# freeipa/CLAUDE.md Host-specific guardrails for the `domain-controller` FreeIPA server. ## Host: `domain-controller.sweet.home` - **VMID 108 on `pve1.sweet.home`** — this is production infrastructure. Treat it the same as any other pve1 guest: no changes without explicit same-session operator authorisation. - **Read-only is always fine**: SSH in as `wayne`, inspect IPA state with `ipa *` commands or `kinit admin && ipa ...`, check service status with `ipactl status` — none of that needs authorisation. - **Never modify FreeIPA topology, replicas, or the LDAP DIT directly** without the operator's go-ahead. That means no `ipa user-del`, no `ipa-replica-manage`, no `ldapmodify` against the live directory. - **Do not commit secrets.** The Directory Manager password and the `admin` Kerberos password must not appear in any file in this repo. Scripts that need them must read from environment variables or prompt interactively. - The `admin` password and Directory Manager password were generated at install time and stored only in the operator's password manager — not in this repo. See `README.md` for how to retrieve/reset them. ## What is safe to run automatically - `scripts/verify.sh` — read-only health check, no side effects. - `scripts/configure-pihole-dns.sh` — idempotent DNS forwarder setup in Pi-hole; safe to re-run. ## What requires operator go-ahead - `scripts/install.sh` — destructive if run against an already-provisioned host. Always check first with `ipactl status`. - Any `ipa-replica-install` or `ipa-server-upgrade` invocation.