41 -05:00
jmrothst 994eae66bc Use ansible_os_family instead of ansbile_distribution for EL based distributions on templates 2020-03-28 16:37:11 -05:00
jmrothst 604b001e46 Make days retained configurable 2020-03-28 16:34:52 -05:00
jmrothst 2e31082b3f Add rotation policy to EL based OS to match Fedora 2020-03-28 16:29:32 -05:00
jmrothst cc14a5aa34 Typo fix 2020-03-28 16:17:22 -05:00
jmrothst c1257e6274 Set Fedora policy to 90 days of compressed logs 2020-03-28 15:47:29 -05:00
jmrothst 3279b7ea6b Package install really needs to be done with package module 2020-03-27 23:33:45 -05:00
jmrothst 1c63d23fef Ensure packages are installed before service management 2020-03-27 23:30:16 -05:00
jmrothst cd612ab714 Remove logrotate.service from services on Fedora as only the timer should be touched 2020-03-27 23:16:19 -05:00
jmrothst c1fce9aecc Iterate over service_list for service module only 2020-03-27 23:15:55 -05:00
jmrothst 0a007e1eec Remove services from the RedHat OS family as the EL releases use cron for this instead of SystemD Timers 2020-03-27 23:02:04 -05:00
jmrothst a8e91b8ac0 Remove check for service installed before managing it and expect the input provided to be correct 2020-03-27 22:50:25 -05:00
jmrothst 9f8f9826ba Ensure logrotate is installed and enabled 2020-03-27 22:33:48 -05:00
jmrothst 42331a851a Add role shell 2020-03-27 22:11:51 -05:00
AnsibleRoles 5ad47b7898 Initial commit 2020-03-28 03:09:23 +00:00
jmrothst 214fb9d7cc Use error ignore instead of skip yes to remove deprecation warning 2020-01-01 23:48:51 -06:00
jmrothst 2efa793608 Skip if we don't have special things to do, and pass right values for EL6 service changes 2020-01-01 23:02:58 -06:00
jmrothst a3dab8f6d3 Add support for apt based distributions like Debian 2020-01-01 22:57:56 -06:00
jmrothst 116f5fa1c2 Remove service states from Debian as we don't have any... yet 2020-01-01 22:50:50 -06:00
jmrothst 00aa81a572 Strip debian cdrom repos 2020-01-01 22:49:40 -06:00
jmrothst 41b6e92f40 Handle OS requirements for Ansible 2020-01-01 22:34:15 -06:00
jmrothst 9bf9244bfc Install by url not name 2019-12-30 20:30:42 -06:00
jmrothst 6910e92cc8 Install by URL not name 2019-12-30 20:29:55 -06:00
jmrothst f393e9cf03 Enable Fedora 30+ and EPEL 6+ support 2019-12-30 20:23:51 -06:00
jmrothst 0c574875cd Deploy rpmfusion on EL and Fedora distro for supported versions 2019-12-30 16:41:27 -06:00
jmrothst 9a29d460dd Mark handlers with psuedo namespace to prevent unintended consequences 2019-12-30 15:53:51 -06:00
jmrothst 6d66539a4f Deploy EPEL for all EL class OS 2019-12-30 15:52:52 -06:00
AnsibleRoles 134a0feb5b Initial commit 2019-12-30 21:37:29 +00:00
AnsibleRoles b9f7b64a0b Initial commit 2019-12-30 21:36:52 +00:00
AnsibleRoles d6c9fae8df Initial commit 2019-12-30 21:36:05 +00:00
jmrothst 09a336598e Make work for any dnf/yum compatible system, not just what we know about 2019-12-24 23:30:01 -06:00
jmrothst 73256203cc Ensure OS Patch 2019-11-21 21:35:13 -06:00
AnsibleRoles 25f3545bbe Initial commit 2019-11-22 03:27:31 +00:00
1067 changed files with 40978 additions and 74 deletions
+5 -5
View File
@@ -21,22 +21,22 @@ collectionforce:
ansible-galaxy collection install -r ./collections/requirements.yml --force
.PHONY: ping
ping:
ping: galaxy
ansible -m ping all
.PHONY: setup
setup:
setup: galaxy
ansible -m setup all
.PHONY: reboot
reboot:
reboot: galaxy
ansible -m reboot all
.PHONY: playbook
playbook:
playbook: galaxy
ansible-playbook test.yml
.PHONY: checkdiff
checkdiff:
checkdiff: galaxy
ansible-playbook test.yml --check --diff
+1 -1
View File
@@ -12,4 +12,4 @@ callbacks_enabled = ansible.posix.profile_tasks,ansible.posix.profile_roles
[ssh_connection]
pipelining = true
# ssh_args = -o ControlMaster=auto
ssh_args = -o ControlMaster=auto
+10 -5
View File
@@ -6,19 +6,24 @@ collections:
- name: 'awx.awx'
- name: 'community.crypto'
- name: 'community.digitalocean'
- name: 'community.docker'
- name: 'community.dns'
- name: 'community.general'
- name: 'community.grafana'
- name: 'community.kubernetes'
- name: 'community.hashi_vault'
- name: 'community.libvirt'
- name: 'community.mysql'
- name: 'community.network'
- name: 'community.postgresql'
- name: 'community.network'
- name: 'community.proxysql'
- name: 'community.rabbitmq'
- name: 'community.windows'
- name: 'community.zabbix'
- name: 'containers.podman'
- name: 'grafana.grafana'
- name: 'gluster.gluster'
- name: 'kubernetes.core'
- name: 'kubevirt.core'
- name: 'openstack.cloud'
- name: 'ovirt.ovirt'
- name: 'microsoft.ad'
- name: 'microsoft.iis'
...
+29
View File
@@ -0,0 +1,29 @@
---
language: python
python: "2.7"
# Use the new container infrastructure
sudo: false
# Install ansible
addons:
apt:
packages:
- python-pip
install:
# Install ansible
- pip install ansible
# Check ansible version
- ansible --version
# Create ansible.cfg with correct roles_path
- printf '[defaults]\nroles_path=../' >ansible.cfg
script:
# Basic role syntax check
- ansible-playbook tests/test.yml -i tests/inventory --syntax-check
notifications:
webhooks: https://galaxy.ansible.com/api/v1/notifications/
+38
View File
@@ -0,0 +1,38 @@
Role Name
=========
A brief description of the role goes here.
Requirements
------------
Any pre-requisites that may not be covered by Ansible itself or the role should be mentioned here. For instance, if the role uses the EC2 module, it may be a good idea to mention in this section that the boto package is required.
Role Variables
--------------
A description of the settable variables for this role should go here, including any variables that are in defaults/main.yml, vars/main.yml, and any variables that can/should be set via parameters to the role. Any variables that are read from other roles and/or the global scope (ie. hostvars, group vars, etc.) should be mentioned here as well.
Dependencies
------------
A list of other roles hosted on Galaxy should go here, plus any details in regards to parameters that may need to be set for other roles, or variables that are used from other roles.
Example Playbook
----------------
Including an example of how to use your role (for instance, with variables passed in as parameters) is always nice for users too:
- hosts: servers
roles:
- { role: username.rolename, x: 42 }
License
-------
LGPL-3.0-or-later
Author Information
------------------
An optional section for the role authors to include contact information, or a website (HTML is not allowed).
@@ -0,0 +1,2 @@
---
# defaults file for ensure_ansible_prereq
@@ -0,0 +1,29 @@
---
# handlers file for ensure_ansible_prereq
- name: 'ensure_ansible_prereq.package_facts'
ansible.builtin.package_facts:
- name: 'ensure_ansible_prereq.service_facts'
ansible.builtin.service_facts:
- name: 'ensure_ansible_prereq.service_reload'
when:
- ansible_facts["system"] == 'Linux'
- ansible_facts["service_mgr"] == 'systemd'
- ensure_ansible_prereq is defined
ansible.builtin.systemd:
daemon_reload: 'yes'
- name: 'ensure_ansible_prereq.service_restart'
when:
- ansible_facts["system"] == 'Linux'
- ensure_ansible_prereq is defined
- ensure_ansible_prereq.service_list is defined
- ensure_ansible_prereq.service_list is iterable
- item.state == 'started'
ansible.builtin.service:
enabled: '{{ item.enabled }}'
name: '{{ item.name }}'
state: 'restarted'
loop: '{{ ensure_ansible_prereq.service_list }}'
loop_control:
label: '{{ item.name }} will be restarted'
...
+53
View File
@@ -0,0 +1,53 @@
galaxy_info:
author: Jason Rothstein
description: Ensure required pre-req are present for ansible management
company: your company (optional)
# If the issue tracker for your role is not on github, uncomment the
# next line and provide a value
# issue_tracker_url: http://example.com/issue/tracker
# Choose a valid license ID from https://spdx.org - some suggested licenses:
# - BSD-3-Clause (default)
# - MIT
# - GPL-2.0-or-later
# - GPL-3.0-only
# - Apache-2.0
# - CC-BY-4.0
license: LGPL-3.0-or-later
min_ansible_version: 2.9
# If this a Container Enabled role, provide the minimum Ansible Container version.
# min_ansible_container_version:
#
# Provide a list of supported platforms, and for each platform a list of versions.
# If you don't wish to enumerate all versions for a particular platform, use 'all'.
# To view available platforms and versions (or releases), visit:
# https://galaxy.ansible.com/api/v1/platforms/
#
# platforms:
# - name: Fedora
# versions:
# - all
# - 25
# - name: SomePlatform
# versions:
# - all
# - 1.0
# - 7
# - 99.99
galaxy_tags: []
# List tags for your role here, one per line. A tag is a keyword that describes
# and categorizes the role. Users find roles by searching for tags. Be sure to
# remove the '[]' above, if you add tags to this list.
#
# NOTE: A tag is limited to a single word comprised of alphanumeric characters.
# Maximum 20 tags per role.
dependencies: []
# List your role dependencies here, one per line. Be sure to remove the '[]' above,
# if you add dependencies to this list.
@@ -0,0 +1,9 @@
---
# tasks file for ensure_ansible_prereq
- name: 'repository changes'
ansible.builtin.lineinfile:
path: '/etc/apt/sources.list'
state: 'absent'
regexp: 'deb cdrom:'
...
@@ -0,0 +1,2 @@
---
# tasks file for ensure_ansible_prereq
+107
View File
@@ -0,0 +1,107 @@
---
# tasks file for ensure_ansible_prereq
- name: 'include vendor / version specific tasks'
when:
- ansible_facts["system"] == 'Linux'
include_tasks:
file: '{{ lookup("first_found", findme ) }}'
vars:
findme:
files:
- '{{ ansible_facts["distribution"] }}-{{ ansible_facts["distribution_major_version"] }}-{{ ansible_facts["architecture"] }}.yml'
- '{{ ansible_facts["distribution"] }}-{{ ansible_facts["distribution_major_version"] }}-default.yml'
- '{{ ansible_facts["distribution"] }}-default.yml'
- '{{ ansible_facts["os_family"] }}-{{ ansible_facts["distribution_major_version"] }}-{{ ansible_facts["architecture"] }}.yml'
- '{{ ansible_facts["os_family"] }}-{{ ansible_facts["distribution_major_version"] }}-default.yml'
- '{{ ansible_facts["os_family"]}}-default.yml'
- 'default.yml'
errors: 'ignore'
- name: 'include vendor / version specific variables'
when:
- ansible_facts["system"] == 'Linux'
include_vars:
file: '{{ lookup("first_found", findme ) }}'
name: 'ensure_ansible_prereq'
vars:
findme:
files:
- '{{ ansible_facts["distribution"] }}-{{ ansible_facts["distribution_major_version"] }}-{{ ansible_facts["architecture"] }}.yml'
- '{{ ansible_facts["distribution"] }}-{{ ansible_facts["distribution_major_version"] }}-default.yml'
- '{{ ansible_facts["distribution"] }}-default.yml'
- '{{ ansible_facts["os_family"] }}-{{ ansible_facts["distribution_major_version"] }}-{{ ansible_facts["architecture"] }}.yml'
- '{{ ansible_facts["os_family"] }}-{{ ansible_facts["distribution_major_version"] }}-default.yml'
- '{{ ansible_facts["os_family"] }}-default.yml'
- 'default.yml'
paths:
- '../vars/'
errors: 'ignore'
- name: 'package discovery'
when:
- ansible_facts["system"] == 'Linux'
- ansible_facts["packages"] is not defined
ansible.builtin.package_facts:
- name: 'service discovery'
when:
- ansible_facts["system"] == 'Linux'
- ansible_facts["services"] is not defined
ansible.builtin.service_facts:
- name: 'ensure packages'
when:
- ansible_facts["system"] == 'Linux'
- ensure_ansible_prereq is defined
- ensure_ansible_prereq.package_list is defined
- ensure_ansible_prereq.package_list is iterable
ansible.builtin.package:
name: '{{ item.name }}'
state: '{{ item.state }}'
loop: '{{ ensure_ansible_prereq.package_list }}'
loop_control:
label: '{{ item.name }} will be {{ item.state }}'
notify:
- 'ensure_ansible_prereq.package_facts'
- 'ensure_ansible_prereq.service_facts'
- name: 'ensure configurations'
when:
- ansible_facts["system"] == 'Linux'
- ensure_ansible_prereq is defined
- ensure_ansible_prereq.template_list is defined
- ensure_ansible_prereq.template_list is iterable
ansible.builtin.template:
backup: 'no'
dest: '{{ item.dest }}'
group: '{{ item.group | default(omit) }}'
mode: '{{ item.mode | default(omit) }}'
owner: '{{ item.owner | default(omit) }}'
selevel: '{{ iteml.selevel | default(omit) }}'
serole: '{{ item.serole | default(omit) }}'
setype: '{{ item.setype | default(omit) }}'
seuser: '{{ item.seuser | default(omit) }}'
src: '{{ item.src }}'
loop: '{{ ensure_ansible_prereq.template_list }}'
loop_control:
label: '{{ item.dest }} will be ensured'
notify:
- 'ensure_ansible_prereq.package_facts'
- 'ensure_ansible_prereq.service_facts'
- 'ensure_ansible_prereq.service_reload'
- 'ensure_ansible_prereq.service_restart'
- name: 'ensure services'
when:
- ansible_facts["system"] == 'Linux'
- ensure_ansible_prereq is defined
- ensure_ansible_prereq.service_list is defined
- ensure_ansible_prereq.service_list is iterable
ansible.builtin.service:
enabled: '{{ item.enabled }}'
name: '{{ item.name }}'
state: '{{ item.state }}'
loop: '{{ ensure_ansible_prereq.service_list }}'
loop_control:
label: '{{ item.name }} will be {{ item.state }}'
notify:
- 'ensure_ansible_prereq.package_facts'
- 'ensure_ansible_prereq.service_facts'
- name: 'flush handlers'
meta: 'flush_handlers'
...
@@ -0,0 +1,2 @@
localhost
@@ -0,0 +1,5 @@
---
- hosts: localhost
remote_user: root
roles:
- ensure_ansible_prereq
@@ -0,0 +1,2 @@
---
# vars file for ensure_ansible_prereq
@@ -0,0 +1,2 @@
---
# vars file for ensure_ansible_prereq
+29
View File
@@ -0,0 +1,29 @@
---
language: python
python: "2.7"
# Use the new container infrastructure
sudo: false
# Install ansible
addons:
apt:
packages:
- python-pip
install:
# Install ansible
- pip install ansible
# Check ansible version
- ansible --version
# Create ansible.cfg with correct roles_path
- printf '[defaults]\nroles_path=../' >ansible.cfg
script:
# Basic role syntax check
- ansible-playbook tests/test.yml -i tests/inventory --syntax-check
notifications:
webhooks: https://galaxy.ansible.com/api/v1/notifications/
+73
View File
@@ -0,0 +1,73 @@
Role Name
=========
A brief description of the role goes here.
Requirements
------------
Any pre-requisites that may not be covered by Ansible itself or the role should be mentioned here. For instance, if the role uses the EC2 module, it may be a good idea to mention in this section that the boto package is required.
Feature List
------------
* Apache deployed
* Enables HTTP/2
* Enables and convets connections to HTTPS by default
* ACME based TLS Certificate request and renewal
* ACME uses Lets Encrypt by default, alternative ACME Providers may be specified
* Optionally act as a proxy to another URL
* Optionally redirect traffic to another URL
* Optionally populate DocumentRoot with git clone
* Multiple DocumentRoots supported, with aliases
Role Variables
--------------
* Lets Encrypt configuration
* lets_encrypt_admin : The Email address your Lets Encrypt account is with
* lets_encrypt_url : The ACME URL to speak with, defaults to Lets Encrypt, may set to 'https://acme-staging-v02.api.letsencrypt.org/directory' for Staging
* Web Host variable of type list
* http_vhost
* required dictionary elements
* fqdn : The FQDN of the website
* optional dictionary elements
* aliases : list of alternative FQDN for the website
* proxy : URL to direct traffic for the FQDN to, e.g. http://localhost:8080
* redirect : Where should we send traffic?
* repo : git URL of website repo to clone/update
~~~
lets_encrypt_admin: 'acme@example.com'
lets_encrypt_url: 'https://ipa.example.com'
http_vhost:
- fqdn: 'www.example.com'
aliases:
- 'exmaple.com'
proxy: 'http://localhost:8080'
~~~
Dependencies
------------
A list of other roles hosted on Galaxy should go here, plus any details in regards to parameters that may need to be set for other roles, or variables that are used from other roles.
Example Playbook
----------------
Including an example of how to use your role (for instance, with variables passed in as parameters) is always nice for users too:
- hosts: servers
roles:
- { role: username.rolename, x: 42 }
License
-------
BSD
Author Information
------------------
An optional section for the role authors to include contact information, or a website (HTML is not allowed).
+4
View File
@@ -0,0 +1,4 @@
---
# defaults file for ensure_apache
lets_encrypt_admin: 'root@example.com'
lets_encrypt_url: 'https://acme-v02.api.letsencrypt.org/directory'
+29
View File
@@ -0,0 +1,29 @@
---
# handlers file for ensure_apache
- name: 'ensure_apache.package_facts'
ansible.builtin.package_facts:
- name: 'ensure_apache.service_facts'
ansible.builtin.service_facts:
- name: 'ensure_apache.service_reload'
when:
- ansible_facts["system"] == 'Linux'
- ansible_facts["service_mgr"] == 'systemd'
- ensure_apache is defined
ansible.builtin.systemd:
daemon_reload: 'yes'
- name: 'ensure_apache.service_restart'
when:
- ansible_facts["system"] == 'Linux'
- ensure_apache is defined
- ensure_apache.service_list is defined
- ensure_apache.service_list is iterable
- item.state == 'started'
ansible.builtin.service:
enabled: '{{ item.enabled }}'
name: '{{ item.name }}'
state: 'restarted'
loop: '{{ ensure_apache.service_list }}'
loop_control:
label: '{{ item.name }} will be restarted'
...
+53
View File
@@ -0,0 +1,53 @@
galaxy_info:
author: Jason Rothstein
description: Ensure Apache is installed, running, and functional
company: your company (optional)
# If the issue tracker for your role is not on github, uncomment the
# next line and provide a value
# issue_tracker_url: http://example.com/issue/tracker
# Choose a valid license ID from https://spdx.org - some suggested licenses:
# - BSD-3-Clause (default)
# - MIT
# - GPL-2.0-or-later
# - GPL-3.0-only
# - Apache-2.0
# - CC-BY-4.0
license: LGPL-3.0-or-later
min_ansible_version: 2.9
# If this a Container Enabled role, provide the minimum Ansible Container version.
# min_ansible_container_version:
#
# Provide a list of supported platforms, and for each platform a list of versions.
# If you don't wish to enumerate all versions for a particular platform, use 'all'.
# To view available platforms and versions (or releases), visit:
# https://galaxy.ansible.com/api/v1/platforms/
#
# platforms:
# - name: Fedora
# versions:
# - all
# - 25
# - name: SomePlatform
# versions:
# - all
# - 1.0
# - 7
# - 99.99
galaxy_tags: []
# List tags for your role here, one per line. A tag is a keyword that describes
# and categorizes the role. Users find roles by searching for tags. Be sure to
# remove the '[]' above, if you add tags to this list.
#
# NOTE: A tag is limited to a single word comprised of alphanumeric characters.
# Maximum 20 tags per role.
dependencies: []
# List your role dependencies here, one per line. Be sure to remove the '[]' above,
# if you add dependencies to this list.
+225
View File
@@ -0,0 +1,225 @@
---
# tasks file for ensure_apache
- name: 'include variables'
when:
- ansible_facts["system"] == 'Linux'
include_vars:
file: '{{ lookup("first_found", findme ) }}'
name: 'ensure_apache'
vars:
findme:
files:
- '{{ ansible_facts["distribution"] }}-{{ ansible_facts["distribution_major_version"] }}-{{ ansible_facts["architecture"] }}.yml'
- '{{ ansible_facts["distribution"] }}-{{ ansible_facts["distribution_major_version"] }}-default.yml'
- '{{ ansible_facts["distribution"] }}-default.yml'
- '{{ ansible_facts["os_family"] }}-{{ ansible_facts["distribution_major_version"] }}-{{ ansible_facts["architecture"] }}.yml'
- '{{ ansible_facts["os_family"] }}-{{ ansible_facts["distribution_major_version"] }}-default.yml'
- '{{ ansible_facts["os_family"] }}-default.yml'
- 'default.yml'
paths:
- '../vars/'
errors: 'ignore'
- name: 'package discovery'
when:
- ansible_facts["system"] == 'Linux'
- ansible_facts["packages"] is not defined
ansible.builtin.package_facts:
- name: 'service discovery'
when:
- ansible_facts["system"] == 'Linux'
- ansible_facts["services"] is not defined
ansible.builtin.service_facts:
- name: 'ensure sysctl'
when:
- ansible_facts["system"] == 'Linux'
- ensure_apache is defined
- ensure_apache.sysctl_list is defined
- ensure_apache.sysctl_list is iterable
ansible.posix.sysctl:
name: '{{ item.name }}'
reload: '{{ item.reload | default(omit) }}'
state: '{{ item.state }}'
sysctl_file: '{{ item.sysctl_file | default(omit) }}'
sysctl_set: '{{ item.sysctl_set | default(omit) }}'
value: '{{ item.value | default(omit) }}'
loop: '{{ ensure_apache.sysctl_list }}'
loop_control:
label: '{{ item.name }} will be {{ item.value }}'
notify:
- 'ensure_apache.package_facts'
- 'ensure_apache.service_facts'
- 'ensure_apache.service_reload'
- 'ensure_apache.service_restart'
- name: 'ensure packages'
when:
- ansible_facts["system"] == 'Linux'
- ensure_apache is defined
- ensure_apache.package_list is defined
- ensure_apache.package_list is iterable
ansible.builtin.package:
name: '{{ item.name }}'
state: '{{ item.state }}'
loop: '{{ ensure_apache.package_list }}'
loop_control:
label: '{{ item.name }} will be {{ item.state }}'
notify:
- 'ensure_apache.package_facts'
- 'ensure_apache.service_facts'
- 'ensure_apache.service_reload'
- 'ensure_apache.service_restart'
- name: 'ensure seboolean'
when:
- ansible_facts["system"] == 'Linux'
- ensure_apache is defined
- ensure_apache.seboolean_list is defined
- ensure_apache.seboolean_list is iterable
ansible.posix.seboolean:
name: '{{ item.name }}'
persistent: '{{ item.persistent }}'
state: '{{ item.state }}'
loop: '{{ ensure_apache.seboolean_list }}'
loop_control:
label: '{{ item.name }} will be {{ item.state }}'
notify:
- 'ensure_apache.package_facts'
- 'ensure_apache.service_facts'
- 'ensure_apache.service_reload'
- 'ensure_apache.service_restart'
- name: 'ensure configurations'
when:
- ansible_facts["system"] == 'Linux'
- http_vhost is defined
- ensure_apache is defined
- ensure_apache.template_list is defined
- ensure_apache.template_list is iterable
ansible.builtin.template:
backup: 'no'
dest: '{{ item.dest }}'
group: '{{ item.group | default(omit) }}'
mode: '{{ item.mode | default(omit) }}'
owner: '{{ item.owner | default(omit) }}'
selevel: '{{ iteml.selevel | default(omit) }}'
serole: '{{ item.serole | default(omit) }}'
setype: '{{ item.setype | default(omit) }}'
seuser: '{{ item.seuser | default(omit) }}'
src: '{{ item.src }}'
loop: '{{ ensure_apache.template_list }}'
loop_control:
label: '{{ item.dest }} will be ensured'
notify:
- 'ensure_apache.package_facts'
- 'ensure_apache.service_facts'
- 'ensure_apache.service_reload'
- 'ensure_apache.service_restart'
- name: 'ensure firewall'
when:
- ansible_facts["system"] == 'Linux'
- ansible_facts.packages["firewalld"] is defined
- ansible_facts.packages["python3-firewall"] is defined
- ensure_apache is defined
- ensure_apache.firewall_list is defined
- ensure_apache.firewall_list is iterable
ansible.posix.firewalld:
permanent: '{{ item.permanent }}'
service: '{{ item.service }}'
state: '{{ item.state }}'
loop: '{{ ensure_apache.firewall_list }}'
loop_control:
label: '{{ item.service }} will be {{ item.state }}'
notify:
- 'ensure_apache.package_facts'
- 'ensure_apache.service_facts'
- 'ensure_apache.service_reload'
- 'ensure_apache.service_restart'
- name: 'ensure permissions'
when:
- ansible_facts["system"] == 'Linux'
- ensure_apache is defined
- http_vhost is defined
- http_vhost is iterable
- ensure_apache.permission_list is defined
- ensure_apache.permission_list is iterable
ansible.builtin.file:
attributes: '{{ item.attributes | default(omit) }}'
follow: '{{ item.follow | default(omit) }}'
force: '{{ item.force | default(omit) }}'
group: '{{ item.group | default(omit) }}'
owner: '{{ item.owner | default(omit) }}'
mode: '{{ item.mode | default(omit) }}'
path: '{{ item.path }}'
reuse: '{{ item.reuse | default(omit) }}'
selevel: '{{ item.selevel | default(omit) }}'
serole: '{{ item.serole | default(omit) }}'
setype: '{{ item.setype | default(omit) }}'
seuser: '{{ item.seuser | default(omit) }}'
src: '{{ item.src | default(omit) }}'
state: '{{ item.state }}'
loop: '{{ ensure_apache.permission_list }}'
loop_control:
label: '{{ item.path }} will be ensured'
notify:
- 'ensure_apache.package_facts'
- 'ensure_apache.service_facts'
- 'ensure_apache.service_reload'
- 'ensure_apache.service_restart'
- name: 'ensure vhost document roots'
when:
- ansible_facts["system"] == 'Linux'
- ensure_apache is defined
- http_vhost is defined
- http_vhost is iterable
- item.fqdn is defined
ansible.builtin.file:
path: '/srv/http/{{ item.fqdn }}'
state: 'directory'
setype: 'httpd_sys_content_t'
loop: '{{ http_vhost }}'
loop_control:
label: '/srv/http/{{ item.fqdn }} will be ensured'
notify:
- 'ensure_apache.package_facts'
- 'ensure_apache.service_facts'
- 'ensure_apache.service_reload'
- 'ensure_apache.service_restart'
- name: 'ensure website content from git repos'
when:
- ansible_facts["system"] == 'Linux'
- ensure_apache is defined
- http_vhost is defined
- http_vhost is iterable
- item.fqdn is defined
- item.repo is defined
ansible.builtin.git:
accept_hostkey: 'yes'
dest: '/srv/http/{{ item.fqdn }}'
repo: '{{ item.repo }}'
loop: '{{ http_vhost }}'
loop_control:
label: '/srv/http/{{ item.fqdn }} will be populated...'
notify:
- 'ensure_apache.package_facts'
- 'ensure_apache.service_facts'
- 'ensure_apache.service_reload'
- 'ensure_apache.service_restart'
- name: 'ensure services'
when:
- ansible_facts["system"] == 'Linux'
- ensure_apache is defined
- ensure_apache.service_list is defined
- ensure_apache.service_list is iterable
ansible.builtin.service:
enabled: '{{ item.enabled }}'
name: '{{ item.name }}'
state: '{{ item.state }}'
loop: '{{ ensure_apache.service_list }}'
loop_control:
label: '{{ item.name }} will be {{ item.state }}'
notify:
- 'ensure_apache.package_facts'
- 'ensure_apache.service_facts'
- 'ensure_apache.service_reload'
- 'ensure_apache.service_restart'
- name: 'flush handlers'
meta: 'flush_handlers'
...
@@ -0,0 +1,9 @@
This directory holds configuration files for the Apache HTTP Server;
any files in this directory which have the ".conf" extension will be
processed as httpd configuration files. The directory is used in
addition to the directory /etc/httpd/conf.modules.d/, which contains
configuration files necessary to load modules.
Files are processed in sorted order. See httpd.conf(5) for more
information.
@@ -0,0 +1,93 @@
#
# Directives controlling the display of server-generated directory listings.
#
# Required modules: mod_authz_core, mod_authz_host,
# mod_autoindex, mod_alias
#
# To see the listing of a directory, the Options directive for the
# directory must include "Indexes", and the directory must not contain
# a file matching those listed in the DirectoryIndex directive.
#
#
# IndexOptions: Controls the appearance of server-generated directory
# listings.
#
IndexOptions FancyIndexing HTMLTable VersionSort
# We include the /icons/ alias for FancyIndexed directory listings. If
# you do not use FancyIndexing, you may comment this out.
#
Alias /icons/ "/usr/share/httpd/icons/"
<Directory "/usr/share/httpd/icons">
Options Indexes MultiViews FollowSymlinks
AllowOverride None
Require all granted
</Directory>
#
# AddIcon* directives tell the server which icon to show for different
# files or filename extensions. These are only displayed for
# FancyIndexed directories.
#
AddIconByEncoding (CMP,/icons/compressed.gif) x-compress x-gzip
AddIconByType (TXT,/icons/text.gif) text/*
AddIconByType (IMG,/icons/image2.gif) image/*
AddIconByType (SND,/icons/sound2.gif) audio/*
AddIconByType (VID,/icons/movie.gif) video/*
AddIconByType /icons/bomb.gif application/x-coredump
AddIcon /icons/binary.gif .bin .exe
AddIcon /icons/binhex.gif .hqx
AddIcon /icons/tar.gif .tar
AddIcon /icons/world2.gif .wrl .wrl.gz .vrml .vrm .iv
AddIcon /icons/compressed.gif .Z .z .tgz .gz .zip
AddIcon /icons/a.gif .ps .ai .eps
AddIcon /icons/layout.gif .html .shtml .htm .pdf
AddIcon /icons/text.gif .txt
AddIcon /icons/c.gif .c
AddIcon /icons/p.gif .pl .py
AddIcon /icons/f.gif .for
AddIcon /icons/dvi.gif .dvi
AddIcon /icons/uuencoded.gif .uu
AddIcon /icons/script.gif .conf .sh .shar .csh .ksh .tcl
AddIcon /icons/tex.gif .tex
AddIcon /icons/back.gif ..
AddIcon /icons/hand.right.gif README
AddIcon /icons/folder.gif ^^DIRECTORY^^
AddIcon /icons/blank.gif ^^BLANKICON^^
#
# DefaultIcon is which icon to show for files which do not have an icon
# explicitly set.
#
DefaultIcon /icons/unknown.gif
#
# AddDescription allows you to place a short description after a file in
# server-generated indexes. These are only displayed for FancyIndexed
# directories.
# Format: AddDescription "description" filename
#
#AddDescription "GZIP compressed document" .gz
#AddDescription "tar archive" .tar
#AddDescription "GZIP compressed tar archive" .tgz
#
# ReadmeName is the name of the README file the server will look for by
# default, and append to directory listings.
#
# HeaderName is the name of a file which should be prepended to
# directory indexes.
ReadmeName README.html
HeaderName HEADER.html
#
# IndexIgnore is a set of filenames which directory indexing should ignore
# and not include in the listing. Shell-style wildcarding is permitted.
#
IndexIgnore .??* *~ *# HEADER* README* RCS CVS *,v *,t
@@ -0,0 +1,62 @@
#
# The following lines prevent .user.ini files from being viewed by Web clients.
#
<Files ".user.ini">
Require all denied
</Files>
#
# Allow php to handle Multiviews
#
AddType text/html .php
#
# Add index.php to the list of files that will be served as directory
# indexes.
#
DirectoryIndex index.php
#
# Redirect to local php-fpm (no mod_php in default configuration)
#
<IfModule !mod_php.c>
# Enable http authorization headers
SetEnvIfNoCase ^Authorization$ "(.+)" HTTP_AUTHORIZATION=$1
<FilesMatch \.(php|phar)$>
SetHandler "proxy:unix:/run/php-fpm/www.sock|fcgi://localhost"
</FilesMatch>
</IfModule>
#
# mod_php is deprecated as FPM is now used by default with httpd in event mode
# mod_php is only used when explicitly enabled or httpd switch to prefork mode
#
# mod_php options
#
<IfModule mod_php.c>
#
# Cause the PHP interpreter to handle files with a .php extension.
#
<FilesMatch \.(php|phar)$>
SetHandler application/x-httpd-php
</FilesMatch>
#
# Uncomment the following lines to allow PHP to pretty-print .phps
# files as PHP source code:
#
#<FilesMatch \.phps$>
# SetHandler application/x-httpd-php-source
#</FilesMatch>
#
# Apache specific PHP configuration options
# those can be override in each configured vhost
#
php_value session.save_handler "files"
php_value session.save_path "/var/lib/php/session"
php_value soap.wsdl_cache_dir "/var/lib/php/wsdlcache"
#php_value opcache.file_cache "/var/lib/php/opcache"
</IfModule>
@@ -0,0 +1,219 @@
#
# When we also provide SSL we have to listen to the
# standard HTTPS port in addition.
#
Listen 443 https
##
## SSL Global Context
##
## All SSL configuration in this context applies both to
## the main server and all SSL-enabled virtual hosts.
##
# Pass Phrase Dialog:
# Configure the pass phrase gathering process.
# The filtering dialog program (`builtin' is a internal
# terminal dialog) has to provide the pass phrase on stdout.
SSLPassPhraseDialog exec:/usr/libexec/httpd-ssl-pass-dialog
# Inter-Process Session Cache:
# Configure the SSL Session Cache: First the mechanism
# to use and second the expiring timeout (in seconds).
SSLSessionCache shmcb:/run/httpd/sslcache(512000)
SSLSessionCacheTimeout 300
# Pseudo Random Number Generator (PRNG):
# Configure one or more sources to seed the PRNG of the
# SSL library. The seed data should be of good random quality.
# WARNING! On some platforms /dev/random blocks if not enough entropy
# is available. This means you then cannot use the /dev/random device
# because it would lead to very long connection times (as long as
# it requires to make more entropy available). But usually those
# platforms additionally provide a /dev/urandom device which doesn't
# block. So, if available, use this one instead. Read the mod_ssl User
# Manual for more details.
SSLRandomSeed startup file:/dev/urandom 256
SSLRandomSeed connect builtin
#SSLRandomSeed startup file:/dev/random 512
#SSLRandomSeed connect file:/dev/random 512
#SSLRandomSeed connect file:/dev/urandom 512
#
# Use "SSLCryptoDevice" to enable any supported hardware
# accelerators. Use "openssl engine -v" to list supported
# engine names. NOTE: If you enable an accelerator and the
# server does not start, consult the error logs and ensure
# your accelerator is functioning properly.
#
SSLCryptoDevice builtin
#SSLCryptoDevice ubsec
##
## SSL Virtual Host Context
##
<VirtualHost _default_:443>
# General setup for the virtual host, inherited from global configuration
#DocumentRoot "/var/www/html"
#ServerName www.example.com:443
# Use separate log files for the SSL virtual host; note that LogLevel
# is not inherited from httpd.conf.
ErrorLog logs/ssl_error_log
TransferLog logs/ssl_access_log
LogLevel warn
# SSL Engine Switch:
# Enable/Disable SSL for this virtual host.
SSLEngine on
# List the protocol versions which clients are allowed to connect with.
# The OpenSSL system profile is configured by default. See
# update-crypto-policies(8) for more details.
#SSLProtocol all -SSLv3
#SSLProxyProtocol all -SSLv3
# User agents such as web browsers are not configured for the user's
# own preference of either security or performance, therefore this
# must be the prerogative of the web server administrator who manages
# cpu load versus confidentiality, so enforce the server's cipher order.
SSLHonorCipherOrder on
# SSL Cipher Suite:
# List the ciphers that the client is permitted to negotiate.
# See the mod_ssl documentation for a complete list.
# The OpenSSL system profile is configured by default. See
# update-crypto-policies(8) for more details.
SSLCipherSuite PROFILE=SYSTEM
SSLProxyCipherSuite PROFILE=SYSTEM
# Point SSLCertificateFile at a PEM encoded certificate. If
# the certificate is encrypted, then you will be prompted for a
# pass phrase. Note that restarting httpd will prompt again. Keep
# in mind that if you have both an RSA and a DSA certificate you
# can configure both in parallel (to also allow the use of DSA
# ciphers, etc.)
# Some ECC cipher suites (http://www.ietf.org/rfc/rfc4492.txt)
# require an ECC certificate which can also be configured in
# parallel.
SSLCertificateFile /etc/pki/tls/certs/localhost.crt
# Server Private Key:
# If the key is not combined with the certificate, use this
# directive to point at the key file. Keep in mind that if
# you've both a RSA and a DSA private key you can configure
# both in parallel (to also allow the use of DSA ciphers, etc.)
# ECC keys, when in use, can also be configured in parallel
SSLCertificateKeyFile /etc/pki/tls/private/localhost.key
# Server Certificate Chain:
# Point SSLCertificateChainFile at a file containing the
# concatenation of PEM encoded CA certificates which form the
# certificate chain for the server certificate. Alternatively
# the referenced file can be the same as SSLCertificateFile
# when the CA certificates are directly appended to the server
# certificate for convenience.
#SSLCertificateChainFile /etc/pki/tls/certs/server-chain.crt
# Certificate Authority (CA):
# Set the CA certificate verification path where to find CA
# certificates for client authentication or alternatively one
# huge file containing all of them (file must be PEM encoded)
#SSLCACertificateFile /etc/pki/tls/certs/ca-bundle.crt
# Client Authentication (Type):
# Client certificate verification type and depth. Types are
# none, optional, require and optional_no_ca. Depth is a
# number which specifies how deeply to verify the certificate
# issuer chain before deciding the certificate is not valid.
#SSLVerifyClient require
#SSLVerifyDepth 10
# Access Control:
# With SSLRequire you can do per-directory access control based
# on arbitrary complex boolean expressions containing server
# variable checks and other lookup directives. The syntax is a
# mixture between C and Perl. See the mod_ssl documentation
# for more details.
#<Location />
#SSLRequire ( %{SSL_CIPHER} !~ m/^(EXP|NULL)/ \
# and %{SSL_CLIENT_S_DN_O} eq "Snake Oil, Ltd." \
# and %{SSL_CLIENT_S_DN_OU} in {"Staff", "CA", "Dev"} \
# and %{TIME_WDAY} >= 1 and %{TIME_WDAY} <= 5 \
# and %{TIME_HOUR} >= 8 and %{TIME_HOUR} <= 20 ) \
# or %{REMOTE_ADDR} =~ m/^192\.76\.162\.[0-9]+$/
#</Location>
# SSL Engine Options:
# Set various options for the SSL engine.
# o FakeBasicAuth:
# Translate the client X.509 into a Basic Authorisation. This means that
# the standard Auth/DBMAuth methods can be used for access control. The
# user name is the `one line' version of the client's X.509 certificate.
# Note that no password is obtained from the user. Every entry in the user
# file needs this password: `xxj31ZMTZzkVA'.
# o ExportCertData:
# This exports two additional environment variables: SSL_CLIENT_CERT and
# SSL_SERVER_CERT. These contain the PEM-encoded certificates of the
# server (always existing) and the client (only existing when client
# authentication is used). This can be used to import the certificates
# into CGI scripts.
# o StdEnvVars:
# This exports the standard SSL/TLS related `SSL_*' environment variables.
# Per default this exportation is switched off for performance reasons,
# because the extraction step is an expensive operation and is usually
# useless for serving static content. So one usually enables the
# exportation for CGI and SSI requests only.
# o StrictRequire:
# This denies access when "SSLRequireSSL" or "SSLRequire" applied even
# under a "Satisfy any" situation, i.e. when it applies access is denied
# and no other module can change it.
# o OptRenegotiate:
# This enables optimized SSL connection renegotiation handling when SSL
# directives are used in per-directory context.
#SSLOptions +FakeBasicAuth +ExportCertData +StrictRequire
<FilesMatch "\.(cgi|shtml|phtml|php)$">
SSLOptions +StdEnvVars
</FilesMatch>
<Directory "/var/www/cgi-bin">
SSLOptions +StdEnvVars
</Directory>
# SSL Protocol Adjustments:
# The safe and default but still SSL/TLS standard compliant shutdown
# approach is that mod_ssl sends the close notify alert but doesn't wait for
# the close notify alert from client. When you need a different shutdown
# approach you can use one of the following variables:
# o ssl-unclean-shutdown:
# This forces an unclean shutdown when the connection is closed, i.e. no
# SSL close notify alert is sent or allowed to be received. This violates
# the SSL/TLS standard but is needed for some brain-dead browsers. Use
# this when you receive I/O errors because of the standard approach where
# mod_ssl sends the close notify alert.
# o ssl-accurate-shutdown:
# This forces an accurate shutdown when the connection is closed, i.e. a
# SSL close notify alert is sent and mod_ssl waits for the close notify
# alert of the client. This is 100% SSL/TLS standard compliant, but in
# practice often causes hanging connections with brain-dead browsers. Use
# this only for browsers where you know that their SSL implementation
# works correctly.
# Notice: Most problems of broken clients are also related to the HTTP
# keep-alive facility, so you usually additionally want to disable
# keep-alive for those clients, too. Use variable "nokeepalive" for this.
# Similarly, one has to force some clients to use HTTP/1.0 to workaround
# their broken HTTP/1.1 implementation. Use variables "downgrade-1.0" and
# "force-response-1.0" for this.
BrowserMatch "MSIE [2-5]" \
nokeepalive ssl-unclean-shutdown \
downgrade-1.0 force-response-1.0
# Per-Server Logging:
# The home of a custom SSL log file. Use this when you want a
# compact non-error SSL logfile on a virtual host basis.
CustomLog logs/ssl_request_log \
"%t %h %{SSL_PROTOCOL}x %{SSL_CIPHER}x \"%r\" %b"
</VirtualHost>
@@ -0,0 +1,36 @@
#
# UserDir: The name of the directory that is appended onto a user's home
# directory if a ~user request is received.
#
# The path to the end user account 'public_html' directory must be
# accessible to the webserver userid. This usually means that ~userid
# must have permissions of 711, ~userid/public_html must have permissions
# of 755, and documents contained therein must be world-readable.
# Otherwise, the client will only receive a "403 Forbidden" message.
#
<IfModule mod_userdir.c>
#
# UserDir is disabled by default since it can confirm the presence
# of a username on the system (depending on home directory
# permissions).
#
UserDir disabled
#
# To enable requests to /~user/ to serve the user's public_html
# directory, remove the "UserDir disabled" line above, and uncomment
# the following line instead:
#
#UserDir public_html
</IfModule>
#
# Control access to UserDir directories. The following is an example
# for a site where these directories are restricted to read-only.
#
<Directory "/home/*/public_html">
AllowOverride FileInfo AuthConfig Limit Indexes
Options MultiViews Indexes SymLinksIfOwnerMatch IncludesNoExec
Require method GET POST OPTIONS
</Directory>
@@ -0,0 +1,78 @@
MDBaseServer on
MDCertificateAgreement accepted
MDCertificateAuthority {{ lets_encrypt_url }}
MDContactEmail {{ lets_encrypt_admin }}
MDPrivateKeys secp384r1 secp256r1 RSA 4096
MDRequireHttps temporary
MDStoreDir md
<Directory "/srv/http">
AllowOverride None
Require all granted
</Directory>
{% for item in http_vhost %}
<Directory "/srv/http/{{ item.fqdn }}">
Options Indexes FollowSymLinks
AllowOverride None
Require all granted
</Directory>
<VirtualHost *:80>
ServerName {{ item.fqdn }}
{% if item.aliases is defined %}
{% for item_alias in item.aliases %}
ServerAlias {{ item_alias }}
{% endfor %}
{% endif %}
ServerAdmin webmaster@{{ item.fqdn }}
DocumentRoot /srv/http/{{ item.fqdn }}
{% if item.redirect is defined %}
RedirectMatch "^(?!/\.well-known/).*" {{ item.redirect }}
{% endif %}
</VirtualHost>
MDomain {{ item.fqdn }}
<VirtualHost *:443>
SSLEngine on
SSLProtocol all -TLSv1.1
SSLProxyProtocol all -TLSv1.1
SSLHonorCipherOrder on
SSLCipherSuite PROFILE=SYSTEM
SSLProxyCipherSuite PROFILE=SYSTEM
ServerName {{ item.fqdn }}
{% if item.aliases is defined %}
{% for item_alias in item.aliases %}
ServerAlias {{ item_alias }}
{% endfor %}
{% endif %}
ServerAdmin webmaster@{{ item.fqdn }}
DocumentRoot /srv/http/{{ item.fqdn }}
Alias /error/ "/var/www/error/"
{% if item.proxy is defined %}
ProxyPass "/.well-known" "!"
ProxyPass "/phpMyAdmin" "!"
ProxyPass "/phpmyadmin" "!"
ProxyPass "/" "{{ item.proxy }}"
ProxyPassReverse "/" "{{ item.proxy }}"
ProxyTimeout 300
{% endif %}
{% if item.rewrite is defined %}
RewriteEngine On
RewriteCond %{HTTP:Upgrade} websocket [NC]
RewriteCond %{HTTP:Connection} upgrade [NC]
RewriteRule ^/?(.*) ws://{{ item.proxy }}/$1 [P,L]
{% endif %}
{% if item.redirect is defined %}
RedirectMatch "^(?!/\.well-known/).*" {{ item.redirect }}
{% endif %}
<Location /.env>
Require all denied
</Location>
<Location /.git>
Require all denied
</Location>
</VirtualHost>
{% endfor %}
@@ -0,0 +1,20 @@
#
# This configuration file enables the default "Welcome" page if there
# is no default index page present for the root URL. To disable the
# Welcome page, comment out all the lines below.
#
# NOTE: if this file is removed, it will be restored on upgrades.
#
<LocationMatch "^/+$">
Options -Indexes
ErrorDocument 403 /.noindex.html
</LocationMatch>
<Directory /usr/share/httpd/noindex>
AllowOverride None
Require all granted
</Directory>
Alias /.noindex.html /usr/share/httpd/noindex/index.html
Alias /poweredby.png /usr/share/httpd/icons/apache_pb3.png
Alias /system_noindex_logo.png /usr/share/httpd/icons/system_noindex_logo.png
@@ -0,0 +1,69 @@
#
# This file loads most of the modules included with the Apache HTTP
# Server itself.
#
LoadModule access_compat_module modules/mod_access_compat.so
LoadModule actions_module modules/mod_actions.so
LoadModule alias_module modules/mod_alias.so
LoadModule allowmethods_module modules/mod_allowmethods.so
LoadModule auth_basic_module modules/mod_auth_basic.so
LoadModule auth_digest_module modules/mod_auth_digest.so
LoadModule authn_anon_module modules/mod_authn_anon.so
LoadModule authn_core_module modules/mod_authn_core.so
LoadModule authn_dbd_module modules/mod_authn_dbd.so
LoadModule authn_dbm_module modules/mod_authn_dbm.so
LoadModule authn_file_module modules/mod_authn_file.so
LoadModule authn_socache_module modules/mod_authn_socache.so
LoadModule authnz_fcgi_module modules/mod_authnz_fcgi.so
LoadModule authz_core_module modules/mod_authz_core.so
LoadModule authz_dbd_module modules/mod_authz_dbd.so
LoadModule authz_dbm_module modules/mod_authz_dbm.so
LoadModule authz_groupfile_module modules/mod_authz_groupfile.so
LoadModule authz_host_module modules/mod_authz_host.so
LoadModule authz_owner_module modules/mod_authz_owner.so
LoadModule authz_user_module modules/mod_authz_user.so
LoadModule autoindex_module modules/mod_autoindex.so
LoadModule cache_module modules/mod_cache.so
LoadModule cache_disk_module modules/mod_cache_disk.so
LoadModule cache_socache_module modules/mod_cache_socache.so
LoadModule data_module modules/mod_data.so
LoadModule dbd_module modules/mod_dbd.so
LoadModule deflate_module modules/mod_deflate.so
LoadModule dir_module modules/mod_dir.so
LoadModule dumpio_module modules/mod_dumpio.so
LoadModule echo_module modules/mod_echo.so
LoadModule env_module modules/mod_env.so
LoadModule expires_module modules/mod_expires.so
LoadModule ext_filter_module modules/mod_ext_filter.so
LoadModule filter_module modules/mod_filter.so
LoadModule headers_module modules/mod_headers.so
LoadModule include_module modules/mod_include.so
LoadModule info_module modules/mod_info.so
LoadModule log_config_module modules/mod_log_config.so
LoadModule logio_module modules/mod_logio.so
LoadModule macro_module modules/mod_macro.so
LoadModule mime_magic_module modules/mod_mime_magic.so
LoadModule mime_module modules/mod_mime.so
LoadModule negotiation_module modules/mod_negotiation.so
LoadModule remoteip_module modules/mod_remoteip.so
LoadModule reqtimeout_module modules/mod_reqtimeout.so
LoadModule request_module modules/mod_request.so
LoadModule rewrite_module modules/mod_rewrite.so
LoadModule setenvif_module modules/mod_setenvif.so
LoadModule slotmem_plain_module modules/mod_slotmem_plain.so
LoadModule slotmem_shm_module modules/mod_slotmem_shm.so
LoadModule socache_dbm_module modules/mod_socache_dbm.so
LoadModule socache_memcache_module modules/mod_socache_memcache.so
LoadModule socache_redis_module modules/mod_socache_redis.so
LoadModule socache_shmcb_module modules/mod_socache_shmcb.so
LoadModule status_module modules/mod_status.so
LoadModule substitute_module modules/mod_substitute.so
LoadModule suexec_module modules/mod_suexec.so
LoadModule unique_id_module modules/mod_unique_id.so
LoadModule unixd_module modules/mod_unixd.so
LoadModule userdir_module modules/mod_userdir.so
LoadModule version_module modules/mod_version.so
LoadModule vhost_alias_module modules/mod_vhost_alias.so
LoadModule watchdog_module modules/mod_watchdog.so
@@ -0,0 +1 @@
LoadModule brotli_module modules/mod_brotli.so
@@ -0,0 +1,3 @@
LoadModule dav_module modules/mod_dav.so
LoadModule dav_fs_module modules/mod_dav_fs.so
LoadModule dav_lock_module modules/mod_dav_lock.so
@@ -0,0 +1 @@
LoadModule lua_module modules/mod_lua.so
@@ -0,0 +1,23 @@
# Select the MPM module which should be used by uncommenting exactly
# one of the following LoadModule lines. See the httpd.conf(5) man
# page for more information on changing the MPM.
# prefork MPM: Implements a non-threaded, pre-forking web server
# See: http://httpd.apache.org/docs/2.4/mod/prefork.html
#
# NOTE: If enabling prefork, the httpd_graceful_shutdown SELinux
# boolean should be enabled, to allow graceful stop/shutdown.
#
#LoadModule mpm_prefork_module modules/mod_mpm_prefork.so
# worker MPM: Multi-Processing Module implementing a hybrid
# multi-threaded multi-process web server
# See: http://httpd.apache.org/docs/2.4/mod/worker.html
#
#LoadModule mpm_worker_module modules/mod_mpm_worker.so
# event MPM: A variant of the worker MPM with the goal of consuming
# threads only for connections with active processing
# See: http://httpd.apache.org/docs/2.4/mod/event.html
#
LoadModule mpm_event_module modules/mod_mpm_event.so
@@ -0,0 +1,18 @@
#
# This file lists modules included with the Apache HTTP Server
# which are not enabled by default.
#
#LoadModule asis_module modules/mod_asis.so
#LoadModule buffer_module modules/mod_buffer.so
#LoadModule heartbeat_module modules/mod_heartbeat.so
#LoadModule heartmonitor_module modules/mod_heartmonitor.so
#LoadModule usertrack_module modules/mod_usertrack.so
#LoadModule dialup_module modules/mod_dialup.so
#LoadModule charset_lite_module modules/mod_charset_lite.so
#LoadModule log_debug_module modules/mod_log_debug.so
#LoadModule log_forensic_module modules/mod_log_forensic.so
#LoadModule ratelimit_module modules/mod_ratelimit.so
#LoadModule reflector_module modules/mod_reflector.so
#LoadModule sed_module modules/mod_sed.so
#LoadModule speling_module modules/mod_speling.so
@@ -0,0 +1,18 @@
# This file configures all the proxy modules:
LoadModule proxy_module modules/mod_proxy.so
LoadModule lbmethod_bybusyness_module modules/mod_lbmethod_bybusyness.so
LoadModule lbmethod_byrequests_module modules/mod_lbmethod_byrequests.so
LoadModule lbmethod_bytraffic_module modules/mod_lbmethod_bytraffic.so
LoadModule lbmethod_heartbeat_module modules/mod_lbmethod_heartbeat.so
LoadModule proxy_ajp_module modules/mod_proxy_ajp.so
LoadModule proxy_balancer_module modules/mod_proxy_balancer.so
LoadModule proxy_connect_module modules/mod_proxy_connect.so
LoadModule proxy_express_module modules/mod_proxy_express.so
LoadModule proxy_fcgi_module modules/mod_proxy_fcgi.so
LoadModule proxy_fdpass_module modules/mod_proxy_fdpass.so
LoadModule proxy_ftp_module modules/mod_proxy_ftp.so
LoadModule proxy_http_module modules/mod_proxy_http.so
LoadModule proxy_hcheck_module modules/mod_proxy_hcheck.so
LoadModule proxy_scgi_module modules/mod_proxy_scgi.so
LoadModule proxy_uwsgi_module modules/mod_proxy_uwsgi.so
LoadModule proxy_wstunnel_module modules/mod_proxy_wstunnel.so
@@ -0,0 +1 @@
LoadModule ssl_module modules/mod_ssl.so
@@ -0,0 +1,2 @@
# This file configures systemd module:
LoadModule systemd_module modules/mod_systemd.so
@@ -0,0 +1,11 @@
# This configuration file loads a CGI module appropriate to the MPM
# which has been configured in 00-mpm.conf. mod_cgid should be used
# with a threaded MPM; mod_cgi with the prefork MPM.
<IfModule !mpm_prefork_module>
LoadModule cgid_module modules/mod_cgid.so
</IfModule>
<IfModule mpm_prefork_module>
LoadModule cgi_module modules/mod_cgi.so
</IfModule>
@@ -0,0 +1 @@
LoadModule md_module modules/mod_md.so
@@ -0,0 +1 @@
LoadModule http2_module modules/mod_http2.so
@@ -0,0 +1 @@
LoadModule proxy_http2_module modules/mod_proxy_http2.so
@@ -0,0 +1,10 @@
This directory holds configuration files for the Apache HTTP Server;
any files in this directory which have the ".conf" extension will be
processed as httpd configuration files. This directory contains
configuration fragments necessary only to load modules.
Administrators should use the directory "/etc/httpd/conf.d" to modify
the configuration of httpd, or any modules.
Files are processed in sorted order and should have a two digit
numeric prefix. See httpd.conf(5) for more information.
@@ -0,0 +1,374 @@
#
# This is the main Apache HTTP server configuration file. It contains the
# configuration directives that give the server its instructions.
# See <URL:http://httpd.apache.org/docs/2.4/> for detailed information.
# In particular, see
# <URL:http://httpd.apache.org/docs/2.4/mod/directives.html>
# for a discussion of each configuration directive.
#
# See the httpd.conf(5) man page for more information on this configuration,
# and httpd.service(8) on using and configuring the httpd service.
#
# Do NOT simply read the instructions in here without understanding
# what they do. They're here only as hints or reminders. If you are unsure
# consult the online docs. You have been warned.
#
# Configuration and logfile names: If the filenames you specify for many
# of the server's control files begin with "/" (or "drive:/" for Win32), the
# server will use that explicit path. If the filenames do *not* begin
# with "/", the value of ServerRoot is prepended -- so 'log/access_log'
# with ServerRoot set to '/www' will be interpreted by the
# server as '/www/log/access_log', where as '/log/access_log' will be
# interpreted as '/log/access_log'.
#
# ServerRoot: The top of the directory tree under which the server's
# configuration, error, and log files are kept.
#
# Do not add a slash at the end of the directory path. If you point
# ServerRoot at a non-local disk, be sure to specify a local disk on the
# Mutex directive, if file-based mutexes are used. If you wish to share the
# same ServerRoot for multiple httpd daemons, you will need to change at
# least PidFile.
#
ServerRoot "/etc/httpd"
#
# Listen: Allows you to bind Apache to specific IP addresses and/or
# ports, instead of the default. See also the <VirtualHost>
# directive.
#
# Change this to Listen on a specific IP address, but note that if
# httpd.service is enabled to run at boot time, the address may not be
# available when the service starts. See the httpd.service(8) man
# page for more information.
#
#Listen 12.34.56.78:80
Listen 80
#
# Dynamic Shared Object (DSO) Support
#
# To be able to use the functionality of a module which was built as a DSO you
# have to place corresponding `LoadModule' lines at this location so the
# directives contained in it are actually available _before_ they are used.
# Statically compiled modules (those listed by `httpd -l') do not need
# to be loaded here.
#
# Example:
# LoadModule foo_module modules/mod_foo.so
#
Include conf.modules.d/*.conf
#
# If you wish httpd to run as a different user or group, you must run
# httpd as root initially and it will switch.
#
# User/Group: The name (or #number) of the user/group to run httpd as.
# It is usually good practice to create a dedicated user and group for
# running httpd, as with most system services.
#
User apache
Group apache
# 'Main' server configuration
#
# The directives in this section set up the values used by the 'main'
# server, which responds to any requests that aren't handled by a
# <VirtualHost> definition. These values also provide defaults for
# any <VirtualHost> containers you may define later in the file.
#
# All of these directives may appear inside <VirtualHost> containers,
# in which case these default settings will be overridden for the
# virtual host being defined.
#
#
# ServerAdmin: Your address, where problems with the server should be
# e-mailed. This address appears on some server-generated pages, such
# as error documents. e.g. admin@your-domain.com
#
ServerAdmin root@localhost
#
# ServerName gives the name and port that the server uses to identify itself.
# This can often be determined automatically, but we recommend you specify
# it explicitly to prevent problems during startup.
#
# If your host doesn't have a registered DNS name, enter its IP address here.
#
#ServerName www.example.com:80
#
# Deny access to the entirety of your server's filesystem. You must
# explicitly permit access to web content directories in other
# <Directory> blocks below.
#
<Directory />
AllowOverride none
Require all denied
</Directory>
#
# Note that from this point forward you must specifically allow
# particular features to be enabled - so if something's not working as
# you might expect, make sure that you have specifically enabled it
# below.
#
#
# DocumentRoot: The directory out of which you will serve your
# documents. By default, all requests are taken from this directory, but
# symbolic links and aliases may be used to point to other locations.
#
DocumentRoot "/var/www/html"
#
# Relax access to content within /var/www.
#
<Directory "/var/www">
AllowOverride None
# Allow open access:
Require all granted
</Directory>
# Further relax access to the default document root:
<Directory "/var/www/html">
#
# Possible values for the Options directive are "None", "All",
# or any combination of:
# Indexes Includes FollowSymLinks SymLinksifOwnerMatch ExecCGI MultiViews
#
# Note that "MultiViews" must be named *explicitly* --- "Options All"
# doesn't give it to you.
#
# The Options directive is both complicated and important. Please see
# http://httpd.apache.org/docs/2.4/mod/core.html#options
# for more information.
#
Options Indexes FollowSymLinks
#
# AllowOverride controls what directives may be placed in .htaccess files.
# It can be "All", "None", or any combination of the keywords:
# AllowOverride FileInfo AuthConfig Limit
#
AllowOverride None
#
# Controls who can get stuff from this server.
#
Require all granted
</Directory>
#
# DirectoryIndex: sets the file that Apache will serve if a directory
# is requested.
#
<IfModule dir_module>
DirectoryIndex index.html
</IfModule>
#
# The following lines prevent .htaccess and .htpasswd files from being
# viewed by Web clients.
#
<Files ".ht*">
Require all denied
</Files>
#
# ErrorLog: The location of the error log file.
# If you do not specify an ErrorLog directive within a <VirtualHost>
# container, error messages relating to that virtual host will be
# logged here. If you *do* define an error logfile for a <VirtualHost>
# container, that host's errors will be logged there and not here.
#
ErrorLog "logs/error_log"
#
# LogLevel: Control the number of messages logged to the error_log.
# Possible values include: debug, info, notice, warn, error, crit,
# alert, emerg.
#
LogLevel warn
<IfModule log_config_module>
#
# The following directives define some format nicknames for use with
# a CustomLog directive (see below).
#
LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
LogFormat "%h %l %u %t \"%r\" %>s %b" common
<IfModule logio_module>
# You need to enable mod_logio.c to use %I and %O
LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" %I %O" combinedio
</IfModule>
#
# The location and format of the access logfile (Common Logfile Format).
# If you do not define any access logfiles within a <VirtualHost>
# container, they will be logged here. Contrariwise, if you *do*
# define per-<VirtualHost> access logfiles, transactions will be
# logged therein and *not* in this file.
#
#CustomLog "logs/access_log" common
#
# If you prefer a logfile with access, agent, and referer information
# (Combined Logfile Format) you can use the following directive.
#
CustomLog "logs/access_log" combined
</IfModule>
<IfModule alias_module>
#
# Redirect: Allows you to tell clients about documents that used to
# exist in your server's namespace, but do not anymore. The client
# will make a new request for the document at its new location.
# Example:
# Redirect permanent /foo http://www.example.com/bar
#
# Alias: Maps web paths into filesystem paths and is used to
# access content that does not live under the DocumentRoot.
# Example:
# Alias /webpath /full/filesystem/path
#
# If you include a trailing / on /webpath then the server will
# require it to be present in the URL. You will also likely
# need to provide a <Directory> section to allow access to
# the filesystem path.
#
# ScriptAlias: This controls which directories contain server scripts.
# ScriptAliases are essentially the same as Aliases, except that
# documents in the target directory are treated as applications and
# run by the server when requested rather than as documents sent to the
# client. The same rules about trailing "/" apply to ScriptAlias
# directives as to Alias.
#
ScriptAlias /cgi-bin/ "/var/www/cgi-bin/"
</IfModule>
#
# "/var/www/cgi-bin" should be changed to whatever your ScriptAliased
# CGI directory exists, if you have that configured.
#
<Directory "/var/www/cgi-bin">
AllowOverride None
Options None
Require all granted
</Directory>
<IfModule headers_module>
#
# Avoid passing HTTP_PROXY environment to CGI's on this or any proxied
# backend servers which have lingering "httpoxy" defects.
# 'Proxy' request header is undefined by the IETF, not listed by IANA
#
RequestHeader unset Proxy early
</IfModule>
<IfModule mime_module>
#
# TypesConfig points to the file containing the list of mappings from
# filename extension to MIME-type.
#
TypesConfig /etc/mime.types
#
# AddType allows you to add to or override the MIME configuration
# file specified in TypesConfig for specific file types.
#
#AddType application/x-gzip .tgz
#
# AddEncoding allows you to have certain browsers uncompress
# information on the fly. Note: Not all browsers support this.
#
#AddEncoding x-compress .Z
#AddEncoding x-gzip .gz .tgz
#
# If the AddEncoding directives above are commented-out, then you
# probably should define those extensions to indicate media types:
#
AddType application/x-compress .Z
AddType application/x-gzip .gz .tgz
#
# AddHandler allows you to map certain file extensions to "handlers":
# actions unrelated to filetype. These can be either built into the server
# or added with the Action directive (see below)
#
# To use CGI scripts outside of ScriptAliased directories:
# (You will also need to add "ExecCGI" to the "Options" directive.)
#
#AddHandler cgi-script .cgi
# For type maps (negotiated resources):
#AddHandler type-map var
#
# Filters allow you to process content before it is sent to the client.
#
# To parse .shtml files for server-side includes (SSI):
# (You will also need to add "Includes" to the "Options" directive.)
#
AddType text/html .shtml
AddOutputFilter INCLUDES .shtml
</IfModule>
#
# Specify a default charset for all content served; this enables
# interpretation of all content as UTF-8 by default. To use the
# default browser choice (ISO-8859-1), or to allow the META tags
# in HTML content to override this choice, comment out this
# directive:
#
AddDefaultCharset UTF-8
<IfModule mime_magic_module>
#
# The mod_mime_magic module allows the server to use various hints from the
# contents of the file itself to determine its type. The MIMEMagicFile
# directive tells the module where the hint definitions are located.
#
MIMEMagicFile conf/magic
</IfModule>
#
# Customizable error responses come in three flavors:
# 1) plain text 2) local redirects 3) external redirects
#
# Some examples:
#ErrorDocument 500 "The server made a boo boo."
#ErrorDocument 404 /missing.html
#ErrorDocument 404 "/cgi-bin/missing_handler.pl"
#ErrorDocument 402 http://www.example.com/subscription_info.html
#
#
# MaxRanges: Maximum number of Ranges in a request before
# returning the entire resource, or one of the special
# values 'default', 'none' or 'unlimited'.
# Default setting is to accept 200 Ranges.
#MaxRanges unlimited
#
# EnableMMAP and EnableSendfile: On systems that support it,
# memory-mapping or the sendfile syscall may be used to deliver
# files. This usually improves server performance, but must
# be turned off when serving from networked-mounted
# filesystems or if support for these functions is otherwise
# broken on your system.
# Defaults if commented: EnableMMAP On, EnableSendfile Off
#
#EnableMMAP off
EnableSendfile on
# Supplemental configuration
#
# Load config files in the "/etc/httpd/conf.d" directory, if any.
IncludeOptional conf.d/*.conf
@@ -0,0 +1,397 @@
# Magic data for mod_mime_magic Apache module (originally for file(1) command)
# The module is described in /manual/mod/mod_mime_magic.html
#
# The format is 4-5 columns:
# Column #1: byte number to begin checking from, ">" indicates continuation
# Column #2: type of data to match
# Column #3: contents of data to match
# Column #4: MIME type of result
# Column #5: MIME encoding of result (optional)
#------------------------------------------------------------------------------
# Localstuff: file(1) magic for locally observed files
# Add any locally observed files here.
#------------------------------------------------------------------------------
# end local stuff
#------------------------------------------------------------------------------
#------------------------------------------------------------------------------
# Java
0 short 0xcafe
>2 short 0xbabe application/java
#------------------------------------------------------------------------------
# audio: file(1) magic for sound formats
#
# from Jan Nicolai Langfeldt <janl@ifi.uio.no>,
#
# Sun/NeXT audio data
0 string .snd
>12 belong 1 audio/basic
>12 belong 2 audio/basic
>12 belong 3 audio/basic
>12 belong 4 audio/basic
>12 belong 5 audio/basic
>12 belong 6 audio/basic
>12 belong 7 audio/basic
>12 belong 23 audio/x-adpcm
# DEC systems (e.g. DECstation 5000) use a variant of the Sun/NeXT format
# that uses little-endian encoding and has a different magic number
# (0x0064732E in little-endian encoding).
0 lelong 0x0064732E
>12 lelong 1 audio/x-dec-basic
>12 lelong 2 audio/x-dec-basic
>12 lelong 3 audio/x-dec-basic
>12 lelong 4 audio/x-dec-basic
>12 lelong 5 audio/x-dec-basic
>12 lelong 6 audio/x-dec-basic
>12 lelong 7 audio/x-dec-basic
# compressed (G.721 ADPCM)
>12 lelong 23 audio/x-dec-adpcm
# Bytes 0-3 of AIFF, AIFF-C, & 8SVX audio files are "FORM"
# AIFF audio data
8 string AIFF audio/x-aiff
# AIFF-C audio data
8 string AIFC audio/x-aiff
# IFF/8SVX audio data
8 string 8SVX audio/x-aiff
# Creative Labs AUDIO stuff
# Standard MIDI data
0 string MThd audio/unknown
#>9 byte >0 (format %d)
#>11 byte >1 using %d channels
# Creative Music (CMF) data
0 string CTMF audio/unknown
# SoundBlaster instrument data
0 string SBI audio/unknown
# Creative Labs voice data
0 string Creative\ Voice\ File audio/unknown
## is this next line right? it came this way...
#>19 byte 0x1A
#>23 byte >0 - version %d
#>22 byte >0 \b.%d
# [GRR 950115: is this also Creative Labs? Guessing that first line
# should be string instead of unknown-endian long...]
#0 long 0x4e54524b MultiTrack sound data
#0 string NTRK MultiTrack sound data
#>4 long x - version %ld
# Microsoft WAVE format (*.wav)
# [GRR 950115: probably all of the shorts and longs should be leshort/lelong]
# Microsoft RIFF
0 string RIFF
# - WAVE format
>8 string WAVE audio/x-wav
# MPEG audio.
0 beshort&0xfff0 0xfff0 audio/mpeg
# C64 SID Music files, from Linus Walleij <triad@df.lth.se>
0 string PSID audio/prs.sid
#------------------------------------------------------------------------------
# c-lang: file(1) magic for C programs or various scripts
#
# XPM icons (Greg Roelofs, newt@uchicago.edu)
# ideally should go into "images", but entries below would tag XPM as C source
0 string /*\ XPM image/x-xbm 7bit
# this first will upset you if you're a PL/1 shop... (are there any left?)
# in which case rm it; ascmagic will catch real C programs
# C or REXX program text
0 string /* text/plain
# C++ program text
0 string // text/plain
#------------------------------------------------------------------------------
# compress: file(1) magic for pure-compression formats (no archives)
#
# compress, gzip, pack, compact, huf, squeeze, crunch, freeze, yabba, whap, etc.
#
# Formats for various forms of compressed data
# Formats for "compress" proper have been moved into "compress.c",
# because it tries to uncompress it to figure out what's inside.
# standard unix compress
0 string \037\235 application/octet-stream x-compress
# gzip (GNU zip, not to be confused with [Info-ZIP/PKWARE] zip archiver)
0 string \037\213 application/octet-stream x-gzip
# According to gzip.h, this is the correct byte order for packed data.
0 string \037\036 application/octet-stream
#
# This magic number is byte-order-independent.
#
0 short 017437 application/octet-stream
# XXX - why *two* entries for "compacted data", one of which is
# byte-order independent, and one of which is byte-order dependent?
#
# compacted data
0 short 0x1fff application/octet-stream
0 string \377\037 application/octet-stream
# huf output
0 short 0145405 application/octet-stream
# Squeeze and Crunch...
# These numbers were gleaned from the Unix versions of the programs to
# handle these formats. Note that I can only uncrunch, not crunch, and
# I didn't have a crunched file handy, so the crunch number is untested.
# Keith Waclena <keith@cerberus.uchicago.edu>
#0 leshort 0x76FF squeezed data (CP/M, DOS)
#0 leshort 0x76FE crunched data (CP/M, DOS)
# Freeze
#0 string \037\237 Frozen file 2.1
#0 string \037\236 Frozen file 1.0 (or gzip 0.5)
# lzh?
#0 string \037\240 LZH compressed data
#------------------------------------------------------------------------------
# frame: file(1) magic for FrameMaker files
#
# This stuff came on a FrameMaker demo tape, most of which is
# copyright, but this file is "published" as witness the following:
#
0 string \<MakerFile application/x-frame
0 string \<MIFFile application/x-frame
0 string \<MakerDictionary application/x-frame
0 string \<MakerScreenFon application/x-frame
0 string \<MML application/x-frame
0 string \<Book application/x-frame
0 string \<Maker application/x-frame
#------------------------------------------------------------------------------
# html: file(1) magic for HTML (HyperText Markup Language) docs
#
# from Daniel Quinlan <quinlan@yggdrasil.com>
# and Anna Shergold <anna@inext.co.uk>
#
0 string \<!DOCTYPE\ HTML text/html
0 string \<!doctype\ html text/html
0 string \<HEAD text/html
0 string \<head text/html
0 string \<TITLE text/html
0 string \<title text/html
0 string \<html text/html
0 string \<HTML text/html
0 string \<!-- text/html
0 string \<h1 text/html
0 string \<H1 text/html
# XML eXtensible Markup Language, from Linus Walleij <triad@df.lth.se>
0 string \<?xml text/xml
#------------------------------------------------------------------------------
# images: file(1) magic for image formats (see also "c-lang" for XPM bitmaps)
#
# originally from jef@helios.ee.lbl.gov (Jef Poskanzer),
# additions by janl@ifi.uio.no as well as others. Jan also suggested
# merging several one- and two-line files into here.
#
# XXX - byte order for GIF and TIFF fields?
# [GRR: TIFF allows both byte orders; GIF is probably little-endian]
#
# [GRR: what the hell is this doing in here?]
#0 string xbtoa btoa'd file
# PBMPLUS
# PBM file
0 string P1 image/x-portable-bitmap 7bit
# PGM file
0 string P2 image/x-portable-greymap 7bit
# PPM file
0 string P3 image/x-portable-pixmap 7bit
# PBM "rawbits" file
0 string P4 image/x-portable-bitmap
# PGM "rawbits" file
0 string P5 image/x-portable-greymap
# PPM "rawbits" file
0 string P6 image/x-portable-pixmap
# NIFF (Navy Interchange File Format, a modification of TIFF)
# [GRR: this *must* go before TIFF]
0 string IIN1 image/x-niff
# TIFF and friends
# TIFF file, big-endian
0 string MM image/tiff
# TIFF file, little-endian
0 string II image/tiff
# possible GIF replacements; none yet released!
# (Greg Roelofs, newt@uchicago.edu)
#
# GRR 950115: this was mine ("Zip GIF"):
# ZIF image (GIF+deflate alpha)
0 string GIF94z image/unknown
#
# GRR 950115: this is Jeremy Wohl's Free Graphics Format (better):
# FGF image (GIF+deflate beta)
0 string FGF95a image/unknown
#
# GRR 950115: this is Thomas Boutell's Portable Bitmap Format proposal
# (best; not yet implemented):
# PBF image (deflate compression)
0 string PBF image/unknown
# GIF
0 string GIF image/gif
# JPEG images
0 beshort 0xffd8 image/jpeg
# PC bitmaps (OS/2, Windoze BMP files) (Greg Roelofs, newt@uchicago.edu)
0 string BM image/bmp
#>14 byte 12 (OS/2 1.x format)
#>14 byte 64 (OS/2 2.x format)
#>14 byte 40 (Windows 3.x format)
#0 string IC icon
#0 string PI pointer
#0 string CI color icon
#0 string CP color pointer
#0 string BA bitmap array
0 string \x89PNG image/png
0 string FWS application/x-shockwave-flash
0 string CWS application/x-shockwave-flash
#------------------------------------------------------------------------------
# lisp: file(1) magic for lisp programs
#
# various lisp types, from Daniel Quinlan (quinlan@yggdrasil.com)
0 string ;; text/plain 8bit
# Emacs 18 - this is always correct, but not very magical.
0 string \012( application/x-elc
# Emacs 19
0 string ;ELC\023\000\000\000 application/x-elc
#------------------------------------------------------------------------------
# mail.news: file(1) magic for mail and news
#
# There are tests to ascmagic.c to cope with mail and news.
0 string Relay-Version: message/rfc822 7bit
0 string #!\ rnews message/rfc822 7bit
0 string N#!\ rnews message/rfc822 7bit
0 string Forward\ to message/rfc822 7bit
0 string Pipe\ to message/rfc822 7bit
0 string Return-Path: message/rfc822 7bit
0 string Path: message/news 8bit
0 string Xref: message/news 8bit
0 string From: message/rfc822 7bit
0 string Article message/news 8bit
#------------------------------------------------------------------------------
# msword: file(1) magic for MS Word files
#
# Contributor claims:
# Reversed-engineered MS Word magic numbers
#
0 string \376\067\0\043 application/msword
0 string \333\245-\0\0\0 application/msword
# disable this one because it applies also to other
# Office/OLE documents for which msword is not correct. See PR#2608.
#0 string \320\317\021\340\241\261 application/msword
#------------------------------------------------------------------------------
# printer: file(1) magic for printer-formatted files
#
# PostScript
0 string %! application/postscript
0 string \004%! application/postscript
# Acrobat
# (due to clamen@cs.cmu.edu)
0 string %PDF- application/pdf
#------------------------------------------------------------------------------
# sc: file(1) magic for "sc" spreadsheet
#
38 string Spreadsheet application/x-sc
#------------------------------------------------------------------------------
# tex: file(1) magic for TeX files
#
# XXX - needs byte-endian stuff (big-endian and little-endian DVI?)
#
# From <conklin@talisman.kaleida.com>
# Although we may know the offset of certain text fields in TeX DVI
# and font files, we can't use them reliably because they are not
# zero terminated. [but we do anyway, christos]
0 string \367\002 application/x-dvi
#0 string \367\203 TeX generic font data
#0 string \367\131 TeX packed font data
#0 string \367\312 TeX virtual font data
#0 string This\ is\ TeX, TeX transcript text
#0 string This\ is\ METAFONT, METAFONT transcript text
# There is no way to detect TeX Font Metric (*.tfm) files without
# breaking them apart and reading the data. The following patterns
# match most *.tfm files generated by METAFONT or afm2tfm.
#2 string \000\021 TeX font metric data
#2 string \000\022 TeX font metric data
#>34 string >\0 (%s)
# Texinfo and GNU Info, from Daniel Quinlan (quinlan@yggdrasil.com)
#0 string \\input\ texinfo Texinfo source text
#0 string This\ is\ Info\ file GNU Info text
# correct TeX magic for Linux (and maybe more)
# from Peter Tobias (tobias@server.et-inf.fho-emden.de)
#
0 leshort 0x02f7 application/x-dvi
# RTF - Rich Text Format
0 string {\\rtf application/rtf
#------------------------------------------------------------------------------
# animation: file(1) magic for animation/movie formats
#
# animation formats, originally from vax@ccwf.cc.utexas.edu (VaX#n8)
# MPEG file
0 string \000\000\001\263 video/mpeg
#
# The contributor claims:
# I couldn't find a real magic number for these, however, this
# -appears- to work. Note that it might catch other files, too,
# so BE CAREFUL!
#
# Note that title and author appear in the two 20-byte chunks
# at decimal offsets 2 and 22, respectively, but they are XOR'ed with
# 255 (hex FF)! DL format SUCKS BIG ROCKS.
#
# DL file version 1 , medium format (160x100, 4 images/screen)
0 byte 1 video/unknown
0 byte 2 video/unknown
# Quicktime video, from Linus Walleij <triad@df.lth.se>
# from Apple quicktime file format documentation.
4 string moov video/quicktime
4 string mdat video/quicktime
#------------------------------------------------------------------------------
# application/x-coredump for LE/BE ELF
#
0 string \177ELF
>5 byte 1
>16 leshort 4 application/x-coredump
0 string \177ELF
>5 byte 2
>16 beshort 4 application/x-coredump
@@ -0,0 +1,11 @@
# Note that logs are not compressed unless "compress" is configured,
# which can be done either here or globally in /etc/logrotate.conf.
/var/log/httpd/*log {
missingok
notifempty
sharedscripts
delaycompress
postrotate
/bin/systemctl reload httpd.service > /dev/null 2>/dev/null || true
endscript
}
@@ -0,0 +1,9 @@
/var/log/php-fpm/*log {
missingok
notifempty
sharedscripts
delaycompress
postrotate
/bin/kill -SIGUSR1 `cat /run/php-fpm/php-fpm.pid 2>/dev/null` 2>/dev/null || true
endscript
}
@@ -0,0 +1,135 @@
;;;;;;;;;;;;;;;;;;;;;
; FPM Configuration ;
;;;;;;;;;;;;;;;;;;;;;
; All relative paths in this configuration file are relative to PHP's install
; prefix.
;;;;;;;;;;;;;;;;;;
; Global Options ;
;;;;;;;;;;;;;;;;;;
[global]
; Pid file
; Default Value: none
pid = /run/php-fpm/php-fpm.pid
; Error log file
; If it's set to "syslog", log is sent to syslogd instead of being written
; in a local file.
; Default Value: /var/log/php-fpm.log
error_log = /var/log/php-fpm/error.log
; syslog_facility is used to specify what type of program is logging the
; message. This lets syslogd specify that messages from different facilities
; will be handled differently.
; See syslog(3) for possible values (ex daemon equiv LOG_DAEMON)
; Default Value: daemon
;syslog.facility = daemon
; syslog_ident is prepended to every message. If you have multiple FPM
; instances running on the same server, you can change the default value
; which must suit common needs.
; Default Value: php-fpm
;syslog.ident = php-fpm
; Log level
; Possible Values: alert, error, warning, notice, debug
; Default Value: notice
;log_level = notice
; Log limit on number of characters in the single line (log entry). If the
; line is over the limit, it is wrapped on multiple lines. The limit is for
; all logged characters including message prefix and suffix if present. However
; the new line character does not count into it as it is present only when
; logging to a file descriptor. It means the new line character is not present
; when logging to syslog.
; Default Value: 1024
;log_limit = 4096
; Log buffering specifies if the log line is buffered which means that the
; line is written in a single write operation. If the value is false, then the
; data is written directly into the file descriptor. It is an experimental
; option that can potentionaly improve logging performance and memory usage
; for some heavy logging scenarios. This option is ignored if logging to syslog
; as it has to be always buffered.
; Default value: yes
;log_buffering = no
; If this number of child processes exit with SIGSEGV or SIGBUS within the time
; interval set by emergency_restart_interval then FPM will restart. A value
; of '0' means 'Off'.
; Default Value: 0
;emergency_restart_threshold = 0
; Interval of time used by emergency_restart_interval to determine when
; a graceful restart will be initiated. This can be useful to work around
; accidental corruptions in an accelerator's shared memory.
; Available Units: s(econds), m(inutes), h(ours), or d(ays)
; Default Unit: seconds
; Default Value: 0
;emergency_restart_interval = 0
; Time limit for child processes to wait for a reaction on signals from master.
; Available units: s(econds), m(inutes), h(ours), or d(ays)
; Default Unit: seconds
; Default Value: 0
;process_control_timeout = 0
; The maximum number of processes FPM will fork. This has been designed to control
; the global number of processes when using dynamic PM within a lot of pools.
; Use it with caution.
; Note: A value of 0 indicates no limit
; Default Value: 0
;process.max = 128
; Specify the nice(2) priority to apply to the master process (only if set)
; The value can vary from -19 (highest priority) to 20 (lowest priority)
; Note: - It will only work if the FPM master process is launched as root
; - The pool process will inherit the master process priority
; unless specified otherwise
; Default Value: no set
;process.priority = -19
; Send FPM to background. Set to 'no' to keep FPM in foreground for debugging.
; Default Value: yes
daemonize = yes
; Set open file descriptor rlimit for the master process.
; Default Value: system defined value
;rlimit_files = 1024
; Set max core size rlimit for the master process.
; Possible Values: 'unlimited' or an integer greater or equal to 0
; Default Value: system defined value
;rlimit_core = 0
; Specify the event mechanism FPM will use. The following is available:
; - select (any POSIX os)
; - poll (any POSIX os)
; - epoll (linux >= 2.5.44)
; Default Value: not set (auto detection)
;events.mechanism = epoll
; When FPM is built with systemd integration, specify the interval,
; in seconds, between health report notification to systemd.
; Set to 0 to disable.
; Available Units: s(econds), m(inutes), h(ours)
; Default Unit: seconds
; Default value: 10
;systemd_interval = 10
;;;;;;;;;;;;;;;;;;;;
; Pool Definitions ;
;;;;;;;;;;;;;;;;;;;;
; Multiple pools of child processes may be started with different listening
; ports and different management options. The name of the pool will be
; used in logs and stats. There is no limitation on the number of pools which
; FPM can handle. Your system will tell you anyway :)
; Include one or more files. If glob(3) exists, it is used to include a bunch of
; files from a glob(3) pattern. This directive can be used everywhere in the
; file.
include=/etc/php-fpm.d/*.conf
@@ -0,0 +1,438 @@
; Start a new pool named 'www'.
; the variable $pool can be used in any directive and will be replaced by the
; pool name ('www' here)
[www]
; Per pool prefix
; It only applies on the following directives:
; - 'access.log'
; - 'slowlog'
; - 'listen' (unixsocket)
; - 'chroot'
; - 'chdir'
; - 'php_values'
; - 'php_admin_values'
; When not set, the global prefix (or @php_fpm_prefix@) applies instead.
; Note: This directive can also be relative to the global prefix.
; Default Value: none
;prefix = /path/to/pools/$pool
; Unix user/group of processes
; Note: The user is mandatory. If the group is not set, the default user's group
; will be used.
; RPM: apache user chosen to provide access to the same directories as httpd
user = apache
; RPM: Keep a group allowed to write in log dir.
group = apache
; The address on which to accept FastCGI requests.
; Valid syntaxes are:
; 'ip.add.re.ss:port' - to listen on a TCP socket to a specific IPv4 address on
; a specific port;
; '[ip:6:addr:ess]:port' - to listen on a TCP socket to a specific IPv6 address on
; a specific port;
; 'port' - to listen on a TCP socket to all addresses
; (IPv6 and IPv4-mapped) on a specific port;
; '/path/to/unix/socket' - to listen on a unix socket.
; Note: This value is mandatory.
listen = /run/php-fpm/www.sock
; Set listen(2) backlog.
; Default Value: 511
;listen.backlog = 511
; Set permissions for unix socket, if one is used. In Linux, read/write
; permissions must be set in order to allow connections from a web server.
; Default Values: user and group are set as the running user
; mode is set to 0660
;listen.owner = nobody
;listen.group = nobody
;listen.mode = 0660
; When POSIX Access Control Lists are supported you can set them using
; these options, value is a comma separated list of user/group names.
; When set, listen.owner and listen.group are ignored
listen.acl_users = apache,nginx
;listen.acl_groups =
; List of addresses (IPv4/IPv6) of FastCGI clients which are allowed to connect.
; Equivalent to the FCGI_WEB_SERVER_ADDRS environment variable in the original
; PHP FCGI (5.2.2+). Makes sense only with a tcp listening socket. Each address
; must be separated by a comma. If this value is left blank, connections will be
; accepted from any ip address.
; Default Value: any
listen.allowed_clients = 127.0.0.1
; Specify the nice(2) priority to apply to the pool processes (only if set)
; The value can vary from -19 (highest priority) to 20 (lower priority)
; Note: - It will only work if the FPM master process is launched as root
; - The pool processes will inherit the master process priority
; unless it specified otherwise
; Default Value: no set
; process.priority = -19
; Set the process dumpable flag (PR_SET_DUMPABLE prctl) even if the process user
; or group is differrent than the master process user. It allows to create process
; core dump and ptrace the process for the pool user.
; Default Value: no
; process.dumpable = yes
; Choose how the process manager will control the number of child processes.
; Possible Values:
; static - a fixed number (pm.max_children) of child processes;
; dynamic - the number of child processes are set dynamically based on the
; following directives. With this process management, there will be
; always at least 1 children.
; pm.max_children - the maximum number of children that can
; be alive at the same time.
; pm.start_servers - the number of children created on startup.
; pm.min_spare_servers - the minimum number of children in 'idle'
; state (waiting to process). If the number
; of 'idle' processes is less than this
; number then some children will be created.
; pm.max_spare_servers - the maximum number of children in 'idle'
; state (waiting to process). If the number
; of 'idle' processes is greater than this
; number then some children will be killed.
; ondemand - no children are created at startup. Children will be forked when
; new requests will connect. The following parameter are used:
; pm.max_children - the maximum number of children that
; can be alive at the same time.
; pm.process_idle_timeout - The number of seconds after which
; an idle process will be killed.
; Note: This value is mandatory.
pm = dynamic
; The number of child processes to be created when pm is set to 'static' and the
; maximum number of child processes when pm is set to 'dynamic' or 'ondemand'.
; This value sets the limit on the number of simultaneous requests that will be
; served. Equivalent to the ApacheMaxClients directive with mpm_prefork.
; Equivalent to the PHP_FCGI_CHILDREN environment variable in the original PHP
; CGI. The below defaults are based on a server without much resources. Don't
; forget to tweak pm.* to fit your needs.
; Note: Used when pm is set to 'static', 'dynamic' or 'ondemand'
; Note: This value is mandatory.
pm.max_children = 50
; The number of child processes created on startup.
; Note: Used only when pm is set to 'dynamic'
; Default Value: min_spare_servers + (max_spare_servers - min_spare_servers) / 2
pm.start_servers = 5
; The desired minimum number of idle server processes.
; Note: Used only when pm is set to 'dynamic'
; Note: Mandatory when pm is set to 'dynamic'
pm.min_spare_servers = 5
; The desired maximum number of idle server processes.
; Note: Used only when pm is set to 'dynamic'
; Note: Mandatory when pm is set to 'dynamic'
pm.max_spare_servers = 35
; The number of seconds after which an idle process will be killed.
; Note: Used only when pm is set to 'ondemand'
; Default Value: 10s
;pm.process_idle_timeout = 10s;
; The number of requests each child process should execute before respawning.
; This can be useful to work around memory leaks in 3rd party libraries. For
; endless request processing specify '0'. Equivalent to PHP_FCGI_MAX_REQUESTS.
; Default Value: 0
;pm.max_requests = 500
; The URI to view the FPM status page. If this value is not set, no URI will be
; recognized as a status page. It shows the following informations:
; pool - the name of the pool;
; process manager - static, dynamic or ondemand;
; start time - the date and time FPM has started;
; start since - number of seconds since FPM has started;
; accepted conn - the number of request accepted by the pool;
; listen queue - the number of request in the queue of pending
; connections (see backlog in listen(2));
; max listen queue - the maximum number of requests in the queue
; of pending connections since FPM has started;
; listen queue len - the size of the socket queue of pending connections;
; idle processes - the number of idle processes;
; active processes - the number of active processes;
; total processes - the number of idle + active processes;
; max active processes - the maximum number of active processes since FPM
; has started;
; max children reached - number of times, the process limit has been reached,
; when pm tries to start more children (works only for
; pm 'dynamic' and 'ondemand');
; Value are updated in real time.
; Example output:
; pool: www
; process manager: static
; start time: 01/Jul/2011:17:53:49 +0200
; start since: 62636
; accepted conn: 190460
; listen queue: 0
; max listen queue: 1
; listen queue len: 42
; idle processes: 4
; active processes: 11
; total processes: 15
; max active processes: 12
; max children reached: 0
;
; By default the status page output is formatted as text/plain. Passing either
; 'html', 'xml' or 'json' in the query string will return the corresponding
; output syntax. Example:
; http://www.foo.bar/status
; http://www.foo.bar/status?json
; http://www.foo.bar/status?html
; http://www.foo.bar/status?xml
;
; By default the status page only outputs short status. Passing 'full' in the
; query string will also return status for each pool process.
; Example:
; http://www.foo.bar/status?full
; http://www.foo.bar/status?json&full
; http://www.foo.bar/status?html&full
; http://www.foo.bar/status?xml&full
; The Full status returns for each process:
; pid - the PID of the process;
; state - the state of the process (Idle, Running, ...);
; start time - the date and time the process has started;
; start since - the number of seconds since the process has started;
; requests - the number of requests the process has served;
; request duration - the duration in µs of the requests;
; request method - the request method (GET, POST, ...);
; request URI - the request URI with the query string;
; content length - the content length of the request (only with POST);
; user - the user (PHP_AUTH_USER) (or '-' if not set);
; script - the main script called (or '-' if not set);
; last request cpu - the %cpu the last request consumed
; it's always 0 if the process is not in Idle state
; because CPU calculation is done when the request
; processing has terminated;
; last request memory - the max amount of memory the last request consumed
; it's always 0 if the process is not in Idle state
; because memory calculation is done when the request
; processing has terminated;
; If the process is in Idle state, then informations are related to the
; last request the process has served. Otherwise informations are related to
; the current request being served.
; Example output:
; ************************
; pid: 31330
; state: Running
; start time: 01/Jul/2011:17:53:49 +0200
; start since: 63087
; requests: 12808
; request duration: 1250261
; request method: GET
; request URI: /test_mem.php?N=10000
; content length: 0
; user: -
; script: /home/fat/web/docs/php/test_mem.php
; last request cpu: 0.00
; last request memory: 0
;
; Note: There is a real-time FPM status monitoring sample web page available
; It's available in: @EXPANDED_DATADIR@/fpm/status.html
;
; Note: The value must start with a leading slash (/). The value can be
; anything, but it may not be a good idea to use the .php extension or it
; may conflict with a real PHP file.
; Default Value: not set
;pm.status_path = /status
; The ping URI to call the monitoring page of FPM. If this value is not set, no
; URI will be recognized as a ping page. This could be used to test from outside
; that FPM is alive and responding, or to
; - create a graph of FPM availability (rrd or such);
; - remove a server from a group if it is not responding (load balancing);
; - trigger alerts for the operating team (24/7).
; Note: The value must start with a leading slash (/). The value can be
; anything, but it may not be a good idea to use the .php extension or it
; may conflict with a real PHP file.
; Default Value: not set
;ping.path = /ping
; This directive may be used to customize the response of a ping request. The
; response is formatted as text/plain with a 200 response code.
; Default Value: pong
;ping.response = pong
; The access log file
; Default: not set
;access.log = log/$pool.access.log
; The access log format.
; The following syntax is allowed
; %%: the '%' character
; %C: %CPU used by the request
; it can accept the following format:
; - %{user}C for user CPU only
; - %{system}C for system CPU only
; - %{total}C for user + system CPU (default)
; %d: time taken to serve the request
; it can accept the following format:
; - %{seconds}d (default)
; - %{miliseconds}d
; - %{mili}d
; - %{microseconds}d
; - %{micro}d
; %e: an environment variable (same as $_ENV or $_SERVER)
; it must be associated with embraces to specify the name of the env
; variable. Some exemples:
; - server specifics like: %{REQUEST_METHOD}e or %{SERVER_PROTOCOL}e
; - HTTP headers like: %{HTTP_HOST}e or %{HTTP_USER_AGENT}e
; %f: script filename
; %l: content-length of the request (for POST request only)
; %m: request method
; %M: peak of memory allocated by PHP
; it can accept the following format:
; - %{bytes}M (default)
; - %{kilobytes}M
; - %{kilo}M
; - %{megabytes}M
; - %{mega}M
; %n: pool name
; %o: output header
; it must be associated with embraces to specify the name of the header:
; - %{Content-Type}o
; - %{X-Powered-By}o
; - %{Transfert-Encoding}o
; - ....
; %p: PID of the child that serviced the request
; %P: PID of the parent of the child that serviced the request
; %q: the query string
; %Q: the '?' character if query string exists
; %r: the request URI (without the query string, see %q and %Q)
; %R: remote IP address
; %s: status (response code)
; %t: server time the request was received
; it can accept a strftime(3) format:
; %d/%b/%Y:%H:%M:%S %z (default)
; The strftime(3) format must be encapsuled in a %{<strftime_format>}t tag
; e.g. for a ISO8601 formatted timestring, use: %{%Y-%m-%dT%H:%M:%S%z}t
; %T: time the log has been written (the request has finished)
; it can accept a strftime(3) format:
; %d/%b/%Y:%H:%M:%S %z (default)
; The strftime(3) format must be encapsuled in a %{<strftime_format>}t tag
; e.g. for a ISO8601 formatted timestring, use: %{%Y-%m-%dT%H:%M:%S%z}t
; %u: remote user
;
; Default: "%R - %u %t \"%m %r\" %s"
;access.format = "%R - %u %t \"%m %r%Q%q\" %s %f %{mili}d %{kilo}M %C%%"
; The log file for slow requests
; Default Value: not set
; Note: slowlog is mandatory if request_slowlog_timeout is set
slowlog = /var/log/php-fpm/www-slow.log
; The timeout for serving a single request after which a PHP backtrace will be
; dumped to the 'slowlog' file. A value of '0s' means 'off'.
; Available units: s(econds)(default), m(inutes), h(ours), or d(ays)
; Default Value: 0
;request_slowlog_timeout = 0
; Depth of slow log stack trace.
; Default Value: 20
;request_slowlog_trace_depth = 20
; The timeout for serving a single request after which the worker process will
; be killed. This option should be used when the 'max_execution_time' ini option
; does not stop script execution for some reason. A value of '0' means 'off'.
; Available units: s(econds)(default), m(inutes), h(ours), or d(ays)
; Default Value: 0
;request_terminate_timeout = 0
; Set open file descriptor rlimit.
; Default Value: system defined value
;rlimit_files = 1024
; Set max core size rlimit.
; Possible Values: 'unlimited' or an integer greater or equal to 0
; Default Value: system defined value
;rlimit_core = 0
; Chroot to this directory at the start. This value must be defined as an
; absolute path. When this value is not set, chroot is not used.
; Note: you can prefix with '$prefix' to chroot to the pool prefix or one
; of its subdirectories. If the pool prefix is not set, the global prefix
; will be used instead.
; Note: chrooting is a great security feature and should be used whenever
; possible. However, all PHP paths will be relative to the chroot
; (error_log, sessions.save_path, ...).
; Default Value: not set
;chroot =
; Chdir to this directory at the start.
; Note: relative path can be used.
; Default Value: current directory or / when chroot
;chdir = /var/www
; Redirect worker stdout and stderr into main error log. If not set, stdout and
; stderr will be redirected to /dev/null according to FastCGI specs.
; Note: on highloaded environement, this can cause some delay in the page
; process time (several ms).
; Default Value: no
;catch_workers_output = yes
; Clear environment in FPM workers
; Prevents arbitrary environment variables from reaching FPM worker processes
; by clearing the environment in workers before env vars specified in this
; pool configuration are added.
; Setting to "no" will make all environment variables available to PHP code
; via getenv(), $_ENV and $_SERVER.
; Default Value: yes
;clear_env = no
; Limits the extensions of the main script FPM will allow to parse. This can
; prevent configuration mistakes on the web server side. You should only limit
; FPM to .php extensions to prevent malicious users to use other extensions to
; execute php code.
; Note: set an empty value to allow all extensions.
; Default Value: .php
;security.limit_extensions = .php .php3 .php4 .php5 .php7
; Pass environment variables like LD_LIBRARY_PATH. All $VARIABLEs are taken from
; the current environment.
; Default Value: clean env
;env[HOSTNAME] = $HOSTNAME
;env[PATH] = /usr/local/bin:/usr/bin:/bin
;env[TMP] = /tmp
;env[TMPDIR] = /tmp
;env[TEMP] = /tmp
; Additional php.ini defines, specific to this pool of workers. These settings
; overwrite the values previously defined in the php.ini. The directives are the
; same as the PHP SAPI:
; php_value/php_flag - you can set classic ini defines which can
; be overwritten from PHP call 'ini_set'.
; php_admin_value/php_admin_flag - these directives won't be overwritten by
; PHP call 'ini_set'
; For php_*flag, valid values are on, off, 1, 0, true, false, yes or no.
; Defining 'extension' will load the corresponding shared extension from
; extension_dir. Defining 'disable_functions' or 'disable_classes' will not
; overwrite previously defined php.ini values, but will append the new value
; instead.
; Note: path INI options can be relative and will be expanded with the prefix
; (pool, global or @prefix@)
; Default Value: nothing is defined by default except the values in php.ini and
; specified at startup with the -d argument
;php_admin_value[sendmail_path] = /usr/sbin/sendmail -t -i -f www@my.domain.com
;php_flag[display_errors] = off
php_admin_value[error_log] = /var/log/php-fpm/www-error.log
php_admin_flag[log_errors] = on
;php_admin_value[memory_limit] = 128M
; Set the following data paths to directories owned by the FPM process user.
;
; Do not change the ownership of existing system directories, if the process
; user does not have write permission, create dedicated directories for this
; purpose.
;
; See warning about choosing the location of these directories on your system
; at http://php.net/session.save-path
php_value[session.save_handler] = files
php_value[session.save_path] = /var/lib/php/session
php_value[soap.wsdl_cache_dir] = /var/lib/php/wsdlcache
;php_value[opcache.file_cache] = /var/lib/php/opcache
@@ -0,0 +1,148 @@
; Enable Zend OPcache extension module
zend_extension=opcache
; Determines if Zend OPCache is enabled
opcache.enable=1
; Determines if Zend OPCache is enabled for the CLI version of PHP
opcache.enable_cli=1
; The OPcache shared memory storage size.
;opcache.memory_consumption=128
; The amount of memory for interned strings in Mbytes.
;opcache.interned_strings_buffer=8
; The maximum number of keys (scripts) in the OPcache hash table.
; Only numbers between 200 and 1000000 are allowed.
;opcache.max_accelerated_files=10000
; The maximum percentage of "wasted" memory until a restart is scheduled.
;opcache.max_wasted_percentage=5
; When this directive is enabled, the OPcache appends the current working
; directory to the script key, thus eliminating possible collisions between
; files with the same name (basename). Disabling the directive improves
; performance, but may break existing applications.
;opcache.use_cwd=1
; When disabled, you must reset the OPcache manually or restart the
; webserver for changes to the filesystem to take effect.
;opcache.validate_timestamps=1
; How often (in seconds) to check file timestamps for changes to the shared
; memory storage allocation. ("1" means validate once per second, but only
; once per request. "0" means always validate)
;opcache.revalidate_freq=2
; Enables or disables file search in include_path optimization
;opcache.revalidate_path=0
; If disabled, all PHPDoc comments are dropped from the code to reduce the
; size of the optimized code.
;opcache.save_comments=1
; Allow file existence override (file_exists, etc.) performance feature.
;opcache.enable_file_override=0
; A bitmask, where each bit enables or disables the appropriate OPcache
; passes
;opcache.optimization_level=0x7FFFBFFF
; This hack should only be enabled to work around "Cannot redeclare class"
; errors.
;opcache.dups_fix=0
; The location of the OPcache blacklist file (wildcards allowed).
; Each OPcache blacklist file is a text file that holds the names of files
; that should not be accelerated.
opcache.blacklist_filename=/etc/php-zts.d/opcache*.blacklist
; Allows exclusion of large files from being cached. By default all files
; are cached.
;opcache.max_file_size=0
; Check the cache checksum each N requests.
; The default value of "0" means that the checks are disabled.
;opcache.consistency_checks=0
; How long to wait (in seconds) for a scheduled restart to begin if the cache
; is not being accessed.
;opcache.force_restart_timeout=180
; OPcache error_log file name. Empty string assumes "stderr".
;opcache.error_log=
; All OPcache errors go to the Web server log.
; By default, only fatal errors (level 0) or errors (level 1) are logged.
; You can also enable warnings (level 2), info messages (level 3) or
; debug messages (level 4).
;opcache.log_verbosity_level=1
; Preferred Shared Memory back-end. Leave empty and let the system decide.
;opcache.preferred_memory_model=
; Protect the shared memory from unexpected writing during script execution.
; Useful for internal debugging only.
;opcache.protect_memory=0
; Allows calling OPcache API functions only from PHP scripts which path is
; started from specified string. The default "" means no restriction
;opcache.restrict_api=
; Enables and sets the second level cache directory.
; It should improve performance when SHM memory is full, at server restart or
; SHM reset. The default "" disables file based caching.
; RPM note : file cache directory must be owned by process owner
; for mod_php, see /etc/httpd/conf.d/php.conf
; for php-fpm, see /etc/php-fpm.d/*conf
;opcache.file_cache=
; Enables or disables opcode caching in shared memory.
;opcache.file_cache_only=0
; Enables or disables checksum validation when script loaded from file cache.
;opcache.file_cache_consistency_checks=1
; Implies opcache.file_cache_only=1 for a certain process that failed to
; reattach to the shared memory (for Windows only). Explicitly enabled file
; cache is required.
;opcache.file_cache_fallback=1
; Enables or disables copying of PHP code (text segment) into HUGE PAGES.
; This should improve performance, but requires appropriate OS configuration.
opcache.huge_code_pages=0
; Validate cached file permissions.
; Leads OPcache to check file readability on each access to cached file.
; This directive should be enabled in shared hosting environment, when few
; users (PHP-FPM pools) reuse the common OPcache shared memory.
;opcache.validate_permission=0
; Prevent name collisions in chroot'ed environment.
; This directive prevents file name collisions in different "chroot"
; environments. It should be enabled for sites that may serve requests in
; different "chroot" environments.
;opcache.validate_root=0
; If specified, it produces opcode dumps for debugging different stages of
; optimizations.
;opcache.opt_debug_level=0
; Specifies a PHP script that is going to be compiled and executed at server
; start-up.
; http://php.net/opcache.preload
;opcache.preload=
; Preloading code as root is not allowed for security reasons. This directive
; facilitates to let the preloading to be run as another user.
; http://php.net/opcache.preload_user
;opcache.preload_user=
; Prevents caching files that are less than this number of seconds old. It
; protects from caching of incompletely updated files. In case all file updates
; on your site are atomic, you may increase performance by setting it to "0".
;opcache.file_update_protection=2
; Absolute path used to store shared lockfiles (for *nix only).
;opcache.lockfile_path=/tmp
@@ -0,0 +1,2 @@
; Enable bz2 extension module
extension=bz2
@@ -0,0 +1,2 @@
; Enable calendar extension module
extension=calendar
@@ -0,0 +1,2 @@
; Enable ctype extension module
extension=ctype
@@ -0,0 +1,2 @@
; Enable curl extension module
extension=curl
@@ -0,0 +1,2 @@
; Enable dom extension module
extension=dom
@@ -0,0 +1,2 @@
; Enable exif extension module
extension=exif
@@ -0,0 +1,2 @@
; Enable fileinfo extension module
extension=fileinfo
@@ -0,0 +1,2 @@
; Enable ftp extension module
extension=ftp
@@ -0,0 +1,2 @@
; Enable gettext extension module
extension=gettext
@@ -0,0 +1,2 @@
; Enable iconv extension module
extension=iconv
@@ -0,0 +1,2 @@
; Enable json extension module
extension=json
@@ -0,0 +1,2 @@
; Enable mbstring extension module
extension=mbstring
@@ -0,0 +1,2 @@
; Enable mysqlnd extension module
extension=mysqlnd
@@ -0,0 +1,2 @@
; Enable pdo extension module
extension=pdo
@@ -0,0 +1,2 @@
; Enable phar extension module
extension=phar
@@ -0,0 +1,2 @@
; Enable simplexml extension module
extension=simplexml
@@ -0,0 +1,2 @@
; Enable sockets extension module
extension=sockets
@@ -0,0 +1,2 @@
; Enable sodium extension module
extension=sodium
@@ -0,0 +1,2 @@
; Enable sqlite3 extension module
extension=sqlite3
@@ -0,0 +1,2 @@
; Enable tokenizer extension module
extension=tokenizer
@@ -0,0 +1,2 @@
; Enable xml extension module
extension=xml
@@ -0,0 +1,2 @@
; Enable xmlwriter extension module
extension=xmlwriter
@@ -0,0 +1,2 @@
; Enable xsl extension module
extension=xsl
@@ -0,0 +1,2 @@
; Enable mysqli extension module
extension=mysqli
@@ -0,0 +1,2 @@
; Enable pdo_mysql extension module
extension=pdo_mysql
@@ -0,0 +1,2 @@
; Enable pdo_sqlite extension module
extension=pdo_sqlite
@@ -0,0 +1,2 @@
; Enable xmlreader extension module
extension=xmlreader
@@ -0,0 +1,11 @@
; The blacklist file is a text file that holds the names of files
; that should not be accelerated. The file format is to add each filename
; to a new line. The filename may be a full path or just a file prefix
; (i.e., /var/www/x blacklists all the files and directories in /var/www
; that start with 'x'). Line starting with a ; are ignored (comments).
; Files are usually triggered by one of the following three reasons:
; 1) Directories that contain auto generated code, like Smarty or ZFW cache.
; 2) Code that does not work well when accelerated, due to some delayed
; compile time evaluation.
; 3) Code that triggers an OPcache bug.
@@ -0,0 +1,154 @@
; Enable Zend OPcache extension module
zend_extension=opcache
; Determines if Zend OPCache is enabled
opcache.enable=1
; Determines if Zend OPCache is enabled for the CLI version of PHP
opcache.enable_cli=1
; The OPcache shared memory storage size.
;opcache.memory_consumption=128
; The amount of memory for interned strings in Mbytes.
;opcache.interned_strings_buffer=8
; The maximum number of keys (scripts) in the OPcache hash table.
; Only numbers between 200 and 1000000 are allowed.
;opcache.max_accelerated_files=10000
; The maximum percentage of "wasted" memory until a restart is scheduled.
;opcache.max_wasted_percentage=5
; When this directive is enabled, the OPcache appends the current working
; directory to the script key, thus eliminating possible collisions between
; files with the same name (basename). Disabling the directive improves
; performance, but may break existing applications.
;opcache.use_cwd=1
; When disabled, you must reset the OPcache manually or restart the
; webserver for changes to the filesystem to take effect.
;opcache.validate_timestamps=1
; How often (in seconds) to check file timestamps for changes to the shared
; memory storage allocation. ("1" means validate once per second, but only
; once per request. "0" means always validate)
;opcache.revalidate_freq=2
; Enables or disables file search in include_path optimization
;opcache.revalidate_path=0
; If disabled, all PHPDoc comments are dropped from the code to reduce the
; size of the optimized code.
;opcache.save_comments=1
; If enabled, compilation warnings (including notices and deprecations) will
; be recorded and replayed each time a file is included. Otherwise, compilation
; warnings will only be emitted when the file is first cached.
;opcache.record_warnings=0
; Allow file existence override (file_exists, etc.) performance feature.
;opcache.enable_file_override=0
; A bitmask, where each bit enables or disables the appropriate OPcache
; passes
;opcache.optimization_level=0x7FFFBFFF
; This hack should only be enabled to work around "Cannot redeclare class"
; errors.
;opcache.dups_fix=0
; The location of the OPcache blacklist file (wildcards allowed).
; Each OPcache blacklist file is a text file that holds the names of files
; that should not be accelerated.
opcache.blacklist_filename=/etc/php.d/opcache*.blacklist
; Allows exclusion of large files from being cached. By default all files
; are cached.
;opcache.max_file_size=0
; How long to wait (in seconds) for a scheduled restart to begin if the cache
; is not being accessed.
;opcache.force_restart_timeout=180
; OPcache error_log file name. Empty string assumes "stderr".
;opcache.error_log=
; All OPcache errors go to the Web server log.
; By default, only fatal errors (level 0) or errors (level 1) are logged.
; You can also enable warnings (level 2), info messages (level 3) or
; debug messages (level 4).
;opcache.log_verbosity_level=1
; Preferred Shared Memory back-end. Leave empty and let the system decide.
;opcache.preferred_memory_model=
; Protect the shared memory from unexpected writing during script execution.
; Useful for internal debugging only.
;opcache.protect_memory=0
; Allows calling OPcache API functions only from PHP scripts which path is
; started from specified string. The default "" means no restriction
;opcache.restrict_api=
; Enables and sets the second level cache directory.
; It should improve performance when SHM memory is full, at server restart or
; SHM reset. The default "" disables file based caching.
; RPM note : file cache directory must be owned by process owner
; for mod_php, see /etc/httpd/conf.d/php.conf
; for php-fpm, see /etc/php-fpm.d/*conf
;opcache.file_cache=
; Enables or disables opcode caching in shared memory.
;opcache.file_cache_only=0
; Enables or disables checksum validation when script loaded from file cache.
;opcache.file_cache_consistency_checks=1
; Implies opcache.file_cache_only=1 for a certain process that failed to
; reattach to the shared memory (for Windows only). Explicitly enabled file
; cache is required.
;opcache.file_cache_fallback=1
; Enables or disables copying of PHP code (text segment) into HUGE PAGES.
; Under certain circumstances (if only a single global PHP process is
; started from which all others fork), this can increase performance
; by a tiny amount because TLB misses are reduced. On the other hand, this
; delays PHP startup, increases memory usage and degrades performance
; under memory pressure - use with care.
; Requires appropriate OS configuration.
opcache.huge_code_pages=0
; Validate cached file permissions.
; Leads OPcache to check file readability on each access to cached file.
; This directive should be enabled in shared hosting environment, when few
; users (PHP-FPM pools) reuse the common OPcache shared memory.
;opcache.validate_permission=0
; Prevent name collisions in chroot'ed environment.
; This directive prevents file name collisions in different "chroot"
; environments. It should be enabled for sites that may serve requests in
; different "chroot" environments.
;opcache.validate_root=0
; If specified, it produces opcode dumps for debugging different stages of
; optimizations.
;opcache.opt_debug_level=0
; Specifies a PHP script that is going to be compiled and executed at server
; start-up.
; https://php.net/opcache.preload
;opcache.preload=
; Preloading code as root is not allowed for security reasons. This directive
; facilitates to let the preloading to be run as another user.
; https://php.net/opcache.preload_user
;opcache.preload_user=
; Prevents caching files that are less than this number of seconds old. It
; protects from caching of incompletely updated files. In case all file updates
; on your site are atomic, you may increase performance by setting it to "0".
;opcache.file_update_protection=2
; Absolute path used to store shared lockfiles (for *nix only).
;opcache.lockfile_path=/tmp
@@ -0,0 +1,2 @@
; Enable bz2 extension module
extension=bz2
@@ -0,0 +1,2 @@
; Enable calendar extension module
extension=calendar
@@ -0,0 +1,2 @@
; Enable ctype extension module
extension=ctype
@@ -0,0 +1,2 @@
; Enable curl extension module
extension=curl
@@ -0,0 +1,2 @@
; Enable dom extension module
extension=dom
@@ -0,0 +1,2 @@
; Enable exif extension module
extension=exif
@@ -0,0 +1,2 @@
; Enable fileinfo extension module
extension=fileinfo
@@ -0,0 +1,2 @@
; Enable ftp extension module
extension=ftp
@@ -0,0 +1,2 @@
; Enable gettext extension module
extension=gettext
@@ -0,0 +1,2 @@
; Enable iconv extension module
extension=iconv
@@ -0,0 +1,2 @@
; Enable json extension module
extension=json
@@ -0,0 +1,2 @@
; Enable mbstring extension module
extension=mbstring
@@ -0,0 +1,2 @@
; Enable mysqlnd extension module
extension=mysqlnd
@@ -0,0 +1,2 @@
; Enable pdo extension module
extension=pdo
@@ -0,0 +1,2 @@
; Enable phar extension module
extension=phar
@@ -0,0 +1,2 @@
; Enable simplexml extension module
extension=simplexml
@@ -0,0 +1,2 @@
; Enable sockets extension module
extension=sockets
@@ -0,0 +1,2 @@
; Enable sodium extension module
extension=sodium
@@ -0,0 +1,2 @@
; Enable sqlite3 extension module
extension=sqlite3
@@ -0,0 +1,2 @@
; Enable tokenizer extension module
extension=tokenizer
@@ -0,0 +1,2 @@
; Enable xml extension module
extension=xml
@@ -0,0 +1,2 @@
; Enable xmlwriter extension module
extension=xmlwriter

Some files were not shown because too many files have changed in this diff Show More