- ansipa Setup Guide: add a Firewall section — which inbound ports to open on
the server (minimum LDAP/Kerberos/HTTPS + per-feature SMB/CheckMK/Keycloak/
gateway), that clients need nothing inbound for policy enforcement or CheckMK
push mode, and copy-paste firewalld / ufw / nftables rule examples.
- freeipa-ansible.md: reflect the now-supported mixed fleet (Arch, Fedora,
RHEL/Rocky/Alma, Debian/Ubuntu) instead of "Arch-only", note the Arch
autofs/AUR enrollment caveat, and cross-link the setup guide.
Nothing about the deployment is left to guesswork: architecture, every port,
firewall rules, the nginx portal + reverse-proxy snippets, NAT/push-mode, the
Proxmox LXC generator, and the tools reorg paths are all documented.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01MUhrcFU8J1Hnf7vNqNxZNi