Advertisement
Guest User

Untitled

a guest
Feb 12th, 2016
479
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 21.00 KB | None | 0 0
  1. ---
  2. <%
  3. director_uuid = "XXXXXXXXXXXXXXXXXXXX-XXXXXXXXXXXX"
  4. protocol = "https"
  5. cf_release = "228"
  6. ip_address = "10.0.0.147"
  7. common_password = "c1oudc0w"
  8. root_domain = "cf.test.com"
  9. cc_api_url = "https://api.cf.test.com"
  10. deployment_name = "cloudfoundry-DEV"
  11. %>
  12. name: <%= deployment_name %>
  13. director_uuid: <%= director_uuid %>
  14.  
  15. releases:
  16. - name: cf
  17. version: <%= cf_release %>
  18.  
  19. compilation:
  20. workers: 4
  21. network: default
  22. reuse_compilation_vms: true
  23. cloud_properties:
  24. instance_type: m1.small
  25.  
  26. update:
  27. canaries: 1
  28. canary_watch_time: 30000-300000
  29. update_watch_time: 30000-300000
  30. max_in_flight: 1
  31.  
  32. networks:
  33. - name: floating
  34. type: vip
  35. cloud_properties:
  36. security_groups:
  37. - open
  38. - name: default
  39. type: dynamic
  40. cloud_properties:
  41. security_groups:
  42. - open
  43.  
  44. resource_pools:
  45. - name: small
  46. network: default
  47. size: 11
  48. stemcell:
  49. name: bosh-openstack-kvm-ubuntu-trusty-go_agent
  50. version: 3147
  51. cloud_properties:
  52. instance_type: m1.small
  53.  
  54. jobs:
  55. - name: ha_proxy_z1
  56. templates:
  57. - name: haproxy
  58. - name: metron_agent
  59. - name: consul_agent
  60. release: cf
  61. instances: 1
  62. resource_pool: small
  63. networks:
  64. - name: default
  65. default: [dns, gateway]
  66. - name: floating
  67. static_ips:
  68. - <%= ip_address %>
  69. properties:
  70. router:
  71. servers:
  72. z1:
  73. - 10.0.0.172
  74. z2:
  75. - 10.0.0.172
  76. metron_agent:
  77. zone: z1
  78. ha_proxy:
  79. ssl_pem: |
  80.  
  81. - name: common1
  82. templates:
  83. - name: postgres
  84. release: cf
  85. instances: 1
  86. resource_pool: small
  87. persistent_disk: 16384
  88. networks:
  89. - name: default
  90. default: [dns, gateway]
  91. - name: floating
  92. static_ips:
  93. - 10.0.0.132
  94. properties:
  95. db: databases
  96. metron_agent:
  97. zone: z1
  98.  
  99. - name: common2
  100. templates:
  101. - name: collector
  102. - name: nats
  103. - name: uaa
  104. - name: metron_agent
  105. - name: statsd-injector
  106. - name: route_registrar
  107. - name: consul_agent
  108. release: cf
  109. instances: 1
  110. resource_pool: small
  111. persistent_disk: 16384
  112. networks:
  113. - name: default
  114. default: [dns, gateway]
  115. - name: floating
  116. static_ips:
  117. - 10.0.0.133
  118. properties:
  119. consul:
  120. agent:
  121. services:
  122. uaa: {}
  123. metron_agent:
  124. zone: z1
  125. loggregator_endpoint:
  126. host: 10.0.0.140
  127. port: 3456
  128. shared_secret: ilovesecrets
  129. route_registrar:
  130. routes:
  131. - name: uaa
  132. port: 8080
  133. tags:
  134. component: uaa
  135. uris:
  136. - uaa.<%= root_domain %>
  137. - '*.uaa.<%= root_domain %>'
  138. - login.<%= root_domain %>
  139. - '*.login.<%= root_domain %>'
  140. uaa:
  141. proxy:
  142. servers:
  143. - 10.0.0.172
  144.  
  145. - name: dea
  146. templates:
  147. - name: dea_next
  148. - name: dea_logging_agent
  149. - name: metron_agent
  150. release: cf
  151. instances: 1
  152. resource_pool: small
  153. networks:
  154. - name: default
  155. default: [dns, gateway]
  156. properties:
  157. dea_next:
  158. zone: z1
  159. metron_agent:
  160. zone: z1
  161. networks:
  162. apps: default
  163.  
  164. - name: etcd_z1
  165. release: cf
  166. templates:
  167. - name: etcd
  168. release: cf
  169. - name: etcd_metrics_server
  170. release: cf
  171. - name: metron_agent
  172. release: cf
  173. instances: 1
  174. persistent_disk: 10024
  175. resource_pool: small
  176. networks:
  177. - name: default
  178. default: [dns, gateway]
  179. - name: floating
  180. static_ips:
  181. - 10.0.0.212
  182. properties:
  183. metron_agent:
  184. zone: z1
  185. update:
  186. max_in_flight: 1
  187.  
  188. - name: hm9000_z1
  189. release: cf
  190. templates:
  191. - name: hm9000
  192. - name: metron_agent
  193. - name: route_registrar
  194. instances: 1
  195. resource_pool: small
  196. networks:
  197. - name: default
  198. default: [dns, gateway]
  199. properties:
  200. etcd_ips:
  201. - 10.0.0.212
  202. metron_agent:
  203. zone: z1
  204. route_registrar:
  205. routes:
  206. - name: hm9000
  207. port: 5155
  208. tags:
  209. component: HM9K
  210. uris:
  211. - hm9000.<%= root_domain %>
  212.  
  213. - name: controller
  214. templates:
  215. - name: cloud_controller_ng
  216. - name: gorouter
  217. - name: metron_agent
  218. - name: statsd-injector
  219. - name: route_registrar
  220. - name: consul_agent
  221. release: cf
  222. instances: 1
  223. resource_pool: small
  224. networks:
  225. - name: default
  226. default: [dns, gateway]
  227. - name: floating
  228. static_ips:
  229. - 10.0.0.172
  230. properties:
  231. consul:
  232. agent:
  233. services:
  234. cloud_controller_ng: {}
  235. routing-api: {}
  236. gorouter: {}
  237. metron_agent:
  238. zone: z1
  239. route_registrar:
  240. routes:
  241. - name: api
  242. tags:
  243. component: CloudController
  244. port: 9022
  245. uris:
  246. - api.<%= root_domain %>
  247.  
  248. - name: controller_worker
  249. templates:
  250. - name: cloud_controller_worker
  251. - name: metron_agent
  252. - name: consul_agent
  253. release: cf
  254. instances: 1
  255. resource_pool: small
  256. networks:
  257. - name: default
  258. default: [dns, gateway]
  259. properties:
  260. metron_agent:
  261. zone: z1
  262.  
  263. - name: controller_clock
  264. templates:
  265. - name: cloud_controller_clock
  266. - name: metron_agent
  267. release: cf
  268. instances: 1
  269. resource_pool: small
  270. networks:
  271. - name: default
  272. default: [dns, gateway]
  273. properties:
  274. metron_agent:
  275. zone: z1
  276.  
  277. - name: doppler
  278. templates:
  279. - name: doppler
  280. - name: syslog_drain_binder
  281. - name: metron_agent
  282. release: cf
  283. instances: 1
  284. resource_pool: small
  285. networks:
  286. - name: default
  287. default: [dns, gateway]
  288. - name: floating
  289. static_ips:
  290. - 10.0.0.141
  291. properties:
  292. doppler:
  293. zone: z1
  294. metron_agent:
  295. zone: z1
  296.  
  297. - name: loggregator-trafficecontroller
  298. templates:
  299. - name: loggregator_trafficcontroller
  300. - name: metron_agent
  301. - name: route_registrar
  302. release: cf
  303. instances: 1
  304. resource_pool: small
  305. networks:
  306. - name: default
  307. default: [dns, gateway]
  308. - name: floating
  309. static_ips:
  310. - 10.0.0.140
  311. properties:
  312. traffic_controller:
  313. zone: z1
  314. metron_agent:
  315. zone: z1
  316. route_registrar:
  317. routes:
  318. - name: doppler
  319. port: 8081
  320. uris:
  321. - doppler.<%= root_domain %>
  322. - name: loggregator
  323. port: 8080
  324. uris:
  325. - loggregator.<%= root_domain %>
  326.  
  327. properties:
  328. domain: <%= root_domain %>
  329. system_domain: <%= root_domain %>
  330. system_domain_organization: "main"
  331. app_domains:
  332. - <%= root_domain %>
  333. support_address:
  334. description: "Cloud Foundry v"
  335.  
  336. ssl:
  337. skip_cert_verify: true
  338.  
  339. consul:
  340. require_ssl: false
  341. log_level: debug
  342. agent:
  343. servers:
  344. lan:
  345. - 172.21.28.228
  346. - 172.21.28.148
  347. - 172.21.28.229
  348.  
  349. hm9000:
  350. port: 5155
  351. url: <%= protocol %>://hm9000.<%= root_domain %>
  352.  
  353. loggregator:
  354. debug: false
  355. blacklisted_syslog_ranges: null
  356. etcd:
  357. machines:
  358. - 10.0.0.212
  359. maxRetainedLogMessages: 100
  360. outgoing_dropsonde_port: 8081
  361. tls:
  362. ca: null
  363.  
  364. loggregator_endpoint:
  365. shared_secret: ilovesecrets
  366.  
  367. logger_endpoint:
  368. port: 4443
  369.  
  370. traffic_controller:
  371. outgoing_port: 8080
  372. zone: null
  373.  
  374. doppler_endpoint:
  375. shared_secret: ilovesecrets
  376.  
  377.  
  378. metron_agent:
  379. deployment: cloudfoundry-DEV
  380. buffer_size: null
  381. enable_buffer: null
  382. preferred_protocol: null
  383. tls_client:
  384. cert: null
  385. key: null
  386.  
  387. metron_endpoint:
  388. shared_secret: ilovesecrets
  389.  
  390. nats:
  391. machines:
  392. - 10.0.0.133
  393. address: 10.0.0.133
  394. port: 4222
  395. user: nats
  396. password: <%= common_password %>
  397. authorization_timeout: 10
  398. use_gnatsd: true
  399.  
  400. etcd:
  401. machines:
  402. - 10.0.0.212
  403. require_ssl: false
  404. peer_require_ssl: false
  405.  
  406. etcd_ips:
  407. - 10.0.0.212
  408.  
  409. etcd_metrics_server:
  410. nats:
  411. machines:
  412. - 10.0.0.133
  413. username: nats
  414. password: <%= common_password %>
  415.  
  416. router:
  417. ssl_skip_validation: true
  418. status:
  419. user: gorouter
  420. password: <%= common_password %>
  421.  
  422. dea: &dea
  423. memory_mb: 1396
  424. disk_mb: 16384
  425. directory_server_protocol: <%= protocol %>
  426. memory_overcommit_factor: 4
  427. disk_overcommit_factor: 4
  428. default_health_check_timeout: 60
  429. advertise_interval_in_seconds: 5
  430. heartbeat_interval_in_seconds: 10
  431. allow_host_access: true
  432.  
  433. dea_next: *dea
  434.  
  435. databases: &databases
  436. db_scheme: postgres
  437. address: 10.0.0.132
  438. port: 5524
  439. roles:
  440. - tag: admin
  441. name: ccadmin
  442. password: <%= common_password %>
  443. - tag: admin
  444. name: uaaadmin
  445. password: <%= common_password %>
  446. databases:
  447. - tag: cc
  448. name: ccdb
  449. citext: true
  450. - tag: uaa
  451. name: uaadb
  452. citext: true
  453.  
  454. ccdb:
  455. address: 10.0.0.132
  456. databases:
  457. - name: ccdb
  458. tag: cc
  459. db_scheme: postgres
  460. port: 5524
  461. roles:
  462. - name: ccadmin
  463. tag: admin
  464. password: <%= common_password %>
  465.  
  466. uaadb:
  467. db_scheme: postgresql
  468. address: 10.0.0.132
  469. port: 5524
  470. roles:
  471. - tag: admin
  472. name: uaaadmin
  473. password: <%= common_password %>
  474. databases:
  475. - tag: uaa
  476. name: uaadb
  477. citext: true
  478.  
  479. serialization_data_server:
  480. port: 8080
  481. logging_level: debug
  482. upload_token: 8f7COGvThwlmulIzAgOHxMXurBrG364k
  483. upload_timeout: 10
  484.  
  485. collector:
  486. deployment_name: <%= deployment_name %>
  487. use_tsdb: false
  488. use_aws_cloudwatch: false
  489. use_datadog: false
  490.  
  491. service_lifecycle:
  492. serialization_data_server:
  493. - 10.0.0.133
  494.  
  495. cc_api_version: v2
  496.  
  497. cc: &cc
  498. logging_level: debug2
  499. db_logging_level: debug2
  500.  
  501. cc_partition: default
  502. db_encryption_key: <%= common_password %>
  503. bootstrap_admin_email: "mymail"
  504.  
  505. bulk_api_password: <%= common_password %>
  506. internal_api_user: "internal_user"
  507. internal_api_password: <%= common_password %>
  508.  
  509. external_host: api
  510. external_port: 9022
  511. srv_api_uri: <%= protocol %>://api.<%= root_domain %>
  512.  
  513. uaa_resource_id: cloud_controller
  514. staging_upload_user: upload
  515. staging_upload_password: <%= common_password %>
  516.  
  517. users_can_select_backend: false
  518. default_to_diego_backend: false
  519. allow_app_ssh_access: false
  520.  
  521. resource_pool:
  522. resource_directory_key: <%= root_domain %>-cc-resources-dev
  523. fog_connection:
  524. provider: "AWS"
  525. host: "s3.com"
  526. scheme: "http"
  527. port: 80
  528. aws_signature_version: "2"
  529. aws_access_key_id: "xxxxxxxxx"
  530. aws_secret_access_key: "xxxxxxxxxxxx"
  531. packages:
  532. app_package_directory_key: <%= root_domain %>-cc-packages-dev
  533. fog_connection:
  534. provider: "AWS"
  535. host: "s3.com"
  536. scheme: "http"
  537. port: 80
  538. aws_signature_version: "2"
  539. aws_access_key_id: "xxxxxxxxxxxxxxxxxx"
  540. aws_secret_access_key: "xxxxxxxxxxxx"
  541. droplets:
  542. droplet_directory_key: <%= root_domain %>-cc-droplets-dev
  543. fog_connection:
  544. provider: "AWS"
  545. host: "s3.com"
  546. scheme: "http"
  547. port: 80
  548. aws_signature_version: "2"
  549. aws_access_key_id: "xxxxxxxxxxxxxxxxxxxx"
  550. aws_secret_access_key: "xxxxxxxxxxxxxxxxxx"
  551. buildpacks:
  552. buildpack_directory_key: <%= root_domain %>-cc-buildpacks-dev
  553. fog_connection:
  554. provider: "AWS"
  555. host: "s3.com"
  556. scheme: "http"
  557. port: 80
  558. aws_signature_version: "2"
  559. aws_access_key_id: "xxxxxxxxxxxxxxxxxxxxxxxxx"
  560. aws_secret_access_key: "xxxxx+xxxxxxxxxxxxxxxxxxxxx"
  561. quota_definitions:
  562. free:
  563. non_basic_services_allowed: true
  564. total_services: 4
  565. total_routes: 1000
  566. memory_limit: 8192
  567. paid:
  568. non_basic_services_allowed: true
  569. total_services: 32
  570. total_routes: 1000
  571. memory_limit: 204800
  572. runaway:
  573. non_basic_services_allowed: true
  574. total_services: 500
  575. total_routes: 1000
  576. memory_limit: 204800
  577. trial:
  578. non_basic_services_allowed: false
  579. total_services: 10
  580. total_routes: 1000
  581. memory_limit: 2048
  582. trial_db_allowed: true
  583. default_quota_definition: free
  584. hm9000_noop: false
  585. system_buildpacks:
  586. - name: staticfile_buildpack
  587. package: buildpack_staticfile
  588. - name: java_buildpack
  589. package: buildpack_java
  590. - name: ruby_buildpack
  591. package: buildpack_ruby
  592. - name: nodejs_buildpack
  593. package: buildpack_nodejs
  594. - name: go_buildpack
  595. package: buildpack_go
  596. - name: python_buildpack
  597. package: buildpack_python
  598. - name: php_buildpack
  599. package: buildpack_php
  600. - name: binary_buildpack
  601. package: buildpack_binary
  602. default_buildpacks:
  603. - name: staticfile_buildpack
  604. package: buildpack_staticfile
  605. - name: java_buildpack
  606. package: buildpack_java
  607. - name: ruby_buildpack
  608. package: buildpack_ruby
  609. - name: nodejs_buildpack
  610. package: buildpack_nodejs
  611. - name: go_buildpack
  612. package: buildpack_go
  613. - name: python_buildpack
  614. package: buildpack_python
  615. - name: php_buildpack
  616. package: buildpack_php
  617. - name: binary_buildpack
  618. package: buildpack_binary
  619. install_buildpacks:
  620. - name: staticfile_buildpack
  621. package: buildpack_staticfile
  622. - name: java_buildpack
  623. package: buildpack_java
  624. - name: ruby_buildpack
  625. package: buildpack_ruby
  626. - name: nodejs_buildpack
  627. package: buildpack_nodejs
  628. - name: go_buildpack
  629. package: buildpack_go
  630. - name: python_buildpack
  631. package: buildpack_python
  632. - name: php_buildpack
  633. package: buildpack_php
  634. - name: binary_buildpack
  635. package: buildpack_binary
  636. security_group_definitions:
  637. - name: public_networks
  638. rules:
  639. - protocol: all
  640. destination: 0.0.0.0-9.255.255.255
  641. - protocol: all
  642. destination: 11.0.0.0-169.253.255.255
  643. - protocol: all
  644. destination: 169.255.0.0-172.15.255.255
  645. - protocol: all
  646. destination: 172.32.0.0-192.167.255.255
  647. - protocol: all
  648. destination: 192.169.0.0-255.255.255.255
  649. - protocol: all
  650. destination: 171.0.0.0-171.255.255.255
  651. - protocol: all
  652. destination: 172.0.0.0-175.255.255.255
  653. - protocol: all
  654. destination: 10.0.0.0-11.255.255.255
  655. - name: dns
  656. rules:
  657. - protocol: tcp
  658. destination: 0.0.0.0/0
  659. ports: '53'
  660. - protocol: udp
  661. destination: 0.0.0.0/0
  662. ports: '53'
  663. default_running_security_groups: ["public_networks", "dns"]
  664. default_staging_security_groups: ["public_networks", "dns"]
  665.  
  666. ccng: *cc
  667.  
  668. login:
  669. protocol: <%= protocol %>
  670. links:
  671. home: <%= protocol %>://console.<%= root_domain %>
  672. passwd: <%= protocol %>://console.<%= root_domain %>/password_resets/new
  673. signup: <%= protocol %>://console.<%= root_domain %>/register
  674.  
  675. uaa:
  676. url: <%= protocol %>://uaa.<%= root_domain %>
  677. no_ssl: null
  678. require_https: false
  679. ssl:
  680. port: -1
  681. port: 8080
  682. catalina_opts: -Xmx768m -XX:MaxPermSize=256m
  683. resource_id: account_manager
  684. jwt:
  685. signing_key: |+
  686. -----BEGIN RSA PRIVATE KEY-----
  687. MIIEpQIBAAKCAQEAyRRDqBAk7BM4VsXgEcfnORsFw/ujkiCoKJjfSGZxMCSUbrKc
  688. ZmBvzoTehOxKtGToWXOcve9vImVk7m2j1XSwsOkf33IutN/i0ao8E7Ze4fiflWSt
  689. MoX5vWuXGcycUSg/BSTXPO4ss94FB5mhqNIDJ1QU9dJS73wrBTqNe66XskGKj9yr
  690. iGzDkHDMoqlfKspdW6iEHvVbkB1rF7VXnufIA5earf5eIkq5HV+C3YahS6Z16jww
  691. MnsOfi0w+ThmRHyG2jck89PkenDyNhwkqp93mqgprSmukYkqQbZYpfffIfLpNv5M
  692. RQgAI60i6vtRQ5Utu9FgEHoX0KqLhf8PldV90wIDAQABAoIBACsKV2EF86FEi+6m
  693. 9EtaCrhCfH1yw5RnwRbPghuxMdEoQ01elfOj+MqvziGNon/yiXl8MbTGJ3epVG1k
  694. sojiLV/wxo3BlxXIRniyg6GEi9K6sQ39OsVxv/83pGQ1U9BbWQH03M2B/beScmkq
  695. DVxhd6NXcBUeK/pvDZZU7ivnNzlERP+IPtdPb3bP33Lec5Wv5XN2lHsxUYZPKYiH
  696. jpvRXYedQBlNE/fwU4zRMZwu94bD2XbE9Y/IkdLw01jZxU4RoW1Hn1L0RiBoFwtO
  697. so7L6RDBhv3/GKbo0cYjz5x7TNMrXe3rzt7pJmqADphUZJeWzh99xaPA36kAh0sq
  698. 1wiHMkECgYEA6yW5/+DpqTqabK1/yFa4Nzxwl0/Z3b7pbYeBsnU2KtNltafU+Cvw
  699. Nl28ika1up9jeMw7DCO6YbX5y5oOjqlYkA9cXmP8KF3VCaqcI9JQNM4AbbzPL/mX
  700. oOGOUtEG6NeWxB8FoszWKRJhuMcwadoPRhxVgdDyWXf8qt+HXYyWq2sCgYEA2ukg
  701. lVNOISfvObrzBAd4XDlse9m7ah1mNxcnLa2sMApCQEvs3Fg8qhKxhrBauXTLonr1
  702. Ty9qlREmNvz2Vw+8ZAP98vhO/fFIC4V7hDZI1viNUFmmXOfGdLyKnA3TX98ycZIi
  703. 6ag56yXoVn8hUL87fV7iMGowAxNBeMgB1p57uTkCgYEAydRA2IJ4q/sT7rHgWtks
  704. FqT20rkD+9NQUeWcCcuXKZz20Lt0DWrRLCi6mkjk1IDYBSfuipXj9NgXxoy9b++k
  705. h0nX82CIXzFimIBqskhi9V/XeFk10Cy/26Od4DFvZ80bp8wkrz53lxsi61F0mXZD
  706. 496P+fOY//f/0742VrJD5G8CgYEAxxDwPFpA1g3GkSzcCHHylYryh717nAeYB8ja
  707. K8OerSDnFij0/3qNz+qn3N9J4RPAicReht+LgHrT0XU/XfRFUH4A1I3Q50QeS7va
  708. kmP64OGtP8AGdL2fzlAVi8tWx/vjlztY3DnKUXdrTBzXYuJDasJ51aT6fBFqnDbk
  709. 1RHRWKECgYEAuYBkkwB1gUWSyHsYFkdvTBG7rOwZmTiraZnMkdkHpwfjN4TSXg8y
  710. sPW3XeHrT6qFtbD++BFEJbipIvCLQt1S+le/zwPbMzK5iOcVNqe/SdJXqyz8h0vK
  711. z/J8npVJV6Y64F1ilr7KBegMxxnI4WqFbJ7pw6ZYExkQsqPZ/i9EeW4=
  712. -----END RSA PRIVATE KEY-----
  713. verification_key: |+
  714. -----BEGIN PUBLIC KEY-----
  715. MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyRRDqBAk7BM4VsXgEcfn
  716. ORsFw/ujkiCoKJjfSGZxMCSUbrKcZmBvzoTehOxKtGToWXOcve9vImVk7m2j1XSw
  717. sOkf33IutN/i0ao8E7Ze4fiflWStMoX5vWuXGcycUSg/BSTXPO4ss94FB5mhqNID
  718. J1QU9dJS73wrBTqNe66XskGKj9yriGzDkHDMoqlfKspdW6iEHvVbkB1rF7VXnufI
  719. A5earf5eIkq5HV+C3YahS6Z16jwwMnsOfi0w+ThmRHyG2jck89PkenDyNhwkqp93
  720. mqgprSmukYkqQbZYpfffIfLpNv5MRQgAI60i6vtRQ5Utu9FgEHoX0KqLhf8PldV9
  721. 0wIDAQAB
  722. -----END PUBLIC KEY-----
  723. cc:
  724. client_secret: <%= common_password %>
  725. admin:
  726. client_secret: <%= common_password %>
  727. batch:
  728. username: batch
  729. password: <%= common_password %>
  730. client:
  731. autoapprove:
  732. - cf
  733. - vmc
  734. - my
  735. - micro
  736. - support-signon
  737. - login
  738. - styx
  739. clients:
  740. cc_routing:
  741. authorities: routing.router_groups.read
  742. authorized-grant-types: client_credentials
  743. secret: <%= common_password %>
  744. cf:
  745. access-token-validity: 600
  746. authorities: uaa.none
  747. authorized-grant-types: implicit,password,refresh_token
  748. autoapprove: true
  749. override: true
  750. refresh-token-validity: 2592000
  751. scope: cloud_controller.read,cloud_controller.write,openid,password.write,cloud_controller.admin,scim.read,scim.write,doppler.firehose,uaa.user,routing.router_groups.read
  752. cloud_controller_username_lookup:
  753. authorities: scim.userids
  754. authorized-grant-types: client_credentials
  755. secret: <%= common_password %>
  756. doppler:
  757. authorities: uaa.resource
  758. override: true
  759. secret: <%= common_password %>
  760. gorouter:
  761. authorities: routing.routes.read
  762. authorized-grant-types: client_credentials,refresh_token
  763. secret: <%= common_password %>
  764. login:
  765. authorities: oauth.login,scim.write,clients.read,notifications.write,critical_notifications.write,emails.write,scim.userids,password.write
  766. authorized-grant-types: authorization_code,client_credentials,refresh_token
  767. autoapprove: true
  768. override: true
  769. redirect-uri: <%= protocol %>://login.<%= root_domain %>
  770. scope: openid,oauth.approvals
  771. secret: <%= common_password %>
  772. notifications:
  773. authorities: cloud_controller.admin,scim.read
  774. authorized-grant-types: client_credentials
  775. secret: <%= common_password %>
  776. tcp_emitter:
  777. authorities: routing.routes.write,routing.routes.read
  778. authorized-grant-types: client_credentials,refresh_token
  779. secret: <%= common_password %>
  780. tcp_router:
  781. authorities: routing.routes.read
  782. authorized-grant-types: client_credentials,refresh_token
  783. secret: <%= common_password %>
  784. scim:
  785. userids_enabled: true
  786. users:
  787. - admin|<%= common_password %>|scim.write,scim.read,openid,cloud_controller.admin,uaa.admin,password.write
  788. - services|<%= common_password %>|scim.write,scim.read,openid,cloud_controller.admin
  789. - cloudfoundry|<%= common_password %>|scim.write,scim.read,openid,cloud_controller.admin
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement