Example
A complete seed file, section by section
The following seed file declares every section except oauth2; secrets come from environment variables such as ${SEED_AWX_TOKEN}:
version: 1
awx:
items:
- name: tower
uri: https://tower.example.com
token: ${SEED_AWX_TOKEN}
is_default: true
secret_stores:
items:
- name: vault
type: vault
url: https://vault.example.com:8200
token: ${SEED_VAULT_TOKEN}
credentials:
items:
- name: production-db
user: svc_forms
password: ${SEED_DB_PW}
host: db.example.com
port: 3306
db_type: mysql
is_database: true
repositories:
prune: true
items:
- name: forms
uri: https://git.example.com/forms.git
branch: main
use_for_forms: true
use_for_config: true
rebase_on_start: true
# ldap and settings are single-row sections, so EVERY field must be declared - see
# "Single-row sections are all or nothing" below. Empty is a perfectly good value.
ldap:
server: ldap.example.com
port: 389
ignore_certs: false
enable_tls: false
cert: ""
ca_bundle: ""
bind_user_dn: cn=bind,dc=example,dc=com
bind_user_pw: ${SEED_LDAP_PW}
search_base: dc=example,dc=com
username_attribute: uid
groups_attribute: memberOf
enable: true
groups_search_base: ""
group_class: ""
group_member_attribute: ""
group_member_user_attribute: ""
mail_attribute: mail
groupfilter: "" # optional, see below
settings:
mail_server: smtp.example.com
mail_port: 587
mail_secure: false
mail_username: ""
mail_password: ""
mail_from: ansibleforms@example.com
url: https://forms.example.com
chat: # the chat assistant's model provider (6.5)
provider: anthropic # see below, or "" (chat off)
api_key: ${SEED_CHAT_API_KEY}
base_url: "" # empty for the provider default ; azure and custom need one
model: claude-opus-5-5
max_turns: 20
max_tool_rounds: 6
timeout_seconds: 60
allow_job_status: true
# optional - for a proxy or a vendor with its own ways
auth_type: "" # "" (provider default) | bearer | api-key | x-api-key | none
api_version: "" # e.g. 2024-10-21 for Azure OpenAI
request_user: "" # sent as user, e.g. for a proxy that requires one
ignore_certs: false # true skips the certificate check (a self-signed proxy) - insecure
extra_headers: # a mapping of extra request headers
X-Org: ops
provider is one of:
anthropicopenaiazuregeminigrokmistraldeepseekgroqopenrouterollamacustom: any other OpenAI-compatible endpoint
Like ldap, the chat section is a single row, so every field is required except the optional ones; an optional field that is omitted is left unchanged. The chat assistant also needs ENABLE_CHAT=1; see the Chat assistant page.