mg
8f80c2855f
Co-authored-by: Michael Grote <michael.grote@posteo.de> Reviewed-on: mg/ansible#210 Co-authored-by: mg <mg@noreply.git.mgrote.net> Co-committed-by: mg <mg@noreply.git.mgrote.net>
35 lines
1.1 KiB
YAML
35 lines
1.1 KiB
YAML
---
|
|
### oefenweb.ufw
|
|
ufw_rules:
|
|
- rule: allow
|
|
to_port: 22
|
|
protocol: tcp
|
|
comment: 'ssh'
|
|
from_ip: 0.0.0.0/0
|
|
- rule: allow
|
|
to_port: 123
|
|
comment: 'ntp'
|
|
from_ip: 192.168.2.0/24
|
|
- rule: allow
|
|
to_port: 4949
|
|
protocol: tcp
|
|
comment: 'munin'
|
|
from_ip: 192.168.2.144/24
|
|
### mgrote.ntp_chrony_server
|
|
ntp_chrony_timezone: "Europe/Berlin" # Zeitzone in der sich der Computer befindet
|
|
ntp_chrony_driftfile_directory: "/var/lib/chrony" # Ordner für das driftfile
|
|
ntp_chrony_servers: # welche Server sollen befragt werden
|
|
- address: ptbtime1.ptb.de
|
|
options: iburst #optionaler parameter
|
|
- address: ptbtime2.ptb.de
|
|
options: iburst
|
|
- address: ptbtime3.ptb.de
|
|
options: iburst
|
|
- address: time3.google.com
|
|
options: iburst
|
|
- address: ntp0.fau.de
|
|
options: iburst
|
|
ntp_chrony_user: _chrony # Nutzer + Gruppe für den Dienst
|
|
ntp_chrony_group: _chrony # Nutzer + Gruppe für den Dienst
|
|
ntp_chrony_logging: false # logging an/aus
|
|
ntp_chrony_subnet_allow: 192.168.2.0/24 # welche Netze dürfen den Server befragen
|