- setup-ipa-sudo.sh: grants %admins group NOPASSWD sudo after ipa-client-install;
writes admins-proxmox (pvesh/qm/pct) only when those binaries are present,
so the same script works on PBS/PDM as well as PVE hosts
- create-local-backdoor.sh: creates a local 'pveadmin' account with SSH key
and NOPASSWD sudo as an emergency fallback when IPA/SSSD is unavailable;
password set via BACKDOOR_PASS env var or prompted interactively
- bootstrap.sh: appended post-IPA-enrollment reminder to the final checklist
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
All existing content moved from repo root into proxmox/ to make room
for other Debian machine configs. Adds pihole/ with:
- config/pihole.toml — snapshot of current Pi-hole v6 config
- config/dnsmasq.d/99-ipxe-chainload.conf — custom PXE DHCP rules
(EFI/BIOS iPXE chainload, fixed tag-specificity bug for UEFI boot)
- pull-config.sh <source-host> <dest-dir> — pull live config to disk
- apply-config.sh <source-dir> <dest-host> — push config to a Pi-hole
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01XRzqNDrbnYR22ZgZj1Bg3s