Archived
Installs and documents the FreeIPA identity management server at domain-controller.sweet.home (VMID 108, pve1). Provides Kerberos, LDAP, and integrated DNS for the SWEET.HOME realm. New section: freeipa/ - docs/install.md: full step-by-step reproduction procedure including Proxmox VM prep (Rocky Linux 9 GenericCloud, SeaBIOS, cloud-init), swap setup, static IP, /etc/hosts fix, ipa-server-install flags - docs/pihole-dns.md: how to configure Pi-hole to forward sweet.home queries to the FreeIPA BIND instance - scripts/install.sh: idempotent install script with pre-flight checks; reads passwords from env or interactive prompt (never commits them) - scripts/configure-pihole-dns.sh: idempotent Pi-hole forwarder setup - scripts/verify.sh: read-only health check (13 checks, 0 side effects) - CLAUDE.md: host guardrails for domain-controller Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_015Jbvxx4xbHVcx1NkK3vtmK
56 lines
1.7 KiB
Markdown
56 lines
1.7 KiB
Markdown
# debian-configuration
|
|
|
|
Configuration, hardening toolsets, and operational docs for Wayne's
|
|
Debian-based LAN machines. Each subdirectory covers a different host or
|
|
service type.
|
|
|
|
## Layout
|
|
|
|
```
|
|
proxmox/ Proxmox VE hosts (pve1 production, pve-test sandbox)
|
|
pihole/ Pi-hole DNS/DHCP (config snapshots, pull/apply scripts)
|
|
freeipa/ FreeIPA identity management server (domain-controller.sweet.home)
|
|
scripts/ Repo-wide scripts (secret scanning, git hook installer)
|
|
```
|
|
|
|
## Sections
|
|
|
|
### `proxmox/`
|
|
|
|
Base configuration and hardening toolset for Proxmox VE hosts. See
|
|
`proxmox/README.md` for goals, quick-start, and current status.
|
|
|
|
### `pihole/`
|
|
|
|
Pi-hole v6 configuration management. Stores a sanitised snapshot of the
|
|
live config and provides scripts to pull from or push to a running
|
|
instance. See `pihole/README.md` for usage.
|
|
|
|
### `freeipa/`
|
|
|
|
FreeIPA 4.x identity management server running on Rocky Linux 9
|
|
(`domain-controller.sweet.home`, VMID 108 on pve1). Provides Kerberos,
|
|
LDAP, and integrated DNS for the `sweet.home` realm. See
|
|
`freeipa/README.md` for the quick-start and `freeipa/docs/install.md`
|
|
for the full reproduction procedure.
|
|
|
|
## Secret scanning
|
|
|
|
All commits are scanned for secrets by a CI pipeline that runs on both
|
|
GitHub Actions and Gitea Actions. The same scan can be run locally:
|
|
|
|
```bash
|
|
# One-time setup — installs a pre-commit git hook
|
|
bash scripts/install-hooks.sh
|
|
|
|
# Manual run against the full git history
|
|
bash scripts/check-secrets.sh
|
|
|
|
# Requires gitleaks on PATH; falls back to Docker if available
|
|
# https://github.com/gitleaks/gitleaks#installing
|
|
```
|
|
|
|
`pihole/pull-config.sh` automatically redacts sensitive fields
|
|
(`pwhash`, `totp_secret`, `app_pwhash`) from `pihole.toml` before
|
|
writing it to disk, so the repo stays clean by default.
|