This repository has been archived on 2026-08-17. You can view files and clone it. You cannot open issues or pull requests or push a commit.
Files
debian-configuration/freeipa/CLAUDE.md
beatzaplentyandClaude Sonnet 4.6 89cc8c8cc3 feat(freeipa): add domain-controller setup — Rocky Linux 9 + FreeIPA 4.13
Installs and documents the FreeIPA identity management server at
domain-controller.sweet.home (VMID 108, pve1). Provides Kerberos,
LDAP, and integrated DNS for the SWEET.HOME realm.

New section: freeipa/
- docs/install.md: full step-by-step reproduction procedure including
  Proxmox VM prep (Rocky Linux 9 GenericCloud, SeaBIOS, cloud-init),
  swap setup, static IP, /etc/hosts fix, ipa-server-install flags
- docs/pihole-dns.md: how to configure Pi-hole to forward sweet.home
  queries to the FreeIPA BIND instance
- scripts/install.sh: idempotent install script with pre-flight checks;
  reads passwords from env or interactive prompt (never commits them)
- scripts/configure-pihole-dns.sh: idempotent Pi-hole forwarder setup
- scripts/verify.sh: read-only health check (13 checks, 0 side effects)
- CLAUDE.md: host guardrails for domain-controller

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015Jbvxx4xbHVcx1NkK3vtmK
2026-07-27 07:22:05 +10:00

1.6 KiB

freeipa/CLAUDE.md

Host-specific guardrails for the domain-controller FreeIPA server.

Host: domain-controller.sweet.home

  • VMID 108 on pve1.sweet.home — this is production infrastructure. Treat it the same as any other pve1 guest: no changes without explicit same-session operator authorisation.
  • Read-only is always fine: SSH in as wayne, inspect IPA state with ipa * commands or kinit admin && ipa ..., check service status with ipactl status — none of that needs authorisation.
  • Never modify FreeIPA topology, replicas, or the LDAP DIT directly without the operator's go-ahead. That means no ipa user-del, no ipa-replica-manage, no ldapmodify against the live directory.
  • Do not commit secrets. The Directory Manager password and the admin Kerberos password must not appear in any file in this repo. Scripts that need them must read from environment variables or prompt interactively.
  • The admin password and Directory Manager password were generated at install time and stored only in the operator's password manager — not in this repo. See README.md for how to retrieve/reset them.

What is safe to run automatically

  • scripts/verify.sh — read-only health check, no side effects.
  • scripts/configure-pihole-dns.sh — idempotent DNS forwarder setup in Pi-hole; safe to re-run.

What requires operator go-ahead

  • scripts/install.sh — destructive if run against an already-provisioned host. Always check first with ipactl status.
  • Any ipa-replica-install or ipa-server-upgrade invocation.