feat(demo): add full inventories for mbazürich and phbern
Both demo sites had only a hosts.yml, so every role ran on its defaults (authentik.local.test etc.) and nothing was reachable under the real FQDN. Add the complete group_vars + host_vars analogous to gymburgdorf, with the mbaz.souveredu.ch / phbe.souveredu.ch domain bases, matching Bao mounts, DMZ split-horizon (public + *.int.*), authentik OIDC/LDAP/proxy outposts, nextcloud with S3+LDAP+OIDC, collabora, drawio, garage, send, opnform, homarr and bookstack. authentik_domains lists the *.int.* name too so Traefik requests a cert the DMZ can verify; the storage proxy outpost carries a config block (required by the outpost blueprint serializer).
This commit is contained in:
parent
a8c8ac3e1e
commit
d45e358efc
44 changed files with 1458 additions and 10 deletions
2
inventories/demo-mbazürich/group_vars/all/ansible.yml
Normal file
2
inventories/demo-mbazürich/group_vars/all/ansible.yml
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
---
|
||||
ansible_python_interpreter: /usr/bin/python3
|
||||
1
inventories/demo-mbazürich/group_vars/all/docker.yml
Normal file
1
inventories/demo-mbazürich/group_vars/all/docker.yml
Normal file
|
|
@ -0,0 +1 @@
|
|||
docker_registry_mirrors: ["https://registry-mirror.wksbern.ch"]
|
||||
2
inventories/demo-mbazürich/group_vars/all/vault.yml
Normal file
2
inventories/demo-mbazürich/group_vars/all/vault.yml
Normal file
|
|
@ -0,0 +1,2 @@
|
|||
vault_addr: "https://bao.digitalboard.ch"
|
||||
vault_mount: "demo-mbazürich"
|
||||
|
|
@ -0,0 +1 @@
|
|||
traefik_mode: backend
|
||||
|
|
@ -0,0 +1,19 @@
|
|||
_acme_tsig: "{{ lookup('community.hashi_vault.hashi_vault', vault_mount + '/data/acme-tsig', url=vault_addr ) }}"
|
||||
|
||||
traefik_use_ssl: true
|
||||
traefik_cert_mode: "acme"
|
||||
traefik_ssl_email: "hostmaster@digitalboard.ch"
|
||||
traefik_log_level: DEBUG
|
||||
traefik_network: proxy
|
||||
|
||||
traefik_acme_dns_zone: "demo-mbaz._acme.digitalboard.ch"
|
||||
traefik_acme_dns_nameserver: "{{ _acme_tsig.server }}"
|
||||
traefik_acme_tsig_algorithm: "hmac-sha256"
|
||||
traefik_acme_tsig_key: "{{ _acme_tsig.tsig_key }}"
|
||||
traefik_acme_tsig_secret: "{{ _acme_tsig.tsig_secret }}"
|
||||
|
||||
# UDP/53 egress from the traefik container reaches ns1.digitalboard.ch
|
||||
# unreliably (i/o timeouts on lego's recursive SOA pre-check), while
|
||||
# TCP/53 to the same nameserver is open. Force lego to do its DNS
|
||||
# lookups over TCP so the DNS-01 challenge can proceed.
|
||||
traefik_acme_tcp_only: true
|
||||
Loading…
Add table
Add a link
Reference in a new issue