# oidc_client_secret: "{{oidc_client_secret}}" # Default use wildcard for primary domain, subdomain client specific configuration in vars files in the roles is possible
ldap_network_enabled:false# Activate LDAP network for insecure communitation on localhot between different container instances. Set in vars/main.yml
oauth2_proxy_upstream_application_and_port:"application:80"# The name of the application which the server redirects to. Needs to be defined in role vars.
oauth2_proxy_active:false
defaults_applications:
## Akaunting
akaunting:
version:"latest"
company_name:"{{primary_domain}}"
company_email:"{{administrator_email}}"
setup_admin_email:"{{administrator_email}}"
## Attendize
attendize:
version:"latest"
## Baserow
baserow:
version:"latest"
## Big Blue Button
bigbluebutton:
enable_greenlight:"true"
## Bluesky
bluesky:
administrator_email:"{{administrator_email}}"
pds:
version:"latest"
## Friendica
friendica:
version:"latest"
## Funkwhale
funkwhale:
version:"1.4.0"
## Gitea
gitea:
version:"latest"
## Gitlab
gitlab:
version:"latest"
## Joomla
joomla:
version:"latest"
## Keycloak
keycloak:
version:"latest"
administrator_username:"{{administrator_username}}"# Administrator Username for Keycloak
## LDAP
ldap:
lam:
version:"latest"
administrator_password:"{{user_administrator_initial_password}}"# CHANGE for security reasons
openldap:
version:"latest"
expose_to_internet:false# Set to true if you want to expose the LDAP port to the internet. Keep in mind to
phpldapadmin:
version:"2.0.0-dev"# @todo Attention: Change this as fast as released to latest
webinterface:"lam"# The webinterface which should be used. Possible: lam and phpldapadmin
configuration_file:"oauth2-proxy-keycloak.cfg"# Needs to be set true in the roles which use it
version:"latest"
redirect_url:"https://{{domains.keycloak}}/auth/realms/{{primary_domain}}/protocol/openid-connect/auth"# The redirect URL for the OAuth2 flow. It should match the redirect URL configured in Keycloak.
allowed_roles:admin # Restrict it default to admin role. Use the vars/main.yml to open the specific role for other groups
cookie_secret:"{{applications.oauth2_proxy.cookie_secret}}"# Default use wildcard for primary domain, subdomain client specific configuration in vars files in the roles is possible openssl rand -hex 16
## Peertube
peertube:
version:"bookworm"
## PHPMyAdmin
phpmyadmin:
version:"latest"
autologin:false# This is a high security risk. Just activate this option if you know what you're doing
## Pixelfed
pixelfed:
titel:"Pictures on {{primary_domain}}"
version:"latest"
## Postgres
# Please set an version in your inventory file - Rolling release for postgres isn't recommended